K. Krawczyk - 06-12-01 13:50:42,00 Dodatek Service Pack 2 ComboFix 06.11.27W - Running from: “C:\Documents and Settings\K. Krawczyk\Pulpit” ((((((((((((((((((((((((((((((( Files Created from 2006-11-01 to 2006-12-01 )))))))))))))))))))))))))))))))))) 2006-12-01 13:13 2006-12-01 13:05 2006-12-01 12:50 2006-11-29 07:59 2006-11-29 07:55 2006-11-28 15:55 36,528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys 2006-11-28 15:55 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys 2006-11-28 15:55 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys 2006-11-28 15:55 129,784 --------- C:\WINDOWS\system32\pxafs.dll 2006-11-28 15:55 115,880 --------- C:\WINDOWS\system32\pxinsi64.exe 2006-11-27 15:54 2006-11-27 15:54 2006-11-26 19:08 119,568 --------- C:\WINDOWS\system32\vb6fr.dll 2006-11-25 10:52 133,120 --a------ C:\WINDOWS\system32\zip32.dll 2006-11-24 14:46 2006-11-19 19:48 2006-11-19 16:27 2006-11-19 11:37 131,072 --a------ C:\WINDOWS\system32\SpoonUninstall.exe 2006-11-18 08:36 2006-11-17 20:46 2006-11-17 18:04 2006-11-16 15:44 2006-11-14 16:59 48,128 --a------ C:\Documents and Settings\K. Krawczyk\cnmss Canon MP450 Series Printer (Local).dll 2006-11-14 15:45 2006-11-13 18:44 2006-11-13 18:39 8,704 --a------ C:\WINDOWS\system32\CNMVS7I.DLL 2006-11-13 18:39 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2006-11-13 18:39 26,496 --a------ C:\WINDOWS\system32\drivers\USBSTOR.SYS 2006-11-13 18:39 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2006-11-13 18:39 140,288 --a------ C:\WINDOWS\system32\CNMLM7I.DLL 2006-11-13 18:39 2006-11-13 18:36 2006-11-13 18:36 2006-11-13 18:36 2006-11-13 18:36 2006-11-13 18:36 2006-11-13 18:34 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL 2006-11-13 18:33 69,632 --a------ C:\WINDOWS\system32\CNCI450.DLL 2006-11-13 18:33 49,152 --a------ C:\WINDOWS\system32\cncisco.dll 2006-11-13 18:33 221,184 --a------ C:\WINDOWS\system32\CNCC450.DLL 2006-11-13 18:33 139,264 --a------ C:\WINDOWS\system32\CNCL450.DLL 2006-11-13 18:33 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll 2006-11-13 18:33 2006-11-13 18:33 2006-11-13 18:32 2006-11-12 14:20 2006-11-12 14:19 2006-11-10 13:51 57,344 --a------ C:\WINDOWS\system32\ircomm2k.dll 2006-11-10 13:51 53,248 --a------ C:\WINDOWS\system32\ircomm2k.exe 2006-11-10 13:51 40,960 --a------ C:\WINDOWS\IrCOMM2k-Setup.exe 2006-11-10 13:51 16,026 --a------ C:\WINDOWS\system32\drivers\ircomm2k.sys 2006-11-10 07:49 2006-11-09 17:29 2006-11-09 17:27 2006-11-07 20:31 208,384 --a------ C:\WINDOWS\ADS.exe 2006-11-07 20:29 2006-11-06 08:16 163,712 --a------ C:\WINDOWS\system32\drivers\vidstub.sys 2006-11-05 18:43 2006-11-04 14:14 1,245,696 --a------ C:\WINDOWS\system32\msxml4.dll 2006-11-04 14:03 2006-11-03 20:59 2006-11-03 20:59 2006-11-03 20:58 913,408 --a------ C:\WINDOWS\system32\skype4com.dll 2006-11-03 20:58 16,384 --a------ C:\WINDOWS\system32\rlvacumd.dll 2006-11-03 20:58 2006-11-03 20:58 2006-11-03 14:21 2006-11-01 21:16 2006-11-01 18:54 545 --a------ C:\WINDOWS\UC.PIF 2006-11-01 18:54 545 --a------ C:\WINDOWS\RAR.PIF 2006-11-01 18:54 545 --a------ C:\WINDOWS\PKZIP.PIF 2006-11-01 18:54 545 --a------ C:\WINDOWS\PKUNZIP.PIF 2006-11-01 18:54 545 --a------ C:\WINDOWS\NOCLOSE.PIF 2006-11-01 18:54 545 --a------ C:\WINDOWS\LHA.PIF 2006-11-01 18:54 545 --a------ C:\WINDOWS\ARJ.PIF 2006-11-01 18:54 2006-11-01 18:44 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys 2006-11-01 18:44 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-11-28 22:19 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Skype 2006-11-27 15:54 -------- d-------- C:\Program Files\Common Files 2006-11-12 18:02 464 --a------ C:\WINDOWS\system32\xvid.dll 2006-11-06 21:46 -------- d—s---- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Microsoft 