ComboFix 06.11.27 - Running from: “C:\Documents and Settings-BzzyK-\Pulpit” ((((((((((((((((((((((((((((((( Files Created from 2006-11-18 to 2006-12-18 )))))))))))))))))))))))))))))))))) 2006-12-18 20:00 2006-12-18 18:59 2006-12-18 18:59 2006-12-14 01:37 2006-12-14 01:36 2006-12-14 01:36 2006-12-14 01:36 2006-12-14 01:26 2006-12-13 22:42 2006-12-13 22:38 2006-12-13 09:07 2006-12-12 12:26 2006-12-10 02:38 2006-12-09 18:15 2006-12-09 18:14 10,578 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2006-12-09 18:14 2006-12-07 12:46 2006-12-07 12:46 2006-12-04 22:55 2006-12-03 21:14 327,168 --a------ C:\WINDOWS\IsUn0415.exe 2006-12-03 21:12 2006-12-02 14:17 7,552 --a------ C:\WINDOWS\system32\drivers\enodpl.sys 2006-12-02 14:17 4,736 --a------ C:\WINDOWS\system32\drivers\tandpl.sys 2006-11-29 20:04 2006-11-26 16:34 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2006-11-26 16:09 223,128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys 2006-11-26 16:09 2006-11-26 16:04 89,984 --a------ C:\WINDOWS\system32\drivers\sptd4349.sys 2006-11-26 16:04 643,072 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2006-11-25 13:59 2006-11-24 19:15 21,760 --a------ C:\WINDOWS\system32\drivers\USBSTOR.SYS (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-12-18 20:10 -------- d-------- C:\Program Files\Mozilla Firefox 2006-12-18 15:13 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\teamspeak2 2006-12-17 16:59 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\Hamachi 2006-12-17 14:11 -------- d-------- C:\Program Files\NetMeeting 2006-12-14 01:37 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\Media Player Classic 2006-12-13 01:52 -------- d-------- C:\Program Files\Gadu-Gadu 2006-12-12 12:26 -------- d—s---- C:\Documents and Settings-BzzyK-\Dane aplikacji\Microsoft 2006-12-07 13:15 -------- d-------- C:\Program Files\Common Files\Adobe 2006-12-07 12:46 -------- d-------- C:\Program Files\Common Files\Symantec Shared 2006-12-07 12:46 -------- d-------- C:\Program Files\Common Files 2006-12-03 20:53 -------- d–h----- C:\Program Files\InstallShield Installation Information 2006-11-13 00:58 -------- d-------- C:\Program Files\WinRAR 2006-11-12 13:26 -------- d-------- C:\Program Files\xp-AntiSpy 2006-11-12 13:14 -------- d-------- C:\Program Files\Common Files\Microsoft Shared 2006-11-12 13:13 -------- d-------- C:\Program Files\Microsoft Works 2006-11-12 13:13 -------- d-------- C:\Program Files\Microsoft Office 2006-11-12 13:13 -------- d-------- C:\Program Files\Common Files\DESIGNER 2006-11-12 13:09 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\Mozilla 2006-11-11 22:54 -------- d-------- C:\Program Files\Windows Media Player 2006-11-11 21:30 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\Macromedia 2006-11-11 12:32 -------- d-------- C:\Program Files\Teamspeak2_RC2 2006-11-11 12:13 -------- d-------- C:\Program Files\ToniArts 2006-11-11 12:12 -------- d-------- C:\Program Files\Common Files\InstallShield 2006-11-11 12:10 -------- d-------- C:\Program Files\Lavasoft 2006-11-11 12:03 -------- d-------- C:\Program Files\Sunbelt Software 2006-11-11 11:51 1284 --a------ C:\WINDOWS\system32\dobe851d.sys 2006-11-11 11:50 8464 --a------ C:\WINDOWS\system32\sporder.dll 2006-11-11 11:49 729088 --a------ C:\WINDOWS\system32\directxclickers.exe 2006-11-11 11:49 6656 --a------ C:\WINDOWS\system32\directxclks.sys 2006-11-11 11:47 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\Symantec 2006-11-11 11:38 -------- d-------- C:\Program Files\Kerio 2006-11-11 11:31 -------- d-------- C:\Program Files\Thomson 2006-11-11 11:31 -------- d-------- C:\Program Files\Neostrada TP 2006-11-09 13:31 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys 2006-11-07 21:28 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\ATI 2006-11-07 21:24 -------- d-------- C:\Program Files\ATI Technologies 2006-11-07 21:22 -------- d-------- C:\Program Files\Internet Explorer 2006-11-07 21:10 -------- d-------- C:\Program Files\CyberLink DVD Solution 2006-11-07 13:43 -------- d-------- C:\Program Files\Adobe 2006-11-07 13:43 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\InterTrust 