ComboFix 08-09-05.12 - Michal Machalewski 2008-09-09 20:33:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.221 [GMT 2:00]
Running from: C:\Documents and Settings\Michal Machalewski\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\History\search
.
((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
.
2008-09-09 19:09 . 2008-09-09 19:09
2008-09-09 19:09 . 2008-09-09 19:09
2008-09-09 19:09 . 2008-09-09 19:09
2008-09-09 19:08 . 2008-09-09 19:09
2008-09-07 11:13 . 2008-09-07 19:58
2008-09-07 11:12 . 2008-09-07 11:12
2008-09-07 11:10 . 2008-09-07 11:10
2008-09-07 11:10 . 2008-09-07 20:01
2008-09-05 17:15 . 2008-04-14 02:12 7,680 --a------ C:\WINDOWS\system32\spdwnwxp.exe
2008-09-05 16:25 . 2008-09-06 11:04
2008-09-01 16:12 . 2008-09-01 16:12
2008-09-01 16:11 . 2008-09-01 16:12
2008-09-01 16:05 . 2008-09-01 16:05
2008-08-29 12:25 . 2008-08-29 12:25 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-08-29 12:23 . 2008-08-29 12:23
2008-08-24 22:58 . 2008-08-24 22:58
2008-08-24 22:57 . 2008-08-24 22:57
2008-08-24 22:57 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-24 22:56 . 2008-08-24 22:57
2008-08-24 22:53 . 2008-08-24 22:53
2008-08-24 20:47 . 2008-08-24 20:47
2008-08-24 00:16 . 2008-08-24 00:16
2008-08-24 00:16 . 2007-06-29 21:05 520,192 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-08-24 00:15 . 2008-08-24 00:15
2008-08-24 00:06 . 2008-08-24 00:06 10 --a------ C:\WINDOWS\WININIT.INI
2008-08-23 23:51 . 2008-08-23 23:51
2008-08-23 23:50 . 2008-09-09 19:24
2008-08-23 23:50 . 2008-08-23 23:50
2008-08-23 23:50 . 2008-08-23 23:51
2008-08-23 23:50 . 2007-12-06 15:51 28,568 --a------ C:\WINDOWS\system32\drivers\AVHook.sys
2008-08-23 23:50 . 2007-12-06 15:51 21,912 --a------ C:\WINDOWS\system32\drivers\AVRec.sys
2008-08-23 23:50 . 2008-02-12 10:44 21,904 --a------ C:\WINDOWS\system32\drivers\AVFilter.sys
2008-08-22 12:52 . 2008-08-22 12:52
2008-08-21 11:55 . 2008-08-21 11:55
2008-08-21 11:55 . 2008-08-21 11:55
2008-08-14 09:14 . 2008-08-14 09:14
2008-08-09 18:11 . 2005-05-04 13:39 94,208 --a------ C:\WINDOWS\system32\China.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-09 18:32 --------- d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-08 19:45 --------- d-----w C:\Program Files\BearShare
2008-09-08 16:12 --------- d-----w C:\Program Files\eSkiMoS R2
2008-08-29 21:02 --------- d-----w C:\Documents and Settings\Michal Machalewski\Application Data\Skype
2008-08-29 10:25 --------- d-----w C:\Program Files\Free Sound Recorder
2008-08-11 07:32 --------- d-----w C:\Program Files\Winamp
2008-08-11 07:32 --------- d-----w C:\Documents and Settings\Michal Machalewski\Application Data\Winamp
2008-08-09 13:01 --------- d-----w C:\Program Files\18 Wheels of Steel American Long Haul
2008-08-09 08:52 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-08-08 09:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-08-04 21:23 --------- d-----w C:\Program Files\SHOUTcast
2008-08-04 08:55 --------- d-----w C:\Documents and Settings\Michal Machalewski\Application Data\Cool Record Edit Pro
2008-08-01 20:56 --------- d-----w C:\Documents and Settings\Michal Machalewski\Application Data\Roxio
2008-07-30 22:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\EmailNotifier
2008-07-21 20:17 --------- d-----w C:\Documents and Settings\Michal Machalewski\Application Data\InstallShield
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-12 18:08 57,344 ----a-w C:\WINDOWS\uneng.exe
2008-07-12 18:08 49,152 ----a-w C:\WINDOWS\system32\cdrtc.dll
2008-07-12 18:08 45,056 ----a-w C:\WINDOWS\system32\cdral.dll
2008-07-12 18:08 --------- d-----w C:\Program Files\directx
2008-07-12 18:08 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-07-12 18:08 --------- d-----w C:\Program Files\Common Files\Adaptec Shared
2008-07-12 17:32 --------- d-----w C:\Program Files\Skype
2008-07-12 17:32 --------- d-----w C:\Program Files\Common Files\Skype
2008-07-12 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:12 667,136 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-22 16:14 64,650 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-06-22 16:14 6,120 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-06-22 16:14 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-16 17:45 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
.
