“dworek admiral” - 07-01-26 13:18:01 Dodatek Service Pack 2 ComboFix 07-01-25 - Running from: “C:\Documents and Settings\dworek admiral\Moje dokumenty” (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\adir.dll C:\WINDOWS\system32\taskdir.exe C:\WINDOWS\system32\zlbw.dll ((((((((((((((((((((((((((((((( Files Created from 2006-12-26 to 2007-01-26 )))))))))))))))))))))))))))))))))) 2007-01-26 12:49 2007-01-26 12:49 2007-01-26 12:47 235 --a------ C:\WINDOWS\gmer.reg 2007-01-26 12:19 48,259 —h----- C:\WINDOWS\system32\alsys.exe 2007-01-26 11:38 80 --a------ C:\WINDOWS\gmer_uninstall.cmd 2007-01-26 01:10 2007-01-26 00:59 21,840 --a----t- C:\WINDOWS\system32\SIntfNT.dll 2007-01-26 00:59 17,212 --a----t- C:\WINDOWS\system32\SIntf32.dll 2007-01-26 00:59 12,067 --a----t- C:\WINDOWS\system32\SIntf16.dll 2007-01-25 14:26 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe 2007-01-25 14:26 718 --a------ C:\WINDOWS\system32\tmp.reg 2007-01-25 14:26 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-01-25 14:26 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2007-01-25 14:26 40,960 --a------ C:\WINDOWS\system32\swsc.exe 2007-01-25 14:26 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2007-01-25 14:26 135,168 --a------ C:\WINDOWS\system32\swreg.exe 2007-01-25 13:34 2007-01-25 13:27 2007-01-24 23:03 54,382 --a------ C:\WINDOWS\system32\game.exe 2007-01-24 15:33 2007-01-24 14:20 2007-01-24 14:20 2007-01-24 14:20 2007-01-24 14:20 2007-01-24 14:20 2007-01-24 14:20 2007-01-24 14:20 2007-01-24 14:04 2007-01-24 14:04 2007-01-24 14:04 2007-01-24 14:04 2007-01-24 14:02 2007-01-24 14:02 2007-01-24 14:02 2007-01-24 13:49 54,382 --a------ C:\WINDOWS\system32\game0.exe 2007-01-24 13:10 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-01-24 13:10 2007-01-24 12:25 2007-01-24 12:22 2007-01-24 12:22 2007-01-24 12:22 2007-01-24 12:22 2007-01-24 12:22 2007-01-24 12:22 2007-01-24 12:22 2007-01-24 10:06 2007-01-24 10:05 2007-01-23 18:04 30,720 --a------ C:\WINDOWS\system32\nmwcdcocls.dll 2007-01-23 18:04 2007-01-23 18:04 2007-01-23 18:03 2007-01-22 20:18 48,259 --a------ C:\WINDOWS\system32\game3.exe 2007-01-22 12:00 719,088 --a------ C:\WINDOWS\system32\SkanerOnline.dll 2007-01-19 09:40 89,088 --a------ C:\WINDOWS\system32\SkanerOnlineUninstall.exe 2007-01-19 09:23 6,307 --a------ C:\WINDOWS\system32\game4.exe 2007-01-19 09:23 6,307 --a------ C:\WINDOWS\system32\clcbt.exe 2007-01-19 09:23 6,307 --a------ C:\WINDOWS\system32\adirss.exe 2007-01-19 09:23 6,275 --a------ C:\WINDOWS\system32\game2.exe 2007-01-19 09:23 6,275 --a------ C:\WINDOWS\system32\game1.exe 2007-01-16 21:01 2007-01-11 10:46 2007-01-07 21:59 2006-12-26 01:28 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-26 10:18 -------- d-------- C:\Program Files\mozilla firefox 2007-01-26 03:32 -------- d-------- C:\Program Files\windows nt 2007-01-26 03:32 -------- d-------- C:\Program Files\winamp 2007-01-26 03:32 -------- d-------- C:\Program Files\pc connectivity solution 2007-01-26 03:32 -------- d-------- C:\Program Files\my downloaded games 2007-01-26 03:31 -------- d-------- C:\Program Files\messenger 2007-01-26 03:31 -------- d-------- C:\Program Files\gadu-gadu 2007-01-26 03:31 -------- d-------- C:\Program Files\dosbox-0.65 2007-01-26 03:31 -------- d-------- C:\Program Files\brownie 2007-01-26 01:06 -------- d–h----- C:\Program Files\installshield installation information 2007-01-25 23:37 -------- d-------- C:\DOCUME~1\DWOREK~1\Dane aplikacji\openoffice.org2 2007-01-25 17:18 -------- d-------- C:\Program Files\ganymedenet 2007-01-22 21:08 -------- d-------- C:\Program Files\Common Files\real 2007-01-14 17:55 -------- d-------- C:\DOCUME~1\DWOREK~1\Dane aplikacji\nokia 2006-12-25 16:32 -------- d-------- C:\Program Files\nokia pc suite 6 2006-12-25 16:32 -------- d-------- C:\Program Files\gimp-2.0 2006-12-25 15:24 -------- d-------- C:\Program Files\globalmapper8 2006-12-25 14:39 -------- d-------- C:\DOCUME~1\DWOREK~1\Dane aplikacji\datalayer 2006-12-25 14:38 -------- d-------- C:\DOCUME~1\DWOREK~1\Dane aplikacji\pc suite 2006-12-25 14:31 -------- d-------- C:\Program Files\difx 2006-12-10 05:44 -------- d-------- C:\Program Files\orban 2006-12-07 06:29 2374472 --a------ C:\WINDOWS\system32\wmvcore.dll 2006-12-05 12:27 -------- d-------- C:\Program Files\Common Files\adobe 2006-12-05 12:15 -------- d-------- C:\Program Files\boonty 2006-11-30 12:27 -------- d-------- C:\DOCUME~1\DWOREK~1\Dane aplikacji\adobe 2006-11-30 03:46 -------- d-------- C:\DOCUME~1\DWOREK~1\Dane aplikacji\ganymedenet 2006-11-29 18:09 -------- d-------- C:\Program Files\aod 2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll 2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll 2006-10-26 22:27 0 --a------ C:\DOCUME~1\DWOREK~1\Dane aplikacji\avsdvdplayer.m3u (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “KernelFaultCheck”=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\ 65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk” “backup”=“C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE " “item”=“Adobe Reader Speed Launch” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Service Manager.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Service Manager.lnk” “backup”=“C:\WINDOWS\pss\Service Manager.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\MICROS~2\80\Tools\Binn\sqlmangr.exe /n” “item”=“Service Manager” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Skrót do internet.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Skrót do internet.lnk” “backup”=“C:\WINDOWS\pss\Skrót do internet.lnkCommon Startup” “location”=“Common Startup” “command”=“D:\HOTEL\internet.exe " “item”=“Skrót do internet” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^dworek admiral^Menu Start^Programy^Autostart^OpenOffice.org 2.0.lnk] “path”=“C:\Documents and Settings\dworek admiral\Menu Start\Programy\Autostart\OpenOffice.org 2.0.lnk” “backup”=“C:\WINDOWS\pss\OpenOffice.org 2.0.lnkStartup” “location”=“Startup” “command”=“C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe " “item”=“OpenOffice.org 2.0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg!AVG Anti-Spyware] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“avgas” “hkey”=“HKLM” “command”=”“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\clcbt.exe] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“clcbt” “hkey”=“HKLM” “command”=“C:\WINDOWS\system32\clcbt.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CS DVD Player 3] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“CS DVD Player 3” “hkey”=“HKCU” “command”=“C:\Program Files\CS Corporation\CS DVD Player 3 PRO\CS DVD Player 3.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“ctfmon” “hkey”=“HKCU” “command”=“C:\WINDOWS\system32\ctfmon.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“HDAShCut” “hkey”=“HKLM” “command”=“HDAShCut.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“dumprep 0 -k” “hkey”=“HKLM” “command”=”%systemroot%\system32\dumprep 0 -k" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“msmsgs” “hkey”=“HKCU” “command”="“C:\Program Files\Messenger\msmsgs.exe” /background" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NeroCheck” “hkey”=“HKLM” “command”=“C:\WINDOWS\system32\NeroCheck.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NvCpl” “hkey”=“HKLM” “command”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NvMcTray” “hkey”=“HKLM” “command”=“RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“nwiz” “hkey”=“HKLM” “command”=“nwiz.exe /install” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“qttask” “hkey”=“HKLM” “command”="“C:\Program Files\QuickTime\qttask.exe” -atboottime" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“jusched” “hkey”=“HKLM” “command”=“C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“GoogleToolbarNotifier” “hkey”=“HKCU” “command”=“C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sysinter] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“adirss” “hkey”=“HKLM” “command”=“C:\WINDOWS\system32\adirss.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“winampa” “hkey”=“HKLM” “command”=“C:\Program Files\Winamp\winampa.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “ServiceLayer”=dword:00000003 “NVSvc”=dword:00000002 “DFSerwis”=dword:00000002 “Boonty Games”=dword:00000003 “Adobe LM Service”=dword:00000003 “AVG Anti-Spyware Guard”=dword:00000002 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“AVG Anti-Spyware 7.5” [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “taskdir”=“C:\WINDOWS\system32\taskdir.exe” “Agent”=“C:\WINDOWS\system32\alsys.exe” [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] “taskdir”=“C:\WINDOWS\system32\taskdir.exe” “Agent”=“C:\WINDOWS\system32\alsys.exe” [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 Completion time: 07-01-26 13:19:06