07-06-18.2 - c:\ComboFix.exe “kkum” - 2007-06-29 18:46:37 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\msxml3a.dll ((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-29 ))))))))))))))))))))))))))))))) 2007-06-29 18:45 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-29 18:40 1,087,754 --a------ C:\ComboFix.exe 2007-06-29 18:32 50,688 --a------ C:\ATF-Cleaner.exe 2007-06-29 13:44 2007-06-29 13:20 9,488 --a------ C:\WINDOWS\system32\sporder.dll 2007-06-29 13:20 85,456 --a------ C:\WINDOWS\system32\drivers\Teefer.sys 2007-06-29 13:20 8,023 --a------ C:\WINDOWS\system32\drivers\wg3n.sys 2007-06-29 13:20 58,624 --a------ C:\WINDOWS\system32\drivers\Pavdrv51.sys 2007-06-29 13:20 15,360 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys 2007-06-29 13:20 2007-06-29 13:20 2007-06-29 13:16 51,232 --a------ C:\wwdc.exe 2007-06-29 13:05 2,226,922 --a------ C:\regcleaner-jv16pt_setup(dobreprogramy.pl).exe 2007-06-29 12:22 36,820,992 --a------ C:\panda-T2006promo3m.exe 2007-06-29 12:21 6,134,272 --a------ C:\pqremove.com 2007-06-29 11:46 1,291,040 --a------ C:\WindowsXP-KB823980-x86-ENU.exe 2007-06-29 11:18 2007-06-28 21:12 17,180,760 --a------ C:\antivir_workstation_win7u_en_h.exe 2007-06-28 21:09 1,508,117 --a------ C:\hammerhead_install.exe 2007-06-28 20:58 7,875,761 --a------ C:\nod-ne98plst.exe 2007-06-28 20:31 90,112 --a------ C:\WINDOWS\system32\AVASTSS.scr 2007-06-28 20:31 87,936 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-06-28 20:31 85,760 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-06-28 20:31 597,504 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-06-28 20:31 36,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-06-28 20:31 24,240 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-06-28 20:31 16,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-06-28 20:31 2007-06-28 20:19 11,082,792 --a------ C:\setuppol.exe 2007-06-28 13:38 23,649,352 --a------ C:\avg75free_476a1048.exe 2007-06-28 12:49 2007-06-28 12:39 140,288 --a------ C:\vcleaner.exe 2007-06-22 00:39 2007-06-13 11:57 2007-06-06 00:52 796,672 --a------ C:\WINDOWS\GPInstall.exe 2007-06-05 23:33 49,152 --------- C:\WINDOWS\system32\INETWH32.dll 2007-06-05 23:33 1,089,536 --------- C:\WINDOWS\system32\ROBOEX32.DLL 2007-06-05 23:33 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-29 12:15:44 -------- d-----w C:\Program Files\totalcmd 2007-06-29 12:13:02 -------- d-----w C:\Program Files\Opera 2007-06-29 12:05:10 -------- d-----w C:\Program Files\D-Tools 2007-06-29 12:03:50 -------- d-----w C:\Program Files\Common Files\Autodesk Shared 2007-06-29 11:58:52 -------- d-----w C:\Program Files\ACAD2000 2007-06-29 11:20:20 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-06-28 12:48:21 -------- d-----w C:\Program Files\SnadBoy’s Revelation v2 2007-06-27 17:17:11 -------- d-----w C:\Program Files\eMule 2007-06-25 21:36:50 -------- d-----w C:\DOCUME~1\kkum\DANEAP~1\Tlen.pl 2007-06-19 19:51:48 -------- d-----w C:\DOCUME~1\kkum\DANEAP~1\Skype 2007-05-17 20:35:18 -------- d-----w C:\Program Files\Rzeczpospolita - Mała Księgowość 2007-05-16 15:18:58 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-04-28 08:28:10 -------- d-----w C:\Program Files\PITy 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-18 16:14:32 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-04-16 20:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll 2007-04-16 20:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll 2007-01-23 15:53:09 56 --sh–r C:\WINDOWS\system32\D976EDEBE0.sys 2007-01-23 15:53:09 11,270 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=d:\programy\Reader\ActiveX\AcroIEHelper.ocx [2001-04-16 17:39] {AE7CD045-E861-484f-8273-0445EE161910}=C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 02:13] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “DAEMON Tools-1033”=“C:\Program Files\D-Tools\daemon.exe” [2004-08-22 18:05] “SunJavaUpdateSched”=“C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe” [2004-09-28 21:26] “EEventManager”=“C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe” [2005-04-08 14:09] “Acrobat Assistant 7.0”=“C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe” [2004-12-14 02:12] “@”="" [] “TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2006-09-21 23:25] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [] “SCANINICIO”=“C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe” [2003-01-29 19:20] “APVXDWIN”=“C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.exe” [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “Creative Detector”=“C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe” [2004-12-02 19:23] “Komunikator”=“C:\Program Files\Tlen.pl\tlen.exe” [2006-10-02 11:30] “BitTorrent”=“C:\Program Files\BitTorrent\bittorrent.exe” [] “Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2006-10-13 17:20] SafeBoot registry key needs repairs. This machine cannot enter Safe Mode. \SafeBoot\Minimal\Base \SafeBoot\Minimal\Boot Bus Extender \SafeBoot\Minimal\Boot file system \SafeBoot\Minimal\dmboot.sys \SafeBoot\Minimal\dmio.sys \SafeBoot\Minimal\dmload.sys \SafeBoot\Minimal\dmserver \SafeBoot\Minimal\File system \SafeBoot\Minimal\Filter \SafeBoot\Minimal\PCI Configuration \SafeBoot\Minimal\Primary disk \SafeBoot\Minimal\RpcSs \SafeBoot\Minimal\SCSI Class \SafeBoot\Minimal\sermouse.sys \SafeBoot\Minimal\System Bus Extender \SafeBoot\Minimal\vga.sys \SafeBoot\Minimal\vgasave.sys \SafeBoot\Minimal{4D36E967-E325-11CE-BFC1-08002BE10318} \SafeBoot\Minimal{4D36E96A-E325-11CE-BFC1-08002BE10318} \SafeBoot\Minimal{4D36E96B-E325-11CE-BFC1-08002BE10318} \SafeBoot\Minimal{4D36E96F-E325-11CE-BFC1-08002BE10318} \SafeBoot\Minimal{4D36E97D-E325-11CE-BFC1-08002BE10318} ~~\SafeBoot\Minimal{71A27CDD-812A-11D0-BEC7-08002BE2092F} *Newly Created Service* - ROSA Contents of the ‘Scheduled Tasks’ folder 2007-06-27 14:07:02 C:\WINDOWS\tasks\AppleSoftwareUpdate.job ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-29 18:48:01 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … HKCU\Software\Microsoft\Windows\CurrentVersion\Run Creative Detector = “C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe” /R???w0??w???*??w???w?w??O??w???m???h???h???wO??w???m???k!?s???w???wJ???>w???w??n???w???>w???w???s???g??w???w???w??>wJ??? scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “hldrrr”=“C:\WINDOWS\system32\hldrrr.exe” [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “drvsyskit”=“C:\Documents and Settings\kkum\Dane aplikacji\hidires\hidr.exe” “hldrrr”=“C:\WINDOWS\system32\hldrrr.exe” “german.exe”=“C:\WINDOWS\system32\wintems.exe” Completion time: 2007-06-29 18:48:33 C:\ComboFix-quarantined-files.txt … 2007-06-29 18:48 — E O F —