"master" - 2007-05-16 20:14:11 Dodatek Service Pack 2
ComboFix 07-05.13.2.V - Running from: ""
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\byxyvur.dll
C:\WINDOWS\system32\gebabax.dll
C:\WINDOWS\system32\qomkkki.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wpcap.dll
C:\Program Files\screensavers.com\Installer\bin\iebyterange.xml
C:\Program Files\screensavers.com\Installer\bin\iebyterange.xml.backup
C:\Program Files\screensavers.com\Installer\bin\siuninst.exe
C:\Program Files\screensavers.com\Wallpaper\swpstart.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\Program Files\screensavers.com
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\WINDOWS\WNSXS~1
C:\qoobox\purity\C\WINDOWS\WNSXS~1\smss.exe~
C:\qoobox\purity\C\WINDOWS\WNSXS~1\W?nSxS
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NM
-------\LEGACY_NPF
-------\nm
-------\NPF
-------\pe386
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-16 ))))))))))))))))))))))))))))))))))
2007-05-15 19:26 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-05-15 19:26 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-05-15 19:26 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-05-15 17:23 196,608 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-05-15 17:23 1,040,384 --a------ C:\WINDOWS\system32\libeay32.dll
2007-05-15 15:28 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Spybot - Search & Destroy
2007-05-15 15:25 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-05-15 14:05 2,940 --a------ C:\WINDOWS\system32\tmp.reg
2007-05-15 13:07 <DIR> d-------- C:\Program Files\ochrona
2007-05-14 23:19 82,258 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-05-14 23:19 82,258 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-05-14 23:18 5,531,936 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-05-14 23:18 15,136 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-05-14 23:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Kaspersky Lab
2007-05-14 23:04 71,680 --a------ C:\WINDOWS\g142796.exe
2007-05-14 22:42 71,680 --a------ C:\WINDOWS\g262656.exe
2007-05-14 22:15 71,680 --a------ C:\WINDOWS\g143140.exe
2007-05-14 21:45 71,680 --a------ C:\WINDOWS\g31861359.exe
2007-05-14 21:23 71,680 --a------ C:\WINDOWS\g30541578.exe
2007-05-14 21:01 71,680 --a------ C:\WINDOWS\g29219625.exe
2007-05-14 20:39 71,680 --a------ C:\WINDOWS\g27886718.exe
2007-05-14 20:17 71,680 --a------ C:\WINDOWS\g26566265.exe
2007-05-14 19:55 71,680 --a------ C:\WINDOWS\g25245890.exe
2007-05-14 19:33 71,680 --a------ C:\WINDOWS\g23925562.exe
2007-05-14 19:11 71,680 --a------ C:\WINDOWS\g22605296.exe
2007-05-14 18:51 71,680 --a------ C:\WINDOWS\g21404656.exe
2007-05-14 18:29 71,680 --a------ C:\WINDOWS\g20084406.exe
2007-05-14 18:07 71,680 --a------ C:\WINDOWS\g18764062.exe
2007-05-14 17:45 71,680 --a------ C:\WINDOWS\g17450578.exe
2007-05-14 17:23 71,680 --a------ C:\WINDOWS\g16119921.exe
2007-05-14 17:01 71,680 --a------ C:\WINDOWS\g14799265.exe
2007-05-14 16:39 71,680 --a------ C:\WINDOWS\g13479843.exe
2007-05-14 16:17 71,680 --a------ C:\WINDOWS\g12158593.exe
2007-05-14 15:55 71,680 --a------ C:\WINDOWS\g10837843.exe
2007-05-14 15:33 71,680 --a------ C:\WINDOWS\g9517953.exe
2007-05-14 15:11 71,680 --a------ C:\WINDOWS\g8198000.exe
2007-05-14 14:51 71,680 --a------ C:\WINDOWS\g6996921.exe
