Jacek - 06-12-22 19:08:36,01 Dodatek Service Pack 2 ComboFix 06.11.27 - Running from: “C:\Documents and Settings\Jacek\Pulpit” ((((((((((((((((((((((((((((((( Files Created from 2006-11-22 to 2006-12-22 )))))))))))))))))))))))))))))))))) 2006-12-22 00:39 2006-12-21 16:40 2006-12-20 17:14 2006-12-11 11:16 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll 2006-12-07 16:51 233,472 --a------ C:\WINDOWS\system32\libmysql.dll 2006-12-01 21:27 2006-11-28 10:52 2006-11-28 10:51 15,440 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2006-11-28 10:51 2006-11-27 11:05 2006-11-26 23:41 2006-11-23 13:17 2006-11-22 11:54 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-12-22 01:19 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Skype 2006-12-21 23:32 -------- d-------- C:\Program Files\Winamp 2006-12-21 22:15 -------- d-------- C:\Program Files\FlashGet 2006-12-21 17:44 -------- d–h----- C:\Program Files\InstallShield Installation Information 2006-12-20 15:42 -------- d-------- C:\Program Files\DC++ 2006-12-14 22:44 -------- d-------- C:\Program Files\Internet Explorer 2006-12-14 22:42 -------- d-------- C:\Program Files\Outlook Express 2006-12-14 22:42 -------- d-------- C:\Program Files\Common Files\System 2006-12-13 12:13 -------- d-------- C:\Program Files\Common Files\InstallShield 2006-12-07 17:02 2174976 --a------ C:\WINDOWS\system32\wmvcore.dll 2006-12-04 16:02 -------- d-------- C:\Program Files\Java 2006-12-02 17:06 -------- d—s---- C:\Documents and Settings\Jacek\Dane aplikacji\Microsoft 2006-12-01 21:28 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Lavasoft 2006-12-01 02:09 -------- d-------- C:\Program Files\SkanerOnline 2006-11-27 14:00 707360 --a------ C:\WINDOWS\system32\SkanerOnline.dll 2006-11-27 14:00 69920 --a------ C:\WINDOWS\system32\SkanerOnlineUninstall.exe 2006-11-20 20:58 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\teamspeak2 2006-11-20 16:37 -------- d-------- C:\Program Files\Common Files\Borland Shared 2006-11-20 16:35 -------- d-------- C:\Program Files\Borland 2006-11-18 21:57 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Real 2006-11-18 21:15 -------- d-------- C:\Program Files\Real Alternative 2006-11-18 20:48 3082 --a------ C:\WINDOWS\system32\affv208325p1now.sys 2006-11-17 23:31 -------- d-------- C:\Program Files\ESET 2006-11-15 11:42 -------- d-------- C:\Program Files\Common Files 2006-11-11 16:47 -------- d-------- C:\Program Files\Common Files\NSV 2006-11-08 21:03 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\AdobeUM 2006-11-08 20:22 -------- d-------- C:\Program Files\Common Files\Synactis 2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll 2006-11-06 12:13 640512 --a------ C:\WINDOWS\system32\oc30.dll 2006-11-06 12:13 62464 --a------ C:\WINDOWS\system32\vspell32.dll 2006-11-06 12:13 566784 --a------ C:\WINDOWS\system32\vcfiwz32.dll 2006-11-06 12:13 527360 --a------ C:\WINDOWS\system32\stdvcl40.dll 2006-11-06 12:13 345536 --a------ C:\WINDOWS\system32\stdvcl32.dll 2006-11-06 12:13 149504 --a------ C:\WINDOWS\system32\mfcans32.dll 2006-11-06 12:13 1115136 --a------ C:\WINDOWS\system32\vcfidl32.dll 2006-11-05 15:43 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Media Player Classic 2006-11-05 15:41 -------- d-------- C:\Program Files\K-Lite Codec 2006-11-05 12:50 -------- d-------- C:\Program Files\RegCleaner 2006-11-03 12:15 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys 2006-11-02 20:31 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Help 2006-10-31 14:54 -------- d-------- C:\Program Files\Nero 2006-10-31 14:54 -------- d-------- C:\Program Files\Common Files\Ahead 2006-10-31 14:38 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Adobe 2006-10-30 22:12 -------- d-------- C:\Program Files\Skype 2006-10-30 21:56 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Sun 2006-10-28 23:07 -------- d-------- C:\Program Files\Common Files\Nero 2006-10-28 22:55 -------- d-------- C:\Program Files\Gadu-Gadu 2006-10-28 22:50 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Macromedia 2006-10-28 22:25 -------- d-------- C:\Program Files\Switch Off 2006-10-28 22:19 -------- d-------- C:\Program Files\Daemon 2006-10-28 22:14 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\CyberLink 2006-10-28 19:28 -------- d-------- C:\Program Files\Common Files\SpeechEngines 2006-10-28 19:28 -------- d-------- C:\Program Files\Common Files\ODBC 2006-10-28 19:27 62 --ahs---- C:\Documents and Settings\Jacek\Dane aplikacji\desktop.ini 2006-10-28 19:16 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Ahead 2006-10-28 19:06 -------- d-------- C:\Program Files\CyberLink 2006-10-28 18:29 -------- d-------- C:\Program Files\Common Files\Microsoft