“ewelina” - 2007-07-28 22:43:49 [GMT 2:00] - ComboFix 07-07-24 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system\smss.exe ((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-28 ))))))))))))))))))))))))))))))) 2007-07-28 17:39 110,592 --a------ C:\WINDOWS\system32\tsccvid.dll 2007-07-28 17:09 2007-07-26 20:18 921,600 --a------ C:\WINDOWS\system32\vorbisenc.dll 2007-07-26 20:18 45,056 --a------ C:\WINDOWS\system32\ogg.dll 2007-07-26 20:18 237,568 --a------ C:\WINDOWS\system32\OggDS.dll 2007-07-26 20:18 188,416 --a------ C:\WINDOWS\system32\vorbis.dll 2007-07-26 20:18 1,415,680 --a------ C:\WINDOWS\system32\WMV9VCM.dll 2007-07-26 20:17 2007-07-26 20:17 2007-07-26 20:17 2007-07-26 16:43 2007-07-26 16:13 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-07-26 16:13 2007-07-26 15:21 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-07-26 15:21 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll 2007-07-26 15:21 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-07-26 15:21 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll 2007-07-26 15:21 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll 2007-07-26 15:21 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-07-26 15:21 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-07-26 15:19 2007-07-25 18:13 2007-07-25 17:45 1,078,601 --a------ C:\WINDOWS\screen saver mp3 01.scr 2007-07-25 17:40 2007-07-25 17:38 2007-07-24 11:20 817,664 —h----- C:\WINDOWS\system32\wodfamoh.dll 2007-07-23 18:05 2007-07-23 17:55 2007-07-23 17:04 2007-07-23 11:10 2007-07-23 10:27 682,232 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-07-22 12:13 71,680 --------- C:\WINDOWS\system32\drivers\PAVDRV51.SYS 2007-07-22 12:13 45,056 --a------ C:\WINDOWS\system32\avldr.dll 2007-07-22 12:13 248 --a------ C:\WINDOWS\system32\PavCPL.dat 2007-07-22 12:13 2007-07-22 12:13 2007-07-22 12:02 2007-07-21 12:42 2007-07-07 19:21 2007-07-07 19:21 2007-07-07 10:42 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-28 14:08:39 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-07-26 18:17:55 9,216 ----a-w C:\WINDOWS\system32\cpuinf32.dll 2007-07-22 10:16:30 68,554 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-07-22 10:16:30 439,538 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-07-19 21:14:19 -------- d-----w C:\DOCUME~1\ewelina\DANEAP~1\Skype 2007-07-07 08:21:31 283 ----a-w C:\WINDOWS\comm.bin 2007-07-07 06:34:33 -------- d-----w C:\Program Files\Lx_cats 2007-06-20 20:53:36 77,824 ----a-w C:\WINDOWS\insmall.dll 2007-06-19 11:16:25 257 ----a-w C:\WINDOWS\msdres.bin 2007-06-08 18:01:28 -------- d-----w C:\Program Files\MSXML 4.0 2007-06-08 15:49:20 -------- d-----w C:\Program Files\Bonjour 2007-06-08 14:54:36 -------- d-----w C:\Program Files\Common Files\Macrovision Shared 2007-06-08 09:18:04 -------- d-----w C:\Program Files\Common Files\InstallShield 2007-06-08 09:12:45 85 ----a-w C:\AUTOEXEC.BAT 2007-06-07 21:23:43 -------- d-----w C:\DOCUME~1\ewelina\DANEAP~1\Sony Setup 2007-06-05 14:29:11 -------- d-----w C:\Program Files\TGTSoft 2007-05-31 13:59:12 287 ----a-w C:\WINDOWS\PowerReg.dat 2007-05-31 13:58:16 -------- d-----w C:\Program Files\Common Files\Vbox 2007-05-31 06:45:07 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2007-05-31 06:44:55 