“Michaˆ” - 2007-06-23 23:44:39 - ComboFix 07-06-23.5 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\drivers\npf.sys C:\WINDOWS\system32\packet.dll C:\WINDOWS\system32\pthreadVC.dll C:\WINDOWS\system32\wpcap.dll ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_NPF -------\NPF ((((((((((((((((((((((((( Files Created from 2007-05-23 to 2007-06-23 ))))))))))))))))))))))))))))))) 2007-06-23 23:43 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-23 15:13 2,560 --a------ C:\WINDOWS_MSRSTRT.EXE 2007-06-23 15:12 2007-06-20 15:35 2007-06-20 15:20 2007-06-20 12:18 2007-06-13 00:01 2007-06-13 00:01 2007-06-08 15:29 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys 2007-06-08 15:29 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys 2007-06-08 15:29 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS 2007-06-08 15:29 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys 2007-06-08 15:29 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys 2007-06-08 15:29 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys 2007-06-08 15:29 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys 2007-06-08 15:28 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll 2007-06-08 15:24 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-06-08 15:22 90,568 --a------ C:\WINDOWS\system32\drivers\usbVM31b.sys 2007-06-08 15:22 61,440 --a------ C:\WINDOWS\system32\VM31bSTI.dll 2007-06-08 15:22 53,248 --a------ C:\WINDOWS\StillCap.exe 2007-06-08 15:22 49,152 --a------ C:\WINDOWS\amcap.exe 2007-06-08 15:22 40,960 --a------ C:\WINDOWS\VM_STI.EXE 2007-06-08 15:22 307,200 --a------ C:\WINDOWS\vidcap32.Exe 2007-06-08 15:22 24,576 --a------ C:\WINDOWS\system32\RunSetup.dll 2007-06-08 15:22 24,576 --a------ C:\WINDOWS\RunSetup.dll 2007-06-08 15:22 147,456 --a------ C:\WINDOWS\VMCap.exe 2007-06-08 15:22 2007-06-08 15:22 2007-06-05 21:27 2007-06-05 21:27 2007-06-05 21:27 2007-06-02 01:21 2007-06-02 01:21 2007-06-02 01:20 614,400 --a------ C:\WINDOWS\system32\ExButton.dll 2007-06-02 01:20 585,728 --a------ C:\WINDOWS\system32\ExMenu.dll 2007-06-02 01:20 507,904 --a------ C:\WINDOWS\system32\ExTab.dll 2007-06-02 01:20 368,912 --a------ C:\WINDOWS\system32\vbar332.dll 2007-06-02 01:20 356,352 --a------ C:\WINDOWS\system32\eSellerateEngine.dll 2007-06-02 01:20 307,200 --a------ C:\WINDOWS\system32\ExPMenu.dll 2007-06-02 01:20 118,784 --a------ C:\WINDOWS\system32\eWebControl.dll 2007-06-02 01:20 1,658,880 --a------ C:\WINDOWS\system32\ExGrid.dll 2007-06-02 01:20 2007-06-02 01:20 2007-05-27 00:24 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-23 13:14:27 -------- d-----w C:\Program Files\GetRight 2007-06-21 00:33:52 -------- d-----w C:\DOCUME~1\MICHA~1\DANEAP~1\teamspeak2 2007-06-20 13:20:21 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-06-20 13:13:58 -------- d-----w C:\DOCUME~1\MICHA~1\DANEAP~1\foobar2000 2007-06-19 18:54:50 -------- d-----w C:\DOCUME~1\MICHA~1\DANEAP~1\BitTorrent 2007-06-14 19:17:49 -------- d-----w C:\DOCUME~1\MICHA~1\DANEAP~1\BearShare 2007-06-12 21:14:48 -------- d-----w C:\Program Files\Acala 3GP Movies Free 2007-05-21 14:55:57 -------- d-----w C:\Program Files\F12007WM by PMG 2007-05-16 15:18:58 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-05-12 20:24:17 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2007-05-08 14:12:56 4,096 ----a-w C:\WINDOWS\d3dx.dat 2007-05-08 14:09:43 12,400 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-05-08 12:46:10 -------- d-----w C:\Program Files\coolpro2 2007-05-08 12:32:11 -------- d-----w C:\Program Files\Audacity 2007-05-08 12:28:48 -------- d-----w C:\Program Files\CDex_150 2007-05-06 11:31:21 208,384 ----a-w C:\WINDOWS\ADS.exe 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-18 16:14:32 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-03-25 13:07:40 83,486 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-03-25 13:07:40 488,194 ----a-w C:\WINDOWS\system32\perfh015.dat ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 07:12] {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}=C:\Program Files\FlashGet\jccatch.dll [2007-05-16 15:39] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21] {F156768E-81EF-470C-9057-481BA8380DBA}=C:\Program Files\FlashGet\getflash.dll [2007-05-16 15:39] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “AtiPTA”=“atiptaxx.exe” [2005-11-23 03:05 C:\WINDOWS\system32\atiptaxx.exe] “avgnt”=“C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe” [2007-04-22 10:24] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2006-11-14 11:12] “AtiTrayTools”=“C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe” [2005-10-19 09:22] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “PcSync”=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^GetRight - Tray Icon.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\GetRight - Tray Icon.lnk backup=C:\WINDOWS\pss\GetRight - Tray Icon.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Michał^Menu Start^Programy^Autostart^Adobe Gamma.lnk] path=C:\Documents and Settings\Michał\Menu Start\Programy\Autostart\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Michał^Menu Start^Programy^Autostart^Rapidown.lnk] path=C:\Documents and Settings\Michał\Menu Start\Programy\Autostart\Rapidown.lnk backup=C:\WINDOWS\pss\Rapidown.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADS] C:\Windows\ADS.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] “C:\Program Files\Ares\Ares.exe” -h [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] “C:\Program Files\BitTorrent\bittorrent.exe” --force_start_minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] “C:\Program Files\DAEMON Tools\daemon.exe” -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeRAM XP] “C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe” -win [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] “C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe” ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-23 23:48:38 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-23 23:52:04 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-06-23 23:51 — E O F —