“ShaM” - 07-08-26 12:07:22 Dodatek Service Pack 2 ComboFix 07-01-21 - Running from: “D:\Documents and Settings\ShaM\Moje dokumenty” ((((((((((((((((((((((((((((((( Files Created from 2007-07-26 to 2007-08-26 )))))))))))))))))))))))))))))))))) 2007-08-25 11:08 2007-08-24 17:43 53,248 --a------ D:\WINDOWS\system32\ImageOle.dll 2007-08-24 17:42 2007-08-23 23:32 2,829 --a------ D:\WINDOWS\War3Unin.pif 2007-08-23 23:32 139,264 --a------ D:\WINDOWS\War3Unin.exe 2007-08-18 01:06 4,682 --a------ D:\WINDOWS\system32\npptNT2.sys 2007-08-17 10:13 2007-08-16 12:27 98,304 -ra------ D:\WINDOWS\system32\nvrsel.dll 2007-08-16 12:27 94,208 -ra------ D:\WINDOWS\system32\nvrspt.dll 2007-08-16 12:27 94,208 -ra------ D:\WINDOWS\system32\nvdmcpl.dll 2007-08-16 12:27 90,112 -ra------ D:\WINDOWS\system32\nvrstr.dll 2007-08-16 12:27 90,112 -ra------ D:\WINDOWS\system32\nvrssl.dll 2007-08-16 12:27 90,112 -ra------ D:\WINDOWS\system32\nvrssk.dll 2007-08-16 12:27 90,112 -ra------ D:\WINDOWS\system32\nvrspl.dll 2007-08-16 12:27 90,112 -ra------ D:\WINDOWS\system32\nvrshu.dll 2007-08-16 12:27 86,016 -ra------ D:\WINDOWS\system32\nvrsja.dll 2007-08-16 12:27 81,920 -ra------ D:\WINDOWS\system32\nvrsko.dll 2007-08-16 12:27 81,920 -ra------ D:\WINDOWS\system32\nvrshe.dll 2007-08-16 12:27 73,728 -ra------ D:\WINDOWS\system32\nvrszht.dll 2007-08-16 12:27 61,440 -ra------ D:\WINDOWS\system32\nvrszhc.dll 2007-08-16 12:27 114,688 -ra------ D:\WINDOWS\system32\nvrsptb.dll 2007-08-16 12:27 114,688 -ra------ D:\WINDOWS\system32\nvrsnl.dll 2007-08-16 12:27 114,688 -ra------ D:\WINDOWS\system32\nvrsit.dll 2007-08-16 12:27 114,688 -ra------ D:\WINDOWS\system32\nvrsfr.dll 2007-08-16 12:27 114,688 -ra------ D:\WINDOWS\system32\nvrses.dll 2007-08-16 12:27 110,592 -ra------ D:\WINDOWS\system32\nvrsru.dll 2007-08-16 12:27 110,592 -ra------ D:\WINDOWS\system32\nvrsde.dll 2007-08-16 12:27 110,592 -ra------ D:\WINDOWS\system32\nvqtwk.dll 2007-08-16 12:27 106,496 -ra------ D:\WINDOWS\system32\nvrssv.dll 2007-08-16 12:27 106,496 -ra------ D:\WINDOWS\system32\nvrsno.dll 2007-08-16 12:27 106,496 -ra------ D:\WINDOWS\system32\nvrsfi.dll 2007-08-16 12:27 106,496 -ra------ D:\WINDOWS\system32\nvrseng.dll 2007-08-16 12:27 106,496 -ra------ D:\WINDOWS\system32\nvrsda.dll 2007-08-16 12:27 106,496 -ra------ D:\WINDOWS\system32\nvrscs.dll 2007-08-16 12:27 102,400 -ra------ D:\WINDOWS\system32\nvrsar.dll 2007-08-16 12:27 102,400 -ra------ D:\WINDOWS\system32\nvdesk32.dll 2007-08-08 18:13 2007-08-08 10:30 2007-08-08 10:30 2007-08-08 10:02 2007-08-08 09:31 25,664 --a------ D:\WINDOWS\system32\Ui3v63do.exe 2007-08-06 23:44 80 --a------ D:\WINDOWS\gmer_uninstall.cmd 2007-08-06 23:37 464 --a------ D:\WINDOWS\system32\tmp.reg 2007-08-06 22:21 23 --ahs---- D:\WINDOWS\system32\adafaecafa_r.dll 2007-08-06 22:21 2007-08-05 21:43 2007-08-05 21:42 2007-08-05 21:41 2007-08-05 21:26 2007-08-05 20:58 2007-07-28 23:17 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-24 17:43 -------- d–h----- D:\Program Files\installshield installation information 2007-08-08 18:20 -------- d—s---- D:\DOCUME~1\ShaM\Dane