ComboFix 07-12-02.5 - admin Shaddow 2007-12-02 12:01:43.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.0.1250.1.1045.18.84 [GMT 1:00] Running from: D:\Documents and Settings\admin Shaddow\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDQN8X2B\ComboFix[1].exe * Created a new restore point . /wow section - STAGE 3 ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . D:\WINDOWS\system32\a.exe . ((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 ))))))))))))))))))))))))))))))) . 2007-12-02 11:10 . 2007-12-02 11:10 2007-12-01 19:47 . 2007-12-01 19:47 2007-11-28 20:14 . 2007-11-28 20:33 2007-11-28 17:25 . 2007-11-28 17:25 2007-11-24 15:54 . 2004-12-07 09:11 258,352 --a------ D:\WINDOWS\system32\unicows.dll 2007-11-24 15:54 . 2006-01-30 11:32 5,632 --a------ D:\WINDOWS\system32\pxc25pm.dll 2007-11-24 15:53 . 2007-11-24 15:55 2007-11-23 23:35 . 2007-11-23 23:35 2007-11-23 23:29 . 2004-07-09 04:26 1,230,336 --a------ D:\WINDOWS\system32\msvidctl.dll 2007-11-23 23:28 . 2003-05-30 09:00 1,962,496 --a------ D:\WINDOWS\system32\quartz.dll 2007-11-23 22:27 . 2007-11-23 22:27 2007-11-23 21:44 . 2007-11-23 21:44 2007-11-23 20:45 . 2007-11-23 20:50 2007-11-20 20:30 . 2007-11-20 20:30 2007-11-20 20:30 . 2007-11-20 20:30 264,097 --a------ D:\WINDOWS\PDFCreator_Toolbar_Uninstaller_8218.exe 2007-11-20 20:29 . 2007-11-20 20:31 2007-11-20 20:29 . 2001-10-28 17:42 116,224 --a------ D:\WINDOWS\system32\pdfcmnnt.dll 2007-11-20 20:29 . 1998-07-06 01:00 23,552 --a------ D:\WINDOWS\system32\MSMPIDE.DLL 2007-11-19 18:21 . 2007-11-19 18:21 2007-11-19 18:21 . 2007-11-19 18:21 24 --a------ D:\WINDOWS\Wilga-PSJP.INI 2007-11-10 07:59 . 2007-11-10 07:59 685,816 --a------ D:\WINDOWS\system32\drivers\sptd.sys 2007-11-07 20:25 . 2007-11-07 20:25 2007-11-07 18:06 . 2001-10-26 17:29 146,944 --a------ D:\WINDOWS\system32\ptpusd.dll 2007-11-07 18:06 . 2001-10-26 17:29 5,632 --a------ D:\WINDOWS\system32\ptpusb.dll 2007-11-07 17:57 . 2007-11-07 17:57 2007-11-07 17:57 . 2007-11-07 17:58 2007-11-06 08:59 . 2007-11-06 08:59 197 --a------ D:\WINDOWS\system32\MRT.INI 2007-11-06 08:52 . 2002-11-14 20:44 219,648 --a------ D:\WINDOWS\system32\srrstr.dll 2007-11-06 08:52 . 2002-11-14 20:44 219,648 --a–c— D:\WINDOWS\system32\dllcache\srrstr.dll 2007-11-06 08:37 . 2007-11-06 08:37 2007-11-06 08:36 . 2004-07-01 23:10 360,448 --a–c— D:\WINDOWS\system32\dllcache\qmgr.dll 2007-11-06 08:36 . 2004-07-01 23:10 331,776 --a------ D:\WINDOWS\system32\winhttp.dll 2007-11-06 08:36 . 2004-07-01 23:10 17,408 --a------ D:\WINDOWS\system32\qmgrprxy.dll 2007-11-06 08:36 . 2004-07-01 23:10 17,408 --a–c— D:\WINDOWS\system32\dllcache\qmgrprxy.dll 2007-11-06 08:36 . 2004-07-01 23:10 7,680 -----c— D:\WINDOWS\system32\dllcache\bitsprx2.dll 2007-11-06 08:36 . 2004-07-01 23:10 7,680 --------- D:\WINDOWS\system32\bitsprx2.dll 2007-11-06 08:36 . 2004-07-01 23:10 7,168 -----c— D:\WINDOWS\system32\dllcache\bitsprx3.dll 2007-11-06 08:36 . 2004-07-01 23:10 7,168 --------- D:\WINDOWS\system32\bitsprx3.dll 2007-11-06 08:34 . 2007-07-30 19:19 549,720 --a------ D:\WINDOWS\system32\wuapi.dll 2007-11-06 08:34 . 2007-07-30 19:19 325,976 --a------ D:\WINDOWS\system32\wucltui.dll 2007-11-06 08:34 . 