2006-11-07 13:43 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\Adobe 2006-11-07 13:41 -------- d-------- C:\Program Files\Ahead 2006-11-07 13:40 -------- d-------- C:\Program Files\Common Files\Ahead 2006-11-07 13:38 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\CyberLink 2006-11-07 13:36 -------- d-------- C:\Program Files\CyberLink 2006-11-07 13:32 -------- d-------- C:\Program Files\K-Lite Codec Pack 2006-11-07 13:23 451072 --a------ C:\WINDOWS\Radeon Omega Drivers v3.8.252 Uninstall.exe 2006-11-07 13:20 -------- d-------- C:\Program Files\C-Media 3D Audio 2006-11-07 13:16 -------- d–h----- C:\Program Files\Uninstall Information 2006-11-07 13:16 -------- d-------- C:\Documents and Settings-BzzyK-\Dane aplikacji\Identities 2006-11-07 13:14 -------- d–h----- C:\Program Files\WindowsUpdate 2006-11-07 13:10 -------- d-------- C:\Program Files\xerox 2006-11-07 13:10 -------- d-------- C:\Program Files\microsoft frontpage 2006-11-07 13:09 0 -rahs---- C:\MSDOS.SYS 2006-11-07 13:09 0 -rahs---- C:\IO.SYS 2006-11-07 13:09 0 --a------ C:\CONFIG.SYS 2006-11-07 13:09 0 --a------ C:\AUTOEXEC.BAT 2006-11-07 13:07 -------- d-------- C:\Program Files\Movie Maker 2006-11-07 13:06 -------- d-------- C:\Program Files\Outlook Express 2006-11-07 13:06 -------- d-------- C:\Program Files\Common Files\System 2006-11-07 13:06 -------- d-------- C:\Program Files\Common Files\Services 2006-11-07 13:06 -------- d-------- C:\Program Files\Common Files\MSSoap 2006-11-07 13:05 -------- d-------- C:\Program Files\MSN 2006-11-07 13:04 -------- d-------- C:\Program Files\Windows NT 2006-11-07 13:04 -------- d-------- C:\Program Files\MSN Gaming Zone 2006-11-07 12:56 62 --ahs---- C:\Documents and Settings-BzzyK-\Dane aplikacji\desktop.ini 2006-11-07 12:56 -------- d-------- C:\Program Files\Common Files\SpeechEngines 2006-11-07 12:56 -------- d-------- C:\Program Files\Common Files\ODBC (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “Gadu-Gadu”="“C:\Program Files\Gadu-Gadu\gg.exe” /tray" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “Cmaudio”=“RunDll32 cmicnfg.cpl,CMICtrlWnd” “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] “DeskHtmlVersion”=dword:00000110 “DeskHtmlMinorVersion”=dword:00000005 “Settings”=dword:00000001 “GeneralFlags”=dword:00000005 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] “Source”=“About:Home” “SubscribedURL”=“About:Home” “FriendlyName”=“Moja bieżąca strona główna” “Flags”=dword:00000002 “Position”=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 “CurrentState”=hex:04,00,00,40 “OriginalStateInfo”=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,\ 00,00,04,00,00,40 “RestoredStateInfo”=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,\ 00,00,01,00,00,00 [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” “Microsoft Directx clicks”=“directxclickers.exe” [HKEY_USERS.default\software\microsoft\windows\currentversion\runservices] “Microsoft Directx clicks”=“directxclickers.exe” [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” “Microsoft Directx clicks”=“directxclickers.exe” [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runservices] “Microsoft Directx clicks”=“directxclickers.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] “{438755C2-A8BA-11D1-B96B-00A0C90312E1}”=“Moduł wstępnego ładowania interfejsu Browseui” “{8C7461EF-2B13-11d2-BE35-3078302C2030}”=“Demon buforu kategorii składników” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{AEB6717E-7E19-11d0-97EE-00C04FD91972}”="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “dontdisplaylastusername”=dword:00000000 “legalnoticecaption”="" “legalnoticetext”="" “shutdownwithoutlogon”=dword:00000001 “undockwithoutlogon”=dword:00000001 [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] “PostBootReminder”="{7849596a-48ea-486e-8937-a2a3009f31a9}" “CDBurn”="{fbeb8a05-beee-4442-804e-409d6c4515e9}" “WebCheck”="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" “SysTray”="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” Contents of the ‘Scheduled Tasks’ folder C:\WINDOWS\tasks\Symantec NetDetect.job Completion time: 06-12-18 20:32:06.21 C:\ComboFix.txt … 06-12-18 20:32