ComboFix 07-12-21.4 - piotr 2007-12-21 11:32:01.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1250.1.1045.18.1236 [GMT 1:00] Running from: C:\Users\piotr\Desktop\instalki\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-11-21 to 2007-12-21 ))))))))))))))))))))))))))))))) . 2007-12-21 03:01 . 2007-12-21 03:02 2007-12-21 03:01 . 2007-12-21 03:02 2007-12-20 18:35 . 2007-12-21 11:01 2007-12-20 17:03 . 2007-12-20 17:03 2007-12-20 15:47 . 2007-12-20 15:47 2007-12-20 14:15 . 2007-12-20 14:15 2007-12-20 14:15 . 2007-12-20 14:15 2007-12-20 14:15 . 2007-12-20 14:15 2007-12-20 14:14 . 2007-12-20 14:14 2007-12-19 10:47 . 2007-09-24 23:31 69,632 --a------ C:\Windows\System32\javacpl.cpl 2007-12-19 10:46 . 2007-12-19 10:47 2007-12-19 09:59 . 2007-12-19 09:59 2007-12-15 23:04 . 2007-12-15 23:04 2007-12-15 20:18 . 2007-12-15 20:18 2007-12-12 14:30 . 2007-12-12 14:30 1,327,104 --a------ C:\Windows\System32\quartz.dll 2007-12-12 14:30 . 2007-12-12 14:30 223,232 --a------ C:\Windows\System32\WMASF.DLL 2007-12-12 14:30 . 2007-12-12 14:30 9,728 --a------ C:\Windows\System32\LAPRXY.DLL 2007-12-12 14:30 . 2007-12-12 14:30 2,048 --a------ C:\Windows\System32\asferror.dll 2007-12-12 14:28 . 2007-12-12 14:28 130,048 --a------ C:\Windows\System32\drivers\srv2.sys 2007-12-12 14:28 . 2007-12-12 14:28 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys 2007-12-12 14:28 . 2007-12-12 14:28 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys 2007-12-12 14:28 . 2007-12-12 14:28 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys 2007-12-12 14:27 . 2007-12-12 14:27 3,504,824 --a------ C:\Windows\System32\ntkrnlpa.exe 2007-12-12 14:27 . 2007-12-12 14:27 3,470,520 --a------ C:\Windows\System32\ntoskrnl.exe 2007-12-12 14:27 . 2007-12-12 14:27 2,048 --a------ C:\Windows\System32\tzres.dll 2007-12-11 12:48 . 2007-12-11 12:48 2007-12-11 12:41 . 2007-03-08 00:51 129,784 --------- C:\Windows\System32\pxafs.dll 2007-12-08 15:36 . 2007-12-08 22:41 2007-12-07 18:28 . 2007-12-07 18:28 224,768 --a------ C:\Windows\System32\drivers\usbport.sys 2007-12-07 18:28 . 2007-12-07 18:28 193,536 --a------ C:\Windows\System32\drivers\usbhub.sys 2007-12-07 18:28 . 2007-12-07 18:28 73,216 --a------ C:\Windows\System32\drivers\usbccgp.sys 2007-12-07 18:28 . 2007-12-07 18:28 38,400 --a------ C:\Windows\System32\drivers\usbehci.sys 2007-12-07 18:28 . 2007-12-07 18:28 23,040 --a------ C:\Windows\System32\drivers\usbuhci.sys 2007-12-07 18:28 . 2007-12-07 18:28 8,704 --a------ C:\Windows\System32\hcrstco.dll 2007-12-07 18:28 . 2007-12-07 18:28 8,704 --a------ C:\Windows\System32\hccoin.dll 2007-12-07 18:28 . 2007-12-07 18:28 5,888 --a------ C:\Windows\System32\drivers\usbd.sys 2007-12-03 11:21 . 2007-12-03 11:36 2007-11-29 15:48 . 2007-11-29 15:48 2007-11-29 08:42 . 2007-12-20 14:04 2007-11-29 08:42 . 2007-12-20 14:04 2007-11-26 08:35 . 2007-11-26 09:44 2007-11-26 08:01 . 2002-01-09 09:34 131,856 --a------ C:\Windows\System32\temp.005 2007-11-24 20:27 . 2007-11-24 20:27 1,244,672 --a------ C:\Windows\System32\mcmde.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-21 10:01 13,025 ----a-w C:\Users\piotr\AppData\Roaming\nvModes.dat 2007-12-21 10:01 --------- d-----w C:\Users\piotr\AppData\Roaming\OpenOffice.org2 2007-12-20 13:08 --------- d-----w C:\Program Files\DAEMON Tools 2007-12-20 02:21 --------- d-----w C:\Users\piotr\AppData\Roaming\Skype 2007-12-20 00:21 --------- d-----w C:\Users\piotr\AppData\Roaming\skypePM 2007-12-18 13:40 --------- d-----w C:\Program Files\Google 2007-12-12 13:29 56,320 ----a-w C:\Windows\System32\iesetup.dll 2007-12-12 13:29 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2007-12-12 13:29 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2007-11-30 06:21 --------- d-----w C:\Users\piotr\AppData\Roaming\Toshiba 