“Jola” - 2007-07-14 16:17:43 - ComboFix 07-07-14.6 - Dodatek Service Pack. 1 NTFS ADS removed - svchost.exe: deleted 68 bytes in 1 streams. (((((((((((((((((((((((((((((((((((((((((((( V Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\lxmslhpw.dll C:\WINDOWS\system32\lxxktnha.dll C:\WINDOWS\system32\ccwmuwut.dll C:\WINDOWS\system32\dockvkwr.dll C:\WINDOWS\system32\vcnxkona.dll C:\WINDOWS\system32\woxehkej.dll C:\WINDOWS\system32\wvnepafo.dll C:\WINDOWS\system32\wphlsmxl.ini C:\WINDOWS\system32\ahntkxxl.ini * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\DOWNLO~1\UERSD_0001_N91M2407NetInstaller.exe C:\WINDOWS\system32\xpdx.sys C:\WINDOWS\wr.txt ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_POOF -------\kprof -------\poof -------\xpdx ((((((((((((((((((((((((( Files Created from 2007-06-14 to 2007-07-14 ))))))))))))))))))))))))))))))) 2007-07-14 16:16 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-14 15:28 2007-07-13 18:37 2007-07-13 17:33 593,408 --a------ C:\WINDOWS\system32\h323msp.dll 2007-07-13 17:33 549,888 --a------ C:\WINDOWS\system32\rtcdll.dll 2007-07-13 17:33 439,296 --a------ C:\WINDOWS\system32\ipnathlp.dll 2007-07-13 17:33 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe 2007-07-13 17:06 2007-07-12 08:37 1,001,472 --a------ C:\WINDOWS\system32\esent.dll 2007-07-12 08:14 2007-07-12 08:13 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-07-12 08:13 2007-07-12 08:13 2007-07-11 22:16 7,680 --------- C:\WINDOWS\system32\bitsprx2.dll 2007-07-11 22:16 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll 2007-07-11 22:16 331,776 --a------ C:\WINDOWS\system32\winhttp.dll 2007-07-11 22:16 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll 2007-07-11 22:09 2007-07-11 22:07 549,720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-11 22:07 33,624 --a------ C:\WINDOWS\system32\wups.dll 2007-07-11 22:07 325,976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-11 22:07 203,096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-11 22:07 187,160 --a------ C:\WINDOWS\system32\wuaueng1.dll 2007-07-11 22:07 170,264 --a------ C:\WINDOWS\system32\wuauclt1.exe 2007-07-11 22:07 2007-07-11 11:01 89,088 --a------ C:\WINDOWS\system32\atl71.dll 2007-07-11 11:01 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll 2007-07-11 10:36 2007-07-11 10:32 2007-07-11 10:30 2007-07-11 09:10 114,816,742 --a------ C:\Program Files\OOo_2.2.1_Win32Intel_install_wJRE_pl.exe 2007-07-10 22:22 2007-07-10 22:07 2007-07-10 22:07 2007-07-10 21:31 2007-07-10 20:38 70,144 --a------ C:\WINDOWS\system32\usbui.dll 2007-07-10 20:38 51,968 --a------ C:\WINDOWS\system32\drivers\usbhub.sys 2007-07-10 20:38 5,120 --a------ C:\WINDOWS\system32\hccoin.dll 2007-07-10 20:38 19,328 --a------ C:\WINDOWS\system32\drivers\usbehci.sys 2007-07-10 20:38 135,552 --a------ C:\WINDOWS\system32\drivers\usbport.sys 2007-07-10 20:37 917,504 -ra------ C:\WINDOWS\system\cmids3d.dll 2007-07-10 20:37 81,920 -ra------ C:\WINDOWS\system32\cmuda.dll 2007-07-10 20:37 77,440 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys 2007-07-10 20:37 743,887 -ra------ C:\WINDOWS\system32\drivers\cmuda.sys 2007-07-10 20:37 712,704 -ra------ C:\WINDOWS\system32\Audio3D.dll 2007-07-10 20:37 712,704 -ra------ C:\WINDOWS\system32\a3d.dll 2007-07-10 20:37 57,856 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-07-10 20:37 56,832 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys 2007-07-10 20:37 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys 2007-07-10 20:37 50,048 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-07-10 20:37 5,888 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-07-10 20:37 32,768 -ra------ C:\WINDOWS\system32\udaprop.dll 2007-07-10 20:37 28,672 -ra------ C:\WINDOWS\system32\cmirmdrv.dll 2007-07-10 20:37 221,184 -ra------ C:\WINDOWS\system32\cmirmdrv.exe 2007-07-10 20:37 2,816 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys 2007-07-10 20:37 159,360 --a------ C:\WINDOWS\system32\drivers\kmixer.sys 2007-07-10 20:37 142,208 --a------ C:\WINDOWS\system32\drivers\aec.sys 2007-07-10 20:37 134,272 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-07-10 20:37 1,900,544 -ra------ C:\WINDOWS\system32\cmiwcnfg.dll 2007-07-10 20:32 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS 2007-07-10 20:25 