Andzia - 06-09-04 16:21:02,99 
ComboFix 06.09.04BT - Running from: C:\Documents and Settings\Andzia.LENCZEWSKI\Pulpit 
Microsoft Windows XP [Wersja 5.1.2600]
((((((((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
 
 
C:\Documents and Settings\Andzia.LENCZEWSKI\Dane aplikacji\Install.dat
 
 
(((((((((((((((((((((((((((((((   Files Created from 2006-08-04 to 2006-09-04  ))))))))))))))))))))))))))))))))))
 
2006-09-04	15:37	671,744	-r-hs----	C:\WINDOWS\system32\nqfgaaesh.exe
2006-09-02	20:25	671,744	-r-hs----	C:\WINDOWS\system32\yfiyyezap.exe
2006-08-31	12:51	671,744	-r-hs----	C:\WINDOWS\system32\hzhspckar.exe
2006-08-31	12:42	671,744	-r-hs----	C:\WINDOWS\system32\aogszewal.exe
2006-08-30	23:31	671,744	-r-hs----	C:\WINDOWS\system32\lhnuavhwn.exe
2006-08-30	13:24	8,628	--a------	C:\WINDOWS\system32\mszsrn32.dll
2006-08-30	12:56	671,744	-r-hs----	C:\WINDOWS\system32\hwgpcllng.exe
2006-08-29	20:05	671,744	-r-hs----	C:\WINDOWS\system32\reezgpqge.exe
2006-08-29	13:34	671,744	-r-hs----	C:\WINDOWS\system32\fbvccxktb.exe
2006-08-26	13:12	671,744	-ra------	C:\WINDOWS\system32\jjeuskkie.exe
2006-08-26	13:12	671,744	-r-hs----	C:\WINDOWS\system32\omecztrox.exe
2006-08-26	12:57	171,520	--a------	C:\WINDOWS\system32\LXAESUI.DLL
2006-08-26	12:55	221,696	--a------	C:\WINDOWS\system32\qmgr.dll
2006-08-26	12:55	17,408	--a------	C:\WINDOWS\system32\qmgrprxy.dll
2006-08-26	12:54	869,376	--a------	C:\WINDOWS\system32\msdtctm.dll
2006-08-26	12:54	83,968	--a------	C:\WINDOWS\system32\mtxoci.dll
2006-08-26	12:54	582,656	--a------	C:\WINDOWS\system32\catsrvut.dll
2006-08-26	12:54	56,832	--a------	C:\WINDOWS\system32\colbact.dll
2006-08-26	12:54	495,616	--a------	C:\WINDOWS\system32\comuid.dll
2006-08-26	12:54	494,592	--a------	C:\WINDOWS\system32\hypertrm.dll
2006-08-26	12:54	468,480	--a------	C:\WINDOWS\system32\clbcatq.dll
2006-08-26	12:54	359,936	--a------	C:\WINDOWS\system32\msdtcprx.dll
2006-08-26	12:54	215,040	--a------	C:\WINDOWS\system32\catsrv.dll
2006-08-26	12:54	151,040	--a------	C:\WINDOWS\system32\msdtcuiu.dll
2006-08-26	12:54	114,968	--a------	C:\WINDOWS\system32\wuauclt.exe
2006-08-26	12:54	100,864	--a------	C:\WINDOWS\system32\clbcatex.dll
2006-08-26	12:54	1,172,992	--a------	C:\WINDOWS\system32\comsvcs.dll
2006-08-26	12:54	1,081,112	--a------	C:\WINDOWS\system32\wuaueng.dll
2006-08-26	12:46	51,200	--a------	C:\WINDOWS\system32\sfman32.dll
2006-08-26	12:46	495,616	--a------	C:\WINDOWS\system32\sblfx.dll
2006-08-26	12:46	4,096	--a------	C:\WINDOWS\system32\ctwdm32.dll
2006-08-26	12:46	256,512	--a------	C:\WINDOWS\system32\devcon32.dll
2006-08-26	12:46	24,064	--a------	C:\WINDOWS\system32\devldr32.exe
2006-08-26	12:44	24,661	--a------	C:\WINDOWS\system32\spxcoins.dll
2006-08-26	12:44	13,312	--a------	C:\WINDOWS\system32\irclass.dll
2006-08-15	14:21	274,432	--a------	C:\WINDOWS\system32\imon.dll
2006-08-04	16:37	73,728	--a------	C:\WINDOWS\system32\dpl100.dll
2006-08-04	16:37	196,608	--a------	C:\WINDOWS\system32\dtu100.dll
 
