Re: Prosím o preventivku.
Napsal: 18 kvě 2015 16:51
Link z Virustotal: https://www.virustotal.com/cs/file/37c9 ... 431963459/
--------------------------------------------------------------------------------------------------------------------------------Fixlist:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-05-2015 02
Ran by notebook at 2015-05-18 17:42:09 Run:1
Running from C:\Users\notebook\Desktop
Loaded Profiles: notebook (Available profiles: notebook)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
Folder: C:\Program Files (x86)\Safesoft Protector
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd)
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\...\MountPoints2: {627f2a0e-cced-11e4-a6b8-70f395aae471} - E:\autorun.exe
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/?gfe_rd=cr&ei=bNQ ... gws_rd=ssl
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
2015-05-18 12:38 - 2015-05-18 12:38 - 00009213 _____ () C:\Users\notebook\Desktop\Nepotvrzeno 188167.crdownload
2015-05-18 10:58 - 2015-05-18 10:58 - 00003110 _____ () C:\Users\notebook\Desktop\AdwCleaner[S0].txt
2015-05-18 10:56 - 2015-05-18 10:56 - 00000056 _____ () C:\Windows\setupact.log
2015-05-18 10:56 - 2015-05-18 10:56 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-18 10:44 - 2015-05-18 10:54 - 00000000 ____D () C:\AdwCleaner
CMD: dir "C:\Users\notebook\AppData\Roaming\*.tmp"
CMD: dir "C:\Windows\SysWOW64\*.tmp"
2015-04-27 08:45 - 2015-04-27 08:45 - 00000000 _____ () C:\Users\notebook\AppData\Roaming\D417.tmp
2015-04-16 23:16 - 2015-04-16 23:16 - 00000000 _____ () C:\Windows\SysWOW64\RENA36F.tmp
CMD: del "C:\Users\notebook\AppData\Roaming\*.tmp"
CMD: del "C:\Windows\SysWOW64\*.tmp"
2015-04-13 08:20 - 2015-05-18 12:15 - 00000000 ____D () C:\Program Files\trend micro
2015-04-13 08:20 - 2015-04-13 08:20 - 00000000 ____D () C:\rsit
2015-04-12 21:22 - 2015-04-12 21:24 - 01222144 _____ () C:\Users\notebook\Desktop\RSITx64.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
========================= Folder: C:\Program Files (x86)\Safesoft Protector ========================
2015-04-27 08:46 - 2015-04-27 08:47 - 0135168 _____ (SecureSoft) C:\Program Files (x86)\Safesoft Protector\amie.dll
2015-04-27 08:46 - 2015-04-27 08:47 - 0000411 _____ () C:\Program Files (x86)\Safesoft Protector\config.txt
2015-04-27 08:46 - 2015-04-27 08:47 - 0000021 _____ () C:\Program Files (x86)\Safesoft Protector\default.action
2015-04-27 08:46 - 2015-04-27 08:47 - 0000142 _____ () C:\Program Files (x86)\Safesoft Protector\default.filter
2015-04-27 08:46 - 2015-04-27 08:47 - 0158720 _____ (Jelbrus) C:\Program Files (x86)\Safesoft Protector\itchromium64.exe
2015-04-27 08:46 - 2015-04-27 08:47 - 0086528 _____ () C:\Program Files (x86)\Safesoft Protector\mgwz.dll
2015-04-27 08:46 - 2015-04-27 08:47 - 0371200 _____ (The Privoxy team - www.privoxy.org) C:\Program Files (x86)\Safesoft Protector\privoxy.exe
2015-04-27 08:46 - 2015-04-27 08:46 - 0000000 _____ () C:\Program Files (x86)\Safesoft Protector\privoxy.log
2015-04-27 08:46 - 2015-04-27 08:47 - 0110080 _____ (Jelbrus) C:\Program Files (x86)\Safesoft Protector\ssweb64.dll
====== End of Folder: ======
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => Value not found.
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Pro Agent => Value not found.
