Andzia - 06-09-04 16:21:02,99
ComboFix 06.09.04BT - Running from: C:\Documents and Settings\Andzia.LENCZEWSKI\Pulpit
Microsoft Windows XP [Wersja 5.1.2600]
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\Andzia.LENCZEWSKI\Dane aplikacji\Install.dat
((((((((((((((((((((((((((((((( Files Created from 2006-08-04 to 2006-09-04 ))))))))))))))))))))))))))))))))))
2006-09-04 15:37 671,744 -r-hs---- C:\WINDOWS\system32\nqfgaaesh.exe
2006-09-02 20:25 671,744 -r-hs---- C:\WINDOWS\system32\yfiyyezap.exe
2006-08-31 12:51 671,744 -r-hs---- C:\WINDOWS\system32\hzhspckar.exe
2006-08-31 12:42 671,744 -r-hs---- C:\WINDOWS\system32\aogszewal.exe
2006-08-30 23:31 671,744 -r-hs---- C:\WINDOWS\system32\lhnuavhwn.exe
2006-08-30 13:24 8,628 --a------ C:\WINDOWS\system32\mszsrn32.dll
2006-08-30 12:56 671,744 -r-hs---- C:\WINDOWS\system32\hwgpcllng.exe
2006-08-29 20:05 671,744 -r-hs---- C:\WINDOWS\system32\reezgpqge.exe
2006-08-29 13:34 671,744 -r-hs---- C:\WINDOWS\system32\fbvccxktb.exe
2006-08-26 13:12 671,744 -ra------ C:\WINDOWS\system32\jjeuskkie.exe
2006-08-26 13:12 671,744 -r-hs---- C:\WINDOWS\system32\omecztrox.exe
2006-08-26 12:57 171,520 --a------ C:\WINDOWS\system32\LXAESUI.DLL
2006-08-26 12:55 221,696 --a------ C:\WINDOWS\system32\qmgr.dll
2006-08-26 12:55 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2006-08-26 12:54 869,376 --a------ C:\WINDOWS\system32\msdtctm.dll
2006-08-26 12:54 83,968 --a------ C:\WINDOWS\system32\mtxoci.dll
2006-08-26 12:54 582,656 --a------ C:\WINDOWS\system32\catsrvut.dll
2006-08-26 12:54 56,832 --a------ C:\WINDOWS\system32\colbact.dll
2006-08-26 12:54 495,616 --a------ C:\WINDOWS\system32\comuid.dll
2006-08-26 12:54 494,592 --a------ C:\WINDOWS\system32\hypertrm.dll
2006-08-26 12:54 468,480 --a------ C:\WINDOWS\system32\clbcatq.dll
2006-08-26 12:54 359,936 --a------ C:\WINDOWS\system32\msdtcprx.dll
2006-08-26 12:54 215,040 --a------ C:\WINDOWS\system32\catsrv.dll
2006-08-26 12:54 151,040 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2006-08-26 12:54 114,968 --a------ C:\WINDOWS\system32\wuauclt.exe
2006-08-26 12:54 100,864 --a------ C:\WINDOWS\system32\clbcatex.dll
2006-08-26 12:54 1,172,992 --a------ C:\WINDOWS\system32\comsvcs.dll
2006-08-26 12:54 1,081,112 --a------ C:\WINDOWS\system32\wuaueng.dll
2006-08-26 12:46 51,200 --a------ C:\WINDOWS\system32\sfman32.dll
2006-08-26 12:46 495,616 --a------ C:\WINDOWS\system32\sblfx.dll
2006-08-26 12:46 4,096 --a------ C:\WINDOWS\system32\ctwdm32.dll
2006-08-26 12:46 256,512 --a------ C:\WINDOWS\system32\devcon32.dll
2006-08-26 12:46 24,064 --a------ C:\WINDOWS\system32\devldr32.exe
2006-08-26 12:44 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2006-08-26 12:44 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2006-08-15 14:21 274,432 --a------ C:\WINDOWS\system32\imon.dll
2006-08-04 16:37 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2006-08-04 16:37 196,608 --a------ C:\WINDOWS\system32\dtu100.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-04 15:09 -------- d-------- C:\Program Files\Warez
2006-09-04 15:09 -------- d-------- C:\Documents and Settings\Andzia.LENCZEWSKI\Dane aplikacji\Warez
2006-08-29 19:50 -------- d-------- C:\Program Files\Spik
2006-08-26 18:57 -------- d-------- C:\Program Files\URUSoft
2006-08-26 18:35 -------- d-------- C:\Program Files\SubEdit-Player
2006-08-26 12:54 -------- d-------- C:\Program Files\Messenger
2006-08-25 12:37 -------- d-------- C:\Program Files\Codec
2006-08-25 12:07 -------- d-------- C:\Program Files\XP Codec Pack
2006-08-15 14:21 502368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2006-07-27 03:06 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2006-07-13 10:51 700184 --a------ C:\WINDOWS\system32\SkanerOnline.dll
2006-07-03 22:40 620180 --a------ C:\WINDOWS\system32\divx.dll
2006-06-29 15:14 69944 --a------ C:\WINDOWS\system32\SkanerOnlineUninstall.exe
2006-06-28 16:11 675 --a------ C:\fix.reg
2006-06-21 11:43 520192 --a------ C:\WINDOWS\system32\divxsm.exe
2006-06-21 11:42 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="\"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE"
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
"Winsockett"="nqfgaaesh.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Warez"="\"C:\\Program Files\\Warez\\Warez.exe\" /minimized"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices]
"msvcc25"="svcchost.exe"
"Winsockett"="nqfgaaesh.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="http://www.tapety4u.pl/albums/krajobrazy/national_geographic/normal_126.jpg"