------- Sigcheck -------
2007-06-13 12:23 975360 9784e0719124e4a23989aef9e7ca02d6 C:\WINDOWS\explorer.exe
2007-06-13 13:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS$hf_mig$\KB938828\SP2QFE\explorer.exe
2006-03-15 14:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS$NtUninstallKB938828$\explorer.exe
2008-04-14 02:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe
2007-06-13 12:23 975360 9784e0719124e4a23989aef9e7ca02d6 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-15 15360]
“Gadu-Gadu”=“D:\PROGRAMY\Gadu-Gadu\gg.exe” [2007-07-09 2119104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ehTray”=“C:\WINDOWS\ehome\ehtray.exe” [2005-08-05 64512]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 155648]
“VMSnap3”=“C:\WINDOWS\VMSnap3.EXE” [2006-08-30 49152]
“Domino”=“C:\WINDOWS\Domino.EXE” [2006-06-28 49152]
“HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2006-02-19 49152]
“TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2008-06-15 180269]
“WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2008-08-04 36352]
“DAEMON Tools-1033”=“C:\Program Files\D-Tools\daemon.exe” [2004-03-12 81920]
“PCTAVApp”=“C:\Program Files\PC Tools AntiVirus\PCTAV.exe” [2008-07-23 1259408]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe” [2008-06-10 144784]
“c0.exe”=“C:\aidualc3\c0.exe” [2008-04-19 421888]
“SoundMan”=“SOUNDMAN.EXE” [2006-03-01 C:\WINDOWS\soundman.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2006-03-15 15360]
C:\Documents and Settings\Michal Machalewski\Start Menu\Programs\Startup\
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 630784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“InstallVisualStyle”= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
“InstallTheme”= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.l3fhg”= mp3fhg.acm
“VIDC.X264”= x264vfw.dll
“VIDC.HFYU”= huffyuv.dll
“vidc.i263”= i263_32.drv
“vidc.yv12”= yv12vfw.dll
“msacm.imc”= imc32.acm
“msacm.divxa32”= divxa32.acm
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“D:\PROGRAMY\Gadu-Gadu\gg.exe”=
“C:\Program Files\BitComet\BitComet.exe”=
“C:\Program Files\Valve\hl.exe”=
“C:\Program Files\Messenger\msmsgs.exe”=
“C:\Program Files\SHOUTcast\sc_serv.exe”=
“D:\Gierki\UnknownKalOnline\Unknown Launcher.exe”=
“D:\Gierki\Metin2-PL\metin2.bin”=
“C:\Program Files\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“16138:TCP”= 16138:TCP:BitComet 16138 TCP
“16138:UDP”= 16138:UDP:BitComet 16138 UDP
“8461:TCP”= 8461:TCP:GoD High Port
“8462:TCP”= 8462:TCP:GoD Low Port
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 156800]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 5248]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 9728]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 11264]
R3 vmfilter303;vmfilter303;C:\WINDOWS\system32\drivers\vmfilter303.sys [2006-04-25 428160]
S3 KS-959;Kingsun KS-959 USB Infrared Adapter;C:\WINDOWS\system32\DRIVERS\KS-959.sys [2005-09-05 19034]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS []
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
HKLM-Run-BigDog303 - C:\WINDOWS\VM303_STI.EXE
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Michal Machalewski\Application Data\Mozilla\Firefox\Profiles\1m323va8.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-09 20:35:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)???0???@?9???
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-09 20:36:10
ComboFix-quarantined-files.txt 2008-09-09 18:36:05
Pre-Run: 40,270,127,104 bytes free
Post-Run: 40,480,546,816 bajtów wolnych
187 — E O F — 2008-09-05 15:21:05