"HKU\S-1-5-21-4054755293-3890498329-465695249-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{627f2a0e-cced-11e4-a6b8-70f395aae471}" => Key deleted successfully.
HKCR\CLSID\{627f2a0e-cced-11e4-a6b8-70f395aae471} => Key not found.
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
xhunter1 => Service deleted successfully.
"C:\Users\notebook\Desktop\Nepotvrzeno 188167.crdownload" => File/Directory not found.
"C:\Users\notebook\Desktop\AdwCleaner[S0].txt" => File/Directory not found.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\AdwCleaner => Moved successfully.
========= dir "C:\Users\notebook\AppData\Roaming\*.tmp" =========
Svazek v jednotce C nem� ��dnou jmenovku.
S�riov� ��slo svazku je 5470-0AA6.
V�pis adres��e C:\Users\notebook\AppData\Roaming
27.04.2015 08:45 0 D417.tmp
Soubor�: 1, Bajt�: 0
Adres���: 0, Voln�ch bajt�: 212�394�881�024
========= End of CMD: =========
========= dir "C:\Windows\SysWOW64\*.tmp" =========
Svazek v jednotce C nem� ��dnou jmenovku.
S�riov� ��slo svazku je 5470-0AA6.
V�pis adres��e C:\Windows\SysWOW64
16.04.2015 23:16 0 RENA36F.tmp
Soubor�: 1, Bajt�: 0
Adres���: 0, Voln�ch bajt�: 212�394�872�832
========= End of CMD: =========
C:\Users\notebook\AppData\Roaming\D417.tmp => Moved successfully.
C:\Windows\SysWOW64\RENA36F.tmp => Moved successfully.
========= del "C:\Users\notebook\AppData\Roaming\*.tmp" =========
Nelze naj�t C:\Users\notebook\AppData\Roaming\*.tmp.
========= End of CMD: =========
========= del "C:\Windows\SysWOW64\*.tmp" =========
Nelze naj�t C:\Windows\SysWOW64\*.tmp.
========= End of CMD: =========
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\notebook\Desktop\RSITx64.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 725.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog 17:42:25 ====
--------------------------------------------------------------------------------------------------------------------------------Fixlist:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-05-2015 02
Ran by notebook at 2015-05-18 17:42:09 Run:1
Running from C:\Users\notebook\Desktop
Loaded Profiles: notebook (Available profiles: notebook)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
Folder: C:\Program Files (x86)\Safesoft Protector
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd)
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\...\MountPoints2: {627f2a0e-cced-11e4-a6b8-70f395aae471} - E:\autorun.exe
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/?gfe_rd=cr&ei=bNQ ... gws_rd=ssl
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
2015-05-18 12:38 - 2015-05-18 12:38 - 00009213 _____ () C:\Users\notebook\Desktop\Nepotvrzeno 188167.crdownload
2015-05-18 10:58 - 2015-05-18 10:58 - 00003110 _____ () C:\Users\notebook\Desktop\AdwCleaner[S0].txt
2015-05-18 10:56 - 2015-05-18 10:56 - 00000056 _____ () C:\Windows\setupact.log
2015-05-18 10:56 - 2015-05-18 10:56 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-18 10:44 - 2015-05-18 10:54 - 00000000 ____D () C:\AdwCleaner
CMD: dir "C:\Users\notebook\AppData\Roaming\*.tmp"
CMD: dir "C:\Windows\SysWOW64\*.tmp"
2015-04-27 08:45 - 2015-04-27 08:45 - 00000000 _____ () C:\Users\notebook\AppData\Roaming\D417.tmp
2015-04-16 23:16 - 2015-04-16 23:16 - 00000000 _____ () C:\Windows\SysWOW64\RENA36F.tmp
CMD: del "C:\Users\notebook\AppData\Roaming\*.tmp"
CMD: del "C:\Windows\SysWOW64\*.tmp"
2015-04-13 08:20 - 2015-05-18 12:15 - 00000000 ____D () C:\Program Files\trend micro