2006-11-05 19:32 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\AVG7 2006-11-04 21:00 576512 --a------ C:\WINDOWS\system32\logonuiX.exe 2006-11-04 20:48 219648 --a------ C:\WINDOWS\system32\uxtheme.dll 2006-11-04 14:49 -------- d-------- C:\Program Files\Common Files\Microsoft Shared 2006-11-03 14:21 -------- d-------- C:\Program Files\Citrix 2006-11-01 18:44 816672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys 2006-11-01 18:44 4960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys 2006-11-01 18:44 4224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys 2006-11-01 18:44 28416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-11-01 14:54 180224 --a------ C:\WINDOWS\system32\xvidvfw.dll 2006-11-01 14:52 765952 --a------ C:\WINDOWS\system32\xvidcore.dll 2006-10-31 20:54 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Azureus 2006-10-30 17:14 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Dev-Cpp 2006-10-27 06:44 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Real 2006-10-21 18:52 464 --a------ C:\WINDOWS\system32\vorbisenc.dll 2006-10-21 18:52 464 --a------ C:\WINDOWS\system32\vorbis.dll 2006-10-21 18:52 464 --a------ C:\WINDOWS\system32\OggDS.dll 2006-10-21 18:52 464 --a------ C:\WINDOWS\system32\ogg.dll 2006-10-21 18:52 464 --a------ C:\WINDOWS\system32\mplvpx.dll 2006-10-21 18:52 464 --a------ C:\WINDOWS\system32\cpuinf32.dll 2006-10-21 16:08 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\BitTorrent 2006-10-21 16:05 -------- d-------- C:\Program Files\BitTorrent 2006-10-18 14:33 249316 --a------ C:\WINDOWS\Alcohol_Toolbar_Uninstaller_4344.exe 2006-10-18 14:33 223128 --a------ C:\WINDOWS\system32\drivers\vaxscsi.sys 2006-10-17 18:32 611064 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2006-10-15 15:17 10345 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2006-10-13 17:44 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Thunderbird 2006-10-13 17:44 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Mozilla 2006-10-13 13:41 65536 --a------ C:\WINDOWS\system32\nwwks.dll 2006-10-13 13:41 64000 --a------ C:\WINDOWS\system32\nwapi32.dll 2006-10-13 13:41 143872 --a------ C:\WINDOWS\system32\nwprovau.dll 2006-10-13 11:23 163584 --a------ C:\WINDOWS\system32\drivers\nwrdr.sys 2006-10-13 07:00 -------- d-------- C:\Program Files\RAKS2000 2006-10-09 17:38 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Media Player Classic 2006-10-08 12:10 -------- d-------- C:\Program Files\Common Files\InstallShield 2006-10-07 09:16 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Download Manager 2006-10-05 16:08 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Macromedia 2006-10-03 20:49 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Nvu 2006-10-02 15:54 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Apple Computer 2006-10-02 14:42 -------- d-------- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\Help 2006-10-01 21:06 -------- d-------- C:\Program Files\Common Files\System 2006-10-01 18:28 73216 --a------ C:\WINDOWS\ST6UNST.EXE 2006-10-01 18:28 249856 --------- C:\WINDOWS\Setup1.exe 2006-09-28 17:44 138752 --a------ C:\WINDOWS\system32\sndvol32.exe 2006-09-26 17:56 62 --ahs---- C:\Documents and Settings\K. Krawczyk\Dane aplikacji\desktop.ini 2006-09-26 17:16 0 -rahs---- C:\MSDOS.SYS 2006-09-26 17:16 0 -rahs---- C:\IO.SYS 2006-09-26 17:16 0 --a------ C:\CONFIG.SYS 2006-09-26 17:16 0 --a------ C:\AUTOEXEC.BAT 2006-09-19 15:43 109360 --a------ C:\WINDOWS\system32\GEARAspi.dll 2006-09-15 15:39 208896 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2006-09-15 15:39 208896 --a------ C:\WINDOWS\system32\nvudisp.exe 2006-09-13 22:14 593938 --a------ C:\WINDOWS\system32\x264vfw.dll 2006-09-13 