ComboFix 07-07-30.2 - “Seba” 2007-07-30 16:28:23.1 [GMT 2:00] - FAT32 Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.Prawda * Created a new restore point ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\5_exception.nls C:\WINDOWS\system32\drivers\runtime2.sys C:\WINDOWS\system32\drivers\secdrv.sys C:\WINDOWS\system32\ksys.sys ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_NDNET1 -------\LEGACY_RUNTIME -------\LEGACY_RUNTIME2 -------\NDnet1 -------\runtime ((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-30 ))))))))))))))))))))))))))))))) 2007-07-30 16:27 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-30 16:13 5,897 --a------ C:\dnsbak.reg 2007-07-30 15:21 2007-07-30 15:19 2007-07-29 22:15 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-07-29 22:14 2007-07-29 20:21 2007-07-29 16:52 2007-07-29 16:01 2007-07-29 15:40 2007-07-29 14:20 2007-07-29 14:18 2,018 --a------ C:\WINDOWS\mozver.dat 2007-07-29 14:15 0 --a------ C:\WINDOWS\nsreg.dat 2007-07-29 10:08 2007-07-29 10:06 2007-07-29 10:06 2007-07-29 10:06 2007-07-29 10:06 2007-07-28 22:57 2007-07-28 13:54 2007-07-28 13:52 549,720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-28 13:52 33,624 --a------ C:\WINDOWS\system32\wups.dll 2007-07-28 13:52 325,976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-28 13:52 203,096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-28 13:52 187,160 --a------ C:\WINDOWS\system32\wuaueng1.dll 2007-07-28 13:52 170,264 --a------ C:\WINDOWS\system32\wuauclt1.exe 2007-07-28 13:52 2007-07-28 13:45 310,272 --a------ C:\WINDOWS\system32\winhttp.dll 2007-07-28 12:39 2007-07-28 10:15 60,273 --a------ C:\WINDOWS\system32\pthreadGC2.dll 2007-07-28 10:15 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll 2007-07-28 10:15 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll 2007-07-28 10:15 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-07-28 10:15 2007-07-27 00:39 2007-07-27 00:39 2007-07-25 12:27 2007-07-25 12:27 2007-07-24 11:33 2007-07-23 12:25 2007-07-23 09:27 2007-07-22 09:18 4,608 --a------ C:\WINDOWS\system32\W95Inf32.DLL 2007-07-22 09:18 2,272 --a------ C:\WINDOWS\system32\W95Inf16.DLL 2007-07-22 09:18 2007-07-21 20:01 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys 2007-07-21 20:01 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys 2007-07-21 20:01 43,528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys 2007-07-21 20:01 129,784 --------- C:\WINDOWS\system32\pxafs.dll 2007-07-21 19:57 2007-07-20 20:46 2007-07-20 20:45 4 --a------ C:\WINDOWS\system32\proc-385240966.bin 2007-07-20 20:45 2007-07-20 17:58 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-07-20 17:12 2007-07-20 16:38 2007-07-20 16:35 2007-07-20 16:34 79,616 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys 2007-07-20 16:34 57,472 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys 2007-07-20 16:34 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys 2007-07-20 16:34 50,048 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-07-20 16:34 5,632 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-07-20 16:34 2,816 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys 2007-07-20 16:34 159,232 --a------ C:\WINDOWS\system32\drivers\kmixer.sys 2007-07-20 16:34 122,472 --a------ C:\WINDOWS\system32\drivers\aec.sys 2007-07-20 16:33 917,504 -ra------ C:\WINDOWS\system\cmids3d.dll 2007-07-20 16:33 821,760 -ra------ C:\WINDOWS\system32\drivers\cmuda.sys 2007-07-20 16:33 712,704 -ra------ C:\WINDOWS\system32\Audio3D.dll 2007-07-20 16:33 712,704 -ra------ C:\WINDOWS\system32\a3d.dll 