ComboFix 07-11-08.1 - slimak 2007-11-16 16:35:11.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.461 [GMT 1:00] Running from: W:\PROGRAMY\skan i log startujacych programow\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-10-16 to 2007-11-16 ))))))))))))))))))))))))))))))) . 2007-11-16 16:34 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-11-16 16:11 90,112 --a------ C:\WINDOWS\system32\RegDACL.exe 2007-11-16 16:11 53,248 --a------ C:\WINDOWS\system32\process.exe 2007-11-16 16:11 8,925 --a------ C:\clean.bat 2007-11-16 16:11 4,096 --a------ C:\WINDOWS\system32\reboot.exe 2007-11-16 16:11 347 --a------ C:\run2.reg 2007-11-13 20:23 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll 2007-11-13 20:23 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll 2007-11-13 20:23 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll 2007-11-13 20:23 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll 2007-11-13 20:11 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS 2007-11-13 19:55 202,240 -ra------ C:\WINDOWS\system32\fdco1.dll 2007-11-13 19:55 33,664 -ra------ C:\WINDOWS\system32\drivers\NVENETFD.sys 2007-11-13 19:54 283,136 -ra------ C:\WINDOWS\system32\drivers\nvnrm.sys 2007-11-13 19:54 209,920 -ra------ C:\WINDOWS\system32\drivers\nvsnpu.sys 2007-11-13 19:54 180,224 --a------ C:\WINDOWS\system32\nvunrm.exe 2007-11-13 19:54 101,120 -ra------ C:\WINDOWS\system32\drivers\nvtcp.sys 2007-11-13 19:54 33,280 -ra------ C:\WINDOWS\system32\nvconrmins.dll 2007-11-13 19:54 33,280 -ra------ C:\WINDOWS\system32\nvconrm.dll 2007-11-13 19:54 12,928 -ra------ C:\WINDOWS\system32\drivers\nvnetbus.sys 2007-11-13 19:54 9,728 -ra------ C:\WINDOWS\system32\bdco1.dll 2007-11-13 19:45 5,112 --a------ C:\WINDOWS\GPCIDrv.sys 2007-11-13 19:43 2007-11-13 19:43 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe 2007-11-13 19:42 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2007-11-13 19:21 2007-11-13 19:21 664 --a------ C:\WINDOWS\system32\d3d9caps.dat 2007-11-13 19:21 552 --a------ C:\WINDOWS\system32\d3d8caps.dat 2007-11-12 06:51 1,089,536 --a------ C:\WINDOWS\system32\nvcuda.dll 2007-11-12 06:27 2007-11-10 21:09 2007-11-09 23:45 2007-11-09 22:47 2007-11-09 22:47 2007-11-07 17:37 2007-11-04 14:47 2007-11-04 14:47 2007-11-04 14:47 2007-11-04 14:27 2007-11-01 22:10 23,176 -ra------ C:\WINDOWS\system32\drivers\s116nd5.sys 2007-11-01 11:03 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys 2007-11-01 11:03 14,848 --a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys 2007-11-01 11:03 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2007-11-01 11:03 12,160 --a–c— C:\WINDOWS\system32\dllcache\mouhid.sys 2007-11-01 10:54 2007-11-01 10:14 100,488 -ra------ C:\WINDOWS\system32\drivers\s116mgmt.sys 2007-11-01 10:14 99,080 -ra------ C:\WINDOWS\system32\drivers\s116unic.sys 2007-11-01 10:14 98,696 -ra------ C:\WINDOWS\system32\drivers\s116obex.sys 2007-11-01 10:14 11,016 -ra------ C:\WINDOWS\system32\drivers\s116cr.sys 2007-11-01 09:44 2007-11-01 09:42 163,328 -r-hs---- C:\WINDOWS\system32\flvDX.dll 2007-11-01 09:42 31,232 -r-hs---- C:\WINDOWS\system32\msfDX.dll 2007-11-01 08:57 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-11-01 08:57 31,616 --a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys 2007-11-01 08:56 108,680 -ra------ C:\WINDOWS\system32\drivers\s116mdm.sys 2007-11-01 08:56 83,336 -ra------ C:\WINDOWS\system32\drivers\s116bus.sys 2007-11-01 08:56 15,112 -ra------ C:\WINDOWS\system32\drivers\s116mdfl.sys 2007-11-01 08:56 12,424 -ra------ C:\WINDOWS\system32\drivers\s116whnt.sys 2007-11-01 08:56 12,424 -ra------ C:\WINDOWS\system32\drivers\s116wh.sys 2007-11-01 08:56 12,424 -ra------ C:\WINDOWS\system32\drivers\s116cmnt.sys 2007-11-01 08:56 12,424 -ra------ C:\WINDOWS\system32\drivers\s116cm.sys 2007-11-01 08:55 2007-11-01 08:51 2007-11-01 08:50 2007-11-01 08:50 2007-11-01 08:50 2007-11-01 08:49 2007-11-01 08:49 2007-11-01 08:41 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys 2007-11-01 08:41 5,504 --a–c— C:\WINDOWS\system32\dllcache\mstee.sys 2007-11-01 08:40 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys 2007-11-01 08:40 15,360 --a–c— C:\WINDOWS\system32\dllcache\streamip.sys 2007-11-01 08:40 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys 2007-11-01 08:40 10,880 --a–c— C:\WINDOWS\system32\dllcache\ndisip.sys 2007-11-01 08:39 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys 2007-11-01 08:39 85,376 --a–c— C:\WINDOWS\system32\dllcache\nabtsfec.sys 2007-11-01 08:39 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS 2007-11-01 08:39 19,328 --a–c— C:\WINDOWS\system32\dllcache\wstcodec.sys 2007-11-01 08:39 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys 2007-11-01 08:39 17,024 --a–c— C:\WINDOWS\system32\dllcache\ccdecode.sys 2007-11-01 08:39 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys 2007-11-01 08:39 11,136 --a–c— C:\WINDOWS\system32\dllcache\slip.sys 2007-11-01 08:38 54,784 --a------ C:\WINDOWS\system32\drivers\vfwwdm32.dll 2007-10-28 12:39 2007-10-28 11:32 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys 2007-10-28 11:32 38,016 --a–c— C:\WINDOWS\system32\dllcache\bthmodem.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-16 15:37 --------- d-----w C:\Documents and Settings\slimak\Dane aplikacji\uTorrent 2007-11-16 14:46 17,962 ----a-w C:\WINDOWS\system32\drivers\GVTDrv.sys 2007-11-16 09:35 --------- d-----w C:\Program Files\PeerGuardian2 2007-11-13 17:26 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-11-13 15:29 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2007-11-13 15:29 22,328 ----a-w C:\Documents and Settings\slimak\Dane aplikacji\PnkBstrK.sys 2007-11-13 15:28 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2007-11-13 15:28 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2007-11-12 05:51 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll 2007-11-12 05:51 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll 2007-11-12 05:51 8,523,776 ----a-w C:\WINDOWS\system32\nvcpl.dll 2007-11-12 05:51 757,760 ----a-w C:\WINDOWS\system32\nvcplui.exe 2007-11-12 05:51 7,433,504 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys 2007-11-12 05:51 6,901,760 ----a-w C:\WINDOWS\system32\nvoglnt.dll 2007-11-12 05:51 6,537,216 ----a-w C:\WINDOWS\system32\nvdisps.dll 2007-11-12 05:51 5,770,880 ----a-w C:\WINDOWS\system32\nv4_disp.dll 2007-11-12 05:51 5,611,520 ----a-w C:\WINDOWS\system32\nvdispsr.dll 2007-11-12 05:51 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll 2007-11-12 05:51 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll 2007-11-12 05:51 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2007-11-12 05:51 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe 2007-11-12 05:51 425,984 ----a-w C:\WINDOWS\system32\keystone.exe 2007-11-12 05:51 385,024 ----a-w C:\WINDOWS\system32\nvapi.dll 2007-11-12 05:51 35,328 ----a-w C:\WINDOWS\system32\nvcodins.dll 2007-11-12 05:51 