2007-11-29 14:48 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-11-24 19:48 --------- d-----w C:\Program Files\Windows Mail 2007-11-24 19:29 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr 2007-11-24 19:29 67,584 ----a-w C:\Windows\System32\wlanhlp.dll 2007-11-24 19:29 542,720 ----a-w C:\Windows\System32\sysmain.dll 2007-11-24 19:29 502,784 ----a-w C:\Windows\System32\wlansvc.dll 2007-11-24 19:29 47,104 ----a-w C:\Windows\System32\wlanapi.dll 2007-11-24 19:29 297,984 ----a-w C:\Windows\System32\wlansec.dll 2007-11-24 19:29 290,816 ----a-w C:\Windows\System32\wlanmsm.dll 2007-11-24 19:29 28,344 ----a-w C:\Windows\system32\drivers\battc.sys 2007-11-24 19:29 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys 2007-11-24 19:29 24,064 ----a-w C:\Windows\System32\wtsapi32.dll 2007-11-24 19:29 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys 2007-11-24 19:29 2,923,520 ----a-w C:\Windows\explorer.exe 2007-11-24 19:29 2,027,008 ----a-w C:\Windows\System32\win32k.sys 2007-11-24 19:29 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys 2007-11-20 06:15 --------- d-----w C:\Program Files\Wiedźmin 2007-11-15 16:37 32 ----a-w C:\Users\All Users\ezsid.dat 2007-11-15 16:37 32 ----a-w C:\ProgramData\ezsid.dat 2007-11-15 16:36 --------- d-----w C:\ProgramData\Skype 2007-11-15 16:36 --------- d-----w C:\Program Files\Skype 2007-11-15 16:35 --------- d-----w C:\Program Files\Common Files\Skype 2007-11-07 16:01 621,056 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys 2007-11-07 16:01 36,864 ----a-w C:\Windows\System32\cdd.dll 2007-11-06 16:30 --------- d-----w C:\ProgramData\Microsoft Help 2007-11-06 16:28 --------- d-----w C:\Program Files\Microsoft Works 2007-11-06 16:27 --------- d-----w C:\Program Files\MSBuild 2007-11-06 16:21 --------- d-----w C:\Program Files\Microsoft Visual Studio 8 2007-11-01 13:25 278,984 ----a-w C:\Windows\system32\drivers\atksgt.sys 2007-11-01 13:25 25,416 ----a-w C:\Windows\system32\drivers\lirsgt.sys 2007-10-29 14:57 --------- d-----w C:\Users\piotr\AppData\Roaming\Talkback 2007-10-25 12:20 --------- d-----w C:\Program Files\Common Files\France Telecom 2007-10-13 21:43 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL 2007-10-13 21:43 7,680 ----a-w C:\Windows\System32\spwmp.dll 2007-10-13 21:43 4,096 ----a-w C:\Windows\System32\dxmasf.dll 2007-10-13 21:43 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll 2007-10-13 21:41 84,480 ----a-w C:\Windows\System32\INETRES.dll 2007-10-13 21:41 788,992 ----a-w C:\Windows\System32\rpcrt4.dll 2007-10-13 21:41 737,792 ----a-w C:\Windows\System32\inetcomm.dll 2007-10-12 18:47 33,280 ----a-w C:\Windows\System32\slwmi.dll 2007-10-12 18:47 268,288 ----a-w C:\Windows\System32\mcbuilder.exe 2007-10-12 18:47 223,232 ----a-w C:\Windows\System32\SLC.dll 2007-10-12 18:46 57,856 ----a-w C:\Windows\System32\SLUINotify.dll 2007-10-12 18:46 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll 2007-10-12 18:46 39,936 ----a-w C:\Windows\System32\slcinst.dll 2007-10-12 18:46 351,232 ----a-w C:\Windows\System32\SLUI.exe 2007-10-12 18:46 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe 2007-10-12 18:46 186,368 ----a-w C:\Windows\System32\SLLUA.exe 2007-09-06 07:39 174 --sha-w C:\Program Files\desktop.ini . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Sidebar”=“C:\Program Files\Windows Sidebar\sidebar.exe” [2006-11-02 13:35] “TOSCDSPD”=“C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe” [2006-11-13 15:49] “ehTray.exe”=“C:\Windows\ehome\ehTray.exe” [2006-11-02 13:35] “Rainlendar2”=“C:\Program Files\Rainlendar2\Rainlendar2.exe” [2007-07-24 08:12] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2007-09-04 20:58] “RtHDVCpl”=“RtHDVCpl.exe” [2007-01-18 14:46 C:\Windows\RtHDVCpl.exe] “TPwrMain”=“C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE” [2006-12-19 23:16] “HSON”=“C:\Program Files\TOSHIBA\TBS\HSON.exe” [2006-12-07 16:49] “SmoothView”=“C:\Program Files\Toshiba\SmoothView\SmoothView.exe” [2007-02-06 14:21] “00TCrdMain”=“C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe” [2007-01-17 13:46] “KeNotify”=“C:\Program Files\TOSHIBA\Utilities\KeNotify.exe” [2006-11-06 17:14] “HWSetup”=“C:\Program Files\TOSHIBA\Utilities\HWSetup.exe” [2006-11-01 08:06] “SVPWUTIL”=“C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe” [2006-11-01 11:08] “NDSTray.exe”=“NDSTray.exe” [] “topi”=“C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe” [2007-03-02 14:10] “NvSvc”=“RUNDLL32.exe” [2006-11-02 10:45 C:\Windows\System32\rundll32.exe] “NvCplDaemon”=“RUNDLL32.exe” [2006-11-02 10:45 C:\Windows\System32\rundll32.exe] “NvMediaCenter”=“RUNDLL32.exe” [2006-11-02 10:45 C:\Windows\System32\rundll32.exe] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2007-02-02 13:36] “Toshiba Registration”=“C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe” [2007-02-19 15:00] “Camera Assistant Software”=“C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe” [2007-02-13 08:30] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 11:06] “BEWINTERNET-PLSessionManager”=“C:\Program Files\OrangeBS\BEWInternet-PL\SessionManager\SessionManager.exe” [2007-07-24 18:03] “GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-27 00:47] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11] C:\Users\piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 16:54:56] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders credssp.dll R0 LPCFilter;LPC Lower Filter Driver;C:\Windows\system32\DRIVERS\LPCFilter.sys [2006-07-28 16:25] R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-09-06 11:02] R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 14:56] R3 NETw4v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2006-12-09 01:01] R3 nvlddmkm;nvlddmkm;C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-01-13 09:40] R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys [2006-11-28 20:46] R3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-04 09:35] R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 11:50] R3 tosrfec;Bluetooth ACPI;C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 16:32] R3 UVCFTR;UVCFTR;C:\Windows\system32\DRIVERS\UVCFTR_S.SYS [2007-01-26 16:13] S3 athr;Sterownik urządzenia rozszerzalnej bezprzewodowej sieci LAN Atheros;C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 08:30] S3 NETw3v32;Sterownik karty Intel® PRO/Wireless 3945ABG dla 32-bitowej wersji systemu Windows Vista;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 08:30] S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys [2006-11-28 20:46] S3 SQLWriter;SQL Server VSS Writer;“C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe” [2005-10-14 02:53] S4 KR10I;KR10I;C:\Windows\system32\drivers\kr10i.sys [2007-01-18 15:40] S4 KR10N;KR10N;C:\Windows\system32\drivers\kr10n.sys [2007-01-18 15:47] S4 msvsmon80;Visual Studio 2005 Remote Debugger;“C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe” /service msvsmon80 [] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{f75a7a31-6425-11dc-8dd9-001b3816c7b6}] \shell\AutoRun\command - H:\AutorunMenu.exe *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . Contents of the ‘Scheduled Tasks’ folder “2007-12-20 19:33:29 C:\Windows\Tasks\User_Feed_Synchronization-{087B31D7-FE11-460E-BDEB-101A1A6742CB}.job” - C:\Windows\system32\msfeedssync.exe . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-21 11:33:36 Windows 6.0.6000 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-21 11:34:48 C:\ComboFix2.txt … 2007-12-21 11:27 . 2007-12-21 00:06:34 — E O F —