ComboFix 07-12-02.5 - vs 2007-12-02 18:17:07.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.342 [GMT 1:00] Running from: F:\skanery\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 ))))))))))))))))))))))))))))))) . 2007-11-30 17:09 . 2007-11-30 17:09 2007-11-30 17:09 . 2007-11-30 17:09 2007-11-30 13:20 . 2007-11-30 13:19 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys 2007-11-30 13:20 . 2007-11-30 13:19 298,104 --a------ C:\WINDOWS\system32\imon.dll 2007-11-30 13:20 . 2007-11-30 13:19 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys 2007-11-29 19:07 . 2007-12-02 15:12 69 --a------ C:\WINDOWS\NeroDigital.ini 2007-11-29 15:12 . 2004-01-28 14:42 1,531,904 --a------ C:\WINDOWS\adiras.exe 2007-11-29 15:12 . 2002-05-09 16:12 155,648 --a------ C:\WINDOWS\system32\adadix32.dll 2007-11-29 15:12 . 2001-07-27 14:25 127,456 --a------ C:\WINDOWS\system32\ipdetect.exe 2007-11-29 15:12 . 2004-03-02 09:24 127,065 --a------ C:\WINDOWS\system32\drivers\adiusbaw.sys 2007-11-29 15:12 . 2004-06-25 12:32 12,169 --a------ C:\WINDOWS\system32\drivers\adiusbaw.cat 2007-11-29 15:12 . 2007-11-29 15:12 998 --a------ C:\WINDOWS\adiras.ini 2007-11-29 15:12 . 2007-11-29 15:13 154 --a------ C:\WINDOWS\adidsl.ini 2007-11-29 15:12 . 2007-11-29 15:12 21 --a------ C:\WINDOWS\Fast800.ini 2007-11-29 15:11 . 2007-11-29 15:11 2007-11-29 13:54 . 2004-07-27 19:18 36,864 -ra------ C:\WINDOWS\StmClean.exe 2007-11-29 06:11 . 2007-11-29 06:11 2007-11-29 06:11 . 2007-06-21 22:58 547,072 --a------ C:\WINDOWS\system32\drivers\ar5211.sys 2007-11-28 07:27 . 2007-11-28 07:27 2007-11-28 07:27 . 2007-11-28 07:27 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat 2007-11-28 07:24 . 2007-11-28 07:24 2007-11-28 07:24 . 2007-11-28 07:24 2007-11-28 07:24 . 2007-11-28 07:31 2007-11-28 07:24 . 2007-11-28 07:24 2007-11-27 22:08 . 2007-11-30 13:28 217 --a------ C:\WINDOWS\Wyniki_przetargow.INI 2007-11-27 22:00 . 2007-10-17 16:27 707,024 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys 2007-11-27 21:57 . 2007-12-02 18:17 2007-11-27 21:57 . 2007-10-17 16:26 281,552 --a------ C:\WINDOWS\system32\cfosspeed.dll 2007-11-27 21:34 . 2007-11-27 21:38 2007-11-27 21:03 . 2007-12-02 11:02 49 --a------ C:\WINDOWS\transp.gif 2007-11-27 20:49 . 2007-11-27 20:49 2007-11-27 20:20 . 2003-08-04 13:22 94,208 --a------ C:\WINDOWS\system32\W32n50.dll 2007-11-27 20:20 . 2004-08-23 13:50 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll 2007-11-27 20:20 . 2003-08-04 13:22 16,128 --------- C:\WINDOWS\system32\PCANDIS5.SYS 2007-11-27 20:11 . 2007-12-02 11:00 2007-11-27 19:57 . 2007-11-27 19:57 2007-11-26 16:08 . 2007-11-26 16:08 2007-11-26 12:39 . 2007-11-26 12:39 2007-11-25 13:42 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll 2007-11-25 13:42 . 2007-12-02 11:02 546 --a------ C:\WINDOWS\ODBC.INI 2007-11-25 13:40 . 2007-11-25 13:41 2007-11-25 13:40 . 2007-11-25 13:40 2007-11-25 13:40 . 2007-11-25 13:43 2007-11-25 13:27 . 2007-11-25 13:27 2007-11-25 13:20 . 2007-11-25 13:20 223,128 --a------ C:\WINDOWS\system32\drivers\vaxscsi.sys 2007-11-25 13:16 . 2007-11-25 13:16 643,072 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-11-25 13:16 . 2007-11-25 13:16 96,256 --a------ C:\WINDOWS\system32\drivers\sptd3245.sys 2007-11-25 13:05 . 