ComboFix 08-08-19.06 - Ja 2008-08-21 16:05:39.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.316 [GMT 2:00] Running from: C:\Documents and Settings\Ja\Pulpit\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED . ((((((((((((((((((((((((( Files Created from 2008-07-21 to 2008-08-21 ))))))))))))))))))))))))))))))) . 2008-08-20 20:51 . 2008-08-20 20:51 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2008-08-16 10:12 . 2008-08-16 10:12 2008-08-16 10:12 . 2008-08-17 13:13 2008-08-09 22:17 . 2008-08-09 22:17 0 --a------ C:\WINDOWS\nsreg.dat 2008-08-09 22:11 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-08-09 22:08 . 2008-08-09 22:11 2008-08-09 22:06 . 2008-08-09 22:06 2008-08-09 14:24 . 2008-08-09 15:17 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat 2008-08-09 14:24 . 2008-08-09 15:17 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat 2008-08-09 14:23 . 2008-08-21 16:13 2008-08-09 14:23 . 2008-08-21 16:12 892,448 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2008-08-09 14:23 . 2008-08-21 16:12 213,024 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2008-08-09 14:23 . 2008-08-21 16:12 10,148 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2008-08-09 14:23 . 2008-08-21 16:12 3,904 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2008-08-04 08:19 . 2008-08-21 11:13 2008-08-01 19:14 . 2008-08-01 19:14 2008-07-29 18:56 . 2008-07-29 18:56 2008-07-29 15:15 . 2008-07-29 15:15 2008-07-29 13:45 . 2008-07-29 13:45 47 --a------ C:\WINDOWS\NeroDigital.ini 2008-07-28 13:43 . 2008-07-28 13:43 2008-07-28 13:41 . 2008-07-28 13:42 2008-07-28 13:38 . 2008-07-28 13:38 2008-07-28 13:38 . 2008-07-28 13:38 2008-07-28 13:38 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2008-07-28 13:38 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2008-07-28 13:38 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2008-07-28 13:38 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2008-07-28 13:38 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2008-07-28 13:38 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2008-07-28 12:23 . 2008-07-28 12:23 2008-07-24 19:57 . 2008-07-27 13:19 2008-07-23 20:32 . 2008-07-29 16:34 2008-07-23 19:53 . 2008-07-28 09:10 2008-07-23 10:22 . 2008-06-14 20:01 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-07-23 10:22 . 2008-06-14 20:01 273,024 -----c— C:\WINDOWS\system32\dllcache\bthport.sys 2008-07-22 23:22 . 2008-08-13 23:14 2008-07-22 23:22 . 2005-02-25 05:36 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-20 18:42 --------- d–h--w C:\Program Files\InstallShield Installation Information 2008-08-20 18:33 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\GanymedeNet 2008-08-14 18:52 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\Tibia 2008-08-09 12:23 --------- d-----w C:\Program Files\Kaspersky Lab 2008-08-09 12:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files 2008-08-03 16:04 --------- d-----w C:\Program Files\Ganymede 2008-08-01 17:15 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2008-07-26 07:41 --------- d-----w C:\Program Files\JetAudio 2008-07-25 11:57 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\Spik 2008-07-20 21:15 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search Destroy 2008-07-20 20:29 --------- d-----w C:\Program Files\Spybot - Search Destroy 2008-07-12 06:07 --------- d-----w C:\Program Files\Sun 2008-07-10 16:27 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\COWON 2008-07-10 15:22 --------- d-----w C:\Program Files\Common Files\COWON 2008-07-10 15:21 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\InstallShield 2008-07-10 11:51 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\eMule 2008-07-10 08:56 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\Gadu-Gadu 2008-07-10 08:55 --------- d-----w C:\Program Files\Gadu-Gadu 2008-07-10 08:31 --------- d-----w C:\Program Files\Realtek Sound Manager 2008-07-10 08:31 --------- d-----w C:\Program Files\AvRack 2008-07-10 08:30 --------- d-----w C:\Program Files\AMD 2008-07-10 08:27 --------- d-----w C:\Program Files\Opera 2008-07-10 08:26 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-07-10 08:22 --------- d-----w C:\Program Files\Thomson 2008-07-10 08:16 --------- d-----w C:\Program Files\microsoft frontpage 2008-07-10 08:14 --------- d-----w C:\Program Files\Usługi online 2008-07-07 20:33 253,952 ----a-w C:\WINDOWS\system32\es.dll 2008-06-24 16:24 74,240 ----a-w C:\WINDOWS\system32\mscms.dll 2008-06-23 15:41 662,016 ----a-w C:\WINDOWS\system32\wininet.dll 2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll . ((((((((((((((((((((((((((((( snapshot@2008-07-29_15.56.57.21 ))))))))))))))))))))))))))))))))))))))))) . + 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE - 2008-04-21 07:03:48 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll + 2008-06-23 15:41:35 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll - 2008-04-21 07:03:48 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll + 2008-06-23 15:41:35 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll - 2008-04-21 07:03:50 1,055,744 ----a-w C:\WINDOWS\system32\danim.dll + 2008-06-23 15:41:36 1,055,744 ----a-w C:\WINDOWS\system32\danim.dll - 2008-04-21 07:03:48 1,023,488 -c–a-w C:\WINDOWS\system32\dllcache\browseui.dll + 2008-06-23 15:41:35 1,023,488 -c–a-w C:\WINDOWS\system32\dllcache\browseui.dll - 2008-04-21 07:03:48 151,552 -c–a-w C:\WINDOWS\system32\dllcache\cdfview.dll + 2008-06-23 15:41:35 151,552 -c–a-w C:\WINDOWS\system32\dllcache\cdfview.dll - 2008-04-21 07:03:50 1,055,744 -c–a-w C:\WINDOWS\system32\dllcache\danim.dll + 2008-06-23 15:41:36 1,055,744 -c–a-w C:\WINDOWS\system32\dllcache\danim.dll - 2008-04-21 07:03:50 357,888 -c–a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll + 2008-06-23 15:41:36 357,888 -c–a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll - 2008-04-21 07:03:50 205,312 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll + 2008-06-23 15:41:36 205,312 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll - 2004-08-03 22:43:58 243,200 -c–a-w C:\WINDOWS\system32\dllcache\es.dll + 2008-07-07 20:33:22 253,952 -c–a-w C:\WINDOWS\system32\dllcache\es.dll - 2008-04-21 07:03:50 55,808 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll + 2008-06-23 15:41:36 55,808 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll - 2008-04-17 10:52:54 18,432 -c–a-w C:\WINDOWS\system32\dllcache\iedw.exe + 2008-06-23 09:49:29 18,432 -c–a-w C:\WINDOWS\system32\dllcache\iedw.exe - 2008-04-21 07:03:51 251,392 -c–a-w C:\WINDOWS\system32\dllcache\iepeers.dll + 2008-06-23 15:41:36 251,392 -c–a-w C:\WINDOWS\system32\dllcache\iepeers.dll - 2004-08-03 22:44:00 678,400 -c–a-w C:\WINDOWS\system32\dllcache\inetcomm.dll + 2008-04-11 18:51:52 683,520 -c–a-w C:\WINDOWS\system32\dllcache\inetcomm.dll - 2008-04-21 07:03:51 96,768 -c–a-w C:\WINDOWS\system32\dllcache\inseng.dll + 2008-06-23 15:41:36 96,768 -c–a-w C:\WINDOWS\system32\dllcache\inseng.dll - 2004-08-03 22:44:02 450,560 -c–a-w C:\WINDOWS\system32\dllcache\jscript.dll + 2007-12-18 14:42:55 450,560 -c–a-w C:\WINDOWS\system32\dllcache\jscript.dll - 2008-04-21 07:03:51 16,384 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll + 2008-06-23 15:41:36 16,384 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll - 2004-08-03 22:44:04 331,776 -c–a-w C:\WINDOWS\system32\dllcache\msadce.dll + 2008-05-01 14:33:01 331,776 -c–a-w C:\WINDOWS\system32\dllcache\msadce.dll - 2004-08-03 22:44:04 73,728 -c–a-w C:\WINDOWS\system32\dllcache\mscms.dll + 2008-06-24 16:24:26 74,240 -c–a-w C:\WINDOWS\system32\dllcache\mscms.dll - 2008-04-21 07:03:55 3,080,704 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll + 2008-06-23 15:41:37 3,080,704 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll - 2008-04-21 07:03:56 449,024 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll + 2008-06-23 15:41:37 449,024 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll - 2008-04-21 07:03:56 146,432 