

Task: {252E4A59-65C7-4E7F-85BE-6ED129EB6EEB} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-05-20] (Enigma Software Group USA, LLC.)
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Browser Manage" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem" /f
C:\Program Files\Enigma Software Group
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
C:\Users\Dell Vostro 3555\AppData\Roaming\Enigma Software Group
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3092275392-180616631-1705628173-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
CHR StartupUrls: Default -> "hxxp://www.sweet-page.com/?type=hp&ts=1432107101&z=605d62829ace93a81f2bdb7g1z9cdobgbe7m9e4ccw&from=cor&uid=HitachiXHTS727550A9E364_J3320082GKMAAAGKMAAAX"
StartMenuInternet: (HKLM) Opera - C:\Program Files\Opera x64\Opera.exe http://isearch.omiga-plus.com/?type=sc&ts=1423516923&from=ild&uid=HitachiXHTS727550A9E364_J3320082GKMAAAGKMAAAX
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026432 2015-05-20] (Enigma Software Group USA, LLC.)
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-05-20] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-05-20] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 STHDA; system32\DRIVERS\stwrt64.sys [X]
C:\Windows\System32\Tasks\SpyHunter4Startup
C:\sh4ldr
C:\Windows\system32\Drivers\EsgScanner.sys
C:\Windows\Minidump\*.dmp
EmptyTemp:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 3 gości