ComboFix 08-07-01.3 - Home 2008-07-02 18:19:51.1 - NTFSx86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.837 [GMT 2:00] Running from: C:\Documents and Settings\Home\Pulpit\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\drivers\ETNADiag.exe . ((((((((((((((((((((((((( Files Created from 2008-06-02 to 2008-07-02 ))))))))))))))))))))))))))))))) . 2008-06-26 12:43 . 2008-06-26 12:43 2008-06-22 16:17 . 2008-06-22 16:17 2008-06-21 22:34 . 2008-06-21 22:34 2008-06-21 22:25 . 2008-06-21 22:25 2008-06-21 22:25 . 2008-06-21 22:29 2008-06-21 20:03 . 2008-06-21 20:03 2008-06-21 20:02 . 2008-06-21 20:24 2008-06-21 20:01 . 2008-06-21 20:02 270 --a------ C:\WINDOWS{6ECB6EE7-DF64-4F26-9273-9525FC11A417}_WiseFW.ini 2008-06-21 19:57 . 2008-06-21 19:57 2008-06-19 20:28 . 2008-06-19 20:28 2008-06-19 20:19 . 2004-08-03 23:08 26,496 --a–c— C:\WINDOWS\system32\dllcache\usbstor.sys 2008-06-19 17:15 . 2008-06-19 17:15 2008-06-19 17:04 . 2008-04-23 09:20 6,066,176 -----c— C:\WINDOWS\system32\dllcache\ieframe.dll 2008-06-19 17:04 . 2007-04-17 11:32 2,455,488 -----c— C:\WINDOWS\system32\dllcache\ieapfltr.dat 2008-06-19 17:04 . 2007-03-08 07:11 1,036,288 -----c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui 2008-06-19 17:04 . 2008-04-23 09:20 459,264 -----c— C:\WINDOWS\system32\dllcache\msfeeds.dll 2008-06-19 17:04 . 2008-04-23 09:20 383,488 -----c— C:\WINDOWS\system32\dllcache\ieapfltr.dll 2008-06-19 17:04 . 2008-04-23 09:20 267,776 -----c— C:\WINDOWS\system32\dllcache\iertutil.dll 2008-06-19 17:04 . 2008-04-23 09:20 63,488 -----c— C:\WINDOWS\system32\dllcache\icardie.dll 2008-06-19 17:04 . 2008-04-23 09:20 52,224 -----c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2008-06-19 17:04 . 2008-04-22 09:39 13,824 -----c— C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-06-19 14:49 . 2008-06-19 14:49 2008-06-19 14:49 . 2008-06-19 14:49 2008-06-19 14:30 . 2008-06-19 17:41 2008-06-19 14:24 . 2008-06-19 14:24 2008-06-19 14:24 . 2008-06-19 14:24 2008-06-19 14:20 . 2004-08-04 12:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2008-06-19 14:15 . 2008-06-19 14:16 2008-06-19 14:15 . 2008-06-19 14:15 2008-06-19 14:15 . 2008-06-19 14:16 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-06-19 14:15 . 2008-06-19 14:16 1,409 --a------ C:\WINDOWS\QTFont.for 2008-06-19 14:14 . 2008-06-19 14:14 2008-06-19 12:38 . 2008-06-14 20:01 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-19 12:38 . 2008-06-14 20:01 273,024 -----c— C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-19 12:12 . 2006-09-25 17:58 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe 2008-06-18 17:39 . 2004-09-13 08:17 2,146,304 --------- C:\WINDOWS\UNNMP.exe 2008-06-18 17:39 . 2004-10-15 12:02 52,536 --------- C:\WINDOWS\UNNMP.cfg 2008-06-18 17:37 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2008-06-18 17:36 . 2004-10-14 10:19 2,285,568 --------- C:\WINDOWS\UNNeroVision.exe 2008-06-18 17:36 . 2004-10-15 12:02 97,294 --------- C:\WINDOWS\UNNeroVision.cfg 2008-06-18 17:36 . 2001-03-08 19:30 24,064 --------- C:\WINDOWS\system32\msxml3a.dll 2008-06-18 17:35 . 