:OTL MOD - [2011-01-21 14:57:26 | 000,116,224 | RHS- | M] () – C:\WINDOWS\system32\mgking0.dll MOD - [2011-01-21 14:57:20 | 000,075,264 | RHS- | M] () – C:\Documents and Settings\Samanta\Ustawienia lokalne\Temp\dsoqq0.dll DRV - File not found [Kernel | On_Demand | Running] – -- (xp) IE - HKU\S-1-5-21-329068152-1078145449-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/ IE - HKU\S-1-5-21-329068152-1078145449-1417001333-1003…\URLSearchHook: {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files\Mario_Forever\tbMar2.dll (Conduit Ltd.) FF - prefs.js…browser.search.defaultengine: “Ask.com” FF - prefs.js…browser.search.defaultenginename: “BearShare Web Search” FF - prefs.js…browser.search.order.1: “BearShare Web Search” FF - prefs.js…keyword.URL: “http://search.bearshare.com/web?src=ffb&systemid=2&q=” [2010-09-14 13:41:12 | 000,002,506 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll () O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Mario Forever Toolbar) - {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files\Mario_Forever\tbMar2.dll (Conduit Ltd.) O3 - HKLM…\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll () O3 - HKLM…\Toolbar: (Mario Forever Toolbar) - {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files\Mario_Forever\tbMar2.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-329068152-1078145449-1417001333-1003…\Toolbar\WebBrowser: (Mario Forever Toolbar) - {707DB484-2428-402D-AFB5-D85B387544C7} - C:\Program Files\Mario_Forever\tbMar2.dll (Conduit Ltd.) O4 - HKU\S-1-5-21-329068152-1078145449-1417001333-1003…\Run: [api32] C:\Documents and Settings\Samanta\Ustawienia lokalne\Temp\apiqq.exe () O4 - HKU\S-1-5-21-329068152-1078145449-1417001333-1003…\Run: [dso32] C:\Documents and Settings\Samanta\Ustawienia lokalne\Temp\dsoqq.exe () O4 - HKU\S-1-5-21-329068152-1078145449-1417001333-1003…\Run: [King_ar] C:\WINDOWS\system32\arking.exe () O4 - HKU\S-1-5-21-329068152-1078145449-1417001333-1003…\Run: [king_mg] C:\WINDOWS\system32\mgking.exe () O4 - Startup: C:\Documents and Settings\All Users\My applications\Windows Defender Apps Control.exe () O20 - AppInit_DLLs: (C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\datamngr.dll) - C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngr.dll (MusicLab, LLC) O20 - AppInit_DLLs: (C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll) - C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC) O32 - AutoRun File - [2011-01-21 16:12:50 | 000,000,053 | ---- | M] () - C:\autorun.inf – [NTFS] O32 - AutoRun File - [2011-01-21 16:12:38 | 000,000,063 | RHS- | M] () - D:\autorun.inf – [NTFS] O32 - AutoRun File - [2011-01-21 16:12:42 | 000,000,063 | RHS- | M] () - E:\autorun.inf – [NTFS] O32 - AutoRun File - [2011-01-21 16:12:46 | 000,000,063 | RHS- | M] () - F:\autorun.inf – [NTFS] O33 - MountPoints2{005327b0-bc41-11df-8889-0017314dac98}\Shell\AutoRun\command - “” = I:\kyme.exe O33 - MountPoints2{005327b0-bc41-11df-8889-0017314dac98}\Shell\open\Command - “” = I:\kyme.exe O33 - MountPoints2{725b00a4-b605-11df-8882-0017314dac98}\Shell\AutoRun\command - “” = I:\bu8.exe O33 - MountPoints2{725b00a4-b605-11df-8882-0017314dac98}\Shell\open\Command - “” = I:\bu8.exe O33 - MountPoints2{7b44ebc0-8def-11df-8e3d-806d6172696f}\Shell\AutoRun\command - “” = C:\i00dvoym.exe – [2010-11-19 15:18:30 | 000,177,152 | RHS- | M] () O33 - MountPoints2{7b44ebc0-8def-11df-8e3d-806d6172696f}\Shell\open\Command - “” = C:\i00dvoym.exe – [2010-11-19 15:18:30 | 000,177,152 | RHS- | M] () O33 - MountPoints2{7b44ebc1-8def-11df-8e3d-806d6172696f}\Shell\AutoRun\command - “” = D:\i00dvoym.exe – [2010-11-19 15:18:30 | 000,177,152 | RHS- | M] () O33 - MountPoints2{7b44ebc1-8def-11df-8e3d-806d6172696f}\Shell\open\Command - “” = D:\i00dvoym.exe – [2010-11-19 15:18:30 | 000,177,152 | RHS- | M] () O33 - MountPoints2{7b44ebc2-8def-11df-8e3d-806d6172696f}\Shell\AutoRun\command - “” = E:\i00dvoym.exe – [2010-11-19 15:18:30 | 000,177,152 | RHS- | M] () O33 - MountPoints2{7b44ebc2-8def-11df-8e3d-806d6172696f}\Shell\open\Command - “” = E:\i00dvoym.exe – [2010-11-19 15:18:30 | 000,177,152 | RHS- | M] () O33 - MountPoints2{7b44ebc3-8def-11df-8e3d-806d6172696f}\Shell\AutoRun\command - “” = F:\i00dvoym.exe – [2010-11-19 15:18:30 | 000,177,152 | RHS- | M] () O33 - MountPoints2{7b44ebc3-8def-11df-8e3d-806d6172696f}\Shell\open\Command - “” = F:\i00dvoym.exe – [2010-11-19 15:18:30 | 000,177,152 | RHS- | M] () O33 - MountPoints2{c1025e91-8de2-11df-8816-d1ab9f9abc90}\Shell\AutoRun\command - “” = I:\i00dvoym.exe O33 - MountPoints2{c1025e91-8de2-11df-8816-d1ab9f9abc90}\Shell\open\Command - “” = I:\i00dvoym.exe [2011-01-10 18:46:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Samanta\Ustawienia lokalne\Dane aplikacji\ConduitEngine [2011-01-21 15:02:53 | 000,000,260 | ---- | M] () – C:\WINDOWS\tasks\WGASetup.job [2011-01-21 14:57:26 | 000,116,224 | RHS- | M] () – C:\WINDOWS\System32\mgking0.dll [2011-01-20 16:00:41 | 000,121,344 | RHS- | M] () – C:\WINDOWS\System32\arking0.dll [2010-12-31 16:50:44 | 000,177,152 | RHS- | C] () – C:\i00dvoym.exe [2010-12-23 22:40:09 | 000,114,688 | RHS- | C] () – C:\bu8.exe [2010-11-30 14:39:41 | 000,121,344 | RHS- | C] () – C:\WINDOWS\System32\arking0.dll [2010-11-19 15:18:35 | 000,116,224 | RHS- | C] () – C:\WINDOWS\System32\mgking1.dll [2010-11-18 15:14:48 | 000,116,224 | RHS- | C] () – C:\WINDOWS\System32\mgking0.dll [2010-10-17 15:30:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\BearShare [2010-11-06 10:08:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Samanta\Dane aplikacji\bearsharemediabartb :Files C:\et3ypes.exe C:\kyme.exe :Commands [emptytemp]