“wazka” - 2007-06-03 19:39:54 Dodatek Service Pack 2 ComboFix 07-05.27.BV - Running from: “D:\TOOLS” ((((((((((((((((((((((((((((((( Files Created from 2007-05-03 to 2007-06-03 )))))))))))))))))))))))))))))))))) 2007-06-03 17:12 2007-06-03 16:59 2007-06-03 14:36 2007-06-01 18:52 60,273 --a------ C:\WINDOWS\system32\pthreadGC2.dll 2007-06-01 18:40 2007-06-01 17:02 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys 2007-06-01 17:02 298,104 --a------ C:\WINDOWS\system32\imon.dll 2007-06-01 17:02 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys 2007-05-21 14:39 2007-05-21 14:39 2007-05-19 12:52 2007-05-19 12:07 2007-05-19 10:21 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-05-19 10:18 2007-05-19 10:17 2007-05-19 08:47 0 --a------ C:\WINDOWS\system32\drivers\wnmsav.dat 2007-05-19 07:08 2007-05-19 02:00 2007-05-19 00:50 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2007-05-19 00:50 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2007-05-19 00:20 2007-05-19 00:20 2007-05-19 00:20 2007-05-19 00:19 2007-05-18 23:32 2007-05-18 22:07 2007-05-18 22:06 2007-05-18 21:46 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-05-18 21:45 2007-05-18 21:44 2007-05-18 21:44 2007-05-18 21:28 2007-05-18 21:14 2007-05-18 21:14 2007-05-18 21:14 2007-05-18 20:58 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys 2007-05-18 20:58 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys 2007-05-18 20:58 2007-05-18 19:24 2007-05-18 18:15 20,096 --a------ C:\WINDOWS\system32\drivers\PCASp50.SYS 2007-05-18 18:15 123,392 --a------ C:\WINDOWS\system32\dzip32.dll 2007-05-18 18:15 2007-05-18 18:15 2007-05-18 18:15 2007-05-18 18:15 2007-05-18 18:11 92,416 -ra------ C:\WINDOWS\system32\drivers\cfvn4c51.sys 2007-05-18 18:11 92,288 -ra------ C:\WINDOWS\system32\drivers\cfvn4c50.sys 2007-05-18 18:11 9,900 -ra------ C:\WINDOWS\system32\drivers\WCMLib2K.sys 2007-05-18 18:11 9,600 -ra------ C:\WINDOWS\system32\drivers\WCMLibXP.sys 2007-05-18 18:11 87,456 -ra------ C:\WINDOWS\system32\drivers\k600mdm.sys 2007-05-18 18:11 8,064 --a------ C:\WINDOWS\system32\drivers\gtptser.sys 2007-05-18 18:11 79,248 -ra------ C:\WINDOWS\system32\drivers\k600mgmt.sys 2007-05-18 18:11 77,952 -ra------ C:\WINDOWS\system32\drivers\nwusbmdm.sys 2007-05-18 18:11 77,072 -ra------ C:\WINDOWS\system32\drivers\k600obex.sys 2007-05-18 18:11 76,045 -ra------ C:\WINDOWS\system32\drivers\WCMBus2K.sys 2007-05-18 18:11 71,552 -ra------ C:\WINDOWS\system32\drivers\WCMBusXP.sys 2007-05-18 18:11 70,388 -ra------ C:\WINDOWS\system32\drivers\WS01UPH.BIN 2007-05-18 18:11 7,296 -ra------ C:\WINDOWS\system32\drivers\semwlntp.sys 2007-05-18 18:11 7,278 -ra------ C:\WINDOWS\system32\drivers\nmwcdc.sys 2007-05-18 18:11 67,840 -ra------ C:\WINDOWS\system32\drivers\NWADIEnum.sys 2007-05-18 18:11 63,360 -ra------ C:\WINDOWS\system32\drivers\nwusbser.sys 2007-05-18 18:11 6,672 -ra------ C:\WINDOWS\system32\drivers\k600wh95.sys 2007-05-18 18:11 6,112 -ra------ C:\WINDOWS\system32\drivers\k600cmnt.sys 2007-05-18 18:11 6,096 -ra------ C:\WINDOWS\system32\drivers\k600mdfl.sys 2007-05-18 18:11 58,856 -ra------ C:\WINDOWS\system32\drivers\dpphys.sys 2007-05-18 18:11 57,536 -ra------ C:\WINDOWS\system32\drivers\WCMVmd2K.sys 2007-05-18 18:11 57,344 -ra------ C:\WINDOWS\system32\drivers\V620.dll 2007-05-18 18:11 55,808 -ra------ C:\WINDOWS\system32\drivers\WCMVmdXP.sys 2007-05-18 18:11 53,248 -ra------ C:\WINDOWS\system32\drivers\GCXXNet.sys 2007-05-18 18:11 53,248 -ra------ C:\WINDOWS\system32\drivers\CInsX500.dll 2007-05-18 18:11 53,040 -ra------ C:\WINDOWS\system32\drivers\nmwcdcls.dll 2007-05-18 18:11 52,864 -ra------ C:\WINDOWS\system32\drivers\GTEDGNet.sys 2007-05-18 18:11 52,384 -ra------ C:\WINDOWS\system32\drivers\k600bus.sys 2007-05-18 18:11 51,328 -ra------ C:\WINDOWS\system32\drivers\uart0.sys 2007-05-18 18:11 50,206 -ra------ C:\WINDOWS\system32\drivers\Serialnw.sys 2007-05-18 18:11 5,744 -ra------ C:\WINDOWS\system32\drivers\k600whnt.sys 2007-05-18 18:11 45,161 -ra------ C:\WINDOWS\system32\drivers\GCXXLog.exe 2007-05-18 18:11 4,990 -ra------ C:\WINDOWS\system32\drivers\PCX500MP.SYS 2007-05-18 18:11 4,960 -ra------ C:\WINDOWS\system32\drivers\nmwcdlog.dll 2007-05-18 18:11 4,480 -ra------ C:\WINDOWS\system32\drivers\g3grpm.sys 2007-05-18 18:11 38,656 -ra------ C:\WINDOWS\system32\drivers\ZD1UXP.SYS 2007-05-18 18:11 368,896 -ra------ C:\WINDOWS\system32\drivers\semwl5.sys 2007-05-18 18:11 35 --a------ C:\WINDOWS\system32\RTELM.dll 2007-05-18 18:11 32,000 --a------ C:\WINDOWS\system32\drivers\gtf32bus.sys 2007-05-18 18:11 3,984 -ra------ C:\WINDOWS\system32\drivers\k600cr.sys 2007-05-18 18:11 280,576 -ra------ C:\WINDOWS\system32\drivers\Mrvw123.sys 2007-05-18 18:11 280,448 -ra------ C:\WINDOWS\system32\drivers\Mrvw125.sys 2007-05-18 18:11 269,056 -ra------ C:\WINDOWS\system32\drivers\NWVNdis.sys 2007-05-18 18:11 266,496 -ra------ C:\WINDOWS\system32\drivers\gtwl5.sys 2007-05-18 18:11 26,496 -ra------ C:\WINDOWS\system32\drivers\g3grumdm.sys 2007-05-18 18:11 258,560 -ra------ C:\WINDOWS\system32\drivers\MRV8K51.sys 2007-05-18 18:11 258,432 -ra------ C:\WINDOWS\system32\drivers\MRV8K50.SYS 2007-05-18 18:11 241,792 -ra------ C:\WINDOWS\system32\drivers\nw620.sys 2007-05-18 18:11 23,296 -ra------ C:\WINDOWS\system32\drivers\g3gruser.sys 2007-05-18 18:11 222,782 -ra------ C:\WINDOWS\system32\drivers\PCX500.SYS 2007-05-18 18:11 22,284 -ra------ C:\WINDOWS\system32\drivers\WcmSc2K.sys 2007-05-18 18:11 21,888 -ra------ C:\WINDOWS\system32\drivers\GTEDGSC.sys 2007-05-18 18:11 21,888 -ra------ C:\WINDOWS\system32\drivers\GCXXSC.sys 2007-05-18 18:11 21,224 -ra------ C:\WINDOWS\system32\drivers\DPFDrv.sys 2007-05-18 18:11 21,120 -ra------ C:\WINDOWS\system32\drivers\WcmScXP.sys 2007-05-18 18:11 18,944 --a------ C:\WINDOWS\system32\drivers\gtscser.sys 2007-05-18 18:11 16,256 -ra------ C:\WINDOWS\system32\drivers\g3grsc.sys 2007-05-18 18:11 128,797 -ra------ C:\WINDOWS\system32\drivers\nmwcd.sys 2007-05-18 18:11 114,944 -ra------ C:\WINDOWS\system32\drivers\GCXX.sys 2007-05-18 18:11 107,904 -ra------ C:\WINDOWS\system32\drivers\GTEDG.sys 2007-05-18 18:11 10,991 -ra------ C:\WINDOWS\system32\drivers\nmwcdcm.sys 2007-05-18 18:11 10,991 -ra------ C:\WINDOWS\system32\drivers\nmwcdcj.sys 2007-05-18 18:11 10,672 -ra------ C:\WINDOWS\system32\drivers\k600cm95.sys 2007-05-18 18:11 