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll + 2008-06-23 15:41:37 146,432 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll - 2008-04-21 07:03:56 532,480 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll + 2008-06-23 15:41:37 532,480 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll - 2008-04-21 07:03:56 39,424 -c–a-w C:\WINDOWS\system32\dllcache\pngfilt.dll + 2008-06-23 15:41:37 39,424 -c–a-w C:\WINDOWS\system32\dllcache\pngfilt.dll - 2008-04-21 07:03:57 1,494,528 -c–a-w C:\WINDOWS\system32\dllcache\shdocvw.dll + 2008-06-23 15:41:37 1,494,528 -c–a-w C:\WINDOWS\system32\dllcache\shdocvw.dll - 2008-04-21 07:03:58 474,112 -c–a-w C:\WINDOWS\system32\dllcache\shlwapi.dll + 2008-06-23 15:41:37 474,112 -c–a-w C:\WINDOWS\system32\dllcache\shlwapi.dll - 2008-04-21 07:03:58 616,960 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll + 2008-06-23 15:41:37 616,960 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll - 2004-08-03 22:44:14 417,792 -c–a-w C:\WINDOWS\system32\dllcache\vbscript.dll + 2007-12-18 14:42:55 417,792 -c–a-w C:\WINDOWS\system32\dllcache\vbscript.dll - 2008-04-21 07:03:59 662,016 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll + 2008-06-23 15:41:38 662,016 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll - 2008-07-10 09:02:36 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys + 2008-04-16 12:23:44 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys + 2008-01-29 16:29:38 32,784 ----a-w C:\WINDOWS\system32\drivers\klbg.sys - 2007-12-28 17:51:04 195,344 ----a-w C:\WINDOWS\system32\drivers\klif.sys + 2008-08-09 13:17:37 187,920 ----a-w C:\WINDOWS\system32\drivers\klif.sys - 2007-12-13 11:28:40 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys + 2008-03-25 18:07:10 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys - 2008-02-08 16:35:42 23,604 ----a-w C:\WINDOWS\system32\drivers\klopp.dat + 2008-04-25 16:21:06 26,964 ----a-w C:\WINDOWS\system32\drivers\klopp.dat - 2008-04-21 07:03:50 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll + 2008-06-23 15:41:36 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll - 2008-04-21 07:03:50 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll + 2008-06-23 15:41:36 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll - 2008-04-21 07:03:50 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll + 2008-06-23 15:41:36 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll - 2008-07-10 08:19:33 93,480 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT + 2008-08-05 06:15:25 91,888 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT - 2008-04-21 07:03:51 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll + 2008-06-23 15:41:36 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll - 2004-08-03 22:44:00 678,400 ----a-w C:\WINDOWS\system32\inetcomm.dll + 2008-04-11 18:51:52 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll - 2008-04-21 07:03:51 96,768 ----a-w C:\WINDOWS\system32\inseng.dll + 2008-06-23 15:41:36 96,768 ----a-w C:\WINDOWS\system32\inseng.dll + 2008-06-09 23:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe + 2008-06-09 23:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe + 2008-06-10 00:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe - 2004-08-03 22:44:02 450,560 ----a-w C:\WINDOWS\system32\jscript.dll + 2007-12-18 14:42:55 450,560 ----a-w C:\WINDOWS\system32\jscript.dll - 2008-04-21 07:03:51 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll + 2008-06-23 15:41:36 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll - 2008-02-08 16:37:44 219,664 ----a-w C:\WINDOWS\system32\klogon.dll + 2008-04-25 16:22:24 206,088 ----a-w C:\WINDOWS\system32\klogon.dll - 2008-06-25 07:15:48 17,972,344 ----a-w C:\WINDOWS\system32\MRT.exe + 2008-08-05 18:11:01 15,888,504 ----a-w C:\WINDOWS\system32\MRT.exe - 2008-04-21 07:03:55 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll + 2008-06-23 15:41:37 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll - 2008-04-21 07:03:56 