ComboFix 07-08-04.3 - “Robert” 2001-01-03 7:58:35.5 [GMT 1:00] - NTFS Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.Prawda ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\svchost.exe C:\WINDOWS\system32\a.exe C:\WINDOWS\system32\kernel32.exe ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_MSDIRECT -------\msdirect ((((((((((((((((((((((((( Files Created from 2000-12-03 to 2001-01-03 ))))))))))))))))))))))))))))))) 2001-01-11 22:29 2001-01-11 18:48 2001-01-11 12:27 2001-01-09 19:04 2001-01-08 22:11 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2001-01-08 12:15 2001-01-08 10:54 2001-01-08 10:54 2001-01-08 10:54 2001-01-08 03:55 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll 2001-01-08 03:55 8,192 --a------ C:\WINDOWS\system32\kbdkor.dll 2001-01-08 03:55 6,144 --a------ C:\WINDOWS\system32\kbd106.dll 2001-01-08 03:55 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll 2001-01-08 03:55 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll 2001-01-08 03:55 5,632 --a------ C:\WINDOWS\system32\kbd103.dll 2001-01-08 03:55 2001-01-08 03:54 2001-01-08 03:54 2001-01-08 03:50 2001-01-08 03:44 2001-01-07 11:47 2001-01-07 11:47 2001-01-07 06:58 2001-01-07 03:46 97,088 -ra------ C:\WINDOWS\system32\drivers\se45mdm.sys 2001-01-07 03:46 90,800 -ra------ C:\WINDOWS\system32\drivers\se45unic.sys 2001-01-07 03:46 9,360 -ra------ C:\WINDOWS\system32\drivers\se45mdfl.sys 2001-01-07 03:46 88,624 -ra------ C:\WINDOWS\system32\drivers\se45mgmt.sys 2001-01-07 03:46 86,432 -ra------ C:\WINDOWS\system32\drivers\se45obex.sys 2001-01-07 03:46 61,536 -ra------ C:\WINDOWS\system32\drivers\se45bus.sys 2001-01-07 03:46 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cmnt.sys 2001-01-07 03:46 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cm.sys 2001-01-07 03:46 5,872 -ra------ C:\WINDOWS\system32\drivers\se45whnt.sys 2001-01-07 03:46 5,872 -ra------ C:\WINDOWS\system32\drivers\se45wh.sys 2001-01-07 03:46 4,128 -ra------ C:\WINDOWS\system32\drivers\se45cr.sys 2001-01-07 03:46 18,704 -ra------ C:\WINDOWS\system32\drivers\se45nd5.sys 2001-01-07 03:46 2001-01-07 03:45 2001-01-07 03:43 2001-01-07 03:42 2001-01-07 03:42 2001-01-07 03:42 2001-01-07 03:42 2001-01-07 03:41 2001-01-06 16:26 2001-01-06 16:17 2001-01-06 16:17 2001-01-06 16:16 2001-01-06 11:14 24,816 --a------ C:\WINDOWS\system32\mdimon.dll 2001-01-06 11:09 2001-01-06 10:44 2001-01-06 08:28 5,888 --------- C:\WINDOWS\system32\drivers\imagedrv.sys 2001-01-06 08:28 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2001-01-06 08:28 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2001-01-06 08:28 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2001-01-06 08:28 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2001-01-06 08:28 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2001-01-06 08:28 127,488 --------- C:\WINDOWS\system32\drivers\imagesrv.sys 2001-01-06 08:28 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2001-01-06 08:28 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2001-01-06 08:28 2001-01-06 06:20 2001-01-05 23:39 2001-01-05 22:10 2001-01-05 20:05 2001-01-05 17:28 18 --a------ C:\WINDOWS\system32\dna4699646.dat 2001-01-05 16:57 2001-01-05 11:21 2001-01-05 06:34 2001-01-04 07:28 2001-01-04 05:54 2001-01-04 03:21 2001-01-03 21:57 626,688 --a------ C:\WINDOWS\system32\xvid.dll 2001-01-03 21:57 414,272 --a------ C:\WINDOWS\system32\DivXc32f.dll 2001-01-03 21:57 414,272 --a------ C:\WINDOWS\system32\DivXc32.dll 2001-01-03 21:57 2001-01-03 17:12 2001-01-03 06:46 1,614 --ahs---- C:\WINDOWS\system32\index.dat 2001-01-03 04:53 2001-01-03 03:25 218 --a------ C:\WINDOWS\system32\drivers\atmapi.sys 2001-01-03 03:10 52,776 --a------ C:\WINDOWS\system32\csypm.exe 2001-01-03 03:09 178,688 --a------ C:\WINDOWS\system32\nvrsma.dll 2001-01-03 03:06 2,816 --a------ C:\WINDOWS\system32\msdirect.sys 2001-01-03 03:06 2001-01-03 03:05 980 --a------ C:\0xf9.exe 2001-01-03 02:49 42,776 --a------ C:\WINDOWS\mssadv.dll 2001-01-03 02:49 14,848 --a------ C:\svchost2.exe 2001-01-03 02:49 10,752 --a------ C:\WINDOWS\msscan.dll 2001-01-03 02:49 10,752 --a------ C:\WINDOWS\msiemon.dll 2001-01-03 02:49 10,752 --a------ C:\WINDOWS\msfw.dll 2001-01-03 02:49 10,752 --a------ C:\WINDOWS\msctrl.dll 2001-01-03 02:49 10,752 --a------ C:\WINDOWS\msavsc.dll 2001-01-03 02:49 2001-01-02 19:10 2001-01-02 19:10 2001-01-02 14:57 520,192 --a------ C:\WinDjView-0.5.exe 2001-01-02 14:57 51,200 --a------ C:\WINDOWS\nircmd.exe 2001-01-02 14:57 289,280 --a------ C:\WINDOWS\uninst.exe 2001-01-02 14:57 2001-01-02 13:03 2001-01-02 12:31 741,632 --a------ C:\WINDOWS\system32\bpmlttxh.dat (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-27 00:06 200704 --a------ C:\WINDOWS\system32\ssldivx.dll 2007-07-27 00:06 1044480 --a------ C:\WINDOWS\system32\libdivx.dll 2004-11-29 19:46 77824 --a------ C:\WINDOWS\system32\btw_ci.dll 2004-09-17 12:55 50176 --a------ C:\WINDOWS\system32\CSH.DLL 2004-08-04 01:56 1788 --a------ C:\WINDOWS\system32\Dcache.bin 2004-08-04 01:54 80256 --a------ C:\WINDOWS\system32\drivers\parport.sys 2004-08-04 01:54 63744 --a------ C:\WINDOWS\system32\drivers\mf.sys 2004-08-04 01:54 61824 --a------ C:\WINDOWS\system32\drivers\nic1394.sys 2004-08-04 01:54 60800 --a------ C:\WINDOWS\system32\drivers\arp1394.sys 2004-08-04 01:54 55296 --a------ C:\WINDOWS\system32\dmutil.dll 2004-08-04 01:54 51712 --a------ C:\WINDOWS\system32\wzcsapi.dll 2004-08-04 01:54 49152 --a------ C:\WINDOWS\system32\cnbjmon.dll 2004-08-04 01:54 47616 --a------ C:\WINDOWS\system32\iyuv_32.dll 2004-08-04 01:54 46592 --a------ C:\WINDOWS\system32\drivers\p3.sys 2004-08-04 01:54 4352 --a------ C:\WINDOWS\system32\drivers\swenum.sys 2004-08-04 01:54 41472 --a------ C:\WINDOWS\system32\drivers\amdk7.sys 2004-08-04 01:54 41088 --a------ C:\WINDOWS\system32\drivers\amdk6.sys 2004-08-04 01:54 40704 --a------ C:\WINDOWS\system32\drivers\crusoe.sys 2004-08-04 01:54 39552 --a------ C:\WINDOWS\system32\drivers\processr.sys 2004-08-04 01:54 359936 --a------ C:\WINDOWS\system32\wzcsvc.dll 2004-08-04 01:54 35328 --a------ C:\WINDOWS\system32\pid.dll 2004-08-04 01:54 30208 --a------ C:\WINDOWS\system32\drivers\modem.sys 2004-08-04 01:54 25472 --a------ C:\WINDOWS\system32\drivers\sonydcam.sys 2004-08-04 01:54 23296 --a------ C:\WINDOWS\system32\drivers\mouclass.sys 2004-08-04 01:54 20992 --a------ C:\WINDOWS\system32\hid.dll 2004-08-04 01:54 17408 --a------ C:\WINDOWS\system32\msyuv.dll 2004-08-04 01:54 16000 --a------ C:\WINDOWS\system32\drivers\usbintel.sys 2004-08-04 01:54 15488 --a------ C:\WINDOWS\system32\drivers\mssmbios.sys 2004-08-04 01:54 15360 --a------ C:\WINDOWS\system32\pjlmon.dll 2004-08-04 01:54 12928 --a------ C:\WINDOWS\system32\drivers\ndisuio.sys 2004-08-04 01:54 12416 --a------ C:\WINDOWS\system32\drivers\tunmp.sys 2004-08-04 01:46 332288 --a–c— C:\WINDOWS\system32\dllcache\netsetup.exe 2004-08-04 01:46 332288 --a------ C:\WINDOWS\system32\netsetup.exe 2004-08-04 01:44 997888 --a–c— C:\WINDOWS\system32\dllcache\msgina.dll 2004-08-04 01:44 997888 --a------ C:\WINDOWS\system32\msgina.dll 2004-08-04 01:44 996352 --a–c— C:\WINDOWS\system32\dllcache\setupapi.dll 2004-08-04 01:44 996352 --a------ C:\WINDOWS\system32\setupapi.dll 2004-08-04 01:44 99328 --a–c— C:\WINDOWS\system32\dllcache\winscard.dll 2004-08-04 01:44 99328 --a------ C:\WINDOWS\system32\winscard.dll 2004-08-04 01:44 991744 --a–c— C:\WINDOWS\system32\dllcache\syssetup.dll 2004-08-04 01:44 991744 --a------ C:\WINDOWS\system32\syssetup.dll 2004-08-04 01:44 98816 --a–c— C:\WINDOWS\system32\dllcache\loadperf.dll 2004-08-04 01:44 98816 --a------ C:\WINDOWS\system32\loadperf.dll 2004-08-04 01:44 98304 --a–c— C:\WINDOWS\system32\dllcache\slbiop.dll 2004-08-04 01:44 98304 --a–c— C:\WINDOWS\system32\dllcache\scardsvr.exe 2004-08-04 01:44 98304 --a–c— C:\WINDOWS\system32\dllcache\cscript.exe 2004-08-04 01:44 98304 --a–c— C:\WINDOWS\system32\dllcache\ahui.exe 2004-08-04 01:44 98304 --a------ C:\WINDOWS\system32\slbiop.dll 2004-08-04 01:44 98304 --a------ C:\WINDOWS\system32\scardsvr.exe 2004-08-04 01:44 98304 --a------ C:\WINDOWS\system32\cscript.exe 2004-08-04 01:44 98304 --a------ C:\WINDOWS\system32\ahui.exe 2004-08-04 01:44 97280 --a–c— C:\WINDOWS\system32\dllcache\psbase.dll 2004-08-04 01:44 97280 --a–c— C:\WINDOWS\system32\dllcache\occache.dll 2004-08-04 01:44 97280 --a------ C:\WINDOWS\system32\psbase.dll 2004-08-04 01:44 9728 --a–c— C:\WINDOWS\system32\dllcache\proxycfg.exe 2004-08-04 01:44 9728 --a------ C:\WINDOWS\system32\proxycfg.exe 2004-08-04 01:44 96768 --a–c— C:\WINDOWS\system32\dllcache\srvsvc.dll 2004-08-04 01:44 96768 --a–c— C:\WINDOWS\system32\dllcache\inseng.dll 2004-08-04 01:44 96768 --a------ C:\WINDOWS\system32\srvsvc.dll 2004-08-04 01:44 95744 --a–c— C:\WINDOWS\system32\dllcache\mqsec.dll 2004-08-04 01:44 95744 --a–c— C:\WINDOWS\system32\dllcache\iphlpapi.dll 2004-08-04 01:44 95744 --a------ C:\WINDOWS\system32\mqsec.dll 2004-08-04 01:44 93184 --a–c— C:\WINDOWS\system32\dllcache\wlnotify.dll 2004-08-04 01:44 93184 --a------ C:\WINDOWS\system32\wlnotify.dll 2004-08-04 01:44 92168 --a–c— C:\WINDOWS\system32\dllcache\rdpdd.dll 2004-08-04 01:44 92168 --a------ C:\WINDOWS\system32\rdpdd.dll 2004-08-04 01:44 92160 --a–c— C:\WINDOWS\system32\dllcache\ntprint.dll 2004-08-04 01:44 92160 --a------ C:\WINDOWS\system32\ntprint.dll 2004-08-04 01:44 9216 --a–c— C:\WINDOWS\system32\dllcache\scrnsave.scr 2004-08-04 01:44 9216 --a------ C:\WINDOWS\system32\scrnsave.scr 2004-08-04 01:44 91648 --a–c— C:\WINDOWS\system32\dllcache\xactsrv.dll 2004-08-04 01:44 91648 --a------ C:\WINDOWS\system32\xactsrv.dll 2004-08-04 01:44 91136 --a–c— C:\WINDOWS\system32\dllcache\smlogsvc.exe 2004-08-04 01:44 91136 --a–c— C:\WINDOWS\system32\dllcache\mydocs.dll 2004-08-04 01:44 91136 --a------ C:\WINDOWS\system32\smlogsvc.exe 2004-08-04 01:44 91136 --a------ C:\WINDOWS\system32\mydocs.dll 2004-08-04 01:44 90624 --a–c— C:\WINDOWS\system32\dllcache\trkwks.dll 2004-08-04 01:44 90624 --a------ C:\WINDOWS\system32\trkwks.dll 2004-08-04 01:44 896512 --a–c— C:\WINDOWS\system32\dllcache\wmspdmoe.dll 2004-08-04 01:44 896512 --a------ C:\WINDOWS\system32\wmspdmoe.dll 2004-08-04 01:44 89088 --a–c— C:\WINDOWS\system32\dllcache\rasauto.dll 2004-08-04 01:44 89088 --a–c— C:\WINDOWS\system32\dllcache\mqlogmgr.dll 2004-08-04 01:44 89088 --a------ C:\WINDOWS\system32\rasauto.dll 2004-08-04 01:44 89088 --a------ C:\WINDOWS\system32\mqlogmgr.dll 2004-08-04 01:44 88064 --a–c— C:\WINDOWS\system32\dllcache\p2pnetsh.dll 2004-08-04 01:44 88064 --a------ C:\WINDOWS\system32\p2pnetsh.dll 2004-08-04 01:44 880128 --a–c— C:\WINDOWS\system32\dllcache\netplwiz.dll 2004-08-04 01:44 880128 --a------ C:\WINDOWS\system32\netplwiz.dll 2004-08-04 01:44 87040 --a–c— C:\WINDOWS\system32\dllcache\netsh.exe 2004-08-04 01:44 87040 --a–c— C:\WINDOWS\system32\dllcache\mprapi.dll 2004-08-04 01:44 87040 --a------ C:\WINDOWS\system32\netsh.exe 2004-08-04 01:44 87040 --a------ C:\WINDOWS\system32\mprapi.dll 2004-08-04 01:44 860160 --a–c— C:\WINDOWS\system32\dllcache\tapi3.dll 2004-08-04 01:44 860160 --a------ C:\WINDOWS\system32\tapi3.dll 2004-08-04 01:44 86016 --a–c— C:\WINDOWS\system32\dllcache\p2pgasvc.dll 2004-08-04 01:44 86016 --a–c— C:\WINDOWS\system32\dllcache\msapsspc.dll 2004-08-04 01:44 86016 --a------ C:\WINDOWS\system32\p2pgasvc.dll 2004-08-04 01:44 86016 --a------ C:\WINDOWS\system32\msapsspc.dll 2004-08-04 01:44 85504 --a–c— C:\WINDOWS\system32\dllcache\makecab.exe 2004-08-04 01:44 85504 --a–c— C:\WINDOWS\system32\dllcache\diantz.exe ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{B4F69C3B-7779-43C1-8BE6-5F0094CD661E}] 2001-01-02 12:31 83456 --a------ c:\windows\system32\devmgrp.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{D6FCCA7A-9D7A-462B-AAD6-17A00E6E1F6E}] 2004-08-04 01:43 94720 --a------ C:\WINDOWS\system32\battc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43] “HPDJ Taskbar Utility”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe” [2003-05-14 08:35] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2006-01-12 15:40] “Sony Ericsson PC Suite”=“E:\SE\Application Launcher\Application Launcher.exe” [2006-11-24 01:06] “mssadv.exe”="" [] “msctrl.exe”=“C:\Program Files\Microsoft Security Adviser\msctrl.exe” [2001-01-03 02:50] “msavsc.exe”=“C:\Program Files\Microsoft Security Adviser\msavsc.exe” [2001-01-03 02:50] “msscan.exe”=“C:\Program Files\Microsoft Security Adviser\msscan.exe” [2001-01-03 02:50] “msiemon.exe”=“C:\Program Files\Microsoft Security Adviser\msiemon.exe” [2001-01-03 02:50] “msfw.exe”=“C:\Program Files\Microsoft Security