ten subor oznacil jedine mcaffe:
McAfee 5.400.0.1158 2011.07.20 BackDoor-EXI!conf
log z combofixu:
ComboFix 11-07-20.05 - Doma . 07. 2011 23:21:00.6.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.3199.2812 [GMT 2:00]
Running from: C:\Documents and Settings\Doma\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\Doma\Plocha\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"C:\Documents and Settings\Doma\Local Settings\Temp\explorer.exe"
"C:\Documents and Settings\Doma\Nabídka Start\Programy\Po spuštění\license.dll"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Doma\LOCALS~1\Temp\8386345.exe
C:\Documents and Settings\Doma\Data aplikací\dwm.exe
C:\Documents and Settings\Doma\Data aplikací\Microsoft\conhost.exe
C:\Documents and Settings\Doma\Dokumenty\cc_20110720_172710.reg
C:\Microsoft
C:\Program Files\Internet Explorer\conhost.exe
C:\WINDOWS\btc_client_iplist.txt
C:\WINDOWS\ddh_iplist.txt
C:\WINDOWS\front_ip_list.txt
C:\WINDOWS\gbot111.exe
C:\WINDOWS\iecheck_iplist.txt
C:\WINDOWS\info1
C:\WINDOWS\iplist.txt
C:\WINDOWS\l1rezerv.exe
C:\WINDOWS\loader2.exe_ok
C:\WINDOWS\phoenix
C:\WINDOWS\phoenix\kernels\phatk\__init__.py
C:\WINDOWS\phoenix\kernels\phatk\__init__.pyc
C:\WINDOWS\phoenix\kernels\phatk\BFIPatcher.py
C:\WINDOWS\phoenix\kernels\phatk\kernel.cl
C:\WINDOWS\phoenix\kernels\poclbm\__init__.py
C:\WINDOWS\phoenix\kernels\poclbm\__init__.pyc
C:\WINDOWS\phoenix\kernels\poclbm\BFIPatcher.py
C:\WINDOWS\phoenix\kernels\poclbm\kernel.cl
C:\WINDOWS\phoenix\phoenix.exe
C:\WINDOWS\proc_list1.log
C:\WINDOWS\rpcminer
C:\WINDOWS\rpcminer\bitcoinminercuda_10.cubin
C:\WINDOWS\rpcminer\bitcoinminercuda_11.cubin
C:\WINDOWS\rpcminer\bitcoinminercuda_20.cubin
C:\WINDOWS\rpcminer\bitcoinmineropencl.cl
C:\WINDOWS\rpcminer\cudart32_32_16.dll
C:\WINDOWS\rpcminer\curllib.dll
C:\WINDOWS\rpcminer\libeay32.dll
C:\WINDOWS\rpcminer\libsasl.dll
C:\WINDOWS\rpcminer\openldap.dll
C:\WINDOWS\rpcminer\rpcminer-4way.exe
C:\WINDOWS\rpcminer\rpcminer-cpu.exe
C:\WINDOWS\rpcminer\rpcminer-cuda.exe
C:\WINDOWS\rpcminer\rpcminer-opencl.exe
C:\WINDOWS\rpcminer\ssleay32.dll
C:\WINDOWS\sysdriver32.exe
C:\WINDOWS\sysdriver32_.exe
C:\WINDOWS\system32\drivers\etc\HSTS~1
C:\WINDOWS\systemup.exe
C:\WINDOWS\TEMP\4075020.exe
C:\WINDOWS\ufa
C:\WINDOWS\ufa\ufa.exe
C:\WINDOWS\update.2
C:\WINDOWS\update.2\svchost.exe
C:\WINDOWS\update.5.0
C:\WINDOWS\update.5.0\svchost.exe
C:\WINDOWS\update.tray-2-0-lnk
C:\WINDOWS\update.tray-2-0-lnk\svchost.exe
C:\WINDOWS\update.tray-3-0-lnk
C:\WINDOWS\update.tray-3-0-lnk\svchost.exe
---- Previous Run -------
C:\DOCUME~1\Doma\LOCALS~1\Temp\6278303.exe
C:\Program Files\Windows NT\05E2.BA8
C:\Program Files\Windows NT\Accessories\mswrd6.wpc
C:\Program Files\Windows NT\Accessories\mswrd8.wpc
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Windows NT\Accessories\write.wpc
C:\Program Files\Windows NT\dialer.exe
C:\Program Files\Windows NT\dwm.exe
C:\Program Files\Windows NT\htrn_jis.dll
C:\Program Files\Windows NT\hypertrm.exe
C:\Program Files\Windows NT\Pinball\FONT.DAT
C:\Program Files\Windows NT\Pinball\PINBALL.DAT
C:\Program Files\Windows NT\Pinball\PINBALL.EXE
