ComboFix 07-11-05.2 - Domeq 2007-11-05 21:31:11.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.147 [GMT 1:00] Running from: C:\Downloads\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-10-05 to 2007-11-05 ))))))))))))))))))))))))))))))) . 2007-11-05 20:24 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe 2007-11-05 20:24 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2007-11-05 20:24 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-11-05 20:24 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2007-11-05 20:24 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe 2007-11-05 20:24 2,322 --a------ C:\WINDOWS\system32\tmp.reg 2007-11-05 19:12 2007-11-05 18:29 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-11-05 18:01 2007-11-05 18:01 2007-11-05 18:01 525,088 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2007-11-05 18:01 82,061 --a------ C:\WINDOWS\system32\drivers\klick.dat 2007-11-05 18:01 81,549 --a------ C:\WINDOWS\system32\drivers\klin.dat 2007-11-05 18:01 6,944 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2007-11-05 18:00 2007-11-05 17:39 2007-11-03 12:47 2007-10-30 15:22 2007-10-30 15:21 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-10-28 16:47 2007-10-28 16:47 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll 2007-10-28 16:32 2007-10-28 16:32 2007-10-23 19:25 2007-10-23 19:25 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-10-23 15:06 2007-10-17 12:22 2007-10-17 12:22 4 --a------ C:\WINDOWS\system32\proc625010911.bin 2007-10-13 16:49 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-10-13 16:49 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll 2007-10-13 16:49 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll 2007-10-13 16:49 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll 2007-10-13 16:49 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll 2007-10-13 16:49 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll 2007-10-13 16:49 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll 2007-10-13 16:49 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-10-13 16:49 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll 2007-10-13 10:30 2007-10-13 10:15 2007-10-13 10:15 2007-10-13 10:15 25,544 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2007-10-12 14:12 2007-10-10 17:50 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys 2007-10-10 17:13 2007-10-09 17:51 2007-10-09 17:51 2007-10-09 17:51 2007-10-09 17:49 2007-10-09 17:49 77,824 -ra------ C:\WINDOWS\system32\HPZIDS01.dll 2007-10-09 17:49 49,664 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys 2007-10-09 17:49 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys 2007-10-09 17:48 48,128 --a------ C:\WINDOWS\system32\hpzll054.dll 2007-10-09 17:48 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-10-09 17:48 15,104 --a–c— C:\WINDOWS\system32\dllcache\usbscan.sys 2007-10-09 17:44 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-10-09 17:44 282,680 --a------ C:\WINDOWS\system32\HPZidr12.dll 2007-10-09 17:44 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll 2007-10-09 17:44 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll 2007-10-09 17:44 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe 2007-10-09 17:44 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe 2007-10-09 17:44 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll 2007-10-09 17:43 2007-10-09 17:41 120,279 --a------ C:\WINDOWS\hpoins11.dat 2007-10-09 17:40 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-10-09 17:40 25,856 --a–c— C:\WINDOWS\system32\dllcache\usbprint.sys 2007-10-08 19:01 2007-10-08 18:20 2007-10-08 18:19 2007-10-08 18:04 2007-10-08 16:46 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll 2007-10-08 16:46 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll 2007-10-08 16:46 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll 2007-10-08 16:46 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll 2007-10-08 16:46 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-10-08 16:46 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-10-08 13:46 26,496 --a–c— C:\WINDOWS\system32\dllcache\usbstor.sys 2007-10-07 20:27 21,504 --a------ C:\WINDOWS\system32\hidserv.dll 2007-10-07 20:27 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-10-07 20:26 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-10-07 20:26 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-10-07 20:26 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS 2007-10-07 20:26 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:25 2007-10-07 20:24 2007-10-07 20:24 2007-10-07 20:24 2007-10-07 20:24 2007-10-07 20:24 2007-10-07 20:17 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-05 20:18 --------- d-----w C:\Program Files\neostrada tp 2007-11-05 17:01 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx 2007-11-05 17:01 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2007-10-30 14:41 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-10-19 19:21 --------- d-----w C:\Program Files\Gadu-Gadu 2007-10-08 16:29 33 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg 2007-10-08 16:29 --------- d-----w C:\Program Files\SAGEM 2007-10-08 16:25 --------- d-----w C:\Program Files\CyberLink 2007-10-08 16:25 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\CyberLink 2007-10-08 16:24 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-10-08 16:23 --------- d-----w C:\Program Files\Common Files\Nero 2007-10-08 16:23 --------- d-----w C:\Program Files\Common Files\Ahead 2007-10-08 16:23 --------- d-----w C:\Program Files\Ahead 2007-10-08 16:15 --------- d-----w C:\Program Files\VIA 2007-10-08 16:13 --------- d-----w C:\Program Files\Analog Devices 2007-10-08 16:09 --------- d-----w C:\Program Files\ASUSTeK 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe” [2006-05-03 01:56] “NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-03-09 08:29] “nwiz”=“nwiz.exe” [2006-03-09 08:29 C:\WINDOWS\system32\nwiz.exe] “NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2006-03-09 08:29] “High Definition Audio Property Page Shortcut”=“HDAShCut.exe” [2004-10-27 14:21 C:\WINDOWS\system32\HdAShCut.exe] “SoundMAXPnP”=“C:\Program Files\Analog Devices\Core\smax4pnp.exe” [2005-05-20 10:11] “SoundMAX”=“C:\Program Files\Analog Devices\SoundMAX\Smax4.exe” [2005-09-07 14:35] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 09:50] “RemoteControl”=“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [2005-01-12 02:01] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2004-08-23 13:49] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\GestMaj.exe” [2004-10-14 15:55] “WireLessKeyboard”=“C:\Program Files\Multimedia Keyboard Driver\StartAutorun.exe” [2005-11-30 11:48] “HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2006-02-19 01:41] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [] “AVP”=“C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe” [2007-06-28 12:51] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 13:00] “Komunikator”=“C:\Program Files\Tlen.pl\tlen.exe” [2007-10-05 14:20] “DAEMON Tools”=“C:\Program Files\DAEMON Tools\daemon.exe” [2007-08-29 16:09] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22] R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys S0 viamraid;viamraid;C:\WINDOWS\system32\drivers\viamraid.sys S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-05 21:39:26 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-05 21:40:45 . — E O F —