((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-04 15:09	--------	d--------	C:\Program Files\Warez
2006-09-04 15:09	--------	d--------	C:\Documents and Settings\Andzia.LENCZEWSKI\Dane aplikacji\Warez
2006-08-29 19:50	--------	d--------	C:\Program Files\Spik
2006-08-26 18:57	--------	d--------	C:\Program Files\URUSoft
2006-08-26 18:35	--------	d--------	C:\Program Files\SubEdit-Player
2006-08-26 12:54	--------	d--------	C:\Program Files\Messenger
2006-08-25 12:37	--------	d--------	C:\Program Files\Codec
2006-08-25 12:07	--------	d--------	C:\Program Files\XP Codec Pack
2006-08-15 14:21	502368	--a------	C:\WINDOWS\system32\drivers\amon.sys
2006-07-27 03:06	3596288	--a------	C:\WINDOWS\system32\qt-dx331.dll
2006-07-13 10:51	700184	--a------	C:\WINDOWS\system32\SkanerOnline.dll
2006-07-03 22:40	620180	--a------	C:\WINDOWS\system32\divx.dll
2006-06-29 15:14	69944	--a------	C:\WINDOWS\system32\SkanerOnlineUninstall.exe
2006-06-28 16:11	675	--a------	C:\fix.reg
2006-06-21 11:43	520192	--a------	C:\WINDOWS\system32\divxsm.exe
2006-06-21 11:42	1044480	--a------	C:\WINDOWS\system32\libdivx.dll
 
((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
 
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="\"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE"
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
"Winsockett"="nqfgaaesh.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Warez"="\"C:\\Program Files\\Warez\\Warez.exe\" /minimized"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices]
"msvcc25"="svcchost.exe"
"Winsockett"="nqfgaaesh.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="http://www.tapety4u.pl/albums/krajobrazy/national_geographic/normal_126.jpg"
"SubscribedURL"="http://www.tapety4u.pl/albums/krajobrazy/national_geographic/normal_126.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,e6,00,00,00,00,00,00,00,9a,03,00,00,42,03,00,00,00,\
  00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,98,00,00,00,00,00,00,00,e8,03,00,00,42,03,\
  00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,98,00,00,00,00,00,00,00,e8,03,00,00,42,03,\
  00,00,01,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Moja bieżąca strona główna"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,52,01,00,00,23,00,00,00,7c,00,00,00,72,00,00,00,ea,\
  03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,72,03,00,00,23,00,00,00,fc,00,00,00,f2,00,\
  00,00,01,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,72,03,00,00,23,00,00,00,fc,00,00,00,f2,00,\
  00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^abcHood Pager 1.0.lnk]
"backup"="C:\\WINDOWS\\pss\\abcHood Pager 1.0.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\ScannerU\\PageABC\\abcPager\\abcPager.exe -loadstatus -hide"
"item"="abcHood Pager 1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Action Manager 32.lnk]
"backup"="C:\\WINDOWS\\pss\\Action Manager 32.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\ScannerU\\AM32.exe "
"item"="Action Manager 32"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Kalendarz XP.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programy\\Autostart\\Kalendarz XP.lnk"
"backup"="C:\\WINDOWS\\pss\\Kalendarz XP.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\KALEND~1\\KALEND~1.EXE "
"item"="Kalendarz XP"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^TV Remote Control.lnk]
"backup"="C:\\WINDOWS\\pss\\TV Remote Control.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\AVACSM~1\\TV88XU~1\\C8XRCtl.exe "
"item"="TV Remote Control"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\bme91d0e]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="bme91d0e"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\CTFMON.EXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\System32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Internet Optimizer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="optimize"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\msvcc25]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="svcchost"
"hkey"="HKLM"
"command"="svcchost.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NBJ]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NBJ"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PowerS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PowerS"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Preview AdService]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PrevAdServ"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vxh8jkdq2"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\System32\\vxh8jkdq2.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Run]
"key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows"
"item"="winlogon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\inet20004\\winlogon.exe"
"inimapping"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\salm]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="salm"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Speed racer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTSRReg"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Spik]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Spik"
"hkey"="HKLM"
"command"="C:\\Program Files\\Spik\\Spik.exe -autostart"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Updreg"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\Updreg.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Warez]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Warez"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Warez\\Warez.exe\" /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winampa"
"hkey"="HKLM"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Windows installer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winstall"
"hkey"="HKCU"
"command"="C:\\winstall.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Winsockett]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="yfiyyezap"
"hkey"="HKLM"
"command"="yfiyyezap.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\xp_system]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winlogon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\inet20004\\winlogon.exe"
"inimapping"="0"
  
 
 
Completion time: 2006-09-04 16:21:30.13 
ComboFix.txt