35,328 ----a-w C:\WINDOWS\system32\nvcod.dll 2007-11-12 05:51 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll 2007-11-12 05:51 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll 2007-11-12 05:51 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll 2007-11-12 05:51 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll 2007-11-12 05:51 327,680 ----a-w C:\WINDOWS\system32\nvrshe.dll 2007-11-12 05:51 327,680 ----a-w C:\WINDOWS\system32\nvrsar.dll 2007-11-12 05:51 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll 2007-11-12 05:51 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll 2007-11-12 05:51 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll 2007-11-12 05:51 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll 2007-11-12 05:51 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll 2007-11-12 05:51 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll 2007-11-12 05:51 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll 2007-11-12 05:51 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll 2007-11-12 05:51 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll 2007-11-12 05:51 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll 2007-11-12 05:51 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll 2007-11-12 05:51 3,715,072 ----a-w C:\WINDOWS\system32\nvvitvsr.dll 2007-11-12 05:51 3,698,688 ----a-w C:\WINDOWS\system32\nvvitvs.dll 2007-11-12 05:51 3,407,872 ----a-w C:\WINDOWS\system32\nvgames.dll 2007-11-12 05:51 3,330,048 ----a-w C:\WINDOWS\system32\nvgamesr.dll 2007-11-12 05:51 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll 2007-11-12 05:51 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll 2007-11-12 05:51 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll 2007-11-12 05:51 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll 2007-11-12 05:51 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll 2007-11-12 05:51 290,816 ----a-w C:\WINDOWS\system32\nvwrsth.dll 2007-11-12 05:51 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll 2007-11-12 05:51 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll 2007-11-12 05:51 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll 2007-11-12 05:51 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll 2007-11-12 05:51 282,624 ----a-w C:\WINDOWS\system32\nvrsfr.dll 2007-11-12 05:51 282,624 ----a-w C:\WINDOWS\system32\nvrses.dll 2007-11-12 05:51 282,624 ----a-w C:\WINDOWS\system32\nvrsel.dll 2007-11-12 05:51 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll 2007-11-12 05:51 278,528 ----a-w C:\WINDOWS\system32\nvrsit.dll 2007-11-12 05:51 278,528 ----a-w C:\WINDOWS\system32\nvrsde.dll 2007-11-12 05:51 274,432 ----a-w C:\WINDOWS\system32\nvrspt.dll 2007-11-12 05:51 274,432 ----a-w C:\WINDOWS\system32\nvrsnl.dll 2007-11-12 05:51 274,432 ----a-w C:\WINDOWS\system32\nvrsesm.dll 2007-11-12 05:51 270,336 ----a-w C:\WINDOWS\system32\nvrsru.dll 2007-11-12 05:51 266,240 ----a-w C:\WINDOWS\system32\nvrsptb.dll 2007-11-12 05:51 266,240 ----a-w C:\WINDOWS\system32\nvrsja.dll 2007-11-12 05:51 258,048 ----a-w C:\WINDOWS\system32\nvrstr.dll 2007-11-12 05:51 258,048 ----a-w C:\WINDOWS\system32\nvrssl.dll 2007-11-12 05:51 258,048 ----a-w C:\WINDOWS\system32\nvrssk.dll 2007-11-12 05:51 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll 2007-11-12 05:51 258,048 ----a-w C:\WINDOWS\system32\nvrshu.dll 2007-11-12 05:51 253,952 ----a-w C:\WINDOWS\system32\nvrsth.dll 2007-11-12 05:51 253,952 ----a-w