ComboFix 09-01-09.03 - Lion 2009-01-10 16:22:26.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1029.18.3069.2232 [GMT 1:00]
Spuštěný z: c:\users\Lion\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((( Soubory vytvořené od 2008-12-10 do 2009-01-10 )))))))))))))))))))))))))))))))
.
2009-01-10 13:57 . 2009-01-10 13:57 <DIR> d-------- c:\program files\Trend Micro
2009-01-07 14:42 . 2009-01-07 19:02 0 --a------ c:\windows\System32\
0A6DD.tmp
2009-01-06 18:11 . 2008-12-10 16:37 135,680 --a------ c:\windows\System32\drivers\Rtlh86.sys
2009-01-06 18:11 . 2008-12-02 13:37 10,240 --a------ c:\windows\System32\RtNicProp32.dll
2009-01-06 16:06 . 2009-01-06 16:15 <DIR> d-------- c:\users\Lion\AppData\Roaming\Hamachi
2009-01-06 16:06 . 2009-01-06 16:06 25,280 --a------ c:\windows\System32\drivers\hamachi.sys
2009-01-06 10:02 . 2008-11-17 07:40 3,668,480 --a------ c:\windows\System32\drivers\NETw5v32.sys
2009-01-06 10:02 . 2008-06-20 09:33 2,756,608 --a------ c:\windows\System32\NETw5r32.dll
2009-01-06 10:02 . 2008-06-20 09:32 663,552 --a------ c:\windows\System32\NETw5c32.dll
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d----c--- c:\windows\System32\DRVSTORE
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\users\Lion\AppData\Roaming\Apple Computer
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\users\All Users\Apple Computer
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\programdata\Apple Computer
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\program files\QuickTime
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\program files\iTunes
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\program files\iPod
2009-01-05 22:46 . 2009-01-05 22:46 <DIR> d-------- c:\program files\Bonjour
2009-01-05 22:46 . 2008-04-17 13:12 107,368 --a------ c:\windows\System32\GEARAspi.dll
2009-01-05 22:46 . 2008-04-17 13:12 15,464 --a------ c:\windows\System32\drivers\GEARAspiWDM.sys
2009-01-05 22:44 . 2009-01-05 22:46 <DIR> d-------- c:\program files\Common Files\Apple
2009-01-05 22:44 . 2009-01-05 22:44 <DIR> d-------- c:\program files\Apple Software Update
2009-01-05 22:13 . 2009-01-07 19:03 0 --a------ c:\windows\System32\
0E1ED.tmp
2009-01-04 13:45 . 2009-01-04 13:45 <DIR> d-------- c:\windows\Sun
2009-01-03 00:07 . 2009-01-03 00:07 <DIR> d-------- c:\program files\Toshiba
2009-01-02 16:04 . 2009-01-02 16:04 <DIR> d--h----- c:\users\All Users\CanonBJ
2009-01-02 16:04 . 2009-01-02 16:04 <DIR> d--h----- c:\programdata\CanonBJ
2009-01-02 16:03 . 2006-11-05 20:00 198,656 --a------ c:\windows\System32\CNMLM8O.DLL
2008-12-30 13:33 . 2009-01-10 10:20 31,776 --a------ c:\users\All Users\nvModes.dat
2008-12-30 13:33 . 2009-01-10 10:20 31,776 --a------ c:\programdata\nvModes.dat
2008-12-30 13:31 . 2008-12-08 17:42 1,108,512 --a------ c:\windows\System32\nvcpluir.dll
2008-12-30 13:31 . 2008-12-08 17:42 797,216 --a------ c:\windows\System32\nvcplui.exe
2008-12-30 13:31 . 2008-12-08 17:42 420,384 --a------ c:\windows\System32\nvcpl.cpl
2008-12-30 13:22 . 2008-12-30 13:22 <DIR> d-------- C:\NVIDIA
2008-12-30 13:22 . 2008-12-16 22:07 453,152 --a------ c:\windows\System32\NVUNINST.EXE
2008-12-30 00:05 . 2008-12-30 00:05 <DIR> d-------- c:\program files\MobilityDotNETnV
2008-12-27 21:45 . 2007-11-02 04:30 7,630,272 --a------ c:\windows\System32\nvlddmkm.sys
2008-12-27 21:45 . 2007-11-02 04:30 3,872,559 --a------ c:\windows\System32\nvlddmkm.sy_
2008-12-27 21:29 . 2007-11-02 04:30 795,104 --a------ c:\windows\System32\dpinst.exe