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll + 2008-06-23 15:41:37 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll - 2008-04-21 07:03:56 146,432 ----a-w C:\WINDOWS\system32\msrating.dll + 2008-06-23 15:41:37 146,432 ----a-w C:\WINDOWS\system32\msrating.dll - 2008-04-21 07:03:56 532,480 ----a-w C:\WINDOWS\system32\mstime.dll + 2008-06-23 15:41:37 532,480 ----a-w C:\WINDOWS\system32\mstime.dll - 2008-04-21 07:03:56 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll + 2008-06-23 15:41:37 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll - 2008-04-21 07:03:57 1,494,528 ----a-w C:\WINDOWS\system32\shdocvw.dll + 2008-06-23 15:41:37 1,494,528 ----a-w C:\WINDOWS\system32\shdocvw.dll - 2008-04-21 07:03:58 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll + 2008-06-23 15:41:37 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll - 2007-11-30 11:21:28 19,320 ------w C:\WINDOWS\system32\spmsg.dll + 2007-11-30 12:40:46 19,320 ------w C:\WINDOWS\system32\spmsg.dll - 2008-03-27 09:24:20 60,416 ------w C:\WINDOWS\system32\tzchange.exe + 2008-07-14 11:09:18 62,976 ------w C:\WINDOWS\system32\tzchange.exe - 2008-04-21 07:03:58 616,960 ----a-w C:\WINDOWS\system32\urlmon.dll + 2008-06-23 15:41:37 616,960 ----a-w C:\WINDOWS\system32\urlmon.dll - 2004-08-03 22:44:14 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll + 2007-12-18 14:42:55 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll - 2008-04-17 11:03:57 369,152 ------w C:\WINDOWS\system32\xpsp3res.dll + 2008-07-03 09:42:47 369,152 ----a-w C:\WINDOWS\system32\xpsp3res.dll . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search Destroy\TeaTimer.exe” [2008-07-07 09:42 2156368] “BySoft FreeRAM”=“C:\Program Files\BySoft FreeRAM\FreeRAM.exe” [2007-09-28 14:32 318976] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SpeedTouch USB Diagnostics”=“C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” [2004-01-26 11:38 866816] “NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2005-12-10 13:06 7311360] “NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2005-12-10 13:06 86016] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50 155648] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe” [2008-06-10 04:27 144784] “AVP”=“C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe” [2008-04-25 18:21 201992] “nwiz”=“nwiz.exe” [2005-12-10 13:06 1519616 C:\WINDOWS\system32\nwiz.exe] “SoundMan”=“SOUNDMAN.EXE” [2004-12-22 11:09 77824 C:\WINDOWS\SOUNDMAN.EXE] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoResolveTrack”= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoResolveTrack”= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] “DisableMonitoring”=dword:00000001 [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\system32\sessmgr.exe”= “C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 7.0.1.325\Polish\setup.exe”= “F:\Program Files\eMule\emule.exe”= “C:\Program Files\Opera\opera.exe”= “E:\Program Files\Tibia\Tibia.exe”= “C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\Polish\setup.exe”= “E:\Program Files\SopCast\SopCast.exe”= “E:\Program Files\SopCast\adv\SopAdver.exe”= “C:\Program Files\Tlen.pl\tlen.exe”= R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29] R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07] . . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Documents and Settings\Ja\Dane aplikacji\Mozilla\Firefox\Profiles\6y1vyhr2.default\ . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-21 16:13:48 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\rundll32.exe . ************************************************************************** . Completion time: 2008-08-21 16:17:15 - machine was rebooted ComboFix-quarantined-files.txt 2008-08-21 14:16:43 Pre-Run: 14,998,986,752 bajtów wolnych Post-Run: 14,950,318,080 bajt˘w wolnych 265 — E O F — 2008-08-13 21:14:21 Czy proces Isass.exe jest bezpieczny. Co może być przyczyną wolnej pracy komputera. Czy dokupienie pamieci naprawiło by ten problem. Pozdrawiam