Itt at deletelés utáni Combo log
ComboFix 09-01-01.02 - Gergely 2009-01-03 16:55:18.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.512.182 [GMT 1:00]
Running from: c:\documents and settings\Gergely\Asztal\ComboFix.exe
Command switches used :: c:\documents and settings\Gergely\Asztal\CFScript.txt.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\windows\hpqEmlSz.INI
c:\windows\system32\
01.tmp
c:\windows\system32\drivers\SET11.tmp
c:\windows\system32\drivers\SET12.tmp
c:\windows\system32\drivers\SET14.tmp
c:\windows\system32\drivers\SET15.tmp
c:\windows\system32\drivers\SET16.tmp
c:\windows\system32\drivers\SET18.tmp
c:\windows\system32\drivers\SET1A.tmp
c:\windows\system32\drivers\SET1FC.tmp
c:\windows\system32\drivers\SET200.tmp
c:\windows\system32\drivers\SET207.tmp
c:\windows\system32\drivers\SET20B.tmp
c:\windows\system32\drivers\SET20F.tmp
c:\windows\system32\drivers\SET213.tmp
c:\windows\system32\drivers\SET217.tmp
c:\windows\system32\drivers\SET56.tmp
c:\windows\system32\drivers\SET5A.tmp
c:\windows\system32\drivers\SET5E.tmp
c:\windows\system32\drivers\SET62.tmp
c:\windows\system32\drivers\SET66.tmp
c:\windows\system32\drivers\SET6A.tmp
c:\windows\system32\drivers\SET6E.tmp
c:\windows\system32\drivers\SET72.tmp
c:\windows\system32\drivers\SET76.tmp
c:\windows\system32\drivers\SET7A.tmp
c:\windows\system32\drivers\SETAB.tmp
c:\windows\system32\drivers\SETAF.tmp
c:\windows\system32\drivers\SETC.tmp
c:\windows\system32\drivers\SETE.tmp
c:\windows\system32\drivers\SETF.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\hpqEmlSz.INI
c:\windows\system32\
01.tmp
c:\windows\system32\bxnykdg.dll
c:\windows\system32\drivers\SET11.tmp
c:\windows\system32\drivers\SET12.tmp
c:\windows\system32\drivers\SET14.tmp
c:\windows\system32\drivers\SET15.tmp
c:\windows\system32\drivers\SET16.tmp
c:\windows\system32\drivers\SET18.tmp
c:\windows\system32\drivers\SET1A.tmp
c:\windows\system32\drivers\SET1FC.tmp
c:\windows\system32\drivers\SET200.tmp
c:\windows\system32\drivers\SET207.tmp
c:\windows\system32\drivers\SET20B.tmp
c:\windows\system32\drivers\SET20F.tmp
c:\windows\system32\drivers\SET213.tmp
c:\windows\system32\drivers\SET217.tmp
c:\windows\system32\drivers\SET56.tmp
c:\windows\system32\drivers\SET5A.tmp
c:\windows\system32\drivers\SET5E.tmp
c:\windows\system32\drivers\SET62.tmp
c:\windows\system32\drivers\SET66.tmp
c:\windows\system32\drivers\SET6A.tmp
c:\windows\system32\drivers\SET6E.tmp
c:\windows\system32\drivers\SET72.tmp
c:\windows\system32\drivers\SET76.tmp
c:\windows\system32\drivers\SET7A.tmp
c:\windows\system32\drivers\SETAB.tmp
c:\windows\system32\drivers\SETAF.tmp
c:\windows\system32\drivers\SETC.tmp
c:\windows\system32\drivers\SETE.tmp
c:\windows\system32\drivers\SETF.tmp
c:\windows\system32\fddeca8_z.dll
W:\autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WOWUWCBOE
-------\Legacy_XZEMGOX
-------\Service_wowuwcboe
-------\Service_xzemgox
((((((((((((((((((((((((( Files Created from 2008-12-03 to 2009-01-03 )))))))))))))))))))))))))))))))
.
