ComboFix 07-12-21.4 - MICHU 2007-12-27 22:41:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1607 [GMT 1:00]
Running from: C:\Documents and Settings\MICHU\Pulpit\ComboFix(2).exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-11-27 to 2007-12-27 )))))))))))))))))))))))))))))))
.
2007-12-27 22:38 . 2007-12-27 22:38 <DIR> d--h----- C:\WINDOWS\PIF
2007-12-27 22:07 . 2007-12-27 22:07 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-27 21:36 . 2007-12-27 21:36 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\Thinstall
2007-12-27 20:55 . 2007-10-16 14:29 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-27 20:55 . 2007-10-16 14:29 1,036,288 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-27 20:43 . 2007-10-25 17:44 8,488,960 -----c--- C:\WINDOWS\system32\dllcache\shell32.dll
2007-12-27 20:39 . 2007-04-02 07:37 546,304 -----c--- C:\WINDOWS\system32\dllcache\hhctrl.ocx
2007-12-27 13:05 . 2007-12-27 13:05 <DIR> d-------- C:\Program Files\FastStone Image Viewer
2007-12-27 13:05 . 2007-12-27 13:05 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\FastStone
2007-12-21 20:54 . 2007-12-22 11:25 <DIR> d-------- C:\Program Files\Kyodai Mahjongg 2006
2007-12-21 18:27 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2007-12-21 18:27 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-12-21 18:27 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll
2007-12-21 18:27 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-12-21 18:27 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll
2007-12-21 18:27 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-12-21 18:27 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2007-12-21 18:27 . 2007-07-20 00:57 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll
2007-12-19 21:06 . 2007-12-19 21:06 <DIR> d-------- C:\Program Files\SAGEM
2007-12-18 16:25 . 2007-12-18 16:25 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\Media Player Classic
2007-12-14 21:56 . 2007-12-14 21:56 <DIR> d-------- C:\Program Files\Common Files\Agnitum Shared
2007-12-14 21:23 . 2007-12-19 21:25 <DIR> d-------- C:\Program Files\Creative
2007-12-14 21:22 . 2007-12-27 21:25 <DIR> d-------- C:\WINDOWS\CtDrvInstall
2007-12-14 19:53 . 2007-12-18 21:43 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\PC Tools
2007-12-14 18:47 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-12-14 18:47 . 2004-01-09 11:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2007-12-14 18:47 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-12-14 18:47 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-14 18:47 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-14 18:47 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-14 18:47 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-14 18:47 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-14 16:02 . 2003-06-12 23:25 7,062 --a------ C:\WINDOWS\system32\audiopid.vxd
2007-12-14 16:01 . 2000-05-22 09:58 647,872 --------- C:\WINDOWS\system32\Mscomct2.ocx
2007-12-14 16:01 . 1999-10-11 02:00 41,984 --------- C:\WINDOWS\Ctregrun.exe
2007-12-14 15:58 . 2003-03-19 06:19 1,060,864 --a------ C:\WINDOWS\system32\MFC71.DLL
2007-12-14 15:58 . 2003-03-18 13:14 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-12-14 15:58 . 2003-02-21 05:42 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-12-14 15:58 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-12-12 17:34 . 2007-12-27 18:09 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\skypePM
2007-12-12 17:34 . 2007-12-12 17:34 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2007-12-12 17:31 . 2007-12-12 17:31 <DIR> d-------- C:\Program Files\Skype