06:07 1084416 --a------ C:\WINDOWS\system32\msxml3.dll 2006-09-11 20:00 86073 --a------ C:\WINDOWS\system32\usrfaxa.dll 2006-09-11 20:00 8192 --a------ C:\WINDOWS\system32\streamci.dll 2006-09-11 20:00 77891 --a------ C:\WINDOWS\system32\usrmlnka.exe 2006-09-11 20:00 77890 --a------ C:\WINDOWS\system32\usrdpa.dll 2006-09-11 20:00 77883 --a------ C:\WINDOWS\system32\usrrtosa.dll 2006-09-11 20:00 72192 --a------ C:\WINDOWS\system32\sprio800.dll 2006-09-11 20:00 70656 --a------ C:\WINDOWS\system32\sprio600.dll 2006-09-11 20:00 69700 --a------ C:\WINDOWS\system32\usrshuta.exe 2006-09-11 20:00 69699 --a------ C:\WINDOWS\system32\usrcoina.dll 2006-09-11 20:00 69632 --a------ C:\WINDOWS\system32\spnike.dll 2006-09-11 20:00 61508 --a------ C:\WINDOWS\system32\usrprbda.exe 2006-09-11 20:00 61500 --a------ C:\WINDOWS\system32\usrcntra.dll 2006-09-11 20:00 57856 --a------ C:\WINDOWS\system32\dvdplay.exe 2006-09-11 20:00 53305 --a------ C:\WINDOWS\system32\usrlbva.dll 2006-09-11 20:00 49211 --a------ C:\WINDOWS\system32\usrvpa.dll 2006-09-11 20:00 49211 --a------ C:\WINDOWS\system32\usrsdpia.dll 2006-09-11 20:00 49209 --a------ C:\WINDOWS\system32\usrv80a.dll 2006-09-11 20:00 45116 --a------ C:\WINDOWS\system32\usrvoica.dll 2006-09-11 20:00 41019 --a------ C:\WINDOWS\system32\usrsvpia.dll 2006-09-11 20:00 323641 --a------ C:\WINDOWS\system32\usrdtea.dll 2006-09-11 20:00 3200 --a------ C:\WINDOWS\system32\wowfax.dll 2006-09-11 20:00 157696 --a------ C:\WINDOWS\system32\paqsp.dll 2006-09-11 20:00 147968 --a------ C:\WINDOWS\system32\mdwmdmsp.dll 2006-09-11 20:00 13824 --a------ C:\WINDOWS\system32\wowfaxui.dll 2006-09-11 20:00 102457 --a------ C:\WINDOWS\system32\usrv42a.dll 2006-09-11 18:22 945664 --a------ C:\WINDOWS\system32\syssetub.dll 2006-09-11 18:22 87040 --a------ C:\WINDOWS\system32\wiafbdrv.dll 2006-09-11 18:21 8192 --a------ C:\WINDOWS\system32\tsbyuv.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “AVG7_CC”=“D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP” “NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” “BootSkin Startup Jobs”="“D:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe” /StartupJobs" “NvMediaCenter”=“RunDLL32.exe NvMCTray.dll,NvTaskbarInit” “Spik”=“D:\Program Files\Spik\Spik.exe -autostart” “QuickTime Task”="“D:\Program Files\QuickTime\qttask.exe” -atboottime" “iTunesHelper”="“D:\Program Files\iTunes\iTunesHelper.exe”" “WinampAgent”=“D:\Program Files\Winamp\winampa.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] “DeskHtmlVersion”=dword:00000110 “DeskHtmlMinorVersion”=dword:00000005 “Settings”=dword:00000001 “GeneralFlags”=dword:00000005 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] “Source”=“About:Home” “SubscribedURL”=“About:Home” “FriendlyName”=“Moja bieżąca strona główna” “Flags”=dword:00000002 “Position”=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 “CurrentState”=hex:04,00,00,40 “OriginalStateInfo”=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,\ 00,00,04,00,00,40 “RestoredStateInfo”=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,\ 00,00,01,00,00,00 [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” “AVG7_Run”=“D:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE” [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” “AVG7_Run”=“D:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] “{438755C2-A8BA-11D1-B96B-00A0C90312E1}”=“Moduł wstępnego ładowania interfejsu Browseui” “{8C7461EF-2B13-11d2-BE35-3078302C2030}”=“Demon buforu kategorii składników” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{AEB6717E-7E19-11d0-97EE-00C04FD91972}”="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 “NoSMMyDocs”=dword:00000001 “NoSMMyPictures”=dword:00000001 “NoSMConfigurePrograms”=dword:00000001 “ClearRecentDocsOnExit”=dword:00000001 “NoInstrumentation”=dword:00000001 “NoStartMenuMFUprogramsList”=dword:00000001 “NoLowDiskSpaceChecks”=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “dontdisplaylastusername”=dword:00000000 “legalnoticecaption”="" “legalnoticetext”="" “shutdownwithoutlogon”=dword:00000001 “undockwithoutlogon”=dword:00000001 [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 “NoSMMyDocs”=dword:00000001 “NoSMMyPictures”=dword:00000001 “NoSMConfigurePrograms”=dword:00000001 “ClearRecentDocsOnExit”=dword:00000001 “NoInstrumentation”=dword:00000001 “NoStartMenuMFUprogramsList”=dword:00000001 “NoLowDiskSpaceChecks”=dword:00000001 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 “NoSMMyDocs”=dword:00000001 “NoSMMyPictures”=dword:00000001 “NoSMConfigurePrograms”=dword:00000001 “ClearRecentDocsOnExit”=dword:00000001 “NoInstrumentation”=dword:00000001 “NoStartMenuMFUprogramsList”=dword:00000001 “NoLowDiskSpaceChecks”=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] “PostBootReminder”="{7849596a-48ea-486e-8937-a2a3009f31a9}" “CDBurn”="{fbeb8a05-beee-4442-804e-409d6c4515e9}" “WebCheck”="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" “SysTray”="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] “SpybotSD TeaTimer”=“D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^ScanPanel.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ScanPanel.lnk” “backup”=“C:\WINDOWS\pss\ScanPanel.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\SCANPA~1\ScnPanel.exe " “item”=“ScanPanel” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^TV Remote Control.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\TV Remote Control.lnk” “backup”=“C:\WINDOWS\pss\TV Remote Control.lnkCommon Startup” “location”=“Common Startup” “command”=“D:\PROGRA~1\V-STRE~1\TV713X~1\P3XRCtl.exe " “item”=“TV Remote Control” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^K. Krawczyk^Menu Start^Programy^Autostart^Adobe Gamma.lnk] “path”=“C:\Documents and Settings\K. Krawczyk\Menu Start\Programy\Autostart\Adobe Gamma.lnk” “backup”=“C:\WINDOWS\pss\Adobe Gamma.lnkStartup” “location”=“Startup” “command”=“C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE " “item”=“Adobe Gamma” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^K. Krawczyk^Menu Start^Programy^Autostart^Animated Desktop.lnk] “path”=“C:\Documents and Settings\K. Krawczyk\Menu Start\Programy\Autostart\Animated Desktop.lnk” “backup”=“C:\WINDOWS\pss\Animated Desktop.lnkStartup” “location”=“Startup” “command”=“C:\Documents and Settings\K. Krawczyk\Pulpit\AnimatedDesktop\AnimatedDesktop.exe " “item”=“Animated Desktop” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^K. Krawczyk^Menu Start^Programy^Autostart^Canon IJ Status Monitor Canon MP450 Series Printer.lnk] “path”=“C:\Documents and Settings\K. Krawczyk\Menu Start\Programy\Autostart\Canon IJ Status Monitor Canon MP450 Series Printer.lnk” “backup”=“C:\WINDOWS\pss\Canon IJ Status Monitor Canon MP450 Series Printer.lnkStartup” “location”=“Startup” “command”=“C:\WINDOWS\system32\rundll32.exe C:\DOCUME~1\KFB85~1.KRA\CNMSSC~1.DLL,SMStarterEntryPoint USB001;Canon MP450 Series Printer;cnmss Canon MP450 Series Printer (Local).dll;Canon IJ Status Monitor Canon MP450 Series Printer.lnk” “item”=“Canon IJ Status Monitor Canon MP450 Series Printer” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^K. Krawczyk^Menu Start^Programy^Autostart^Monitor Apache Servers.lnk] “path”=“C:\Documents and Settings\K. Krawczyk\Menu Start\Programy\Autostart\Monitor Apache Servers.lnk” “backup”=“C:\WINDOWS\pss\Monitor Apache Servers.lnkStartup” “location”=“Startup” “command”=“D:\PROGRA~1\APACHE~1\Apache2.2\bin\APACHE~1.EXE " “item”=“Monitor Apache Servers” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^K. Krawczyk^Menu Start^Programy^Autostart^PopTray.lnk] “path”=“C:\Documents and Settings\K. Krawczyk\Menu Start\Programy\Autostart\PopTray.lnk” “backup”=“C:\WINDOWS\pss\PopTray.lnkStartup” “location”=“Startup” “command”=“D:\PROGRA~1\PopTray\PopTray.exe " “item”=“PopTray” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADS] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“ADS” “hkey”=“HKCU” “command”=“C:\Windows\ADS.