ComboFix 07-11-19.4 - Piotr 2007-11-26 19:22:24.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1250.1.1045.18.377 [GMT 0:00] Running from: C:\Users\Piotr\Desktop\ComboFix.exe Command switches used :: C:\Users\Piotr\Desktop\CFScript.txt * Created a new restore point FILE C:\Windows\System32\PowerVideo.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Windows\System32\PowerVideo.dll . ((((((((((((((((((((((((( Files Created from 2007-10-26 to 2007-11-26 ))))))))))))))))))))))))))))))) . 2007-11-26 18:33 2007-11-26 18:11 0 --a------ C:\Windows\nsreg.dat 2007-11-25 22:55 2007-11-25 11:18 2007-11-25 11:18 2007-11-25 11:18 32 --a------ C:\Users\All Users\ezsid.dat 2007-11-25 11:18 32 --a------ C:\ProgramData\ezsid.dat 2007-11-24 20:33 2,560 --a------ C:\Windows_MSRSTRT.EXE 2007-11-24 18:55 2007-11-24 18:55 2007-11-21 22:38 2007-11-21 22:38 2007-11-18 22:58 237,568 --a------ C:\Windows\System32\lame_enc.dll 2007-11-18 22:55 2007-11-18 21:52 2007-11-18 21:52 2007-11-18 21:51 2007-11-18 21:51 2007-11-18 12:25 1,244,672 --a------ C:\Windows\System32\mcmde.dll 2007-11-15 19:13 2,923,520 --a------ C:\Windows\explorer.exe 2007-11-15 19:13 2,027,008 --a------ C:\Windows\System32\win32k.sys 2007-11-15 19:13 1,655,289 --a------ C:\Windows\System32\wlan.tmf 2007-11-15 19:13 714,240 --a------ C:\Windows\System32\timedate.cpl 2007-11-15 19:13 704,000 --a------ C:\Windows\System32\PhotoScreensaver.scr 2007-11-15 19:13 542,720 --a------ C:\Windows\System32\sysmain.dll 2007-11-15 19:13 502,784 --a------ C:\Windows\System32\wlansvc.dll 2007-11-15 19:13 297,984 --a------ C:\Windows\System32\wlansec.dll 2007-11-15 19:13 290,816 --a------ C:\Windows\System32\wlanmsm.dll 2007-11-15 19:13 258,232 --a------ C:\Windows\System32\drivers\acpi.sys 2007-11-15 19:13 67,584 --a------ C:\Windows\System32\wlanhlp.dll 2007-11-15 19:13 47,104 --a------ C:\Windows\System32\wlanapi.dll 2007-11-15 19:13 24,064 --a------ C:\Windows\System32\wtsapi32.dll 2007-11-15 19:12 224,768 --a------ C:\Windows\System32\drivers\usbport.sys 2007-11-15 19:12 192,000 --a------ C:\Windows\System32\drivers\usbhub.sys 2007-11-15 19:12 73,216 --a------ C:\Windows\System32\drivers\usbccgp.sys 2007-11-15 19:12 38,400 --a------ C:\Windows\System32\drivers\usbehci.sys 2007-11-15 19:12 19,456 --a------ C:\Windows\System32\drivers\usbohci.sys 2007-11-15 19:12 5,888 --a------ C:\Windows\System32\drivers\usbd.sys 2007-11-11 21:00 2007-11-11 20:33 2007-11-11 17:29 2007-11-11 17:28 2007-11-09 20:08 2007-11-09 20:06 2007-11-09 20:06 2007-11-09 20:06 2007-11-09 20:06 2007-11-09 20:06 5,627,904 --a------ C:\Windows\System32\RLVirDev.ocx 2007-11-09 20:06 73,728 --a------ C:\Windows\System32\ISUSPM.cpl 2007-11-08 20:20 2007-11-08 20:20 765,952 --a------ C:\Windows\System32\xvidcore.dll 2007-11-08 20:20 180,224 --a------ C:\Windows\System32\xvidvfw.dll 2007-11-08 20:20 77,824 --a------ C:\Windows\System32\xvid.ax 2007-11-08 19:45 197,522 --a------ C:\Windows\System32\V0260530.set 2007-11-08 19:45 178,913 --a------ C:\Windows\System32\drivers\V0260Vid.sys 2007-11-08 19:45 126,976 --a------ C:\Windows\System32\V0260Vfw.dll 2007-11-08 19:45 94,208 --a------ C:\Windows\System32\V0260Ext.ax 2007-11-08 19:45 36,864 --a------ C:\Windows\System32\V0260Pin.dll 2007-11-08 19:45 32,874 --a------ C:\Windows\V0260Cfg.exe 2007-11-08 19:45 28,672 --a------ C:\Windows\System32\V0260Hwx.dll 2007-11-08 19:45 24,872 --a------ C:\Windows\System32\drivers\V0260Cmd.sys 2007-11-08 19:45 20,564 --a------ C:\Windows\System32\V0260Srv.exe 2007-11-08 