Re: Prosim o pomoc
Napsal: 17 lis 2015 00:56
ComboFix 15-11-15.01 - Dodo 16.11.2015 23:50:19.8.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3001.2499 [GMT 1:00]
Spuštěný z: c:\documents and settings\Dodo\Plocha\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Avira Antivirus *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Free Firewall Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-10-16 do 2015-11-16 )))))))))))))))))))))))))))))))
.
.
2015-11-15 18:17 . 2015-11-15 18:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes' Anti-Malware (portable)
2015-11-15 18:17 . 2015-11-15 18:17 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-11-13 08:37 . 2015-11-13 08:37 -------- d-----w- C:\_OTM
2015-11-13 08:19 . 2015-11-13 08:19 -------- d-----w- c:\documents and settings\Dodo\Data aplikací\Avira
2015-11-13 08:15 . 2015-11-13 08:23 136728 ----a-w- c:\windows\system32\drivers\avipbb.sys
2015-11-13 08:15 . 2015-04-16 14:23 37896 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2015-11-13 08:15 . 2015-11-13 08:23 108448 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2015-11-13 08:15 . 2015-11-13 08:15 -------- d-----w- c:\program files\Avira
2015-11-11 09:03 . 2015-11-13 18:14 -------- d-----w- C:\FRST
2015-11-11 09:00 . 2015-11-11 09:00 15327 ----a-w- c:\documents and settings\Dodo\Local Settings\Data aplikací\LM.bat
2015-11-10 06:41 . 2015-11-10 06:41 -------- d-----w- c:\program files\Common Files\Lavasoft
2015-11-10 06:39 . 2015-11-10 06:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Lavasoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-11-15 18:17 . 2015-09-05 10:05 121560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-11-13 05:40 . 2014-04-02 16:47 780488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-11-13 05:40 . 2014-04-02 16:47 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-09-11 07:28 . 2015-09-10 06:23 40960 ----a-r- c:\documents and settings\Dodo\Data aplikací\Microsoft\Installer\{B2073246-67E3-40CD-A7EF-8882D37119BC}\assassin.exe1_B207324667E340CDA7EF8882D37119BC.exe
2015-09-11 07:28 . 2015-09-10 06:23 40960 ----a-r- c:\documents and settings\Dodo\Data aplikací\Microsoft\Installer\{B2073246-67E3-40CD-A7EF-8882D37119BC}\assassin.exe_B207324667E340CDA7EF8882D37119BC.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-10-09 . FF876311F58C86EC3E1A24F585949C25 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"f.lux"="c:\documents and settings\Dodo\Local Settings\Data aplikací\FluxSoftware\Flux\flux.exe" [2013-10-23 1017224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2013-12-16 73832]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-05 1434920]
"snuvcdsm"="c:\windows\snuvcdsm.exe" [2011-01-13 30080]
"snp2uvc"="c:\windows\system32\csnp2uvc.dll" [2011-01-13 202112]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"avgnt"="c:\program files\Avira\Antivirus\avgnt.exe" [2015-11-13 782520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SoftwareSASGeneration"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2010-01-14 304128]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean.exe\0sprestrt
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LiveUpdateSvc"=2 (0x2)
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
"SDWSCService"=2 (0x2)
"SDUpdateService"=2 (0x2)
"SDScannerService"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Documents and Settings\\Dodo\\Data aplikací\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
.
R0 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [15.11.2015 19:17 170200]
R0 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [27.7.2015 19:11 15688]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [13.11.2015 9:15 37896]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\Antivirus\sched.exe [13.11.2015 9:15 461672]
R2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [15.10.2013 5:38 50704]
R3 L1c;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [28.2.2014 9:43 82072]
R3 SmbDrvI;SmbDrvI;c:\windows\system32\drivers\Smb_driver_Intel.sys [17.8.2014 18:14 28656]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [14.1.2010 16:04 9472]
S2 AntiVirMailService;Avira Mail Protection;c:\program files\Avira\Antivirus\avmailc.exe [13.11.2015 9:15 916968]
S2 AntiVirWebService;Avira Web Protection;c:\program files\Avira\Antivirus\avwebgrd.exe [13.11.2015 9:15 1210512]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [18.2.2015 19:11 315488]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [12.5.2015 19:05 83168]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\SophosMEMSWEEP.SYS --> c:\windows\system32\SophosMEMSWEEP.SYS [?]
S3 nlqrmejr;nlqrmejr; [x]
S3 poshxhhc;poshxhhc; [x]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [27.7.2015 19:11 10320]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [30.6.2014 23:15 171520]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [12.5.2015 19:05 181344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-07-29 06:16 995144 ----a-w- c:\program files\Google\Chrome\Application\44.0.2403.125\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-09-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-02 05:40]
.
2014-10-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2015-11-16 c:\windows\Tasks\G2MUploadTask-S-1-5-21-854245398-1677128483-842925246-1004.job
- c:\program files\Citrix\GoToMeeting\2759\g2mupload.exe [2015-06-23 21:18]
.
2014-10-27 c:\windows\Tasks\Opera scheduled Autoupdate 1393579374.job
- c:\program files\Opera\launcher.exe [2014-02-28 09:39]
.
2015-11-14 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2006-06-19 22:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-11-17 00:04
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3912)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Avira\Antivirus\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\Antivirus\avshadow.exe
.
**************************************************************************
.
Celkový čas: 2015-11-17 00:10:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-11-16 23:10
.
Před spuštěním: Volných bajtů: 21 211 365 376
Po spuštění: Volných bajtů: 21 201 281 024
.
