ComboFix 07-12-02.5 - Łukasz 2007-12-02 17:15:28.1 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.54 [GMT 1:00] Running from: C:\DOCUME~1\ŁUKASZ\USTAWI~1\Temp\Temporary Internet Files\Content.IE5\Q3Y9G56P\ComboFix[1].exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Łukasz\Dane aplikacji\ASEMBL~1 C:\Documents and Settings\Łukasz\Dane aplikacji\ASEMBL~1??plorer.exe C:\Documents and Settings\Łukasz\Dane aplikacji\ICROSO~1 C:\Documents and Settings\Łukasz\Dane aplikacji\Install.dat C:\Documents and Settings\Łukasz\Dane aplikacji\MANTEC~1 C:\Documents and Settings\Łukasz\Dane aplikacji\SMBOLS~1 C:\Documents and Settings\Łukasz\Menu Start\Programy\Brave-Sentry C:\Documents and Settings\Łukasz\Menu Start\Programy\Brave-Sentry\BraveSentry.lnk C:\Documents and Settings\Łukasz\Menu Start\Programy\Brave-Sentry\Uninstall.lnk C:\Documents and Settings\Łukasz\Menu Start\Programy\Outerinfo C:\Documents and Settings\Łukasz\Menu Start\Programy\Outerinfo\Terms.lnk C:\Documents and Settings\Łukasz\Menu Start\Programy\Outerinfo\Uninstall.lnk C:\Documents and Settings\Łukasz\Moje dokumenty\DOBE~1 C:\Documents and Settings\Łukasz\Moje dokumenty\MBOLS~1 C:\Documents and Settings\Łukasz\Moje dokumenty\WNSXS~1 C:\Documents and Settings\Łukasz\spooldr.ini C:\Program Files\asembl~1 C:\Program Files\bravesentry C:\Program Files\bravesentry\BraveSentry.lic C:\Program Files\bravesentry\BraveSentry0.bs C:\Program Files\bravesentry\BraveSentry1.bs C:\Program Files\Common Files\crosof~1.net C:\Program Files\Common Files\Yazzle1122OinAdmin.exe C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe C:\Program Files\inetget2 C:\Program Files\myglobalsearch C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST C:\Program Files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL C:\Program Files\myglobalsearch\bar\1.bin\MGSBAR.DLL C:\Program Files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL C:\Program Files\myglobalsearch\bar\Cache\00C6CE2A C:\Program Files\myglobalsearch\bar\Cache\00C6D483 C:\Program Files\myglobalsearch\bar\Cache\00C76D0A.bin C:\Program Files\myglobalsearch\bar\Cache\00C77854.bin C:\Program Files\myglobalsearch\bar\Cache\00C77A19.bin C:\Program Files\myglobalsearch\bar\Cache\files.ini C:\Program Files\myglobalsearch\bar\History\search C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm C:\Program Files\outerinfo C:\Program Files\outerinfo\FF\chrome.manifest C:\Program Files\outerinfo\FF\components\FF.dll C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt C:\Program Files\outerinfo\FF\install.rdf C:\Program Files\outerinfo\OiUninstaller.exe C:\Program Files\outerinfo\outerinfo.ico C:\Program Files\outerinfo\Terms.rtf C:\Program Files\Temporary C:\Program Files\WinAble C:\Program Files\WinAble\winable.exe C:\Program Files\ystem3~1 C:\Program Files\ystem3~1?ystem32\ C:\Program