ComboScan v20070306.20 run by KUBA on 2007-04-09 at 10:15:08 Computer is in Normal Mode. -------------------------------------------------------------------------------- – System Restore -------------------------------------------------------------- Successfully created ComboScan Restore Point. – Last 5 Restore Point(s) – 20: 2007-04-09 08:15:11 UTC - RP20 - ComboScan Restore Point 19: 2007-04-08 21:17:31 UTC - RP19 - Punkt kontrolny systemu 18: 2007-04-07 00:02:01 UTC - RP18 - Installed J2SE Runtime Environment 5.0 Update 11 17: 2007-04-06 10:59:11 UTC - RP17 - Software Distribution Service 2.0 16: 2007-04-06 10:26:05 UTC - RP16 - Punkt kontrolny systemu – First Restore Point – 1: 2007-03-26 20:30:55 UTC - RP1 - Punkt kontrolny systemu Performed disk cleanup. – HijackThis (run as KUBA.exe) ------------------------------------------------ Logfile of HijackThis v1.99.1 Scan saved at 10:15:51, on 2007-04-09 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\G DATA\AntiVirus 2007\AVK\AVKService.exe C:\Program Files\G DATA\AntiVirus 2007\AVK\AVKWCtl.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\HPQ\IAM\bin\asghost.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\WINDOWS\SMINST\Scheduler.exe C:\Program Files\G DATA\AntiVirus 2007\AVKTray\AVKTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netia\Net\netianet.exe C:\Program Files\Gadu-Gadu\gg.exe C:\Program Files\Ares\Ares.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\KUBA\Pulpit\comboscan.exe C:\PROGRA~1\HIJACK~1\KUBA.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll O4 - HKLM…\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM…\Run: [soundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe” O4 - HKLM…\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start O4 - HKLM…\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM…\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE O4 - HKLM…\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM…\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM…\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM…\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM…\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM…\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule O4 - HKLM…\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM…\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM…\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe O4 - HKLM…\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe O4 - HKLM…\Run: [scheduler] C:\WINDOWS\SMINST\Scheduler.exe O4 - HKLM…\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM…\Run: [AVKTray] “C:\Program Files\G DATA\AntiVirus 2007\AVKTray\AVKTray.exe” O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU…\Run: [NETIANET] C:\Program Files\Netia\Net\netianet.exe O4 - HKCU…\Run: [Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray O4 - HKCU…\Run: [ares] “C:\Program Files\Ares\Ares.exe” -h O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BTTray.lnk = ? O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Wyślij do interfejsu &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra ‘Tools’ menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com