Pierwszy log:
ComboFix 08-03-30.2 - BabciaEla 2008-04-01 22:23:30.2 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1250.48.1033.18.30 [GMT 2:00]
Running from: D:\ComboFix.exe
Command switches used :: D:\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\DOCUME~1\Lipka\LOCALS~1\Temp\jkhfe.dll
C:\WINNT\Internet Logs\xDB1.tmp
C:\WINNT\Internet Logs\xDB2.tmp
C:\WINNT\Internet Logs\xDB3.tmp
C:\WINNT\Internet Logs\xDB4.tmp
C:\WINNT\Internet Logs\xDB5.tmp
C:\WINNT\Internet Logs\xDB6.tmp
C:\WINNT\Internet Logs\xDB7.tmp
C:\WINNT\system32\axnxpvii.dll
C:\WINNT\system32\aygdxjfp.dll
C:\WINNT\system32\bprynajc.dll
C:\WINNT\system32\dkhkcrnc.dll
C:\WINNT\system32\fgxwxqyc.dll
C:\WINNT\system32\iidaamdp.dll
C:\WINNT\system32\iqracbcv.dll
C:\WINNT\system32\jahbqrei.dll
C:\WINNT\system32\madqkvrp.dll
C:\WINNT\system32\pciunswd.dll
C:\WINNT\system32\qjxgujpx.dll
C:\WINNT\system32\qttueefv.dll
C:\WINNT\system32\uarpqbsc.dll
C:\WINNT\system32\yvvqlvvy.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINNT\Internet Logs\xDB1.tmp
C:\WINNT\Internet Logs\xDB2.tmp
C:\WINNT\Internet Logs\xDB3.tmp
C:\WINNT\Internet Logs\xDB4.tmp
C:\WINNT\Internet Logs\xDB5.tmp
C:\WINNT\Internet Logs\xDB6.tmp
C:\WINNT\Internet Logs\xDB7.tmp
C:\WINNT\system32\axnxpvii.dll
C:\WINNT\system32\aygdxjfp.dll
C:\WINNT\system32\bprynajc.dll
C:\WINNT\system32\dkhkcrnc.dll
C:\WINNT\system32\fgxwxqyc.dll
C:\WINNT\system32\iidaamdp.dll
C:\WINNT\system32\iqracbcv.dll
C:\WINNT\system32\jahbqrei.dll
C:\WINNT\system32\madqkvrp.dll
C:\WINNT\system32\pciunswd.dll
C:\WINNT\system32\qjxgujpx.dll
C:\WINNT\system32\qttueefv.dll
C:\WINNT\system32\uarpqbsc.dll
C:\WINNT\system32\yvvqlvvy.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-01 to 2008-04-01 )))))))))))))))))))))))))))))))
.
2008-04-01 21:26 . 08-04-01 21:26 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2cc.dat
2008-04-01 21:22 . 08-04-01 21:22 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2c8.dat
2008-03-30 22:29 . 08-03-30 22:29 54,156 --ah----- C:\WINNT\QTFont.qfn
2008-03-30 22:29 . 08-03-30 22:29 1,409 --a------ C:\WINNT\QTFont.for
2008-03-29 08:36 . 08-04-01 22:19 1,284,404 ---h----- C:\WINNT\ShellIconCache
2008-03-28 16:25 . 08-03-28 16:26 <DIR> d-------- C:\WINNT\ERUNT
2008-03-28 15:57 . 08-03-30 09:15 <DIR> d-------- C:\SDFix
2008-03-23 13:03 . 08-03-23 13:03 <DIR> dr------- C:\New Briefcase
2008-03-22 20:19 . 08-03-22 20:19 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_358.dat
2008-03-12 10:15 . 08-03-12 10:15 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2f8.dat
2008-03-03 20:24 . 08-03-03 20:24 129 --a------ C:\WINNT\system32\test.aok
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-01 20:08 --------- d-----w C:\Documents and Settings\Lipka\Application Data\Skype
2008-04-01 20:07 --------- d---a-w C:\Program Files\Neostrada TP
2008-04-01 20:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-03-28 06:37 13,236,137 ----a-w C:\WINNT\Internet Logs\tvDebug.zip
2008-03-27 23:12 --------- d---a-w C:\Program Files\Spyware Terminator
2008-03-27 23:12 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-03-27 22:35 --------- d---a-w C:\Documents and Settings\Lipka\Application Data\Spyware Terminator
2008-03-27 22:33 --------- d-----w C:\Documents and Settings\Lipka\Application Data\ZoomBrowser EX
2008-03-27 10:25 --------- d-----w C:\Documents and Settings\Lipka\Application Data\CameraWindowDC
2008-03-26 09:02 --------- d-----w C:\Program Files\SkanerOnline
2008-02-27 21:03 --------- d-----w C:\Documents and Settings\Lipka\Application Data\CANON INC
2008-02-27 20:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ZoomBrowser EX
2008-02-27 20:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CameraWindowDC
2008-02-27 20:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CANON INC
2008-02-26 16:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 16:27 --------- d-----w C:\Program Files\Canon
