ComboFix 07-08-04.3 - “Administrator” 2007-08-05 13:12:16.3 [GMT 2:00] - NTFS Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.Prawda ((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 ))))))))))))))))))))))))))))))) 2007-08-05 13:02 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-05 12:47 2007-08-05 12:05 416 --a------ C:\CFCleanUp.bat 2007-08-05 11:13 2007-08-01 20:27 2007-08-01 20:06 2007-07-30 14:06 64,000 --a------ C:\WINDOWS\system32\drivers\e4ldr.sys 2007-07-30 14:06 50,007 --a------ C:\WINDOWS\system32\drivers\adildr.sys 2007-07-30 14:06 46,892 --a------ C:\WINDOWS\system32\ADADIX16.DLL 2007-07-30 14:06 4,981 --a------ C:\WINDOWS\system32\ADADIX2K.DLL 2007-07-30 14:06 24,576 --a------ C:\WINDOWS\enddisk32.exe 2007-07-30 14:06 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin 2007-07-30 14:06 176,128 --a------ C:\WINDOWS\autoclk.exe 2007-07-30 14:06 155,648 --a------ C:\WINDOWS\system32\adadix32.dll 2007-07-30 14:06 152,220 --a------ C:\WINDOWS\system32\drivers\L1E4I2.BIN 2007-07-30 14:06 152,220 --a------ C:\WINDOWS\system32\drivers\L1E4I1.BIN 2007-07-30 14:06 152,220 --a------ C:\WINDOWS\system32\drivers\L1E4I0.BIN 2007-07-30 14:06 152,132 --a------ C:\WINDOWS\system32\drivers\L1E4P2.BIN 2007-07-30 14:06 152,132 --a------ C:\WINDOWS\system32\drivers\L1E4P1.BIN 2007-07-30 14:06 152,132 --a------ C:\WINDOWS\system32\drivers\L1E4P0.BIN 2007-07-30 14:06 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P2.BIN 2007-07-30 14:06 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P1.BIN 2007-07-30 14:06 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P0.BIN 2007-07-30 14:06 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I2.BIN 2007-07-30 14:06 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I1.BIN 2007-07-30 14:06 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I0.BIN 2007-07-30 14:06 152,036 --a------ C:\WINDOWS\system32\drivers\L1E4D2.BIN 2007-07-30 14:06 152,034 --a------ C:\WINDOWS\system32\drivers\L1E4D1.BIN 2007-07-30 14:06 152,034 --a------ C:\WINDOWS\system32\drivers\L1E4D0.BIN 2007-07-30 14:06 143,360 --a------ C:\WINDOWS\adiras.exe 2007-07-30 14:06 135,168 --a------ C:\WINDOWS\system32\unaddrv.exe 2007-07-30 14:06 127,456 --a------ C:\WINDOWS\system32\IPDETECT.EXE 2007-07-30 14:06 126,976 --a------ C:\WINDOWS\system32\coclassfast.dll 2007-07-30 14:06 126,489 --a------ C:\WINDOWS\system32\drivers\adiusbaw.sys 2007-07-30 14:06 116,992 --a------ C:\WINDOWS\system32\drivers\e4usbaw.sys 2007-07-30 14:06 2007-07-29 20:05 2007-07-29 19:56 2007-07-22 02:21 2007-07-21 09:49 2007-07-21 01:30 2007-07-21 01:30 2007-07-21 01:30 2007-07-11 18:53 2007-07-11 14:21 2007-07-11 13:44 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe 2007-07-08 11:39 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2007-07-08 11:39 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2007-07-08 11:39 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-05 13:11 281408 --a------ C:\WINDOWS\system32\drivers\APPFCONT.DAT 2007-08-05 13:11 1132 --a------ C:\WINDOWS\system32\drivers\APPFLTR.CFG 2007-08-05 12:57 --------- d-------- C:\DOCUME~1\ADMINI~1\DANEAP~1\Skype 2007-08-05 12:49 --------- d-------- C:\Program Files\eMule 2007-08-05 12:32 --------- d-------- C:\Program Files\Gadu-Gadu 2007-08-05 12:31 --------- d-------- C:\Program Files\Winamp 2007-08-05 11:42 --------- d-------- C:\Program Files\CCleaner 2007-08-04 18:27 --------- d-------- C:\DOCUME~1\ADMINI~1\DANEAP~1\uTorrent 2007-08-04 18:15 --------- d-------- C:\Program Files\uTorrent 2007-08-04 17:31 --------- d-------- C:\Program Files\UberIcon 2007-08-04 17:31 --------- d-------- C:\Program Files\TuneUp Utilities 2006 2007-08-04 17:31 --------- d-------- C:\Program Files\CursorXP 2007-08-04 17:31 --------- d-------- C:\Program Files\ClocX 2007-08-04 17:31 --------- d-------- C:\Program Files\ATS2 