C:\WINDOWS\system32\nvrssv.dll 2007-11-12 05:51 253,952 ----a-w C:\WINDOWS\system32\nvrspl.dll 2007-11-12 05:51 253,952 ----a-w C:\WINDOWS\system32\nvrsno.dll 2007-11-12 05:51 253,952 ----a-w C:\WINDOWS\system32\nvrsda.dll 2007-11-12 05:51 249,856 ----a-w C:\WINDOWS\system32\nvrsfi.dll 2007-11-12 05:51 249,856 ----a-w C:\WINDOWS\system32\nvrscs.dll 2007-11-12 05:51 245,760 ----a-w C:\WINDOWS\system32\nvrseng.dll 2007-11-12 05:51 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll 2007-11-12 05:51 225,280 ----a-w C:\WINDOWS\system32\nvrszhc.dll 2007-11-12 05:51 212,992 ----a-w C:\WINDOWS\system32\nvwrsja.dll 2007-11-12 05:51 2,854,912 ----a-w C:\WINDOWS\system32\nvmoblsr.dll 2007-11-12 05:51 2,519,040 ----a-w C:\WINDOWS\system32\nvwssr.dll 2007-11-12 05:51 2,486,272 ----a-w C:\WINDOWS\system32\nvwss.dll 2007-11-12 05:51 196,608 ----a-w C:\WINDOWS\system32\nvwrsko.dll 2007-11-12 05:51 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll 2007-11-12 05:51 167,936 ----a-w C:\WINDOWS\system32\nvwrszht.dll 2007-11-12 05:51 163,840 ----a-w C:\WINDOWS\system32\nvwrszhc.dll 2007-11-12 05:51 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe 2007-11-12 05:51 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe 2007-11-12 05:51 126,976 ----a-w C:\WINDOWS\system32\nvrszht.dll 2007-11-12 05:51 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll 2007-11-12 05:51 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe 2007-11-12 05:51 1,474,560 ----a-w C:\WINDOWS\system32\nview.dll 2007-11-12 05:51 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe 2007-11-12 05:51 1,212,416 ----a-w C:\WINDOWS\system32\nvmobls.dll 2007-11-12 05:51 1,073,152 ----a-w C:\WINDOWS\system32\nvcpluir.dll 2006-05-03 09:06:54 163,328 --sh–r C:\WINDOWS\system32\flvDX.dll 2007-02-21 10:47:16 31,232 --sh–r C:\WINDOWS\system32\msfDX.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [2006-08-02 22:12 C:\WINDOWS\soundman.exe] “VGAUtil”=“C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe” [2007-01-02 09:22] “RemoteControl”=“C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe” [2004-11-02 19:24] “CoolSwitch”=“C:\WINDOWS\system32\taskswitch.exe” [2002-03-19 16:30] “nod32kui”=“C:\Program Files\Eset\nod32kui.exe” [2007-08-25 19:19] “amd_dc_opt”=“C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe” [2006-11-17 15:49] “ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [2006-03-20 16:40] “UnlockerAssistant”=“C:\Program Files\Unlocker\UnlockerAssistant.exe” [2006-09-07 18:19] “Outpost Firewall”=“C:\Program Files\Agnitum\Outpost Firewall\outpost.exe” [2007-04-05 15:56] “OutpostFeedBack”=“C:\Program Files\Agnitum\Outpost Firewall\feedback.exe” [2007-06-28 12:18] “NetTime”=“C:\Program Files\NetTime\NetTime.exe” [2000-12-31 16:12] “ISUSPM”=“C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe” [2006-03-20 16:40] “cFosSpeed”=“D:\CFOSSPEED\cFosSpeed.exe” [2007-07-09 17:10] “BluetoothAuthenticationAgent”=“bthprops.cpl” [2004-08-03 23:44 C:\WINDOWS\system32\bthprops.cpl] “Sony Ericsson PC Suite”=“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2007-06-13 08:16] “QuickTime Task”=“Y:\qUICK TIME PLAYER\QTTask.exe” [2007-06-29 06:24] “NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2007-11-12 06:51] “nwiz”=“nwiz.exe” [2007-11-12 06:51 C:\WINDOWS\system32\nwiz.exe] “NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2007-11-12 06:51] “Anti Trojan Elite”=“Y:\free trojan scan\Anti Trojan