C:\Program Files\Windows NT\Pinball\PINBALL.MID
C:\Program Files\Windows NT\Pinball\PINBALL2.MID
C:\Program Files\Windows NT\Pinball\SOUND1.WAV
C:\Program Files\Windows NT\Pinball\SOUND104.WAV
C:\Program Files\Windows NT\Pinball\SOUND105.WAV
C:\Program Files\Windows NT\Pinball\SOUND108.WAV
C:\Program Files\Windows NT\Pinball\SOUND111.WAV
C:\Program Files\Windows NT\Pinball\SOUND112.WAV
C:\Program Files\Windows NT\Pinball\SOUND12.WAV
C:\Program Files\Windows NT\Pinball\SOUND13.WAV
C:\Program Files\Windows NT\Pinball\SOUND131.WAV
C:\Program Files\Windows NT\Pinball\SOUND136.WAV
C:\Program Files\Windows NT\Pinball\SOUND14.WAV
C:\Program Files\Windows NT\Pinball\SOUND16.WAV
C:\Program Files\Windows NT\Pinball\SOUND17.WAV
C:\Program Files\Windows NT\Pinball\SOUND18.WAV
C:\Program Files\Windows NT\Pinball\SOUND181.WAV
C:\Program Files\Windows NT\Pinball\SOUND19.WAV
C:\Program Files\Windows NT\Pinball\SOUND20.WAV
C:\Program Files\Windows NT\Pinball\SOUND21.WAV
C:\Program Files\Windows NT\Pinball\SOUND22.WAV
C:\Program Files\Windows NT\Pinball\SOUND24.WAV
C:\Program Files\Windows NT\Pinball\SOUND240.WAV
C:\Program Files\Windows NT\Pinball\SOUND243.WAV
C:\Program Files\Windows NT\Pinball\SOUND25.WAV
C:\Program Files\Windows NT\Pinball\SOUND26.WAV
C:\Program Files\Windows NT\Pinball\SOUND27.WAV
C:\Program Files\Windows NT\Pinball\SOUND28.WAV
C:\Program Files\Windows NT\Pinball\SOUND29.WAV
C:\Program Files\Windows NT\Pinball\SOUND3.WAV
C:\Program Files\Windows NT\Pinball\SOUND30.WAV
C:\Program Files\Windows NT\Pinball\SOUND34.WAV
C:\Program Files\Windows NT\Pinball\SOUND35.WAV
C:\Program Files\Windows NT\Pinball\SOUND36.WAV
C:\Program Files\Windows NT\Pinball\SOUND38.WAV
C:\Program Files\Windows NT\Pinball\SOUND39.WAV
C:\Program Files\Windows NT\Pinball\SOUND4.WAV
C:\Program Files\Windows NT\Pinball\SOUND42.WAV
C:\Program Files\Windows NT\Pinball\SOUND43.WAV
C:\Program Files\Windows NT\Pinball\SOUND45.WAV
C:\Program Files\Windows NT\Pinball\SOUND49.WAV
C:\Program Files\Windows NT\Pinball\SOUND49D.WAV
C:\Program Files\Windows NT\Pinball\SOUND5.WAV
C:\Program Files\Windows NT\Pinball\SOUND50.WAV
C:\Program Files\Windows NT\Pinball\SOUND528.WAV
C:\Program Files\Windows NT\Pinball\SOUND53.WAV
C:\Program Files\Windows NT\Pinball\SOUND54.WAV
C:\Program Files\Windows NT\Pinball\SOUND55.WAV
C:\Program Files\Windows NT\Pinball\SOUND560.WAV
C:\Program Files\Windows NT\Pinball\SOUND563.WAV
C:\Program Files\Windows NT\Pinball\SOUND57.WAV
C:\Program Files\Windows NT\Pinball\SOUND58.WAV
C:\Program Files\Windows NT\Pinball\SOUND6.WAV
C:\Program Files\Windows NT\Pinball\SOUND65.WAV
C:\Program Files\Windows NT\Pinball\SOUND68.WAV
C:\Program Files\Windows NT\Pinball\SOUND7.WAV
C:\Program Files\Windows NT\Pinball\SOUND713.WAV
C:\Program Files\Windows NT\Pinball\SOUND735.WAV
C:\Program Files\Windows NT\Pinball\SOUND8.WAV
C:\Program Files\Windows NT\Pinball\SOUND827.WAV
C:\Program Files\Windows NT\Pinball\SOUND9.WAV
C:\Program Files\Windows NT\Pinball\SOUND999.WAV
C:\Program Files\Windows NT\Pinball\table.bmp
C:\Program Files\Windows NT\Pinball\wavemix.inf
