ComboFix 07-04-25.4V - Running from: “e:\Free Download Manager” /wow section - STAGE #3 (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) D:\Program Files\outerinfo\Terms.rtf D:\windows\system32\explorer.exe D:\WINDOWS\hosts D:\Program Files\outerinfo ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: D:\qoobox\purity\D\DOCUME~1 D:\qoobox\purity\D\DOCUME~1\User D:\qoobox\purity\D\DOCUME~1\User\DANEAP~1 D:\qoobox\purity\D\DOCUME~1\User\MOJEDO~1 D:\qoobox\purity\D\DOCUME~1\User\DANEAP~1\CROSOF~1 D:\qoobox\purity\D\DOCUME~1\User\DANEAP~1\ECURIT~1 D:\qoobox\purity\D\DOCUME~1\User\DANEAP~1\FNTS~1 D:\qoobox\purity\D\DOCUME~1\User\DANEAP~1\MCROSO~1.NET D:\qoobox\purity\D\DOCUME~1\User\DANEAP~1\SSEMBL~1 D:\qoobox\purity\D\DOCUME~1\User\DANEAP~1\STEM~1 D:\qoobox\purity\D\DOCUME~1\User\MOJEDO~1\CROSOF~1 D:\qoobox\purity\D\DOCUME~1\User\MOJEDO~1\ECURIT~1 D:\qoobox\purity\D\DOCUME~1\User\MOJEDO~1\RACLE~1 D:\qoobox\purity\D\DOCUME~1\User\MOJEDO~1\SEMBLY~1 D:\qoobox\purity\D\DOCUME~1\User\MOJEDO~1\SEMBLY~1\n?tepad.exe D:\qoobox\purity\D\Program Files\ASKS~1 D:\qoobox\purity\D\Program Files\CROSOF~1.NET D:\qoobox\purity\D\Program Files\FNTS~1 D:\qoobox\purity\D\Program Files\STEM~1 D:\qoobox\purity\D\Program Files\Common Files\FNTS~1 D:\qoobox\purity\D\Program Files\Common Files\TSKS~1 D:\qoobox\purity\D\WINDOWS\DOBE~1 D:\qoobox\purity\D\WINDOWS\system32\APPATC~1 D:\qoobox\purity\D\WINDOWS\system32\ASKS~1 D:\qoobox\purity\D\WINDOWS\system32\SSEMBL~1 D:\qoobox\purity\D\WINDOWS\system32\WNSXS~1 ((((((((((((((((((((((((((((((( Files Created from 2007-04-06 to 2007-05-06 )))))))))))))))))))))))))))))))))) 2007-05-06 16:08 71,680 --a------ D:\WINDOWS\g2876656.exe 2007-05-06 15:47 71,680 --a------ D:\WINDOWS\g1621515.exe 2007-05-06 15:27 71,680 --a------ D:\WINDOWS\g421609.exe 2007-05-06 00:36 71,680 --a------ D:\WINDOWS\g19919937.exe 2007-05-06 00:16 71,680 --a------ D:\WINDOWS\g18727203.exe 2007-05-05 23:56 71,680 --a------ D:\WINDOWS\g17512500.exe 2007-05-05 23:36 71,680 --a------ D:\WINDOWS\g16303828.exe 2007-05-05 22:56 71,680 --a------ D:\WINDOWS\g13893968.exe 2007-05-05 22:15 71,680 --a------ D:\WINDOWS\g11472921.exe 2007-05-05 22:01 2007-05-05 21:53 71,680 --a------ D:\WINDOWS\g10140250.exe 2007-05-05 21:33 71,680 --a------ D:\WINDOWS\g8930375.exe 2007-05-05 21:13 71,680 --a------ D:\WINDOWS\g7718203.exe 2007-05-05 20:53 71,680 --a------ D:\WINDOWS\g6517031.exe 2007-05-05 20:32 71,680 --a------ D:\WINDOWS\g5287062.exe 2007-05-05 20:10 71,680 --a------ D:\WINDOWS\g3969000.exe 2007-05-05 19:50 71,680 --a------ D:\WINDOWS\g2761312.exe 2007-05-05 19:30 71,680 --a------ D:\WINDOWS\g1564531.exe 2007-05-05 19:10 71,680 --a------ D:\WINDOWS\g361359.exe 2007-05-05 18:55 53,248 --a------ D:\WINDOWS\system32\Process.exe 2007-05-05 18:55 51,200 --a------ D:\WINDOWS\system32\dumphive.exe 2007-05-05 18:55 288,417 --a------ D:\WINDOWS\system32\SrchSTS.exe 2007-05-05 18:55 1,604 --a------ D:\WINDOWS\system32\tmp.reg 2007-05-05 18:38 71,680 --a------ D:\WINDOWS\g7987312.exe 2007-05-05 18:18 71,680 --a------ D:\WINDOWS\g6775140.exe 2007-05-05 17:58 71,680 --a------ D:\WINDOWS\g5570343.exe 