Shared 2006-10-28 18:28 -------- d-------- C:\Program Files\Microsoft Works 2006-10-28 18:28 -------- d-------- C:\Program Files\Microsoft Visual Studio 2006-10-28 18:28 -------- d-------- C:\Program Files\Microsoft Office 2006-10-28 18:28 -------- d-------- C:\Program Files\Common Files\DESIGNER 2006-10-28 18:27 -------- d-------- C:\Program Files\Microsoft.NET 2006-10-28 18:24 -------- d-------- C:\Program Files\Common Files\Adobe 2006-10-28 18:23 -------- d-------- C:\Program Files\Adobe 2006-10-28 18:20 502368 --a------ C:\WINDOWS\system32\drivers\amon.sys 2006-10-28 18:20 274432 --a------ C:\WINDOWS\system32\imon.dll 2006-10-28 18:15 -------- d-------- C:\Program Files\Malicious Software Removal Tool 2006-10-28 18:10 -------- d-------- C:\Program Files\Windows Media Player 2006-10-28 18:07 -------- d-------- C:\Program Files\HighMAT CD Writing Wizard 2006-10-28 17:52 -------- d-------- C:\Program Files\Synaptics 2006-10-28 17:50 -------- d-------- C:\Program Files\Realtek 2006-10-28 17:46 -------- d-------- C:\Program Files\WinRAR 2006-10-28 17:44 -------- d–h----- C:\Program Files\Uninstall Information 2006-10-28 17:44 -------- d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Identities 2006-10-28 17:39 -------- d-------- C:\Program Files\xerox 2006-10-28 17:39 -------- d-------- C:\Program Files\microsoft frontpage 2006-10-28 17:37 -------- d-------- C:\Program Files\Common Files\Java 2006-10-28 17:34 0 -rahs---- C:\MSDOS.SYS 2006-10-28 17:34 0 -rahs---- C:\IO.SYS 2006-10-28 17:34 0 --a------ C:\CONFIG.SYS 2006-10-28 17:34 0 --a------ C:\AUTOEXEC.BAT 2006-10-28 17:33 -------- d–h----- C:\Program Files\WindowsUpdate 2006-10-28 17:32 -------- d-------- C:\Program Files\NetMeeting 2006-10-28 17:32 -------- d-------- C:\Program Files\Movie Maker 2006-10-28 17:32 -------- d-------- C:\Program Files\Common Files\Services 2006-10-28 17:32 -------- d-------- C:\Program Files\Common Files\MSSoap 2006-10-28 17:31 -------- d-------- C:\Program Files\Windows NT 2006-10-28 17:31 -------- d-------- C:\Program Files\MSN Gaming Zone 2006-10-20 02:41 714240 --a------ C:\WINDOWS\system32\sxs.dll 2006-10-13 13:41 143872 --a------ C:\WINDOWS\system32\nwprovau.dll 2006-10-04 04:25 556032 --a------ C:\WINDOWS\system32\x264vfw.dll 2006-10-02 21:04 635486 --a------ C:\WINDOWS\system32\divx.dll 2006-10-02 13:44 5120 --a------ C:\WINDOWS\system32\ff_vfw.dll 2006-09-26 23:00 561152 --a------ C:\WINDOWS\system32\NETw3c32.dll 2006-09-26 23:00 2732032 --a------ C:\WINDOWS\system32\NETw3r32.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “SunJavaUpdateSched”="“C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe”" “RTHDCPL”=“RTHDCPL.EXE” “Alcmtr”=“ALCMTR.EXE” “SynTPEnh”="“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe”" “nod32kui”="“C:\Program Files\Eset\nod32kui.exe” /WAITSERVICE" “RemoteControl”="“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”" “NvCplDaemon”="“RUNDLL32.EXE” C:\WINDOWS\system32\NvCpl.dll,NvStartup" “nwiz”=“nwiz.exe /install” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] “DeskHtmlVersion”=dword:00000110 “DeskHtmlMinorVersion”=dword:00000005 “Settings”=dword:00000001 “GeneralFlags”=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] “Source”=“About:Home” “SubscribedURL”=“About:Home” “FriendlyName”=“Moja bieżąca strona główna” “Flags”=dword:00000002 “Position”=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,fe,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 “CurrentState”=hex:04,00,00,40 “OriginalStateInfo”=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\ 00,00,04,00,00,40 “RestoredStateInfo”=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\ 00,00,01,00,00,00 [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] “{438755C2-A8BA-11D1-B96B-00A0C90312E1}”=“Moduł wstępnego ładowania interfejsu Browseui” “{8C7461EF-2B13-11d2-BE35-3078302C2030}”=“Demon buforu kategorii składników” “{ab340860-fd81-4a65-b345-82eb77a66b5e}”=“featherweed” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{AEB6717E-7E19-11d0-97EE-00C04FD91972}”="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “dontdisplaylastusername”=dword:00000000 “legalnoticecaption”="" “legalnoticetext”="" “shutdownwithoutlogon”=dword:00000001 “undockwithoutlogon”=dword:00000001 [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] “NoDriveTypeAutoRun”=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] “PostBootReminder”="{7849596a-48ea-486e-8937-a2a3009f31a9}" “CDBurn”="{fbeb8a05-beee-4442-804e-409d6c4515e9}" “WebCheck”="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" “SysTray”="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” Completion time: 06-12-22 19:08:56.64 C:\ComboFix.txt … 06-12-22 19:08