ComboFix 08-05-15.2 - bubu 2008-05-16 8:56:40.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.523 [GMT 2:00] Running from: C:\Documents and Settings\bubu\Pulpit\ComboFix.exe Command switches used :: C:\Documents and Settings\bubu\Pulpit\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED FILE :: C:\WINDOWS\exqb.exe C:\WINDOWS\oadkxrts.exe C:\WINDOWS\SET3.tmp C:\WINDOWS\system32\blackster.scr C:\WINDOWS\system32\ctfmonb.bmp . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\exqb.exe C:\WINDOWS\oadkxrts.exe C:\WINDOWS\SET3.tmp C:\WINDOWS\system32\blackster.scr C:\WINDOWS\system32\ctfmonb.bmp C:\WINDOWS\system32\Desktop_.ini . ---- Previous Run ------- . C:\Documents and Settings\bubu\Pulpit\Error Cleaner.url C:\Documents and Settings\bubu\Pulpit\Privacy Protector.url C:\Documents and Settings\bubu\Pulpit\SpywareMalware Protection.url C:\Documents and Settings\bubu\Ulubione\Error Cleaner.url C:\Documents and Settings\bubu\Ulubione\Privacy Protector.url C:\Documents and Settings\bubu\Ulubione\SpywareMalware Protection.url C:\Program Files\myglobalsearch C:\Program Files\myglobalsearch\bar\History\search C:\WINDOWS\fvowketqonp.dll C:\WINDOWS\mpfanvqg.dll C:\WINDOWS\privacy_danger C:\WINDOWS\privacy_danger\images\capt.gif C:\WINDOWS\privacy_danger\images\danger.jpg C:\WINDOWS\privacy_danger\images\down.gif C:\WINDOWS\privacy_danger\images\spacer.gif C:\WINDOWS\privacy_danger\index.htm C:\WINDOWS\pvnsmfor.dll C:\WINDOWS\rs.txt C:\WINDOWS\system32\ctfmona.exe c:\windows\system32\Drivers\Mtb31.sys C:\WINDOWS\system32\WLCtrl32.dl_ C:\WINDOWS\SYSTEM32\WLCtrl32.dll C:\WINDOWS\vbksrofa.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_MTB31 -------\Service_Mtb31 ((((((((((((((((((((((((( Files Created from 2008-04-16 to 2008-05-16 ))))))))))))))))))))))))))))))) . 2008-05-16 00:21 . 2008-05-16 00:29 96,645 --a------ C:\WINDOWS\system32\drivers\klin.dat 2008-05-16 00:21 . 2008-05-16 00:29 87,941 --a------ C:\WINDOWS\system32\drivers\klick.dat 2008-05-16 00:20 . 2008-05-16 00:20 2008-05-16 00:20 . 2008-05-16 08:40 2008-05-16 00:20 . 2008-05-16 09:01 136,224 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2008-05-16 00:20 . 2008-05-16 09:01 6,432 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2008-05-16 00:20 . 2008-05-16 00:37 2,252 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2008-05-16 00:20 . 2008-05-16 00:37 1,292 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2008-05-16 00:19 . 2008-05-16 00:19 2008-05-15 23:24 . 2008-05-15 23:24 2008-05-15 23:24 . 2008-05-15 23:24 2008-05-15 23:24 . 2008-05-15 23:24 2008-05-15 23:24 . 2008-05-15 23:24 2008-05-15 23:10 . 2008-05-16 08:56 1,024 --ah----- C:\Documents and Settings\Default User.WINDOWS\ntuser.dat.LOG 2008-05-15 22:35 . 2008-05-15 22:35 2008-05-15 22:27 . 2008-05-15 23:58 2008-05-15 21:22 . 2008-05-15 23:57 2008-05-15 20:57 . 2008-05-15 20:57 2008-05-15 19:26 . 2008-05-15 21:12 2008-05-15 19:26 . 2008-05-15 21:01 2008-05-15 19:26 . 2008-05-16 08:39 2008-05-15 18:56 . 2008-05-15 18:57 2008-05-15 18:53 . 2008-05-15 18:53 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2008-05-15 09:48 . 2008-05-15 09:48 2008-05-15 09:46 . 2008-05-15 09:46 2008-05-15 09:17 . 2008-05-15 09:18 2008-05-15 09:05 . 2007-10-25 18:44 8,488,960 --------- C:\WINDOWS\system32\dllcache\shell32.dll 2008-05-15 09:03 . 2008-05-15 09:03 1,160 --a------ C:\WINDOWS\mozver.dat 2008-05-15 09:03 . 