2007-07-30 19:19 216,408 --a------ D:\WINDOWS\system32\wuaucpl.cpl 2007-11-06 08:34 . 2007-07-30 19:19 43,352 --a------ D:\WINDOWS\system32\wups2.dll 2007-11-06 08:34 . 2007-07-30 19:19 38,232 --a------ D:\WINDOWS\system32\wucltui.dll.mui 2007-11-06 08:34 . 2007-07-30 19:18 33,624 --a------ D:\WINDOWS\system32\wups.dll 2007-11-06 08:34 . 2007-07-30 19:20 30,040 --a------ D:\WINDOWS\system32\wuaucpl.cpl.mui 2007-11-06 08:34 . 2007-07-30 19:20 30,040 --a------ D:\WINDOWS\system32\wuapi.dll.mui 2007-11-06 08:34 . 2007-07-30 19:18 21,336 --a------ D:\WINDOWS\system32\wuaueng.dll.mui 2007-11-05 19:40 . 2007-11-05 19:40 2007-11-04 19:17 . 2007-11-04 19:17 2007-11-04 18:57 . 2007-11-04 18:57 2007-11-03 15:58 . 2007-11-03 15:58 51,204 —hs---- D:\WINDOWS\system32\mdm.exe 2007-11-03 15:38 . 2007-11-03 15:38 38,649 --a------ D:\WINDOWS\system32\kl.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-02 10:55 --------- d-----w D:\Documents and Settings\admin Shaddow\Dane aplikacji\Skype 2007-12-02 10:54 --------- d-----w D:\Program Files\Neostrada TP 2007-12-02 09:47 --------- d-----w D:\Documents and Settings\admin Shaddow\Dane aplikacji\uTorrent 2007-11-30 11:06 --------- d-----w D:\Program Files\Lx_cats 2007-11-27 15:31 --------- d-----w D:\Documents and Settings\admin Shaddow\Dane aplikacji\LimeWire 2007-11-23 19:50 --------- d–h--w D:\Program Files\InstallShield Installation Information 2007-11-16 08:00 --------- d-----w D:\Program Files\uTorrent 2007-11-14 07:02 --------- d-----w D:\Program Files\Maxthon2 2007-10-28 15:17 --------- d-----w D:\Program Files\QuickTime 2007-10-28 15:16 --------- d-----w D:\Program Files\Apple Software Update 2007-10-28 15:16 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\Apple Computer 2007-10-28 15:16 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\Apple 2007-10-28 11:21 --------- d-----w D:\Program Files\Common Files\InstallShield 2007-10-25 16:05 94,416 ----a-w D:\WINDOWS\system32\drivers\aswmon2.sys 2007-10-25 16:05 93,264 ----a-w D:\WINDOWS\system32\drivers\aswmon.sys 2007-10-25 16:03 23,152 ----a-w D:\WINDOWS\system32\drivers\aswRdr.sys 2007-10-25 16:01 42,912 ----a-w D:\WINDOWS\system32\drivers\aswTdi.sys 2007-10-25 15:58 26,624 ----a-w D:\WINDOWS\system32\drivers\aavmker4.sys 2007-10-25 15:50 --------- d-----w D:\Program Files\Thomson 2007-10-25 15:24 815,480 ----a-w D:\WINDOWS\system32\aswBoot.exe 2007-10-25 15:14 95,608 ----a-w D:\WINDOWS\system32\AvastSS.scr 2007-10-23 07:08 --------- d-----w D:\Program Files\Common Files\Adobe 2007-10-23 06:45 --------- d-----w D:\Program Files\Google 2007-10-22 20:10 --------- d-----w D:\Program Files\Java 2007-10-22 19:57 --------- d-----w D:\Program Files\SubEdit-Player 2007-10-22 17:57 --------- d-----w D:\Program Files\LimeWire 2007-10-22 17:50 --------- d-----w D:\Program Files\Common Files\Java 2007-10-22 17:01 --------- d-----w D:\Program Files\Skype 2007-10-22 17:01 --------- d-----w D:\Program Files\Common Files\Skype 2007-10-22 17:01 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\Skype 2007-10-22 16:32 --------- d-----w D:\Documents and Settings\admin Shaddow\Dane aplikacji\Winamp 2007-10-22 16:27 --------- d-----w