2008-12-27 21:29 . 2007-11-02 04:30 36,864 --a------ c:\windows\System32\nvcod100.dll
2008-12-26 15:53 . 2008-12-26 15:53 <DIR> dr------- c:\windows\System32\config\systemprofile\Music
2008-12-26 13:55 . 2008-12-26 13:55 <DIR> d-------- c:\program files\MSI
2008-12-25 14:19 . 2008-12-25 14:19 98,304 ---hs---- c:\windows\System32\rzr-c5kg.exe
2008-12-24 22:37 . 2009-01-10 15:57 69 --a------ c:\windows\NeroDigital.ini
2008-12-23 11:29 . 2008-12-23 11:29 <DIR> d-------- C:\OscarData
2008-12-23 11:28 . 2008-12-23 22:52 <DIR> d-------- c:\program files\OSCAR Editor
2008-12-23 11:27 . 2008-12-23 11:27 <DIR> d-------- C:\Oscar
2008-12-22 14:00 . 2008-12-22 14:00 0 --a------ c:\windows\tosOBEX.INI
2008-12-22 13:40 . 2008-12-26 13:53 <DIR> d-------- c:\program files\Setup Files
2008-12-22 13:34 . 1998-10-02 19:00 327,168 --a------ c:\windows\IsUninst.exe
2008-12-22 11:17 . 2007-07-26 17:09 520,192 --a------ c:\windows\RtlExUpd.dll
2008-12-22 09:54 . 2008-08-05 10:49 428,544 --a------ c:\windows\System32\EncDec.dll
2008-12-22 09:54 . 2008-08-05 10:49 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-12-22 09:54 . 2008-08-05 10:48 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-12-22 09:54 . 2008-08-05 10:48 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-12-22 09:54 . 2008-08-05 10:48 80,896 --a------ c:\windows\System32\MSNP.ax
2008-12-22 09:54 . 2008-04-23 05:41 57,856 --a------ c:\windows\System32\MSDvbNP.ax
2008-12-22 02:03 . 2008-10-21 06:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-12-22 02:03 . 2008-08-28 04:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-12-22 02:03 . 2008-08-28 04:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-12-22 02:03 . 2008-08-28 04:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-12-22 02:03 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-12-22 02:03 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-12-22 02:02 . 2008-10-22 04:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-12-18 23:48 . 2008-12-18 23:54 <DIR> d-------- c:\program files\Prime95
2008-12-18 22:35 . 2009-01-10 10:20 65,536 --------- c:\windows\System32\Ikeext.etl
2008-12-18 03:00 . 2008-10-02 02:32 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2008-12-17 15:10 . 2007-06-20 12:21 7,563,744 --a------ c:\windows\System32\drivers\nvlddmkm.sys.old
2008-12-17 01:23 . 2008-12-17 01:23 <DIR> d-------- C:\Vista_Dox_18084
2008-12-17 01:23 . 2008-12-02 11:11 1,253,376 --a------ c:\windows\System32\NvPVEnc.ax
2008-12-17 01:23 . 2008-12-02 11:11 4,160 --a------ c:\windows\System32\drivers\nvBridge.kmd
2008-12-16 20:45 . 2008-12-16 20:46 <DIR> d-------- c:\program files\SystemRequirementsLab
2008-12-16 20:44 . 2008-12-16 20:45 <DIR> d-------- c:\users\Lion\SystemRequirementsLab
2008-12-16 18:48 . 2008-06-26 02:45 12,240,896 --a------ c:\windows\System32\NlsLexicons0007.dll
2008-12-16 18:48 . 2008-06-26 02:45 2,644,480 --a------ c:\windows\System32\NlsLexicons0009.dll
2008-12-16 18:48 . 2008-06-26 04:29 801,280 --a------ c:\windows\System32\NaturalLanguage6.dll
2008-12-16 03:08 . 2008-10-22 02:22 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-15 21:52 . 2008-04-26 09:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2008-12-15 21:52 . 2008-04-12 04:32 784,896 --a------ c:\windows\System32\rpcrt4.dll
2008-12-15 21:52 . 2008-06-19 04:31 361,984 --a------ c:\windows\System32\IPSECSVC.DLL
2008-12-15 21:52 . 2008-10-21 06:25 296,960 --a------ c:\windows\System32\gdi32.dll
2008-12-15 21:52 . 2008-04-05 02:21 72,192 --a------ c:\windows\System32\drivers\pacer.sys