2008-06-18 17:36 2008-06-18 17:35 . 2008-06-18 17:39 2008-06-18 17:35 . 2008-06-18 17:35 2008-06-18 17:35 . 2004-07-20 17:24 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2008-06-18 17:35 . 2004-07-20 17:24 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2008-06-18 17:35 . 2004-07-20 17:24 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2008-06-18 17:35 . 2004-07-09 09:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2008-06-18 17:35 . 2004-07-20 17:24 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2008-06-18 17:35 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2008-06-18 17:35 . 2001-06-26 08:15 38,912 --------- C:\WINDOWS\system32\picn20.dll 2008-06-18 17:28 . 2008-06-18 17:28 2008-06-18 17:21 . 2008-07-02 11:19 2008-06-18 17:20 . 2008-06-18 17:21 2008-06-18 17:13 . 2008-06-19 14:24 2008-06-18 16:57 . 2008-06-18 16:57 2008-06-18 16:57 . 2008-06-18 16:57 2008-06-18 16:57 . 2007-01-16 13:52 20,608 --a------ C:\WINDOWS\system32\drivers\BRGSp50.sys 2008-06-18 16:57 . 2007-01-16 13:52 17,664 --a------ C:\WINDOWS\system32\drivers\ZDPSp50.sys 2008-06-18 16:55 . 2005-06-17 10:26 114,688 --a------ C:\WINDOWS\system32\WLANUTL.dll 2008-06-18 16:55 . 2005-06-17 10:26 61,440 --a------ C:\WINDOWS\system32\W32N50.dll 2008-06-18 16:32 . 2007-01-10 10:14 450,560 --a------ C:\WINDOWS\system32\drivers\WlanBZXP.sys 2008-06-18 15:53 . 2008-06-18 15:53 2008-06-17 22:08 . 2008-06-17 22:08 2008-06-17 21:31 . 2008-06-17 21:31 2008-06-17 21:29 . 2008-06-17 21:29 2008-06-17 21:28 . 2008-06-17 21:28 2008-06-17 21:28 . 2008-01-09 12:26 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll 2008-06-17 21:28 . 2008-01-09 12:27 170,512 --a------ C:\WINDOWS\system32\kemutb.dll 2008-06-17 21:28 . 2008-01-09 12:28 141,840 --a------ C:\WINDOWS\system32\KemUtil.dll 2008-06-17 21:28 . 2008-01-09 12:28 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll 2008-06-17 21:28 . 2008-01-09 12:28 76,304 --a------ C:\WINDOWS\system32\KemXML.dll 2008-06-17 21:27 . 2008-06-17 21:27 2008-06-17 21:27 . 2008-06-17 21:28 2008-06-17 21:27 . 2008-06-17 21:27 2008-06-17 21:24 . 2008-07-02 17:57 2008-06-17 21:23 . 2008-06-17 21:23 2008-06-17 21:22 . 2008-06-17 21:22 2008-06-17 21:22 . 2008-06-17 21:22 2008-06-17 21:22 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-06-17 21:20 . 2008-06-17 21:25 2008-06-17 21:19 . 2008-06-17 21:44 2008-06-17 21:12 . 2008-06-17 21:12 2008-06-17 20:57 . 2007-03-16 18:10 1,060,864 --a------ C:\WINDOWS\system32\MFC71.DLL 2008-06-17 20:57 . 2007-03-16 18:10 770,048 --a------ C:\WINDOWS\system32\BCMLogon.dll 2008-06-17 20:57 . 2007-03-16 18:10 499,712 --a------ C:\WINDOWS\system32\MSVCP71.DLL 2008-06-17 20:57 . 2007-03-16 18:10 348,160 --a------ C:\WINDOWS\system32\MSVCR71.DLL 2008-06-17 20:57 . 2007-03-16 18:10 89,088 --a------ C:\WINDOWS\system32\ATL71.DLL 2008-06-17 20:57 . 2007-03-16 18:10 86,016 --a------ C:\WINDOWS\system32\preflib.dll 2008-06-17 20:57 . 2007-03-16 18:10 33,664 --a------ C:\WINDOWS\system32\drivers\BCMWLNPF.SYS 2008-06-17 20:56 . 