ComboFix 07-11-08.1 - stworek 2007-11-16 1:00:09.1 - NTFSx86 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1250.1.1045.18.330 [GMT 1:00] Running from: D:\PROGRAMY\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Program Files\baidu C:\Program Files\uusee C:\Program Files\uusee\UFDeMux.ax C:\Users\stworek\AppData\Local\baidu C:\Windows\system32\iexp_log.txt C:\Windows\system32\x64 . ((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 ))))))))))))))))))))))))))))))) . 2007-11-16 00:57 51,200 --a------ C:\Windows\NirCmd.exe 2007-11-14 23:29 2007-11-14 00:46 23,152 --a------ C:\Windows\System32\drivers\aswRdr.sys 2007-11-14 00:45 2007-11-14 00:45 801,144 --a------ C:\Windows\System32\aswBoot.exe 2007-11-14 00:45 95,608 --a------ C:\Windows\System32\AvastSS.scr 2007-11-14 00:45 45,648 --a------ C:\Windows\System32\drivers\aswMonFlt.sys 2007-11-14 00:45 42,912 --a------ C:\Windows\System32\drivers\aswTdi.sys 2007-11-03 22:58 2007-10-28 19:04 916,200 --a------ C:\Windows\System32\Untitled, 19-Jun-01 At 09-58.scr 2007-10-26 01:00 2007-10-17 22:05 2007-10-17 20:05 573,440 --a------ C:\Windows\System32\pcast.dll 2007-10-17 20:05 491,520 --a------ C:\Windows\System32\pCastCtl.dll 2007-10-17 20:05 159,744 --a------ C:\Windows\System32\PcastUpdate.dll 2007-10-17 20:03 2007-10-17 20:03 2007-10-17 18:27 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-14 21:05 --------- d-----w C:\Program Files\Windows Mail 2007-11-13 15:29 --------- d-----w C:\Program Files\Norton 360 2007-11-13 11:19 --------- d-----w C:\ProgramData\Symantec 2007-11-10 22:33 --------- d-----w C:\Program Files\Gadu-Gadu 2007-11-09 21:41 --------- d-----w C:\Users\stworek\AppData\Roaming\LimeWire 2007-11-08 20:46 --------- d-----w C:\Program Files\NAPI-PROJEKT 2007-11-07 17:20 --------- d-----w C:\Program Files\Zoom Player 2007-11-02 01:29 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr 2007-11-02 01:29 67,584 ----a-w C:\Windows\System32\wlanhlp.dll 2007-11-02 01:29 542,720 ----a-w C:\Windows\System32\sysmain.dll 2007-11-02 01:29 502,784 ----a-w C:\Windows\System32\wlansvc.dll 2007-11-02 01:29 47,104 ----a-w C:\Windows\System32\wlanapi.dll 2007-11-02 01:29 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe 2007-11-02 01:29 3,471,032 ----a-w C:\Windows\System32\ntoskrnl.exe 2007-11-02 01:29 297,984 ----a-w C:\Windows\System32\wlansec.dll 2007-11-02 01:29 290,816 ----a-w C:\Windows\System32\wlanmsm.dll 2007-11-02 01:29 28,344 ----a-w C:\Windows\system32\drivers\battc.sys 2007-11-02 01:29 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys 2007-11-02 01:29 24,064 ----a-w C:\Windows\System32\wtsapi32.dll 2007-11-02 01:29 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys 2007-11-02 01:29 2,923,520 ----a-w C:\Windows\explorer.exe 2007-11-02 01:29 2,027,008 ----a-w C:\Windows\System32\win32k.sys 2007-11-02 01:29 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys 2007-11-02 01:29 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys 2007-10-26 00:01 --------- d-----w C:\Program Files\Winamp 2007-10-22 16:25 --------- d-----w C:\Program Files\Real Alternative 2007-10-10 22:38 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL 2007-10-10 22:38 7,680 ----a-w C:\Windows\System32\spwmp.dll 2007-10-10 22:38 4,096 ----a-w C:\Windows\System32\dxmasf.dll 2007-10-10 22:38 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll 2007-10-10 22:36 56,320 ----a-w C:\Windows\System32\iesetup.dll 2007-10-10 22:36 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2007-10-10 22:36 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2007-10-10 22:35 84,480 ----a-w C:\Windows\System32\INETRES.dll 2007-10-10 22:35 737,792 ----a-w C:\Windows\System32\inetcomm.dll 2007-10-10 22:34 788,992 ----a-w C:\Windows\System32\rpcrt4.dll 2007-10-09 16:32 --------- d-----w C:\Program Files\LimeWire 2007-10-08 19:43 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-10-08 19:43 --------- d-----w C:\Program Files\Blue Byte 2007-10-08 08:05 --------- d-----w C:\Program Files\Java 2007-10-05 09:58 --------- d-----w C:\Program Files\iTunes 2007-10-05 09:57 --------- d-----w C:\ProgramData\Apple Computer 2007-10-05 