2008-05-15 09:03 0 --a------ C:\WINDOWS\nsreg.dat 2008-05-15 08:57 . 2008-05-15 08:57 2008-05-15 08:57 . 2008-05-15 08:57 2008-05-15 08:54 . 2007-05-02 11:00 546,976 --a------ C:\WINDOWS\system32\drivers\ar5211.sys 2008-05-15 08:54 . 2007-05-02 11:00 546,976 --a------ C:\WINDOWS\system32\ar5211.sys 2008-05-15 08:54 . 2007-05-02 11:00 84,470 --a------ C:\WINDOWS\system32\net5211.inf 2008-05-15 08:54 . 2007-05-09 10:16 20,888 --a------ C:\WINDOWS\system32\net5211.cat 2008-05-15 08:53 . 2008-05-15 08:53 2008-05-15 08:53 . 2008-05-15 08:53 2008-05-15 08:41 . 2005-12-13 23:08 1,124,097 --a------ C:\WINDOWS\system32\drivers\AGRSM.sys 2008-05-15 08:41 . 2005-12-13 21:50 88,204 --a------ C:\WINDOWS\AGRSMMSG.exe 2008-05-15 08:41 . 2005-05-03 18:10 68,096 --a------ C:\WINDOWS\agrsmdel.exe 2008-05-15 08:41 . 2006-07-04 17:48 64,512 --------- C:\WINDOWS\system32\agrsmdel.exe 2008-05-15 08:35 . 2006-06-13 09:57 143,360 --a------ C:\WINDOWS\system32\igfxres.dll 2008-05-15 08:31 . 2008-05-15 08:31 2008-05-15 08:30 . 2008-05-15 08:30 2008-05-15 08:26 . 2008-05-15 08:26 2008-05-15 08:26 . 2006-07-14 12:13 147,456 --a------ C:\WINDOWS\UNINST32.EXE 2008-05-15 08:26 . 2006-07-14 12:13 49,152 --a------ C:\WINDOWS\system32\QtBtLib.dll 2008-05-15 08:26 . 2006-07-14 12:13 16,896 --a------ C:\WINDOWS\system32\drivers\DKbFltr.SYS 2008-05-15 08:26 . 2006-07-14 12:13 5,120 --a------ C:\WINDOWS\system32\FILTRCOI.DLL 2008-05-15 08:26 . 2008-05-15 08:26 83 --a------ C:\WINDOWS\QtZgAcer.UNI 2008-05-15 08:24 . 2005-06-21 13:32 28,544 --a------ C:\WINDOWS\system32\drivers\callistx.sys 2008-05-15 08:23 . 2006-07-19 09:41 487,424 --a------ C:\WINDOWS\RtlExUpd.dll 2008-05-15 08:23 . 2006-07-19 09:42 135,168 --a------ C:\WINDOWS\system32\RtlCPAPI.dll 2008-05-15 08:23 . 2006-07-19 09:41 40,960 --a------ C:\WINDOWS\system32\ChCfg.exe 2008-05-15 08:21 . 2008-05-15 08:21 2008-05-15 08:21 . 2006-04-29 05:54 193,056 --a------ C:\WINDOWS\system32\drivers\SynTP.sys 2008-05-15 08:21 . 2006-04-29 06:00 114,688 --a------ C:\WINDOWS\system32\SynCtrl.dll 2008-05-15 08:21 . 2006-04-29 06:00 94,297 --a------ C:\WINDOWS\system32\SynTPAPI.dll 2008-05-15 08:21 . 2006-04-29 05:59 82,012 --a------ C:\WINDOWS\system32\SynCOM.dll 2008-05-15 08:21 . 2006-04-29 06:17 81,920 --a------ C:\WINDOWS\system32\SynTPCo2.dll 2008-05-15 08:21 . 2006-04-29 06:14 69,721 --a------ C:\WINDOWS\system32\SynTPFcs.dll 2008-05-15 00:04 . 2004-08-04 02:35 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2008-05-15 00:03 . 2004-08-04 02:44 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2008-05-15 00:03 . 2004-08-04 01:07 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys 2008-05-15 00:03 . 2001-08-17 23:57 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys 2008-05-15 00:03 . 2001-08-17 23:58 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys 2008-05-15 00:03 . 2004-08-04 01:07 8,832 --a------ C:\WINDOWS\system32\drivers\wmiacpi.sys 2008-05-14 23:57 . 2008-05-15 10:07 1,374 --a------ C:\WINDOWS\imsins.BAK 2008-05-14 23:56 . 2008-05-16 09:01 2008-05-14 23:56 . 2008-05-14 23:56 2008-05-14 23:56 . 2008-05-14 22:10 2008-05-14 23:56 . 2008-05-14 23:56 2008-05-14 23:56 . 2008-05-14 23:56 2008-05-14 23:56 . 2008-05-14 23:56 2008-05-14 23:56 . 2008-05-14 23:56 2008-05-14 23:56 . 2008-05-14 23:56 2008-05-14 23:56 . 2008-05-16 00:08 2008-05-14 23:56 . 