2007-03-16 18:10 3,395,584 --a------ C:\WINDOWS\system32\BCMWLCPL.CPL 2008-06-17 20:56 . 2007-03-16 18:10 2,129,920 --a------ C:\WINDOWS\system32\WLBCGCBPRO731.DLL 2008-06-17 20:56 . 2007-03-16 18:10 1,392,640 --a------ C:\WINDOWS\system32\WLTRAY.EXE 2008-06-17 20:56 . 2007-03-16 18:10 1,253,376 --a------ C:\WINDOWS\system32\BCMWLTRY.EXE 2008-06-17 20:56 . 2007-03-16 18:10 757,760 --a------ C:\WINDOWS\system32\bcm1xsup.dll 2008-06-17 20:56 . 2007-03-16 18:10 253,952 --a------ C:\WINDOWS\system32\bcmwlu00.exe 2008-06-17 20:56 . 2007-03-16 18:10 69,632 --a------ C:\WINDOWS\system32\bcmwlpkt.dll 2008-06-17 20:56 . 2007-03-16 18:10 44,032 --a------ C:\WINDOWS\system32\wltrynt.dll 2008-06-17 20:56 . 2007-03-16 18:10 20,480 --a------ C:\WINDOWS\system32\WLTRYSVC.EXE 2008-06-17 20:55 . 2008-06-17 20:56 2008-06-17 20:54 . 2008-06-17 20:54 2008-06-17 20:54 . 2005-08-12 17:50 16,128 --a------ C:\WINDOWS\system32\drivers\APPDRV.SYS 2008-06-17 20:51 . 2007-03-30 19:58 172,032 --a------ C:\WINDOWS\system32\igfxres.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-21 18:07 6,144 ----a-w C:\WINDOWS\system32\mksidsa.sys 2008-06-21 18:07 15,360 ----a-w C:\WINDOWS\system32\mksfwallt.sys 2008-06-21 18:07 11,776 ----a-w C:\WINDOWS\system32\mksidsf.sys 2008-06-21 18:06 13,312 ----a-w C:\WINDOWS\system32\mksfwallf.sys 2008-06-18 14:57 --------- d–h--w C:\Program Files\InstallShield Installation Information 2008-06-17 19:07 --------- d-----w C:\Program Files\Broadcom 2008-06-17 16:36 319,488 ----a-w C:\WINDOWS\system32\AegisI5Installer.exe 2008-06-17 16:36 21,425 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-17 16:36 --------- d-----w C:\Documents and Settings\NetworkService\Dane aplikacji\Intel 2008-06-17 16:36 --------- d-----w C:\Documents and Settings\Home\Dane aplikacji\Intel 2008-06-17 16:36 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Intel 2008-06-17 16:35 --------- d-----w C:\Program Files\Intel 2008-06-17 16:16 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Dane aplikacji\Intel 2008-06-17 16:10 --------- d-----w C:\Program Files\WIDCOMM 2008-06-17 15:52 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-06-17 15:51 --------- d-----w C:\Program Files\DIFX 2008-06-17 15:48 --------- d-----w C:\Program Files\CONEXANT 2008-06-17 15:46 --------- d-----w C:\Program Files\SigmaTel 2008-06-17 15:06 --------- d-----w C:\Program Files\microsoft frontpage 2008-06-17 15:04 --------- d-----w C:\Program Files\Usługi online 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll 2008-04-23 07:20 826,368 ----a-w C:\WINDOWS\system32\wininet.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 12:00 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “IntelZeroConfig”=“C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe” [2006-10-18 18:04 802816] “IntelWireless”=“C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” [2006-10-18 17:58 696320] “IgfxTray”=“C:\WINDOWS\system32\igfxtray.exe” [2007-03-30 20:00 138008] “HotKeysCmds”=“C:\WINDOWS\system32\hkcmd.exe” [2007-03-30 20:00 162584] “Persistence”=“C:\WINDOWS\system32\igfxpers.exe” [2007-03-30 