ComboFix 07-07-30.2 - "1" 2007-07-30 20:08:34.3 [GMT 2:00] -
FAT32
Microsoft Windows XP Professional 5.1.2600.1.1250.1.1045.18.Prawda
((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-30 )))))))))))))))))))))))))))))))
2007-07-30 19:51 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-30 17:36 <DIR> d-------- C:\DOCUME~1\1\DANEAP~1\Apple Computer
2007-07-30 17:32 <DIR> d-------- C:\Program Files\Apple Software Update
2007-07-30 17:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Apple Computer
2007-07-30 17:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Apple
2007-07-23 11:28 2,855 --a------ C:\WINDOWS\system32\mem.PIF
2007-07-20 16:56 19,018 -ra------ C:\WINDOWS\system32\drivers\KS-959.sys
2007-07-18 09:31 69,120 --a------ C:\WINDOWS\system32\olecli32.dll
2007-07-18 09:31 34,304 --a------ C:\WINDOWS\system32\olecnv32.dll
2007-07-18 09:31 263,680 --a------ C:\WINDOWS\system32\rpcss.dll
2007-07-18 09:31 1,183,744 --a------ C:\WINDOWS\system32\ole32.dll
2007-07-10 11:38 <DIR> d-------- C:\Program Files\Lavalys
2007-07-07 21:39 <DIR> d-------- C:\KAV
2007-06-27 03:59 344,064 --a------ C:\WINDOWS\system32\ATIDEMGX.dll
2007-06-27 03:44 8,232,960 --a------ C:\WINDOWS\system32\atioglx2.dll
2007-06-27 03:17 266,240 --a------ C:\WINDOWS\system32\atikvmag.dll
2007-06-27 03:15 49,152 --a------ C:\WINDOWS\system32\drivers\ati2erec.dll
2007-06-27 03:14 176,128 --a------ C:\WINDOWS\system32\atiok3x2.dll
2007-06-25 14:52 1,028,608 --a------ C:\WINDOWS\system32\esent.dll
2007-06-24 00:43 <DIR> d--hs---- C:\FOUND.042
2007-06-23 20:53 <DIR> d--hs---- C:\FOUND.041
2007-06-23 10:35 2,815 --a------ C:\WINDOWS\unins000.dat
2007-06-22 20:47 <DIR> d--hs---- C:\FOUND.040
2007-06-21 14:47 <DIR> d-------- C:\WINDOWS\Prefetch
2007-06-21 13:52 31,104 --a------ C:\WINDOWS\system32\drivers\ShlDrv51.sys
2007-06-21 13:52 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2007-06-20 08:23 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-06-18 12:13 <DIR> d-------- C:\DOCUME~1\1\Gadu-Gadu
2007-06-14 18:00 <DIR> d--hs---- C:\FOUND.039
2007-06-13 20:57 972,072 --a------ C:\WINDOWS\system32\ativva6x.dat
2007-06-13 20:57 3,107,788 --a------ C:\WINDOWS\system32\ativva5x.dat
2007-06-09 17:32 524,288 --ah----- C:\DOCUME~1\ADMINI~1\ntuser.dat
2007-06-09 17:32 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Dane aplikacji
2007-06-09 17:32 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menu Start
2007-06-09 17:32 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ustawienia lokalne
2007-06-09 17:32 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Szablony
2007-06-09 17:32 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Ulubione
2007-06-09 17:32 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Pulpit
2007-06-09 17:32 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Moje dokumenty
2007-06-07 13:00 <DIR> d-------- C:\Program Files\Google
2007-06-07 00:06 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-06-06 22:53 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-06-05 19:40 149,278 --a------ C:\WINDOWS\system32\atiicdxx.dat
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2060-08-18 19:02 1496064 --------- C:\WINDOWS\system32\CC3250MT.DLL
2060-08-18 18:40 909824 --------- C:\WINDOWS\system32\cp3245mt.dll
2060-08-18 18:40 24064 --------- C:\WINDOWS\system32\borlndmm.dll
2007-07-30 18:37 3932 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-07-30 18:37 32540 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-07-30 18:37 30496 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-07-30 18:37 2801664 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-07-30 16:34 10 --a------ C:\WINDOWS\popcinfo.dat
2007-06-27 04:27 44240 --a------ C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-06-26 15:41 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-06-08 09:02 3680 --a------ C:\WINDOWS\mozver.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" [2007-01-29 23:02]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
"d:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"d:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Device Detector]
"C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe" -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\MSMSGS.EXE" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
d:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PSIMSVC"=2 (0x2)
"wuauserv"=2 (0x2)
R0 prohlp02;StarForce Protection Helper Driver v2;C:\WINDOWS\System32\drivers\prohlp02.sys
R0 prosync1;StarForce Protection Synchronization Driver v1;C:\WINDOWS\System32\drivers\prosync1.sys
R0 sfhlp01;StarForce Protection Helper Driver;C:\WINDOWS\System32\drivers\sfhlp01.sys
R1 prodrv06;StarForce Protection Environment Driver v6;C:\WINDOWS\System32\drivers\prodrv06.sys
R1 SSHDRV76;SSHDRV76;\??\C:\WINDOWS\System32\drivers\SSHDRV76.sys
R1 SSHDRV79;SSHDRV79;\??\C:\WINDOWS\System32\drivers\SSHDRV79.sys
R2 ElbyCDIO;ElbyCDIO Driver;C:\WINDOWS\System32\Drivers\ElbyCDIO.sys
R2 GDTdiInterceptor;GDTdiInterceptor;\??\C:\WINDOWS\System32\drivers\GDTdiIcpt.sys
R2 SoundMAX Agent Service (default);SoundMAX Agent Service;C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
R3 adiusbaw;USB ADSL WAN Adapter;C:\WINDOWS\System32\DRIVERS\adiusbaw.sys
R3 ElbyCDFL;ElbyCDFL;C:\WINDOWS\System32\Drivers\ElbyCDFL.sys
S2 ADILOADER;General Purpose USB Driver (adildr.sys);C:\WINDOWS\System32\Drivers\adildr.sys
S3 adxapie;adxapie;\??\C:\DOCUME~1\1\USTAWI~1\Temp\adxapie.sys
S3 ASUSHWIO;ASUSHWIO;\??\C:\WINDOWS\System32\drivers\ASUSHWIO.sys
S3 dtscsi;dtscsi;C:\WINDOWS\System32\Drivers\dtscsi.sys
S3 EGATHDRV;IBM Access Support;\??\C:\WINDOWS\Downloaded Program Files\EGATHDRV.SYS
S3 FETNDIS;Sterownik NT karty VIA PCI 10/100Mb Fast Ethernet;C:\WINDOWS\System32\DRIVERS\fetnd5.sys
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\System32\DRIVERS\fetnd5b.sys
S3 hidgame;WĄcznik Microsoft HID do portu joysticka;C:\WINDOWS\System32\DRIVERS\hidgame.sys
S3 Ip6FwHlp;Zapora poĄczenia internetowego IPv6;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 KS-959;Kingsun KS-959 USB Infrared Adapter;C:\WINDOWS\System32\DRIVERS\KS-959.sys
S3 MSIRCOMM;Microsoft IR Communications Driver;C:\WINDOWS\System32\DRIVERS\MSIRCOMM.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\System32\ntsim.sys
Contents of the 'Scheduled Tasks' folder
2007-07-30 15:32:18 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-30 20:11:19
Windows 5.1.2600 Dodatek Service Pack. 1 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-30 20:12:39
--- E O F ---