09:57 --------- d-----w C:\Program Files\iPod 2007-10-03 18:47 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF 2007-10-03 18:47 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS 2007-10-03 18:47 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT 2007-10-03 18:47 --------- d-----w C:\Program Files\Symantec 2007-09-26 12:51 --------- d-----w C:\Program Files\Apple Software Update 2007-09-21 11:47 --------- d-----w C:\ProgramData\Lavasoft 2007-09-21 11:47 --------- d-----w C:\Program Files\Lavasoft 2007-09-21 11:45 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-09-18 12:44 10,662 ----a-w C:\Windows\system32\drivers\srtspx.cat 2007-09-18 12:44 10,662 ----a-w C:\Windows\system32\drivers\srtspl.cat 2007-09-18 12:44 10,658 ----a-w C:\Windows\system32\drivers\srtsp.cat 2007-09-18 12:44 1,430 ----a-w C:\Windows\system32\drivers\srtspl.inf 2007-09-18 12:44 1,421 ----a-w C:\Windows\system32\drivers\srtspx.inf 2007-09-18 12:44 1,415 ----a-w C:\Windows\system32\drivers\srtsp.inf 2007-09-18 12:43 43,696 ----a-w C:\Windows\system32\drivers\srtspx.sys 2007-09-18 12:43 317,616 ----a-w C:\Windows\system32\drivers\srtspl.sys 2007-09-18 12:43 278,576 ----a-w C:\Windows\system32\drivers\srtsp.sys 2007-09-01 20:17 740,442 ----a-w C:\Windows\System32\DivX.dll 2007-08-29 18:00 167,936 ----a-w C:\Windows\System32\ts.dll 2007-08-29 17:59 79,360 ----a-w C:\Windows\System32\mkzlib.dll 2007-08-29 17:59 23,552 ----a-w C:\Windows\System32\mkunicode.dll 2007-08-29 17:59 151,040 ----a-w C:\Windows\System32\mkx.dll 2007-08-29 17:59 142,848 ----a-w C:\Windows\System32\mp4.dll 2007-08-29 17:29 1,559,040 ----a-w C:\Windows\System32\xvidcore.dll 2007-08-29 10:41 8,192 ----a-w C:\Windows\System32\riched32.dll 2007-08-29 10:41 77,824 ----a-w C:\Windows\System32\rascfg.dll 2007-08-29 10:41 694,784 ----a-w C:\Windows\System32\localspl.dll 2007-08-29 10:41 52,736 ----a-w C:\Windows\System32\rasdiag.dll 2007-08-29 10:41 384,000 ----a-w C:\Windows\System32\netcfgx.dll 2007-08-29 10:41 36,864 ----a-w C:\Windows\System32\cdd.dll 2007-08-29 10:41 33,280 ----a-w C:\Windows\System32\traffic.dll 2007-08-29 10:41 32,768 ----a-w C:\Windows\System32\rasmxs.dll 2007-08-29 10:41 286,208 ----a-w C:\Windows\System32\ipnathlp.dll 2007-08-29 10:41 22,016 ----a-w C:\Windows\System32\rasser.dll 2007-08-29 10:41 15,360 ----a-w C:\Windows\System32\pacerprf.dll 2007-08-29 10:41 134,656 ----a-w C:\Windows\System32\dps.dll 2007-08-29 10:41 13,824 ----a-w C:\Windows\System32\wshqos.dll 2007-08-29 10:41 13,824 ----a-w C:\Windows\System32\icsunattend.exe 2007-08-29 10:22 174 --sha-w C:\Program Files\desktop.ini 2007-08-29 10:07 61,440 ----a-w C:\Windows\System32\ntprint.exe 2007-08-29 10:07 269,824 ----a-w C:\Windows\System32\schannel.dll 2007-08-29 10:07 220,160 ----a-w C:\Windows\System32\ntprint.dll 2007-08-29 10:06 88,576 ----a-w C:\Windows\System32\avifil32.dll 2007-08-29 10:06 82,944 ----a-w C:\Windows\System32\mciavi32.dll 2007-08-29 10:06 8,138,240 ----a-w C:\Windows\System32\ssBranded.scr 2007-08-29 10:06 712,192 ----a-w C:\Windows\System32\WindowsCodecs.dll 2007-08-29 10:06 69,632 ----a-w C:\Windows\System32\sendmail.dll 2007-08-29 10:06 65,024 ----a-w C:\Windows\System32\avicap32.dll 2007-08-29 10:06 31,232 ----a-w C:\Windows\System32\msvidc32.dll 2007-08-29 10:06 123,904 ----a-w C:\Windows\System32\msvfw32.dll 2007-08-29 10:06 120,320 ----a-w C:\Windows\System32\dhcpcsvc6.dll 2007-08-29 10:06 12,800 ----a-w C:\Windows\System32\msrle32.dll 2007-08-29 10:06 10,240 ----a-w C:\Windows\System32\dhcpcmonitor.dll 2007-08-29 10:06 1,984,512 ----a-w C:\Windows\System32\authui.dll 2007-08-29 10:04 750,080 ----a-w C:\Windows\System32\qmgr.dll 2007-08-24 16:08 1,275,392 ----a-w C:\Windows\System32\msxml4.dll 2007-08-24 08:07 53,080 ----a-w C:\Windows\System32\wuauclt.exe 2007-03-13 14:18:20 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 2007-03-13 14:18:20 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 2007-03-13 14:18:20 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2007-04-12 16:59] “NvSvc”=“C:\Windows\system32\nvsvc.dll” [2006-11-22 08:29] “NvCplDaemon”=“C:\Windows\system32\NvCpl.dll” [2006-11-22 