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“Ares” “hkey”=“HKCU” “command”=”“D:\Program Files\Ares\Ares.exe” -h” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearFlix] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“BearFlix” “hkey”=“HKLM” “command”=”“D:\Program Files\BearFlix\BearFlix.exe” /pause” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“BearShare” “hkey”=“HKLM” “command”=”“D:\Program Files\BearShare\BearShare.exe” /pause” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“BitComet” “hkey”=“HKCU” “command”="“D:\Program Files\BitComet\BitComet.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“bittorrent” “hkey”=“HKCU” “command”="“D:\Program Files\BitTorrent\bittorrent.exe” --force_start_minimized" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CT4Skype] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“CT4Skype” “hkey”=“HKCU” “command”="“D:\Program Files\Reallusion\CrazyTalk for Skype\CT4Skype.exe” iMode" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“ctfmon” “hkey”=“HKCU” “command”=“C:\WINDOWS\system32\ctfmon.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“daemon” “hkey”=“HKLM” “command”="“D:\Program Files\DAEMON Tools\daemon.exe” -lang 1033" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HiDownload] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“hidownload” “hkey”=“HKLM” “command”=“D:\Program Files\HiDownload\hidownload.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“iTunesHelper” “hkey”=“HKLM” “command”="“D:\Program Files\iTunes\iTunesHelper.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“tlen” “hkey”=“HKCU” “command”="“D:\Program Files\Tlen.pl\tlen.exe” --confdir=home" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogonStudio] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“logonstudio” “hkey”=“HKLM” “command”="“D:\Program Files\WinCustomize\LogonStudio\logonstudio.exe” /RANDOM" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NeroCheck” “hkey”=“HKLM” “command”=“C:\WINDOWS\system32\\NeroCheck.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NvCpl” “hkey”=“HKLM” “command”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NvMcTray” “hkey”=“HKLM” “command”=“RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“nwiz” “hkey”=“HKLM” “command”=“nwiz.exe /install” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“OpwareSE2” “hkey”=“HKLM” “command”="“D:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVR Agent] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“Scheduled” “hkey”=“HKLM” “command”=“D:\Program Files\V-Stream Multimedia\PVR Plus\TVR\Scheduled.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“qttask” “hkey”=“HKLM” “command”="“D:\Program Files\QuickTime\qttask.exe” -atboottime" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“Skype” “hkey”=“HKCU” “command”="“D:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“jusched” “hkey”=“HKLM” “command”=“D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“winampa” “hkey”=“HKLM” “command”=“D:\Program Files\Winamp\winampa.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” Contents of the ‘Scheduled Tasks’ folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job Completion time: 06-12-01 13:52:00.91 C:\ComboFix.txt … 06-12-01 13:52 C:\ComboFix2.txt … 06-11-25 22:37