ComboFix 07-09-08.7 - “Piotrek” 2007-09-08 14:40:54.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.1.1250.1.1045.18.298 [GMT 2:00] . ADS - svchost.exe: deleted 51712 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\DOCUME~1\Piotrek\DANEAP~1\install.dat C:\DOCUME~1\Piotrek\MENUST~1\Programy\Brave-Sentry C:\DOCUME~1\Piotrek\MENUST~1\Programy\Brave-Sentry\BraveSentry.lnk C:\DOCUME~1\Piotrek\MENUST~1\Programy\Brave-Sentry\Uninstall.lnk C:\Program Files\inetget2 C:\Program Files\inetget2\popinstall.exe C:\Program Files\winpop C:\Program Files\winpop\UnInstall.exe C:\Program Files\winpop\winpop.exe C:\WINDOWS\b122.exe C:\WINDOWS\retadpu27.exe C:\WINDOWS\system32\9_exception.nls C:\WINDOWS\system32\DefLib.sys C:\WINDOWS\system32\dllh8jkd1q1.exe C:\WINDOWS\system32\dllh8jkd1q2.exe C:\WINDOWS\system32\dllh8jkd1q5.exe C:\WINDOWS\system32\dllh8jkd1q6.exe C:\WINDOWS\system32\dllh8jkd1q7.exe C:\WINDOWS\system32\dllh8jkd1q8.exe C:\WINDOWS\system32\drivers\runtime2.sys C:\WINDOWS\system32\drivers\secdrv.sys C:\WINDOWS\system32\home.exe.exe C:\WINDOWS\system32\kernelwind32.exe C:\WINDOWS\system32\max1d11643v.exe C:\WINDOWS\system32\spoolsvv.exe C:\WINDOWS\system32\svchh2b.dll C:\WINDOWS\system32\svcp.csv C:\WINDOWS\system32\tmp_k42.exe C:\WINDOWS\system32\vedxg4am1et2.exe C:\WINDOWS\system32\vedxg6ame4.exe C:\WINDOWS\system32\vedxga1me4t1.exe C:\WINDOWS\system32\vedxga3me2.exe C:\WINDOWS\system32\vedxga4m1et4.exe C:\WINDOWS\system32\vedxga4me1.exe C:\WINDOWS\system32\vedxga5me3.exe C:\WINDOWS\system32\vx.tll C:\WINDOWS\system32\winsub.xml ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_ICF -------\LEGACY_RUNTIME -------\LEGACY_RUNTIME2 -------\LEGACY_SYSLIBRARY -------\ICF -------\runtime -------\SysLibrary ((((((((((((((((((((((((( Files Created from 2007-08-08 to 2007-09-08 ))))))))))))))))))))))))))))))) . 2007-09-08 14:40 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-09-08 13:50 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-09-08 13:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2007-09-08 13:50 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe 2007-09-08 13:50 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2007-09-08 13:50 1,094 --a------ C:\WINDOWS\system32\tmp.reg 2007-09-08 13:49 2007-09-08 13:49 2007-09-08 13:49 2007-09-08 13:49 2007-09-08 13:49 2007-09-08 13:49 2007-09-08 13:49 2007-09-08 13:06 254,168 --a------ C:\WINDOWS\system32\findstr.dll 2007-09-08 13:05 6,485 --a------ C:\msntciov.exe 2007-09-08 13:05 59,342 --a------ C:\WINDOWS\system32\msdnc0.exe 2007-09-08 13:05 5,549 --a------ C:\WINDOWS\system32\msdnc2.exe 2007-09-08 13:05 35,812 --a------ C:\WINDOWS\system32\msdnc1.exe 2007-09-08 13:05 21,504 --a------ C:\WINDOWS\system32\msdnc8.exe 2007-09-08 13:05 18,944 --ah----- C:\WINDOWS\system32\drivers\protect.sys 2007-09-07 12:34 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-09-07 12:34 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll 2007-09-07 12:34 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll 2007-09-07 12:34 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll 2007-09-07 12:34 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-09-07 12:34 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll 2007-09-07 12:34 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-09-07 12:33 2007-09-04 15:58 2007-08-24 22:30 2007-08-17 02:58 23,070 --a–c— C:\WINDOWS\system32\dllcache\rtl8139.sys 2007-08-17 02:58 23,070 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2007-08-14 09:53 2007-08-13 15:20 2007-08-13 13:58 21,760 --a–c— C:\WINDOWS\system32\dllcache\usbstor.sys 