- - End Of File - - F4782520EF41998A020F32BE804E158B
413FC2A0C716421B3158746D63736515
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3001.2499 [GMT 1:00]
Spuštěný z: c:\documents and settings\Dodo\Plocha\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Avira Antivirus *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Free Firewall Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-10-16 do 2015-11-16 )))))))))))))))))))))))))))))))
.
.
2015-11-15 18:17 . 2015-11-15 18:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes' Anti-Malware (portable)
2015-11-15 18:17 . 2015-11-15 18:17 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-11-13 08:37 . 2015-11-13 08:37 -------- d-----w- C:\_OTM
2015-11-13 08:19 . 2015-11-13 08:19 -------- d-----w- c:\documents and settings\Dodo\Data aplikací\Avira
2015-11-13 08:15 . 2015-11-13 08:23 136728 ----a-w- c:\windows\system32\drivers\avipbb.sys
2015-11-13 08:15 . 2015-04-16 14:23 37896 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2015-11-13 08:15 . 2015-11-13 08:23 108448 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2015-11-13 08:15 . 2015-11-13 08:15 -------- d-----w- c:\program files\Avira
2015-11-11 09:03 . 2015-11-13 18:14 -------- d-----w- C:\FRST
2015-11-11 09:00 . 2015-11-11 09:00 15327 ----a-w- c:\documents and settings\Dodo\Local Settings\Data aplikací\LM.bat
2015-11-10 06:41 . 2015-11-10 06:41 -------- d-----w- c:\program files\Common Files\Lavasoft
2015-11-10 06:39 . 2015-11-10 06:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Lavasoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-11-15 18:17 . 2015-09-05 10:05 121560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-11-13 05:40 . 2014-04-02 16:47 780488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-11-13 05:40 . 2014-04-02 16:47 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-09-11 07:28 . 2015-09-10 06:23 40960 ----a-r- c:\documents and settings\Dodo\Data aplikací\Microsoft\Installer\{B2073246-67E3-40CD-A7EF-8882D37119BC}\assassin.exe1_B207324667E340CDA7EF8882D37119BC.exe
2015-09-11 07:28 . 2015-09-10 06:23 40960 ----a-r- c:\documents and settings\Dodo\Data aplikací\Microsoft\Installer\{B2073246-67E3-40CD-A7EF-8882D37119BC}\assassin.exe_B207324667E340CDA7EF8882D37119BC.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-10-09 . FF876311F58C86EC3E1A24F585949C25 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"f.lux"="c:\documents and settings\Dodo\Local Settings\Data aplikací\FluxSoftware\Flux\flux.exe" [2013-10-23 1017224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2013-12-16 73832]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-05 1434920]
"snuvcdsm"="c:\windows\snuvcdsm.exe" [2011-01-13 30080]
"snp2uvc"="c:\windows\system32\csnp2uvc.dll" [2011-01-13 202112]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"avgnt"="c:\program files\Avira\Antivirus\avgnt.exe" [2015-11-13 782520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SoftwareSASGeneration"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2010-01-14 304128]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean.exe\0sprestrt
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LiveUpdateSvc"=2 (0x2)
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
"SDWSCService"=2 (0x2)
"SDUpdateService"=2 (0x2)
"SDScannerService"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Documents and Settings\\Dodo\\Data aplikací\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
.
R0 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [15.11.2015 19:17 170200]
R0 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [27.7.2015 19:11 15688]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [13.11.2015 9:15 37896]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\Antivirus\sched.exe [13.11.2015 9:15 461672]
R2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [15.10.2013 5:38 50704]
R3 L1c;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [28.2.2014 9:43 82072]
R3 SmbDrvI;SmbDrvI;c:\windows\system32\drivers\Smb_driver_Intel.sys [17.8.2014 18:14 28656]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [14.1.2010 16:04 9472]
S2 AntiVirMailService;Avira Mail Protection;c:\program files\Avira\Antivirus\avmailc.exe [13.11.2015 9:15 916968]
S2 AntiVirWebService;Avira Web Protection;c:\program files\Avira\Antivirus\avwebgrd.exe [13.11.2015 9:15 1210512]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [18.2.2015 19:11 315488]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [12.5.2015 19:05 83168]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\SophosMEMSWEEP.SYS --> c:\windows\system32\SophosMEMSWEEP.SYS [?]
S3 nlqrmejr;nlqrmejr; [x]
S3 poshxhhc;poshxhhc; [x]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [27.7.2015 19:11 10320]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [30.6.2014 23:15 171520]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [12.5.2015 19:05 181344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-07-29 06:16 995144 ----a-w- c:\program files\Google\Chrome\Application\44.0.2403.125\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-09-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-02 05:40]
.
2014-10-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2015-11-16 c:\windows\Tasks\G2MUploadTask-S-1-5-21-854245398-1677128483-842925246-1004.job
- c:\program files\Citrix\GoToMeeting\2759\g2mupload.exe [2015-06-23 21:18]
.
2014-10-27 c:\windows\Tasks\Opera scheduled Autoupdate 1393579374.job
- c:\program files\Opera\launcher.exe [2014-02-28 09:39]
.
2015-11-14 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2006-06-19 22:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-11-17 00:04
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3912)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Avira\Antivirus\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\Antivirus\avshadow.exe
.
**************************************************************************
.
Celkový čas: 2015-11-17 00:10:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-11-16 23:10
.
Před spuštěním: Volných bajtů: 21 211 365 376
Po spuštění: Volných bajtů: 21 201 281 024
.
- - End Of File - - F4782520EF41998A020F32BE804E158B
413FC2A0C716421B3158746D63736515