Files\ystem3~1\winspool.exe C:\WINDOWS\b122.exe C:\WINDOWS\b128.exe C:\WINDOWS\crosof~1.net C:\WINDOWS\g32.txt C:\WINDOWS\s32.txt C:\WINDOWS\stem32~1 C:\WINDOWS\system32\aspimgr.exe C:\WINDOWS\system32\dllh8jkd1q8.exe C:\WINDOWS\system32\drivers\ctl_w32.sys C:\WINDOWS\system32\drivers\ip6fw.sys C:\WINDOWS\system32\drivers\runtime2.sys C:\WINDOWS\system32\drivers\smtpdrv.sys C:\WINDOWS\system32\racle~1 C:\WINDOWS\system32\sstem3~1 C:\WINDOWS\system32\svcp.csv C:\WINDOWS\system32\vedxga3me2.exe C:\WINDOWS\system32\vedxga4m1et4.exe C:\WINDOWS\system32\vedxga4me1.exe C:\WINDOWS\system32\vx.tll C:\WINDOWS\system32\winservcs32.dll C:\WINDOWS\system32\winsub.xml C:\WINDOWS\system32\wnsapisu32.exe C:\WINDOWS\system32\xsx.dll C:\WINDOWS\system32\ystem~1 C:\WINDOWS\Temp\1178377765.exe C:\WINDOWS\Temp\1331833892.exe C:\WINDOWS\Temp\900526570.exe C:\WINDOWS\Temp\999781336.exe C:\WINDOWS\tsitra.exe C:\WINDOWS\ws386.ini D:\Autorun.inf . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_ASPIMGR -------\LEGACY_DRIVER -------\LEGACY_FCI -------\LEGACY_RUNTIME -------\LEGACY_RUNTIME2 -------\LEGACY_SMTPDRV -------\LEGACY_SYMAVC32 -------\LEGACY_SYSLIBRARY -------\asc355O -------\aspimgr -------\Driver -------\FCI -------\runtime -------\smtpdrv ((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 ))))))))))))))))))))))))))))))) . 2007-12-01 18:38 . 2007-12-01 18:38 2007-11-29 21:18 . 2007-11-29 21:18 51,712 --a------ C:\WINDOWS\system32\e404d.dll 2007-11-20 22:45 . 2007-11-20 22:45 2007-11-20 22:44 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2007-11-20 22:42 . 2007-11-20 22:42 2007-11-20 22:41 . 2007-11-20 22:41 2007-11-18 21:01 . 2007-11-18 21:01 2007-11-16 00:41 . 2007-11-16 00:41 643 --a------ C:\WINDOWS\system32\MRT.INI 2007-11-14 04:42 . 2007-11-14 04:42 2007-11-14 04:03 . 2007-11-14 04:03 2007-11-13 16:40 . 2007-11-13 16:40 2007-11-07 21:20 . 2007-11-07 21:20 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-15 15:16 402,432 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2007-11-15 15:16 402,432 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2007-10-29 21:07 --------- d-----w C:\Program Files\Lexmark X1100 Series 2007-10-28 21:59 --------- d-----w C:\Program Files\Wykresy 2007-10-28 20:01 --------- d-----w C:\Program Files\Arkadiusz Jachnik 2007-10-25 16:57 8,483,328 ------w C:\WINDOWS\system32\dllcache\shell32.dll 2007-10-15 12:23 98,304 ----a-w C:\WINDOWS\system32\LtTtf14n.Dll 2007-10-15 12:23 94,208 ----a-w C:\WINDOWS\system32\ltdoc14n.dll 2007-10-15 12:23 89,232 ----a-w C:\WINDOWS\system32\LPCPN05N.dll 2007-10-15 12:23 86,016 ----a-w C:\WINDOWS\system32\lffax14n.dll 2007-10-15 12:23 85,136 ----a-w C:\WINDOWS\system32\LPINS05N.dll 2007-10-15 12:23 77,898 ----a-w C:\WINDOWS\system32\lfjb214n.dll 2007-10-15 12:23 72,848 ----a-w C:\WINDOWS\system32\LpTxt05n.dll 