ComboFix 07-09-21.2 - “Fil P” 2007-09-26 13:18:30.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.48.1045.18.117 [GMT 8:00] * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . E:\Autorun.inf F:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2007-08-26 to 2007-09-26 ))))))))))))))))))))))))))))))) . 2007-09-26 13:17 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-09-26 11:59 2007-09-26 11:44 2007-09-26 03:04 4 --a------ C:\WINDOWS\system32\proc683804487.bin 2007-09-26 02:02 2007-09-21 19:52 2007-09-21 19:52 2007-09-21 19:51 2007-09-20 21:36 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-09-20 21:34 2007-09-20 21:34 2007-09-20 21:34 2007-09-20 21:28 2007-09-19 23:19 2007-09-19 23:19 2007-09-17 23:11 2007-09-15 19:53 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2007-09-15 19:53 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2007-09-15 19:53 38,912 --------- C:\WINDOWS\system32\picn20.dll 2007-09-15 19:53 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2007-09-15 19:53 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2007-09-15 19:53 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-09-15 19:53 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-09-15 19:53 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2007-09-15 19:53 2007-09-15 19:53 2007-09-15 19:48 2007-09-14 21:30 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys 2007-09-14 21:30 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys 2007-09-14 21:30 129,784 --------- C:\WINDOWS\system32\pxafs.dll 2007-09-14 21:30 2007-09-13 15:48 2007-09-12 21:59 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2007-09-12 21:59 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2007-09-12 21:19 740,442 --a------ C:\WINDOWS\system32\divx.dll 2007-09-12 21:19 73,728 --a------ C:\WINDOWS\system32\dpl100.dll 2007-09-12 21:19 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-09-12 21:19 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-09-12 21:19 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-09-12 21:19 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll 2007-09-12 21:19 163,840 --a------ C:\WINDOWS\system32\unrar.dll 2007-09-12 21:19 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-09-12 21:19 2007-09-12 02:50 2007-09-11 23:47 2007-09-11 23:25 2007-09-11 23:16 2007-09-11 23:16 2007-09-11 23:04 98,304 -----c— C:\WINDOWS\system32\dllcache\nlhtml.dll 2007-09-11 23:04 29,696 -----c— C:\WINDOWS\system32\dllcache\mimefilt.dll 2007-09-11 23:04 192,000 -----c— C:\WINDOWS\system32\dllcache\offfilt.dll 2007-09-11 22:57 2007-09-11 22:57 2007-09-11 22:46 23,040 -----c— C:\WINDOWS\system32\dllcache\fltmc.exe 2007-09-11 22:46 16,896 -----c— C:\WINDOWS\system32\dllcache\fltlib.dll 2007-09-11 22:46 128,896 -----c— C:\WINDOWS\system32\dllcache\fltmgr.sys 2007-09-11 22:46 2007-09-11 22:45 2007-09-11 22:19 26,496 --a–c— C:\WINDOWS\system32\dllcache\usbstor.sys 2007-09-11 22:17 2007-09-11 22:06 2007-09-11 22:04 2,362,184 -----c— C:\WINDOWS\system32\dllcache\wmvcore.dll 2007-09-11 22:01 2007-09-11 21:58 202,240 -----c— C:\WINDOWS\system32\dllcache\rmcast.sys 2007-09-11 21:56 2007-09-11 21:54 2007-09-11 21:54 2007-09-11 21:53 2007-09-11 21:53 2007-09-11 21:52 2007-09-11 21:52 2007-09-11 21:51 2007-09-11 21:51 2007-09-11 21:47 2007-09-11 21:46 2007-09-11 21:29 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-09-11 21:10 2007-09-11 21:05 69,120 -----c— C:\WINDOWS\system32\dllcache\ciodm.dll 2007-09-11 21:05 1,439,744 -----c— C:\WINDOWS\system32\dllcache\query.dll 2007-09-11 21:05 1,013,248 -----c— C:\WINDOWS\system32\dllcache\kernel32.dll 2007-09-11 20:53 2007-09-11 20:52 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys 2007-09-11 20:41 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-09-11 20:38 458,752 --a------ C:\WINDOWS\system32\w29NCPA.dll 2007-09-11 20:38 3,222,784 --a------ C:\WINDOWS\system32\drivers\w29n51.sys 2007-09-11 20:38 1,654,784 --a------ C:\WINDOWS\system32\W29MLRES.DLL 2007-09-11 20:33 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2007-09-11 20:33 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-09-26 13:04 --------- d-------- C:\Program Files\Common Files\Symantec Shared 2007-09-11 21:11 --------- d-------- C:\Program Files\Symantec 2007-09-11 20:50 --------- d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Symantec 2007-09-11 20:40 0 -rahs---- C:\WINDOWS\system32\drivers\TOSHIBA_Satellite L20_03209000-PL_PSL20E-00C00.MRK 2007-08-16 16:17 51568 --a------ C:\WINDOWS\system32\sirenacm.dll 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll 2007-06-26 14:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “IgfxTray”=“C:\WINDOWS\system32\igfxtray.exe” [2005-06-08 17:02] “HotKeysCmds”=“C:\WINDOWS\system32\hkcmd.exe” [2005-06-08 16:59] “Persistence”=“C:\WINDOWS\system32\igfxpers.exe” [2005-06-08 17:03] “SynTPLpr”=“C:\Program Files\Synaptics\SynTP\SynTPLpr.exe” [2004-10-08 20:44] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2004-10-08 20:43] “Toshiba Hotkey Utility”=“C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe” [2005-08-01 20:25] “PadTouch”=“C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe” [2004-11-17 16:56] “NDSTray.exe”=“NDSTray.exe” [] “SmoothView”=“C:\Program Files\TOSHIBA\Program narzędziowy TOSHIBA Zooming Utility\SmoothView.exe” [] “dla”=“C:\WINDOWS\system32\dla\tfswctrl.exe” [2005-05-31 11:33] “ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2007-02-06 17:41] “Symantec NetDriver Monitor”=“C:\PROGRA~1\SYMNET~1\SNDMon.exe” [2007-09-11 21:10] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-06-29 06:24] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50] “CFSServ.exe”=“CFSServ.exe” [] “iTunesHelper”=“C:\Program Files\iTunes\iTunesHelper.exe” [2007-09-14 10:00] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 18:00] “TOSCDSPD”=“C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe” [2005-04-12 18:04] “Free Download Manager”=“C:\Program Files\Free Download Manager\fdm.exe” [2007-09-09 22:36] “Free Upload Manager”=“C:\Program Files\Free Download Manager\fum\fum.exe” [2007-07-29 20:13] “Free Uploader Oe Integration”=“C:\Program Files\Free Download Manager\FUM\fumoei.exe” [2007-06-10 19:02] “MsnMsgr”=“C:\Program Files\Windows Live\Messenger\MsnMsgr.exe” [2007-08-16 16:19] “BitComet”=“C:\Program Files\BitLord\BitLord.exe” [] C:\DOCUME~1\ALLUSE~1\MENUST~1\Programy\AUTOST~1\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 20:44:06] R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;“C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe” R3 BoiHwsetup;Access 32bits INT15 routine;C:\WINDOWS\system32\drivers\BoiHwSetup.sys R3 qkbfiltr;Quanta HotKey Keyboard Filter Driver;C:\WINDOWS\system32\drivers\qkbfiltr.sys R3 qmofiltr;Quanta HotKey Mouse Filter Driver;C:\WINDOWS\system32\drivers\qmofiltr.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] Auto\command- fun.xls.exe AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{2125b121-606c-11dc-96f0-0016362ae0f4}] Auto\command- E:\fun.xls.exe AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{2125b122-606c-11dc-96f0-0016362ae0f4}] Auto\command- F:\fun.xls.exe AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe *Newly Created Service* - CATCHME . Contents of the ‘Scheduled Tasks’ folder “2007-09-19 14:08:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job” - C:\Program Files\Apple Software Update\SoftwareUpdate.exe “2007-09-21 12:16:02 C:\WINDOWS\Tasks\Norton AntiVirus - Skanuj komputer - Fil P.job” - C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe . ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-26 13:21:31 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\H a r m o n o g r a m a u t o m a t y c z n e j u s Bu g i L i v e U p d a t e] “ImagePath”="“C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe”" [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\helpsvc] “ServiceDll”="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll" [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HidServ] “ServiceDll”="%SystemRoot%\System32\hidserv.dll" [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HidUsb] “ImagePath”=“system32\DRIVERS\hidusb.sys” [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\hpn] [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HSFHWICH] “ImagePath”=“system32\DRIVERS\HSFHWICH.sys” [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HSF_DPV] “ImagePath”=“system32\DRIVERS\HSF_DPV.sys” [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HTTP] “ImagePath”=“System32\Drivers\HTTP.sys” [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HTTPFilter] “ServiceDll”="%SystemRoot%\System32\w3ssl.dll" . Completion time: 2007-09-26 13:22:15 C:\ComboFix-quarantined-files.txt … 2007-09-26 13:22 . — E O F —