“Szymo” - 2007-07-18 11:09:34 - ComboFix 07-07-14.6 - Dodatek Service Pack 2 NTFS [sAFE MODE] ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\drivers\runtime2.sys ((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 ))))))))))))))))))))))))))))))) 2007-07-18 10:43 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-16 13:49 2007-07-16 13:49 2007-07-16 13:49 2007-07-16 13:49 2007-07-15 09:34 2007-07-15 09:24 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-07-15 09:24 2007-07-15 09:24 2007-07-15 09:24 2007-07-14 12:11 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-07-14 11:29 2007-07-14 11:14 2007-07-13 22:49 58,737 --a------ C:\WINDOWS\system32\sysdrv1.exe 2007-07-13 22:49 23,026 --a------ C:\WINDOWS\system32\sysdrv8.exe 2007-07-12 17:05 2007-07-12 17:05 2007-07-12 17:04 2007-07-12 17:04 2007-07-12 17:01 8,704 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys 2007-07-12 17:01 4,608 --a------ C:\WINDOWS\system32\nmwcdlog.dll 2007-07-12 17:01 30,720 --a------ C:\WINDOWS\system32\nmwcdcocls.dll 2007-07-12 17:01 13,312 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys 2007-07-12 17:01 13,312 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys 2007-07-12 17:01 127,488 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys 2007-07-12 17:01 2007-07-12 17:01 2007-07-12 17:01 2007-07-12 17:00 50,688 --a------ C:\WINDOWS\system32\nmwcdcls.dll 2007-07-12 17:00 2007-07-12 17:00 2007-07-12 17:00 2007-07-12 17:00 2007-07-12 17:00 2007-07-11 23:02 2007-07-10 09:09 2007-07-09 14:55 2007-07-06 17:35 4 --a------ C:\WINDOWS\system32\proc20744962.bin 2007-07-06 17:35 2007-07-05 16:15 2007-07-05 16:14 49,152 --a------ C:\WINDOWS\system32\ctpde.dll 2007-07-05 16:14 385,109 --a------ C:\WINDOWS\system32\ctjb2sp.dll 2007-07-05 16:14 32,768 --a------ C:\WINDOWS\system32\PdePgHlp.dll 2007-07-05 16:14 28,672 --a------ C:\WINDOWS\system32\PdeSrvps.dll 2007-07-05 16:14 28,672 --a------ C:\WINDOWS\system32\Jb4Inst.dll 2007-07-05 16:14 229,376 --a------ C:\WINDOWS\system32\CTPmsMan.dll 2007-07-05 16:14 200,704 --a------ C:\WINDOWS\system32\CTPdeSrv.exe 2007-07-05 16:14 16,880 --a------ C:\WINDOWS\system32\drivers\ctpdusb.sys 2007-07-05 16:14 149,504 --a------ C:\WINDOWS\UNWISE.EXE 2007-07-05 16:14 143,360 --a------ C:\WINDOWS\system32\CTPmsWma.dll 2007-07-04 13:45 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2007-07-04 13:45 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2007-07-04 13:45 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-07-03 03:00 2007-07-02 17:29 2007-06-30 10:24 2007-06-30 10:07 2007-06-30 10:02 2007-06-30 10:02 2007-06-30 10:02 2007-06-30 10:00 2007-06-30 10:00 2007-06-30 09:53 2007-06-30 09:49 5,248 --a------ C:\WINDOWS\system32\drivers\Vax347s.sys 2007-06-30 09:49 159,616 --a------ C:\WINDOWS\system32\drivers\Vax347b.sys 2007-06-30 09:46 2007-06-30 09:28 2007-06-30 09:19 77,824 -ra------ C:\WINDOWS\system32\drivers\SioUi2k.dll 2007-06-30 09:19 63,488 -ra------ C:\WINDOWS\system32\drivers\wssbtr1f.sys 2007-06-30 09:19 54,784 --a------ C:\WINDOWS\system32\drivers\vfwwdm32.dll 2007-06-30 09:19 51,169 -ra------ C:\WINDOWS\system32\drivers\OXSER.SYS 2007-06-30 09:19 48,556 -ra------ C:\WINDOWS\system32\drivers\SktBt2k.sys 2007-06-30 09:19 48,076 -ra------ C:\WINDOWS\system32\drivers\Sio9502k.sys 2007-06-30 09:19 40,960 -ra------ C:\WINDOWS\system32\drivers\SCTray.exe 2007-06-30 09:19 2007-06-30 09:18 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys 2007-06-30 09:18 82,148 --a------ C:\WINDOWS\system32\drivers\VcommMgr.sys 2007-06-30 09:18 7,680 --a------ C:\WINDOWS\system32\btinstall.dll 2007-06-30 09:18 61,312 --a------ C:\WINDOWS\system32\drivers\VComm.sys 2007-06-30 09:18 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys 2007-06-30 09:18 49,152 --a------ C:\WINDOWS\system32\btfunc.dll 2007-06-30 09:18 28,271 --a------ C:\WINDOWS\system32\drivers\BTHidMgr.sys 2007-06-30 09:18 23,000 --a------ C:\WINDOWS\system32\drivers\btcusb.sys 2007-06-30 09:18 20,480 --a------ C:\WINDOWS\system32\drivers\blueletaudio.sys 2007-06-30 09:18 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS 2007-06-30 09:18 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys 2007-06-30 09:18 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys 2007-06-30 09:18 148,830 --a------ C:\WINDOWS\system32\drivers\bcbthub.sys 2007-06-30 09:18 13,304 --a------ C:\WINDOWS\system32\drivers\BTNetFilter.sys 2007-06-30 09:18 116,021 --a------ C:\WINDOWS\system32\drivers\fw203x.sys 2007-06-30 09:18 11,860 --a------ C:\WINDOWS\system32\drivers\vbtenum.sys 2007-06-30 09:18 11,736 --a------ C:\WINDOWS\system32\drivers\VHIDMini.sys 2007-06-30 09:18 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys 2007-06-30 09:18 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys 2007-06-30 09:18 10,804 --a------ C:\WINDOWS\system32\drivers\BtNetDrv.sys 2007-06-30 09:18 2007-06-30 09:16 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll 2007-06-30 09:16 39,424 -ra------ C:\WINDOWS\system32\drivers\LVUSBSta.sys 2007-06-30 09:16 380,928 -ra------ C:\WINDOWS\system32\LVUI2RC.dll 2007-06-30 09:16 287,360 -ra------ C:\WINDOWS\system32\drivers\LV561AV.SYS (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-13 20:49:42 14,336 ----a-w C:\WINDOWS\system32\svchost.exe 2007-07-11 21:32:51 74,230 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-07-11 21:32:51 448,004 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-27 18:18:37 -------- d-----w C:\Program Files\Usługi online 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-18 16:14:32 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2003-05-15 00:47 50376 --a------ C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe” [2006-05-10 11:12] “CTHelper”=“CTHELPER.EXE” [2003-08-28 10:45 C:\WINDOWS\system32\CTHELPER.EXE] “Jet Detection”=“C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe” [2001-11-29 01:00] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-06-29 17:09] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2006-06-21 19:14] “RemoteControl”=“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [2004-11-02 20:24] “PCSuiteTrayApplication”=“C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe” [2006-06-15 12:36] “!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 11:25] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 02:44] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2006-11-14 11:12] “Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2006-07-06 18:53] “PcSync”=“C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe” [2006-06-27 16:21] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce] “combofix”=C:\WINDOWS\system32\cmd.exe /c C:\ComboFix\Combobatch.bat [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2007-05-30 14:29] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard] *Newly Created Service* - CATCHME ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-18 11:10:16 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-18 11:10:40 C:\ComboFix-quarantined-files.txt … 2007-07-18 11:10 C:\ComboFix2.txt … 2007-07-18 10:47 — E O F —
Złączono Posta : 18.07.2007 (Sro) 11:27
SDFix: Version 1.92
Run by Szymo on 2007-07-18 at 11:21
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\windows_log.txt - Deleted
Removing Temp Files…
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll ,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll ,-22019"
Remaining Files:
Files with Hidden Attributes:
C:\Program Files\Autodesk\Autodesk DWF Viewer_Setupx.dll
C:\Program Files\Autodesk\Autodesk DWF Viewer\Setup.exe
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\SAM.tmp.LOG
C:\WINDOWS\system32\config\SECURITY.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG
Finished