O17 - HKLM\System\CCS\Services\Tcpip…{CEDAB4FE-EEB1-485B-B9B6-DE99D68BE824}: NameServer = 213.241.79.37 83.238.255.76 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: AVKProxy - G DATA Software AG - C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe O23 - Service: AVK Service (AVKService) - G DATA Software AG - C:\Program Files\G DATA\AntiVirus 2007\AVK\AVKService.exe O23 - Service: Strażnik AVK (AVKWCtl) - Unknown owner - C:\Program Files\G DATA\AntiVirus 2007\AVK\AVKWCtl.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe – File Associations ----------------------------------------------------------- .bat - batfile - “%1” %* .chm - chm.file - “C:\WINDOWS\hh.exe” %1 .cmd - cmdfile - “%1” %* .com - comfile - “%1” %* .exe - exefile - “%1” %* .hlp - hlpfile - %SystemRoot%\System32\winhlp32.exe %1 .inf - inffile - %SystemRoot%\System32\NOTEPAD.EXE %1 .ini - inifile - %SystemRoot%\System32\NOTEPAD.EXE %1 .js - JSFile - %SystemRoot%\System32\WScript.exe “%1” %* .lnk - lnkfile - {00021401-0000-0000-C000-000000000046} .pif - piffile - “%1” %* .reg - regfile - regedit.exe “%1” .scr - scrfile - “%1” /S .txt - txtfile - %SystemRoot%\system32\NOTEPAD.EXE %1 .vbs - VBSFile - %SystemRoot%\System32\WScript.exe “%1” %* – Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- 3R ADIHdAudAddService (ADI UAA Function Driver for High Definition Audio Service) - C:\WINDOWS\system32\drivers\ADIHdAud.sys 2S ADILOADER (General Purpose USB Driver (adildr.sys)) - C:\WINDOWS\system32\drivers\adildr.sys 3R adiusbaw (USB ADSL WAN Adapter) - C:\WINDOWS\system32\drivers\adiusbaw.sys 3R AEAudioService (AEAudio Service) - C:\WINDOWS\system32\drivers\aeaudio.sys 3R AgereSoftModem (Agere Systems Soft Modem) - C:\WINDOWS\system32\drivers\AGRSM.sys 3R Arp1394 (Protokół klienta 1394 ARP) - C:\WINDOWS\system32\drivers\arp1394.sys 3R bcm4sbxp (Broadcom 440x 10/100 Integrated Controller) - C:\WINDOWS\system32\drivers\bcm4sbxp.sys 3S btaudio (Urządzenie dźwiękowe Bluetooth) - C:\WINDOWS\system32\drivers\btaudio.sys 3S BTDriver (Sterownik do komunikacji wirtualnej Bluetooth) - C:\WINDOWS\system32\drivers\btport.sys 3R BTKRNL (Licznik magistrali Bluetooth) - C:\WINDOWS\system32\drivers\btkrnl.sys 3S BTWDNDIS (Serwer dostępu do sieci LAN Bluetooth) - C:\WINDOWS\system32\drivers\btwdndis.sys 3S btwmodem (Modem Bluetooth) - C:\WINDOWS\system32\drivers\btwmodem.sys 3S BTWUSB (WIDCOMM USB Bluetooth Driver) - C:\WINDOWS\system32\drivers\btwusb.sys 2R DLABOIOM - C:\WINDOWS\system32\DLA\DLABOIOM.SYS 1R DLACDBHM - C:\WINDOWS\system32\drivers\DLACDBHM.SYS 2R DLADResN - C:\WINDOWS\system32\DLA\DLADResN.SYS 2R DLAIFS_M - C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 2R DLAOPIOM - C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 2R DLAPoolM - C:\WINDOWS\system32\DLA\DLAPoolM.SYS 1R DLARTL_N - C:\WINDOWS\system32\drivers\DLARTL_N.SYS 2R DLAUDFAM - C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 2R DLAUDF_M - C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 0R DRVMCDB - C:\WINDOWS\system32\drivers\DRVMCDB.SYS 2R DRVNDDM - C:\WINDOWS\system32\drivers\DRVNDDM.SYS 1R eabfiltr - C:\WINDOWS\system32\drivers\eabfiltr.sys 3S eabusb - C:\WINDOWS\system32\drivers\EabUsb.sys 3R GDMnIcpt - C:\WINDOWS\system32\drivers\MiniIcpt.sys 2R GDTdiInterceptor - C:\WINDOWS\system32\drivers\GDTdiIcpt.sys 3R GEARAspiWDM - C:\WINDOWS\system32\drivers\GEARAspiWDM.sys 3R HBtnKey - C:\WINDOWS\system32\drivers\CPQBttn.sys 3R HDAudBus (Sterownik magistrali Microsoft UAA dla High Definition Audio) - C:\WINDOWS\system32\drivers\Hdaudbus.sys 3S HidUsb (Sterownik Microsoft klasy HID) - C:\WINDOWS\system32\drivers\hidusb.sys 3R HookCentre - C:\WINDOWS\system32\drivers\HookCentre.sys 3R ialm - C:\WINDOWS\system32\drivers\ialmnt5.sys 0R iaStor (Intel AHCI Controller) - C:\WINDOWS\system32\drivers\iaStor.sys 1R intelppm (Sterownik procesora Intel) - C:\WINDOWS\system32\drivers\intelppm.sys 1R kbdhid (Sterownik klawiatury HID) - C:\WINDOWS\system32\drivers\kbdhid.sys 3S mouhid (Sterownik myszy HID) - C:\WINDOWS\system32\drivers\mouhid.sys 3R NIC1394 (Sterownik sieci 1394) - C:\WINDOWS\system32\drivers\nic1394.sys 0R ohci1394 (Kontroler hosta Texas Instruments IEEE 1394 zgodny z OHCI) - C:\WINDOWS\system32\drivers\ohci1394.sys 0R PxHelp20 - C:\WINDOWS\system32\drivers\pxhelp20.sys 3S Rasirda (WAN Miniport (IrDA)) - C:\WINDOWS\system32\drivers\rasirda.sys 3S SMCIRDA (Sterownik urządzenia SMC IrCC Miniport) - C:\WINDOWS\system32\drivers\smcirda.sys 3S SYMIDSCO - C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20070330.002\symidsco.sys (not found) 3R SynTP (Synaptics TouchPad Driver) - C:\WINDOWS\system32\drivers\SynTP.sys 3R usbehci (Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft) - C:\WINDOWS\system32\drivers\usbehci.sys 3S USBSTOR (Sterownik magazynu masowego USB) - C:\WINDOWS\system32\drivers\USBSTOR.SYS 3R w39n51 (Intel® PRO/Wireless 3945ABG Adapter Driver) - C:\WINDOWS\system32\drivers\w39n51.sys 1R WmiAcpi (Interfejs zarządzania Microsoft Windows dla ACPI) - C:\WINDOWS\system32\drivers\wmiacpi.sys – Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- 3S AresChatServer (Ares Chatroom server) - C:\Program Files\Ares\chatServer.exe 2R ASChannel (Local Communication Channel) - C:\WINDOWS\System32\svchost.exe -k Cognizance 3S aspnet_state (Usługa stanu ASP.NET) - C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe 2R AVKProxy - “C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe” 2R AVKService (AVK Service) - C:\Program Files\G DATA\AntiVirus 2007\AVK\AVKService.exe 2R AVKWCtl (Strażnik AVK) - C:\Program Files\G DATA\AntiVirus 2007\AVK\AVKWCtl.exe 2R btwdins (Bluetooth Service) - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe 2R hpqwmiex - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 3S IDriverT (InstallDriver Table Manager) - “c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe” 2R LightScribeService (LightScribeService Direct Disc Labeling Service) - “C:\Program Files\Common Files\LightScribe\LSSrvc.exe” 2S PCA (PC Angel) - C:\WINDOWS\SMINST\PCAngel.exe 2R UMWdf (Windows User Mode Driver Framework) - C:\WINDOWS\system32\wdfmgr.exe 3S WmcCds (Windows Media Connect (WMC)) - c:\program files\windows media connect\mswmccds.exe 3S WmcCdsLs (Pomocnik programu Windows Media Connect (WMC)) - C:\Program Files\Windows Media Connect\mswmcls.exe – Files