2007-12-12 17:31 . 2007-12-12 17:31 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-12-12 17:31 . 2007-12-27 21:04 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\Skype
2007-12-12 17:31 . 2007-12-12 17:31 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Skype
2007-12-10 15:37 . 2007-12-20 17:44 <DIR> d-------- C:\Documents and Settings\CZESŁAW\Dane aplikacji\SolSuite
2007-12-10 00:05 . 2007-12-26 20:48 116 --a------ C:\WINDOWS\NeroDigital.ini
2007-12-09 22:36 . 2007-12-09 22:36 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-12-09 22:36 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-12-09 22:36 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-12-09 22:36 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-12-09 22:36 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-12-09 22:36 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-12-09 22:36 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-12-09 22:27 . 2007-12-09 22:27 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\THQ
2007-12-09 22:25 . 2007-12-09 22:25 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\InstallShield
2007-12-09 18:28 . 2007-12-09 18:30 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\SolSuite
2007-12-09 18:28 . 2007-12-09 18:28 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\TreeCardGames
2007-12-09 11:48 . 2007-12-09 11:48 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-12-09 11:48 . 2004-03-22 15:17 24,816 --a------ C:\WINDOWS\system32\mdimon.dll
2007-12-09 11:47 . 2007-12-09 11:47 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-12-08 22:27 . 2007-12-24 13:36 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\Hamachi
2007-12-08 22:27 . 2007-12-08 22:27 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2007-12-08 22:04 . 2007-12-08 22:04 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-12-08 22:04 . 2007-12-08 22:22 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-12-08 22:04 . 2007-12-08 22:22 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-12-08 22:04 . 2007-12-08 22:22 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-08 22:04 . 2007-12-08 22:04 22,328 --a------ C:\Documents and Settings\MICHU\Dane aplikacji\PnkBstrK.sys
2007-12-08 22:04 . 2007-12-08 22:04 298 --a------ C:\WINDOWS\game.ini
2007-12-08 21:53 . 2007-12-08 21:53 <DIR> d--hs---- C:\WINDOWS\ftpcache
2007-12-08 21:37 . 2007-12-08 21:53 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Pro
2007-12-08 21:26 . 2007-12-08 21:26 <DIR> d-------- C:\Documents and Settings\MICHU\Dane aplikacji\DAEMON Tools Pro
2007-12-08 21:22 . 2007-12-08 21:22 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-08 20:42 . 2007-12-12 18:57 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Eset
2007-12-08 18:05 . 2006-06-14 13:20 6,272 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-12-08 18:05 . 2006-06-14 13:20 6,272 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2007-12-08 18:03 . 2004-11-18 10:42 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-12-08 17:43 . 2004-05-25 17:06 417,792 --a------ C:\WINDOWS\system32\ac3filter.ax
2007-12-08 17:43 . 2007-08-18 08:54 380,928 --a------ C:\WINDOWS\system32\ac3filter.acm
2007-12-08 16:44 . 2007-12-08 16:44 <DIR> d-------- C:\Program Files\Realtek
2007-12-08 16:41 . 2007-12-08 16:41 <DIR> d-------- C:\Program Files\Real Alternative
2007-12-08 16:41 . 2007-12-08 16:41 <DIR> d-------- C:\Program Files\QuickTime Alternative
2007-12-08 16:41 . 2007-12-08 16:41 <DIR> d-------- C:\Program Files\Media Player Classic
