06-11-29 15:04:02,87 Dodatek Service Pack 2 ComboFix 06.11.27W - Running from: “C:\Documents and Settings\Pulpit” ((((((((((((((((((((((((((((((( Files Created from 2006-10-29 to 2006-11-29 )))))))))))))))))))))))))))))))))) 2006-11-29 15:03 2006-11-29 11:04 53,248 --a------ C:\WINDOWS\system32\Process.exe 2006-11-29 11:04 40,960 --a------ C:\WINDOWS\system32\swsc.exe 2006-11-29 11:04 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2006-11-29 11:04 2,244 --a------ C:\WINDOWS\system32\tmp.reg 2006-11-29 11:04 135,168 --a------ C:\WINDOWS\system32\swreg.exe 2006-11-20 14:44 61,952 --------- C:\WINDOWS\system32\icardie.dll 2006-11-20 14:44 6,049,280 --------- C:\WINDOWS\system32\ieframe.dll 2006-11-20 14:44 50,688 --------- C:\WINDOWS\system32\msfeedsbs.dll 2006-11-20 14:44 458,752 --------- C:\WINDOWS\system32\msfeeds.dll 2006-11-20 14:44 380,928 --------- C:\WINDOWS\system32\ieapfltr.dll 2006-11-20 14:44 266,752 --------- C:\WINDOWS\system32\iertutil.dll 2006-11-20 14:44 206,336 --------- C:\WINDOWS\system32\WinFXDocObj.exe 2006-11-20 14:44 180,736 --------- C:\WINDOWS\system32\ieui.dll 2006-11-20 14:44 13,312 --a------ C:\WINDOWS\system32\ieudinit.exe 2006-11-20 14:44 12,288 --------- C:\WINDOWS\system32\msfeedssync.exe 2006-11-20 14:44 2006-11-20 14:44 2006-11-20 14:44 2006-11-20 14:44 2006-11-20 14:43 536,888 --a------ C:\WINDOWS\system32\xmllitesetup.exe 2006-11-20 14:43 20,480 --a------ C:\WINDOWS\system32\normaliz.dll 2006-11-20 14:43 121,856 --------- C:\WINDOWS\system32\xmllite.dll 2006-11-19 23:31 577,536 --a------ C:\WINDOWS\system32\SWISSLib.dll 2006-11-19 23:31 57,344 --a------ C:\WINDOWS\system32\HtmlLib.dll 2006-11-19 23:31 3,235,840 --a------ C:\WINDOWS\system32\SWISS_ENG_RES.dll 2006-11-19 23:31 1,183,744 --a------ C:\WINDOWS\system32\SWISSD_ENG_RES.dll 2006-11-19 23:30 2006-11-18 21:55 2006-11-14 13:48 2006-11-09 15:11 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll 2006-11-09 15:11 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll 2006-11-09 15:10 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe 2006-11-09 15:10 194,320 --a------ C:\WINDOWS\system32\qcut.dll 2006-11-09 15:10 10,240 --a------ C:\WINDOWS\system32\vidx16.dll 2006-11-09 15:09 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll 2006-11-09 15:09 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll 2006-11-05 22:22 2006-11-05 22:17 2006-10-30 17:29 2006-10-30 17:00 2006-10-30 17:00 2006-10-29 22:38 2006-10-29 22:38 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-11-29 14:27 -------- d-------- C:\Documents and Settings\Dane aplikacji\Skype 2006-11-29 14:15 -------- d-------- C:\Documents and Settings\Dane aplikacji\Desktop Sidebar 2006-11-29 11:13 -------- d-------- C:\Documents and Settings\Dane aplikacji\Tlen.pl 2006-11-26 16:28 -------- d-------- C:\Documents and Settings\Dane aplikacji\foobar2000 2006-11-20 14:48 -------- d-------- C:\Program Files\Internet Explorer 2006-11-18 15:24 -------- d-------- C:\Documents and Settings\Dane aplikacji\Canon 2006-11-15 23:40 -------- d-------- C:\Program Files\Common Files 2006-11-14 13:48 -------- d–h----- C:\Program Files\InstallShield Installation Information 2006-11-09 15:10 -------- d-------- C:\Program Files\Windows Media Player 2006-11-07 15:33 -------- d-------- C:\Program Files\Mozilla Firefox 2006-10-30 21:23 -------- d-------- C:\Program Files\Common Files\Adobe 2006-10-30 17:30 -------- d-------- C:\Program Files\Common Files\Microsoft Shared 2006-10-30 17:30 -------- d-------- C:\Program Files\Common Files\DESIGNER 2006-10-30 17:00 -------- d-------- C:\Program Files\Common Files\InstallShield 2006-10-30 12:11 -------- d—s---- C:\Documents and Settings\Dane aplikacji\Microsoft 2006-10-29 22:44 -------- d-------- C:\Documents and Settings\Dane aplikacji\Adobe 2006-10-29 22:42 -------- d-------- C:\Program Files\Adobe 2006-10-28 22:36 10752 --a------ C:\WINDOWS\system32\BASSMOD.dll 2006-10-28 22:29 5 --ahs---- C:\WINDOWS\system32\adcfafafdde1_s.dll 2006-10-20 18:42 20096 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys 2006-10-18 12:47 -------- d-------- C:\Program Files\AutoPatcher 2006-10-18 00:04 -------- d-------- C:\Documents and Settings\Dane aplikacji\PWNEncy2005 2006-10-17 19:10 -------- d-------- C:\Program Files\Common Files\Ahead 2006-10-17 13:33 413696 --a------ C:\WINDOWS\system32\vbscript.dll 2006-10-17 13:33 231424 --a------ C:\WINDOWS\system32\webcheck.dll 2006-10-17 13:33 156160 --a------ C:\WINDOWS\system32\msls31.dll 2006-10-17 13:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll 2006-10-17 13:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll 2006-10-17 13:05 105984 --a------ C:\WINDOWS\system32\url.dll 2006-10-17 13:04 101376 --a------ C:\WINDOWS\system32\occache.dll 2006-10-17 13:03 17408 --a------ C:\WINDOWS\system32\corpol.dll 2006-10-17 13:01 71680 --a------ C:\WINDOWS\system32\admparse.dll 2006-10-17 13:01 55296 --a------ C:\WINDOWS\system32\iesetup.dll 2006-10-17 13:01 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll 2006-10-17 13:01 229376 --a------ C:\WINDOWS\system32\ieaksie.dll 2006-10-17 13:01 152064 --a------ C:\WINDOWS\system32\ieakeng.dll 2006-10-17 13:00 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe 2006-10-17 13:00 43008 --a------ C:\WINDOWS\system32\iernonce.dll 2006-10-17 13:00 123904 --a------ C:\WINDOWS\system32\advpack.dll 2006-10-17 12:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll 2006-10-17 12:56 45568 --a------ C:\WINDOWS\system32\mshta.exe 2006-10-17 12:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll 2006-10-17 12:23 161792 --a------ C:\WINDOWS\system32\ieakui.dll 2006-10-12 19:17 61072 --a------ C:\WINDOWS\system32\drivers\klick.sys 2006-10-12 19:17 59536 --a------ C:\WINDOWS\system32\drivers\klin.sys 2006-10-07 14:52 -------- d-------- C:\Program Files\WinFast 2006-09-29 08:17 -------- d-------- C:\Program Files\Techland 2006-09-22 07:30 126976 --------- C:\WINDOWS\system32\fppr332.dll 2006-09-18 12:13 307200 --------- C:\WINDOWS\system32\fppmon3.dll 2006-09-13 15:22 561761 --a------ C:\WINDOWS\pharmag time&date v2.0 OK.scr 2006-09-13 15:17 572098 --a------ C:\WINDOWS\Koma Nord - v3.scr 2006-09-13 15:15 634134 --a------ C:\WINDOWS\Czas Europa.scr 2006-09-08 12:03 1826816 --a------ C:\WINDOWS\system32\DobreProgramyPirat.scr 2006-09-08 10:45 28672 --a------ C:\WINDOWS\system32\DobreProgramyClassic.scr 2006-09-06 17:43 22752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2006-08-07 22:20 2508 --a------ C:\Documents and Settings\Dane aplikacji$_hpcst$.hpc (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “Komunikator”=“D:\Program Files\Tlen.pl\tlen.exe” “SIDEBAR”="“D:\Program Files\Desktop Sidebar\dsidebar.exe”" “H/PC Connection Agent”="“D:\Program Files\Microsoft ActiveSync\wcescomm.exe”" “AnyDVD”=“D:\Program Files\SlySoft\AnyDVD\AnyDVD.exe” “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” “D:\Program Files\NetMeter\NetMeter.exe”=“D:\Program Files\NetMeter\NetMeter.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “kis”="“D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe”" “{0228e555-4f9c-4e35-a3ec-b109a192b4c2}”=“D:\Program Files\Google\Gmail Notifier\gnotify.exe” “hmonitor”=“D:\Program Files\HardwareMonitor\hmonitor.exe” “KernelFaultCheck”=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\ 65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00 “WinFast Schedule”=“C:\Program Files\WinFast\WFTVFM\WFWIZ.exe” @="" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex] “Flag”=dword:00000002 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] “DeskHtmlVersion”=dword:00000110 “DeskHtmlMinorVersion”=dword:00000005 “Settings”=dword:00000001 “GeneralFlags”=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] “Source”=“About:Home” “SubscribedURL”=“About:Home” “FriendlyName”=“Moja bieżąca strona główna” “Flags”=dword:00000002 “Position”=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 “CurrentState”=hex:04,00,00,40 “OriginalStateInfo”=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 “RestoredStateInfo”=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] “{438755C2-A8BA-11D1-B96B-00A0C90312E1}”=“Moduł wstępnego ładowania interfejsu Browseui” “{8C7461EF-2B13-11d2-BE35-3078302C2030}”=“Demon buforu kategorii składników” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{AEB6717E-7E19-11d0-97EE-00C04FD91972}”="" “{81559C35-8464-49F7-BB0E-07A383BEF910}”="" “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“ewido anti-spyware 4.0” [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 “NoNetHood”=hex:01,00,00,00 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “dontdisplaylastusername”=dword:00000000 “legalnoticecaption”="" “legalnoticetext”="" “shutdownwithoutlogon”=dword:00000001 “undockwithoutlogon”=dword:00000001 [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] “PostBootReminder”="{7849596a-48ea-486e-8937-a2a3009f31a9}" “CDBurn”="{fbeb8a05-beee-4442-804e-409d6c4515e9}" “WebCheck”="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" “SysTray”="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” Completion time: 06-11-29 15:05:38.67 C:\ComboFix.txt … 06-11-29 15:05