2009-01-03 14:38 . 2009-01-03 14:38 <DIR> d-------- c:\windows\ERUNT
2009-01-03 14:35 . 2009-01-03 15:28 <DIR> d-------- C:\SDFix
2008-12-29 19:49 . 2008-03-05 15:56 3,786,760 --a------ c:\windows\system32\D3DX9_37.dll
2008-12-29 19:49 . 2007-10-12 15:14 3,734,536 --a------ c:\windows\system32\d3dx9_36.dll
2008-12-29 19:49 . 2008-03-05 15:56 1,420,824 --a------ c:\windows\system32\D3DCompiler_37.dll
2008-12-29 19:49 . 2007-10-12 15:14 1,374,232 --a------ c:\windows\system32\D3DCompiler_36.dll
2008-12-29 19:49 . 2008-03-05 16:03 479,752 --a------ c:\windows\system32\XAudio2_0.dll
2008-12-29 19:49 . 2008-02-05 23:07 462,864 --a------ c:\windows\system32\d3dx10_37.dll
2008-12-29 19:49 . 2007-10-02 09:56 444,776 --a------ c:\windows\system32\d3dx10_36.dll
2008-12-29 19:49 . 2007-10-22 03:39 267,272 --a------ c:\windows\system32\xactengine2_10.dll
2008-12-29 19:49 . 2008-03-05 16:03 238,088 --a------ c:\windows\system32\xactengine3_0.dll
2008-12-29 19:49 . 2008-03-05 16:00 25,608 --a------ c:\windows\system32\X3DAudio1_3.dll
2008-12-29 16:53 . 2008-12-29 16:53 367,612 --a------ c:\windows\Freedom Fighters Eltávolító.exe
2008-12-29 11:03 . 2008-12-29 11:03 <DIR> dr-h----- c:\documents and settings\Gergely\Application Data\SecuROM
2008-12-29 11:03 . 2008-12-29 11:03 98,304 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-29 02:52 . 2008-12-29 02:52 <DIR> d-------- c:\documents and settings\Gergely\Application Data\ImgBurn
2008-12-29 02:51 . 2008-12-29 02:51 <DIR> d-------- c:\program files\ImgBurn
2008-12-29 01:21 . 2008-12-29 02:45 <DIR> d-------- c:\program files\DAEMON Tools Pro
2008-12-29 01:21 . 2008-12-29 01:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2008-12-28 13:54 . 2008-12-28 13:54 159,483 --a------ c:\windows\EASEUS Partition Manager Personal v1.6.4 Uninstaller.exe
2008-12-28 13:53 . 2008-06-19 11:45 817,152 -ra------ c:\windows\system32\bootman.exe
2008-12-28 13:45 . 2008-12-28 13:46 <DIR> d-------- c:\program files\CPU Speed Pro
2008-12-28 13:12 . 2008-12-29 02:18 <DIR> d-------- c:\documents and settings\Gergely\Application Data\DAEMON Tools Pro
2008-12-28 01:25 . 2008-12-28 01:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\WEBREG
2008-12-28 01:05 . 2008-12-28 01:37 <DIR> d-------- c:\documents and settings\Gergely\Application Data\HP
2008-12-28 01:04 . 2007-10-30 10:25 49,920 -ra------ c:\windows\system32\drivers\HPZid412.sys
2008-12-28 01:04 . 2007-10-30 10:25 16,496 -ra------ c:\windows\system32\drivers\HPZipr12.sys
2008-12-28 01:03 . 2008-12-28 01:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-28 01:03 . 2007-10-30 10:11 581,632 -ra------ c:\windows\system32\hpotscl6.dll
2008-12-28 01:03 . 2007-10-30 10:25 372,736 -ra------ c:\windows\system32\hppldcoi.dll
2008-12-28 01:03 . 2007-10-30 10:25 309,760 -ra------ c:\windows\system32\difxapi.dll
2008-12-28 01:03 . 2007-10-30 10:11 303,104 -ra------ c:\windows\system32\hpovst15.dll
2008-12-28 01:03 . 2007-11-08 15:52 271,704 -ra------ c:\windows\system32\hpzids01.dll
2008-12-28 01:03 . 2007-10-20 18:25 117,760 --a------ c:\windows\system32\hpzll5mu.dll
2008-12-28 01:03 . 2007-10-30 10:25 21,568 -ra------ c:\windows\system32\drivers\HPZius12.sys
2008-12-28 00:53 . 2008-12-28 00:53 <DIR> d-------- c:\program files\Hewlett-Packard
2008-12-28 00:53 . 2008-12-28 00:53 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2008-12-28 00:53 . 2008-12-28 00:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-28 00:53 . 2008-12-28 01:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\HP
2008-12-28 00:52 . 2008-12-28 00:52 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-12-28 00:52 . 2008-12-28 00:52 <DIR> d-------- c:\program files\Common Files\HP
2008-12-28 00:51 . 2008-12-28 01:04 <DIR> d-------- c:\program files\HP