2008-05-15 08:32 2008-05-14 23:56 . 2008-05-15 19:51 2008-05-14 23:55 . 2008-05-14 23:56 2008-05-14 23:55 . 2008-05-15 23:10 2008-05-14 23:55 . 2008-05-16 00:20 2008-05-14 23:55 . 2008-05-15 18:56 2008-05-14 23:54 . 2008-05-14 22:16 606 --a------ C:\WINDOWS\system32$winnt$.inf 2008-05-14 23:46 . 2008-05-14 22:13 2008-05-14 23:46 . 2008-05-14 23:46 2008-05-14 23:46 . 2008-05-14 23:49 2008-05-14 22:37 . 2008-05-14 22:37 2008-05-14 22:34 . 2008-05-15 09:37 2008-05-14 22:21 . 2008-05-16 09:01 2008-05-14 22:21 . 2008-05-15 23:15 2008-05-14 22:21 . 2008-05-14 22:10 2008-05-14 22:21 . 2008-05-16 08:56 2008-05-14 22:21 . 2008-05-16 00:22 2008-05-14 22:21 . 2008-05-14 22:34 2008-05-14 22:21 . 2008-05-15 23:57 2008-05-14 22:21 . 2008-05-16 00:36 2008-05-14 22:21 . 2008-05-14 22:21 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav 2008-05-14 22:21 . 2008-05-14 22:21 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav 2008-05-14 22:21 . 2008-05-16 09:01 65,536 --ah----- C:\Documents and Settings\bubu\ntuser.dat.LOG 2008-05-14 22:17 . 2008-05-16 09:01 2008-05-14 22:17 . 2008-05-16 09:01 2008-05-14 22:17 . 2008-05-14 22:17 2008-05-14 22:17 . 2008-05-14 22:17 2008-05-14 22:17 . 2008-05-14 22:17 2008-05-14 22:17 . 2008-05-16 09:01 2008-05-14 22:17 . 2008-05-16 09:01 2008-05-14 22:17 . 2008-05-14 22:17 2008-05-14 22:17 . 2008-05-14 22:17 2008-05-14 22:17 . 2008-05-14 22:17 2008-05-14 22:17 . 2008-05-14 22:17 8,192 --a------ C:\WINDOWS\REGLOCS.OLD 2008-05-14 22:17 . 2008-05-16 08:40 1,024 --ah----- C:\Documents and Settings\NetworkService.ZARZĄDZANIE NT\ntuser.dat.LOG 2008-05-14 22:17 . 2008-05-16 08:40 1,024 --ah----- C:\Documents and Settings\NetworkService.ZARZĄDZANIE NT\ntuser.dat.LOG 2008-05-14 22:17 . 2008-05-16 08:48 1,024 --ah----- C:\Documents and Settings\LocalService.ZARZĄDZANIE NT\ntuser.dat.LOG 2008-05-14 22:17 . 2008-05-16 08:48 1,024 --ah----- C:\Documents and Settings\LocalService.ZARZĄDZANIE NT\ntuser.dat.LOG 2008-05-14 22:15 . 2008-05-14 22:15 316,640 --a------ C:\WINDOWS\WMSysPr9.prx 2008-05-14 22:15 . 2006-11-08 10:51 62,336 --------- C:\WINDOWS\system32\drivers\rspndr.sys 2008-05-14 22:15 . 2008-05-14 22:15 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb 2008-05-14 22:15 . 2008-05-14 22:15 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb 2008-05-14 22:15 . 2006-11-08 10:51 10,752 --------- C:\WINDOWS\system32\rspndr.exe 2008-05-14 22:15 . 2008-05-14 22:15 2,596 --a------ C:\WINDOWS\system32\CONFIG.NT 2008-05-14 22:15 . 2008-05-14 22:15 0 --a------ C:\WINDOWS\control.ini 2008-05-14 22:14 . 2008-05-15 10:07 2008-05-14 22:14 . 2008-05-15 19:49 2008-05-14 22:13 . 2008-05-14 22:13 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-15 07:18 --------- d-----w C:\Program Files\Winamp 2008-05-15 06:55 --------- d-----w C:\Program Files\Atheros 2008-05-15 06:24 --------- d–h--w C:\Program Files\InstallShield Installation Information 2008-05-14 20:10 --------- d-----w C:\Program Files\Windows Media Connect 2 2008-05-14 19:37 --------- d-----w C:\Program Files\Kalendarz XP 2008-05-14 19:28 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\skypePM 2008-05-14 19:28 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Skype 2008-05-14 12:50 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Vso 2008-05-03 16:12 --------- d-----w C:\Program Files\Vstplugins 2008-05-02 07:03 --------- d-----w C:\Program