2007-08-03 18:25 --------- d-------- C:\Program Files\WinZix 2007-08-01 22:30 --------- d-------- C:\Program Files\SubEdit-Player 2007-08-01 19:37 --------- d-------- C:\Program Files\Anti-Trojan-55 2007-08-01 00:05 --------- d-------- C:\Program Files\FrostWire 2007-07-31 18:04 126289 --a------ C:\WINDOWS\HPHins12.dat 2007-07-30 14:06 33 --a------ C:\WINDOWS\system32\drivers\adidsl.cfg 2007-07-30 14:06 --------- d–h----- C:\Program Files\InstallShield Installation Information 2007-07-29 20:05 --------- d-------- C:\Program Files\Skype 2007-07-29 18:08 3473 --a------ C:\WINDOWS\unins000.dat 2007-07-19 16:54 --------- d-------- C:\Program Files\Movie Maker 2007-07-18 22:27 4489 --a------ C:\WINDOWS\mozver.dat 2007-07-11 17:08 2321408 --a------ C:\WINDOWS\system32\TUKernel.exe 2007-07-11 13:50 --------- d-------- C:\Program Files\QuickTime 2007-07-11 12:39 50968 --a------ C:\WINDOWS\system32\perfc015.dat 2007-07-11 12:39 359178 --a------ C:\WINDOWS\system32\perfh015.dat 2007-07-11 12:34 --------- d-------- C:\Program Files\Common Files\Real 2007-07-11 12:33 --------- d-------- C:\DOCUME~1\ADMINI~1\DANEAP~1\Real 2007-07-11 12:27 --------- d-------- C:\Program Files\Live_TV 2007-07-10 00:39 --------- d-------- C:\Program Files\Pasek TVN24 2007-07-09 10:38 --------- d-------- C:\Program Files\AdwareAlert 2007-07-09 10:38 --------- d-------- C:\DOCUME~1\ADMINI~1\DANEAP~1\HideTheCake 2007-07-06 13:33 --------- d-------- C:\Program Files\The FilmMachine 2007-06-15 00:02 --------- d-------- C:\Program Files\HideTheCake 2007-06-12 20:53 --------- d-------- C:\Program Files\ArkMicro 2007-06-08 23:49 --------- d-------- C:\Program Files\ACE Mega CoDecS Pack 2007-06-08 23:45 --------- d-------- C:\Program Files\Codec 2007-06-08 23:25 --------- d-------- C:\Program Files\Common Files\Ahead 2007-06-08 11:54 --------- d-------- C:\DOCUME~1\ADMINI~1\DANEAP~1\Apple Computer 2007-06-07 23:10 --------- d-------- C:\Program Files\Recuva 2007-06-06 19:24 --------- d-------- C:\Program Files\IVT Corporation 2007-05-16 17:18 683520 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-04-21 09:30 476 --a------ C:\Program Files\INSTALL.LOG 2007-03-19 20:13 6422611 --a------ C:\Program Files\frostwire-4.13.1.6.windows.exe ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [2004-12-22 11:09 C:\WINDOWS\SOUNDMAN.EXE] “APVXDWIN”=“C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.exe” [2006-09-13 08:59] “GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-27 00:47] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43] “NvMediaCenter”=“NvMCTray.dll” [2006-06-01 11:22 C:\WINDOWS\system32\nvmctray.dll] “ClocX”=“C:\Program Files\ClocX\ClocX.exe” [2005-01-26 11:04] “Tweak UI”=“TWEAKUI.CPL” [2003-03-25 05:49 C:\WINDOWS\system32\tweakui.cpl] “NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-06-01 11:22] “BigDog303”=“C:\WINDOWS\VM303_STI.exe” [2005-06-23 05:13] “THGuard”=“C:\Program Files\TrojanHunter 4.7\THGuard.exe” [2007-06-23 00:19] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CursorXP”=“C:\Program Files\CursorXP\CursorXP.exe” [2005-01-19 17:34] “UberIcon”=“C:\Program Files\UberIcon\UberIcon Manager.exe” [2006-07-17 23:16] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-28 13:17:05] DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-07-30 14:06:46] HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr] avldr.dll 2005-09-27 12:13 45056 C:\WINDOWS\system32\avldr.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled] “NvCplDaemon”=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup “BigDog303”=C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH) “NeroFilterCheck”=C:\WINDOWS\system32\NeroCheck.exe “adwarealert”=C:\Program Files\AdwareAlert\AdwareAlert.exe -boot R0 BTHidMgr;Bluetooth HID Manager Service;C:\WINDOWS\system32\Drivers\BTHidMgr.sys R0 netflt;Panda Net Driver [NDIS Layer];C:\WINDOWS\system32\Drivers\NETFLT.SYS R0 sojubus;sojubus;C:\WINDOWS\system32\DRIVERS\sojubus.sys R0 sojuscsi;sojuscsi;C:\WINDOWS\system32\DRIVERS\sojuscsi.sys R1 AmdK8;Sterownik procesora AMD;C:\WINDOWS\system32\DRIVERS\AmdK8.sys R1 APPFLT;App Filter Plugin;??