2007-12-08 16:41 . 2007-12-08 16:41 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2007-12-08 16:41 . 2004-12-20 11:08 155,648 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-12-08 16:41 . 2005-12-08 13:56 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-08 16:41 . 2005-12-08 13:56 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
2007-12-08 16:36 . 2004-12-20 11:03 679,936 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-12-08 14:55 . 2007-12-08 14:55 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-12-08 14:14 . 2007-12-08 14:14 <DIR> d-------- C:\Documents and Settings\CZESŁAW\Dane aplikacji\TuneUp Software
2007-12-08 14:11 . 2007-12-08 14:11 <DIR> d-------- C:\Documents and Settings\CZESŁAW\Dane aplikacji\Talkback
2007-12-08 14:05 . 2007-12-07 18:23 <DIR> d--h----- C:\Documents and Settings\CZESŁAW\Ustawienia lokalne
2007-12-08 14:05 . 2007-12-07 18:23 <DIR> d--h----- C:\Documents and Settings\CZESŁAW\Ustawienia lokalne
2007-12-08 14:05 . 2007-12-08 14:06 <DIR> dr------- C:\Documents and Settings\CZESŁAW\Ulubione
2007-12-08 14:05 . 2007-12-08 14:06 <DIR> dr------- C:\Documents and Settings\CZESŁAW\Ulubione
2007-12-08 14:05 . 2007-12-07 17:27 <DIR> d--h----- C:\Documents and Settings\CZESŁAW\Szablony
2007-12-08 14:05 . 2007-12-07 17:27 <DIR> d--h----- C:\Documents and Settings\CZESŁAW\Szablony
2007-12-08 14:05 . 2007-12-23 22:44 <DIR> d-------- C:\Documents and Settings\CZESŁAW\Pulpit
2007-12-08 14:05 . 2007-12-23 22:44 <DIR> d-------- C:\Documents and Settings\CZESŁAW\Pulpit
2007-12-08 14:05 . 2007-12-20 13:36 <DIR> dr------- C:\Documents and Settings\CZESŁAW\Moje dokumenty
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 21:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-19 20:07 32 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2007-12-09 21:18 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-07 17:54 --------- d-----w C:\Documents and Settings\MICHU\Dane aplikacji\TuneUp Software
2007-12-07 17:53 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-07 17:53 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software
2007-12-07 16:31 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-07 16:29 --------- d-----w C:\Program Files\Usługi online
2007-12-07 16:27 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:41 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-22 02:37 17,928 ----a-w C:\WINDOWS\system32\X3DAudio1_2.dll
2007-10-16 18:44 615,641 ----a-w C:\WINDOWS\system32\logon.scr
2007-10-16 13:37 1,548,288 ----a-w C:\WINDOWS\system32\sfcfiles.dll
2007-10-16 13:36 55,296 ----a-w C:\WINDOWS\system32\dmutil.dll
2007-10-16 13:36 51,712 ----a-w C:\WINDOWS\system32\wzcsapi.dll
2007-10-16 13:36 49,152 ----a-w C:\WINDOWS\system32\cnbjmon.dll
2007-10-16 13:36 359,936 ----a-w C:\WINDOWS\system32\wzcsvc.dll
2007-10-16 13:36 35,328 ----a-w C:\WINDOWS\system32\pid.dll
2007-10-16 13:36 20,992 ----a-w C:\WINDOWS\system32\hid.dll
2007-10-16 13:36 2,060,672 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2007-10-16 13:36 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
2007-10-16 13:35 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2007-10-16 13:35 8,192 ----a-w C:\WINDOWS\system32\streamci.dll
2007-10-16 13:35 77,891 ----a-w C:\WINDOWS\system32\usrmlnka.exe
2007-10-16 13:35 77,890 ----a-w C:\WINDOWS\system32\usrdpa.dll
2007-10-16 13:35 77,883 ----a-w C:\WINDOWS\system32\usrrtosa.dll
2007-10-16 13:35 72,192 ----a-w C:\WINDOWS\system32\sprio800.dll
2007-10-16 13:35 70,656 ----a-w C:\WINDOWS\system32\sprio600.dll
2007-10-16 13:35 69,700 ----a-w C:\WINDOWS\system32\usrshuta.exe
2007-10-16 13:35 69,699 ----a-w C:\WINDOWS\system32\usrcoina.dll
2007-10-16 13:35 69,632 ----a-w C:\WINDOWS\system32\spnike.dll