2007-08-10 16:21 2007-08-10 16:18 2007-08-10 08:13 89,184 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys 2007-08-10 08:13 569,344 --a------ C:\WINDOWS\system32\imagr5.dll 2007-08-10 08:13 544,768 --a------ C:\WINDOWS\system32\imagx5.dll 2007-08-10 08:13 38,912 --a------ C:\WINDOWS\system32\picn20.dll 2007-08-10 08:13 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll 2007-08-10 08:13 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-08-10 08:13 2007-08-09 22:43 2007-08-09 22:35 15,360 -ra------ C:\WINDOWS\system32\drivers\NetMotCM.sys 2007-08-09 22:34 2007-08-09 22:32 2007-08-09 21:54 57,856 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-08-09 21:54 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-08-09 21:53 70,144 --a------ C:\WINDOWS\system32\usbui.dll 2007-08-09 21:53 27,392 --a------ C:\WINDOWS\system32\drivers\VIAAGP.SYS 2007-08-09 21:53 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:51 2007-08-09 21:43 851,968 --a------ C:\WINDOWS\system32\nvdspsch.exe 2007-08-09 21:43 782,336 --a------ C:\WINDOWS\system32\nwiz.exe 2007-08-09 21:43 454,656 --a------ C:\WINDOWS\system32\nvshell.dll 2007-08-09 21:43 401,408 --a------ C:\WINDOWS\system32\nvappbar.exe 2007-08-09 21:43 315,392 --a------ C:\WINDOWS\system32\keystone.exe 2007-08-09 21:43 110,592 --a------ C:\WINDOWS\system32\nvudisp.exe 2007-08-09 21:43 1,335,296 --a------ C:\WINDOWS\system32\nview.dll 2007-08-09 21:43 1,019,904 --a------ C:\WINDOWS\system32\nvwimg.dll 2007-08-09 21:43 2007-08-09 21:42 2007-08-09 21:42 2007-08-09 21:33 327,168 --a------ C:\WINDOWS\IsUn0415.exe 2007-08-09 21:33 32,768 --a------ C:\WINDOWS\system32\UnAudioNT.dll 2007-08-09 21:33 2007-08-09 21:31 36,224 --a–c— C:\WINDOWS\system32\dllcache\isapnp.sys 2007-08-09 21:31 36,224 --a------ C:\WINDOWS\system32\drivers\isapnp.sys 2007-08-09 21:26 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-08-09 21:26 24,064 --a------ C:\WINDOWS\autoload.exe 2007-08-09 21:26 2007-08-09 21:24 2007-08-09 21:24 2007-08-09 21:24 2007-08-09 21:24 2007-08-09 21:24 2007-08-09 21:24 2007-08-09 21:24 2007-08-09 21:24 2007-08-09 21:18 2007-08-09 21:18 2007-08-09 21:18 2007-08-09 21:18 2007-08-09 21:14 20,540 --a–c— C:\WINDOWS\system32\dllcache\admin.dll 2007-08-09 21:14 2007-08-09 21:14 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-09-08 13:06 12800 --a------ C:\WINDOWS\system32\svchost.exe --------- C:\Program Files\Usługi online . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NvCplDaemon”=“C:\WINDOWS\System32\NvCpl.dll” [2004-03-03 10:29] “nwiz”=“nwiz.exe” [2004-03-03 10:29 C:\WINDOWS\system32\nwiz.exe] “NvMediaCenter”=“C:\WINDOWS\System32\NvMcTray.dll” [2004-03-03 10:29] “NeroCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\System32\ctfmon.exe” [2002-09-20 19:05] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\botreg] C:\Documents and Settings\All Users\Dokumenty\Settings\bot.dll 2007-09-08 13:06 14238 C:\Documents and Settings\All Users\Dokumenty\Settings\bot.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\partnershipreg] C:\Documents and Settings\All Users\Dokumenty\Settings\partnership.dll 2007-09-08 14:05 14357 C:\Documents and Settings\All Users\Dokumenty\Settings\partnership.dll R0 protect;protect;C:\WINDOWS\System32\drivers\protect.sys *Newly Created Service* - ALG *Newly Created Service* - IPNAT . ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-08 14:42:50 Windows 5.1.2600 Dodatek Service Pack. 1 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-09-08 14:43:18 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-09-08 14:43 . — E O F —