created between 2007-03-09 and 2007-04-09 ----------------------------- 2007-04-08 23:57:48 0 d-------- C:\SAV32CLI 2007-04-08 23:46:13 0 d-------- C:\WINDOWS\system32\NtmsData 2007-04-08 21:32:25 164352 --a------ C:\WINDOWS\uninepse.exe 2007-04-08 21:32:24 0 d-------- C:\Program Files\CeeBot-Teen DEMO 2007-04-08 21:17:01 42496 --a------ C:\WINDOWS\setdebug.exe 2007-04-08 21:17:00 140048 --a------ C:\WINDOWS\system32\jit.dll 2007-04-08 21:17:00 135168 --a------ C:\WINDOWS\system32\javaee.dll 2007-04-08 21:17:00 313856 --a------ C:\WINDOWS\system32\dx3j.dll 2007-04-08 21:17:00 6550 --a------ C:\WINDOWS\jautoexp.dat 2007-04-08 21:16:55 113 --a------ C:\WINDOWS\system32\zonedon.reg 2007-04-08 21:16:54 147456 --a------ C:\WINDOWS\wjview.exe 2007-04-08 21:16:54 113 --a------ C:\WINDOWS\system32\zonedoff.reg 2007-04-08 21:16:54 207872 --a------ C:\WINDOWS\system32\vmhelper.dll 2007-04-08 21:16:54 73728 --a------ C:\WINDOWS\system32\msjdbc10.dll 2007-04-08 21:16:54 843024 --a------ C:\WINDOWS\system32\msjava.dll 2007-04-08 21:16:53 155920 --a------ C:\WINDOWS\system32\msawt.dll 2007-04-08 21:16:53 14848 --a------ C:\WINDOWS\system32\jdbgmgr.exe 2007-04-08 21:16:53 361744 --a------ C:\WINDOWS\system32\javart.dll 2007-04-08 21:16:53 32528 --a------ C:\WINDOWS\system32\javaprxy.dll 2007-04-08 21:16:53 154112 --a------ C:\WINDOWS\jview.exe 2007-04-08 21:16:52 209168 --a------ C:\WINDOWS\system32\javacypt.dll 2007-04-08 21:16:51 103424 --a------ C:\WINDOWS\extrac32.exe 2007-04-08 21:16:51 44544 --a------ C:\WINDOWS\clspack.exe 2007-04-08 17:29:15 0 d-------- C:\Program Files\Microsoft Games 2007-04-07 20:24:29 0 d-------- C:\Program Files\QuickTime Alternative 2007-04-07 02:00:19 0 d-------- C:\WINDOWS\Sun 2007-04-05 22:17:01 0 d-------- C:\Program Files\VideoLAN 2007-04-01 20:03:53 0 d-------- C:\WINDOWS\ShellNew 2007-04-01 18:22:39 0 -rahs---- C:\MSDOS.SYS 2007-04-01 18:22:39 0 -rahs---- C:\IO.SYS 2007-03-31 11:04:38 28307 --a------ C:\WINDOWS\system32\drivers\GDTdiIcpt.sys 2007-03-31 11:04:32 34143 --a------ C:\WINDOWS\system32\drivers\MiniIcpt.sys 2007-03-31 11:04:32 29730 --a------ C:\WINDOWS\system32\drivers\HookCentre.sys 2007-03-31 11:04:11 0 d-------- C:\WINDOWS\gear_dlls 2007-03-31 11:04:03 0 d-------- C:\Program Files\G DATA 2007-03-31 11:04:03 0 d-------- C:\Program Files\Common Files\G DATA 2007-03-31 10:51:20 0 d-------- C:\Program Files\Ares 2007-03-30 23:19:06 115880 -----n— C:\WINDOWS\system32\pxinsi64.exe 2007-03-30 23:19:06 129784 -----n— C:\WINDOWS\system32\pxafs.dll 2007-03-30 23:19:06 2560 -----n— C:\WINDOWS\system32\drivers\cdralw2k.sys 2007-03-30 23:19:06 2432 -----n— C:\WINDOWS\system32\drivers\cdr4_xp.sys 2007-03-30 23:19:00 0 d-------- C:\Program Files\Winamp 2007-03-30 18:03:14 0 d-------- C:\WINDOWS\system32\PreInstall 2007-03-30 16:55:51 0 d-------- C:\Program Files\Gadu-Gadu 2007-03-30 16:53:34 1168 --a------ C:\WINDOWS\mozver.dat 2007-03-30 16:51:24 0 --a------ C:\WINDOWS\nsreg.dat 2007-03-30 16:51:09 0 d-------- C:\Program Files\Mozilla Firefox 2007-03-30 16:46:23 0 d-------- C:\WINDOWS\system32\SoftwareDistribution 2007-03-28 20:35:23 2916352 -----n— C:\WINDOWS\UNNMP.exe 2007-03-28 20:33:30 