2007-10-16 13:35 61,508 ----a-w C:\WINDOWS\system32\usrprbda.exe
2007-10-16 13:35 61,500 ----a-w C:\WINDOWS\system32\usrcntra.dll
2007-10-16 13:35 57,856 ----a-w C:\WINDOWS\system32\dvdplay.exe
2007-10-16 13:35 53,305 ----a-w C:\WINDOWS\system32\usrlbva.dll
2007-10-16 13:35 49,211 ----a-w C:\WINDOWS\system32\usrvpa.dll
2007-10-16 13:35 49,211 ----a-w C:\WINDOWS\system32\usrsdpia.dll
2007-10-16 13:35 49,209 ----a-w C:\WINDOWS\system32\usrv80a.dll
2007-10-16 13:35 45,116 ----a-w C:\WINDOWS\system32\usrvoica.dll
2007-10-16 13:35 41,019 ----a-w C:\WINDOWS\system32\usrsvpia.dll
2007-10-16 13:35 323,641 ----a-w C:\WINDOWS\system32\usrdtea.dll
2007-10-16 13:35 3,200 ----a-w C:\WINDOWS\system32\wowfax.dll
2007-10-16 13:35 157,696 ----a-w C:\WINDOWS\system32\paqsp.dll
2007-10-16 13:35 147,968 ----a-w C:\WINDOWS\system32\mdwmdmsp.dll
2007-10-16 13:35 13,824 ----a-w C:\WINDOWS\system32\wowfaxui.dll
2007-10-16 13:35 102,457 ----a-w C:\WINDOWS\system32\usrv42a.dll
2007-10-16 13:29 991,744 ----a-w C:\WINDOWS\system32\syssetup.dll
2007-10-16 13:26 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2007-10-16 13:26 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2007-10-16 13:26 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2007-10-16 13:26 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2007-10-16 13:26 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll
2007-10-16 13:26 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2007-10-16 13:26 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2007-10-16 13:26 26,112 ----a-w C:\WINDOWS\system32\idndl.dll
2007-10-16 13:26 24,576 ----a-w C:\WINDOWS\system32\nlsdl.dll
2007-10-16 13:26 23,552 ----a-w C:\WINDOWS\system32\normaliz.dll
2007-10-16 13:26 17,408 ----a-w C:\WINDOWS\system32\corpol.dll
2007-10-16 13:26 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2007-10-16 13:25 71,680 ----a-w C:\WINDOWS\system32\admparse.dll
2007-10-16 13:25 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-10-16 13:25 582,656 ----a-w C:\WINDOWS\system32\rpcrt4.dll
2007-10-16 13:25 549,888 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-10-16 13:25 414,720 ----a-w C:\WINDOWS\system32\msscp.dll
2007-10-16 13:25 282,112 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-10-16 13:25 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-10-16 13:25 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-10-16 13:25 1,104,896 ----a-w C:\WINDOWS\system32\msxml3.dll
2007-10-16 13:25 1,034,752 ----a-w C:\WINDOWS\explorer.exe
2007-10-16 13:24 981,760 ----a-w C:\WINDOWS\system32\mfc42u.dll
2007-10-16 13:24 927,504 ----a-w C:\WINDOWS\system32\mfc40u.dll
2007-10-16 13:24 579,584 ----a-w C:\WINDOWS\system32\user32.dll
2007-10-16 13:24 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-10-16 13:24 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-10-16 13:24 2,183,424 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2007-10-16 13:24 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll
2007-10-16 13:24 1,844,224 ----a-w C:\WINDOWS\system32\win32k.sys
2007-10-16 13:23 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-16 13:23 72,704 ----a-w C:\WINDOWS\system32\hlink.dll
2007-10-16 13:23 714,240 ----a-w C:\WINDOWS\system32\sxs.dll
2007-10-16 13:23 69,120 ----a-w C:\WINDOWS\system32\ciodm.dll
2007-10-16 13:23 65,536 ----a-w C:\WINDOWS\system32\nwwks.dll
2007-10-16 13:23 64,000 ----a-w C:\WINDOWS\system32\nwapi32.dll
2007-10-16 13:23 617,472 ----a-w C:\WINDOWS\system32\comctl32.dll
2007-10-16 13:23 499,766 ----a-w C:\WINDOWS\system32\dxmasf.dll
2007-10-16 13:23 28,672 ----a-w C:\WINDOWS\system32\verclsid.exe