2007-05-14 14:29 71,680 --a------ C:\WINDOWS\g5676046.exe
2007-05-14 14:07 71,680 --a------ C:\WINDOWS\g4355312.exe
2007-05-14 13:45 71,680 --a------ C:\WINDOWS\g3034812.exe
2007-05-14 13:23 71,680 --a------ C:\WINDOWS\g1714734.exe
2007-05-14 13:01 71,680 --a------ C:\WINDOWS\g394281.exe
2007-05-14 08:24 71,680 --a------ C:\WINDOWS\g1355906.exe
2007-05-14 08:04 71,680 --a------ C:\WINDOWS\g154687.exe
2007-05-14 00:58 71,680 --a------ C:\WINDOWS\g3514921.exe
2007-05-14 00:38 71,680 --a------ C:\WINDOWS\g2314546.exe
2007-05-14 00:16 71,680 --a------ C:\WINDOWS\g994359.exe
2007-05-13 23:55 71,680 --a------ C:\WINDOWS\g6884984.exe
2007-05-13 23:33 71,680 --a------ C:\WINDOWS\g5573203.exe
2007-05-13 23:11 71,680 --a------ C:\WINDOWS\g4241437.exe
2007-05-13 22:49 71,680 --a------ C:\WINDOWS\g2920531.exe
2007-05-13 22:29 71,680 --a------ C:\WINDOWS\g1719390.exe
2007-05-13 22:03 71,680 --a------ C:\WINDOWS\g158218.exe
2007-05-13 21:10 71,680 --a------ C:\WINDOWS\g159843.exe
2007-05-13 20:07 71,680 --a------ C:\WINDOWS\g34138203.exe
2007-05-13 19:45 71,680 --a------ C:\WINDOWS\g32817812.exe
2007-05-13 19:23 71,680 --a------ C:\WINDOWS\g31497546.exe
2007-05-13 19:01 71,680 --a------ C:\WINDOWS\g30176984.exe
2007-05-13 18:41 71,680 --a------ C:\WINDOWS\g28976156.exe
2007-05-13 18:19 71,680 --a------ C:\WINDOWS\g27655812.exe
2007-05-13 17:57 71,680 --a------ C:\WINDOWS\g26335531.exe
2007-05-13 17:35 71,680 --a------ C:\WINDOWS\g25015515.exe
2007-05-13 17:15 71,680 --a------ C:\WINDOWS\g23814796.exe
2007-05-13 16:53 71,680 --a------ C:\WINDOWS\g22494593.exe
2007-05-13 16:33 71,680 --a------ C:\WINDOWS\g21295656.exe
2007-05-13 16:13 71,680 --a------ C:\WINDOWS\g20093000.exe
2007-05-13 15:51 71,680 --a------ C:\WINDOWS\g18772609.exe
2007-05-13 15:29 71,680 --a------ C:\WINDOWS\g17452296.exe
2007-05-13 15:07 71,680 --a------ C:\WINDOWS\g16132046.exe
2007-05-13 14:47 71,680 --a------ C:\WINDOWS\g14931000.exe
2007-05-13 14:25 71,680 --a------ C:\WINDOWS\g13610796.exe
2007-05-13 13:55 71,680 --a------ C:\WINDOWS\g11809734.exe
2007-05-13 13:33 71,680 --a------ C:\WINDOWS\g10488203.exe
2007-05-13 13:11 71,680 --a------ C:\WINDOWS\g9168281.exe
2007-05-13 12:51 71,680 --a------ C:\WINDOWS\g7965875.exe
2007-05-13 12:29 71,680 --a------ C:\WINDOWS\g6645343.exe
2007-05-13 12:07 71,680 --a------ C:\WINDOWS\g5327656.exe
2007-05-13 11:45 71,680 --a------ C:\WINDOWS\g4004718.exe
2007-05-13 11:23 71,680 --a------ C:\WINDOWS\g2682000.exe
2007-05-13 11:01 71,680 --a------ C:\WINDOWS\g1360406.exe
2007-05-13 10:41 71,680 --a------ C:\WINDOWS\g157859.exe
2007-05-13 08:51 71,680 --a------ C:\WINDOWS\g278593.exe
2007-05-13 00:41 71,680 --a------ C:\WINDOWS\g25005781.exe
2007-05-13 00:19 71,680 --a------ C:\WINDOWS\g23685531.exe
2007-05-12 23:59 71,680 --a------ C:\WINDOWS\g22484531.exe
2007-05-12 23:37 71,680 --a------ C:\WINDOWS\g21164750.exe
2007-05-12 23:15 71,680 --a------ C:\WINDOWS\g19844125.exe
2007-05-12 22:53 71,680 --a------ C:\WINDOWS\g18523578.exe
2007-05-12 22:31 71,680 --a------ C:\WINDOWS\g17203343.exe
2007-05-12 22:11 71,680 --a------ C:\WINDOWS\g16003078.exe
2007-05-12 21:48 71,680 --a------ C:\WINDOWS\g14682343.exe
2007-05-12 21:26 71,680 --a------ C:\WINDOWS\g13361875.exe
2007-05-12 21:05 71,680 --a------ C:\WINDOWS\g12042203.exe
2007-05-12 20:42 71,680 --a------ C:\WINDOWS\g10721187.exe
