Itt az eredményem:
ComboFix 09-01-12.04 - Krati 2009-01-14 20:29:06.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.2047.1624 [GMT 1:00]
Running from: d:\krati\Programok\Vírusirtás lépések\1. lépés\ComboFix.exe
Command switches used :: c:\documents and settings\Krati\Asztal\CFScript.txt
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Outdated)
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
d:\resycled\boot.com
f:\resycled\boot.com
g:\resycled\boot.com
.
((((((((((((((((((((((((( Files Created from 2008-12-14 to 2009-01-14 )))))))))))))))))))))))))))))))
.
2009-01-13 17:21 . 2001-10-26 20:25 899,402 --a--c--- c:\windows\system32\dllcache\r2mdkxga.sys
2009-01-13 17:20 . 2001-08-17 22:05 351,616 --a--c--- c:\windows\system32\dllcache\ovcodek2.sys
2009-01-13 17:19 . 2001-08-17 21:28 802,683 --a--c--- c:\windows\system32\dllcache\ltsm.sys
2009-01-13 17:18 . 2001-10-26 21:24 1,733,120 --a--c--- c:\windows\system32\dllcache\g400d.dll
2009-01-13 17:17 . 2001-10-26 18:57 980,034 --a--c--- c:\windows\system32\dllcache\cicap.sys
2009-01-13 17:16 . 2001-08-17 21:28 871,388 --a--c--- c:\windows\system32\dllcache\bcmdm.sys
2009-01-13 17:15 . 2001-08-17 21:28 762,780 --a--c--- c:\windows\system32\dllcache\3cwmcru.sys
2009-01-13 17:14 . 2001-10-26 21:24 66,048 --a--c--- c:\windows\system32\dllcache\s3legacy.dll
2009-01-13 15:30 . 2009-01-13 15:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-01-07 17:06 . 2009-01-07 17:06 <DIR> d-------- c:\documents and settings\Krati\WINDOWS
2009-01-07 16:56 . 2009-01-07 16:58 <DIR> d-------- c:\program files\Runtime Software
2009-01-02 12:00 . 2009-01-02 12:00 7,680 --a------ C:\AssistentGraph.grf
2009-01-02 11:56 . 1995-05-05 10:50 14,025 --------- c:\windows\TWAINCAP.INI
2009-01-02 11:56 . 1997-06-11 08:02 5,526 --------- c:\windows\TWAINCAP.SRC
2009-01-02 10:28 . 2008-04-14 18:01 363,520 --a------ c:\windows\system32\PsisDecd.dll
2009-01-02 10:28 . 2008-04-14 18:01 363,520 --a--c--- c:\windows\system32\dllcache\psisdecd.dll
2009-01-02 10:28 . 2008-04-14 18:02 56,832 --a------ c:\windows\system32\MSDvbNP.ax
2009-01-02 10:28 . 2008-04-14 18:02 56,832 --a--c--- c:\windows\system32\dllcache\msdvbnp.ax
2009-01-02 10:28 . 2008-04-14 18:02 33,280 --a------ c:\windows\system32\PsisRndr.ax
2009-01-02 10:28 . 2008-04-14 18:02 33,280 --a--c--- c:\windows\system32\dllcache\psisrndr.ax
2009-01-02 10:28 . 2008-04-14 18:02 18,432 --a--c--- c:\windows\system32\dllcache\bdaplgin.ax
2009-01-02 10:28 . 2008-04-14 18:02 18,432 --a------ c:\windows\system32\BdaPlgIn.ax
2009-01-02 10:28 . 2008-04-13 20:46 15,232 --a------ c:\windows\system32\drivers\MPE.sys
2009-01-02 10:28 . 2008-04-13 20:46 15,232 --a--c--- c:\windows\system32\dllcache\mpe.sys
2009-01-02 10:28 . 2008-04-13 20:46 11,776 --a------ c:\windows\system32\drivers\BdaSup.sys
2009-01-02 10:28 . 2008-04-13 20:46 11,776 --a--c--- c:\windows\system32\dllcache\bdasup.sys
2008-12-16 10:02 . 2008-12-16 10:02 <DIR> d-------- c:\documents and settings\Krati\Application Data\Ulead Systems
2008-12-16 09:56 . 2008-12-16 09:56 <DIR> d-------- c:\program files\Windows Media Components
2008-12-16 09:56 . 2008-12-16 09:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2008-12-16 09:55 . 2008-12-16 09:55 <DIR> d-------- c:\program files\Ulead Systems
2008-12-16 09:55 . 2008-12-16 09:56 <DIR> d-------- c:\program files\Common Files\Ulead Systems
2008-12-16 09:55 . 2008-12-16 10:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ulead Systems
2008-12-16 09:55 . 2005-06-10 10:43 73,728 --a------ c:\windows\system32\ISUSPM.cpl
2008-12-16 09:50 . 2008-12-16 09:50 <DIR> d-------- c:\program files\Nokia
2008-12-16 09:50 . 2008-12-16 09:53 <DIR> d-------- c:\program files\Common Files\PCSuite
2008-12-16 09:50 . 2008-12-16 09:51 <DIR> d-------- c:\documents and settings\Krati\Application Data\PC Suite
2008-12-16 09:50 . 2008-12-16 09:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Suite
2008-12-16 09:50 . 2006-05-29 08:26 127,488 --a------ c:\windows\system32\drivers\nmwcd.sys
2008-12-16 09:50 . 2006-05-29 08:26 50,688 --a------ c:\windows\system32\nmwcdcls.dll
2008-12-16 09:50 . 2006-05-29 08:26 30,720 --a------ c:\windows\system32\nmwcdcocls.dll
2008-12-16 09:50 . 2006-05-29 08:26 13,312 --a------ c:\windows\system32\drivers\nmwcdcm.sys
2008-12-16 09:50 . 2006-05-29 08:26 8,704 --a------ c:\windows\system32\drivers\nmwcdc.sys