Elite\TJEnder.exe” [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “STYLEXP”=“C:\Program Files\TGTSoft\StyleXP\StyleXP.exe” [2005-03-14 20:21] “DAEMON Tools”=“W:\Daemon\DAEMON Tools\daemon.exe” [2006-11-12 11:48] “PeerGuardian”=“C:\Program Files\PeerGuardian2\pg2.exe” [2005-09-18 17:44] “TV Watcher”=“W:\program tv\TV Watcher\TV Watcher.exe” [2007-10-14 16:21] “uTorrent”=“C:\Program Files\uTorrent\uTorrent.exe” [2007-10-19 23:01] “Uniblue Registry Booster2”=“W:\Uniblue\Registry booster\RegistryBooster2\RegistryBooster.exe” [2007-04-23 15:40] “Uniblue SpyEraser”=“D:\SpyEraser\SpyEraser.exe” [2007-05-16 10:45] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce] “NCInstallQueue”=rundll32 netman.dll,ProcessQueue [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoRecentDocsMenu”=1 (0x1) “NoSMConfigurePrograms”=1 (0x1) “ForceClassicControlPanel”=1 (0x1) “NoChangeKeyboardNavigationIndicators”=0 (0x0) “NoSharedDocuments”=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] “UIHost”=“C:\Program Files\TGTSoft\StyleXP\CurrentLogon.EXE” [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “AppInit_DLLs”= SF3.DLL R0 pe3agqwb;Loki Environment Driver (pe3agqwb);C:\WINDOWS\system32\drivers\pe3agqwb.sys R0 ps6agqwb;Loki Synchronization Driver (ps6agqwb);C:\WINDOWS\system32\drivers\ps6agqwb.sys R1 SandBox;Outpost Firewall Sandbox Driver;??\C:\Program Files\Agnitum\Outpost Firewall\kernel\Sandbox.SYS R1 SysTool;SysTool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\SysTool.sys R1 VFILT;Outpost Firewall Kernel Driver;??\C:\Program Files\Agnitum\Outpost Firewall\kernel\FILTNT.SYS R2 NetTimeSvc;NetTime;C:\Program Files\NetTime\NeTmSvNT.exe R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL R3 AmdLLD;AMD Low Level Device Driver;C:\WINDOWS\system32\DRIVERS\AmdLLD.sys R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\ARP.DLL R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\CONTENT.DLL R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL R3 GPCIDrv;GPCIDrv;??\C:\WINDOWS\GPCIDrv.sys R3 GVTDrv;GVTDrv;??\C:\WINDOWS\system32\Drivers\GVTDrv.sys R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\PROTECT.DLL R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);??\C:\Program Files\Agnitum\Outpost Firewall\kernel\SECRET.DLL S2 pr2agqwb;Loki Drivers Auto Removal (pr2agqwb);C:\WINDOWS\system32\pr2agqwb.exe svc S3 ATE_PROCMON;ATE_PROCMON;??\Y:\free trojan scan\Anti Trojan Elite\ATEPMon.sys S3 s116bus;Sony Ericsson Device 116 driver (WDM);C:\WINDOWS\system32\DRIVERS\s116bus.sys S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s116mdfl.sys S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s116mdm.sys S3 s116mgmt;Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s116mgmt.sys S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS);C:\WINDOWS\system32\DRIVERS\s116nd5.sys S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s116obex.sys S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM);C:\WINDOWS\system32\DRIVERS\s116unic.sys S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS *Newly Created Service* - CATCHME . Contents of the ‘Scheduled Tasks’ folder “2007-11-09 15:40:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job” - C:\Program Files\Apple Software Update\SoftwareUpdate.exe “2007-11-15 16:02:05 C:\WINDOWS\Tasks\Uniblue SpyEraser.job” - D:\SpyEraser\SpyEraser.exe . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-16 16:37:31 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-16 16:38:10 . — E O F —