ComboFix 07-08-04.3 - “PIOTREK” 2007-08-06 16:52:08.2 [GMT 2:00] - NTFS Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.Prawda ((((((((((((((((((((((((( Files Created from 2007-07-06 to 2007-08-06 ))))))))))))))))))))))))))))))) 2007-08-06 16:50 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-06 15:19 2007-08-06 14:57 2007-08-05 15:44 2007-08-05 15:24 2007-08-05 13:55 2007-08-05 13:55 2007-08-05 13:44 2007-08-05 13:43 2007-08-05 13:31 2007-08-05 13:22 2007-08-05 13:22 2007-08-05 11:28 2007-08-05 11:25 2007-08-05 11:25 2007-08-05 11:25 2007-08-05 11:25 2007-08-04 11:39 90,112 -ra------ C:\WINDOWS\SOUNDMAN.EXE 2007-08-04 11:39 82,944 --a–c— C:\WINDOWS\system32\dllcache\wdmaud.sys 2007-08-04 11:39 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys 2007-08-04 11:39 70,144 -ra------ C:\WINDOWS\system32\drivers\Rtlnicxp.sys 2007-08-04 11:39 7,552 --a–c— C:\WINDOWS\system32\dllcache\mskssrv.sys 2007-08-04 11:39 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys 2007-08-04 11:39 60,800 --a–c— C:\WINDOWS\system32\dllcache\sysaudio.sys 2007-08-04 11:39 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys 2007-08-04 11:39 60,672 -ra------ C:\WINDOWS\system32\drivers\viamraid.sys 2007-08-04 11:39 60,288 --a–c— C:\WINDOWS\system32\dllcache\drmk.sys 2007-08-04 11:39 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-08-04 11:39 6,400 --a–c— C:\WINDOWS\system32\dllcache\splitter.sys 2007-08-04 11:39 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-08-04 11:39 54,272 --a–c— C:\WINDOWS\system32\dllcache\swmidi.sys 2007-08-04 11:39 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys 2007-08-04 11:39 52,864 --a–c— C:\WINDOWS\system32\dllcache\dmusic.sys 2007-08-04 11:39 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-08-04 11:39 5,376 --a–c— C:\WINDOWS\system32\dllcache\mspclock.sys 2007-08-04 11:39 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2007-08-04 11:39 4,992 --a–c— C:\WINDOWS\system32\dllcache\mspqm.sys 2007-08-04 11:39 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys 2007-08-04 11:39 4,096 --a–c— C:\WINDOWS\system32\dllcache\ksuser.dll 2007-08-04 11:39 4,096 --a------ C:\WINDOWS\system32\ksuser.dll 2007-08-04 11:39 3,727,680 -ra------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2007-08-04 11:39 2,944 --a–c— C:\WINDOWS\system32\dllcache\drmkaud.sys 2007-08-04 11:39 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys 2007-08-04 11:39 172,416 --a–c— C:\WINDOWS\system32\dllcache\kmixer.sys 2007-08-04 11:39 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys 2007-08-04 11:39 157,184 -ra------ C:\WINDOWS\system32\RTLCPAPI.dll 2007-08-04 11:39 145,792 --a–c— C:\WINDOWS\system32\dllcache\portcls.sys 2007-08-04 11:39 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-08-04 11:39 142,464 --a–c— C:\WINDOWS\system32\dllcache\aec.sys 2007-08-04 11:39 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys 2007-08-04 11:39 10,459,136 -ra------ C:\WINDOWS\system32\RTLCPL.EXE 2007-08-04 11:38 2007-08-04 11:38 2007-08-04 11:38 2007-08-04 11:37 2007-08-04 11:33 2007-08-04 11:31 2007-08-04 11:31 2007-08-04 11:31 2007-08-04 11:23 77,824 --a------ C:\WINDOWS\system32\mplaw7.dll 2007-08-04 11:23 77,824 --a------ C:\WINDOWS\system32\mplaa6.dll 2007-08-04 11:23 761,856 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-08-04 11:23 65,536 --a------ C:\WINDOWS\system32\mplapx.dll 2007-08-04 11:23 65,536 --a------ C:\WINDOWS\system32\mplam6.dll 2007-08-04 11:23 19,968 --a------ C:\WINDOWS\system32\cpuinf32.dll 2007-08-04 11:23 152,064 --a------ C:\WINDOWS\system32\unrar.dll 2007-08-04 11:23 1,650,688 --a------ C:\WINDOWS\system32\mplva6.dll 2007-08-04 11:23 1,581,056 --a------ C:\WINDOWS\system32\mplvw7.dll 2007-08-04 11:23 1,552,384 --a------ C:\WINDOWS\system32\mplvm6.dll 2007-08-04 11:23 1,122,304 --a------ C:\WINDOWS\system32\mplvpx.dll 2007-08-04 11:23 2007-08-04 11:19 2007-08-03 22:11 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-08-02 22:21 2007-08-02 08:27 2007-08-01 21:37 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-08-01 21:37 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-08-01 21:36 870,784 --a------ C:\WINDOWS\system32\ati3d1ag.dll 2007-08-01 21:36 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-08-01 21:36 701,440 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys 2007-08-01 21:36 516,768 --a------ C:\WINDOWS\system32\ativvaxx.dll 2007-08-01 21:36 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS 2007-08-01 21:36 229,376 --a------ C:\WINDOWS\system32\ati2cqag.dll 2007-08-01 21:36 201,728 --a------ C:\WINDOWS\system32\ati2dvag.dll 2007-08-01 21:36 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2007-08-01 21:36 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll 2007-08-01 21:34 774,144 --a–c— C:\WINDOWS\system32\dllcache\spttseng.dll 2007-08-01 21:34 77,824 --a–c— C:\WINDOWS\system32\dllcache\spcommon.dll 2007-08-01 21:34 741,376 --a–c— C:\WINDOWS\system32\dllcache\sapi.dll 2007-08-01 21:34 61,440 --a–c— C:\WINDOWS\system32\dllcache\spcplui.dll 2007-08-01 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-08-01 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-08-01 21:34 6,144 --a–c— C:\WINDOWS\system32\dllcache\kbdtuq.dll 2007-08-01 21:34 6,144 --a–c— C:\WINDOWS\system32\dllcache\kbdtuf.dll 2007-08-01 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-08-01 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-08-01 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-08-01 21:34 5,632 --a–c— C:\WINDOWS\system32\dllcache\kbdycc.dll 2007-08-01 21:34 5,632 --a–c— C:\WINDOWS\system32\dllcache\kbduzb.dll 2007-08-01 21:34 5,632 --a–c— C:\WINDOWS\system32\dllcache\kbdur.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-05 13:44 --------- d-------- C:\DOCUME~1\PIOTREK\DANEAP~1.BitTornado 2007-08-02 06:44 49712 --a------ C:\WINDOWS\system32\perfc015.dat 2007-08-02 06:44 355830 --a------ C:\WINDOWS\system32\perfh015.dat 2007-08-01 20:57 2560 --a------ C:\WINDOWS\system32\BitCometRes.dll --------- C:\Program Files\Usługi online ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-07-28 00:03] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2007-05-15 00:22] “BearShare”=“C:\Program Files\BearShare\BearShare.exe” [2006-08-01 17:04] “SoundMan”=“SOUNDMAN.EXE” [2005-09-22 10:42 C:\WINDOWS\SOUNDMAN.EXE] “MMTray”=“C:\Program Files\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe” [2003-03-25 05:49] “mmtraylsi”=“C:\Program Files\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe” [2003-03-25 05:49] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 14:00] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-07-09 09:39] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 02:48:00] Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 01:01:00] R0 uagp35;Filtr AGPv3.5 firmy Microsoft;C:\WINDOWS\system32\DRIVERS\uagp35.sys R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys R3 usbstor;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS S3 GMSIPCI;GMSIPCI;??\H:\INSTALL\GMSIPCI.SYS S3 MSICPL;MSICPL;??\H:\install4\MSICPL.sys S3 NTACCESS;NTACCESS;??\H:\NTACCESS.sys S3 SetupNTGLM7X;SetupNTGLM7X;??\H:\NTGLM7X.sys ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-06 16:52:40 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00 scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-06 16:53:15 — E O F —