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-03-28 20:33:00 0 d-------- C:\Program Files\Common Files\Nero 2007-03-28 20:32:18 3006464 -----n— C:\WINDOWS\UNNeroVision.exe 2007-03-28 20:32:18 24064 -----n— C:\WINDOWS\system32\msxml3a.dll 2007-03-28 20:31:15 364544 -----n— C:\WINDOWS\system32\TwnLib4.dll 2007-03-28 20:31:15 471040 -----n— C:\WINDOWS\system32\ImagXRA7.dll 2007-03-28 20:31:15 262144 -----n— C:\WINDOWS\system32\ImagXR7.dll 2007-03-28 20:31:14 476320 -----n— C:\WINDOWS\system32\ImagXpr7.dll 2007-03-28 20:31:14 1568768 -----n— C:\WINDOWS\system32\ImagX7.dll 2007-03-28 20:31:13 106496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-03-28 20:31:13 38912 -----n— C:\WINDOWS\system32\picn20.dll 2007-03-28 20:31:07 0 d-------- C:\Program Files\Common Files\Ahead 2007-03-28 20:31:05 0 d-------- C:\Program Files\Ahead 2007-03-28 17:49:28 12160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2007-03-28 17:49:17 9600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2007-03-27 20:28:33 0 d-------- C:\Program Files\AC3Filter 2007-03-27 20:27:18 0 d-------- C:\Program Files\Real Alternative 2007-03-27 20:27:18 0 d-------- C:\Program Files\Media Player Classic 2007-03-27 20:26:46 626688 --a------ C:\WINDOWS\system32\vp7vfw.dll 2007-03-27 20:26:46 438272 --a------ C:\WINDOWS\system32\vp6vfw.dll 2007-03-27 20:26:46 446464 --a------ C:\WINDOWS\system32\vp31vfw.dll 2007-03-27 20:26:44 157696 --a------ C:\WINDOWS\system32\unrar.dll 2007-03-27 20:26:44 421888 --a------ C:\WINDOWS\system32\OpenQuicktimeLib.dll 2007-03-27 20:26:44 413760 --a------ C:\WINDOWS\system32\mpg4c32.dll 2007-03-27 20:26:44 286720 --a------ C:\WINDOWS\system32\3ivxVfWCodec.dll<3IVXVF~1.DLL> 2007-03-27 20:26:44 1024000 --a------ C:\WINDOWS\system32\3ivx.dll 2007-03-27 20:26:43 155648 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-03-27 20:26:43 679936 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-03-27 20:26:43 1415680 --a------ C:\WINDOWS\system32\WMV9VCM.dll 2007-03-27 20:26:42 2024448 --a------ C:\WINDOWS\system32\divx.dll 2007-03-27 20:26:40 245408 --a------ C:\WINDOWS\system32\unicows.dll 2007-03-27 20:26:39 19968 --a------ C:\WINDOWS\system32\cpuinf32.dll 2007-03-27 20:26:39 0 d-------- C:\Program Files\K-Lite Codec Pack 2007-03-27 19:34:17 0 d-------- C:\Program Files\Netia 2007-03-27 19:31:01 32768 --a------ C:\WINDOWS\system32\WooDial2000.dll 2007-03-27 19:30:13 127456 --a------ C:\WINDOWS\system32\ipdetect.exe 2007-03-27 19:30:13 127065 --a------ C:\WINDOWS\system32\drivers\adiusbaw.sys 2007-03-27 19:30:13 155648 --a------ C:\WINDOWS\system32\adadix32.dll 2007-03-27 19:30:12 126976 --a------ C:\WINDOWS\system32\coclassfast.dll 2007-03-27 19:30:11 114688 --a------ C:\WINDOWS\system32\unaddrv.exe 2007-03-27 19:30:11 50007 --a------ C:\WINDOWS\system32\drivers\adildr.sys 2007-03-27 19:30:11 4981 --a------ C:\WINDOWS\system32\adadix2k.dll 2007-03-27 19:30:11 46892 --a------ C:\WINDOWS\system32\adadix16.dll 2007-03-27 19:30:07 0 d-------- C:\Program Files\SAGEM 2007-03-27 19:29:20 0 d-------- C:\Program Files\Neostrada TP 2007-03-27 19:28:54 0 d–hs---- C:\WINDOWS\ftpcache 2007-03-27 07:21:33 60 --a------ C:\WINDOWS\system32\SYSDRV.DAT 2007-03-27 07:20:59 0 d-------- C:\WINDOWS\i386 2007-03-26 22:33:51 0 d-------- C:\Program Files\WIDCOMM 2007-03-26 22:33:41 0 d-------- C:\Program Files\Google 2007-03-26 22:32:45 204800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll 2007-03-26 22:32:45 188416 --a------ C:\WINDOWS\system32\IVIresizePX.dll 2007-03-26 22:32:45 192512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll 2007-03-26 22:32:45 192512 --a------ C:\WINDOWS\system32\IVIresizeM6.dll 2007-03-26 22:32:44 200704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll 2007-03-26 22:32:44 20480 --a------ C:\WINDOWS\system32\IVIresize.dll 2007-03-26 22:32:27 0 d-------- C:\Program Files\InterVideo 2007-03-26 22:30:46 0 d-------- C:\Program Files\Skróty programów 2007-03-26 22:24:46 0 d-------- C:\WINDOWS\Prefetch – Find3M Report --------------------------------------------------------------- 2007-04-09 10:14:34 436560 --a------ C:\WINDOWS\system32\perfh015.dat 2007-04-09 10:14:34 67496 --a------ C:\WINDOWS\system32\perfc015.dat 2007-04-07 02:03:01 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Google 2007-04-07 02:02:47 0 d-------- C:\Program Files\Java 2007-04-07 02:00:19 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Sun 2007-04-06 11:45:52 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\AdobeUM 2007-04-05 22:18:22 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\vlc 2007-04-04 21:19:20 25744 --a------ C:\Documents and Settings\KUBA\Dane aplikacji\GDIPFONTCACHEV1.DAT 2007-04-01 21:27:03 0 d—s---- C:\Documents and Settings\KUBA\Dane aplikacji\Microsoft 2007-03-31 11:05:44 0 d-------- C:\Program Files\Common Files\Symantec Shared 2007-03-31 11:05:43 0 d-------- C:\Program Files\Symantec 2007-03-31 11:04:01 0 d–h----- C:\Program Files\InstallShield Installation Information 2007-03-30 17:50:58 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Real 2007-03-30 16:53:42 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Macromedia 2007-03-30 16:51:19 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Mozilla 2007-03-30 16:06:22 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Adobe 2007-03-28 21:20:06 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Ahead 2007-03-27 20:32:18 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Media Player Classic 2007-03-27 07:06:53 0 d-------- C:\Program Files\Windows Media Connect 2007-03-27 07:06:51 0 d-------- C:\Program Files\Windows NT 2007-03-27 07:06:51 0 d-------- C:\Program Files\Usługi online 2007-03-27 07:06:47 0 d-------- C:\Program Files\Synaptics 2007-03-27 07:05:49 0 d-------- C:\Program Files\Sonic 2007-03-27 07:05:35 0 d-------- C:\Program Files\MSN Gaming Zone 2007-03-27 07:05:35 0 d-------- C:\Program Files\Movie Maker 2007-03-27 07:05:34 0 d-------- C:\Program Files\microsoft frontpage 2007-03-27 07:05:34 0 d-------- C:\Program Files\Messenger 2007-03-27 07:05:05 0 d-------- C:\Program Files\Hp 2007-03-27 07:04:58 0 d-------- C:\Program Files\Hewlett-Packard 2007-03-27 07:04:58 0 d-------- C:\Program Files\Fingerprint Sensor 2007-03-27 07:04:58 0 d-------- C:\Program Files\Common Files\TiVo Shared 2007-03-27 07:04:38 0 d-------- C:\Program Files\Common Files\SureThing Shared 