2008-12-15 21:52 . 2008-04-05 04:34 15,360 --a------ c:\windows\System32\pacerprf.dll
2008-12-15 21:51 . 2008-11-01 02:21 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-15 21:51 . 2008-03-08 05:21 1,695,744 --a------ c:\windows\System32\gameux.dll
2008-12-15 21:51 . 2008-04-18 06:48 269,312 --a------ c:\windows\System32\es.dll
2008-12-15 21:51 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-12-15 21:51 . 2008-11-01 04:44 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2008-12-15 21:50 . 2008-10-29 07:29 2,927,104 --a------ c:\windows\explorer.exe
2008-12-15 21:50 . 2008-09-18 03:16 2,032,640 --a------ c:\windows\System32\win32k.sys
2008-12-15 21:50 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-12-15 21:50 . 2008-10-16 05:47 827,392 --a------ c:\windows\System32\wininet.dll
2008-12-15 21:50 . 2008-06-26 04:29 303,616 --a------ c:\windows\System32\wmpeffects.dll
2008-12-15 21:33 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-12-15 21:33 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-12-15 21:33 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-12-15 21:33 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-12-15 21:33 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-12-15 21:33 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-12-15 21:33 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll
2008-12-15 21:32 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-12-15 21:32 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-12-15 13:39 . 2008-12-15 13:39 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-12-15 09:05 . 2008-12-16 09:16 <DIR> d-------- c:\users\Lion\AppData\Roaming\.ABC
2008-12-14 22:42 . 2008-12-14 22:42 301 --a------ c:\windows\doom3.ini
2008-12-14 21:39 . 2008-12-14 21:39 <DIR> d-------- c:\program files\DOOM 3
2008-12-14 21:35 . 2008-12-14 21:35 <DIR> d-------- c:\users\Lion\AppData\Roaming\DAEMON Tools Pro
2008-12-14 21:35 . 2008-12-14 21:35 <DIR> d-------- c:\users\Lion\AppData\Roaming\DAEMON Tools
2008-12-14 21:35 . 2008-12-14 21:35 <DIR> d-------- c:\users\All Users\DAEMON Tools Lite
2008-12-14 21:35 . 2008-12-14 21:35 <DIR> d-------- c:\programdata\DAEMON Tools Lite
2008-12-14 21:34 . 2008-12-14 21:34 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-12-14 21:26 . 2008-12-14 21:26 <DIR> d-------- c:\program files\ABC
2008-12-14 21:25 . 2008-12-14 21:38 <DIR> d-------- c:\users\Lion\AppData\Roaming\DAEMON Tools Lite
2008-12-14 21:25 . 2008-12-14 21:25 717,296 --a------ c:\windows\System32\drivers\sptd.sys
2008-12-13 01:12 . 2008-12-22 11:19 <DIR> d-------- c:\windows\System32\RTCOM
2008-12-13 01:12 . 2007-08-01 16:40 2,072,064 --a------ c:\windows\System32\RtkAPO.dll
2008-12-13 01:12 . 2008-12-22 11:18 319,456 --a------ c:\windows\DIFxAPI.dll
2008-12-13 01:11 . 2008-12-13 01:11 315,392 --a------ c:\windows\HideWin.exe
2008-12-12 21:37 . 2009-01-08 23:48 279,213,258 --a------ c:\windows\MEMORY.DMP
2008-12-12 21:30 . 2008-12-12 21:34 <DIR> d-------- c:\users\Lion\AppData\Roaming\Ventrilo
2008-12-12 21:19 . 2008-12-12 21:19 <DIR> d-------- c:\program files\Ventrilo
2008-12-12 21:18 . 2008-12-12 21:18 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-12 21:14 . 2008-12-12 21:14 <DIR> d-------- c:\users\Lion\AppData\Roaming\CyberLink
2008-12-12 20:49 . 2008-12-30 13:14 27,744 --a------ c:\users\Lion\AppData\Roaming\nvModes.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-22 09:00 --------- d-----w c:\program files\Windows Mail
2008-12-11 11:43 174 --sha-w c:\program files\desktop.ini
