ComboFix 07-11-01.1 - Ja 2007-11-07 16:20:28.8 - NTFSx86 NETWORK Microsoft Windows XP Home Edition 5.1.2600.2.1251.7.1045.18.784 [GMT 1:00] Running from: D:\Wir Mir\AVZ i KIS-7\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 ))))))))))))))))))))))))))))))) . 2007-11-05 13:49 2007-11-05 10:49 2007-11-05 10:46 2007-11-05 10:04 2007-11-05 09:59 2007-11-01 22:16 2007-10-31 10:22 2007-10-30 06:32 60,928 --a–c— C:\WINDOWS\system32\dllcache\msimn.exe 2007-10-30 06:30 363,520 --a------ C:\WINDOWS\system32\PsisDecd.dll 2007-10-30 06:30 363,520 --a–c— C:\WINDOWS\system32\dllcache\psisdecd.dll 2007-10-30 06:30 15,360 --a------ C:\WINDOWS\system32\drivers\MPE.sys 2007-10-30 06:30 15,360 --a–c— C:\WINDOWS\system32\dllcache\mpe.sys 2007-10-30 06:14 11,776 --a------ C:\WINDOWS\system32\drivers\BdaSup.sys 2007-10-30 06:14 11,776 --a–c— C:\WINDOWS\system32\dllcache\bdasup.sys 2007-10-29 15:52 2007-10-27 19:14 2007-10-25 14:34 2007-10-25 14:34 2007-10-25 07:52 3,110 --a------ C:\WINDOWS\system32\tmp.reg 2007-10-25 07:50 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe 2007-10-25 07:50 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2007-10-25 07:50 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-10-25 07:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2007-10-25 07:50 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe 2007-10-24 12:39 2007-10-24 12:38 2007-10-24 12:37 2007-10-22 18:56 2007-10-22 18:08 2007-10-22 17:53 2007-10-21 21:29 2007-10-19 15:45 2007-10-19 15:39 2007-10-19 15:35 2,973,696 --------- C:\WINDOWS\NuNinst.exe 2007-10-19 15:35 99,584 --------- C:\WINDOWS\system32\drivers\InCDfs.sys 2007-10-19 15:35 29,696 --------- C:\WINDOWS\system32\drivers\InCDpass.sys 2007-10-19 15:35 8,704 --------- C:\WINDOWS\system32\drivers\InCDrec.sys 2007-10-19 15:34 2007-10-19 15:34 28,672 --------- C:\WINDOWS\system32\drivers\InCDrm.sys 2007-10-16 20:54 21,495,072 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2007-10-16 20:54 473,120 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2007-10-16 20:54 82,061 --a------ C:\WINDOWS\system32\drivers\klick.dat 2007-10-16 20:54 81,549 --a------ C:\WINDOWS\system32\drivers\klin.dat 2007-10-16 18:47 2007-10-16 18:47 2007-10-16 18:47 2007-10-16 18:21 2007-10-16 17:33 2007-10-13 19:37 2007-10-10 16:05 2007-10-08 17:19 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-07 15:18 46,472 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx 2007-11-07 15:18 291,044 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2007-11-07 14:31 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\OpenOffice.org2 2007-11-07 13:57 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab 2007-11-06 20:27 --------- d-----w C:\Documents and Settings\75D1~1\Dane aplikacji\Skype 2007-11-06 17:13 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\Skype 2007-11-05 12:07 --------- d-----w C:\Program Files\Mozilla Thunderbird 2007-11-05 07:13 --------- d-----w C:\Program Files\Microsoft SQL Server 2007-11-04 18:51 230,432 ----a-w C:\StiImg.dat 2007-11-01 21:12 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-10-28 14:23 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2007-10-25 13:50 --------- d—a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP 2007-10-25 06:00 --------- d-----w C:\Program Files\Opera 2007-10-22 02:39 267,272 ----a-w C:\WINDOWS\system32\xactengine2_10.dll 2007-10-21 20:14 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\Uniblue 2007-10-20 12:38 --------- d-----w C:\Program Files\MultiKeyboard Driver 2007-10-19 14:34 --------- d-----w C:\Program Files\CyberLink DVD Solution 2007-10-17 13:42 --------- d-----w C:\Program Files\OpenOffice.org 2.3 2007-10-16 20:09 --------- d-----w C:\Program Files\Kaspersky Lab 2007-10-12 14:14 3,734,536 ----a-w C:\WINDOWS\system32\d3dx9_36.dll 2007-10-12 14:14 1,374,232 ----a-w C:\WINDOWS\system32\D3DCompiler_36.dll 2007-10-10 14:40 --------- d-----w C:\Program Files\Google 2007-10-07 06:49 --------- d-----w C:\Program Files\Microsoft Silverlight 2007-10-05 20:22 --------- d-----w C:\Program Files\PRMT8 2007-10-05 13:13 --------- d-----w C:\Documents and Settings\75D1~1\Dane aplikacji\Nero 2007-10-05 13:01 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\Nero 2007-10-05 13:00 --------- d-----w C:\Program Files\Common Files\Nero 2007-10-05 12:58 --------- d-----w C:\Program Files\Nero 2007-10-05 12:58 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Nero 2007-10-05 12:47 --------- d-----w C:\Program Files\Common Files\Ahead 2007-10-05 12:47 --------- d-----w C:\Program Files\Ahead 2007-10-04 17:09 --------- d-----w C:\Documents and Settings\75D1~1\Dane aplikacji\PRMT 2007-10-04 11:04 --------- d-----w C:\Program Files\MSXML 4.0 2007-10-03 20:40 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\PROject MT 2007-10-02 08:56 444,776 ----a-w C:\WINDOWS\system32\d3dx10_36.dll 2007-09-29 20:08 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\PRMT 2007-09-28 12:46 --------- d-----w C:\Program Files\K-Lite Codec Pack 2007-09-27 08:30 --------- d-----w C:\Documents and Settings\Ja\Dane aplikacji\ChemTable Software 2007-09-26 21:34 269,824 ----a-w C:\WINDOWS\system32\baksm.dll 2007-09-24 07:05 132,904 ----a-w C:\WINDOWS\system32\drivers\imagesrv.sys 2007-09-24 07:05 11,304 ----a-w C:\WINDOWS\system32\drivers\imagedrv.sys 2007-09-20 07:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe 2007-09-20 07:55 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe 2007-09-20 07:55 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll 2007-09-17 13:41 --------- d-----w C:\Documents and Settings\75D1~1\Dane aplikacji\CyberLink 2007-09-15 08:34 --------- d-----w C:\Program Files\Java 2007-09-13 13:35 --------- d-----w C:\Program Files\MSN Messenger 2007-09-11 18:02 --------- d-----w C:\Program Files\Skype 2007-09-11 18:02 --------- d-----w C:\Program Files\Common Files\Skype 2007-09-10 06:52 --------- d-----w C:\Program Files\Trend Micro 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-13 17:54 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll 2007-08-13 17:54 156,160 ----a-w C:\WINDOWS\system32\msls31.dll 2007-08-13 17:45 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll 2007-08-13 17:44 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll 2007-08-13 17:39 71,680 ----a-w C:\WINDOWS\system32\admparse.dll 2007-08-13 17:39 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll 2007-08-13 17:36 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll 2007-08-13 17:32 45,568 ----a-w C:\WINDOWS\system32\mshta.exe 2007-08-13 17:01 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll 2007-06-20 19:00 702,644 ----a-w C:\Program Files\JUN2007_d3dx10_34_x64.cab 2007-06-20 19:00 702,072 ----a-w C:\Program Files\JUN2007_d3dx10_34_x86.cab 2007-06-20 19:00 45,302 ----a-w C:\Program Files\dxdllreg_x86.cab 2007-06-20 19:00 200,722 ----a-w C:\Program Files\JUN2007_XACT_x64.cab 2007-06-20 19:00 156,509 ----a-w C:\Program Files\JUN2007_XACT_x86.cab 2007-06-20 19:00 1,611,374 ----a-w C:\Program Files\JUN2007_d3dx9_34_x64.cab 2007-06-20 19:00 1,610,886 ----a-w C:\Program Files\JUN2007_d3dx9_34_x86.cab 2007-06-20 18:40 976,020 ------w C:\Program Files\BDAXP.cab 2007-06-20 18:40 917,318 ------w C:\Program Files\Apr2006_MDX1_x86.cab 2007-06-20 18:40 88,102 ------w C:\Program Files\AUG2006_xinput_x64.cab 2007-06-20 18:40 87,989 ------w C:\Program Files\Apr2006_xinput_x64.cab 2007-06-20 18:40 86,925 ------w C:\Program Files\Oct2005_xinput_x64.cab 2007-06-20 18:40 86,400 ----a-w C:\Program Files\dxupdate.cab 2007-06-20 18:40 77,160 ----a-w C:\Program Files\DSETUP.dll 2007-06-20 18:40 702,212 ------w C:\Program Files\APR2007_d3dx10_33_x64.cab 2007-06-20 18:40 699,465 ------w C:\Program Files\APR2007_d3dx10_33_x86.cab 2007-06-20 18:40 56,902 ------w C:\Program Files\APR2007_xinput_x86.cab 2007-06-20 18:40 503,144 ----a-w C:\Program Files\DXSETUP.exe 2007-06-20 18:40 47,018 ------w C:\Program