2008-12-16 09:50 . 2006-05-29 08:26 4,608 --a------ c:\windows\system32\nmwcdlog.dll
2008-12-16 09:49 . 2008-12-16 09:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-14 19:12 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-14 18:30 --------- d-----w c:\documents and settings\Krati\Application Data\uTorrent
2009-01-13 20:32 --------- d-----w c:\documents and settings\Krati\Application Data\Xfire
2009-01-13 18:24 137,688 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-01-09 13:54 --------- d-----w c:\program files\Xfire
2009-01-02 10:55 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-02 10:53 --------- d-----w c:\program files\Pinnacle
2008-12-16 08:55 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-11-26 08:51 --------- d-----w c:\program files\Java
2008-11-26 08:50 --------- d-----w c:\program files\Common Files\Java
2008-11-25 11:47 --------- d-----w c:\program files\PicLensIE
2008-11-23 08:45 22,328 -c--a-w c:\documents and settings\Krati\Application Data\PnkBstrK.sys
2008-11-23 08:28 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-23 08:28 --------- d-----w c:\program files\AGEIA Technologies
2008-11-20 12:03 --------- d-----w c:\program files\Google
2008-04-14 13:58 56 -csh--r c:\windows\system32\A2A18710D4.sys
2008-04-14 13:58 1,682 -csha-w c:\windows\system32\KGyGaAvL.sys
2008-09-09 15:54 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090920080910\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-13_18.09.19.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-12 08:44:23 593,920 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-01-14 04:11:08 593,920 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-12-12 08:44:23 12,288 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-01-14 04:11:08 12,288 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-12-12 08:44:23 86,016 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-01-14 04:11:08 86,016 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-12-12 08:44:23 135,168 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-01-14 04:11:08 135,168 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-12-12 08:44:24 11,264 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-01-14 04:11:09 11,264 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-12-12 08:44:24 27,136 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-01-14 04:11:09 27,136 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-12-12 08:44:24 4,096 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-01-14 04:11:09 4,096 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-12-12 08:44:24 794,624 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-01-14 04:11:09 794,624 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-12-12 08:44:23 249,856 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2009-01-14 04:11:08 249,856 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-12-12 08:44:23 61,440 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2009-01-14 04:11:08 61,440 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-12-12 08:44:24 23,040 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-01-14 04:11:09 23,040 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-12-12 08:44:23 286,720 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-01-14 04:11:08 286,720 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-12-12 08:44:23 409,600 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-01-14 04:11:08 409,600 ----a-r c:\windows\Installer\{9011040E-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-09-08 10:41:42 333,824 -c--a-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 10:57:09 333,952 -c--a-w c:\windows\system32\dllcache\srv.sys
- 2008-12-09 23:24:37 17,593,280 ----a-w c:\windows\system32\MRT.exe
+ 2009-01-10 01:35:28 20,853,704 ----a-w c:\windows\system32\MRT.exe
- 2009-01-13 16:57:57 202,040 ----a-w c:\windows\system32\PnkBstrB.exe
+ 2009-01-13 18:24:02 202,040 ----a-w c:\windows\system32\PnkBstrB.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-06 707360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 1447168]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Indˇt˘pult\
Pinnacle Scheduler.lnk - c:\program files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe [2009-01-02 245760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.ffds"= c:\program files\ffdshow\ffdshow.ax