2008-12-28 00:38 . 2008-12-28 01:05 177,582 --a------ c:\windows\hpoins27.dat
2008-12-28 00:38 . 2008-01-18 16:56 932 --------- c:\windows\hpomdl27.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-03 14:09 --------- d-----w c:\program files\Common Files\Panda Software
2008-12-29 18:57 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-29 02:02 --------- d-----w c:\program files\MoBiMouse
2008-12-29 00:12 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-12-28 22:56 --------- d-----w c:\program files\Unlocker
2008-12-28 22:56 --------- d-----w c:\program files\Lexmark 3300 Series
2008-12-28 22:56 --------- d-----w c:\program files\DAEMON Tools
2008-12-28 12:53 --------- d-----w c:\program files\EASEUS
2008-12-28 09:19 --------- d-----w c:\program files\VoipCheapCom
2008-12-14 14:20 --------- d-----w c:\program files\Lx_cats
2008-12-01 22:13 3,452,928 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2008-12-01 20:51 318,464 ------w c:\windows\system32\ati2dvag.dll
2008-12-01 20:27 4,120,384 ------w c:\windows\system32\ati3duag.dll
2008-12-01 20:11 2,495,360 ------w c:\windows\system32\ativvaxx.dll
2008-12-01 19:45 577,536 ------w c:\windows\system32\ati2cqag.dll
2008-11-08 20:20 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-08 20:08 --------- d-----w c:\program files\Common Files\Adobe
2008-11-08 19:48 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-04-24 10:07 47,360 ----a-w c:\documents and settings\Gergely\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@2009-01-02_23.02.01.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 14:27:04 163,328 ----a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2009-01-03 14:19:15 5,873,664 ----a-w c:\windows\ERUNT\SDFIX\Users\
00000001\ntuser.dat
+ 2009-01-03 14:19:15 147,456 ----a-w c:\windows\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-08-07 14:27:04 163,328 ----a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2009-01-03 13:38:38 5,865,472 ----a-w c:\windows\ERUNT\SDFIX_First_Run\Users\
00000001\ntuser.dat
+ 2009-01-03 13:38:38 147,456 ----a-w c:\windows\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
+ 2009-01-03 15:59:09 16,384 ----atw c:\windows\temp\Perflib_Perfdata_de4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-18 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-17 1667584]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2008-10-09 200136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2002-10-11 98304]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"VC5Player"="c:\program files\HHVcdV5Sys\VC5Play.exe" [2003-11-07 176128]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-30 2595616]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-30 909208]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-10-30 140568]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-05-06 6656]
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe" [2005-07-21 192512]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"HTpatch"="c:\windows\htpatch.exe" [2002-10-30 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
c:\documents and settings\All Users\Start Menu\Programs\Indˇt˘pult\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-04-19 167936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.divx"= c:\progra~1\ACEMEG~1\SystemS\DivX\DivX520.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0autocheck j
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\InterVideo\\DVD5\\WinDVD.exe"=
"p:\\Panzer Elite Action\\Panzer Elite Action\\pea.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\rserver30\\rserver3.exe"=
"c:\\Program Files\\VoipCheapCom\\VoipCheapCom.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8135:TCP"= 8135:TCP:WWW
