Administrator - 06-10-21 22:05:04,15 Dodatek Service Pack 2 ComboFix 06.10.19 - Running from: “D:\instalki” ((((((((((((((((((((((((((((((( Files Created from 2006-09-21 to 2006-10-21 )))))))))))))))))))))))))))))))))) 2006-10-17 17:31 545 --a------ C:\WINDOWS\UC.PIF 2006-10-17 17:31 545 --a------ C:\WINDOWS\RAR.PIF 2006-10-17 17:31 545 --a------ C:\WINDOWS\PKZIP.PIF 2006-10-17 17:31 545 --a------ C:\WINDOWS\PKUNZIP.PIF 2006-10-17 17:31 545 --a------ C:\WINDOWS\NOCLOSE.PIF 2006-10-17 17:31 545 --a------ C:\WINDOWS\LHA.PIF 2006-10-17 17:31 545 --a------ C:\WINDOWS\ARJ.PIF (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-10-14 14:14 -------- d-------- C:\Program Files\Wolfenstein - Enemy Territory 2006-10-13 18:57 61072 --a------ C:\WINDOWS\system32\drivers\klick.sys 2006-10-13 18:57 59536 --a------ C:\WINDOWS\system32\drivers\klin.sys 2006-10-13 18:45 -------- d-------- C:\Program Files\Kaspersky Lab 2006-10-03 16:48 -------- d-------- C:\Program Files\Gadu-Gadu 2006-09-24 13:05 -------- d-------- C:\Program Files\Mozilla Firefox 2006-09-24 13:05 -------- d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla 2006-09-14 15:24 -------- d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Help 2006-09-13 07:07 1084416 --a------ C:\WINDOWS\system32\msxml3.dll 2006-09-12 22:38 -------- d-------- C:\Program Files\Ares 2006-09-12 22:30 -------- d-------- C:\Program Files\Soulseek 2006-09-11 22:09 -------- d-------- C:\Program Files\eMule 2006-09-11 00:25 -------- d-------- C:\Program Files\BearFlix 2006-09-10 23:08 -------- d-------- C:\Program Files\Shareaza 2006-09-10 23:08 -------- d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Shareaza 2006-09-10 13:34 -------- d-------- C:\Program Files\BearShare 2006-08-31 23:11 -------- d-------- C:\Program Files\Ultimate Systems 2006-08-25 17:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll 2006-08-23 00:11 -------- d-------- C:\Program Files\Opera 2006-08-21 14:28 16896 --a------ C:\WINDOWS\system32\fltlib.dll 2006-08-21 11:14 23040 --a------ C:\WINDOWS\system32\fltMc.exe 2006-08-21 11:14 128896 --a------ C:\WINDOWS\system32\drivers\fltMgr.sys 2006-08-16 13:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll 2006-07-27 15:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll 2006-07-21 10:29 72704 --a------ C:\WINDOWS\system32\hlink.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” “SoundMan”=“SOUNDMAN.EXE” “NVRaidService”=“C:\WINDOWS\system32\nvraidservice.exe” “nwiz”=“nwiz.exe /install” “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe” “kav”="“C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe”" “NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] “DeskHtmlVersion”=dword:00000110 “DeskHtmlMinorVersion”=dword:00000005 “Settings”=dword:00000001 “GeneralFlags”=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] “Source”=“About:Home” “SubscribedURL”=“About:Home” “FriendlyName”=“Moja bieżąca strona główna” “Flags”=dword:00000002 “Position”=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 “CurrentState”=hex:04,00,00,40 “OriginalStateInfo”=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\ 00,00,04,00,00,40 “RestoredStateInfo”=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] “{438755C2-A8BA-11D1-B96B-00A0C90312E1}”=“Moduł wstępnego ładowania interfejsu Browseui” “{8C7461EF-2B13-11d2-BE35-3078302C2030}”=“Demon buforu kategorii składników” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{AEB6717E-7E19-11d0-97EE-00C04FD91972}”="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “dontdisplaylastusername”=dword:00000000 “legalnoticecaption”="" “legalnoticetext”="" “shutdownwithoutlogon”=dword:00000001 “undockwithoutlogon”=dword:00000001 [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] “PostBootReminder”="{7849596a-48ea-486e-8937-a2a3009f31a9}" “CDBurn”="{fbeb8a05-beee-4442-804e-409d6c4515e9}" “WebCheck”="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" “SysTray”="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” ~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ backup-20061019-235851-331 O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing) backup-20061019-235806-419 O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\2.bin\MGSBAR.DLL (file missing) backup-20061019-235750-921 O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\2.bin\MGSBAR.DLL backup-20060404-234719-763 O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing) Completion time: 06-10-21 22:06:00.39 C:\ComboFix.txt … 06-10-21 22:06