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\mpegacm.acm
"VIDC.PIM1"= PCLEPIM1.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Indítópult^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Indítópult\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Indítópult^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Indítópult\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-10-23 14:18 202024 c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
--a------ 2007-01-13 02:48 275800 c:\program files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 17:02 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a--c--- 2007-09-20 08:51 1836328 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2007-03-01 14:57 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-10-07 13:33 13574144 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a--c--- 2004-11-02 20:24 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-06-03 03:52 36975 c:\program files\Java\jre1.5.0_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-10-12 07:28 39408 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
--a------ 2006-12-06 00:38 707360 c:\windows\vVX1000.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"d:\\Krati\\Programok\\Dc++\\Strongdc++\\StrongDC.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"d:\\Games\\Cod4\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1417:UDP"= 1417:UDP:1417
"1417:TCP"= 1417:TCP:1417
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [2008-01-22 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [2008-01-22 5504]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-06-10 34312]
R3 3xHybrid;Pinnacle PCTV Stereo service;c:\windows\system32\drivers\3xHybrid.sys [2004-11-22 556416]
R3 pctvvbi;PCTVVBI;c:\windows\system32\drivers\pctvvbi.sys [2009-01-02 6400]
R4 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-06-10 468224]
S4 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2001-10-26 3584]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-14 20:32:25
Windows 5.1.2600 Szervizcsomag 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1177238915-602609370-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:24,eb,9d,f6,b9,ff,23,82,b0,0d,fe,fb,b9,eb,4c,60,15,56,20,1f,fa,
39,f2,84,65,cd,72,8a,12,80,43,7e,8c,0b,dc,6c,eb,c2,2c,6b,5f,5b,59,8c,bd,ea,\
"rkeysecu"=hex:84,84,17,95,a7,40,b7,7c,dd,1b,ee,be,9f,7b,1b,90
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,09,f7,d5,61,04,
b1,04,1d,e2,63,26,f1,3f,c8,ff,68,40,1a,53,62,0b,d1,48,88,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,b0,62,05,71,36,
c3,f9,cd,6a,9c,d6,61,af,45,84,18,92,9e,2f,ff,35,78,73,01,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,e8,4f,da,c6,70,
7f,0c,91,ff,7c,85,e0,43,d4,0e,fe,34,3b,07,ba,62,58,84,b7,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:6b,65,49,6a,7e,99,74,f7,4d,d3,46,2e,b9,
a8,4c,f8,86,8c,21,01,be,91,eb,e7,8c,0c,41,b0,24,78,33,8f,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,bf,85,26,f7,1d,
bc,20,5a,f5,1d,4d,73,a8,13,5c,05,87,8e,2a,c0,3a,5e,96,38,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,20,a4,20,9b,85,
f4,37,03,df,20,58,62,78,6b,cf,c8,57,a1,11,dd,7c,d5,c4,bc,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,f2,fd,f5,7f,1d,
c5,e5,3f,fb,a7,78,e6,12,2f,9a,ea,b5,43,38,1a,67,19,c4,79,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,d4,b8,2c,9f,dd,
29,8a,a1,01,3a,48,fc,e8,04,4a,f1,29,23,55,55,75,f8,87,90,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,53,8c,44,0b,e9,
5f,38,e1,f6,0f,4e,58,98,5b,89,c9,8b,7a,44,c1,16,20,c3,b5,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,79,0c,16,85,eb,
50,99,08,3d,ce,ea,26,2d,45,aa,78,46,e5,1c,69,4b,ec,d0,af,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,6e,2e,bf,a7,23,
bb,03,21,2a,b7,cc,b5,b9,7f,41,e7,1d,75,ea,76,00,c9,bb,00,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,74,3e,3b,99,3a,
47,73,98,6c,43,2d,1e,aa,22,2f,9c,df,da,61,9c,b5,a9,f8,f9,6c,43,2d,1e,aa,22,\
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
.
**************************************************************************
.
Completion time: 2009-01-14 20:34:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-14 19:34:02
ComboFix2.txt 2009-01-13 17:10:09
Pre-Run: 1 648 095 232 bájt szabad
Post-Run: 1,633,431,552 bájt szabad
308 --- E O F --- 2009-01-14 04:11:10