2007-07-20 16:33 57,344 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-07-20 16:33 32,768 -ra------ C:\WINDOWS\system32\udaprop.dll 2007-07-20 16:33 28,672 -ra------ C:\WINDOWS\system32\cmirmdrv.dll 2007-07-20 16:33 28,672 --a------ C:\WINDOWS\CMIRmDriver.dll 2007-07-20 16:33 266,240 --a------ C:\WINDOWS\CMIUninstall.exe 2007-07-20 16:33 233,472 -ra------ C:\WINDOWS\system32\cmirmdrv.exe 2007-07-20 16:33 225,280 --a------ C:\WINDOWS\CmiRmRedundDir.exe 2007-07-20 16:33 163,840 -ra------ C:\WINDOWS\system32\cmuda.dll 2007-07-20 16:33 135,040 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-07-20 16:33 1,458,176 -ra------ C:\WINDOWS\system\SmWizard.exe 2007-07-20 16:33 2007-07-20 16:32 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS 2007-07-20 16:29 2007-07-20 16:29 2007-07-20 16:25 98,816 --a------ C:\WINDOWS\system32\dmstyle.dll 2007-07-20 16:25 974,848 --a------ C:\WINDOWS\system32\dxdiag.exe 2007-07-20 16:25 83,968 --a------ C:\WINDOWS\system32\drivers\nabtsfec.sys 2007-07-20 16:25 80,896 --a------ C:\WINDOWS\system32\dpvsetup.exe 2007-07-20 16:25 8,192 --a------ C:\WINDOWS\system32\d3d8thk.dll 2007-07-20 16:25 797,184 --a------ C:\WINDOWS\system32\d3dim700.dll 2007-07-20 16:25 79,360 --a------ C:\WINDOWS\system32\dpwsockx.dll 2007-07-20 16:25 77,824 --a------ C:\WINDOWS\system32\dpmodemx.dll 2007-07-20 16:25 76,800 --a------ C:\WINDOWS\system32\dmscript.dll 2007-07-20 16:25 733,184 --a------ C:\WINDOWS\system32\qedwipes.dll 2007-07-20 16:25 723,968 --a------ C:\WINDOWS\system32\dpnet.dll 2007-07-20 16:25 7,424 --a------ C:\WINDOWS\system32\drivers\mskssrv.sys 2007-07-20 16:25 68,096 --a------ C:\WINDOWS\system32\dpnhupnp.dll 2007-07-20 16:25 667,648 --a------ C:\WINDOWS\system32\dinput8.dll 2007-07-20 16:25 648,704 --a------ C:\WINDOWS\system32\dinput.dll 2007-07-20 16:25 64,512 --a------ C:\WINDOWS\system32\amstream.dll 2007-07-20 16:25 602,624 --a------ C:\WINDOWS\system32\dx7vb.dll 2007-07-20 16:25 58,368 --a------ C:\WINDOWS\system32\dmcompos.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-20 16:22 49492 --a------ C:\WINDOWS\system32\perfc015.dat 2007-07-20 16:22 355486 --a------ C:\WINDOWS\system32\perfh015.dat --------- C:\Program Files\Usługi online ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2004-08-25 12:52] “Cmaudio”=“cmicnfg.cpl” [] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2007-05-15 00:22] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\System32\ctfmon.exe” [2001-10-26 17:29] “MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2001-08-02 07:14] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-07-09 09:39] “Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-07-02 17:10] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ PLANET WL-8315 Utility.lnk - C:\Program Files\PLANET\Common\RaUI.exe [2007-07-20 16:19:07] Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26] R2 OneStep Search Service;OneStep Search Service;“C:\Program Files\OneStepSearch\onestep.exe” “C:\Program Files\OneStepSearch\onestep.dll” Service R3 cmuda;C-Media WDM Audio Interface;C:\WINDOWS\System32\drivers\cmuda.sys R3 sermouse;Sterownik myszy szeregowej;C:\WINDOWS\System32\DRIVERS\sermouse.sys S3 FETNDIS;Sterownik NT karty VIA PCI 10/100Mb Fast Ethernet;C:\WINDOWS\System32\DRIVERS\fetnd5.sys *Newly Created Service* - ALG *Newly Created Service* - IPNAT ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-30 16:30:11 Windows 5.1.2600 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-30 16:30:40 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-07-30 16:30 — E O F —