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-01 16:52:21 -------- d-----w C:\Program Files\ffdshow 2007-05-30 20:26:36 -------- d-----w C:\Program Files\SubEdit-Player 2007-05-30 20:25:30 -------- d-----w C:\Program Files\Winamp 2007-05-29 23:25:38 -------- d-----w C:\Program Files\IrfanView 2007-05-29 08:22:16 -------- d-----w C:\Program Files\Quintessential Media Player 2007-05-26 07:25:54 10,752 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2007-05-22 17:23:34 51,166 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-05-22 17:23:34 359,284 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-05-19 00:03:53 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-05-18 17:24:54 -------- d-----w C:\Program Files\Panda Software 2007-05-03 15:49:14 -------- d-----w C:\DOCUME~1\wazka\DANEAP~1\Image Zone Express 2007-04-18 16:14:32 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-04-09 21:55:41 -------- d-----w C:\Program Files\Max Payne 2007-04-09 17:22:18 -------- d-----w C:\Program Files\Symantec 2007-04-09 17:22:18 -------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-03-17 13:47:17 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll 2007-03-15 10:00:36 466,432 ----a-w C:\WINDOWS\system32\SkanerOnline.dll 2007-03-08 15:51:57 579,584 ----a-w C:\WINDOWS\system32\user32.dll 2007-03-08 15:51:57 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll 2007-03-08 15:51:57 282,112 ----a-w C:\WINDOWS\system32\gdi32.dll 2007-03-08 15:49:53 1,844,224 ----a-w C:\WINDOWS\system32\win32k.sys (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2005-07-08 21:05] “High Definition Audio Property Page Shortcut”=“HDAShCut.exe” [2005-01-07 18:07 C:\WINDOWS\system32\HdAShCut.exe] “RTHDCPL”=“RTHDCPL.EXE” [] “RemoteControl”=“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [2005-01-12 04:01] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2007-02-13 20:29] “nod32kui”=“C:\Program Files\Eset\nod32kui.exe” [2007-06-01 17:02] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “RTEGPRS”=“C:\Program Files\Common Files\SmartCom\RTEGPRS.exe” [2006-04-18 09:53] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-04-19 17:43] “Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-01-22 15:23] “PeerGuardian”=“C:\Program Files\PeerGuardian2\pg2.exe” [2005-09-18 18:40] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 02:44] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoLowDiscSpaceChecks”=000000000000f03f [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Ralink Wireless Utility.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Ralink Wireless Utility.lnk backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] “C:\Program Files\DAEMON Tools\daemon.exe” -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] C:\Program Files\Winamp\winampa.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs* ******************************************************************** catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-03 19:41:11 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ******************************************************************** Completion time: 2007-06-03 19:41:45 — E O F —