Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.240 [GMT 2:00]
Running from: C:\Documents and Settings\m@reczek\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-05 to 2008-05-05 )))))))))))))))))))))))))))))))
.
2008-05-05 22:20 . 2008-05-05 22:20 <DIR> d-------- C:\Program Files\Ontrack
2008-05-05 22:00 . 2008-05-05 22:00 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\Lavasoft
2008-05-05 21:53 . 2008-05-05 21:53 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-05 21:53 . 2008-05-05 21:53 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-05-05 21:34 . 2008-05-05 21:34 <DIR> d-------- C:\Program Files\PowerQuest
2008-05-05 21:13 . 2008-05-05 21:13 <DIR> d-------- C:\Program Files\Runtime Software
2008-05-05 21:13 . 2008-05-05 21:13 <DIR> d-------- C:\Documents and Settings\m@reczek\WINDOWS
2008-05-05 21:13 . 1999-03-23 09:12 299,520 --a------ C:\WINDOWS\uninst.exe
2008-04-20 15:36 . 2008-04-20 15:36 <DIR> d-------- C:\Program Files\Sun
2008-04-20 15:35 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-20 15:34 . 2008-04-20 15:34 <DIR> d-------- C:\Program Files\Java
2008-04-20 15:33 . 2008-04-20 15:33 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-20 00:09 . 2008-04-20 00:09 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\CyberLink
2008-04-20 00:09 . 2008-04-20 00:09 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\CyberLink
2008-04-20 00:08 . 2008-04-20 00:08 <DIR> d-------- C:\Program Files\Common Files\CyberLink
2008-04-20 00:07 . 2008-04-20 00:07 <DIR> d-------- C:\Program Files\CyberLink
2008-04-20 00:06 . 2008-04-20 00:06 29,480 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-04-16 17:01 . 2008-04-16 17:01 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\StatSoft
2008-04-16 16:58 . 1999-09-09 11:28 446,464 --a------ C:\WINDOWS\system32\HHActiveX.dll
2008-04-16 16:58 . 2001-03-05 12:11 98,304 --a------ C:\WINDOWS\system32\tsccvid.dll
2008-04-16 16:57 . 2008-04-16 16:57 <DIR> d-------- C:\Program Files\StatSoft
2008-04-14 20:43 . 2008-04-14 20:43 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\ACD Systems
2008-04-14 20:42 . 2008-04-14 20:42 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-04-14 20:42 . 2008-04-14 20:42 <DIR> d-------- C:\Program Files\ACD Systems
2008-04-14 20:42 . 2008-04-14 20:42 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ACD Systems
2008-04-13 20:27 . 2008-04-13 20:27 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\Apple Computer
2008-04-13 20:26 . 2008-04-13 20:26 <DIR> d-------- C:\Program Files\QuickTime
2008-04-13 20:26 . 2008-04-29 22:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-13 20:26 . 2008-04-13 20:26 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-13 20:25 . 2008-04-13 20:25 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2008-04-11 11:57 . 2008-04-11 11:57 <DIR> dr-h----- C:\Documents and Settings\m@reczek\Dane aplikacji\SecuROM
2008-04-11 11:57 . 2008-04-11 11:57 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-04-11 10:39 . 2007-04-05 00:39 442,368 -ra------ C:\WINDOWS\system32\vp6vfw.dll
2008-04-11 09:51 . 2008-04-11 09:51 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-10 22:02 . 2008-04-10 22:02 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\Thunderbird
2008-04-10 22:02 . 2008-04-10 22:02 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\Talkback
2008-04-10 22:02 . 2008-04-10 22:02 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-10 22:01 . 2008-04-10 22:01 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-04-10 16:52 . 2008-04-10 16:52 <DIR> dr------- C:\Documents and Settings\m@reczek\Dane aplikacji\Brother
2008-04-10 16:15 . 2008-04-10 16:15 <DIR> d-------- C:\Program Files\NewSoft
2008-04-10 16:15 . 2008-04-10 16:15 <DIR> d-------- C:\Program Files\Common Files\NewSoft
2008-04-10 16:15 . 2008-04-10 16:15 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Newsoft
2008-04-10 16:15 . 2008-04-10 16:15 1,845 --a------ C:\WINDOWS\if42le.ini
2008-04-10 16:15 . 2008-04-10 16:15 308 --a------ C:\WINDOWS\Pexplore.ini
2008-04-10 15:56 . 2008-04-10 15:57 404 --a------ C:\WINDOWS\BRWMARK.INI
2008-04-10 15:56 . 2008-04-10 15:56 50 --a------ C:\WINDOWS\system32\bridf07a.dat
2008-04-10 15:56 . 2008-04-10 15:57 27 --a------ C:\WINDOWS\BRPP2KA.INI
2008-04-10 15:55 . 2008-04-10 15:55 <DIR> d-------- C:\Program Files\Brother
2008-04-10 15:54 . 2008-04-10 15:54 <DIR> d-------- C:\Program Files\Nuance
2008-04-10 15:54 . 2008-04-10 15:54 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\InstallShield
2008-04-10 15:53 . 2008-04-10 15:53 <DIR> d-------- C:\Program Files\Common Files\ScanSoft Shared
2008-04-10 15:53 . 2008-04-10 15:53 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\InstallShield
2008-04-10 15:53 . 2006-10-24 15:34 31,567 --a------ C:\WINDOWS\maxlink.ini