2008-02-26 16:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-26 15:54 --------- d-----w C:\Program Files\Common Files\Canon
2008-02-02 10:05 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-01-10 08:33 9,024,799 ----a-w C:\WINNT\Internet Logs\vsmon_on_demand_2008_01_10_00_36_09_full.dmp.zip
2006-07-05 12:03 271 ---h--w C:\Program Files\desktop.ini
2006-07-05 12:03 21,952 ---h--w C:\Program Files\folder.htt
1999-12-07 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6E475257-25BD-4A42-B3BF-867D4E8AAF3D}]
C:\DOCUME~1\Lipka\LOCALS~1\Temp\jkhfe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
08-01-09 10:23 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [08-01-09 10:23 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [08-01-09 10:23 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [99-12-07 14:00 20752 C:\WINNT\system32\internat.exe]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [07-09-13 14:31 22880040]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07-07-27 09:34 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\system32\mobsync.exe]
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [03-10-16 19:07 24576]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [03-10-16 19:07 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [03-10-16 19:07 53248]
"DemonStarter"="C:\Program Files\PWN\Definicje\Bin\Starter.exe" [99-12-01 14:47 36864]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [03-06-25 15:30 335872]
"ASUS Probe"="D:\Tools\ASUS Probe\AsusProb.exe" [02-12-06 16:07 617984]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [03-12-22 08:38 241664]
"HPDJ Taskbar Utility"="C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb10.exe" [04-05-12 22:30 172032]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [04-05-12 22:29 49152]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07-11-14 17:05 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [99-12-07 14:00 20752 C:\WINNT\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640]
C:\Documents and Settings\Imiela\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-30 23:30:44 114688]
R2 CINEMSUP;Software Cinemaster NT4.0 Driver;C:\WINNT\system32\DRIVERS\CINEMSUP.SYS [02-01-08 10:16 ]
R3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINNT\system32\drivers\ctlsb16.sys [99-10-23 15:10 ]
R3 TTDec;ATI WDM Teletext Decoder;C:\WINNT\system32\DRIVERS\ATINTTXX.sys [04-08-04 03:07 ]
S3 lsermous;Logitech Serial Mouse Driver;C:\WINNT\system32\DRIVERS\lsermous.sys [99-09-27 20:26 ]
S3 mga64;mga64;C:\WINNT\system32\DRIVERS\mga64m.sys [99-11-29 19:47 ]
S3 MSSEARCH;Microsoft Search;"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe" [04-10-12 23:10 ]
S3 oad;Visibroker Activation Daemon;D:\Borland\vbroker\bin\oad.exe [98-03-12 17:57 ]
S3 osagent;VisiBroker Smart Agent;D:\Borland\vbroker\bin\osagent.exe [98-03-12 17:58 ]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINNT\system32\DRIVERS\w200bus.sys [06-11-07 09:42 ]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINNT\system32\DRIVERS\w200mdfl.sys [06-11-07 09:42 ]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINNT\system32\DRIVERS\w200mdm.sys [06-11-07 09:42 ]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINNT\system32\DRIVERS\w200mgmt.sys [06-11-07 09:42 ]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINNT\system32\DRIVERS\w200obex.sys [06-11-07 09:42 ]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-01 22:27:50
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\tsd32.dll
.
Completion time: 2008-04-01 22:29:33
ComboFix-quarantined-files.txt 2008-04-01 20:29:21
ComboFix2.txt 2008-03-31 05:27:24
Pre-Run: 3,553,923,072 bytes free
Post-Run: 3,546,374,144 bytes free
.
2008-03-23 12:23:17 --- E O F ---
a to log wykonany po restarcie:
ComboFix 08-03-30.2 - BabciaEla 04/01/2008 22:51:53.3 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1250.48.1033.18.18 [GMT 2:00]
Running from: D:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-01 to 2008-04-01 )))))))))))))))))))))))))))))))
.