2007-11-25 13:05 2007-11-25 13:05 . 2007-11-25 13:05 2007-11-22 13:53 . 2007-11-22 13:53 2007-11-22 13:52 . 2007-11-22 13:52 2007-11-22 13:51 . 2004-08-04 00:44 153,088 --a------ C:\WINDOWS\system32\irftp.exe 2007-11-22 13:51 . 2004-08-04 00:44 153,088 --a–c— C:\WINDOWS\system32\dllcache\irftp.exe 2007-11-22 13:51 . 2004-08-04 00:44 27,648 --a------ C:\WINDOWS\system32\irmon.dll 2007-11-22 13:51 . 2004-08-04 00:44 27,648 --a–c— C:\WINDOWS\system32\dllcache\irmon.dll 2007-11-22 13:51 . 2004-08-04 00:44 8,192 --a------ C:\WINDOWS\system32\wshirda.dll 2007-11-22 13:51 . 2004-08-04 00:44 8,192 --a–c— C:\WINDOWS\system32\dllcache\wshirda.dll 2007-11-22 13:23 . 2007-11-22 13:23 2007-11-22 12:15 . 2007-11-22 12:15 2007-11-22 11:48 . 2007-11-22 11:48 2007-11-22 11:47 . 2007-11-22 11:47 2007-11-22 11:47 . 2007-11-22 11:47 2007-11-22 11:30 . 2007-11-22 11:30 2007-11-22 11:30 . 2007-11-22 11:30 2007-11-22 11:30 . 2006-05-16 11:58 73,728 --a------ C:\WINDOWS\system32\ISUSPM.cpl 2007-11-22 11:30 . 2002-03-30 10:06 65,536 --a------ C:\WINDOWS\system32\NTPORT.DLL 2007-11-22 11:30 . 2007-07-29 17:00 14,168 --a------ C:\WINDOWS\system32\drivers\zntport.sys 2007-11-21 18:53 . 2007-07-09 14:11 584,192 -----c— C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-11-21 18:49 . 2007-05-17 12:30 549,376 -----c— C:\WINDOWS\system32\dllcache\oleaut32.dll 2007-11-21 18:48 . 2007-11-21 18:48 2007-11-21 18:48 . 2007-06-26 14:57 851,968 -----c— C:\WINDOWS\system32\dllcache\vgx.dll 2007-11-21 18:46 . 2007-11-21 18:46 2007-11-21 18:46 . 2007-11-21 18:46 2007-11-21 18:46 . 2007-06-26 07:10 1,104,896 -----c— C:\WINDOWS\system32\dllcache\msxml3.dll 2007-11-21 18:45 . 2007-04-25 15:23 144,896 -----c— C:\WINDOWS\system32\dllcache\schannel.dll 2007-11-21 18:44 . 2007-05-16 16:19 1,314,816 -----c— C:\WINDOWS\system32\dllcache\msoe.dll 2007-11-21 18:44 . 2007-05-16 16:19 510,976 -----c— C:\WINDOWS\system32\dllcache\wab32.dll 2007-11-21 18:44 . 2007-04-23 11:14 364,160 -----c— C:\WINDOWS\system32\dllcache\update.sys 2007-11-21 18:44 . 2007-05-16 16:18 86,528 -----c— C:\WINDOWS\system32\dllcache\directdb.dll 2007-11-21 18:44 . 2007-05-16 16:19 85,504 -----c— C:\WINDOWS\system32\dllcache\wabimp.dll 2007-11-21 18:43 . 2007-05-16 16:18 683,520 -----c— C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-11-21 18:43 . 2007-04-16 22:45 43,352 --a------ C:\WINDOWS\system32\wups2.dll 2007-11-21 18:43 . 2007-04-16 22:45 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui 2007-11-21 18:43 . 2007-04-16 22:47 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui 2007-11-21 18:43 . 2007-04-16 22:47 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui 2007-11-21 18:43 . 2007-04-16 22:45 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui 2007-11-21 18:42 . 2007-02-09 12:10 574,464 -----c— C:\WINDOWS\system32\dllcache\ntfs.sys 2007-11-21 18:41 . 2007-03-17 14:45 293,376 -----c— C:\WINDOWS\system32\dllcache\winsrv.dll 2007-11-21 18:41 . 2007-02-05 21:19 185,856 -----c— C:\WINDOWS\system32\dllcache\upnphost.dll 2007-11-21 18:40 . 2007-04-11 07:47 1,843,840 -----c— C:\WINDOWS\system32\dllcache\win32k.sys 2007-11-21 18:40 . 2007-03-08 16:38 579,072 -----c— C:\WINDOWS\system32\dllcache\user32.dll 2007-11-21 18:40 . 2007-06-19 14:32 282,112 -----c— C:\WINDOWS\system32\dllcache\gdi32.dll 2007-11-21 18:40 . 