keď dlhšie nerobím nič na PC (možno cez 1/2 hod alebo viac), samovoľne sa reštartne a následne mi vypíše, že činnosť systému sa obnovila po vážnej chybe. Všimla som si to už dávno, ale až teraz som sa rozhodla to riešiť. Hľadala som tu, či mal niekto podobný problém, našla som toto tu:http://forum.viry.cz/viewtopic.php?f=13&t=84113 a na základe toho som chcela vyskúšať ten program Combofix (bohužiaľ návod na to som si prečítala až po tom, ako som ho použila)..teraz sa obávam, či ten program nevymazal niečo dôležité, čo nemal a či si nemám prostredníctvom bodu obnovy vrátiť PC do pôvodného stavu...Mohli by ste mi prosím skontrolovať ten log z cf, či je všetko ok?
Ďakujem za odpoveď

ComboFix 14-08-31.01 - User 02.09.2014 17:49:57.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.511.200 [GMT 2:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\Administrator\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\ASPNET\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\ASPNET\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\ASPNET\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\ASPNET\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\ASPNET\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\ASPNET\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\ASPNET\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\ASPNET\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\ASPNET\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\Guest\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\Guest\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\Guest\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\SUPPORT_388945a0\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\gwi1rfto.default-1379869318781\extensions\iiou19@doayi-.org
c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\gwi1rfto.default-1379869318781\extensions\iiou19@doayi-.org\bootstrap.js
c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\gwi1rfto.default-1379869318781\extensions\iiou19@doayi-.org\content\bg.js
c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\gwi1rfto.default-1379869318781\extensions\iiou19@doayi-.org\chrome.manifest
c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\gwi1rfto.default-1379869318781\extensions\iiou19@doayi-.org\install.rdf
c:\documents and settings\User\Application Data\PriceGong
c:\documents and settings\User\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\User\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\User\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\User\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\User\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\User\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\User\Local Settings\Application Data\Comodo\Dragon\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\User\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\User\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\User\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\User\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\User\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\User\Local Settings\Application Data\Google\Chrome SxS\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
c:\documents and settings\User\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp
c:\documents and settings\User\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\background.html
c:\documents and settings\User\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\content.js
c:\documents and settings\User\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\lsdb.js
c:\documents and settings\User\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\manifest.json
c:\documents and settings\User\Local Settings\Application Data\Torch\User Data\Default\Extensions\fpchoohjmbhhmchgcblpaecpdlbdbckp\5.14\oYM3Rm42QAX.js
c:\documents and settings\User\SendTo\SNS-Resizer-1000.exe
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\windows\system32\MUI\041b\tourstart.exe
.
.
((((((((((((((((((((((((( Files Created from 2014-08-02 to 2014-09-02 )))))))))))))))))))))))))))))))
.
.
2014-08-04 11:13 . 2014-08-04 11:13 -------- d-----w- c:\program files\Common Files\Java
2014-08-04 11:12 . 2014-08-04 11:10 145408 ----a-w- c:\windows\system32\javacpl.cpl
2014-08-04 11:11 . 2014-08-04 11:10 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-09 14:16 . 2012-06-07 16:03 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-09 14:16 . 2011-08-05 14:29 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-05-01 16:46 260976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"icq"="c:\documents and settings\User\Application Data\ICQM\icq.exe" [2014-03-30 33664344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2005-04-28 589824]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-04-01 1368064]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-08-08 3890208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-07-11 256896]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
Orezávač obrazovky a spúšťač programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2006-10-26 98632]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre7\\launch4j-tmp\\frd.exe"=
"c:\\Documents and Settings\\User\\Application Data\\ICQM\\icq.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"=
.
R0 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [11.7.2012 12:42 21576]
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [22.5.2013 17:55 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [22.5.2013 17:55 180632]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14.8.2011 21:41 436792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswsnx.sys [5.8.2011 16:26 777488]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [5.8.2011 16:26 411680]
R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [1.5.2014 18:46 24184]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswmonflt.sys [22.5.2013 17:55 67824]
S2 CambridgeAudioRecorder;CambridgeAudioRecorder;c:\progra~1\CAMBRI~1\CAMBRI~1\AUDIOS~1.EXE -zglaxservice CambridgeAudioRecorder --> c:\progra~1\CAMBRI~1\CAMBRI~1\AUDIOS~1.EXE -zglaxservice CambridgeAudioRecorder [?]
S2 lijrjjniw;Helper Task;c:\windows\system32\svchost.exe -k netsvcs [4.8.2004 2:56 14336]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [21.6.2013 9:53 162408]
S3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys [3.7.2012 11:43 23040]
S3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys [3.7.2012 11:43 27776]
S3 ussuj;ussuj;\??\c:\windows\system32\0516.tmp --> c:\windows\system32\0516.tmp [?]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [24.5.2014 9:59 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [24.5.2014 9:59 85696]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
lijrjjniw
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-14 18:10 1104200 ----a-w- c:\program files\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-07 14:16]
.
2014-09-02 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2014-05-01 16:45]
.
2014-09-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-06-15 16:59]
.
2014-09-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-06-15 16:59]
.
2014-09-02 c:\windows\Tasks\Opera scheduled Autoupdate 1393782384.job
- c:\program files\Opera\launcher.exe [2014-03-02 09:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://dts.search-results.com/sr?src=ieb&appid=250&systemid=406&sr=0&q={searchTerms}
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
TCP: DhcpNameServer = 192.168.14.1 192.168.0.1
TCP: Interfaces\{5D5D6CCF-7D73-46CB-8735-9EE08691C5F9}: NameServer = 192.168.14.1,8.8.8.8
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\gwi1rfto.default-1379869318781\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.sk/
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
HKCU-Run-OEXPRESS - (no file)
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKCU-Run-MediaGet2 - c:\documents and settings\User\Local Settings\Application Data\MediaGet2\mediaget.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
AddRemove-FreePascal_is1 - c:\program files\unins000.exe
AddRemove-Speed Test 4354 - c:\program files\Speed Test 4354\uninst.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}\bm_installer.exe
AddRemove-{5F189DF5-2D05-472B-9091-84D9848AE48B}{5dee0f7c} - c:\progra~1\GSSUPP~1\ASSIST~1.DLL
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-02 18:01
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ussuj]
"ImagePath"="\??\c:\windows\system32\0516.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lijrjjniw]
"ServiceDll"="c:\windows\system32\dmhxo.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2014-09-02 18:04:45
ComboFix-quarantined-files.txt 2014-09-02 16:04
.
Pre-Run: 994 033 664 bytes free
Post-Run: 1 082 966 016 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 452B555779AEDED8DD337989375E1C77
8F558EB6672622401DA993E1E865C861