2007-05-05 17:37 71,680 --a------ D:\WINDOWS\g4367359.exe 2007-05-05 17:17 71,680 --a------ D:\WINDOWS\g3153562.exe 2007-05-05 16:57 71,680 --a------ D:\WINDOWS\g1951796.exe 2007-05-05 16:37 71,680 --a------ D:\WINDOWS\g737421.exe 2007-05-05 03:13 71,680 --a------ D:\WINDOWS\g1811218.exe 2007-05-05 02:53 71,680 --a------ D:\WINDOWS\g591984.exe 2007-05-04 19:09 71,680 --a------ D:\WINDOWS\g6516312.exe 2007-05-04 18:49 71,680 --a------ D:\WINDOWS\g5311078.exe 2007-05-04 18:29 71,680 --a------ D:\WINDOWS\g4108093.exe 2007-05-04 18:09 71,680 --a------ D:\WINDOWS\g2909484.exe 2007-05-04 17:49 71,680 --a------ D:\WINDOWS\g1706781.exe 2007-05-04 17:29 71,680 --a------ D:\WINDOWS\g513468.exe 2007-05-03 16:03 71,680 --a------ D:\WINDOWS\g5426984.exe 2007-05-03 15:43 71,680 --a------ D:\WINDOWS\g4196968.exe 2007-05-03 15:30 347,253 --a------ D:\Silent Runners.vbs 2007-05-03 14:16 71,680 --a------ D:\WINDOWS\g1386765.exe 2007-05-02 23:37 71,680 --a------ D:\WINDOWS\g39946046.exe 2007-05-02 23:15 71,680 --a------ D:\WINDOWS\g38620921.exe 2007-05-02 20:47 71,680 --a------ D:\WINDOWS\g29719406.exe 2007-05-02 20:09 2007-05-02 19:25 71,680 --a------ D:\WINDOWS\g24800265.exe 2007-05-02 19:05 71,680 --a------ D:\WINDOWS\g23599125.exe 2007-05-02 17:45 71,680 --a------ D:\WINDOWS\g18797218.exe 2007-05-02 17:25 71,680 --a------ D:\WINDOWS\g17597093.exe 2007-05-02 16:05 71,680 --a------ D:\WINDOWS\g12774937.exe 2007-05-02 15:45 71,680 --a------ D:\WINDOWS\g11571343.exe 2007-05-02 14:24 71,680 --a------ D:\WINDOWS\g6767609.exe 2007-05-02 14:05 71,680 --a------ D:\WINDOWS\g5570140.exe 2007-05-02 13:48 2007-05-02 12:44 71,680 --a------ D:\WINDOWS\g753218.exe 2007-05-02 00:06 71,680 --a------ D:\WINDOWS\g5212734.exe 2007-05-01 23:45 71,680 --a------ D:\WINDOWS\g4002953.exe 2007-05-01 17:35 146,432 —hs---- D:\Program Files\Common Files\Yazzle1162OinAdmin.exe 2007-05-01 14:46 4,469,078 --a------ D:\IPChanger20Eng.exe 2007-05-01 14:00 2007-05-01 14:00 2007-05-01 13:59 813,947 --a------ D:\hideippla.exe 2007-05-01 13:51 71,680 --a------ D:\WINDOWS\g12823203.exe 2007-05-01 13:31 71,680 --a------ D:\WINDOWS\g11626765.exe 2007-05-01 13:11 71,680 --a------ D:\WINDOWS\g10425421.exe 2007-05-01 12:51 71,680 --a------ D:\WINDOWS\g9229671.exe 2007-05-01 12:31 71,680 --a------ D:\WINDOWS\g8022437.exe 2007-05-01 12:11 71,680 --a------ D:\WINDOWS\g6825125.exe 2007-05-01 11:51 71,680 --a------ D:\WINDOWS\g5621578.exe 2007-05-01 11:31 71,680 --a------ D:\WINDOWS\g4415859.exe 2007-05-01 11:11 71,680 --a------ D:\WINDOWS\g3213687.exe 2007-05-01 10:51 71,680 --a------ D:\WINDOWS\g2012890.exe 2007-05-01 10:29 71,680 --a------ D:\WINDOWS\g684078.exe 2007-05-01 00:58 71,680 --a------ D:\WINDOWS\g35300468.exe 2007-05-01 00:38 71,680 --a------ D:\WINDOWS\g34094484.exe 2007-05-01 00:18 71,680 --a------ D:\WINDOWS\g32896421.exe 2007-04-30 23:58 71,680 --a------ D:\WINDOWS\g31689734.exe 2007-04-30 23:36 71,680 --a------ D:\WINDOWS\g30361578.exe 2007-04-30 23:16 71,680 --a------ D:\WINDOWS\g29162593.exe 2007-04-30 22:53 71,680 --a------ D:\WINDOWS\g27837046.exe 2007-04-30 22:31 71,680 --a------ D:\WINDOWS\g26517281.exe 2007-04-30 22:12 71,680 --a------ D:\WINDOWS\g25316953.exe 2007-04-30 21:51 71,680 --a------ D:\WINDOWS\g24116546.exe 2007-04-30 21:31 71,680 --a------ D:\WINDOWS\g22909265.exe 2007-04-30 21:11 71,680 --a------ D:\WINDOWS\g21706484.exe 2007-04-30 20:51 71,680 --a------ D:\WINDOWS\g20506250.exe 2007-04-30 20:32 71,680 --a------ D:\WINDOWS\g19317906.exe 2007-04-30 20:11 71,680 --a------ D:\WINDOWS\g18098921.exe 2007-04-30 19:51 71,680 --a------ D:\WINDOWS\g16912625.exe 2007-04-30 19:31 71,680 --a------ D:\WINDOWS\g15704515.exe 2007-04-30 19:11 71,680 --a------ D:\WINDOWS\g14492875.exe 2007-04-30 18:51 71,680 --a------ D:\WINDOWS\g13271937.exe 2007-04-30 18:30 71,680 --a------ D:\WINDOWS\g12056734.exe 2007-04-30 18:09 71,680 --a------ D:\WINDOWS\g10739843.exe 2007-04-30 17:47 71,680 --a------ D:\WINDOWS\g9420203.exe 2007-04-30 17:24 71,680 --a------ D:\WINDOWS\g8096187.exe 2007-04-30 17:04 71,680 --a------ D:\WINDOWS\g6896921.exe 2007-04-30 16:42 71,680 --a------ D:\WINDOWS\g5570953.exe 2007-04-30 16:22 71,680 --a------ D:\WINDOWS\g4376031.exe 2007-04-30 16:00 71,680 --a------ D:\WINDOWS\g3053125.exe 2007-04-30 15:40 71,680 --a------ D:\WINDOWS\g1851953.exe 2007-04-30 15:19 71,680 --a------ D:\WINDOWS\g529078.exe 2007-04-30 06:09 71,680 --a------ D:\WINDOWS\g1753218.exe 2007-04-30 05:49 71,680 --a------ D:\WINDOWS\g551968.exe 2007-04-29 21:44 71,680 --a------ D:\WINDOWS\g43273671.exe 2007-04-29 21:24 71,680 --a------ D:\WINDOWS\g42065531.exe 2007-04-29 21:04 71,680 --a------ D:\WINDOWS\g40865968.exe 2007-04-29 20:44 71,680 --a------ D:\WINDOWS\g39663218.exe 2007-04-29 20:22 71,680 --a------ D:\WINDOWS\g38349296.exe 2007-04-29 20:02 71,680 --a------ D:\WINDOWS\g37153015.exe 2007-04-29 19:42 71,680 --a------ D:\WINDOWS\g35938859.exe 2007-04-29 19:20 71,680 --a------ D:\WINDOWS\g34615578.exe 2007-04-29 19:00 71,680 --a------ D:\WINDOWS\g33421171.exe 2007-04-29 18:40 71,680 --a------ D:\WINDOWS\g32218843.exe 2007-04-29 18:20 71,680 --a------ D:\WINDOWS\g31018656.exe 2007-04-29 18:00 71,680 --a------ D:\WINDOWS\g29816312.exe 2007-04-29 17:40 71,680 --a------ D:\WINDOWS\g28617609.exe 2007-04-29 17:20 71,680 --a------ D:\WINDOWS\g27417781.exe 2007-04-29 17:00 71,680 --a------ D:\WINDOWS\g26211062.exe 2007-04-29 16:39 71,680 --a------ D:\WINDOWS\g25004234.exe 2007-04-29 16:19 71,680 --a------ D:\WINDOWS\g23802296.exe 2007-04-29 15:59 71,680 --a------ D:\WINDOWS\g22597015.exe 2007-04-29 15:19 71,680 --a------ D:\WINDOWS\g20201671.exe 2007-04-29 14:59 71,680 --a------ D:\WINDOWS\g18984140.exe 2007-04-29 14:39 71,680 --a------ D:\WINDOWS\g17781593.exe 2007-04-29 14:17 71,680 --a------ D:\WINDOWS\g16451703.exe 2007-04-29 13:55 71,680 --a------ D:\WINDOWS\g15129890.exe 2007-04-29 13:35 71,680 --a------ D:\WINDOWS\g13928531.exe 2007-04-29 13:15 71,680 --a------ D:\WINDOWS\g12723796.exe 2007-04-29 12:55 71,680 --a------ D:\WINDOWS\g11527437.exe 2007-04-29 12:35 71,680 --a------ D:\WINDOWS\g10329843.exe 2007-04-29 12:15 71,680 --a------ D:\WINDOWS\g9111375.exe 2007-04-29 11:52 71,680 --a------ D:\WINDOWS\g7787328.exe 2007-04-29 11:32 71,680 --a------ D:\WINDOWS\g6588125.exe 2007-04-29 11:12 71,680 --a------ D:\WINDOWS\g5366546.exe 2007-04-29 10:50 71,680 --a------ D:\WINDOWS\g4044218.exe 2007-04-29 10:30 71,680 --a------ D:\WINDOWS\g2847531.exe 2007-04-29 10:17 20,942,920 --a------ D:\SkypeSetup.exe 2007-04-29 10:10 71,680 --a------ D:\WINDOWS\g1650468.exe 2007-04-29 09:50 71,680 --a------ D:\WINDOWS\g447875.exe 2007-04-29 02:56 71,680 --a------ D:\WINDOWS\g42045640.exe 2007-04-29 02:36 71,680 --a------ D:\WINDOWS\g40844312.exe 2007-04-29 02:16 71,680 --a------ D:\WINDOWS\g39643500.exe 2007-04-29 01:56 71,680 --a------ D:\WINDOWS\g38453265.exe 2007-04-29 01:36 71,680 --a------ D:\WINDOWS\g37237437.exe 2007-04-29 01:16 71,680 --a------ D:\WINDOWS\g36035468.exe 2007-04-29 00:56 71,680 --a------ D:\WINDOWS\g34833406.exe 2007-04-29 00:36 71,680 --a------ D:\WINDOWS\g33628437.exe 2007-04-29 00:14 71,680 --a------ D:\WINDOWS\g32309390.exe 2007-04-28 23:54 71,680 --a------ D:\WINDOWS\g31119968.exe 2007-04-28 23:34 71,680 --a------ D:\WINDOWS\g29908984.exe 2007-04-28 23:13 71,680 --a------ D:\WINDOWS\g28695312.exe 2007-04-28 22:53 71,680 --a------ D:\WINDOWS\g27493187.exe 2007-04-28 22:33 71,680 --a------ D:\WINDOWS\g26288531.exe 2007-04-28 22:24 2007-04-28 22:21 2007-04-28 22:14 8,023,276 --a------ D:\konnekt_setup_0.6.22.137.exe 2007-04-28 22:13 71,680 --a------ D:\WINDOWS\g25086203.exe 2007-04-28 21:53 71,680 --a------ D:\WINDOWS\g23877437.exe 2007-04-28 21:33 71,680 --a------ D:\WINDOWS\g22673390.exe 2007-04-28 21:11 71,680 --a------ D:\WINDOWS\g21347546.exe 2007-04-28 20:51 71,680 --a------ D:\WINDOWS\g20152078.exe 2007-04-28 20:29 71,680 --a------ D:\WINDOWS\g18828156.exe 2007-04-28 20:09 71,680 --a------ D:\WINDOWS\g17632781.exe 2007-04-28 19:49 71,680 --a------ D:\WINDOWS\g16429734.exe 2007-04-28 19:29 71,680 --a------ D:\WINDOWS\g15220531.exe 2007-04-28 19:09 71,680 --a------ D:\WINDOWS\g14049656.exe 2007-04-28 18:48 71,680 --a------ D:\WINDOWS\g12780421.exe 2007-04-28 18:26 71,680 --a------ D:\WINDOWS\g11449984.exe 2007-04-28 18:06 71,680 --a------ D:\WINDOWS\g10253421.exe 2007-04-28 18:02 2007-04-28 17:47 71,680 --a------ D:\WINDOWS\g9056406.exe 2007-04-28 17:26 71,680 --a------ D:\WINDOWS\g7843781.exe 2007-04-28 17:06 71,680 --a------ D:\WINDOWS\g6655359.exe 2007-04-28 16:46 71,680 --a------ D:\WINDOWS\g5417765.exe 2007-04-28 16:06 71,680 --a------ D:\WINDOWS\g3013109.exe 2007-04-28 15:45 71,680 --a------ D:\WINDOWS\g1807500.exe 2007-04-28 09:11 71,680 --a------ D:\WINDOWS\g1738125.exe 2007-04-28 08:51 71,680 --a------ D:\WINDOWS\g557062.exe 2007-04-28 00:12 71,680 --a------ D:\WINDOWS\g38441828.exe 2007-04-27 23:50 71,680 --a------ D:\WINDOWS\g37117062.exe 2007-04-27 23:30 71,680 --a------ D:\WINDOWS\g35921406.exe 2007-04-27 23:10 71,680 --a------ D:\WINDOWS\g34716921.exe 2007-04-27 22:48 71,680 --a------ D:\WINDOWS\g33393062.exe 2007-04-27 22:28 71,680 --a------ D:\WINDOWS\g32191890.exe 2007-04-27 22:08 71,680 --a------ D:\WINDOWS\g30991203.exe 2007-04-27 21:46 71,680 --a------ D:\WINDOWS\g29668250.exe 2007-04-27 21:26 71,680 --a------ D:\WINDOWS\g28467593.exe 2007-04-27 21:04 71,680 --a------ D:\WINDOWS\g27146593.exe 2007-04-27 20:42 71,680 --a------ D:\WINDOWS\g25826328.exe 2007-04-27 20:22 71,680 --a------ D:\WINDOWS\g24630421.exe 2007-04-27 20:00 71,680 --a------ D:\WINDOWS\g23305796.exe 2007-04-27 19:38 71,680 --a------ D:\WINDOWS\g21985750.exe 2007-04-27 19:16 71,680 --a------ D:\WINDOWS\g20669781.exe 2007-04-27 18:56 71,680 --a------ D:\WINDOWS\g19469218.exe 2007-04-27 18:34 71,680 --a------ D:\WINDOWS\g18139031.exe 2007-04-27 18:12 71,680 --a------ D:\WINDOWS\g16819187.exe 2007-04-27 17:50 71,680 --a------ D:\WINDOWS\g15497968.exe 2007-04-27 17:30 71,680 --a------ D:\WINDOWS\g14296984.exe 2007-04-27 17:07 71,680 --a------ D:\WINDOWS\g12972578.exe 2007-04-27 16:45 71,680 --a------ D:\WINDOWS\g11651781.exe 2007-04-27 16:24 71,680 --a------ D:\WINDOWS\g10334656.exe 2007-04-27 15:42 71,680 --a------ D:\WINDOWS\g7816703.exe 2007-04-27 15:22 71,680 --a------ D:\WINDOWS\g6607812.exe 2007-04-27 14:59 71,680 --a------ D:\WINDOWS\g5289250.exe 2007-04-27 14:38 71,680 --a------ D:\WINDOWS\g3968953.exe 2007-04-27 14:17 71,680 --a------ D:\WINDOWS\g2770656.exe 2007-04-27 13:57 71,680 --a------ D:\WINDOWS\g1565140.exe 2007-04-27 13:37 71,680 --a------ D:\WINDOWS\g368750.exe 2007-04-27 07:34 71,680 --a------ D:\WINDOWS\g2996765.exe 2007-04-27 07:14 71,680 --a------ D:\WINDOWS\g1813875.exe 2007-04-26 22:06 71,680 --a------ D:\WINDOWS\g6841953.exe 2007-04-26 21:46 71,680 --a------ D:\WINDOWS\g5640468.exe 2007-04-26 21:24 71,680 --a------ D:\WINDOWS\g4316546.exe 2007-04-26 21:02 71,680 --a------ D:\WINDOWS\g2999546.exe 2007-04-26 20:42 71,680 --a------ D:\WINDOWS\g1799234.exe 2007-04-26 20:20 71,680 --a------ D:\WINDOWS\g473609.exe 2007-04-26 20:20 33,792 --------- D:\WINDOWS\system32\wudb.dll 2007-04-16 21:31 2007-04-16 21:27 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-05-06 15:21 -------- d-------- D:\Program Files\netpanel 2007-05-06 00:55 24 --a------ D:\WINDOWS\system32\dvcstatebkp-{00000000-00000000-0000000a-00001102-00000002-80641102}.dat 2007-05-06 00:55 24 --a------ D:\WINDOWS\system32\dvcstate-{00000000-00000000-0000000a-00001102-00000002-80641102}.dat 2007-05-05 23:53 -------- d-------- D:\DOCUME~1\User\DANEAP~1\tlen.pl 2007-05-05 18:56 -------- d-------- D:\Program Files\minicliptoolbar toolbar 2007-05-05 02:48 2 --a------ D:\WINDOWS\system32\wintisv.exe 2007-05-03 18:02 40183 —hs---- D:\Program Files\Common Files\yazzle1162oinuninstaller.exe 2007-05-02 19:20 -------- d-------- D:\DOCUME~1\User\DANEAP~1\skype 2007-04-27 22:32 -------- d-------- D:\DOCUME~1\User\DANEAP~1\teamspeak2 2007-03-30 21:45 3331 --a------ D:\WINDOWS\system32\spoonuninstall-dbpoweramp ogg vorbis lancer encoder.dat 2007-03-30 21:42 806264 --a------ D:\WINDOWS\system32\spoonuninstall.exe 2007-03-25 08:45 50748 --a------ D:\WINDOWS\system32\perfc015.dat 2007-03-25 08:45 358702 --a------ D:\WINDOWS\system32\perfh015.dat 2007-03-25 00:48 11032 --a------ D:\WINDOWS\system32\spoonuninstall-dmc sveta portable audio.dat 2007-03-25 00:47 36417 --a------ D:\WINDOWS\system32\spoonuninstall-dbpoweramp music converter.dat 2007-03-19 21:39 -------- d–h----- D:\Program Files\installshield installation information 2007-03-15 07:41 11816 --a------ D:\WINDOWS\mozver.dat 2007-02-28 15:39 18432 --a------ D:\WINDOWS\system32\winbme32.dll 2007-02-12 06:58 68 --a------ D:\WINDOWS\system32\remstats32.dll 2007-02-10 10:48 0 --a------ D:\DOCUME~1\User\DANEAP~1\milihk32.