Smydowie - 07-01-29 16:15:45,02 Dodatek Service Pack 2 ComboFix 06.11.27 - Running from: “C:\Documents and Settings\Smydowie.SMYDA-47B33471D\Pulpit” ((((((((((((((((((((((((((((((( Files Created from 2006-12-29 to 2007-01-29 )))))))))))))))))))))))))))))))))) 2007-01-27 21:23 94,424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-01-27 21:23 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-01-27 21:23 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-01-27 21:23 31,560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-01-27 21:23 23,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-01-27 21:22 90,112 --a------ C:\WINDOWS\system32\AVASTSS.scr 2007-01-27 21:22 689,280 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-01-27 18:30 2007-01-23 21:11 9,488 --a------ C:\WINDOWS\system32\sporder.dll 2007-01-23 21:10 2007-01-23 21:04 2007-01-23 15:59 2007-01-21 12:55 2007-01-21 12:17 2007-01-20 14:50 299,520 --a------ C:\WINDOWS\uninst.exe 2007-01-19 15:03 2007-01-18 22:05 81,920 --a------ C:\WINDOWS\system32\closeapp.exe 2007-01-18 22:05 19,968 --a------ C:\WINDOWS\system32\reico.exe 2007-01-18 22:05 111,104 --a------ C:\WINDOWS\system32\Uharc.exe 2007-01-18 22:05 2007-01-08 19:57 2007-01-07 11:49 2006-12-29 10:18 2006-12-29 10:03 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-12-10 22:07 -------- d-------- C:\Program Files\Wolfenstein - Enemy Territory (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “LogitechSoftwareUpdate”="“C:\Program Files\Logitech\Video\ManifestEngine.exe” boot" “PowerBar”="" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “LVCOMSX”=“C:\WINDOWS\system32\LVCOMSX.EXE” “LogitechVideoRepair”=“C:\Program Files\Logitech\Video\ISStart.exe " “RemoteControl”=”“C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe”" “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] “DeskHtmlVersion”=dword:00000110 “DeskHtmlMinorVersion”=dword:00000005 “Settings”=dword:00000001 “GeneralFlags”=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] “Source”=“About:Home” “SubscribedURL”=“About:Home” “FriendlyName”=“Moja bieżąca strona główna” “Flags”=dword:00000002 “Position”=hex:2c,00,00,00,e6,00,00,00,00,00,00,00,9a,03,00,00,3e,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 “CurrentState”=hex:04,00,00,40 “OriginalStateInfo”=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 “RestoredStateInfo”=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] “{438755C2-A8BA-11D1-B96B-00A0C90312E1}”=“Moduł wstępnego ładowania interfejsu Browseui” “{8C7461EF-2B13-11d2-BE35-3078302C2030}”=“Demon buforu kategorii składników” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{AEB6717E-7E19-11d0-97EE-00C04FD91972}”="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “dontdisplaylastusername”=dword:00000000 “legalnoticecaption”="" “legalnoticetext”="" “shutdownwithoutlogon”=dword:00000001 “undockwithoutlogon”=dword:00000001 [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] “PostBootReminder”="{7849596a-48ea-486e-8937-a2a3009f31a9}" “CDBurn”="{fbeb8a05-beee-4442-804e-409d6c4515e9}" “WebCheck”="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" “SysTray”="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Start^Programy^Autostart^Logitech Desktop Messenger.lnk] “path”=“C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\Logitech Desktop Messenger.lnk” “backup”=“C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LDMConf.exe /start” “item”=“Logitech Desktop Messenger” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“ctfmon” “hkey”=“HKCU” “command”=“C:\WINDOWS\system32\ctfmon.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“hpotdd01” “hkey”=“HKLM” “command”=“C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“HPWuSchd2” “hkey”=“HKLM” “command”=“C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“hpztsb08” “hkey”=“HKLM” “command”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“LogitechDesktopMessenger” “hkey”=“HKCU” “command”=“C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“LogiTray” “hkey”=“HKLM” “command”=“C:\Program Files\Logitech\Video\LogiTray.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“msmsgs” “hkey”=“HKCU” “command”="“C:\Program Files\Messenger\msmsgs.exe” /background" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NeroCheck” “hkey”=“HKLM” “command”=“C:\WINDOWS\system32\NeroCheck.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“qttask” “hkey”=“HKLM” “command”="“C:\Program Files\QuickTime\qttask.exe” -atboottime" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“Application Launcher” “hkey”=“HKLM” “command”="“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“jusched” “hkey”=“HKLM” “command”="“C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” Contents of the ‘Scheduled Tasks’ folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job Completion time: 07-01-29 16:17:54.05 C:\ComboFix.txt … 07-01-29 16:17