08:29] “NvMediaCenter”=“C:\Windows\system32\NvMcTray.dll” [2006-11-22 08:29] “RtHDVCpl”=“RtHDVCpl.exe” [2006-12-01 06:37 C:\Windows\RtHDVCpl.exe] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2006-10-23 04:00] “PCMService”=“C:\Program Files\Acer\Acer Arcade\PCMService.exe” [2006-11-18 05:57] “WarReg_PopUp”=“C:\Acer\WR_PopUp\WarReg_PopUp.exe” [2006-11-05 21:48] “LManager”=“C:\PROGRA~1\LAUNCH~1\LManager.exe” [2006-12-08 13:35] “eDataSecurity Loader”=“C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe” [2006-11-17 08:26] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 00:11] “autoclk”=“autoclk.exe” [2003-01-30 07:48 C:\Windows\autoclk.exe] “IgfxTray”=“C:\Windows\system32\igfxtray.exe” [2007-03-30 10:04] “HotKeysCmds”=“C:\Windows\system32\hkcmd.exe” [2007-03-30 10:04] “Persistence”=“C:\Windows\system32\igfxpers.exe” [2007-03-30 10:04] “ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2007-01-09 22:59] “Symantec PIF AlertEng”=“C:\Program Files\Common Files\Symantec Shared\PIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe” [2007-03-12 10:22] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Sidebar”=“C:\Program Files\Windows Sidebar\sidebar.exe” [2006-11-02 13:34] “???r”="" [] “???”="???e" [] “ISUSPM Startup”=“C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe” [2005-08-11 15:30] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “NETIANET”=C:\Program Files\Netia\Net\netianet.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26] DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-05-04 17:28:01] Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-29 00:20:40] R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys R0 UBHelper;UBHelper;C:\Windows\system32\drivers\UBHelper.sys R1 DritekPortIO;Dritek General Port I/O;??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys R1 IDSvix86;Symantec Intrusion Prevention Driver;??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20071113.001\IDSvix86.sys R2 {2FF8D163-C3C2-46ce-BD8D-D85AC1BC56DD};{2FF8D163-C3C2-46ce-BD8D-D85AC1BC56DD};??\C:\Program Files\Acer\Acer Arcade\000.fcl R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys R2 eNet Service;eNet Service;C:\Acer\Empowering Technology\eNet\eNet Service.exe R2 eSettingsService;eSettings Service;C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe R2 int15;int15;??\C:\Acer\Empowering Technology\eRecovery\int15.sys R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe -p R2 WMIService;ePower Service;C:\Acer\Empowering Technology\ePower\ePowerSvc.exe R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys R3 DKbFltr;Dritek Keyboard Filter Driver;C:\Windows\system32\DRIVERS\DKbFltr.sys R3 EMSCR;EMSCR;C:\Windows\system32\DRIVERS\EMS7SK.sys R3 ESDCR;ESDCR;C:\Windows\system32\DRIVERS\ESD7SK.sys R3 ESMCR;ESMCR;C:\Windows\system32\DRIVERS\ESM7SK.sys R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\Windows\system32\DRIVERS\k510bus.sys S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\Windows\system32\DRIVERS\k510mdfl.sys S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\Windows\system32\DRIVERS\k510mdm.sys S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\Windows\system32\DRIVERS\k510mgmt.sys S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\Windows\system32\DRIVERS\k510obex.sys S3 NETw3v32;Sterownik karty Intel® PRO/Wireless 3945ABG dla systemu Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys S3 nvlddmkm;nvlddmkm;C:\Windows\system32\DRIVERS\nvlddmkm.sys S3 SMSCIRDA;SMSC Infrared Device Driver;C:\Windows\system32\DRIVERS\SMSCirda.sys S3 USBAAPL;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl.sys [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum LocalServiceNoNetwork PLA DPS BFE mpssvc *Newly Created Service* - CATCHME *Newly Created Service* - COMHOST . Contents of the ‘Scheduled Tasks’ folder “2007-11-16 00:05:00 C:\Windows\Tasks\User_Feed_Synchronization-{5C661786-3E98-4788-A29A-45E1A7337F16}.job” - C:\Windows\system32\msfeedssync.exe . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-16 01:04:42 Windows 6.0.6000 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-16 1:05:49 . — E O F —