2007-03-27 07:04:38 0 d-------- C:\Program Files\Common Files\SpeechEngines 2007-03-27 07:04:34 0 d-------- C:\Program Files\Common Files\Sonic Shared 2007-03-27 07:04:34 0 d-------- C:\Program Files\Common Files\ODBC 2007-03-27 07:04:34 0 d-------- C:\Program Files\Common Files\MSSoap 2007-03-27 07:04:33 0 d-------- C:\Program Files\Common Files\LightScribe 2007-03-27 07:04:27 0 d-------- C:\Program Files\Common Files\Java 2007-03-27 07:04:24 0 d-------- C:\Program Files\Common Files\InstallShield 2007-03-27 07:04:24 0 d-------- C:\Program Files\Common Files\Adobe 2007-03-27 07:04:23 0 d-------- C:\Program Files\Analog Devices 2007-03-27 07:02:20 0 d-------- C:\Documents and Settings\KUBA\Dane aplikacji\Identities 2007-03-26 22:22:45 0 d-------- C:\Program Files\HPQ 2007-03-08 17:38:47 579072 --a------ C:\WINDOWS\system32\user32.dll 2007-03-08 17:38:47 40960 --a------ C:\WINDOWS\system32\mf3216.dll 2007-03-08 17:38:47 281600 --a------ C:\WINDOWS\system32\gdi32.dll 2007-03-08 17:37:33 1843840 --a------ C:\WINDOWS\system32\win32k.sys 2007-01-29 10:58:06 60416 -----n— C:\WINDOWS\system32\tzchange.exe – Registry Dump --------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” “NETIANET”=“C:\Program Files\Netia\Net\netianet.exe” “Gadu-Gadu”="“C:\Program Files\Gadu-Gadu\gg.exe” /tray" “ares”="“C:\Program Files\Ares\Ares.exe” -h" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “SoundMAXPnP”=“C:\Program Files\Analog Devices\Core\smax4pnp.exe” “SoundMAX”=“C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray” “SunJavaUpdateSched”="“C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe”" “PTHOSTTR”=“C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start” “HP Software Update”=“C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe” “DLA”=“C:\WINDOWS\System32\DLA\DLACTRLW.EXE” “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” “igfxtray”=“C:\WINDOWS\system32\igfxtray.exe” “igfxhkcmd”=“C:\WINDOWS\system32\hkcmd.exe” “igfxpers”=“C:\WINDOWS\system32\igfxpers.exe” “hpWirelessAssistant”=“C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe” “CognizanceTS”=“rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule” “QlbCtrl”=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,48,65,77,6c,65,\ 74,74,2d,50,61,63,6b,61,72,64,5c,48,50,20,51,75,69,63,6b,20,4c,61,75,6e,63,\ 68,20,42,75,74,74,6f,6e,73,5c,51,6c,62,43,74,72,6c,2e,65,78,65,20,2f,53,74,\ 61,72,74,00 “Cpqset”=“C:\Program Files\HPQ\Default Settings\cpqset.exe” “Recguard”=“C:\WINDOWS\Sminst\Recguard.exe” “Reminder”=“C:\WINDOWS\Creator\Remind_XP.exe” “Scheduler”=“C:\WINDOWS\SMINST\Scheduler.exe” “WatchDog”=“C:\Program Files\InterVideo\DVD Check\DVDCheck.exe” “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” “AVKTray”="“C:\Program Files\G DATA\AntiVirus 2007\AVKTray\AVKTray.exe”" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” “NETIANET”=“C:\Program Files\Netia\Net\netianet.exe” [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” “NETIANET”=“C:\Program Files\Netia\Net\netianet.exe” HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 Cognizance REG_MULTI_SZ ASChannel\0\0 – End of ComboScan: finished at 2007-04-09 at 10:16:11 ------------------------