Files\AUG2006_xinput_x86.cab 2007-06-20 18:40 46,898 ------w C:\Program Files\Apr2006_xinput_x86.cab 2007-06-20 18:40 46,247 ------w C:\Program Files\Oct2005_xinput_x86.cab 2007-06-20 18:40 4,163,518 ------w C:\Program Files\Apr2006_MDX1_x86_Archive.cab 2007-06-20 18:40 213,767 ------w C:\Program Files\DEC2006_d3dx10_00_x64.cab 2007-06-20 18:40 199,366 ------w C:\Program Files\APR2007_XACT_x64.cab 2007-06-20 18:40 198,275 ------w C:\Program Files\FEB2007_XACT_x64.cab 2007-06-20 18:40 193,435 ------w C:\Program Files\DEC2006_XACT_x64.cab 2007-06-20 18:40 192,680 ------w C:\Program Files\DEC2006_d3dx10_00_x86.cab 2007-06-20 18:40 183,863 ------w C:\Program Files\AUG2006_XACT_x64.cab 2007-06-20 18:40 183,321 ------w C:\Program Files\OCT2006_XACT_x64.cab 2007-06-20 18:40 181,745 ------w C:\Program Files\JUN2006_XACT_x64.cab 2007-06-20 18:40 180,021 ------w C:\Program Files\Apr2006_XACT_x64.cab 2007-06-20 18:40 179,247 ------w C:\Program Files\Feb2006_XACT_x64.cab 2007-06-20 18:40 154,825 ------w C:\Program Files\APR2007_XACT_x86.cab 2007-06-20 18:40 151,583 ------w C:\Program Files\FEB2007_XACT_x86.cab 2007-06-20 18:40 146,559 ------w C:\Program Files\DEC2006_XACT_x86.cab 2007-06-20 18:40 138,977 ------w C:\Program Files\OCT2006_XACT_x86.cab 2007-06-20 18:40 138,195 ------w C:\Program Files\AUG2006_XACT_x86.cab 2007-06-20 18:40 134,631 ------w C:\Program Files\JUN2006_XACT_x86.cab 2007-06-20 18:40 133,991 ------w C:\Program Files\Apr2006_XACT_x86.cab 2007-06-20 18:40 133,297 ------w C:\Program Files\Feb2006_XACT_x86.cab . ((((((((((((((((((((((((((((( snapshot@2007-11-02_ 8.52.43,01 ))))))))))))))))))))))))))))))))))))))))) . + 2007-11-05 22:18:37 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Code.glvw8oj2.dll + 2007-11-05 22:18:36 11,264 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_GlobalResources.gnow9hw-.dll + 2007-11-05 22:18:39 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_LocalResources.root.gmi7vpil.dll + 2007-11-05 22:19:00 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_LocalResources.security.cdcab7d2.c2q6juqa.dll + 2007-11-05 22:18:41 6,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_0sjw0gfm.dll + 2007-11-05 22:18:40 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_8np9x6ec.dll + 2007-11-05 22:19:01 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_fsm6gc6h.dll + 2007-11-05 22:19:00 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_jtvf7zg8.dll + 2007-11-05 22:18:44 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_lgnbxx6m.dll + 2007-11-05 22:18:44 8,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_nidmzbub.dll + 2007-11-05 22:18:43 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_oncxhlft.dll + 2007-11-05 22:18:42 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_s2gpwj2k.dll + 2007-11-05 22:18:42 10,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\App_Web_w9vaqrmw.dll + 2007-11-05 22:18:35 6,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\pl\App_GlobalResources.gnow9hw-.resources.dll + 2007-11-05 22:18:38 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\pl\App_LocalResources.root.gmi7vpil.resources.dll + 2007-11-05 22:18:59 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\pl\App_LocalResources.security.cdcab7d2.c2q6juqa.resources.dll + 2007-11-07 11:09:06 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\5d28e62f\2602964a\App_Web__lrbthdm.dll + 2007-11-07 11:04:44 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\5d28e62f\2602964a\App_Web_8qe8u05n.dll + 2007-11-07 11:10:41 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\5d28e62f\2602964a\App_Web_e2p7d9bu.dll + 2007-11-07 11:15:20 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\5d28e62f\2602964a\App_Web_i4mtyir1.dll + 2007-11-07 10:55:39 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\5d28e62f\2602964a\App_Web_j8fzlb59.dll + 2007-11-07 11:14:13 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\5d28e62f\2602964a\App_Web_jzzdrmu8.dll + 2007-11-07 10:58:22 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\5d28e62f\2602964a\App_Web_o2-p9ju0.dll + 2007-11-07 10:35:43 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\5d28e62f\2602964a\App_Web_olxxh7nn.dll + 2007-11-07 10:58:28 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\f5c58eb9\b60f641f\App_Web_25wvki9x.dll + 2007-11-07 10:55:45 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\f5c58eb9\b60f641f\App_Web_ae-clqip.dll + 2007-11-07 11:15:26 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\f5c58eb9\b60f641f\App_Web_f7h17pj_.dll + 2007-11-07 11:14:19 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\f5c58eb9\b60f641f\App_Web_km-795kl.dll + 2007-11-07 11:09:12 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\f5c58eb9\b60f641f\App_Web_us63pctl.dll + 2007-11-07 11:10:47 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\f5c58eb9\b60f641f\App_Web_vh2tsarw.dll + 2007-11-07 11:04:50 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\f5c58eb9\b60f641f\App_Web_yestins-.dll + 2007-11-05 22:32:02 6,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website2\4557357a\c34828ca\App_Web_f2omx3d5.dll + 2007-11-05 22:32:09 6,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website2\a1330248\91f26399\App_Web_tv96vjpr.dll - 2007-10-30 16:40:39 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2007-11-02 14:19:29 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - 2007-10-30 16:40:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat + 2007-11-02 14:19:29 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat - 2007-10-30 16:40:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat + 2007-11-02 14:19:29 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat - 2007-10-31 11:30:54 6,232 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat + 2007-11-04 22:25:38 40,564 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “High Definition Audio Property Page Shortcut”=“HDAShCut.exe” [2004-10-27 14:21 C:\WINDOWS\system32\HdAShCut.exe] “SoundMAXPnP”=“C:\Program Files\Analog Devices\Core\smax4pnp.exe” [2005-05-20 02:11] “SoundMAX”=“C:\Program Files\Analog Devices\SoundMAX\Smax4.exe” [2005-09-07 14:35] “NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-06-01 10:22] “nwiz”=“nwiz.exe” [2006-06-01 10:22 C:\WINDOWS\system32\nwiz.exe] “SW20”=“C:\WINDOWS\system32\sw20.exe” [2006-05-18 02:15] “SW24”=“C:\WINDOWS\system32\sw24.exe” [2006-05-17 03:37] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe” [2007-07-12 03:00] “Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2007-10-10 18:51] “NeroFilterCheck”=“C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe” [2007-03-01 14:57] “NBKeyScan”=“C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe” [2007-09-20 08:51] “Hotkey”=“C:\Program Files\Hotkey\Hotkey.exe” [2004-04-03 17:38] “AVP”=“C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe” [2007-06-28 12:51] “InCD”=“C:\Program Files\Ahead\InCD\InCD.exe” [2006-03-14 03:06] “NvMediaCenter”=“NvMCTray.dll” [2006-06-01 10:22 C:\WINDOWS\system32\nvmctray.dll] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 13:00] “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-10-14 21:37] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “AppInit_DLLs”=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys S2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe S2 SQLWriter;SQL Server VSS Writer;“C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe” S3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys S3 BTNetFilter;Bluetooth Network Filter;??\C:\WINDOWS\system32\drivers\BTNetFilter.sys S3 PAC207;VideoCAM GE111;C:\WINDOWS\system32\DRIVERS\pfc027.sys S3 SetupNTGLM7X;SetupNTGLM7X;??\E:\NTGLM7X.sys . Contents of the ‘Scheduled Tasks’ folder “2007-10-21 20:12:58 C:\WINDOWS\Tasks\Uniblue SpyEraser.job” - C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-07 16:22:10 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-07 16:22:35 . — E O F —