\C:\WINDOWS\system32\Drivers\APPFLT.SYS R1 DSAFLT;DSA Filter Plugin;??\C:\WINDOWS\system32\Drivers\DSAFLT.SYS R1 FNETMON;NetMon Filter Plugin;??\C:\WINDOWS\system32\Drivers\fnetmon.SYS R1 IDSFLT;Ids Filter Plugin;??\C:\WINDOWS\system32\Drivers\IDSFLT.SYS R1 NETFLTDI;Panda Net Driver [TDI Layer];??\C:\WINDOWS\system32\Drivers\NETFLTDI.SYS R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\drivers\ShldDrv.sys R1 SMSFLT;SMS Filter Plugin;??\C:\WINDOWS\system32\Drivers\SMSFLT.SYS R1 WNMFLT;Wifi Monitor Filter Plugin;??\C:\WINDOWS\system32\Drivers\WNMFLT.SYS R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\Drivers\cpoint.sys R2 PAVDRV;pavdrv;C:\WINDOWS\system32\DRIVERS\pavdrv51.sys R2 PavProc;Panda Process Protection Driver;??\C:\WINDOWS\system32\DRIVERS\PavProc.sys R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe -k netsvcs R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys R3 BlueletAudio;Bluetooth Audio Service;C:\WINDOWS\system32\DRIVERS\blueletaudio.sys R3 BTHidEnum;Bluetooth HID Enumerator;C:\WINDOWS\system32\DRIVERS\vbtenum.sys R3 ComFiltr;Panda Anti-Dialer;??\C:\WINDOWS\system32\DRIVERS\COMFiltr.sys R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys R3 PavTPK.sys;PavTPK.sys;??\C:\WINDOWS\system32\PavTPK.sys R3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32\Drivers\RootMdm.sys R3 VcommMgr;Bluetooth VComm Manager Service;C:\WINDOWS\system32\Drivers\VcommMgr.sys R3 ZSMC303;VIMICRO USB PC Camera (ZC0301PLH);C:\WINDOWS\system32\Drivers\usbVM303.sys S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys S2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\system32\DRIVERS\nvcap.sys S2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\system32\DRIVERS\NVxbar.sys S3 BT;Bluetooth PAN Network Adapter;C:\WINDOWS\system32\DRIVERS\btnetdrv.sys S3 Btcsrusb;Bluetooth USB For Bluetooth Service;C:\WINDOWS\system32\Drivers\btcusb.sys S3 BTNetFilter;Bluetooth Network Filter;??\C:\WINDOWS\system32\drivers\BTNetFilter.sys S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service;“C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe” S3 odserv;Microsoft Office Diagnostics Service;“C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE” S3 PavSRK.sys;PavSRK.sys;??\C:\WINDOWS\system32\PavSRK.sys S3 VComm;Virtual Serial port driver;C:\WINDOWS\system32\DRIVERS\VComm.sys HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{3b21028b-eea6-11db-8752-4d6564696130}] AutoRun\command- I:\SETUP.EXE configure\command- I:\SETUP.EXE install\command- I:\SETUP.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{7be1f246-fb5b-11db-8762-4d6564696130}] AutoRun\command- K:\launcher.exe ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-05 13:15:21 Windows 5.1.2600 Dodatek Service Pack 2 NTFS detected NTDLL code modification: ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile scanning hidden processes … scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,… [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] “C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\Rar$EX00.406\Diskeeper Professional Edition 9.0.524 (espa\x144ol-spanish).by bukito.www.elitexeem.com\setup.exe”="Professional Edition for Windows® " “C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\Rar$EX01.578\Diskeeper Professional Edition 9.0.524 (espa\x144ol-spanish).by bukito.www.elitexeem.com\Parche espa\x144ol Dk Pro 9.0.524.exe”=“Parche espa\xf1ol Dk Pro 9.0.524” scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-05 13:16:29 C:\ComboFix-quarantined-files.txt … 2007-08-05 13:16 C:\ComboFix2.txt … 2007-08-05 12:11 — E O F —