19:59 138008] “Dell QuickSet”=“C:\Program Files\Dell\QuickSet\quickset.exe” [2007-05-14 14:23 1191936] “Broadcom Wireless Manager UI”=“C:\WINDOWS\system32\WLTRAY.exe” [2007-03-16 18:10 1392640] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe” [2008-02-22 04:25 144784] “Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 22:16 39792] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50 155648] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2008-06-19 14:15 155648] “TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2008-06-19 14:24 185896] “mkstray”=“C:\Program Files\mks_vir_2007\bin\mkstray.exe” [2008-06-21 20:08 663552] “mks_mail”=“C:\Program Files\mks_vir_2007\bin\mks_mail.exe” [2008-06-21 20:07 520192] “MKSRegmon”=“C:\Program Files\mks_vir_2007\bin\mksregmon.exe” [2008-06-21 20:07 303104] “SigmatelSysTrayApp”=“stsystra.exe” [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 12:00 15360] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 18:28:28 622653] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-06-17 21:28:01 789008] Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk - C:\Program Files\SAGEM WiFi manager\WLANUTL.exe [2008-06-18 16:57:39 950272] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-01-09 12:30 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MkS_Scan] @=“service” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center] “AntiVirusOverride”=dword:00000001 [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\system32\sessmgr.exe”= “C:\Program Files\IEPro\MiniDM.exe”= “%windir%\Network Diagnostic\xpnetdiag.exe”= S2 MksFwall;MksFwall;“C:\Program Files\mks_vir_2007\bin\MksFwall.exe” [2008-06-21 20:06] S2 MksPC;MksPC;“C:\Program Files\mks_vir_2007\bin\MksPC.exe” [2008-06-21 20:07] S2 MksUpdate;MksUpdate;“C:\Program Files\mks_vir_2007\bin\mksupdate.exe” [2008-06-21 20:04] S3 mksidsf;mksidsf;C:\WINDOWS\system32\mksidsf.sys [2008-06-21 20:07] S3 MksMonEn;MksMonEn;C:\Program Files\mks_vir_2007\bin\MksMonEn.sys [2008-06-21 20:07] S3 MksMonEv;MksMonEv;C:\Program Files\mks_vir_2007\bin\MksMonEv.sys [2008-06-21 20:07] S3 MksMonFd;MksMonFd;C:\Program Files\mks_vir_2007\bin\MksMonFd.sys [2006-10-27 18:03] S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2007-01-10 10:14] S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08] S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS [] S4 mksfwallf;mksfwallf;C:\WINDOWS\system32\mksfwallf.sys [2008-06-21 20:06] S4 mksfwallt;mksfwallt;C:\WINDOWS\system32\mksfwallt.sys [2008-06-21 20:07] S4 mksidsa;mksidsa;C:\WINDOWS\system32\mksidsa.sys [2008-06-21 20:07] *Newly Created Service* - CATCHME *Newly Created Service* - PARPORT . - - - - ORPHANS REMOVED - - - - HKLM-Run-MKS_MENU - C:\Program Files\MKS\Bin\mks_menu.exe ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-02 18:22:04 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-07-02 18:23:07 ComboFix-quarantined-files.txt 2008-07-02 16:22:59 Pre-Run: 23,071,821,824 bajtów wolnych Post-Run: 23,081,316,352 bajtów wolnych 216 — E O F — 2008-06-22 13:13:28