2007-10-16 13:23 246,814 ----a-w C:\WINDOWS\system32\strmdll.dll
2007-10-16 13:23 23,040 ----a-w C:\WINDOWS\system32\fltMc.exe
2007-10-16 13:23 16,896 ----a-w C:\WINDOWS\system32\fltlib.dll
2007-10-16 13:23 143,360 ----a-w C:\WINDOWS\system32\nwprovau.dll
2007-10-16 13:23 132,096 ----a-w C:\WINDOWS\system32\wkssvc.dll
2007-10-16 13:23 123,392 ----a-w C:\WINDOWS\system32\oledlg.dll
2007-10-16 13:23 100,352 ----a-w C:\WINDOWS\system32\6to4svc.dll
2007-10-16 13:23 1,439,744 ----a-w C:\WINDOWS\system32\query.dll
2007-10-16 13:22 97,792 ----a-w C:\WINDOWS\system32\comrepl.dll
2007-10-16 13:22 956,416 ----a-w C:\WINDOWS\system32\msdtctm.dll
2007-10-16 13:22 91,136 ----a-w C:\WINDOWS\system32\mtxoci.dll
2007-10-16 13:22 80,896 ----a-w C:\WINDOWS\system32\fontsub.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="d:\programy\Avast4\ashDisp.exe" [2007-12-04 14:00]
"Outpost Firewall"="d:\PROGRAMY\Outpost Firewall\outpost.exe" [2007-04-05 16:56]
"OutpostFeedBack"="d:\programy\Outpost Firewall\feedback.exe" [2007-06-28 13:18]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:44 C:\WINDOWS\system32\rundll32.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="regsvr32 /s /n /i:U shell32" []
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-12-19 21:07:16]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NOD32krn"=2 (0x2)
R1 SandBox;Outpost Firewall Sandbox Driver;d:\programy\Outpost Firewall\kernel\Sandbox.SYS [2007-06-26 19:01]
R1 VFILT;Outpost Firewall Kernel Driver;d:\programy\Outpost Firewall\kernel\FILTNT.SYS [2007-04-05 16:56]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs []
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);d:\programy\Outpost Firewall\kernel\ADBLOCK.DLL [2007-04-05 16:57]
R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);d:\programy\Outpost Firewall\kernel\ARP.DLL [2007-04-05 16:57]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);d:\programy\Outpost Firewall\kernel\CONTENT.DLL [2007-04-05 16:57]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);d:\programy\Outpost Firewall\kernel\DNSCACHE.DLL [2007-04-05 16:57]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);d:\programy\Outpost Firewall\kernel\FTPFILT.DLL [2007-04-05 16:57]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);d:\programy\Outpost Firewall\kernel\HTMLFILT.DLL [2007-04-05 16:57]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);d:\programy\Outpost Firewall\kernel\HTTPFILT.DLL [2007-04-05 16:57]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);d:\programy\Outpost Firewall\kernel\IMAPFILT.DLL [2007-04-05 16:57]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);d:\programy\Outpost Firewall\kernel\MAILFILT.DLL [2007-04-05 16:57]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);d:\programy\Outpost Firewall\kernel\NNTPFILT.DLL [2007-04-05 16:57]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);d:\programy\Outpost Firewall\kernel\POP3FILT.DLL [2007-04-05 16:57]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);d:\programy\Outpost Firewall\kernel\PROTECT.DLL [2007-04-05 16:57]
R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);d:\programy\Outpost Firewall\kernel\SECRET.DLL [2007-04-05 16:57]
S2 ELOADER;General Purpose USB Driver (adildr.sys);C:\WINDOWS\system32\Drivers\adildr.sys [2007-02-07 16:50]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-12-07 17:54:44 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- D:\programy\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-27 22:51:30
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-27 22:54:51
Zagrożenie wykrywa w rejestrze, ale nie wiem dokładnie gdzie. Program to Ashampoo AntiSpyWare