ComboFix 07-08-07.6 - “Szozda” 2007-08-08 16:15:08.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.196 [GMT 2:00] ((((((((((((((((((((((((( Files Created from 2007-07-08 to 2007-08-08 ))))))))))))))))))))))))))))))) 2007-08-08 15:58 83,592 --a------ C:\WINDOWS\system32\SSSensor.dll 2007-08-08 15:58 61,008 --a------ C:\WINDOWS\system32\drivers\Teefer.sys 2007-08-08 15:58 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys 2007-08-08 15:58 14,944 --a------ C:\WINDOWS\system32\drivers\wg6n.sys 2007-08-08 15:58 14,944 --a------ C:\WINDOWS\system32\drivers\wg5n.sys 2007-08-08 15:58 14,944 --a------ C:\WINDOWS\system32\drivers\wg4n.sys 2007-08-08 15:58 14,944 --a------ C:\WINDOWS\system32\drivers\wg3n.sys 2007-08-08 15:58 2007-08-08 15:58 2007-08-08 14:46 2007-08-08 13:19 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-08 02:33 2007-08-08 02:24 2007-08-08 02:23 94,208 --a------ C:\WINDOWS\system32\pskill.exe 2007-08-08 02:23 8,636 --a------ C:\WINDOWS\system32\modifype.exe 2007-08-08 02:23 19,968 --a------ C:\WINDOWS\system32\reico.exe 2007-08-08 02:23 111,104 --a------ C:\WINDOWS\system32\Uharc.exe 2007-08-07 19:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2007-08-07 19:02 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2007-07-30 12:28 2007-07-29 17:27 2007-07-29 14:43 2007-07-29 14:41 2007-07-29 14:41 2007-07-29 10:54 327,168 --a------ C:\WINDOWS\IsUn0415.exe 2007-07-28 17:45 2007-07-28 15:21 2007-07-26 04:14 2,181,632 -----c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe 2007-07-26 04:14 2,058,880 -----c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe 2007-07-26 03:45 27,648 -----c— C:\WINDOWS\system32\dllcache\jgpl400.dll 2007-07-26 03:45 163,840 -----c— C:\WINDOWS\system32\dllcache\jgdw400.dll 2007-07-26 03:44 28,672 --------- C:\WINDOWS\system32\verclsid.exe 2007-07-25 15:42 2007-07-25 12:24 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys 2007-07-25 12:24 298,104 --a------ C:\WINDOWS\system32\imon.dll 2007-07-25 12:24 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys 2007-07-25 10:00 2007-07-25 10:00 2007-07-25 09:54 2007-07-25 09:29 2007-07-25 09:27 2007-07-25 09:24 1,402 --a------ C:\WINDOWS\mozver.dat 2007-07-25 09:21 0 --a------ C:\WINDOWS\nsreg.dat 2007-07-24 19:38 70,688 --a------ C:\WINDOWS\system32\drivers\alcaudsl.sys 2007-07-24 19:38 53,600 --a------ C:\WINDOWS\system32\drivers\alcan5wn.sys 2007-07-24 19:38 5,606 --a------ C:\WINDOWS\system32\stci.dll 2007-07-24 19:38 5,280 --a------ C:\WINDOWS\system32\drivers\alcawh.sys 2007-07-24 19:38 3,968 --a------ C:\WINDOWS\system32\drivers\alcacr.sys 2007-07-24 19:38 2007-07-24 19:29 2007-07-24 09:56 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-07-24 09:56 2007-07-24 09:56 2007-07-24 09:56 2007-07-24 09:55 2007-07-24 09:55 2007-07-24 09:55 2007-07-24 09:55 2007-07-23 18:50 51,200 --a------ C:\WINDOWS\system32\drivers\UsbSagCom.sys 2007-07-21 14:24 2007-07-21 14:22 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll 2007-07-21 14:22 476,320 --a------ C:\WINDOWS\system32\imagXpr7.dll 2007-07-21 14:22 471,040 --a------ C:\WINDOWS\system32\imagXRA7.dll 2007-07-21 14:22 364,544 --a------ C:\WINDOWS\system32\TwnLib4.dll 2007-07-21 14:22 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll 2007-07-21 14:22 32,768 --a------ C:\WINDOWS\system32\BCGPOleAcc.dll 2007-07-21 14:22 262,144 --a------ C:\WINDOWS\system32\imagXR7.dll 2007-07-21 14:22 2,605,056 --a------ C:\WINDOWS\system32\BCGCBPRO800u.dll 2007-07-21 14:22 2,600,960 --a------ C:\WINDOWS\system32\BCGCBPRO800.dll 2007-07-21 14:22 1,568,768 --a------ C:\WINDOWS\system32\imagX7.dll 2007-07-21 14:22 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll 2007-07-21 14:22 1,047,552 --a------ C:\WINDOWS\system32\mfc71u.dll 2007-07-21 14:22 2007-07-21 14:22 2007-07-21 14:05 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll 2007-07-21 14:04 2007-07-21 14:04 2007-07-21 14:03 2007-07-21 14:01 2007-07-21 14:00 2007-07-21 13:59 2007-07-21 13:59 2007-07-21 13:53 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys 2007-07-21 13:53 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys 2007-07-21 13:53 2007-07-21 13:53 2007-07-21 13:48 2007-07-21 13:47 2007-07-20 09:49 26,496 --a–c— C:\WINDOWS\system32\dllcache\usbstor.sys 2007-07-19 21:50 2007-07-19 18:45 2007-07-19 18:45 2007-07-19 18:18 90,800 -ra------ C:\WINDOWS\system32\drivers\se2Eunic.sys 2007-07-19 18:18 88,688 -ra------ C:\WINDOWS\system32\drivers\SE2Emgmt.sys 2007-07-19 18:18 4,128 -ra------ C:\WINDOWS\system32\drivers\se2Ecr.sys 2007-07-19 18:18 18,704 -ra------ C:\WINDOWS\system32\drivers\se2End5.sys 2007-07-19 18:17 97,184 -ra------ C:\WINDOWS\system32\drivers\SE2Emdm.sys 2007-07-19 18:17 9,360 -ra------ C:\WINDOWS\system32\drivers\SE2Emdfl.sys 2007-07-19 18:17 86,560 -ra------ C:\WINDOWS\system32\drivers\SE2Eobex.sys 2007-07-19 18:17 6,240 -ra------ C:\WINDOWS\system32\drivers\SE2Ecmnt.sys (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-26 09:11 75486 --a------ C:\WINDOWS\system32\perfc015.dat 2007-07-26 09:11 451352 --a------ C:\WINDOWS\system32\perfh015.dat --------- C:\Program Files\Usługi online ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “RTHDCPL”=“RTHDCPL.EXE” [2006-11-14 11:21 C:\WINDOWS\RTHDCPL.exe] “SkyTel”=“SkyTel.EXE” [2006-05-16 12:04 C:\WINDOWS\SkyTel.exe] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2006-01-02 18:41] “DAEMON Tools-1033”=“C:\Program Files\D-Tools\daemon.exe” [2004-08-22 17:05] “GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-27 00:47] “SpeedTouch USB Diagnostics”=“C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” [2004-01-26 11:38] “Flashget”=“C:\Program Files\FlashGet\flashget.exe” [2007-07-23 09:14] “nod32kui”=“C:\Program Files\Eset\nod32kui.exe” [2007-07-25 12:23] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe” [2007-07-12 04:00] “SmcService”=“C:\PROGRA~1\Sygate\SPF\smc.exe” [2005-09-27 12:16] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 14:00] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-07-09 09:39] “Steam”=“d:\css\steam.exe” [2007-08-06 17:23] R0 Teefer;Teefer for NT;C:\WINDOWS\system32\Drivers\Teefer.sys R1 asuskbnt;Enhanced Display Driver Helper Service;C:\WINDOWS\system32\drivers\atkkbnt.sys R1 nod32drv;nod32drv;C:\WINDOWS\system32\drivers\nod32drv.sys R1 wpsdrvnt;wpsdrvnt;??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys R2 EIO;EIO;??\C:\WINDOWS\system32\drivers\EIO.sys R2 wg3n;SyGate for NT, wg3n;C:\WINDOWS\system32\Drivers\wg3n.sys R2 wg4n;SyGate for NT, wg4n;C:\WINDOWS\system32\Drivers\wg4n.sys R2 wg5n;SyGate for NT, wg5n;C:\WINDOWS\system32\Drivers\wg5n.sys R2 wg6n;SyGate for NT, wg6n;C:\WINDOWS\system32\Drivers\wg6n.sys R3 alcan5wn;SpeedTouch USB ADSL PPP Networking Driver (NDISWAN);C:\WINDOWS\system32\DRIVERS\alcan5wn.sys S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service;“C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe” S3 odserv;Microsoft Office Diagnostics Service;“C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE” S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys S3 UsbSagCom;SAGEM Full USB Driver;C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys *Newly Created Service* - SMCSERVICE ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-08 16:15:52 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,… scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-08 16:16:21 C:\ComboFix2.txt … 2007-08-08 15:17 C:\ComboFix3.txt … 2007-08-08 13:33 — E O F —