2008-12-11 11:38 --------- d-----w c:\program files\Windows Sidebar
2008-12-11 11:38 --------- d-----w c:\program files\Windows Photo Gallery
2008-12-11 11:38 --------- d-----w c:\program files\Windows Journal
2008-12-11 11:38 --------- d-----w c:\program files\Windows Defender
2008-12-11 11:38 --------- d-----w c:\program files\Windows Collaboration
2008-12-11 11:38 --------- d-----w c:\program files\Windows Calendar
2008-12-11 11:29 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-12-11 11:29 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-12-11 10:26 --------- d-sh--w c:\programdata\Plocha
2008-12-11 10:26 --------- d-sh--w c:\programdata\Oblíbené položky
2008-12-11 10:26 --------- d-sh--w c:\programdata\Šablony
2008-12-11 10:26 --------- d-sh--w c:\programdata\Nabídka Start
2008-12-11 10:26 --------- d-sh--w c:\programdata\Dokumenty
2008-12-11 10:26 --------- d-sh--w c:\programdata\Data aplikací
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-27 09:04 70,992 ----a-w c:\windows\System32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w c:\windows\System32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w c:\windows\System32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w c:\windows\System32\X3DAudio1_5.dll
2008-10-10 03:52 452,440 ----a-w c:\windows\System32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w c:\windows\System32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w c:\windows\System32\D3DCompiler_40.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"OscarEditor"="c:\program files\OSCAR Editor\OscarEditor.exe" [2008-07-30 2865152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-12-11 949376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-08 13601312]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-08 92704]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-09 136600]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-09 c:\windows\RtHDVCpl.exe]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
aveosti.exe.lnk - c:\program files\AVEO\AVEO UVC Filter Driver Kit\AveoSTI.exe [2008-12-11 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{A5874975-7249-40C4-B52B-B2783F624F68}e:\\strongdc\\strongdc.exe"= UDP:e:\strongdc\strongdc.exe:StrongDC++
"UDP Query User{AB82419F-E2F4-48D4-AC84-FD3C85C2D2FE}e:\\strongdc\\strongdc.exe"= TCP:e:\strongdc\strongdc.exe:StrongDC++
"TCP Query User{50EE70E8-6071-4188-A1E4-10138EB13615}c:\\program files\\abc\\abc.exe"= UDP:c:\program files\abc\abc.exe:abc
"UDP Query User{46C44B82-058A-4B27-BA63-0EF64C703447}c:\\program files\\abc\\abc.exe"= TCP:c:\program files\abc\abc.exe:abc
"TCP Query User{9277AB1A-8969-4890-8F54-662BCD605740}c:\\program files\\qip\\qip.exe"= UDP:c:\program files\qip\qip.exe:Quiet Internet Pager
"UDP Query User{31EEED8E-1623-4B67-B019-E686807FCEA1}c:\\program files\\qip\\qip.exe"= TCP:c:\program files\qip\qip.exe:Quiet Internet Pager
"{854CF371-9513-401C-A514-1F1260315AAC}"= UDP:c:\program files\WinRAR\WinRAR.exe:WinRAR
"{5D78AB85-8C7D-456B-AD0B-20F0835BBD54}"= TCP:c:\program files\WinRAR\WinRAR.exe:WinRAR
"{3CF3F25A-2360-4524-86E5-8BDC69CEF330}"= UDP:e:\cod waw 5\CoDWaW.exe:Call of Duty(R) - World at War(TM)
"{3B5E6C0C-E9D8-422B-801A-B95E02F8525A}"= TCP:e:\cod waw 5\CoDWaW.exe:Call of Duty(R) - World at War(TM)
"{6A2B1706-BB61-4372-8FBC-78935D79F31D}"= UDP:e:\cod waw 5\CoDWaWmp.exe:Call of Duty(R) - World at War(TM)
"{64D1D877-B655-46DB-8E81-884F61FBE436}"= TCP:e:\cod waw 5\CoDWaWmp.exe:Call of Duty(R) - World at War(TM)