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll 2007-05-31 06:44:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll 2007-05-31 06:44:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll 2007-05-31 06:44:54 740,442 ----a-w C:\WINDOWS\system32\DivX.dll 2007-05-16 15:18:58 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2004-03-03 12:00] “WooCnxMon”=“C:\PROGRA~1\NEOSTR~1\CnxMon.exe” [2003-10-16 19:07] “SpeedTouch USB Diagnostics”=“C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” [2004-01-26 11:38] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2003-10-16 19:07] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [2003-10-16 19:07] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43] “APVXDWIN”=“C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.exe” [2007-01-25 18:50] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “STYLEXP”=“C:\Program Files\TGTSoft\StyleXP\StyleXP.exe” [2006-05-24 20:31] “Gadu-Gadu”=“D:\programy\Gadu-Gadu\gg.exe” [2007-05-10 16:36] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr] avldr.dll 2006-07-14 13:46 45056 C:\WINDOWS\system32\avldr.dll R0 BTHidEnum;Bluetooth HID Enumerator;C:\WINDOWS\system32\Drivers\vbtenum.sys R0 BTHidMgr;Bluetooth HID Manager Service;C:\WINDOWS\system32\Drivers\BTHidMgr.sys R0 xmasbus;xmasbus;C:\WINDOWS\system32\DRIVERS\xmasbus.sys R0 xmasscsi;xmasscsi;C:\WINDOWS\system32\Drivers\xmasscsi.sys R1 NetBT;NetBios przez TCP/IP;C:\WINDOWS\system32\DRIVERS\netbt.sys R1 PCLEPCI;PCLEPCI;??\C:\WINDOWS\system32\drivers\pclepci.sys R1 StyleXPHelper;StyleXPHelper;??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe R2 pavdrv;Panda Antivirus Filter Driver for x86;??\C:\WINDOWS\system32\Drivers\pavdrv51.sys R3 alcan5wn;SpeedTouch USB ADSL PPP Networking Driver (NDISWAN);C:\WINDOWS\system32\DRIVERS\alcan5wn.sys R3 alcaudsl;SpeedTouch ADSL Modem ATM Transport;C:\WINDOWS\system32\DRIVERS\alcaudsl.sys R3 ALCXSENS;Service for WDM 3D Audio Driver;C:\WINDOWS\system32\drivers\ALCXSENS.SYS R3 BlueletAudio;Bluetooth Audio Service;C:\WINDOWS\system32\DRIVERS\blueletaudio.sys R3 BlueletSCOAudio;Bluetooth SCO Audio Service;C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys R3 BT;Bluetooth PAN Network Adapter;C:\WINDOWS\system32\DRIVERS\btnetdrv.sys R3 ms_mpu401;Sterownik portu MIDI UART Microsoft MPU-401;C:\WINDOWS\system32\drivers\msmpu401.sys R3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32\Drivers\RootMdm.sys R3 VComm;Virtual Serial port driver;C:\WINDOWS\system32\DRIVERS\VComm.sys R3 VcommMgr;Bluetooth VComm Manager Service;C:\WINDOWS\system32\Drivers\VcommMgr.sys S3 Btcsrusb;Bluetooth USB For Bluetooth Service;C:\WINDOWS\system32\Drivers\btcusb.sys S3 Start BT in service;Start BT in service;D:\programy\bluesoleil\StartSkysolSvc.exe S3 usbser;Motorola USB Modem Driver;C:\WINDOWS\system32\DRIVERS\usbser.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{3b86bcd4-d13b-11da-a671-ad7e452717fb}] AutoRun\command- H:\autorun\autorun.exe Contents of the ‘Scheduled Tasks’ folder 2007-07-26 04:14:05 C:\WINDOWS\tasks\AppleSoftwareUpdate.job ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-28 22:46:24 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,… scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-28 22:48:01 C:\ComboFix-quarantined-files.txt … 2007-07-28 22:47 — E O F —