“emil2” - 2007-07-10 23:15:26 - ComboFix 07-07-10.1 - Dodatek Service Pack 2 FAT32 ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32_000006_.tmp.dll C:\WINDOWS\system32_000007_.tmp.dll C:\WINDOWS\system32_000008_.tmp.dll C:\WINDOWS\system32_000009_.tmp.dll C:\WINDOWS\system32_000012_.tmp.dll ((((((((((((((((((((((((( Files Created from 2007-06-10 to 2007-07-10 ))))))))))))))))))))))))))))))) 2007-07-10 23:12 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-09 16:41 2007-07-08 14:58 2007-07-07 12:22 2007-07-05 21:33 2007-07-05 18:31 2007-07-01 16:13 2007-06-30 20:51 2007-06-28 16:54 2007-06-28 16:50 2007-06-28 16:43 2007-06-28 16:43 2007-06-28 16:43 2007-06-28 13:48 2007-06-28 13:48 2007-06-28 13:39 2007-06-28 13:10 2007-06-28 12:51 2007-06-28 12:12 2007-06-28 11:57 2,621,440 --a------ C:\DOCUME~1\ekil2\ntuser.dat 2007-06-28 11:57 2007-06-28 11:57 2007-06-28 11:57 2007-06-28 11:57 2007-06-28 11:57 2007-06-28 11:57 2007-06-28 11:57 2007-06-28 11:57 2007-06-28 11:57 2007-06-28 11:57 2007-06-27 23:00 2007-06-27 23:00 2007-06-26 22:26 4,747,264 --a------ C:\DOCUME~1\Emil\ntuser.dat 2007-06-25 16:26 2007-06-22 20:26 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS 2007-06-20 22:38 2007-06-20 17:02 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-06-19 18:44 64,000 --a------ C:\WINDOWS\system32\drivers\e4ldr.sys 2007-06-19 18:44 50,007 --a------ C:\WINDOWS\system32\drivers\adildr.sys 2007-06-19 18:44 46,892 --a------ C:\WINDOWS\system32\ADADIX16.DLL 2007-06-19 18:44 4,981 --a------ C:\WINDOWS\system32\ADADIX2K.DLL 2007-06-19 18:44 24,576 --a------ C:\WINDOWS\enddisk32.exe 2007-06-19 18:44 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin 2007-06-19 18:44 176,128 --a------ C:\WINDOWS\autoclk.exe 2007-06-19 18:44 155,648 --a------ C:\WINDOWS\system32\adadix32.dll 2007-06-19 18:44 152,220 --a------ C:\WINDOWS\system32\drivers\L1E4I2.BIN 2007-06-19 18:44 152,220 --a------ C:\WINDOWS\system32\drivers\L1E4I1.BIN 2007-06-19 18:44 152,220 --a------ C:\WINDOWS\system32\drivers\L1E4I0.BIN 2007-06-19 18:44 152,132 --a------ C:\WINDOWS\system32\drivers\L1E4P2.BIN 2007-06-19 18:44 152,132 --a------ C:\WINDOWS\system32\drivers\L1E4P1.BIN 2007-06-19 18:44 152,132 --a------ C:\WINDOWS\system32\drivers\L1E4P0.BIN 2007-06-19 18:44 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P2.BIN 2007-06-19 18:44 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P1.BIN 2007-06-19 18:44 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P0.BIN 2007-06-19 18:44 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I2.BIN 2007-06-19 18:44 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I1.BIN 2007-06-19 18:44 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I0.BIN 2007-06-19 18:44 152,036 --a------ C:\WINDOWS\system32\drivers\L1E4D2.BIN 2007-06-19 18:44 152,034 --a------ C:\WINDOWS\system32\drivers\L1E4D1.BIN 2007-06-19 18:44 152,034 --a------ C:\WINDOWS\system32\drivers\L1E4D0.BIN 2007-06-19 18:44 143,360 --a------ C:\WINDOWS\adiras.exe 2007-06-19 18:44 135,168 --a------ C:\WINDOWS\system32\unaddrv.exe 2007-06-19 18:44 127,456 --a------ C:\WINDOWS\system32\IPDETECT.EXE 2007-06-19 18:44 126,976 --a------ C:\WINDOWS\system32\coclassfast.dll 2007-06-19 18:44 126,489 --a------ C:\WINDOWS\system32\drivers\adiusbaw.sys 2007-06-19 18:44 116,992 --a------ C:\WINDOWS\system32\drivers\e4usbaw.sys 2007-06-19 18:44 2007-06-18 19:29 2007-06-14 22:04 2007-06-13 21:44 2007-06-13 21:44 2007-06-13 21:44 2007-06-13 21:02 110,080 --a------ C:\WINDOWS\system32\Orbitron.scr 2007-06-13 20:28 2007-06-13 20:22 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll 2007-06-13 20:22 2007-06-13 19:35 23 --ahs---- C:\WINDOWS\system32\fddcccfec7_r.dll 2007-06-10 17:17 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-16 10:40:30 1,346 ----a-w C:\WINDOWS\mozver.dat 2007-06-15 20:27:28 75,904 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-15 20:27:28 451,802 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-08 20:30:26 -------- d-----w C:\Program Files\MUGEN 2007-06-01 10:18:10 -------- d-----w C:\Program Files\QuickTime 2007-05-30 20:05:38 -------- d-----w C:\Program Files\Common Files\GTK 2007-05-26 14:16:56 0 ----a-w C:\WINDOWS\system32\UTSCSI.EXE 2007-05-18 17:17:02 -------- d-----w C:\Program Files\NovaLogic 2007-05-16 15:18:58 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-05-12 21:44:50 -------- d-----w C:\Program Files\K-Lite Codec Pack 2007-05-10 