Adviser\msfw.exe” [2001-01-03 02:50] “Microsoft security adviser”=“C:\Program Files\Microsoft Security Adviser\mssadv.exe” [2001-01-03 02:50] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “msctrl.exe”=“C:\Program Files\Microsoft Security Adviser\msctrl.exe” [2001-01-03 02:50] “msavsc.exe”=“C:\Program Files\Microsoft Security Adviser\msavsc.exe” [2001-01-03 02:50] “msscan.exe”=“C:\Program Files\Microsoft Security Adviser\msscan.exe” [2001-01-03 02:50] “msiemon.exe”=“C:\Program Files\Microsoft Security Adviser\msiemon.exe” [2001-01-03 02:50] “msfw.exe”=“C:\Program Files\Microsoft Security Adviser\msfw.exe” [2001-01-03 02:50] “mssadv.exe”="" [] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “DriverLoad”= “DriverCheck”= “SystemDriverLoad”= “SystemDriver”= “FDriver”= “ADriver”= C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ 22M WLAN Adapter.lnk - C:\Program Files\22M WLAN Adapter\WLANMON.exe [2001-01-01 08:17:52] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] “DisableTaskMgr”=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] “DriverLoad”= “DriverCheck”= “SystemDriverLoad”= “Winhost”= “Winhost1”= “Winhost2”= “Winhost3”= “Winhost4”= “SystemDriver”= “FDriver”= “ADriver”= [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] “System”=“cslcf.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tqnsobxs] devmgrp.dll 2001-01-02 12:31 83456 C:\WINDOWS\system32\devmgrp.dll R0 nrbjfbbt;nrbjfbbt;C:\WINDOWS\system32\drivers\igawhhpp.dat R2 rzxhjxap;USB Bus u6d71 Monitor;C:\WINDOWS\System32\svchost.exe -k netsvcs R3 ms_mpu401;Sterownik portu MIDI UART Microsoft MPU-401;C:\WINDOWS\system32\drivers\msmpu401.sys R3 TIACXLN;22M WLAN Adapter;C:\WINDOWS\system32\DRIVERS\tiacxln.sys S0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys S2 Windows Management Service;Windows Management Service;C:\WINDOWS\system32\dmbvz.exe -service S3 Maplom;Maplom;C:\WINDOWS\system32\drivers\Maplom.sys S3 pcouffin;VSO Software pcouffin;C:\WINDOWS\system32\Drivers\pcouffin.sys S3 se45bus;Sony Ericsson Device 069 driver (WDM);C:\WINDOWS\system32\DRIVERS\se45bus.sys S3 se45mdfl;Sony Ericsson Device 069 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\se45mdfl.sys S3 se45mdm;Sony Ericsson Device 069 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\se45mdm.sys S3 se45mgmt;Sony Ericsson Device 069 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\se45mgmt.sys S3 se45nd5;Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (NDIS);C:\WINDOWS\system32\DRIVERS\se45nd5.sys S3 se45obex;Sony Ericsson Device 069 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\se45obex.sys S3 se45unic;Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (WDM);C:\WINDOWS\system32\DRIVERS\se45unic.sys HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs rzxhjxap ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2001-01-03 08:03:40 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,… scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2001-01-03 8:06:08 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2001-01-03 08:05 C:\ComboFix2.txt … 2001-01-02 14:57 C:\ComboFix3.txt … 2001-01-02 14:57 — E O F —