ComboFix 07-11-08.1 - PIOTRK 2007-11-11 10:33:08.4 - FAT32x86 MINIMAL Running from: C:\Instal\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-10-11 to 2007-11-11 ))))))))))))))))))))))))))))))) . 2007-11-10 18:55 2007-11-10 18:04 2007-11-10 17:19 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-11-10 11:36 2007-11-10 11:34 2007-11-10 11:24 2007-11-10 11:23 2007-11-10 11:22 14,048 --------- C:\WINDOWS\system32\spmsg2.dll 2007-11-10 10:41 6,058,496 --------- C:\WINDOWS\system32\dllcache\ieframe.dll 2007-11-10 10:41 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat 2007-11-10 10:41 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll 2007-11-10 10:41 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll 2007-11-10 10:41 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll 2007-11-10 10:41 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll 2007-11-10 10:41 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2007-11-10 00:19 614,912 --a------ C:\WINDOWS\system32\h323msp.dll 2007-11-10 00:19 331,264 --a------ C:\WINDOWS\system32\ipnathlp.dll 2007-11-10 00:19 40,960 --------- C:\WINDOWS\system32\dllcache\evtgprov.dll 2007-11-09 23:50 2007-11-09 22:15 167,936 --a------ C:\WINDOWS\system32\igfxres.dll 2007-11-09 21:42 2,134,528 --a------ C:\WINDOWS\system32\dllcache\EXCH_smtpsnap.dll 2007-11-09 21:42 314,880 --a------ C:\WINDOWS\system32\dllcache\EXCH_aqueue.dll 2007-11-09 21:42 175,104 --a------ C:\WINDOWS\system32\dllcache\EXCH_smtpadm.dll 2007-11-09 21:42 45,056 --a------ C:\WINDOWS\system32\dllcache\EXCH_aqadmin.dll 2007-11-09 21:42 5,632 --a------ C:\WINDOWS\system32\dllcache\EXCH_adsiisex.dll 2007-11-09 21:34 85,376 --a------ C:\WINDOWS\system32\drivers\nabtsfec.sys 2007-11-09 21:34 19,328 --a------ C:\WINDOWS\system32\drivers\wstcodec.sys 2007-11-09 21:34 17,024 --a------ C:\WINDOWS\system32\drivers\ccdecode.sys 2007-11-09 21:34 5,504 --a------ C:\WINDOWS\system32\drivers\mstee.sys 2007-11-09 21:33 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-11-09 21:33 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-11-09 21:33 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-11-09 21:30 4,096 --a------ C:\WINDOWS\system32\ksuser.dll 2007-11-09 21:25 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys 2007-11-09 21:24 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-11-09 21:24 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-11-09 21:24 24,661 --a------ C:\WINDOWS\system32\dllcache\spxcoins.dll 2007-11-09 21:24 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-11-09 21:24 13,312 --a------ C:\WINDOWS\system32\dllcache\irclass.dll 2007-11-09 21:24 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys 2007-11-08 21:18 83,024 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys 2007-11-08 21:18 57,424 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys 2007-11-08 21:18 53,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys 2007-11-08 21:18 39,376 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys 2007-11-08 21:18 29,264 --a------ C:\WINDOWS\system32\drivers\kcom.sys 2007-11-08 21:14 2007-11-08 21:14 2007-11-08 21:14 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2007-11-08 17:37 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-11-07 22:24 4,569 --------- C:\WINDOWS\system32\secupd.dat 2007-11-07 21:57 2007-11-07 18:48 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe 2007-11-07 18:43 1,092,608 --a------ C:\WINDOWS\system32\esent.dll 2007-11-07 18:20 2007-11-07 18:11 2007-11-07 18:10 351,232 --a------ C:\WINDOWS\system32\winhttp.dll 2007-11-07 18:10 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll 2007-11-06 21:01 2007-11-06 00:19 552 --a------ C:\WINDOWS\system32\d3d8caps.dat 2007-11-05 18:21 85,568 --a------ C:\WINDOWS\system32\ryyjgkqo.dll 2007-11-05 18:21 83,008 --a------ C:\WINDOWS\system32\dbsnwkdn.dll 2007-11-04 09:24 78,912 --a------ C:\WINDOWS\system32\jygsrlxo.dll 2007-11-03 22:42 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2007-11-03 22:42 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-11-03 22:42 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2007-11-03 16:37 2007-10-29 16:36 2007-10-26 18:26 2007-10-26 17:51 2007-10-26 17:41 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-08-22 13:19 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll 2007-08-22 13:19 151,552 ------w C:\WINDOWS\system32\dllcache\cdfview.dll 2007-08-22 13:19 1,494,528 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll 2007-08-22 13:19 1,055,744 ----a-w C:\WINDOWS\system32\dllcache\danim.dll 2007-08-22 13:19 1,022,976 ------w C:\WINDOWS\system32\dllcache\browseui.dll 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-21 06:18 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-08-20 11:01 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll 2007-08-20 10:01 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll 2007-08-20 10:01 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll 2007-08-20 10:01 477,696 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll 2007-08-20 10:01 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll 2007-08-20 10:01 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll 2007-08-20 10:01 3,584,512 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2007-08-20 10:01 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll 2007-08-20 10:01 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll 2007-08-20 10:01 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll 2007-08-20 10:01 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll 2007-08-20 10:01 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll 2007-08-20 10:01 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll 2007-08-20 10:01 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll 2007-08-20 10:01 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll 2007-08-20 10:01 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll 2007-08-20 10:01 1,152,000 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll 2007-08-17 10:24 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2007-08-17 10:24 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2007-08-17 10:24 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2007-08-17 07:34 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll 2007-08-13 17:54 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll 2007-08-13 17:54 413,696 ------w C:\WINDOWS\system32\dllcache\vbscript.dll 2007-08-13 17:54 33,792 ------w C:\WINDOWS\system32\dllcache\custsat.dll 2007-08-13 17:54 191,488 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll 2007-08-13 17:54 156,160 ----a-w C:\WINDOWS\system32\msls31.dll 2007-08-13 17:54 156,160 ----a-w C:\WINDOWS\system32\dllcache\msls31.dll 2007-08-13 17:45 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll 2007-08-13 17:45 78,336 ------w C:\WINDOWS\system32\dllcache\ieencode.dll 2007-08-13 17:44 69,120 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe 2007-08-13 17:44 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll 2007-08-13 17:44 40,960 ------w C:\WINDOWS\system32\dllcache\licmgr10.dll 2007-08-13 17:42 17,408 ----a-w C:\WINDOWS\system32\corpol.dll 2007-08-13 17:42 17,408 ------w C:\WINDOWS\system32\dllcache\corpol.dll 2007-08-13 17:39 92,672 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll 2007-08-13 17:39 71,680 ----a-w C:\WINDOWS\system32\admparse.dll 2007-08-13 17:39 71,680 ------w C:\WINDOWS\system32\dllcache\admparse.dll 2007-08-13 17:39 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll 2007-08-13 17:39 55,296 ------w C:\WINDOWS\system32\dllcache\iesetup.dll 2007-08-13 17:38 491,520 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll 2007-08-13 17:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll 2007-08-13 17:36 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll 2007-08-13 17:36 36,352 ------w C:\WINDOWS\system32\dllcache\imgutil.dll 2007-08-13 17:35 346,624 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll 2007-08-13 17:32 45,568 ----a-w C:\WINDOWS\system32\mshta.exe 2007-08-13 17:32 45,568 ------w C:\WINDOWS\system32\dllcache\mshta.exe 2007-08-13 17:18 60,416 ------w C:\WINDOWS\system32\dllcache\hmmapi.dll 2007-08-13 17:01 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll 2007-08-13 17:01 48,128 ------w C:\WINDOWS\system32\dllcache\mshtmler.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{9550d8cd-2003-4c3d-ba9d-0c7b3fe4fd45}] 2007-11-05 18:21 83008 --a------ C:\WINDOWS\system32\dbsnwkdn.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{F8360A5C-9799-4CA1-AC01-B30B1A8439D0}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “EPM-DM”=“c:\acer\epm\epm-dm.exe” [2005-06-01 14:17] “ePowerManagement”=“C:\Acer\ePM\ePM.exe” [2005-03-15 10:03] “MSPY2002”=“C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe” [] “PHIME2002ASync”=“C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe” [] “PHIME2002A”=“C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe” [] “LaunchAp”=“C:\Program Files\Launch Manager\LaunchAp.exe” [2005-07-25 13:36] “CtrlVol”=“C:\Program Files\Launch Manager\CtrlVol.exe” [2003-09-16 14:28] “LMgrOSD”=“C:\Program Files\Launch Manager\OSDCtrl.exe” [2005-07-25 10:45] “Wbutton”=“C:\Program Files\Launch Manager\Wbutton.exe” [2005-07-25 13:34] “ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2005-05-16 14:52] “vptray”=“C:\PROGRA~1\SYMANT~1\VPTray.exe” [2005-05-20 17:18] “SynTPLpr”=“C:\Program Files\Synaptics\SynTP\SynTPLpr.exe” [2005-02-04 11:12] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2005-02-04 11:11] “SoundMan”=“SOUNDMAN.EXE” [2005-04-15 11:01 C:\WINDOWS\SOUNDMAN.EXE] “SDTray”=“C:\Program Files\Spyware Doctor\SDTrayApp.exe” [2007-11-08 21:35] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2006-10-10 16:51] “Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-05-07 10:36] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 08:44] “WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2006-12-01 11:46] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice" R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys S1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys S2 EpmPsd;Acer EPM Power Scheme Driver;??\C:\WINDOWS\system32\drivers\epm-psd.sys S2 EpmShd;Acer EPM System Hardware Driver;??\C:\WINDOWS\system32\drivers\epm-shd.sys S2 int15.sys;int15.sys;??\C:\Program Files\Acer\eRecovery\int15.sys S2 osaio;osaio;??\C:\WINDOWS\system32\drivers\osaio.sys S2 osanbm;osanbm;??\C:\WINDOWS\system32\drivers\osanbm.sys S3 BTNetFilter;Bluetooth Network Filter;??\C:\WINDOWS\system32\drivers\BTNetFilter.sys S3 EraserUtilDrv10733;EraserUtilDrv10733;??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10733.sys S3 POWERKEY;POWERKEY;??\C:\Program Files\Launch Manager\POWERKEY.sys S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{39b1e81a-0d63-11dc-8718-0011671b28a3}] \Shell\AutoRun\command - F:\InstallTomTomHOME.exe . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-11 10:36:04 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-11 10:37:11 C:\ComboFix3.txt … 2007-11-10 17:39 C:\ComboFix2.txt … 2007-11-10 22:23 . — E O F —