ComboFix 07-01-21 - Running from: “C:\Documents and Settings\EMILJUSZ\Moje dokumenty\Specjalne\Combofix” (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\hosts ((((((((((((((((((((((((((((((( Files Created from 2007-02-11 to 2007-03-11 )))))))))))))))))))))))))))))))))) 2007-03-11 11:51 2007-03-11 11:51 2007-03-10 23:52 2007-03-10 23:06 2007-03-10 22:59 2007-03-10 22:58 2007-03-10 22:58 2007-03-10 13:39 2007-03-10 13:27 2007-03-10 13:26 2007-03-09 19:32 2007-03-09 19:21 2007-03-09 09:19 2007-03-06 21:22 17,920 --a------ C:\WINDOWS\SYSTEM32\mdimon.dll 2007-03-06 21:20 2007-03-06 21:15 2007-03-06 20:08 2007-03-06 20:04 180,224 --a------ C:\WINDOWS\SYSTEM32\NVUNINST.EXE 2007-03-06 20:04 180,224 --a------ C:\WINDOWS\SYSTEM32\nvudisp.exe 2007-03-06 20:04 2007-03-06 20:03 2007-03-06 18:51 2007-03-06 18:50 182,880 --a------ C:\WINDOWS\SYSTEM32\iuengine.dll 2007-03-05 22:31 2007-03-05 16:56 2007-03-05 16:19 2007-03-05 16:18 2007-03-05 14:39 2007-03-05 14:36 2007-03-05 13:32 2007-03-05 13:11 2007-03-05 12:53 2007-03-05 12:46 229,376 -ra------ C:\WINDOWS\SYSTEM32\atiiiexx.dll 2007-03-05 12:46 2007-03-04 14:48 2007-03-04 14:21 2007-03-03 20:50 2007-03-03 18:48 2007-03-03 18:48 2007-03-03 15:05 2007-03-03 14:09 94,424 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys 2007-03-03 14:09 90,112 --a------ C:\WINDOWS\SYSTEM32\AVASTSS.scr 2007-03-03 14:09 85,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys 2007-03-03 14:09 689,280 --a------ C:\WINDOWS\SYSTEM32\aswBoot.exe 2007-03-03 14:09 43,176 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys 2007-03-03 14:09 31,560 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys 2007-03-03 14:09 23,352 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys 2007-03-03 14:09 2007-03-02 16:40 2007-02-24 20:46 2007-02-24 19:57 2007-02-23 15:34 2007-02-23 12:56 2007-02-23 12:53 19,456 --a------ C:\WINDOWS\SYSTEM32\asapi.dll 2007-02-23 12:53 10,240 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\asapi.sys 2007-02-23 12:53 2007-02-23 12:53 2007-02-23 12:52 2007-02-23 12:51 1,052,672 --a------ C:\WINDOWS\SYSTEM32\CDDBControl.dll 2007-02-23 10:27 2007-02-22 17:34 33,664 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\disk.sys 2007-02-22 17:32 87,824 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300mgmt.sys 2007-02-22 17:32 85,696 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300obex.sys 2007-02-22 17:24 24,960 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbccgp.sys 2007-02-22 17:20 96,352 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300mdm.sys 2007-02-22 17:20 9,264 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300mdfl.sys 2007-02-22 17:20 60,800 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300bus.sys 2007-02-22 17:20 6,208 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300cmnt.sys 2007-02-22 17:20 6,208 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300cm.sys 2007-02-22 17:20 5,840 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300whnt.sys 2007-02-22 17:20 5,840 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\w300wh.sys 2007-02-22 17:17 2007-02-22 17:15 2007-02-22 17:15 2007-02-22 17:15 2007-02-22 17:14 2007-02-22 17:14 2007-02-22 17:14 2007-02-21 23:42 2007-02-20 18:17 2007-02-17 19:29 2007-02-16 13:14 2007-02-15 22:50 2007-02-15 21:20 2007-02-15 21:20 2007-02-15 20:24 2007-02-15 14:27 8,464 --a------ C:\WINDOWS\SYSTEM32\sporder.dll 2007-02-15 14:18 2007-02-15 12:57 2007-02-15 12:57 2007-02-15 12:52 87,040 --a------ C:\WINDOWS\SYSTEM32\ra32sipr.dll 2007-02-15 12:52 85,504 --a------ C:\WINDOWS\SYSTEM32\encdnet.dll 2007-02-15 12:52 81,920 --a------ C:\WINDOWS\SYSTEM32\ra3214_4.dll 2007-02-15 12:52 72,704 --a------ C:\WINDOWS\SYSTEM32\ra3228_8.dll 2007-02-15 12:52 61,952 --a------ C:\WINDOWS\SYSTEM32\decdnet.dll 2007-02-15 12:52 487,936 --a------ C:\WINDOWS\SYSTEM32\rmbe3260.dll 2007-02-15 12:52 487,424 --a------ C:\WINDOWS\SYSTEM32\msvcp70.dll 2007-02-15 12:52 352,768 --a------ C:\WINDOWS\SYSTEM32\pngu3263.dll 2007-02-15 12:52 344,064 --a------ C:\WINDOWS\SYSTEM32\msvcr70.dll 2007-02-15 12:52 21,504 --a------ C:\WINDOWS\SYSTEM32\ra32dnet.dll 2007-02-15 12:52 131,072 --a------ C:\WINDOWS\SYSTEM32\pneng50.dll 2007-02-15 12:52 130,560 --a------ C:\WINDOWS\SYSTEM32\pnc3250.dll 2007-02-15 12:51 2007-02-15 12:50 700,416 --a------ C:\WINDOWS\SYSTEM32\SYNSOACC.dll 2007-02-15 12:50 45,056 --a------ C:\WINDOWS\SYSTEM32\Synsopos.exe 2007-02-15 12:50 33,792 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\cledx.sys 2007-02-15 12:50 17,784 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\NSynas32.sys 2007-02-15 12:50 16,896 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\synasUSB.sys 2007-02-15 12:50 147,456 --a------ C:\WINDOWS\SYSTEM32\SynsoLChk.dll 2007-02-15 12:50 2007-02-15 11:04 2007-02-15 09:51 2007-02-14 22:03 2007-02-14 15:47 2007-02-11 19:07 2007-02-11 17:18 2007-02-11 13:21 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-03-08 10:26 14848 --ahs---- C:\Program Files\thumbs.db 2007-02-11 19:16 12400 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys 2007-02-07 13:23 -------- d-------- C:\Program Files\deluxe ski jump 3 2007-01-27 23:52 -------- d-------- C:\DOCUME~1\EMILJUSZ\Dane aplikacji\shareaza 2007-01-27 14:40 8864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\CDAC15BA.SYS 2007-01-27 14:40 30720 -r-h----- C:\WINDOWS\cdac13ba.exe 2007-01-27 14:40 112128 -r-h----- C:\WINDOWS\cdac14ba.dll 2007-01-26 14:56 43520 --a------ C:\WINDOWS\SYSTEM32\cmdlineext03.dll 2007-01-22 13:52 -------- d-------- C:\Program Files\interactive vision 2007-01-22 13:18 -------- d-------- C:\Program Files\midtown 2007-01-21 17:45 -------- d-------- C:\Program Files\microsoft reader 2007-01-20 21:03 -------- d-------- C:\Program Files\spyware doctor 2007-01-20 21:03 -------- d-------- C:\DOCUME~1\EMILJUSZ\Dane aplikacji\pc tools 2007-01-20 20:29 -------- d-------- C:\Program Files\roguescanfix 2007-01-19 13:35 719088 --a------ C:\WINDOWS\SYSTEM32\skaneronline.dll 2007-01-19 09:40 89088 --a------ C:\WINDOWS\SYSTEM32\skaneronlineuninstall.exe 2007-01-16 18:09 -------- d-------- C:\Program Files\ivt corporation 2007-01-16 13:08 -------- d-------- C:\Program Files\jowood 2007-01-16 12:19 -------- d-------- C:\Program Files\paragon software 2007-01-14 12:05 535040 --a------ C:\WINDOWS\flashax.exe 2007-01-14 12:05 491520 --a------ C:\WINDOWS\mobuzak screensaver.scr 2007-01-14 12:05 12288 --a------ C:\WINDOWS\impborl.dll 2007-01-12 20:42 -------- d-------- C:\Program Files\gt interactive 2007-01-12 17:37 -------- d-------- C:\DOCUME~1\EMILJUSZ\Dane aplikacji\sun 2007-01-11 16:05 -------- d-------- C:\Program Files\gimnazjum klasa 1 - biologia 2007-01-05 14:57 499712 --a------ C:\WINDOWS\SYSTEM32\msvcp71.dll 2007-01-05 14:57 348160 --a------ C:\WINDOWS\SYSTEM32\msvcr71.dll 2007-01-05 14:46 107008 --a------ C:\WINDOWS\SYSTEM32\migicons.exe 2007-01-05 14:37 62 --ahs---- C:\DOCUME~1\EMILJUSZ\Dane aplikacji\desktop.ini 2007-01-05 14:23 266 —hs---- C:\Program Files\desktop.ini 2007-01-05 14:23 133 --a------ C:\AUTOEXEC.BAT 2007-01-05 14:23 11232 —h----- C:\Program Files\folder.htt 2007-01-05 14:23 100 --a------ C:\CONFIG.SYS 2007-01-05 14:21 1676 -r-hs---- C:\MSDOS.SYS 2007-01-05 14:16 19131 --a------ C:\WINDOWS\setver.