2007-10-15 12:23 703,632 ----a-w C:\WINDOWS\system32\LPRES05N.DLL 2007-10-15 12:23 695,440 ----a-w C:\WINDOWS\system32\LPDLG05N.DLL 2007-10-15 12:23 68,752 ----a-w C:\WINDOWS\system32\Lpdrv05n.DLL 2007-10-15 12:23 65,536 ----a-w C:\WINDOWS\system32\ltserial.dll 2007-10-15 12:23 642,192 ----a-w C:\WINDOWS\system32\LPUIR05r.dll 2007-10-15 12:23 56,464 ----a-w C:\WINDOWS\system32\LPUNI05N.dll 2007-10-15 12:23 56,464 ----a-w C:\WINDOWS\system32\LPRPC05u.dll 2007-10-15 12:23 52,368 ----a-w C:\WINDOWS\system32\LPEML05N.DLL 2007-10-15 12:23 507,024 ----a-w C:\WINDOWS\system32\LtAct14n.dll 2007-10-15 12:23 48,272 ----a-w C:\WINDOWS\system32\LPRNT05N.DLL 2007-10-15 12:23 434,176 ----a-w C:\WINDOWS\system32\ltkrn14n.dll 2007-10-15 12:23 38,032 ----a-w C:\WINDOWS\system32\LPUMD05n.dll 2007-10-15 12:23 364,544 ----a-w C:\WINDOWS\system32\LFCMP14n.dll 2007-10-15 12:23 35,984 ----a-w C:\WINDOWS\system32\LPPMN05u.DLL 2007-10-15 12:23 32,768 ----a-w C:\WINDOWS\system32\Lfwmf14n.dll 2007-10-15 12:23 262,144 ----a-w C:\WINDOWS\system32\LTDIS14n.dll 2007-10-15 12:23 253,952 ----a-w C:\WINDOWS\system32\LTEml14n.dll 2007-10-15 12:23 241,664 ----a-w C:\WINDOWS\system32\ltefx14n.dll 2007-10-15 12:23 228,496 ----a-w C:\WINDOWS\system32\LpPdf05n.dll 2007-10-15 12:23 224,400 ----a-w C:\WINDOWS\system32\LPKRN05N.DLL 2007-10-15 12:23 221,184 ----a-w C:\WINDOWS\system32\Lvkrn14n.dll 2007-10-15 12:23 2,199,552 ----a-w C:\WINDOWS\system32\PdfDll32.dll 2007-10-15 12:23 155,648 ----a-w C:\WINDOWS\system32\LTSGM14n.dll 2007-10-15 12:23 155,648 ----a-w C:\WINDOWS\system32\ltfil14n.dll 2007-10-15 12:23 146,576 ----a-w C:\WINDOWS\system32\LpDoc05n.dll 2007-10-15 12:23 142,480 ----a-w C:\WINDOWS\system32\ltact.dll 2007-10-15 12:23 139,264 ----a-w C:\WINDOWS\system32\lfpdf14n.dll 2007-10-15 12:23 138,384 ----a-w C:\WINDOWS\system32\LpHTM05n.dll 2007-10-15 12:23 138,384 ----a-w C:\WINDOWS\system32\LpEmf05n.dll 2007-10-15 12:23 113,808 ----a-w C:\WINDOWS\system32\LPWSE05n.exe 2007-10-15 12:23 109,712 ----a-w C:\WINDOWS\system32\LpRTF05n.dll 2007-10-15 12:23 106,680 ----a-w C:\WINDOWS\system32\LPUID05n.dll 2007-10-15 12:23 1,703,936 ----a-w C:\WINDOWS\system32\LTCLR14n.dll 2007-10-15 12:23 1,637,520 ----a-w C:\WINDOWS\system32\LPUIT05N.dll 2007-10-15 12:23 1,433,600 ----a-w C:\WINDOWS\system32\LTDic14n.dll 2007-10-15 12:23 1,396,736 ----a-w C:\WINDOWS\system32\ltann14n.dll 2007-10-15 12:23 1,122,304 ----a-w C:\WINDOWS\system32\ltimg14n.dll 2007-09-18 17:54 3,335 --sha-r C:\WINDOWS\system32\msvc32.dll 2007-09-18 17:52 59,342 ----a-w C:\WINDOWS\system32\msdnc0.exe 2007-09-18 17:52 58,880 ----a-w C:\WINDOWS\system32\fci.exe . C:\WINDOWS\system32\drivers\tcpip.sys … is infected (additional data below) 402,432 2007-11-15 15:16:18 C:\WINDOWS\system32\drivers\tcpip.sys 402,432 2007-11-15 15:16:16 C:\WINDOWS\system32\dllcache\tcpip.sys 359,040 