REGLOOKS logfile - version 0.982 Scan started: 2009-10-03 19:59:44,17 --- INFORMATION --- Operating System: Microsoft Windows XP Professional - version 5.1.2600 - Dodatek Service Pack 3 Bootmode: Normal boot User: user (Administrator account) Total RAM: 2047 MB (free 1339 MB - 65%) Internet Explorer Version: 8.0.6001.18702 Antivirus Program: Kaspersky Internet Security 8.0.0.357 [Not Enabled - Updated] Firewall: Kaspersky Internet Security 8.0.0.357 [Enabled] --- SIGCHECK --- C:\WINDOWS\explorer.exe -- sigcheck OK C:\WINDOWS\system32\ctfmon.exe -- sigcheck OK C:\WINDOWS\system32\lsass.exe -- sigcheck OK C:\WINDOWS\system32\ntkrnlpa.exe -- sigcheck OK C:\WINDOWS\system32\ntoskrnl.exe -- sigcheck OK C:\WINDOWS\system32\services.exe -- sigcheck OK C:\WINDOWS\system32\sfcfiles.dll -- sigcheck OK C:\WINDOWS\system32\spoolsv.exe -- sigcheck OK C:\WINDOWS\system32\svchost.exe -- sigcheck OK C:\WINDOWS\system32\termsrv.dll -- sigcheck OK C:\WINDOWS\system32\user32.dll -- sigcheck OK C:\WINDOWS\system32\userinit.exe -- sigcheck OK C:\WINDOWS\system32\wininet.dll -- sigcheck OK C:\WINDOWS\system32\winlogon.exe -- sigcheck OK C:\WINDOWS\system32\ws2_32.dll -- sigcheck OK C:\WINDOWS\system32\wuauclt.exe -- sigcheck OK C:\WINDOWS\system32\drivers\ip6fw.sys -- sigcheck OK C:\WINDOWS\system32\drivers\ndis.sys -- sigcheck OK C:\WINDOWS\system32\drivers\tcpip.sys -- sigcheck OK --- SSODL regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" -- File: %SystemRoot%\system32\SHELL32.dll -- [?] "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" -- File: %SystemRoot%\system32\SHELL32.dll -- [?] "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" -- File: C:\WINDOWS\system32\webcheck.dll -- [236544] -- [2009-03-08 04:34] "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" -- File: C:\WINDOWS\system32\stobject.dll -- [122368] -- [2008-04-14 19:20] "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" -- File: C:\WINDOWS\system32\WPDShServiceObj.dll -- [133632] -- [2006-10-18 22:47] --- STS regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Moduł wstępnego ładowania interfejsu Browseui" -- File: %SystemRoot%\system32\browseui.dll -- [?] "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Demon buforu kategorii składników" -- File: %SystemRoot%\system32\browseui.dll -- [?] --- USERINIT regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," File: C:\WINDOWS\system32\userinit.exe -- [26624] -- [2008-04-14 19:21] --- SHELL regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell"="Explorer.exe" File: C:\WINDOWS\Explorer.exe -- [1035264] -- [2008-04-14 19:21] --- SYSTEM regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" --- APPINIT_DLLS regkey --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1\\mzvkbd.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\adialhk.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\kloehk.dll" File: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll -- [83208] -- [2008-07-17 18:06] File: C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll -- [83208] -- [2008-04-25 18:21] File: C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll -- [11016] -- [2008-04-25 18:22] --- NOTIFY regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] -- File: C:\WINDOWS\system32\crypt32.dll -- [602624] -- [2008-04-14 19:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] -- File: C:\WINDOWS\system32\cryptnet.dll -- [64512] -- [2008-04-14 19:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] -- File: C:\WINDOWS\system32\cscdll.dll -- [102400] -- [2008-04-14 19:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] -- File: %SystemRoot%\System32\dimsntfy.dll -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon] -- File: C:\WINDOWS\system32\klogon.dll -- [206088] -- [2008-04-25 18:22] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] -- File: C:\WINDOWS\system32\wlnotify.dll -- [93184] -- [2008-04-14 19:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] -- File: C:\WINDOWS\system32\wlnotify.dll -- [93184] -- [2008-04-14 19:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] -- File: C:\WINDOWS\system32\sclgntfy.dll -- [22016] -- [2008-04-14 19:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] -- File: C:\WINDOWS\system32\WlNotify.dll -- [93184] -- [2008-04-14 19:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] -- File: C:\WINDOWS\system32\wlnotify.dll -- [93184] -- [2008-04-14 19:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] -- File: C:\WINDOWS\system32\wlnotify.dll -- [93184] -- [2008-04-14 19:20] --- RUN / LOAD regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] "load"="" --- SHELLEXECUTEHOOKS regkey --- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" -- File: shell32.dll -- [?] --- HKLM AUTORUN regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor] "AutoRun"="" --- HKCU AUTORUN regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Command Processor] no AutoRun regkey found --- HKLM\RUN regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup" -- File C:\WINDOWS\RaidTool\xInsIDE.exe -- [36864] -- [2007-03-20 08:36] "36X Raid Configurer" -- File -- C:\WINDOWS\system32\xRaidSetup.exe boot -- [X] "AVP" -- File "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -- [201992] -- [2009-02-10 13:54] "SSBkgdUpdate" -- File: "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot -- [?] "OpwareSE4" -- File "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" -- [79400] -- [2007-02-04 12:02] "nwiz" -- File: nwiz.exe /install -- [?] "NvMediaCenter" -- File: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit -- [?] "AdslTaskBar" -- File: rundll32.exe stmctrl.dll,TaskBar -- [?] "WOOWATCH" -- File C:\PROGRA~1\NEOSTR~1\Watch.exe -- [20480] -- [2004-08-23 13:49] "WOOTASKBARICON" -- File -- C:\PROGRA~1\NEOSTR~1\GestMaj.exe TaskBarIcon.exe -- [X] "SpeedTouch USB Diagnostics" -- File: "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon -- [?] "sysgif32" -- File C:\WINDOWS\Temp\wpv241254489937.exe -- [26112] -- [2009-10-03 15:38] "restorer32_a" -- File C:\WINDOWS\system32\restorer32_a.exe -- [45056] -- [2009-10-03 15:38] "NvCplDaemon" -- File: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup -- [?] "Regedit32" -- File -- C:\WINDOWS\system32\regedit.exe -- [X] --- HKLM\RUNONCE regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] no runonce values found --- HKLM\RUNONCEEX regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] no runonceex values found --- HKLM\RUNSERVICES regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] key not found --- HKLM\RUNSERVICESONCE regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce] key not found --- HKCU\RUN regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE" -- File C:\WINDOWS\system32\ctfmon.exe -- [15360] -- [2008-04-14 19:21] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" -- File "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" -- [143360] -- [2006-12-23 19:05] "restorer32_a" -- File C:\Documents and Settings\user\restorer32_a.exe -- [45056] -- [2009-10-03 15:38] --- HKCU\RUNONCE regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] no runonce values found --- HKCU\RUNONCEEX regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] key not found --- HKCU\RUNSERVICES regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] key not found --- HKCU\RUNSERVICESONCE regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce] key not found --- HKU\.DEFAULT\Run regkeys - Default user --- [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE" -- File C:\WINDOWS\system32\CTFMON.EXE -- [15360] -- [2008-04-14 19:21] --- HKU\S-1-5-18\Run regkeys - user SYSTEM --- [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE" -- File C:\WINDOWS\system32\CTFMON.EXE -- [15360] -- [2008-04-14 19:21] --- HKU\S-1-5-19\Run regkeys - User Lokale service --- [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE" -- File C:\WINDOWS\system32\CTFMON.EXE -- [15360] -- [2008-04-14 19:21] --- HKU\S-1-5-20\Run regkeys - User Lokale service --- [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE" -- File C:\WINDOWS\system32\CTFMON.EXE -- [15360] -- [2008-04-14 19:21] --- HKLM\Explorer\Run regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] key not found --- HKCU\Explorer\Run regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] key not found --- Image File Execution regkeys --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] no debuggers found --- BROWSER HELPER OBJECTS regkeys --- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] -- File: E:\Adobe Reader 7.0\ActiveX\AcroIEHelper.dll -- [63136] -- [2004-12-14 02:56] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}] -- File: C:\Program Files\Winamp Toolbar\winamptb.dll -- [1185120] -- [2007-12-13 18:49] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}] -- File: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll -- [62728] -- [2008-07-17 18:06] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] -- CLSID not found [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] -- File: C:\Program Files\Java\jre6\bin\jp2ssv.dll -- [35840] -- [2009-04-17 23:07] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] -- File: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll -- [73728] -- [2009-04-17 23:09] --- TOOLBAR regkeys --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} -- File: C:\Program Files\Winamp Toolbar\winamptb.dll -- [1185120] -- [2007-12-13 18:49] {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -- CLSID not found --- HKLM\URLSEARCHHOOKS regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks] key not found --- HKCU\URLSEARCHHOOKS regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] {08C06D61-F1F3-4799-86F8-BE1A89362C85} -- File: C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL -- [57344] -- [2004-12-06 13:27] {CFBFAE00-17A6-11D0-99CB-00C04FD64497} -- File: C:\WINDOWS\system32\ieframe.dll -- [11067392] -- [2009-07-19 18:46] --- SRCEENSAVER regkey --- [HKEY_CURRENT_USER\Control Panel\Desktop] "SCRNSAVE.EXE" -- File C:\WINDOWS\system32\logon.scr -- [220672] -- [2008-04-14 19:21] --- ALTERNATESHELL regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot] File: C:\WINDOWS\system32\cmd.exe -- [396288] -- [2008-04-14 19:21] --- SECURITYPROVIDERS regkey --- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" File: C:\WINDOWS\system32\msapsspc.dll -- [86016] -- [2008-04-14 19:20] File: C:\WINDOWS\system32\schannel.dll -- [147456] -- [2009-06-25 10:27] File: C:\WINDOWS\system32\digest.dll -- [68608] -- [2008-04-14 19:20] File: C:\WINDOWS\system32\msnsspc.dll -- [290816] -- [2008-04-14 19:20] --- Active Setup\Installed Components regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] -- File: C:\WINDOWS\system32\ieudinit.exe -- [36864] -- [2009-03-08 04:32] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] -- File: C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] -- File: "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] -- File: RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] -- File: %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] -- File: %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] -- File: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] -- File: regsvr32.exe /s /n /i:U shell32.dll -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] -- File: C:\WINDOWS\system32\ie4uinit.exe -BaseSettings -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] -- File: C:\WINDOWS\system32\ie4uinit.exe -BaseSettings -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -- File: C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9576E2CA-A349-7490-E9D5-2BE0BC82B17A}] -- filepath not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}] -- filepath not found --- Services regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AEAudio] -- File: system32\drivers\AEAudio.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\alcan5wn] -- File: system32\DRIVERS\alcan5wn.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\alcaudsl] -- File: system32\DRIVERS\alcaudsl.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CamAv] -- File: System32\Drivers\CamAv.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ENTECH] -- filepath not found --- SAFEBOOT MINIMAL SERVICES --- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal {533C5B84-EC70-11D2-9505-00C04F79DEAF} --- SAFEBOOT Network SERVICES --- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network DnsCache --- BOOTEXECUTE regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] "BootExecute"= autocheck autochk *\0\0 --- PENDINGFILERENAMEOPERATIONS regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] PendingFileRenameOperations key not found --- WOW-CMDLINE regkeys --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW] "cmdline" = %SystemRoot%\system32\ntvdm.exe "cmdline" = %SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386 --- NETSVCS regkey --- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] -- NETSVCS 0WmdmPmSN --- DNS SERVER regkeys --- no "NameServer" values found --- File associations --- .BAT files: ("%1" %*) .COM files: ("%1" %*) .EXE files: ("%1" %*) .HLP files: (%SystemRoot%\System32\winhlp32.exe %1) .INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1) .INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1) .JS files: (%SystemRoot%\System32\WScript.exe "%1" %*) .PIF files: ("%1" %*) .REG files: (regedit.exe "%1") .SCR files: ("%1" /S) .TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1) .VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*) --- STARTUP FOLDERS --- C:\Documents and Settings\user\Menu Start\Programy\Autostart\desktop.ini -- [84] -- [2007-11-29 18:17] C:\Documents and Settings\user\Menu Start\Programy\Autostart\ikowin32.exe -- [24576] -- [2008-04-14 19:21] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\desktop.ini -- [84] -- [2007-11-29 18:17] C:\Documents and Settings\user\Menu Start\Programy\Autostart\desktop.ini -- [84] -- [2007-11-29 18:17] C:\Documents and Settings\user\Menu Start\Programy\Autostart\ikowin32.exe -- [24576] -- [2008-04-14 19:21] C:\Documents and Settings\user\Menu Start\Programy\Autostart\desktop.ini -- [84] -- [2007-11-29 18:17] C:\Documents and Settings\user\Menu Start\Programy\Autostart\ikowin32.exe -- [24576] -- [2008-04-14 19:21] --- TASK SCHEDULER JOBS --- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-602609370-682003330-1003Core.job -- [1076] -- [2009-10-03 08:37] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-602609370-682003330-1003UA.job -- [1128] -- [2009-10-03 19:37] Scan completed: 2009-10-03 20:00:48,62 FINISHED