ComboFix 07-08-30.3 - “Dom” 2007-09-07 1:54:32.3 - NTFS x86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.465 [GMT 2:00] ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_SROSA -------\srosa ((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 ))))))))))))))))))))))))))))))) 2007-09-07 01:03 2007-09-06 23:16 2007-09-06 07:07 2,181,632 --a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe 2007-09-06 04:04 2007-09-06 03:58 2007-09-06 03:36 2007-09-06 03:09 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-09-06 02:35 2007-09-06 02:28 2007-09-06 02:07 2007-09-06 00:43 138,624 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys 2007-09-06 00:42 2007-09-06 00:42 2007-09-05 23:54 2007-09-05 23:54 2007-09-05 23:50 2007-09-02 07:57 2007-08-31 20:40 2007-08-17 16:33 737,280 --a------ C:\WINDOWS\iun6002.exe 2007-08-17 16:31 2007-08-10 01:12 2007-08-10 01:10 2007-08-08 00:27 2007-08-07 23:19 2007-08-07 19:14 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-09-06 23:16 --------- d–h----- C:\Program Files\InstallShield Installation Information 2007-09-06 00:55 --------- d-------- C:\Program Files\iTunes 2007-09-06 00:22 --------- d-------- C:\Program Files\TurboGo 2007-09-05 23:53 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard 2007-08-07 23:34 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys 2007-08-05 00:11 --------- d-------- C:\Program Files\EA GAMES 2007-08-05 00:07 --------- d-------- C:\Program Files\Alcohol Soft 2007-08-05 00:03 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll 2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll 2007-07-28 00:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-07-28 00:02 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-07-28 00:02 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-07-28 00:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-07-27 23:59 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-07-27 23:58 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-07-27 23:57 95608 --a------ C:\WINDOWS\system32\AvastSS.scr 2007-07-20 00:57 267112 --a------ C:\WINDOWS\system32\xactengine2_9.dll 2007-07-20 00:54 18280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll 2007-07-19 18:14 444776 --a------ C:\WINDOWS\system32\d3dx10_35.dll 2007-07-19 18:14 3727720 --a------ C:\WINDOWS\system32\d3dx9_35.dll 2007-07-19 18:14 1358192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll 2007-07-01 17:08 1 --a------ C:\WINDOWS\system32\SI.bin 2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll 2007-06-20 20:46 266088 --a------ C:\WINDOWS\system32\xactengine2_8.dll 2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll 2007-06-13 15:23 1034752 --a------ C:\WINDOWS\explorer.exe 2005-05-11 23:36 12288 --a------ C:\WINDOWS\Fonts.\RandFont.dll 1999-05-17 14:58 99840 --a------ C:\Program Files\Common Files\IRAABOUT.DLL 1998-12-09 03:53 70144 --a------ C:\Program Files\Common Files\IRAMDMTR.DLL 1998-12-09 03:53 48640 --a------ C:\Program Files\Common Files\IRALPTTR.DLL 1998-12-09 03:53 31744 --a------ C:\Program Files\Common Files\IRAWEBTR.DLL 1998-12-09 03:53 186368 --a------ C:\Program Files\Common Files\IRAREG.DLL 1998-12-09 03:53 17920 --a------ C:\Program Files\Common Files\IRASRIAL.DLL ((((((((((((((((((((((((((((( snapshot_2007-09-06_ 31319,37 ))))))))))))))))))))))))))))))))))))))))) ----a-w 2,180,864 2005-03-02 18:14:56 C:\WINDOWS$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe ----a-w 725,728 2005-02-24 17:36:08 C:\WINDOWS$hf_mig$\KB890859\update\update.exe ----a-w 2,183,424 2007-02-28 16:09:25 C:\WINDOWS$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe ----a-w 723,680 2005-10-12 23:21:33 C:\WINDOWS$hf_mig$\KB931784\update\update.exe -c----w 317,440 2006-12-01 09:45:28 C:\WINDOWS$NtUninstallKB939683$\unregmp2.exe -c----w 216,288 2005-06-28 08:23:38 C:\WINDOWS$NtUninstallKB939683$\spuninst\spuninst.exe -c----w 371,424 2005-06-28 08:23:54 C:\WINDOWS$NtUninstallKB939683$\spuninst\updspapi.dll ----a-w 141,424 2006-08-24 06:28:54 C:\WINDOWS\Downloaded Program Files\asinst.dll ----a-w 231,072 2006-05-17 12:32:30 C:\WINDOWS\Downloaded Program Files\avsniff.dll ----a-w 198,304 2006-05-17 12:32:32 C:\WINDOWS\Downloaded Program Files\avsniffdlgs.dll ----a-w 537,704 2006-05-17 12:26:10 C:\WINDOWS\Downloaded Program Files\AXXPEE.dll ----a-w 500,120 2007-05-07 14:38:46 C:\WINDOWS\Downloaded Program Files\daas_s.dll ----a-w 42,112 2006-05-17 12:26:12 C:\WINDOWS\Downloaded Program Files\ecmldr32.dll ----a-w 284,016 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\ecmsvr32.dll ----a-w 192,920 2007-05-07 14:39:00 C:\WINDOWS\Downloaded Program Files\fsauc.dll ----a-w 254,360 2007-05-07 14:39:24 C:\WINDOWS\Downloaded Program Files\fscax.dll ----a-w 201,896 2006-05-17 12:28:00 C:\WINDOWS\Downloaded Program Files\navapi32.dll ----a-w 124,272 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\naveng32.dll ----a-w 914,800 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\navex32a.dll ----a-w 161,480 2006-05-17 12:32:42 C:\WINDOWS\Downloaded Program Files\rufsi.dll ----a-w 97,744 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\scrauth.dat ----a-w 396,845 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\tcdefs.dat ----a-w 1,773,316 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\tcscan7.dat ----a-w 386,194 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\tcscan8.dat ----a-w 899,759 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\tcscan9.dat ----a-w 67,619 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\tscan1.dat ----a-w 3,240 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\tscan1hd.dat ----a-w 992,973 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan1.dat ----a-w 570,702 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan2.dat ----a-w 149,996 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan3.dat ----a-w 320,253 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan4.dat ----a-w 4,403,699 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan5.dat ----a-w 391,763 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan6.dat ----a-w 11,763,158 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan7.dat ----a-w 1,798,654 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan8.dat ----a-w 4,906,582 2007-08-28 23:00:00 C:\WINDOWS\Downloaded Program Files\virscan9.dat ------w 2,181,632 2007-02-28 16:04:58 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe ----a-w 163,328 2007-09-05 09:43:25 C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE ----a-w 380,928 2007-09-06 23:03:45 C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT ----a-w 8,192 2007-09-06 23:03:45 C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat ----a-w 163,328 2007-09-05 09:43:25 C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE ----a-w 380,928 2007-09-06 23:03:30 C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT ----a-w 8,192 2007-09-06 23:03:30 C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat ----a-w 318,976 2007-06-27 14:00:02 C:\WINDOWS\inf\unregmp2.exe ----a-w 16,096 2005-10-12 23:21:28 C:\WINDOWS\SoftwareDistribution\Download\a5506577491f4ecc1370b18df3c5a494\spmsg.dll ----a-w 216,288 2005-10-12 23:21:30 C:\WINDOWS\SoftwareDistribution\Download\a5506577491f4ecc1370b18df3c5a494\spuninst.exe ----a-w 2,181,632 2007-02-28 16:04:58 C:\WINDOWS\SoftwareDistribution\Download\a5506577491f4ecc1370b18df3c5a494\sp2gdr\ntoskrnl.exe ----a-w 2,183,424 2007-02-28 16:09:25 C:\WINDOWS\SoftwareDistribution\Download\a5506577491f4ecc1370b18df3c5a494\sp2qfe\ntoskrnl.exe ----a-w 22,752 2005-10-12 23:21:27 C:\WINDOWS\SoftwareDistribution\Download\a5506577491f4ecc1370b18df3c5a494\update\spcustom.dll ----a-w 723,680 2005-10-12 23:21:33 C:\WINDOWS\SoftwareDistribution\Download\a5506577491f4ecc1370b18df3c5a494\update\update.exe ----a-w 386,784 2005-10-12 23:21:40 C:\WINDOWS\SoftwareDistribution\Download\a5506577491f4ecc1370b18df3c5a494\update\updspapi.dll ----a-w 16,096 2005-02-24 17:36:08 C:\WINDOWS\SoftwareDistribution\Download\ef0eb4021a89170edd4d57c53df1dbef\spmsg.dll ----a-w 212,704 2005-02-24 17:36:08 C:\WINDOWS\SoftwareDistribution\Download\ef0eb4021a89170edd4d57c53df1dbef\spuninst.exe ----a-w 2,180,608 2005-03-02 18:09:04 C:\WINDOWS\SoftwareDistribution\Download\ef0eb4021a89170edd4d57c53df1dbef\sp2gdr\ntoskrnl.exe ----a-w 2,180,864 2005-03-02 18:14:56 C:\WINDOWS\SoftwareDistribution\Download\ef0eb4021a89170edd4d57c53df1dbef\sp2qfe\ntoskrnl.exe ----a-w 22,240 2005-02-24 17:36:08 C:\WINDOWS\SoftwareDistribution\Download\ef0eb4021a89170edd4d57c53df1dbef\update\spcustom.dll ----a-w 725,728 2005-02-24 17:36:08 C:\WINDOWS\SoftwareDistribution\Download\ef0eb4021a89170edd4d57c53df1dbef\update\update.exe ----a-w 387,296 2005-02-24 17:36:08 C:\WINDOWS\SoftwareDistribution\Download\ef0eb4021a89170edd4d57c53df1dbef\update\updspapi.dll ----a-w 13,536 2005-06-28 08:20:24 C:\WINDOWS\SoftwareDistribution\Download\f4b7db19a20ddac5b17ba8b04cdfd622\spmsg.dll ----a-w 216,288 2005-06-28 08:23:38 C:\WINDOWS\SoftwareDistribution\Download\f4b7db19a20ddac5b17ba8b04cdfd622\spuninst.exe ----a-w 318,976 2007-06-27 14:00:02 C:\WINDOWS\SoftwareDistribution\Download\f4b7db19a20ddac5b17ba8b04cdfd622\unregmp2.exe ----a-w 723,680 2005-06-28 08:25:02 C:\WINDOWS\SoftwareDistribution\Download\f4b7db19a20ddac5b17ba8b04cdfd622\update\update.exe ----a-w 371,424 2005-06-28 08:23:54 C:\WINDOWS\SoftwareDistribution\Download\f4b7db19a20ddac5b17ba8b04cdfd622\update\updspapi.dll ----a-w 73,728 2006-08-02 10:39:06 C:\WINDOWS\system32\asuninst.exe ----a-w 2,181,632 2007-02-28 16:04:58 C:\WINDOWS\system32\ntoskrnl.exe ----a-w 11,776 2003-03-25 16:53:50 C:\WINDOWS\system32\ZPORT4AS.dll ----a-w 110,592 2007-03-29 07:20:50 C:\WINDOWS\system32\ActiveScan\as.dll ----a-w 233,472 2006-10-05 14:15:26 C:\WINDOWS\system32\ActiveScan\ascontrol.dll ----a-w 96,256 2005-06-03 12:03:18 C:\WINDOWS\system32\ActiveScan\asmdat.dll ----a-w 36,864 2003-08-01 09:00:16 C:\WINDOWS\system32\ActiveScan\certdll.dll ----a-w 86,016 2005-05-20 11:42:44 C:\WINDOWS\system32\ActiveScan\instlsp.dll ----a-w 4,608 2006-02-16 16:20:20 C:\WINDOWS\system32\ActiveScan\memvfile.dll ----a-w 348,160 2005-10-25 16:08:32 C:\WINDOWS\system32\ActiveScan\msvcr71.dll ----a-w 139,264 2004-05-04 13:01:02 C:\WINDOWS\system32\ActiveScan\pavaleas.dll ----a-w 45,056 2006-07-14 11:04:10 C:\WINDOWS\system32\ActiveScan\pavdr.exe ----a-w 159,832 2006-04-10 08:50:02 C:\WINDOWS\system32\ActiveScan\pavexcom.dll ----a-w 94,208 2006-02-14 11:05:38 C:\WINDOWS\system32\ActiveScan\pavinas.dll ----a-w 180,224 2006-02-16 16:35:38 C:\WINDOWS\system32\ActiveScan\pavoe.dll ----a-w 122,880 2006-10-05 14:15:38 C:\WINDOWS\system32\ActiveScan\pavpz.dll ----a-w 8,704 2006-06-30 12:13:38 C:\WINDOWS\system32\ActiveScan\pfdnnt.exe ----a-w 49,152 2004-02-04 12:08:42 C:\WINDOWS\system32\ActiveScan\port32.dll ----a-w 69,632 2006-08-01 11:23:10 C:\WINDOWS\system32\ActiveScan\pscpu.dll ----a-w 1,388,544 