D:\Program Files\Winamp 2007-10-22 02:49 867,848 ----a-w D:\Program Files\NOV2007_d3dx10_36_x64.cab 2007-10-22 02:49 807,132 ----a-w D:\Program Files\NOV2007_d3dx10_36_x86.cab 2007-10-22 02:49 49,392 ----a-w D:\Program Files\NOV2007_X3DAudio_x64.cab 2007-10-22 02:49 44,850 ----a-w D:\Program Files\dxdllreg_x86.cab 2007-10-22 02:49 21,744 ----a-w D:\Program Files\NOV2007_X3DAudio_x86.cab 2007-10-22 02:49 200,010 ----a-w D:\Program Files\NOV2007_XACT_x64.cab 2007-10-22 02:49 151,512 ----a-w D:\Program Files\NOV2007_XACT_x86.cab 2007-10-22 02:49 1,805,306 ----a-w D:\Program Files\NOV2007_d3dx9_36_x64.cab 2007-10-22 02:49 1,712,608 ----a-w D:\Program Files\NOV2007_d3dx9_36_x86.cab 2007-10-22 02:39 267,272 ----a-w D:\WINDOWS\system32\xactengine2_10.dll 2007-10-22 02:37 66,056 ----a-w D:\WINDOWS\system32\dxdllreg.exe 2007-10-22 02:37 17,928 ----a-w D:\WINDOWS\system32\X3DAudio1_2.dll 2007-10-22 02:31 976,020 ------w D:\Program Files\BDAXP.cab 2007-10-22 02:31 917,318 ------w D:\Program Files\Apr2006_MDX1_x86.cab 2007-10-22 02:31 88,102 ------w D:\Program Files\AUG2006_xinput_x64.cab 2007-10-22 02:31 87,989 ------w D:\Program Files\Apr2006_xinput_x64.cab 2007-10-22 02:31 86,925 ------w D:\Program Files\Oct2005_xinput_x64.cab 2007-10-22 02:31 86,802 ----a-w D:\Program Files\dxupdate.cab 2007-10-22 02:31 855,886 ------w D:\Program Files\AUG2007_d3dx10_35_x64.cab 2007-10-22 02:31 800,467 ------w D:\Program Files\AUG2007_d3dx10_35_x86.cab 2007-10-22 02:31 76,808 ----a-w D:\Program Files\DSETUP.dll 2007-10-22 02:31 702,644 ------w D:\Program Files\JUN2007_d3dx10_34_x64.cab 2007-10-22 02:31 702,212 ------w D:\Program Files\APR2007_d3dx10_33_x64.cab 2007-10-22 02:31 702,072 ------w D:\Program Files\JUN2007_d3dx10_34_x86.cab 2007-10-22 02:31 699,465 ------w D:\Program Files\APR2007_d3dx10_33_x86.cab 2007-10-22 02:31 56,902 ------w D:\Program Files\APR2007_xinput_x86.cab 2007-10-22 02:31 502,792 ----a-w D:\Program Files\DXSETUP.exe 2007-10-22 02:31 47,018 ------w D:\Program Files\AUG2006_xinput_x86.cab 2007-10-22 02:31 46,898 ------w D:\Program Files\Apr2006_xinput_x86.cab 2007-10-22 02:31 46,247 ------w D:\Program Files\Oct2005_xinput_x86.cab 2007-10-22 02:31 4,163,518 ------w D:\Program Files\Apr2006_MDX1_x86_Archive.cab 2007-10-22 02:31 213,767 ------w D:\Program Files\DEC2006_d3dx10_00_x64.cab 2007-10-22 02:31 201,696 ------w D:\Program Files\AUG2007_XACT_x64.cab 2007-10-22 02:31 200,722 ------w D:\Program Files\JUN2007_XACT_x64.cab 2007-10-22 02:31 199,366 ------w D:\Program Files\APR2007_XACT_x64.cab 2007-10-22 02:31 198,275 ------w D:\Program Files\FEB2007_XACT_x64.cab 2007-10-22 02:31 193,435 ------w D:\Program Files\DEC2006_XACT_x64.cab 2007-10-22 02:31 192,680 ------w D:\Program Files\DEC2006_d3dx10_00_x86.cab 2007-10-22 02:31 183,863 ------w D:\Program Files\AUG2006_XACT_x64.cab 2007-10-22 02:31 183,321 ------w D:\Program Files\OCT2006_XACT_x64.cab 2007-10-22 02:31 181,745 ------w D:\Program Files\JUN2006_XACT_x64.cab 2007-10-22 02:31 180,021 ------w D:\Program Files\Apr2006_XACT_x64.cab 2007-10-22 02:31 179,247 ------w D:\Program Files\Feb2006_XACT_x64.cab 2007-10-22 02:31 156,612 ------w D:\Program Files\AUG2007_XACT_x86.cab 