2015-04-13 08:20 - 2015-04-13 08:20 - 00000000 ____D () C:\rsit
2015-04-12 21:22 - 2015-04-12 21:24 - 01222144 _____ () C:\Users\notebook\Desktop\RSITx64.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
========================= Folder: C:\Program Files (x86)\Safesoft Protector ========================
2015-04-27 08:46 - 2015-04-27 08:47 - 0135168 _____ (SecureSoft) C:\Program Files (x86)\Safesoft Protector\amie.dll
2015-04-27 08:46 - 2015-04-27 08:47 - 0000411 _____ () C:\Program Files (x86)\Safesoft Protector\config.txt
2015-04-27 08:46 - 2015-04-27 08:47 - 0000021 _____ () C:\Program Files (x86)\Safesoft Protector\default.action
2015-04-27 08:46 - 2015-04-27 08:47 - 0000142 _____ () C:\Program Files (x86)\Safesoft Protector\default.filter
2015-04-27 08:46 - 2015-04-27 08:47 - 0158720 _____ (Jelbrus) C:\Program Files (x86)\Safesoft Protector\itchromium64.exe
2015-04-27 08:46 - 2015-04-27 08:47 - 0086528 _____ () C:\Program Files (x86)\Safesoft Protector\mgwz.dll
2015-04-27 08:46 - 2015-04-27 08:47 - 0371200 _____ (The Privoxy team - www.privoxy.org) C:\Program Files (x86)\Safesoft Protector\privoxy.exe
2015-04-27 08:46 - 2015-04-27 08:46 - 0000000 _____ () C:\Program Files (x86)\Safesoft Protector\privoxy.log
2015-04-27 08:46 - 2015-04-27 08:47 - 0110080 _____ (Jelbrus) C:\Program Files (x86)\Safesoft Protector\ssweb64.dll
====== End of Folder: ======
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => Value not found.
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Pro Agent => Value not found.
"HKU\S-1-5-21-4054755293-3890498329-465695249-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{627f2a0e-cced-11e4-a6b8-70f395aae471}" => Key deleted successfully.
HKCR\CLSID\{627f2a0e-cced-11e4-a6b8-70f395aae471} => Key not found.
HKU\S-1-5-21-4054755293-3890498329-465695249-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
xhunter1 => Service deleted successfully.
"C:\Users\notebook\Desktop\Nepotvrzeno 188167.crdownload" => File/Directory not found.
"C:\Users\notebook\Desktop\AdwCleaner[S0].txt" => File/Directory not found.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\AdwCleaner => Moved successfully.
========= dir "C:\Users\notebook\AppData\Roaming\*.tmp" =========
Svazek v jednotce C nem� ��dnou jmenovku.
S�riov� ��slo svazku je 5470-0AA6.
V�pis adres��e C:\Users\notebook\AppData\Roaming
27.04.2015 08:45 0 D417.tmp
Soubor�: 1, Bajt�: 0
Adres���: 0, Voln�ch bajt�: 212�394�881�024
========= End of CMD: =========
========= dir "C:\Windows\SysWOW64\*.tmp" =========
Svazek v jednotce C nem� ��dnou jmenovku.
S�riov� ��slo svazku je 5470-0AA6.
V�pis adres��e C:\Windows\SysWOW64
16.04.2015 23:16 0 RENA36F.tmp
Soubor�: 1, Bajt�: 0
Adres���: 0, Voln�ch bajt�: 212�394�872�832
========= End of CMD: =========
C:\Users\notebook\AppData\Roaming\D417.tmp => Moved successfully.
C:\Windows\SysWOW64\RENA36F.tmp => Moved successfully.
========= del "C:\Users\notebook\AppData\Roaming\*.tmp" =========
Nelze naj�t C:\Users\notebook\AppData\Roaming\*.tmp.
========= End of CMD: =========
========= del "C:\Windows\SysWOW64\*.tmp" =========
Nelze naj�t C:\Windows\SysWOW64\*.tmp.
========= End of CMD: =========
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\notebook\Desktop\RSITx64.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 725.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog 17:42:25 ====