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} D:\PROGRA~1\FlashGet\jccatch.dll {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} C:\BitComet\tools\BitCometBHO.dll {53707962-6F74-2D53-2644-206D7942484F} D:\PROGRA~1\SPYBOT~1\SDHelper.dll {6BB1FD17-6280-1D50-F24E-6BE336E1AECC} D:\WINDOWS\System32\yaslebc.dll [x] {CC59E0F9-7E43-44FA-9FAA-8377850BF205} e:\Free Download Manager\iefdmcks.dll {CE7C3CF0-4B15-11D1-ABED-709549C10000} D:\Program Files\NetPanel\IEHelper.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “NetPanel”="“D:\Program Files\NetPanel\Starter.exe” /path=“D:\Program Files\NetPanel”" “MULTIMEDIA KEYBOARD”=“D:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe” “NvCplDaemon”=“RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup” [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “Komunikator”=“D:\Tlen.pl\tlen.exe” [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoAutoUpdate”=dword:00000001 “ClearRecentDocsOnExit”=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run] HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winbme32 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wudb HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages REG_MULTI_SZ msv1_0\0\0 Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages REG_MULTI_SZ scecli\0\0 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^hp psc 2000 Series.lnk] “location”=“Common Startup” “command”=“D:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpobnz08.exe " “item”=“hp psc 2000 Series” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^officejet 6100.lnk] “location”=“Common Startup” “command”=“D:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hposol08.exe " “item”=“officejet 6100” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“ADGJDet” “hkey”=“HKLM” “command”=”“D:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe”” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“msmsgs” “hkey”=“HKCU” “command”="“D:\Program Files\Messenger\msmsgs.exe” /background" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“hpgs2wnd” “hkey”=“HKLM” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“THGuard” “hkey”=“HKLM” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“UpdReg” “hkey”=“HKLM” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“CTHELPER” “hkey”=“HKLM” “command”=“CTHELPER.EXE” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 ~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ backup-20070506-151720-797 O4 - HKCU…\Run: [Zscwojs] “D:\Documents and Settings\User\Moje dokumenty??sembly\n?tepad.exe” backup-20070506-151720-975 O4 - HKCU…\Run: [Dtrr] “D:\PROGRA~1\COMMON~1\FNTS~1\taskmgr.exe” -vt yazb backup-20070505-185655-555 O3 - Toolbar: Miniclip - {4E7BD74F-2B8D-469E-89B3-BE29F5D3E32D} - D:\PROGRA~1\MINICL~1\MINICL~1.DLL backup-20070505-185654-261 O2 - BHO: Miniclip - {4E7BD74F-2B8D-469E-89B3-BE29F5D3E32D} - D:\PROGRA~1\MINICL~1\MINICL~1.DLL backup-20070505-185450-319 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com backup-20070505-185450-518 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com backup-20070505-185450-187 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank backup-20070505-185450-181 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com backup-20070505-185450-935 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com backup-20070505-185450-672 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com backup-20070505-185450-195 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmyrequest.com/sp.php backup-20070505-185450-625 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://searchmyrequest.com/sp.php backup-20070505-185450-867 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s backup-20070505-185450-142 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com backup-20070505-185450-785 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com backup-20070505-185450-230 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://prosearching.com/ backup-20070505-185450-849 F2 - REG:system.ini: UserInit=userinit.exe backup-20070505-185450-928 O4 - HKLM…\Run: [explorer] D:\WINDOWS\System32\explorer.exe backup-20070505-185450-426 O4 - HKLM…\RunServices: [WINRUN] taskgmr.exe backup-20070505-185450-198 O4 - HKCU…\RunOnce: [FFTI] D:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\ugqesii8.default\extensions{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath=“D:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles/ugqesii8.default\extensions{B13721C7-F507-4982-B2E5-502A71474FED}” backup-20070505-185450-149 O4 - Startup: .protected backup-20070505-185450-384 O4 - Global Startup: .protected backup-20070505-185450-326 O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Media … e-c403.cab backup-20070505-185451-648 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleAc … refid=1162 backup-20070505-185451-725 O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://212.239.40.78/cdo/pl/game.exe backup-20070505-185451-791 O20 - Winlogon Notify: winbme32 - D:\WINDOWS\SYSTEM32\winbme32.dll backup-20070505-185451-241 O20 - Winlogon Notify: winzzd32 - winzzd32.dll (file missing) backup-20070505-185451-240 O20 - Winlogon Notify: wudb - D:\WINDOWS\System32\wudb.dll backup-20070505-185450-241 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.accoona.com/search_assistant … gn=wdz0805 backup-20070505-185450-416 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.accoona.com backup-20070505-185450-121 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com backup-20070505-185450-323 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com Contents of the ‘Scheduled Tasks’ folder D:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1148279505.job ******************************************************************** catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-06 16:20:01 Windows 5.1.2600 NTFS scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files …