C:\WINDOWS\av_ico\ico_avast_desktop.ico
C:\WINDOWS\av_ico\ico_avast_start.ico
C:\WINDOWS\av_ico\ico_NOD_AV_START.ico
C:\WINDOWS\av_ico\ico_NOD_SS_START.ico
C:\WINDOWS\av_ico\ico_NOD_SYSINSP.ico
C:\WINDOWS\av_ico\ico_NOD_SYSRESC.ico
C:\WINDOWS\av_ico\ico_NOD_TXT.ico
C:\WINDOWS\av_ico\ico_NOD_UNINSTALL.ico
C:\WINDOWS\front_ip_list.txt
C:\WINDOWS\info1
C:\WINDOWS\iplist.txt
C:\WINDOWS\proc_list1.log
C:\WINDOWS\sysdriver32.exe
C:\WINDOWS\sysdriver32_.exe
C:\WINDOWS\system32\drivers\ehdrv.sys
C:\WINDOWS\system32\ezGOSvc.dll
C:\WINDOWS\system32\ezGOSvcApp.exe
C:\WINDOWS\system32\tmp19D8.tmp
C:\WINDOWS\system32\tmp19D9.tmp
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1078081533-1770027372-1177238915-1003.job
C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1078081533-1770027372-1177238915-1003.job
C:\WINDOWS\unrar.exe
C:\WINDOWS\update.tray-2-0\svchost.exe
C:\WINDOWS\update.tray-3-0\svchost.exe
-- Previous Run --
Infected copy of C:\WINDOWS\system32\kernel32.dll was found and disinfected
Restored copy from - C:\WINDOWS\ERDNT\cache\kernel32.dll
--------
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SRVIECHECK
-------\Legacy_SRVSYSDRIVER32
-------\Legacy_WXPDRIVERS
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_wxpdrivers
-------\Legacy_srvbtcclient
-------\Legacy_srvbtcclient
-------\Service_srvbtcclient
-------\Service_srvbtcclient
-------\Legacy_EHDRV
-------\Legacy_EPFWTDIR
-------\Legacy_EZGOSVC
-------\Legacy_GUPDATE
-------\Legacy_SRVSYSDRIVER32
-------\Service_ehdrv
-------\Service_epfwtdir
-------\Service_ezGOSvc
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_srvsysdriver32
-------\Legacy_CATCHME
-------\Legacy_EAMON
-------\Legacy_SRVIECHECK
-------\Legacy_SRVSYSDRIVER32
-------\Service_catchme
-------\Service_eamon
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Legacy_srvbtcclient
-------\Legacy_srvbtcclient
-------\Service_srvbtcclient
-------\Service_srvbtcclient
((((((((((((((((((((((((( Files Created from 2011-06-20 to 2011-07-20 )))))))))))))))))))))))))))))))
2011-07-20 21:20:57 . 2008-04-14 06:52:42 282112 ----a-w- C:\Program Files\Windows NT\pinball\PINBALL.EXE
2011-07-20 21:20:56 . 2008-04-14 06:52:56 215552 ----a-w- C:\Program Files\Windows NT\accessories\wordpad.exe
2011-07-20 21:20:56 . 2001-10-25 13:00:00 28160 ----a-w- C:\Program Files\Windows NT\hypertrm.exe
2011-07-20 21:20:56 . 2001-10-25 13:00:00 13312 ----a-w- C:\Program Files\Windows NT\htrn_jis.dll
2011-07-20 21:20:55 . 2008-04-14 06:52:20 543232 ----a-w- C:\Program Files\Windows NT\dialer.exe
2011-07-20 13:41:38 . 2011-07-20 13:59:47 -------- d-----w- C:\Program Files\Windows Doctor
2011-07-20 12:13:53 . 2011-07-20 12:45:16 -------- d-----w- C:\Program Files\Counter-Strike Source
2011-07-19 15:50:28 . 2011-07-17 13:18:08 181760 ----a-w- C:\Program Files\Windows NT\dwm.exe
2011-07-19 13:25:25 . 2011-07-19 13:25:25 -------- d-----w- C:\_OTM
2011-07-17 21:34:55 . 2011-07-04 11:36:32 309848 ----a-w- C:\WINDOWS\system32\drivers\aswSP.sys