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2008-04-20 38432]
R1 raddrvv3;raddrvv3;\??\c:\windows\system32\rserver30\raddrvv3.sys [2008-04-24 45848]
R1 vbev5mp;vbev5mp;c:\windows\system32\DRIVERS\vbev5mp.sys [2003-11-12 56064]
R2 NwSapAgent;SAP-ügynök;c:\windows\system32\svchost.exe -k netsvcs [2004-08-18 14336]
R2 RServer3;Radmin Server V3;"c:\windows\system32\rserver30\RServer3.exe" /service [2008-04-24 1238344]
R3 mirrorv3;mirrorv3;c:\windows\system32\DRIVERS\rminiv3.sys [2006-11-01 3328]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys []
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys []
S3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\PavTPK.sys []
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2002-01-02 356920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Gergely\Application Data\Mozilla\Firefox\Profiles\3juam6go.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\program files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-03 17:00:32
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HTpatch = c:\windows\htpatch.exe?ows\CurrentVersion\Run???\???/??[?????? [?? [???????????????????[???[?????? [$??????[????????????S??[????????m??[???w????(???{??w???w???????w???w???[????????d???b6?[%??[?? [????"??[A??[???[.??wZ??[?3?[?3?[????st.I???????[????d???0=?[?K?[
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vbev5mp]
"ImagePath"="system32\DRIVERS\vbev5mp.sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1844237615-1958367476-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*NULL*]
"??"=hex:b7,2a,63,24,0e,d5,36,62,cc,86,07,07,f8,7c,b7,08,d8,5f,40,d2,0e,29,7a,\
d1,34,c6,9c,00,60,81,60,5c,6d,1f,90,60,c6,7d,80,12,9c,8d,d4,db,41,59,55,68,\
b4,75,81,c4,c7,53,82,4f,20,58,99,65,fd,85,fd,53,28,6a,5c,bf,d9,ef,0d,33,8c,\
a9,64,3c,c9,1a,d7,ea,a2,90,a7,e0,cc,f2,8d,9a,53,fa,fe,10,4b,39,7f,99,1f,7a,\
b7,23,c1,45,4d,84,33,37,6b,16,f1,55,f9,3f,21,b5,07,5c,f5,b8,1a,2b,20,d8,91,\
b6,73,f3,bd,3e,45,b3,4e,a5,24,1f,31,1c,9a,29,fe,86,85,2c,db,87,36,9b,91,28,\
25,80,28,49,d1,fe,25,12,42,0f,91,fc,36,40,18,9d,c3,a0,7f,5b,d0,68,a2,59,f3,\
40,7c,4a,a7,98,1c,53,9d,38,c4,ba,77,7f,a2,79,25,87,58,92,2c,0e,d1,c6,9b,9f,\
c5,a7,8a,d3,f9,42,12,52,d0,e1,a7,8c,1d,b3,9f,10,f4,1b,2d,96,ee,38,f9,fb,15,\
66,2a,8b,7b,90,ae,56,b1,b7,bd,fc,0b,b4,1e,eb,e4,04,d7,cb,53,11,a7,b2,27,2a,\
3d,f5,71,03,06,b6,04,31,bf,33,42,8a,b2,4c,27,13,c4,18,f5,d6,12,9b,ad,a9,dd,\
4a,ab,ba,32,c8,33,e3,1c,61,5a,30,99,c1,84,6d,cd,8a,82,78,d5,07,b6,b2,da,de,\
9a,e7,49,d4,ce,b8,eb,b0,8f,37,9d,3d,73,f5,38,dc,a4,68,48,ee,d0,c8,75,26,d4,\
33,51,79,df,de,fe,47,4b,0c,d8,85,9e,27,10,4c,23,7a,3c,85,4e,5c,5a,ee,24,15,\
23,92,89,4d,9a,d1,db,d0,0c,ad,54,80,bb,13,48,9c,14,65,b7,6e,fe,4a,04,b2,48,\
bc,fe,f9,5b,ef,20,1a,73,f2,75,89,f2,be,fe,a8,7a,0a,ec,9d,90,11,9d,de,38,0b,\
d4,a0,2f,92,80,6c,c4,96,2b,d5,0a,3c,78,fb,02,a9,56,6d,48,f6,8a,e7,57,9b,e4,\
40,46,f3,5e,4f,01,8d,4f,b3,0b,22,ac,65,0b,22,a4,9d,1b,22,bc,a5
"??"=hex:e8,8c,76,e7,fa,c0,de,e5,9d,3d,74,3d,82,01,0d,02
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1020)
c:\windows\system32\relog_ap.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alcohol Soft\Alcohol 120\Alcohol.exe
c:\windows\system32\rundll32.exe
c:\program files\Virtual CD v5\System\VC5Tray.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\rserver30\FamItrfc.Exe
c:\windows\system32\wdfmgr.exe
c:\program files\HHVcdV5Sys\VC5SecS.exe
c:\windows\system32\lxcccoms.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2009-01-03 17:01:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-03 16:01:56
ComboFix2.txt 2009-01-03 14:40:28
ComboFix3.txt 2009-01-02 22:04:21
Pre-Run: 18 568 126 464 bájt szabad
Post-Run: 18,560,253,952 bájt szabad
307