19:45 20,480 --a------ C:\Windows\System32\V0260Ext.crl 2007-11-07 21:34 2007-11-07 21:34 2007-11-07 21:34 483,328 --a------ C:\Windows\System32\actskn45.ocx 2007-11-07 19:44 2007-11-07 19:44 69,632 --a------ C:\Windows\System32\javacpl.cpl 2007-11-07 19:43 2007-11-06 23:41 694,784 --a------ C:\Windows\System32\localspl.dll 2007-11-06 23:41 619,008 --a------ C:\Windows\System32\drivers\dxgkrnl.sys 2007-11-06 23:41 286,208 --a------ C:\Windows\System32\ipnathlp.dll 2007-11-06 23:41 134,656 --a------ C:\Windows\System32\dps.dll 2007-11-06 23:41 77,824 --a------ C:\Windows\System32\rascfg.dll 2007-11-06 23:41 70,144 --a------ C:\Windows\System32\drivers\pacer.sys 2007-11-06 23:41 61,952 --a------ C:\Windows\System32\drivers\wanarp.sys 2007-11-06 23:41 52,736 --a------ C:\Windows\System32\rasdiag.dll 2007-11-06 23:41 48,640 --a------ C:\Windows\System32\drivers\ndproxy.sys 2007-11-06 23:41 38,400 --a------ C:\Windows\System32\kmddsp.tsp 2007-11-06 23:41 33,280 --a------ C:\Windows\System32\traffic.dll 2007-11-06 23:41 32,768 --a------ C:\Windows\System32\rasmxs.dll 2007-11-06 23:41 22,016 --a------ C:\Windows\System32\rasser.dll 2007-11-06 23:41 20,480 --a------ C:\Windows\System32\drivers\ndistapi.sys 2007-11-06 23:41 15,360 --a------ C:\Windows\System32\pacerprf.dll 2007-11-06 23:41 13,824 --a------ C:\Windows\System32\wshqos.dll 2007-11-06 23:41 8,192 --a------ C:\Windows\System32\riched32.dll 2007-11-06 23:41 1,820 --a------ C:\Windows\System32\rasctrnm.h 2007-11-06 23:40 376,320 --a------ C:\Windows\System32\winsrv.dll 2007-11-06 23:40 205,824 --a------ C:\Windows\System32\msoeacct.dll 2007-11-06 23:40 87,040 --a------ C:\Windows\System32\msoert2.dll 2007-11-06 23:40 39,424 --a------ C:\Windows\System32\ACCTRES.dll 2007-11-06 23:38 2,048 --a------ C:\Windows\System32\tzres.dll 2007-11-06 23:37 414,208 --a------ C:\Windows\System32\msscp.dll 2007-11-06 23:36 8,147,968 --a------ C:\Windows\System32\wmploc.DLL 2007-11-06 23:36 396,800 --a------ C:\Windows\System32\MPSSVC.dll 2007-11-06 23:36 356,864 --a------ C:\Windows\System32\MediaMetadataHandler.dll 2007-11-06 23:36 178,688 --a------ C:\Windows\System32\iphlpsvc.dll 2007-11-06 23:36 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys 2007-11-06 23:36 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys 2007-11-06 23:36 16,896 --a------ C:\Windows\System32\wfapigp.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-15 19:13 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe 2007-11-15 19:13 3,471,032 ----a-w C:\Windows\System32\ntoskrnl.exe 2007-11-15 19:12 8,704 ----a-w C:\Windows\System32\hcrstco.dll 2007-11-15 19:12 8,704 ----a-w C:\Windows\System32\hccoin.dll 2007-11-15 19:12 --------- d-----w C:\Program Files\Windows Mail 2007-11-07 18:23 174 --sha-w C:\Program Files\desktop.ini 2007-11-07 18:21 --------- d-----w C:\Program Files\Windows Defender 2007-11-07 18:21 --------- d-----w C:\Program Files\Windows Calendar 2007-11-06 23:41 384,000 ----a-w C:\Windows\System32\netcfgx.dll 2007-11-06 23:41 36,864 ----a-w C:\Windows\System32\cdd.dll 2007-11-06 23:41 13,824 ----a-w C:\Windows\System32\icsunattend.exe 2007-11-06 23:40 49,664 ----a-w C:\Windows\System32\csrsrv.dll 2007-11-06 23:36 86,016 ----a-w C:\Windows\System32\icfupgd.dll 2007-11-06 23:36 61,952 ----a-w C:\Windows\System32\cmifw.dll 2007-11-06 23:36 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll 2007-11-06 23:35 1,191,936 ----a-w C:\Windows\System32\msxml3.dll 2007-11-06 23:34 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll 2007-11-06 23:34 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll 2007-11-06 23:34 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll 2007-11-06 23:34 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll 2007-11-06 23:34 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll 2007-11-06 23:34 1,686,528 ----a-w C:\Windows\System32\gameux.dll 2007-11-06 23:33 56,320 ----a-w C:\Windows\System32\iesetup.dll 2007-11-06 23:33 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2007-11-06 23:33 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2007-11-06 23:32 1,335,296 ----a-w C:\Windows\System32\msxml6.dll 2007-11-06 23:31 974,336 ----a-w C:\Windows\System32\crypt32.dll 2007-11-06 23:31 88,576 ----a-w C:\Windows\System32\avifil32.dll 2007-11-06 23:31 65,024 ----a-w C:\Windows\System32\avicap32.dll 2007-11-06 23:31 61,440 ----a-w C:\Windows\System32\ntprint.exe 2007-11-06 23:31 31,232 ----a-w C:\Windows\System32\msvidc32.dll 2007-11-06 23:31 220,160 ----a-w C:\Windows\System32\ntprint.dll 2007-11-06 23:31 123,904 ----a-w C:\Windows\System32\msvfw32.dll 2007-11-06 23:31 120,320 ----a-w C:\Windows\System32\dhcpcsvc6.dll 2007-11-06 23:31 10,240 ----a-w C:\Windows\System32\dhcpcmonitor.dll 2007-11-06 23:31 1,984,512 ----a-w C:\Windows\System32\authui.dll 2007-11-05 22:48 --------- d-sh–w C:\ProgramData\Ulubione 2007-11-05 22:48 --------- d-sh–w C:\ProgramData\Szablony 2007-11-05 22:48 --------- d-sh–w C:\ProgramData\Pulpit 2007-11-05 22:48 --------- d-sh–w C:\ProgramData\Menu Start 2007-11-05 22:48 --------- d-sh–w C:\ProgramData\Dokumenty 2007-11-05 22:48 --------- d-sh–w C:\ProgramData\Dane aplikacji . ((((((((((((((((((((((((((((( snapshot@2007-11-26_18.56.31,67 ))))))))))))))))))))))))))))))))))))))))) . - 2007-11-26 17:43:14 67,584 --s-a-w C:\Windows\bootstat.dat + 2007-11-26 19:25:06 67,584 --s-a-w C:\Windows\bootstat.dat - 2007-11-26 17:45:42 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT + 2007-11-26 19:25:31 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT + 2007-11-26 19:25:31 262,144 —ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 - 2007-11-26 17:45:31 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT + 2007-11-26 19:25:31 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT + 2007-11-26 19:25:31 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-11-12 15:48] “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe” [2007-11-05 23:54] “FreeCall”=“C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe” [2007-04-17 14:28] “WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2006-11-02 12:36] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-07-09 07:39] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2007-11-06 23:39] “nod32kui”=“C:\Program Files\Eset\nod32kui.exe” [2007-11-05 23:11] “SoundMan”=“SOUNDMAN.EXE” [2007-03-09 16:28 C:\Windows\SOUNDMAN.EXE] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11] “BearFlix”=“C:\Program Files\BearFlix\BearFlix.exe” [] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum . Contents of the ‘Scheduled Tasks’ folder “2007-11-25 22:31:16 C:\Windows\Tasks\User_Feed_Synchronization-{AABF5956-3487-4BC7-B23C-0A397D4097D7}.job” - C:\Windows\system32\msfeedssync.exe . ************************************************************************** catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-26 19:25:38 Windows 6.0.6000 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-26 19:26:51 - machine was rebooted C:\ComboFix2.txt … 2007-11-26 18:57 . — E O F —