16:09:06 21,504 ----a-w C:\WINDOWS\jestertb.dll 2007-05-10 15:22:40 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2 2007-05-09 18:53:50 770,048 ----a-w C:\WINDOWS\3D World Map.scr 2007-05-06 15:01:14 0 ----a-w C:\WINDOWS\nsreg.dat 2007-05-05 22:22:00 48,776 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL 2007-05-02 14:45:34 546 ----a-w C:\WINDOWS\system32\ABA6F.DAT 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-18 16:14:32 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-04-16 20:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll 2007-04-16 20:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{000123B4-9B42-4900-B3F7-F4B073EFC214}] 2007-06-18 13:33 122880 --a------ D:\PROGRAMY\DANE\Orbitdownloader\orbitcth.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2004-12-14 01:56 63136 --a------ c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{85F685C3-20D9-4943-95E4-EB4224056C3F}] 2007-01-23 14:29 102400 --a------ D:\PROGRAMY\DANE\Expressivo\IH_iexplore.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{9ECB9560-04F9-4bbc-943D-298DDF1699E1}] 2005-10-22 20:29 94336 --a------ c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}] 2007-05-23 12:13 140912 --a------ c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{AA58ED58-01DD-4d91-8333-CF10577473F7}] 2007-05-06 15:34 2415680 -ra------ c:\program files\google\googletoolbar1.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] 2007-05-06 21:45 324536 --a------ C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{bf00e119-21a3-4fd1-b178-3b8537e75c92}] D:\PROGRAMY\DANE\MegaIEMn.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{F4D76F01-7896-458a-890F-E1F05C46069F}] 2007-06-13 20:28 241664 --a------ C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Alcmtr”=“ALCMTR.EXE” [2005-05-03 06:43 C:\WINDOWS\Alcmtr.exe] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2005-10-21 02:26] “ccApp”=“c:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2007-01-22 22:19] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 13:00] “MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 18:24] “Gadu-Gadu”=“D:\PROGRAMY\DANE\Gadu-Gadu\gg.exe” [2007-05-10 16:36] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “appinit_dlls”=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^ASUS ChkMail.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ASUS ChkMail.lnk backup=C:\WINDOWS\pss\ASUS ChkMail.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Emil^Menu Start^Programy^Autostart^Adobe Gamma.lnk] path=C:\Documents and Settings\Emil\Menu Start\Programy\Autostart\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator] “C:\Program Files\DAP\DAP.EXE” /STARTUP [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EOUApp] “C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Expressivo] “D:\PROGRAMY\DANE\Expressivo\expressivo.exe” -t [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu] “D:\PROGRAMY\DANE\Gadu-Gadu\gg.exe” /tray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] “C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless] “C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” /tf Intel PROSet/Wireless [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig] “C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InternetCalls] “D:\PROGRAMY\DANE\InternetCalls\internetcalls.exe” -nosplash -minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] “C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] RTHDCPL.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedOptimizer] D:\PROGRAMY\DANE\DAP\SPEEDO~1\SPO.EXE -s [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] C:\Program Files\Steam\Steam.exe -silent [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VS Online] “D:\GRY\MINI\VS Online\VSOnline.exe” /tray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] D:\PROGRAMY\DANE\Winamp\winampa.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “gusvc”=3 (0x3) “GoogleDesktopManager”=3 (0x3) “Adobe LM Service”=3 (0x3) “S24EventMonitor”=2 (0x2) “RegSrvc”=2 (0x2) “iPod Service”=3 (0x3) “EvtEng”=2 (0x2) *Newly Created Service* - COMHOST Contents of the ‘Scheduled Tasks’ folder 2007-07-06 18:00:02 C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Emil.job ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-10 23:17:12 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-10 23:17:44 C:\ComboFix-quarantined-files.txt … 2007-07-10 23:17 — E O F —