“BloodAris” - 2007-12-15 13:39:41 - ComboFix 07-06-27.7 - Dodatek Service Pack 2 ((((((((((((((((((((((((( Files Created from 2007-11-15 to 2007-12-15 ))))))))))))))))))))))))))))))) 2007-12-14 18:01 2007-12-12 22:09 2007-12-12 22:08 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys 2007-12-12 22:08 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys 2007-12-12 22:08 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys 2007-12-12 22:08 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys 2007-12-12 22:08 2007-12-12 22:06 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2007-12-12 16:29 37,376 --a------ C:\WINDOWS\system32\gebbbba.dll.vir 2007-11-27 16:08 2007-11-25 15:03 2007-11-18 09:32 2007-11-18 09:32 2007-11-18 09:25 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-11-18 09:18 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll 2007-11-18 09:18 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll 2007-11-18 09:18 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll 2007-11-18 09:18 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-11-18 09:18 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll 2007-11-18 09:18 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll 2007-11-18 09:18 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll 2007-11-18 09:18 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll 2007-11-18 09:18 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-12-15 13:31:40 12 ----a-w C:\WINDOWS\bthservsdp.dat 2007-12-12 22:09:56 79,188 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-12-12 22:09:56 457,678 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-12-04 14:56:02 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-12-04 14:55:46 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-12-04 14:53:40 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-12-04 14:51:52 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-12-04 14:49:02 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-12-04 13:04:28 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-12-04 12:54:04 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr 2007-11-18 09:18:52 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys 2007-11-13 10:25:56 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-10-30 19:28:02 -------- d-----w C:\Program Files\Common Files\Skype 2007-10-30 17:15:36 -------- d-----w C:\DOCUME~1\BLOODA~1\DANEAP~1\OpenOffice.org2 2007-10-30 17:14:34 -------- d-----w C:\Program Files\OpenOffice.org 2.3 2007-10-29 22:44:30 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-26 17:15:58 -------- d-----w C:\Program Files\Common Files\YDP 2007-10-21 15:54:58 -------- d-----w C:\DOCUME~1\BLOODA~1\DANEAP~1\TwoWorldsCP 2007-10-21 11:59:48 0 ----a-w C:\WINDOWS\ativpsrm.bin 2007-10-20 06:01:32 227,328 ------w C:\WINDOWS\system32\wmasf.dll 2007-10-20 00:56:16 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2007-10-20 00:56:04 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll 2007-10-20 00:56:04 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll 2007-10-20 00:54:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2007-10-20 00:54:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll 2007-10-19 13:37:48 -------- d-----w C:\Program Files\Apple Software Update 2007-10-18 21:19:14 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2007-10-18 09:03:08 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll 2007-10-18 09:03:08 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll 2007-10-18 09:03:08 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll 2007-10-18 09:03:08 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll 2007-10-18 09:03:08 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll 2007-10-18 09:03:08 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll 2007-09-29 04:21:30 9,854,976 ----a-w C:\WINDOWS\system32\atioglx2.dll 2007-09-29 04:07:24 356,352 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll 2007-09-29 04:06:18 268,800 ----a-w C:\WINDOWS\system32\ati2dvag.dll 2007-09-29 03:58:36 143,360 ----a-w C:\WINDOWS\system32\atipdlxx.dll 2007-09-29 03:58:24 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll 2007-09-29 03:58:16 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe 2007-09-29 03:58:08 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll 2007-09-29 03:57:56 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll 2007-09-29 03:56:34 483,328 ----a-w C:\WINDOWS\system32\ati2evxx.exe 2007-09-29 03:55:44 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL 2007-09-29 03:49:20 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll 2007-09-29 03:47:40 172,032 ----a-w C:\WINDOWS\system32\atiok3x2.dll 2007-09-29 03:47:28 3,130,720 ----a-w C:\WINDOWS\system32\ati3duag.dll 2007-09-29 03:36:26 1,593,600 ----a-w C:\WINDOWS\system32\ativvaxx.dll 2007-09-29 03:36:06 972,072 ----a-w C:\WINDOWS\system32\ativva6x.dat 2007-09-29 03:36:06 3,107,788 ----a-w C:\WINDOWS\system32\ativva5x.dat 2007-09-29 03:23:24 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll 2007-09-29 03:22:10 376,832 ----a-w C:\WINDOWS\system32\atikvmag.dll 2007-09-29 03:20:16 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll 2007-09-29 03:14:16 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll 2007-09-28 21:05:00 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe 2007-09-27 14:20:18 16,844,800 ----a-w C:\WINDOWS\RTHDCPL.exe 2007-09-26 19:34:02 28 ----a-w C:\WINDOWS\kmcdfa2200.dat 2007-09-22 18:59:36 42,720 ----a-w C:\DOCUME~1\BLOODA~1\DANEAP~1\GDIPFONTCACHEV1.DAT ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 01:56] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 03:23] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avast!”=“G:\Avast\ashDisp.exe” [2007-12-04 13:00] “BluetoothAuthenticationAgent”=“bthprops.cpl” [2004-08-04 00:44 C:\WINDOWS\system32\bthprops.cpl] “HydraVisionDesktopManager”=“C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe” [2003-09-15 21:00] “ZoneAlarm Client”=“G:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe” [2007-03-09 01:02] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe” [2006-12-15 03:23] “RTHDCPL”=“RTHDCPL.EXE” [2007-09-27 14:20 C:\WINDOWS\RTHDCPL.exe] “StartCCC”=“C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” [2006-11-10 12:35] “QuickTime Task”=“G:\Program Files\Quic\QTTask.exe” [2007-06-29 06:24] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “DAEMON Tools Pro Agent”=“G:\Program Files\DAEMON Tools Pro\DTProAgent.exe” [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoLowDiskSpaceChecks”=1 (0x1) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Image Zone Fast Start.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Image Zone Fast Start.lnk backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] “C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Live! Cam Manager] C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreativeTaskScheduler] “C:\Program Files\Creative\Shared Files\CTSched.exe” /logon [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DefragTaskBar] “G:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] G:\PROGRAMY\HP\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] “m:\steam\steam.exe” -silent [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] C:\Program Files\Winamp\winampa.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “NBService”=3 (0x3) “BlueSoleil Hid Service”=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs BthServ Contents of the ‘Scheduled Tasks’ folder 2007-12-15 12:00:02 C:\WINDOWS\tasks\HPpromotions journeysoftware.job ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-15 13:40:46 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services{00001000-0000-1000-8000-00805f9b34fb}] [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services{00001115-0000-1000-8000-00805f9b34fb}] Files hidden from API: C:\WINDOWS\BĄbelki.bmp C:\WINDOWS\Indiaäski pled.bmp C:\WINDOWS\system32\Pokaľ kanay.scf Completion time: 2007-12-15 13:41:40 C:\ComboFix3.txt … 2007-12-14 18:04 — E O F —