2008-04-10 15:52 . 2008-04-10 15:52 <DIR> d-------- C:\Program Files\ScanSoft
2008-04-10 15:52 . 2008-04-10 15:52 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft
2008-04-10 15:51 . 2008-04-10 15:51 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Brother
2008-04-10 10:29 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-10 10:29 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-10 10:29 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-10 10:29 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-09 23:39 . 2008-04-09 23:39 <DIR> d-------- C:\localtexmf
2008-04-09 23:33 . 2008-04-09 23:33 <DIR> d-------- C:\texmf
2008-04-09 14:40 . 2003-06-19 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-04-09 14:40 . 2008-04-09 14:40 421 --a------ C:\WINDOWS\ODBC.INI
2008-04-09 14:38 . 2008-04-09 14:38 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-04-09 13:38 . 2008-04-09 13:38 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\skypePM
2008-04-09 13:38 . 2008-04-09 13:38 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-04-09 13:36 . 2008-04-09 13:36 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\Skype
2008-04-09 13:35 . 2008-04-09 13:35 <DIR> d-------- C:\Program Files\Skype
2008-04-09 13:35 . 2008-04-09 13:35 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-04-09 13:35 . 2008-04-09 13:35 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-04-08 21:38 . 2008-04-08 21:38 <DIR> d-------- C:\Program Files\BitLord
2008-04-08 14:18 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-04-08 14:00 . 2008-04-08 14:00 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\AdobeUM
2008-04-08 13:03 . 2008-04-08 13:03 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-04-08 12:06 . 2008-04-17 18:30 156 --a------ C:\WINDOWS\matlab.ini
2008-04-08 12:03 . 2008-04-08 12:03 <DIR> d-a------ C:\MATLAB6p5
2008-04-08 11:39 . 2004-08-03 23:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2008-04-07 21:38 . 2008-04-07 21:38 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\Media Player Classic
2008-04-07 21:34 . 2008-04-07 21:34 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2008-04-07 17:29 . 2008-04-07 17:29 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-04-07 17:26 . 2008-04-07 17:26 <DIR> d-------- C:\Program Files\Kyodai Mahjongg 2006
2008-04-07 17:26 . 2008-04-07 17:26 32 --a------ C:\WINDOWS\CD_Start.INI
2008-04-07 17:17 . 2008-04-07 17:17 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-04-07 17:17 . 2004-04-30 09:37 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys
2008-04-07 17:17 . 2004-04-30 09:33 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys
2008-04-07 17:15 . 2008-04-07 17:15 <DIR> d-------- C:\totalcmd
2008-04-07 17:15 . 2006-02-16 06:54 545 --a------ C:\WINDOWS\UC.PIF
2008-04-07 17:15 . 2006-02-16 06:54 545 --a------ C:\WINDOWS\RAR.PIF
2008-04-07 17:15 . 2006-02-16 06:54 545 --a------ C:\WINDOWS\PKZIP.PIF
2008-04-07 17:15 . 2006-02-16 06:54 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2008-04-07 17:15 . 2006-02-16 06:54 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2008-04-07 17:15 . 2006-02-16 06:54 545 --a------ C:\WINDOWS\LHA.PIF
2008-04-07 17:15 . 2006-02-16 06:54 545 --a------ C:\WINDOWS\ARJ.PIF
2008-04-07 17:15 . 2008-05-05 21:53 406 --a------ C:\WINDOWS\wincmd.ini
2008-04-07 17:14 . 2008-04-07 17:14 <DIR> d-------- C:\Program Files\Damian Pasternak
2008-04-07 17:07 . 2008-04-07 17:07 <DIR> d-------- C:\Program Files\Winamp
2008-04-07 17:07 . 2008-05-01 08:15 95 --a------ C:\WINDOWS\winamp.ini
2008-04-07 17:04 . 2008-04-07 17:04 <DIR> d-------- C:\Documents and Settings\m@reczek\Dane aplikacji\Gadu-Gadu
2008-04-07 17:03 . 2008-04-07 17:03 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-04-07 17:03 . 2008-04-07 17:03 <DIR> d-------- C:\Documents and Settings\m@reczek\Gadu-Gadu
2008-04-07 16:50 . 2008-04-07 16:50 <DIR> d-------- C:\Program Files\MarBit
2008-04-07 16:46 . 2008-04-07 16:46 <DIR> d-------- C:\Program Files\Real Alternative
2008-04-07 16:46 . 2008-04-07 16:46 <DIR> d-------- C:\Program Files\Media Player Classic
2008-04-07 16:40 . 2008-04-07 16:40 <DIR> d-------- C:\Program Files\Opera
2008-04-07 16:35 . 2008-04-07 16:35 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-04-07 16:31 . 2008-02-25 21:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-04-07 16:30 . 2008-04-07 16:30 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-07 16:30 . 2008-04-07 16:30 <DIR> d-------- C:\Program Files\ATI Technologies
2008-04-07 16:29 . 2008-04-07 16:29 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-04-07 16:29 . 2008-04-07 16:29 <DIR> d-------- C:\ATI
2008-04-07 15:47 . 2008-04-07 15:47 <DIR> d--hs---- C:\Recycled