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “Gadu-Gadu”="“C:\Program Files\Gadu-Gadu\gg.exe” /tray" “eMuleAutoStart”=“C:\Program Files\eMule\emule.exe -AutoStart” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” “QuickTime Task”="“C:\Program Files\QuickTime\qttask.exe” -atboottime" “NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup” “nwiz”=“nwiz.exe /install” “NvMediaCenter”=“RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit” “Ashampoo FireWall”="“C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe” -TRAY" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “NoChange”=“1” “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys] “LoadPowerProfile”=“Rundll32.exe powrprof.dll,LoadCurrentPwrScheme” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BlueSoleil.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk” “backup”=“C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\IVTCOR~1\BLUESO~1\BLUESO~1.EXE " “item”=“BlueSoleil” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk” “backup”=“C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\MICROS~2\Office\OSA9.EXE -b -l” “item”=“Microsoft Office” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=”" “hkey”=“HKLM” “command”="" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“bittorrent” “hkey”=“HKCU” “command”="“C:\Program Files\BitTorrent\bittorrent.exe” --force_start_minimized" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“BJPSMAIN” “hkey”=“HKLM” “command”=“C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“emule” “hkey”=“HKCU” “command”=“C:\Program Files\eMule\emule.exe -AutoStart” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“cledx” “hkey”=“HKLM” “command”=“C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“ISUSPM” “hkey”=“HKLM” “command”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“issch” “hkey”=“HKLM” “command”="“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“msmsgs” “hkey”=“HKCU” “command”="“C:\Program Files\Messenger\msmsgs.exe” /background" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NeroCheck” “hkey”=“HKLM” “command”=“C:\WINDOWS\System32\\NeroCheck.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“Application Launcher” “hkey”=“HKLM” “command”="“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“jusched” “hkey”=“HKLM” “command”="“C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“SysTray” “hkey”=“HKLM” “command”=“SysTray.Exe” “inimapping”=“0” [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Spyware Doctor”="" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] “Spyware Doctor”="" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{d51361c4-9cc1-11db-8cb8-806d6172696f}] Shell\AutoRun\command E:\RunGame.exe Contents of the ‘Scheduled Tasks’ folder C:\WINDOWS\tasks\Rozpocz©cie aplikacji dostrajania.job C:\WINDOWS\tasks\AppleSoftwareUpdate.job Completion time: 07-03-11 12:31:44