aplikacji\microsoft 2007-07-20 12:48 -------- d-------- D:\Program Files\alwil software 2007-07-18 20:34 -------- d-------- D:\Program Files\bitcomet 2007-07-14 06:45 -------- d-------- D:\DOCUME~1\ShaM\Dane aplikacji\zoo digital publishing 2007-07-13 22:00 -------- d-------- D:\Program Files\Common Files\adobe 2007-07-13 22:00 -------- d-------- D:\DOCUME~1\ShaM\Dane aplikacji\adobe 2007-07-12 13:33 -------- d-------- D:\Program Files\real alternative 2007-07-12 13:33 -------- d-------- D:\Program Files\media player classic 2007-07-12 13:32 -------- d-------- D:\DOCUME~1\ShaM\Dane aplikacji\real 2007-07-09 17:03 -------- d-------- D:\DOCUME~1\ShaM\Dane aplikacji\secondlife 2007-07-09 16:38 -------- d-------- D:\DOCUME~1\ShaM\Dane aplikacji\mozilla 2007-07-07 11:47 -------- d-------- D:\Program Files\softwaredoctor 2007-06-28 18:54 180224 --a------ D:\WINDOWS\system32\xvidvfw.dll 2007-06-28 18:52 765952 --a------ D:\WINDOWS\system32\xvidcore.dll 2007-06-27 17:03 -------- d-------- D:\Program Files\sagem (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“D:\WINDOWS\system32\ctfmon.exe” “DAEMON Tools”="“D:\Program Files\DAEMON Tools\daemon.exe” -lang 1033" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “NeroCheck”=“D:\WINDOWS\system32\NeroCheck.exe” “NvCplDaemon”=“RUNDLL32.EXE NvQTwk,NvCplDaemon initialize” “KernelFaultCheck”=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\ 65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^ShaM^Menu Start^Programy^Autostart^UniSpiker-2.6.lnk] “path”=“D:\Documents and Settings\ShaM\Menu Start\Programy\Autostart\UniSpiker-2.6.lnk” “backup”=“D:\WINDOWS\pss\UniSpiker-2.6.lnkStartup” “location”=“Startup” “command”=“D:\PROGRA~1\ivo\UNISPI~1.6\UNI_SP~1.EXE " “item”=“UniSpiker-2.6” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“tlen” “hkey”=“HKCU” “command”=“D:\Program Files\Tlen.pl\tlen.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load] “key”=“SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows” “item”=“watch” “hkey”=“HKCU” “command”=“D:\YDPDict\watch.exe” “inimapping”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“jhkmsskl” “hkey”=“HKLM” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “wuauserv”=dword:00000002 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{B6C43182-63AE-4F13-9980-714EB0A6CB3F}”=”" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 Contents of the ‘Scheduled Tasks’ folder D:\WINDOWS\tasks\At1.job D:\WINDOWS\tasks\At10.job D:\WINDOWS\tasks\At11.job D:\WINDOWS\tasks\At12.job D:\WINDOWS\tasks\At13.job D:\WINDOWS\tasks\At14.job D:\WINDOWS\tasks\At15.job D:\WINDOWS\tasks\At16.job D:\WINDOWS\tasks\At17.job D:\WINDOWS\tasks\At18.job D:\WINDOWS\tasks\At19.job D:\WINDOWS\tasks\At2.job D:\WINDOWS\tasks\At20.job D:\WINDOWS\tasks\At21.job D:\WINDOWS\tasks\At22.job D:\WINDOWS\tasks\At23.job D:\WINDOWS\tasks\At24.job D:\WINDOWS\tasks\At3.job D:\WINDOWS\tasks\At4.job D:\WINDOWS\tasks\At5.job D:\WINDOWS\tasks\At6.job D:\WINDOWS\tasks\At7.job D:\WINDOWS\tasks\At8.job D:\WINDOWS\tasks\At9.job Completion time: 07-08-26 12:11:07