2007-10-22 02:31 156,509 ------w D:\Program Files\JUN2007_XACT_x86.cab 2007-10-22 02:31 154,825 ------w D:\Program Files\APR2007_XACT_x86.cab 2007-10-22 02:31 151,583 ------w D:\Program Files\FEB2007_XACT_x86.cab 2007-10-22 02:31 146,559 ------w D:\Program Files\DEC2006_XACT_x86.cab 2007-10-22 02:31 138,977 ------w D:\Program Files\OCT2006_XACT_x86.cab 2007-10-22 02:31 138,195 ------w D:\Program Files\AUG2006_XACT_x86.cab 2007-10-22 02:31 134,631 ------w D:\Program Files\JUN2006_XACT_x86.cab 2007-10-22 02:31 133,991 ------w D:\Program Files\Apr2006_XACT_x86.cab 2007-10-22 02:31 133,297 ------w D:\Program Files\Feb2006_XACT_x86.cab 2007-10-22 02:31 13,265,040 ------w D:\Program Files\dxnt.cab 2007-10-22 02:31 100,417 ------w D:\Program Files\APR2007_xinput_x64.cab 2007-10-22 02:31 1,803,760 ------w D:\Program Files\AUG2007_d3dx9_35_x64.cab 2007-10-22 02:31 1,711,752 ------w D:\Program Files\AUG2007_d3dx9_35_x86.cab 2007-10-22 02:31 1,673,224 ----a-w D:\Program Files\dsetup32.dll 2007-10-22 02:31 1,611,374 ------w D:\Program Files\JUN2007_d3dx9_34_x64.cab 2007-10-22 02:31 1,610,958 ------w D:\Program Files\APR2007_d3dx9_33_x64.cab 2007-10-22 02:31 1,610,886 ------w D:\Program Files\JUN2007_d3dx9_34_x86.cab 2007-10-22 02:31 1,609,639 ------w D:\Program Files\APR2007_d3dx9_33_x86.cab 2007-10-22 02:31 1,575,336 ------w D:\Program Files\DEC2006_d3dx9_32_x86.cab 2007-10-22 02:31 1,572,114 ------w D:\Program Files\DEC2006_d3dx9_32_x64.cab 2007-10-22 02:31 1,413,862 ------w D:\Program Files\OCT2006_d3dx9_31_x64.cab 2007-10-22 02:31 1,398,718 ------w D:\Program Files\Apr2006_d3dx9_30_x64.cab 2007-10-22 02:31 1,363,684 ------w D:\Program Files\Feb2006_d3dx9_29_x64.cab 2007-10-22 02:31 1,358,864 ------w D:\Program Files\Dec2005_d3dx9_28_x64.cab . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“D:\WINDOWS\System32\ctfmon.exe” [2001-10-30 13:00] “Skype”=“D:\Program Files\Skype\Phone\Skype.exe” [2007-09-13 12:31] “swg”=“D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-11-08 21:42] “DAEMON Tools”=“C:\Program Files\DAEMON Tools\daemon.exe” [2007-08-29 16:09] “AlcoholAutomount”=“D:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe” [2007-07-02 11:22] “Gadu-Gadu”=“D:\Program Files\Gadu-Gadu\gg.exe” [2007-11-14 11:54] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NvCplDaemon”=“RUNDLL32.exe” [2001-10-30 13:00 D:\WINDOWS\system32\rundll32.exe] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“D:\WINDOWS\System32\CTFMON.EXE” [2001-10-30 13:00] “Microsoft Office”=“D:\WINDOWS\System32\mdm.exe” [2007-11-03 15:58] “Microsoft Windows Driver”=“D:\WINDOWS\rundll32.exe” [] R1 fwdrv;Firewall Driver;D:\WINDOWS\System32\drivers\fwdrv.sys R1 khips;Kerio HIPS Driver;D:\WINDOWS\System32\drivers\khips.sys R2 SPF4;Sunbelt Personal Firewall 4;“D:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe” *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . Contents of the ‘Scheduled Tasks’ folder “2007-10-28 15:16:17 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job” - D:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-02 12:05:14 Windows 5.1.2600 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-02 12:06:37 . — E O F —