"SubscribedURL"="http://www.tapety4u.pl/albums/krajobrazy/national_geographic/normal_126.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,e6,00,00,00,00,00,00,00,9a,03,00,00,42,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,98,00,00,00,00,00,00,00,e8,03,00,00,42,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,98,00,00,00,00,00,00,00,e8,03,00,00,42,03,\
00,00,01,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Moja bieżąca strona główna"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,52,01,00,00,23,00,00,00,7c,00,00,00,72,00,00,00,ea,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,72,03,00,00,23,00,00,00,fc,00,00,00,f2,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,72,03,00,00,23,00,00,00,fc,00,00,00,f2,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^abcHood Pager 1.0.lnk]
"backup"="C:\\WINDOWS\\pss\\abcHood Pager 1.0.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\ScannerU\\PageABC\\abcPager\\abcPager.exe -loadstatus -hide"
"item"="abcHood Pager 1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Action Manager 32.lnk]
"backup"="C:\\WINDOWS\\pss\\Action Manager 32.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\ScannerU\\AM32.exe "
"item"="Action Manager 32"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Kalendarz XP.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programy\\Autostart\\Kalendarz XP.lnk"
"backup"="C:\\WINDOWS\\pss\\Kalendarz XP.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\KALEND~1\\KALEND~1.EXE "
"item"="Kalendarz XP"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^TV Remote Control.lnk]
"backup"="C:\\WINDOWS\\pss\\TV Remote Control.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\AVACSM~1\\TV88XU~1\\C8XRCtl.exe "
"item"="TV Remote Control"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\bme91d0e]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="bme91d0e"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\CTFMON.EXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\System32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Internet Optimizer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="optimize"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\msvcc25]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="svcchost"
"hkey"="HKLM"
"command"="svcchost.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NBJ]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NBJ"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PowerS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PowerS"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Preview AdService]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PrevAdServ"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vxh8jkdq2"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\System32\\vxh8jkdq2.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Run]
"key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows"
"item"="winlogon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\inet20004\\winlogon.exe"
"inimapping"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\salm]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="salm"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Speed racer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTSRReg"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Spik]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Spik"
"hkey"="HKLM"
"command"="C:\\Program Files\\Spik\\Spik.exe -autostart"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Updreg"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\Updreg.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Warez]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Warez"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Warez\\Warez.exe\" /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winampa"
"hkey"="HKLM"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Windows installer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winstall"
"hkey"="HKCU"
"command"="C:\\winstall.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Winsockett]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="yfiyyezap"
"hkey"="HKLM"
"command"="yfiyyezap.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\xp_system]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winlogon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\inet20004\\winlogon.exe"
"inimapping"="0"
Completion time: 2006-09-04 16:21:30.13
ComboFix.txt