2006-08-23 11:06:08 C:\WINDOWS\system32\ActiveScan\pskahk.dll ----a-w 10,752 2006-08-17 09:38:14 C:\WINDOWS\system32\ActiveScan\pskalloc.dll ----a-w 61,440 2006-09-04 09:49:54 C:\WINDOWS\system32\ActiveScan\pskas.dll ----a-w 779,264 2006-08-18 06:46:18 C:\WINDOWS\system32\ActiveScan\pskavs.dll ----a-w 417,792 2007-03-26 12:25:34 C:\WINDOWS\system32\ActiveScan\pskcmp.dll ----a-w 90,112 2006-08-09 08:42:24 C:\WINDOWS\system32\ActiveScan\pskfss.dll ----a-w 208,896 2006-07-19 08:55:58 C:\WINDOWS\system32\ActiveScan\pskhtml.dll ----a-w 9,728 2006-01-20 14:57:00 C:\WINDOWS\system32\ActiveScan\pskmas.dll ----a-w 14,336 2006-05-17 07:50:12 C:\WINDOWS\system32\ActiveScan\pskmdfs.dll ----a-w 33,280 2006-08-16 08:58:12 C:\WINDOWS\system32\ActiveScan\pskpack.dll ----a-w 266,240 2006-06-30 12:42:36 C:\WINDOWS\system32\ActiveScan\pskscs.dll ----a-w 62,976 2006-08-17 12:33:14 C:\WINDOWS\system32\ActiveScan\pskutil.dll ----a-w 13,312 2006-08-08 11:13:10 C:\WINDOWS\system32\ActiveScan\pskvfile.dll ----a-w 69,632 2006-08-18 06:53:08 C:\WINDOWS\system32\ActiveScan\pskvfs.dll ----a-w 167,936 2006-08-18 06:49:50 C:\WINDOWS\system32\ActiveScan\pskvm.dll ----a-w 353,840 2007-04-18 15:16:04 C:\WINDOWS\system32\ActiveScan\psscan.dll ----a-w 35,328 2007-01-22 12:42:48 C:\WINDOWS\system32\ActiveScan\rawvfile.dll ----a-w 9,488 1997-09-18 04:12:32 C:\WINDOWS\system32\ActiveScan\sporder.dll ----a-w 69,632 2006-02-28 15:23:40 C:\WINDOWS\system32\ActiveScan\tcpvfile.dll ----a-w 213,048 2005-05-16 17:34:48 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll ----a-w 65,536 2006-03-20 11:17:24 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe ----a-w 798,720 2006-03-20 11:17:20 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll ----a-w 317,440 2006-12-01 09:45:28 C:\WINDOWS\inf\unregmp2.exe ----a-w 2,182,272 2004-08-04 07:39:10 C:\WINDOWS\system32\ntoskrnl.exe ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-04-27 09:41] “HPHUPD08”=“C:\Program Files\HP\Digital Imaging{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe” [2005-06-01 18:35] “HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2005-05-11 23:12] “Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2007-05-11 03:06] “SpywareTerminator”=“C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe” [2007-09-06 00:42] “!AVG Anti-Spyware”=“F:\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 11:25] “AVPDWIN”=“C:\Program Files\Panda Software\Panda Demo\pandasft.exe” [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 09:44] “Rainlendar2”=“D:\Programy\Rainlendar2\Rainlendar2.exe” [] “Desktop calendar”=“D:\Programy\Rainlendar2\Rainlendar2.exe” [] “AlcoholAutomount”=“C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe” [2007-07-02 12:27] C:\DOCUME~1\Dom\MENUST~1\Programy\AUTOST~1\ Stardock ObjectDock.lnk - D:\Programy\ObjectDock\ObjectDock.exe [2007-05-06 18:35:37] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] “Gadu-Gadu”=“D:\Internet\Gadu-Gadu\gg.exe” /tray [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” R1 sp_rsdrv2;Spyware Terminator Driver 2;??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe -k netsvcs HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp Contents of the ‘Scheduled Tasks’ folder 2007-08-31 15:19:40 C:\WINDOWS\Tasks\1-Click Maintenance.job - D:\Programy\Windows Utilities\SystemOptimizer.exe 2007-08-31 11:44:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-07 01:58:54 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-09-07 2:01:42 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-09-07 02:01 C:\ComboFix2.txt … 2007-09-07 00:02 C:\ComboFix3.txt … 2007-09-06 03:14 — E O F —