2004-08-03 22:14:42 C:\WINDOWS$NtUninstallKB893066$\tcpip.sys 332,928 2002-08-29 00:58:12 C:\WINDOWS$NtServicePackUninstall$\tcpip.sys 359,040 2006-02-23 21:07:02 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys 359,808 2005-05-25 19:04:02 C:\WINDOWS$NtUninstallKB913446$\tcpip.sys 359,936 2005-05-25 19:07:12 C:\WINDOWS$hf_mig$\KB893066\SP2QFE\tcpip.sys 360,448 2006-01-13 17:07:08 C:\WINDOWS$hf_mig$\KB913446\SP2QFE\tcpip.sys 360,576 2006-04-20 13:18:36 C:\WINDOWS$hf_mig$\KB917953\SP2QFE\tcpip.sys 359,808 2006-02-23 21:07:02 C:\WINDOWS$NtUninstallKB917953$\tcpip.sys ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{C8ED1852-D794-A066-BB5A-8C8A37842C96}] C:\WINDOWS\system32\xohycex.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Seab”=“C:\PROGRA~1\YSTEM3~1\winspool.exe” [] “Xbtjn”=“C:\Documents and Settings\Łukasz\Dane aplikacji\a?sembly??plorer.exe” [] “eMuleAutoStart”=“C:\Program Files\eMule\emule.exe” [2005-07-26 14:12] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2006-02-20 16:00] “Sony Ericsson PC Suite”=“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2005-10-26 16:17] “SoundMan”=“SOUNDMAN.EXE” [2005-01-20 20:04 C:\WINDOWS\soundman.exe] “Lexmark X1100 Series”=“C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe” [2003-08-19 16:09] “QuickTime Task”=“C:\PROGRA~1\QUICKT~1\qttask.exe” [2006-12-15 18:01] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [2004-08-04 00:44] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04] WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-02-11 19:20:26] Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-03-03 19:06:37] Ralink Wireless Utility.lnk - C:\Program Files\RALINK\Common\RaUI.exe [2007-02-19 17:22:27] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] “Ghp`amfUbrhLds”= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “Mn@iboddPubswLfov”= 0 (0x0) “Mn@mlrf”= 0 (0x0) “MnOndNeg”= 0 (0x0) “MnQtm”= 0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] “E404Helper”= {199f9717-3152-4dff-9749-38ae8d961b0d} - e404d.dll [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] C:\Program Files\QuickTime\qttask.exe -atboottime R0 ndisrd;ndisrd;C:\WINDOWS\system32\drivers\ndisrd.sys S2 sb70531432;Wi523173Shell Control Servic;C:\WINDOWS\System32\svchost.exe -k netsvcs S3 M2400;IEEE 802.11b Wireless Network Driver;C:\WINDOWS\system32\DRIVERS\M2400.sys S3 rtl8185;802.11g Wireless LAN PCI Card Driver;C:\WINDOWS\system32\DRIVERS\rtl8185.sys S3 SjyPkt;SjyPkt;??\C:\WINDOWS\System32\Drivers\SjyPkt.sys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs cb63718632 sb70531432 . ************************************************************************** catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-02 17:21:27 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-02 17:22:17 - machine was rebooted . — E O F —