2007-03-08 16:38 40,960 -----c— C:\WINDOWS\system32\dllcache\mf3216.dll 2007-11-21 18:39 . 2007-11-21 18:39 2007-11-21 18:39 . 2007-02-19 11:34 343,040 -----c— C:\WINDOWS\system32\dllcache\msvcrt.dll 2007-11-21 18:38 . 2006-12-21 14:16 288,768 --------- C:\WINDOWS\system32\rhttpaa.dll 2007-11-21 18:38 . 2006-12-21 14:16 116,736 --------- C:\WINDOWS\system32\aaclient.dll 2007-11-21 18:38 . 2006-12-21 14:16 36,352 --------- C:\WINDOWS\system32\tsgqec.dll 2007-11-21 18:37 . 2006-12-14 14:45 981,760 -----c— C:\WINDOWS\system32\dllcache\mfc42u.dll 2007-11-21 18:37 . 2006-11-27 15:55 539,136 -----c— C:\WINDOWS\system32\dllcache\msftedit.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-29 14:12 23 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg 2007-11-21 15:27 315,392 ----a-w C:\WINDOWS\HideWin.exe 2007-11-21 13:11 --------- d-----w C:\Program Files\microsoft frontpage 2007-11-21 13:10 558,142 ----a-w C:\WINDOWS\java\Packages\FFXR5777.ZIP 2007-11-21 13:10 155,995 ----a-w C:\WINDOWS\java\Packages\G9ZT3PNN.ZIP 2007-11-21 13:06 --------- d-----w C:\Program Files\Usługi online 2007-10-22 02:39 267,272 ----a-w C:\WINDOWS\system32\xactengine2_10.dll 2007-10-22 02:37 17,928 ----a-w C:\WINDOWS\system32\X3DAudio1_2.dll 2007-10-12 14:14 3,734,536 ----a-w C:\WINDOWS\system32\d3dx9_36.dll 2007-10-12 14:14 1,374,232 ----a-w C:\WINDOWS\system32\D3DCompiler_36.dll 2007-10-02 08:56 444,776 ----a-w C:\WINDOWS\system32\d3dx10_36.dll 2007-09-20 08:55 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “AutoConnect”=“C:\Program Files\AutoConnect\AutoConnect.exe” [2004-08-28 19:27] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “TouchPadHotKey”=“C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe” [2007-06-26 13:58] “RTHDCPL”=“RTHDCPL.EXE” [2007-06-13 14:49 C:\WINDOWS\RTHDCPL.exe] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2007-05-10 19:22] “Adobe Reader Speed Launcher”=“F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2007-10-10 19:51] “cFosSpeed”=“C:\Program Files\cFosSpeed\cFosSpeed.exe” [2007-10-17 16:26] “nod32kui”=“C:\Program Files\Eset\nod32kui.exe” [2007-11-30 13:19] “Outpost Firewall”=“C:\Program Files\Agnitum\Outpost Firewall\outpost.exe” [2006-08-30 10:46] “OutpostFeedBack”=“C:\Program Files\Agnitum\Outpost Firewall\feedback.exe” [2006-09-26 19:36] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [2004-08-04 00:44] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-11-29 15:12:00] R1 SandBox;Outpost Firewall Sandbox Driver;??\C:\Program Files\Agnitum\Outpost Firewall\kernel\Sandbox.SYS R1 VFILT;Outpost Firewall Kernel Driver;??\C:\Program Files\Agnitum\Outpost Firewall\kernel\FILTNT.SYS R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\ARP.DLL R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\CONTENT.DLL R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\PROTECT.DLL R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\SECRET.DLL S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . ************************************************************************** catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-02 18:18:36 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-02 18:19:08 C:\ComboFix2.txt … 2007-12-02 18:16 . — E O F —