2008-04-07 15:09 . 2008-04-07 15:09 <DIR> d-------- C:\Program Files\Alwil Software
2008-04-07 15:06 . 2008-04-07 15:06 <DIR> d---s---- C:\Documents and Settings\m@reczek\UserData
2008-04-07 15:02 . 2008-04-07 14:29 <DIR> d--h----- C:\Documents and Settings\m@reczek\Ustawienia lokalne
2008-04-07 15:02 . 2008-04-07 15:02 <DIR> dr------- C:\Documents and Settings\m@reczek\Ulubione
2008-04-07 15:02 . 2008-04-07 14:29 <DIR> d--h----- C:\Documents and Settings\m@reczek\Szablony
2008-04-07 15:02 . 2008-04-07 14:29 <DIR> d-------- C:\Documents and Settings\m@reczek\Pulpit
2008-04-07 15:02 . 2008-04-07 15:02 <DIR> dr------- C:\Documents and Settings\m@reczek\Moje dokumenty
2008-04-07 15:02 . 2008-04-07 14:29 <DIR> dr------- C:\Documents and Settings\m@reczek\Menu Start
2008-04-07 15:02 . 2008-04-07 14:29 <DIR> dr-h----- C:\Documents and Settings\m@reczek\Dane aplikacji
2008-04-07 15:02 . 2008-04-07 15:02 <DIR> d-------- C:\Documents and Settings\m@reczek
2008-04-07 15:02 . 2008-05-05 22:32 700,416 --ah----- C:\Documents and Settings\m@reczek\NTUSER.DAT.LOG
2008-04-07 15:02 . 2008-04-07 15:02 13,588 --a------ C:\WINDOWS\system32\wpa.bak
2008-04-07 15:02 . 2008-04-07 15:02 1,024 --ah----- C:\Documents and Settings\Default User\NTUSER.DAT.LOG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-08 12:18 155,995 ----a-w C:\WINDOWS\java\Packages\3FTJD3TZ.ZIP
2008-04-07 12:52 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-07 12:49 --------- d-----w C:\Program Files\Usługi online
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-02-26 05:51 2,863,616 ----a-w C:\WINDOWS\system32\dllcache\ati2mtag.sys
2008-02-26 03:12 372,736 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-02-26 03:11 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-02-26 03:10 299,520 ----a-w C:\WINDOWS\system32\dllcache\ati2dvag.dll
2008-02-26 03:10 299,520 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-02-26 03:02 172,032 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-02-26 03:02 126,976 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-02-26 03:01 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-02-26 03:01 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-02-26 03:01 126,976 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-02-26 03:00 520,192 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-02-26 02:59 9,797,632 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-02-26 02:58 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-02-26 02:49 3,176,480 ----a-w C:\WINDOWS\system32\dllcache\ati3duag.dll
2008-02-26 02:49 3,176,480 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-02-26 02:41 1,755,264 ----a-w C:\WINDOWS\system32\dllcache\ativvaxx.dll
2008-02-26 02:41 1,755,264 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-02-26 02:29 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-02-26 02:25 393,216 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-02-26 02:23 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-02-26 02:21 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-02-26 02:19 167,936 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-02-26 02:16 520,192 ----a-w C:\WINDOWS\system32\dllcache\ati2cqag.dll
2008-02-26 02:16 520,192 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:38 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-16 22:35 3,080,704 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-15 09:23 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 12:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"WinampAgent"="C:\Program Files\Winamp\Winampa.exe" [2003-04-02 04:20 12288]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 21:12 30248]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 21:10 46632]
"PPort11reminder"="C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 13:46 255528]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 14:51 663552]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 15:58 65536]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-04-13 20:26 155648]
"RemoteControl8"="C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 20:23 83240]
"PDVD8LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 12:00 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\Kyodai Mahjongg 2006\\kmj.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-11 18:00:02 C:\WINDOWS\Tasks\At1.job"
- C:\Documents
"2008-04-11 16:34:18 C:\WINDOWS\Tasks\At2.job"
- C:\Documents
"2008-04-11 16:34:18 C:\WINDOWS\Tasks\At3.job"
- C:\Documents
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-05 22:35:34
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe

.
Completion time: 2008-05-05 22:36:19
ComboFix-quarantined-files.txt 2008-05-05 20:36:14
Pre-Run: 4,982,775,808 bajtów wolnych
Post-Run: 5,068,480,512 bajtów wolnych
239 --- E O F --- 2008-04-11 07:51:56