2008-04-01 22:47 . 04/01/08 10:47p 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2cc.dat
2008-04-01 21:22 . 04/01/08 09:22p 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2c8.dat
2008-03-30 22:29 . 03/30/08 10:29p 54,156 --ah----- C:\WINNT\QTFont.qfn
2008-03-30 22:29 . 03/30/08 10:29p 1,409 --a------ C:\WINNT\QTFont.for
2008-03-29 08:36 . 04/01/08 10:41p 1,284,404 ---h----- C:\WINNT\ShellIconCache
2008-03-28 16:25 . 03/28/08 04:26p <DIR> d-------- C:\WINNT\ERUNT
2008-03-28 15:57 . 03/30/08 09:15a <DIR> d-------- C:\SDFix
2008-03-23 13:03 . 03/23/08 01:03p <DIR> dr------- C:\New Briefcase
2008-03-22 20:19 . 03/22/08 08:19p 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_358.dat
2008-03-12 10:15 . 03/12/08 10:15a 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2f8.dat
2008-03-03 20:24 . 03/03/08 08:24p 129 --a------ C:\WINNT\system32\test.aok
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-01 20:45 14,290,569 ----a-w C:\WINNT\Internet Logs\tvDebug.zip
2008-04-01 20:41 --------- d---a-w C:\Program Files\Neostrada TP
2008-04-01 20:39 --------- d-----w C:\Documents and Settings\Lipka\Application Data\Skype
2008-04-01 20:31 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-03-27 23:12 --------- d---a-w C:\Program Files\Spyware Terminator
2008-03-27 23:12 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-03-27 22:35 --------- d---a-w C:\Documents and Settings\Lipka\Application Data\Spyware Terminator
2008-03-27 22:33 --------- d-----w C:\Documents and Settings\Lipka\Application Data\ZoomBrowser EX
2008-03-27 10:25 --------- d-----w C:\Documents and Settings\Lipka\Application Data\CameraWindowDC
2008-03-26 09:02 --------- d-----w C:\Program Files\SkanerOnline
2008-02-27 21:03 --------- d-----w C:\Documents and Settings\Lipka\Application Data\CANON INC
2008-02-27 20:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ZoomBrowser EX
2008-02-27 20:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CameraWindowDC
2008-02-27 20:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CANON INC
2008-02-26 16:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 16:27 --------- d-----w C:\Program Files\Canon
2008-02-26 16:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-26 15:54 --------- d-----w C:\Program Files\Common Files\Canon
2008-02-02 10:05 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-01-10 08:33 9,024,799 ----a-w C:\WINNT\Internet Logs\vsmon_on_demand_2008_01_10_00_36_09_full.dmp.zip
2006-07-05 12:03 271 ---h--w C:\Program Files\desktop.ini
2006-07-05 12:03 21,952 ---h--w C:\Program Files\folder.htt
1999-12-07 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6E475257-25BD-4A42-B3BF-867D4E8AAF3D}]
C:\DOCUME~1\Lipka\LOCALS~1\Temp\jkhfe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
01/09/08 10:23a 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [01/09/08 10:23a 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [01/09/08 10:23a 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [12/07/99 02:00p 20752 C:\WINNT\system32\internat.exe]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [09/13/07 02:31p 22880040]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/27/07 09:34a 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [06/19/03 12:05p 111376 C:\WINNT\system32\mobsync.exe]
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [10/16/03 07:07p 24576]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [10/16/03 07:07p 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [10/16/03 07:07p 53248]
"DemonStarter"="C:\Program Files\PWN\Definicje\Bin\Starter.exe" [12/01/99 02:47p 36864]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [06/25/03 03:30p 335872]
"ASUS Probe"="D:\Tools\ASUS Probe\AsusProb.exe" [12/06/02 04:07p 617984]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/22/03 08:38a 241664]
"HPDJ Taskbar Utility"="C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb10.exe" [05/12/04 10:30p 172032]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [05/12/04 10:29p 49152]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [11/14/07 05:05p 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [12/07/99 02:00p 20752 C:\WINNT\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [06/19/03 12:05p 186640]
C:\Documents and Settings\Imiela\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-30 23:30:44 114688]
R2 CINEMSUP;Software Cinemaster NT4.0 Driver;C:\WINNT\system32\DRIVERS\CINEMSUP.SYS [01/08/02 10:16a]
R3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINNT\system32\drivers\ctlsb16.sys [10/23/99 03:10p]
R3 TTDec;ATI WDM Teletext Decoder;C:\WINNT\system32\DRIVERS\ATINTTXX.sys [08/04/04 03:07a]
S3 lsermous;Logitech Serial Mouse Driver;C:\WINNT\system32\DRIVERS\lsermous.sys [09/27/99 08:26p]
S3 mga64;mga64;C:\WINNT\system32\DRIVERS\mga64m.sys [11/29/99 07:47p]
S3 MSSEARCH;Microsoft Search;"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe" [10/12/04 11:10p]
S3 oad;Visibroker Activation Daemon;D:\Borland\vbroker\bin\oad.exe [03/12/98 05:57p]
S3 osagent;VisiBroker Smart Agent;D:\Borland\vbroker\bin\osagent.exe [03/12/98 05:58p]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINNT\system32\DRIVERS\w200bus.sys [11/07/06 09:42a]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINNT\system32\DRIVERS\w200mdfl.sys [11/07/06 09:42a]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINNT\system32\DRIVERS\w200mdm.sys [11/07/06 09:42a]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINNT\system32\DRIVERS\w200mgmt.sys [11/07/06 09:42a]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINNT\system32\DRIVERS\w200obex.sys [11/07/06 09:42a]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-01 22:55:07
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\tsd32.dll
.
Completion time: 04/01/2008 22:56:49
ComboFix-quarantined-files.txt 2008-04-01 20:56:37
ComboFix2.txt 2008-04-01 20:29:35
Pre-Run: 3,702,317,056 bytes free
Post-Run: 3,687,833,600 bytes free
.
2008-03-23 12:23:17 --- E O F ---