2007-05-12 20:20 71,680 --a------ C:\WINDOWS\g9400937.exe
2007-05-12 20:00 71,680 --a------ C:\WINDOWS\g8200031.exe
2007-05-12 19:38 71,680 --a------ C:\WINDOWS\g6879750.exe
2007-05-12 19:28 <DIR> d-------- C:\Program Files\Ganymede
2007-05-12 19:16 71,680 --a------ C:\WINDOWS\g5559515.exe
2007-05-12 18:54 71,680 --a------ C:\WINDOWS\g4239234.exe
2007-05-12 18:32 71,680 --a------ C:\WINDOWS\g2918890.exe
2007-05-12 18:10 71,680 --a------ C:\WINDOWS\g1598515.exe
2007-05-12 17:48 71,680 --a------ C:\WINDOWS\g277062.exe
2007-05-12 16:10 71,680 --a------ C:\WINDOWS\g157531.exe
2007-05-12 13:13 71,680 --a------ C:\WINDOWS\g10099421.exe
2007-05-12 13:13 33,792 --a------ C:\WINDOWS\system32\wudb.dll
2007-05-12 13:12 26,678 --a------ C:\WINDOWS\system32\pmnlmli.dll.vir
2007-05-09 00:06 <DIR> d-------- C:\Program Files\Joost
2007-05-09 00:06 <DIR> d-------- C:\DOCUME~1\master\DANEAP~1\Joost
2007-05-08 00:28 69,632 --a------ C:\WINDOWS\system32\xmltok.dll
2007-05-08 00:28 36,864 --a------ C:\WINDOWS\system32\xmlparse.dll
2007-05-05 20:36 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2007-05-05 20:36 26,096 --a------ C:\WINDOWS\system32\xmlinst.exe
2007-05-05 20:15 <DIR> d-------- C:\WINDOWS\Cache
2007-05-05 19:56 <DIR> d-------- C:\DOCUME~1\master\.thumbnails
2007-05-05 19:54 <DIR> d-------- C:\DOCUME~1\master\.gimp-2.2
2007-05-05 19:53 <DIR> d-------- C:\Program Files\GIMP-2.0
2007-05-05 12:05 <DIR> d-------- C:\DOCUME~1\master\DANEAP~1\Opera
2007-04-28 23:49 <DIR> d-------- C:\Program Files\e frontier
2007-04-28 22:27 59,904 --a------ C:\WINDOWS\system32\Mscc2fr.dll
2007-04-28 22:27 32,768 --a------ C:\WINDOWS\system32\CMDLGFR.DLL
2007-04-28 22:27 21,504 --a------ C:\WINDOWS\system32\TABCTFR.DLL
2007-04-28 22:27 15,360 --a------ C:\WINDOWS\system32\inetfr.DLL
2007-04-28 22:27 141,312 --a------ C:\WINDOWS\system32\MSCMCFR.DLL
2007-04-28 14:33 3,120 --a------ C:\WINDOWS\system32\6ffdbcaf-f6c1-42d3-a4a9-c7957224a70b.dll
2007-04-28 14:33 <DIR> d-------- C:\DOCUME~1\master\DANEAP~1\e frontier
2007-04-28 14:27 <DIR> d-------- C:\Program Files\Manga Studio 3.0 EX Demo
2007-04-27 14:47 <DIR> d-------- C:\Program Files\Audacity
2007-04-27 14:39 34 -rahs---- C:\WINDOWS\system32\WWYMBOOT.DLL
2007-04-27 14:39 <DIR> d-------- C:\Program Files\AST
2007-04-27 14:17 <DIR> d-------- C:\Program Files\aipro
2007-04-25 15:01 <DIR> d-------- C:\WINDOWS\speech
2007-04-25 15:00 <DIR> d-------- C:\Program Files\ivo
2007-04-24 11:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Google
2007-04-22 13:06 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-04-22 13:06 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-04-22 13:06 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-04-22 13:06 115,880 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-04-22 11:27 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-04-22 11:26 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-04-22 11:26 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-04-20 15:43 <DIR> d-------- C:\Program Files\VirtualDub-1.6.17
2007-04-17 17:27 <DIR> d-------- C:\Program Files\CamStudio
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
Rootkit driver pe386 is present. ... attempting disinfection
pe386 ...... driver unloaded successfully.
ADS removed - system32: deleted 79094 bytes in 1 streams.