12,024,151 --------- C:\AVG7QT.DAT 2007-07-10 20:24 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll 2007-07-10 20:24 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll 2007-07-10 20:16 2007-07-10 18:58 473,088 --a------ C:\WINDOWS\ina32.exe 2007-07-10 18:58 409,600 --a------ C:\WINDOWS\WWPST34I.DLL 2007-07-10 18:58 339,640 --a------ C:\WINDOWS\WBDCG34I.DLL 2007-07-10 18:46 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys 2007-07-10 18:46 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys 2007-07-10 18:46 2007-07-10 10:45 2007-07-10 10:44 503,808 --a------ C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-07-10 10:44 2007-07-10 10:44 2007-07-10 10:44 2007-07-10 10:44 2007-07-10 10:44 2007-07-10 10:44 2007-07-10 10:44 2007-07-08 21:13 4,095 --a------ C:\WINDOWS\b122.exe.bin 2007-07-08 21:08 31,254 --a------ C:\WINDOWS\system32\cbxwurp.dll.vir 2007-07-08 20:01 4,789,792 --a------ C:\Program Files\picasa2-current.exe 2007-07-08 20:01 2007-07-08 19:41 2007-07-08 19:40 2007-07-08 19:38 2007-07-08 19:38 2007-07-08 19:37 2007-07-08 19:36 545 --a------ C:\WINDOWS\UC.PIF 2007-07-08 19:36 545 --a------ C:\WINDOWS\RAR.PIF 2007-07-08 19:36 545 --a------ C:\WINDOWS\PKZIP.PIF 2007-07-08 19:36 545 --a------ C:\WINDOWS\PKUNZIP.PIF 2007-07-08 19:36 545 --a------ C:\WINDOWS\NOCLOSE.PIF 2007-07-08 19:36 545 --a------ C:\WINDOWS\LHA.PIF 2007-07-08 19:36 545 --a------ C:\WINDOWS\ARJ.PIF 2007-07-08 19:36 2007-07-08 19:34 229,057 --a------ C:\WINDOWS\Alcohol_Toolbar_Uninstaller_9578.exe 2007-07-08 19:34 2007-07-08 19:33 2007-07-08 19:31 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-10 20:21:46 49,492 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-07-10 20:21:46 355,486 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-07-08 11:35:52 -------- d-----w C:\Program Files\Usługi online 2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2001-03-02 12:02 37808 --------- C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [HKEY_LOCAL_MACHINE~\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] 2007-07-11 10:31 501384 --a------ C:\Program Files\Java\jre1.6.0\bin\ssv.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489}] 2007-07-08 19:34 798720 --a------ C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{FCEDC6E1-774A-4ABE-869F-333FDC9BE8A8}] C:\WINDOWS\System32\pmnll.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “DeviceDiscovery”=“C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe” [2002-12-02 20:56] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2003-09-12 21:10] “Picasa Media Detector”=“C:\Program Files\Picasa2\PicasaMediaDetector.exe” [2007-06-16 01:15] “AVG7_CC”=“C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe” [2007-07-11 09:33] “Cmaudio”=“cmicnfg.cpl” [] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0\bin\jusched.exe” [2007-07-11 10:31] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\System32\ctfmon.exe” [2002-09-20 18:05] “Odkurzacz-MCD”=“C:\Program Files\Odkurzacz\odk_mcd.exe” [2007-03-02 22:38] “Komunikator”=“C:\Program Files\Tlen.pl\tlen.exe” [2006-04-13 14:51] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoRecentDocsMenu”=1 (0x1) “NoFavoritesMenu”=0 (0x0) “NoSMMyDocs”=0 (0x0) “NoSMMyPictures”=0 (0x0) “NoStartMenuMyMusic”=0 (0x0) “NoRecentDocsHistory”=1 (0x1) “NoRecentDocsNetHood”=0 (0x0) “NoSMHelp”=0 (0x0) “NoRun”=0 (0x0) “NoInstrumentation”=0 (0x0) “NoSimpleStartMenu”=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoWindowsUpdate”=0 (0x0) “NoRecentDocsMenu”=1 (0x1) “NoFavoritesMenu”=0 (0x0) “NoSMMyDocs”=0 (0x0) “NoSMMyPictures”=0 (0x0) “NoStartMenuMyMusic”=0 (0x0) “NoRecentDocsHistory”=1 (0x1) “ClearRecentDocsOnExit”=1 (0x1) “NoRecentDocsNetHood”=0 (0x0) “NoSMHelp”=0 (0x0) “NoUserNameInStartMenu”=1 (0x1) “NoInstrumentation”=0 (0x0) “NoStartMenuPinnedList”=0 (0x0) “ForceStartMenuLogoff”=0 (0x0) “NoSharedDocuments”=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wintfj32] wintfj32.dll ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-14 16:20:25 Windows 5.1.2600 Dodatek Service Pack. 1 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … ************************************************************************** Completion time: 2007-07-14 16:22:08 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-07-14 16:21 — E O F —