2011-07-17 21:34:55 . 2011-07-04 11:32:12 19544 ----a-w- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-07-17 21:34:53 . 2011-07-04 11:32:32 25432 ----a-w- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-07-17 21:34:52 . 2011-07-04 11:36:43 441176 ----a-w- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-07-17 21:34:52 . 2011-07-04 11:35:23 43608 ----a-w- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-07-17 21:34:51 . 2011-07-04 11:35:12 102616 ----a-w- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-07-17 21:34:51 . 2011-07-04 11:35:09 96344 ----a-w- C:\WINDOWS\system32\drivers\aswmon.sys
2011-07-17 21:34:51 . 2011-07-04 11:32:13 30808 ----a-w- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-07-17 21:34:41 . 2011-07-04 11:43:53 40112 ----a-w- C:\WINDOWS\avastSS.scr
2011-07-17 21:34:41 . 2011-07-04 11:43:51 199304 ----a-w- C:\WINDOWS\system32\aswBoot.exe
2011-07-17 21:15:09 . 2011-07-17 21:15:09 -------- d-----w- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2011-07-17 12:58:48 . 2011-07-17 12:58:48 -------- d-----w- C:\Documents and Settings\LocalService\Nabídka Start
2011-07-02 05:31:02 . 2011-07-02 05:31:02 -------- d-----w- C:\Program Files\Lavalys
2011-06-21 18:47:08 . 2011-06-21 18:47:08 2106216 ----a-w- C:\Program Files\Mozilla Firefox\D3DCompiler_43.dll
2011-06-21 18:47:07 . 2011-06-21 18:47:07 1998168 ----a-w- C:\Program Files\Mozilla Firefox\d3dx9_43.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-07-11 08:57:06 . 2011-05-29 10:13:19 445016 ----a-w- C:\WINDOWS\system32\wrap_oal.dll
2011-07-11 08:57:05 . 2011-05-29 10:13:19 109144 ----a-w- C:\WINDOWS\system32\OpenAL32.dll
2011-07-09 15:22:59 . 2011-01-29 14:22:24 138184 ----a-w- C:\WINDOWS\system32\drivers\PnkBstrK.sys
2011-07-09 15:22:52 . 2011-01-29 14:22:06 183112 ----a-w- C:\WINDOWS\system32\PnkBstrB.exe
2011-06-28 17:28:46 . 2011-01-29 14:22:05 66872 ----a-w- C:\WINDOWS\system32\PnkBstrA.exe
2011-06-27 03:10:45 . 2011-06-06 03:07:47 404640 ----a-w- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2011-06-21 18:47:07 . 2011-04-03 19:01:02 142296 ----a-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
[-] 2008-12-01 11:20:10 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\sfcfiles.dll
((((((((((((((((((((((((((((( SnapShot@2011-07-18_08.29.55 )))))))))))))))))))))))))))))))))))))))))
+ 2011-07-20 21:32:59 . 2011-07-20 21:32:59 16384 C:\WINDOWS\temp\Perflib_Perfdata_54c.dat
+ 2001-10-25 13:00:00 . 2011-07-20 21:34:29 68156 C:\WINDOWS\system32\perfc009.dat
- 2001-10-25 13:00:00 . 2011-07-18 08:30:10 68156 C:\WINDOWS\system32\perfc009.dat
- 2001-10-25 13:00:00 . 2011-07-18 08:30:09 78720 C:\WINDOWS\system32\perfc005.dat
+ 2001-10-25 13:00:00 . 2011-07-20 21:34:28 78720 C:\WINDOWS\system32\perfc005.dat
+ 2001-10-25 13:00:00 . 2011-07-20 21:34:29 435260 C:\WINDOWS\system32\perfh009.dat
- 2001-10-25 13:00:00 . 2011-07-18 08:30:11 435260 C:\WINDOWS\system32\perfh009.dat
- 2001-10-25 13:00:00 . 2011-07-18 08:30:10 431634 C:\WINDOWS\system32\perfh005.dat
+ 2001-10-25 13:00:00 . 2011-07-20 21:34:29 431634 C:\WINDOWS\system32\perfh005.dat
+ 2011-07-18 09:19:35 . 2011-07-18 09:19:35 691200 C:\WINDOWS\Installer\259ff0.msi