"TCP Query User{4238D87E-72ED-4811-86C9-0E5379E72FF3}e:\\counter-strike\\hl.exe"= UDP:e:\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{8EC8D2F1-F1A0-4A37-AA80-2AF3E0C4F0B2}e:\\counter-strike\\hl.exe"= TCP:e:\counter-strike\hl.exe:Half-Life Launcher
"{12834467-81CC-49F9-938C-05136BEEFFA0}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C07BB913-1BF3-4DD2-B37F-4066E1F1DFDD}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{DFFD0F0B-CAE5-4299-B932-0F7461CD4AB1}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{E514F555-3DFD-4413-93C7-4A4739C3D49E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{8BB01CC6-12C7-4439-9358-47BBDC03100C}e:\\call of duty 2\\cod2mp_s.exe"= UDP:e:\call of duty 2\cod2mp_s.exe:CoD2MP_s
"UDP Query User{558B6660-9EBF-4B67-914E-F71BBD52D167}e:\\call of duty 2\\cod2mp_s.exe"= TCP:e:\call of duty 2\cod2mp_s.exe:CoD2MP_s
"TCP Query User{13EABDD1-AB0D-4D99-958B-4D88F3AE2441}e:\\call of duty 2\\cod2mp_s.exe"= UDP:e:\call of duty 2\cod2mp_s.exe:CoD2MP_s
"UDP Query User{728418D7-0A62-4BC8-87C9-33EB0799787D}e:\\call of duty 2\\cod2mp_s.exe"= TCP:e:\call of duty 2\cod2mp_s.exe:CoD2MP_s
"TCP Query User{7ACAA4D0-3B53-4256-90D1-1212C4BEC4D6}c:\\program files\\qip\\qip.exe"= UDP:c:\program files\qip\qip.exe:Quiet Internet Pager
"UDP Query User{FB0CB487-F0E2-4C49-87CF-0A9F33976498}c:\\program files\\qip\\qip.exe"= TCP:c:\program files\qip\qip.exe:Quiet Internet Pager
"TCP Query User{4D344646-BDDB-4B17-830B-500030C8CFF2}e:\\cod waw 5\\codwaw.exe"= UDP:e:\cod waw 5\codwaw.exe:Call of Duty(R): World at War Campaign/Coop
"UDP Query User{171494EB-7F55-4614-8618-B6B2AEB0441D}e:\\cod waw 5\\codwaw.exe"= TCP:e:\cod waw 5\codwaw.exe:Call of Duty(R): World at War Campaign/Coop
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R0 Si3531;SiI-3531 SATA Controller;c:\windows\System32\drivers\Si3531.sys [2008-07-25 212008]
R1 nod32drv;nod32drv;c:\windows\System32\drivers\nod32drv.sys [2008-12-11 15424]
R1 PSched;Plánovač paketů technologie QoS;c:\windows\System32\drivers\pacer.sys [2008-12-15 72192]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [2008-12-11 32256]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [2009-01-06 3668480]
S4 NishService;SCM Driver Daemon;c:\program files\System Control Manager\edd.exe --> c:\program files\System Control Manager\edd.exe [?]
S4 nvynfv;Installer Manager;c:\windows\system32\svchost.exe -k netsvcs [2008-12-11 21504]
S4 xiwrsoswp;Update Shell;c:\windows\system32\svchost.exe -k netsvcs [2008-12-11 21504]
--- Other Services/Drivers In Memory ---
*Deregistered* - sptd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
xiwrsoswp
nvynfv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77455045-ca1e-11dd-b86b-001d9256a9fc}]
\shell\AutoRun\command - f:\setup\rsrc\Autorun.exe
\shell\dinstall\command - f:\directx\dxsetup.exe
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-AveoKeySti - c:\program files\\AVEO\AVEO_UVC_FILTER_DRIVER_KIT\AveoSTI.exe
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\users\Lion\AppData\Roaming\Mozilla\Firefox\Profiles\nk96jp20.default\
FF - prefs.js: browser.search.selectedEngine - Vyhledávánà videà ve službě YouTube
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.cz/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-10 16:24:06
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2009-01-10 16:25:22
ComboFix-quarantined-files.txt 2009-01-10 15:25:19
Před spuštěním: Volných bajtů: 20 462 612 480
Po spuštění: Volných bajtů: 20,570,468,352
265 --- E O F --- 2009-01-06 08:56:44