2007-05-14 21:05:41 -------- d-----w C:\DOCUME~1\master\DANEAP~1\OpenOffice.ux.pl2
2007-05-14 18:51:58 -------- d-----w C:\Program Files\mIRC
2007-05-13 19:12:45 -------- d---a-w C:\Program Files\flashFXP
2007-05-12 17:29:19 -------- d-----w C:\DOCUME~1\master\DANEAP~1\GanymedeNet
2007-05-07 22:29:00 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-07 08:46:01 -------- d-----w C:\Program Files\Ahead
2007-05-05 19:24:02 -------- d-----w C:\Program Files\Winamp
2007-05-05 18:36:51 -------- d-----w C:\Program Files\Ubisoft
2007-04-22 20:55:40 -------- d-----w C:\Program Files\XBC
2007-04-22 11:01:02 -------- d-----w C:\Program Files\Windows NT
2007-04-21 16:55:58 -------- d-----w C:\Program Files\Apple Software Update
2007-04-21 15:22:27 -------- d-----w C:\Program Files\WinPcap
2007-04-19 12:16:10 -------- d-----w C:\Program Files\iTunes
2007-04-15 19:32:36 -------- d-----w C:\Program Files\WinAce
2007-04-06 14:34:43 -------- d-----w C:\Program Files\BearShare
2007-04-01 13:04:45 -------- d-----w C:\DOCUME~1\master\DANEAP~1\Apple Computer
2007-04-01 13:04:03 -------- d-----w C:\Program Files\QuickTime
2007-03-31 15:19:01 -------- d-----w C:\Program Files\K700Dateimanager
2007-03-25 08:16:46 67,078 ----a-w C:\WINDOWS\system32\perfc015.dat
2007-03-25 08:16:46 435,978 ----a-w C:\WINDOWS\system32\perfh015.dat
2007-03-22 06:32:57 -------- d-----w C:\Program Files\Common Files\Ahead
2007-03-19 16:27:38 -------- d-----w C:\Program Files\Kaspersky Lab
2007-03-17 13:45:36 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-15 17:03:56 -------- d-----w C:\Program Files\SpywareBlaster
2007-03-09 18:52:52 200,768 ----a-w C:\WINDOWS\system32\klogon.dll
2007-03-08 15:38:47 579,072 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:38:47 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:38:47 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:37:33 1,843,840 ----a-w C:\WINDOWS\system32\win32k.sys
2007-03-07 01:21:11 5,766 ----a-w C:\WINDOWS\mozver.dat
2007-03-06 10:58:50 -------- d-----w C:\Program Files\CatchTheSperm2
2007-02-28 22:25:35 6,268 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-02-09 12:52:31 56 --sh--r C:\WINDOWS\system32\A2D3AE6D8C.sys
2007-02-08 13:59:57 4 ----a-w C:\WINDOWS\system32\proc1395793746.bin
2007-02-05 20:19:48 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-05-12 00:47]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"RemoteControl"="\"C:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe\""
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"ISUSPM Startup"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"Kaspersky"="C:\\\\Program Files\\\\Kaspersky Lab\\\\Kaspersky Anti-Virus Personal\\\\kav.exe"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"AVP"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [])
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 22:05]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 18:35]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2005-06-10 16:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 17:30]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 17:30]
"Kaspersky"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus Personal\\kav.exe" []
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 22:09]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2007-03-09 20:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"="" [])
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2003-07-21 19:21]
"Error Safe"="C:\Program Files\Error Safe Free\ers.exe" []
"Rurb"="C:\WINDOWS\WNSXS~1\smss.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"PowerBar"=""
"NBJ"="C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe"
"Error Safe"="\"C:\\Program Files\\Error Safe Free\\ers.exe\" /min"
"Rurb"="\"C:\\WINDOWS\\WNSXS~1\\smss.exe\" -vt yazb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"{F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}"="C:\PROGRA~1\COMMON~1\stardock\MCPCore.dll" [2005-05-10 14:31]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrvc32
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wudb
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="wbsys.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\ersd.sys
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^menu start^programy^autostart^raconfig.lnk
C:\WINDOWS\system32\RaConfig.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter HTTPFilter\0\0
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
DcomLaunch DcomLaunch\0TermService\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
WudfServiceGroup WUDFSvc\0\0
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070515-135915-306
O4 - HKLM\..\Run: [Error Safe] C:\Program Files\Error Safe Free\ers.exe /scan
backup-20070515-135915-786
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
backup-20070515-135915-120
O4 - HKCU\..\Run: [scvhost] c:\windows\system\scvhost.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-16 20:21:34
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ?X?????????????????????????????????????????????????????????????|p??|????m??|?`?w????????@X????@?8?@?????@X??c"?s???s??????@?????N'?s<W7?L|?s????????????u??s????????c"?s???s??????@?8?@?N'?s?W7??$@?8?@?8?@??????????W7??B7????s?B7??V7??B7??B7?0i?s????????HW7????
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-16 20:22:34 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-16 20:22
.