Files\Common Files\Adobe 2008-04-21 20:32 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Hamachi 2008-04-17 07:23 --------- d-----w C:\Program Files\Common Files\MAGIX Shared 2008-04-15 08:29 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Publish Providers 2008-04-15 08:28 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Sony 2008-04-13 05:34 --------- d-----w C:\Program Files\ESET 2008-04-12 14:45 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Thinstall 2008-04-05 18:04 --------- d-----w C:\Program Files\plasq 2008-04-05 18:03 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-04-05 07:56 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\MagicEffect Photo 2008-04-05 07:33 --------- d-----w C:\Program Files\iFoxSoft 2008-04-05 07:26 --------- d-----w C:\Program Files\MagicEffect Photo Editor 2007 2008-04-02 16:09 --------- d-----w C:\Program Files\Gadu-Gadu 2008-03-31 11:51 --------- d-----w C:\Program Files\CDisplay 2008-03-29 14:16 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\vlc 2008-03-29 14:09 --------- d-----w C:\Program Files\VideoLAN 2008-03-29 13:59 --------- d-----w C:\Program Files\Elecard 2008-03-29 13:59 --------- d-----w C:\Program Files\Common Files\Elecard 2008-03-29 13:46 --------- d-----w C:\Program Files\GoldWave 2008-03-29 12:33 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Winamp 2008-03-27 17:12 --------- d-----w C:\Program Files\Paint.NET 2008-03-25 19:29 --------- d-----w C:\Program Files\Hamachi 2008-03-25 10:02 --------- d-----w C:\Program Files\Java 2008-03-25 04:52 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll 2008-03-25 04:52 621,344 ------w C:\WINDOWS\system32\dllcache\mswstr10.dll 2008-03-25 04:52 178,976 ----a-w C:\WINDOWS\system32\msjint40.dll 2008-03-25 04:52 178,976 ------w C:\WINDOWS\system32\dllcache\msjint40.dll 2008-03-20 08:01 1,846,144 ----a-w C:\WINDOWS\system32\win32k.sys 2008-03-20 08:01 1,846,144 ------w C:\WINDOWS\system32\dllcache\win32k.sys 2008-02-22 09:40 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2008-02-22 09:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-02-22 09:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-02-20 18:53 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll 2008-02-20 18:53 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll 2008-02-20 06:53 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll 2008-02-20 06:53 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll 2008-02-20 05:23 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll . ------- Sigcheck ------- 2007-07-10 17:06 642560 ce594e18fe0d0af804f1f3694921ce62 C:\WINDOWS\system32\user32.dll . ((((((((((((((((((((((((((((( snapshot@2008-05-15_23.30.23.73 ))))))))))))))))))))))))))))))))))))))))) . - 2008-05-15 21:24:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-05-16 06:39:11 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2007-10-31 11:41:16 110,096 ----a-w C:\WINDOWS\system32\drivers\kl1.sys + 2007-12-28 17:51:04 195,344 ----a-w C:\WINDOWS\system32\drivers\klif.sys + 2007-12-13 11:28:40 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys + 2008-02-08 16:35:42 23,604 ----a-w C:\WINDOWS\system32\drivers\klopp.dat + 2008-02-08 16:37:44 219,664 ----a-w C:\WINDOWS\system32\klogon.dll - 2008-05-15 20:20:51 39,056 ----a-w C:\WINDOWS\system32\perfc009.dat + 2008-05-16 06:44:19 39,056 ----a-w C:\WINDOWS\system32\perfc009.dat - 2008-05-15 20:20:51 48,316 ----a-w C:\WINDOWS\system32\perfc015.dat + 2008-05-16 06:44:19 48,316 ----a-w C:\WINDOWS\system32\perfc015.dat - 2008-05-15 20:20:51 309,428 ----a-w C:\WINDOWS\system32\perfh009.dat + 2008-05-16 06:44:19 309,428 ----a-w C:\WINDOWS\system32\perfh009.dat - 2008-05-15 20:20:51 353,352 ----a-w C:\WINDOWS\system32\perfh015.dat + 2008-05-16 06:44:19 353,352 ----a-w C:\WINDOWS\system32\perfh015.