+ 2011-07-18 09:19:18 . 2011-07-18 09:19:18 371272 C:\WINDOWS\Installer\{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}\SkypeIcon.exe
+ 2011-07-18 09:19:17 . 2011-07-18 09:19:17 1541120 C:\WINDOWS\Installer\259fd8.msi
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2011-03-30 17:34:30 399736]
"AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-04-27 12:00:02 102400]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2011-06-15 13:02:58 15141768]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 06:52:18 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2009-09-27 17:19:46 13918208]
"ROUTE66Sync"="C:\Program Files\ROUTE 66\ROUTE 66 Sync\Sync9Loader.exe" [2010-12-17 09:26:06 168448]
"sysdriver32.exe"="C:\WINDOWS\sysdriver32.exe" [BU]
"sysdriver32_.exe"="C:\WINDOWS\sysdriver32_.exe" [BU]
"systemup"="C:\WINDOWS\systemup.exe" [BU]
"l1rezerv.exe"="C:\WINDOWS\l1rezerv.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 06:52:18 15360]
C:\Documents and Settings\Doma\Nabˇdka Start\Programy\Po spuçtŘnˇ\
license.dll [2011-2-28 13824]
Orez vaź obrazovky a spŁçśaź programu OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2011-1-22 581632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Atari\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Valve\\hl.exe"=
"D:\\Nová složka (2)\\crysis2(5620)_01_13\\Bin32\\Crysis2.exe"=
"C:\\Documents and Settings\\Doma\\Data aplikací\\RuneScapeDDoSer.exe"=
"c:\\program files\\mozilla firefox\\firefox.exe"=
"C:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"D:\\CRYSIS 2 CZ\\bin32\\Crysis2.exe"=
"C:\\Program Files\\ICQ7.5\\ICQ.exe"=
"C:\\Program Files\\Codemasters\\DiRT 3\\dirt3_game.exe"=
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"C:\\Program Files\\ROUTE 66\\ROUTE 66 Sync\\ROUTE66Sync.exe"=
"C:\\Program Files\\ROUTE 66\\ROUTE 66 Sync\\Sync9Loader.exe"=
"C:\\Documents and Settings\\Doma\\Plocha\\Nová složka (3)\\Counter strike 1.6 by Vinc\\cs\\hl.exe"=
"C:\\Program Files\\Codemasters\\F1 2010\\F1_2010_game.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\WINDOWS\system32\drivers\dtsoftbus01.sys [22.1.2011 19:04:29 218688]
R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [1.6.2011 18:15:27 233472]
R2 ICQ Service;ICQ Service;C:\Program Files\ICQ6Toolbar\ICQ Service.exe [4.5.2011 18:02:00 247608]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service;C:\WINDOWS\system32\drivers\AVerBDA3x.sys [22.1.2011 15:33:25 1171456]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [1.6.2011 18:15:27 36608]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [2.7.2011 7:31:09 27760]
------- Supplementary Scan -------
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyServer = http=127.0.0.1:50889
IE: E&xportovať do programu Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 172.17.110.7 172.17.110.6
FF - ProfilePath - C:\Documents and Settings\Doma\Data aplikací\Mozilla\Firefox\Profiles\u5lxzfpq.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=toolbar2&q=
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKCU-Run-RGSC - C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe