PRC - [2011-06-18 16:24:06 | 000,065,536 | ---- | M] (Microsoft Windows) -- C:\WINDOWS\system\explorer32.exe
PRC - [2009-10-31 21:09:31 | 000,062,976 | ---- | M] () -- C:\Documents and Settings\Komp\Menu Start\Programy\Autostart\ord32.exe
MOD - [2011-06-20 20:21:16 | 000,139,776 | RHS- | M] () -- C:\WINDOWS\system32\arking0.dll
SRV - File not found [Auto | Stopped] -- -- (StarWindServiceAE)
SRV - File not found [Disabled | Stopped] -- -- (AresChatServer)
SRV - [2011-06-16 07:58:20 | 003,435,096 | ---- | M] () [Auto | Running] -- d:\Program Files\Akamai\netsession_win_e877e12.dll -- (Akamai)
IE - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = My Web Search
IE - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultUrl = http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=NMqJ6k5LPNeI.XyZmpXuiw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}
IE - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - D:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - Reg Error: Value error. File not found
IE - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003\..\URLSearchHook: {ef468e5b-5b30-4136-a833-7f2e3a31afdf} - D:\Program Files\2Shared\prxtb2Sh2.dll (Conduit Ltd.)
[2009-12-27 14:52:54 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- D:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009-05-21 08:54:15 | 000,024,684 | ---- | M] (MyWebSearch.com) -- D:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003\..\Toolbar\WebBrowser: (HyperCam Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [HKLM] File not found
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [l33t] C:\WINDOWS\system\iexplore.exe ()
O4 - HKLM..\Run: [MyWebSearch Plugin] D:\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL (MyWebSearch.com)
O4 - HKLM..\Run: [RemoteControl] File not found
O4 - HKLM..\Run: [system] C:\WINDOWS\system\explorer32.exe (Microsoft Windows)
O4 - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003..\Run: [BitTorrent DNA] File not found
O4 - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003..\Run: [King_ar] C:\WINDOWS\system32\arking.exe ()
O4 - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003..\Run: [king_mg] C:\WINDOWS\system32\mgking.exe ()
O4 - HKU\S-1-5-21-1343024091-1606980848-1801674531-1003..\Run: [ratua.exe] C:\WINDOWS\ratua.exe ()
O4 - Startup: C:\Documents and Settings\Komp\Menu Start\Programy\Autostart\ord32.exe ()
O4 - Startup: C:\Documents and Settings\Komp\Menu Start\Programy\Autostart\smgr32.exe ()
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Value error. File not found
O32 - AutoRun File - [2011-06-20 20:21:07 | 000,000,063 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011-06-20 20:21:07 | 000,000,063 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{0d77d624-61b0-11df-b570-00138f185b11}\Shell\AutoRun\command - "" = H:\ji83j.exe
O33 - MountPoints2\{0d77d624-61b0-11df-b570-00138f185b11}\Shell\open\Command - "" = H:\ji83j.exe
O33 - MountPoints2\{1f36d2d6-d91f-11de-b47e-00138f185b11}\Shell\AutoRun\command - "" = H:\ji83j.exe
O33 - MountPoints2\{1f36d2d6-d91f-11de-b47e-00138f185b11}\Shell\open\Command - "" = H:\ji83j.exe
O33 - MountPoints2\{339c57cf-035b-11e0-b5fb-002618d9c2f2}\Shell - "" = AutoRun
O33 - MountPoints2\{7c8cdad8-edb4-11df-b5eb-002618d9c2f2}\Shell\AutoRun\command - "" = H:\ji83j.exe
O33 - MountPoints2\{7c8cdad8-edb4-11df-b5eb-002618d9c2f2}\Shell\open\Command - "" = H:\ji83j.exe
[2011-06-21 17:20:43 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011-06-20 20:19:50 | 000,115,712 | RHS- | M] () -- C:\WINDOWS\System32\mgking0.dll
[2011-06-20 20:19:16 | 000,000,262 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2011-06-20 20:19:16 | 000,000,254 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2011-06-20 20:17:15 | 000,000,300 | -HS- | M] () -- C:\WINDOWS\tasks\Hzclmldnwp.job
[2011-06-20 19:14:00 | 000,001,076 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-1606980848-1801674531-1003Core.job
[2011-06-20 16:48:26 | 000,000,472 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Komp.job
[2011-01-26 18:09:32 | 000,137,728 | RHS- | C] () -- C:\WINDOWS\System32\arking1.dll
[2010-08-14 18:17:11 | 000,167,424 | RHS- | C] () -- C:\WINDOWS\System32\samlibw.dll
[2010-03-16 21:25:43 | 000,114,688 | ---- | C] () -- D:\Program Files\l33t keylogger.exe
[2009-12-06 20:57:07 | 000,147,456 | ---- | C] () -- C:\WINDOWS\Kopia l33t keylogger generator.exe
[2010-12-28 20:37:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software
[2011-04-04 17:16:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\Tasks\wavepadDowngrade.job
[2011-04-05 17:16:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\Tasks\wavepadShakeIcon.job
@Alternate Data Stream - 1710303 bytes