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 06:44 15360] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-05-10 16:36 2111176] “IDMan”=“C:\Program Files\Internet Download Manager\IDMan.exe” [2008-05-13 14:49 2594224] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SkyTel”=“SkyTel.EXE” [2006-07-19 09:42 2879488 C:\WINDOWS\SkyTel.exe] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2006-04-29 06:13 766041] “RTHDCPL”=“RTHDCPL.EXE” [2006-07-19 09:42 16248320 C:\WINDOWS\RTHDCPL.exe] “AzMixerSel”=“C:\Program Files\Realtek\InstallShield\AzMixerSel.exe” [2006-07-19 09:41 53248] “INPROCOMMWireless”=“C:\Program Files\Atheros\Wireless\Utility\WlanUtil.exe” [] “LManager”=“C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE” [2006-07-14 12:13 471040] “igfxtray”=“C:\WINDOWS\system32\igfxtray.exe” [2006-06-13 09:57 94208] “igfxhkcmd”=“C:\WINDOWS\system32\hkcmd.exe” [2006-06-13 09:57 77824] “igfxpers”=“C:\WINDOWS\system32\igfxpers.exe” [2006-06-13 09:57 118784] “AVP”=“C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe” [2008-02-08 18:36 227856] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 06:44 15360] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] “nltide_3”=“advpack.dll” [2008-03-01 14:35 124928 C:\WINDOWS\system32\advpack.dll] C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\ YouTube Uploader.lnk - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\YouTube\Uploader\youtubeuploader.exe [2007-11-09 14:33:08 71152] C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\ BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 10:45:32 618557] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “DisableStatusMessages”= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoSMMyPictures”= 1 (0x1) “NoSMConfigurePrograms”= 1 (0x1) “NoSMHelp”= 1 (0x1) [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer] “NoSMMyPictures”= 1 (0x1) “NoSMConfigurePrograms”= 1 (0x1) “NoSMHelp”= 1 (0x1) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] “mpfanvqg”= {45F2571A-A6FA-4935-8036-20A9FB50A203} - C:\WINDOWS\mpfanvqg.dll [] [HKEY_LOCAL_MACHINE\software\microsoft\security center] “AntiVirusDisableNotify”=dword:00000001 “AntiVirusOverride”=dword:00000001 “FirewallOverride”=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] “DisableMonitoring”=dword:00000001 [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile] “EnableFirewall”= 0 (0x0) [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\Network Diagnostic\xpnetdiag.exe”= “%windir%\system32\sessmgr.exe”= “C:\Program Files\Gadu-Gadu\gg.exe”= R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28] . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-16 09:01:25 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-05-16 9:03:01 ComboFix-quarantined-files.txt 2008-05-16 07:02:54 Pre-Run: 20,804,104,192 bajtów wolnych Post-Run: 20,840,439,808 bajtów wolnych 319 — E O F — 2008-05-15 08:07:44