Prosím o kontrolu,zabydlel se mi Win32:Spyware-gen [Trj]

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

007tom
nováček
Příspěvky: 3
Registrován: prosinec 07
Pohlaví: Nespecifikováno
Stav:
Offline

Prosím o kontrolu,zabydlel se mi Win32:Spyware-gen [Trj]

Příspěvekod 007tom » 05 pro 2007 21:42

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:39:08, on 5.12.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\mHotkey.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\ConMet\ConMet.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
D:\Záloha\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=61005
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=61005
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=61005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ConMet] C:\Program Files\ConMet\ConMet.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Přidat do stávajícího PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d ... o-eula.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 1644830091
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 1644822153
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BA52B1D-74AF-4472-86E2-5F5546D1A51B}: NameServer = 194.228.41.65,194.228.41.113
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe

--
End of file - 10099 bytes

Reklama
Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 05 pro 2007 22:28

Vítej na fóru

Pokud jsi četl to co tu psal Jakub SAFE tak to nedělej:
Jakub SAFE píše:Jenom fixni v HJT toto:

O17 - HKLM\System\CCS\Services\Tcpip\..\{6BA52B1D-74AF-4472-86E2-5F5546D1A51B}: NameServer = 194.228.41.65,194.228.41.113
Tuto položku nefixuj!!!


Stáhni si SUPERAntiSpyware
Nainstaluj a spusť ho a klikni na tlačítko Check for Updates...
Po provedení Update klikni na tlačítko: Scan your computer
Zvol možnost: Perform Complete Scan a klikni na tlačítko Další >

Proběhne kontrola, po skončení vypíše vše co našel.
Ujisti se že všechny položko jsou zaškrtnuty a pak zvol tlačítko Další
Pak klikni na tlačítko Finish a měl by ses dostat na úvodní obrazovku.
Tam klikni na tlačítko: Preferences... a tam zvol záložku Statistics/Logs
Tam klikni na log s dnešním datem který tam bude a dej tlačítko: View Log...
Otevře se ti Okno s logem tak jeho obsah sem zkopíruj.

Kde ti ten problém hlásí, v jakém souboru?

Uživatelský avatar
Baron Prášil
Master Level 7
Master Level 7
Příspěvky: 4882
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod Baron Prášil » 06 pro 2007 21:33

už to fixnul :lol:

007tom
nováček
Příspěvky: 3
Registrován: prosinec 07
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod 007tom » 08 pro 2007 22:37

díky za pomoc výše uvedené jsem udělal (kromě toho fixnutí) a tady je výsledek,toho neřáda jsem našel avastem v tiomhle souboru :

C:\Documents and Settings\Tomas\Local Settings\Data aplikací\Identities\{CCA7DB30-2CCA-47C5-888F-EED6CECC8B0F}\Microsoft\Outlook Express\Odeslaná pošta.dbx\53780_74.eml#19944128\keyfinder.exe#2738714898\findkey.exe


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/08/2007 at 10:26 PM

Application Version : 3.9.1008

Core Rules Database Version : 3358
Trace Rules Database Version: 1357

Scan type : Complete Scan
Total Scan Time : 00:45:15

Memory items scanned : 598
Memory threats detected : 0
Registry items scanned : 7261
Registry threats detected : 5
File items scanned : 44405
File threats detected : 163

Adware.Tracking Cookie
C:\Documents and Settings\Tomas\Cookies\tomas@wlw.122.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@toplist[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@weborama[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@bluestreak[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@xiti[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad2.bbmedia[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adrenaline[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@avsmedia[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ehg-tgpublishing.hitbox[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@dealtime[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adidnes2.bbmedia[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@statcounter[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@spylog[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adarbo2.bbmedia[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@counter.cnw[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@k.iinfo[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@mediaplex[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@komtrack[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad2.billboard[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@tracker.roitesting[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.yieldmanager[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@autoscout24.112.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@casalemedia[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@tracker.affistats[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad2.billboard[4].txt
C:\Documents and Settings\Tomas\Cookies\tomas@s4.shinystat[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@overture[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@wsd-ps-a.bannersystem[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adtech[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@bs.serving-sys[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@serving-sys[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@rotator.adjuggler[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adclickstats[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@as1.falkag[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adrenalinesk[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.burstnet[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@search.etargetnet[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@warezblog[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@stat.dealtime[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@toplist[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.adition[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@tacoda[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@tradedoubler[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@as-eu.falkag[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@184905[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@revsci[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adopt.euroclick[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adv.surinter[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adserver.a1media[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@advertising[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@9F4877B3-B688-4602-AF70-400FD071FDBB[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@bbtrack.billboard[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@atwola[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ads.pointroll[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@upspiral[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@track.webtrekk[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adserver.adreactor[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@track.adform[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@incredimailltd.112.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@wyestatsemea[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@promarkt.122.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@mediabiz[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@tribalfusion[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@4.adbrite[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@fs10.fusestats[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@fincentrum.idnes[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@hotlog[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@statse.webtrendslive[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ads.adbrite[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@webstat[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adserver.71i[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@track.webtrekk[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@imrworldwide[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@richmedia.yahoo[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@klempera.tripod[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ads.addynamix[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@chumtv.122.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ads.newtention[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@azjmp[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@clickaider[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@hitbox[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@list[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@shinystat[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@fr.sitestat[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@mapy.idnes[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@atdmt[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adinterax[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@zbox.zanox[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adserver.easyad[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@hmt.connexpromotions[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ads.guru3d[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ads.heias[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adbrite[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.acn-adserver[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.trackingcenter[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@media.adrevolver[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@topfunadult[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ehg-ati.hitbox[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@nissaneurope.112.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.bstats[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@questionmarket[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ehg-upcchellomedia.hitbox[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad-creatividades.infojobs[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@yadro[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@allesklarcomag.112.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@de.sitestat[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adfarm1.adition[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.mediatransfer[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@smartadserver[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ehg-nokiafin.hitbox[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@specificclick[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.porno-stranky[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.play[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@sevenoneintermedia.112.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adrevolver[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@edsa.122.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@goclick[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@adlegend[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@zedo[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.upspiral[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@divx.112.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.o2active[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@stats.viessmann[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@gemoney.112.2o7[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@eas.apm.emediate[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@partners.webmasterplan[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@realmedia[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ctrack.performance-media[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@indextools[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@2o7[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@tracker.cztorrent[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.gratiscounter[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.adnet[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@hg1.hitbox[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@porno-stranky[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.iqsys[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@fr.sitestat[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.mediabiz[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@estat[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@neostat[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad2.billboard[3].txt
C:\Documents and Settings\Tomas\Cookies\tomas@doubleclick[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.zanox-affiliate[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.googleadservices[6].txt
C:\Documents and Settings\Tomas\Cookies\tomas@fastclick[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.etracker[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ads.revsci[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@rambler[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.zanox[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.crazytomato[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@apmebf[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.googleadservices[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.googleadservices[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@www.digiinfo[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ad.adfox[1].txt
C:\Documents and Settings\Tomas\Cookies\tomas@banner.goldenpalacepoker[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ehg-ittoolbox.hitbox[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@revenue[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@media.adrevolver[3].txt
C:\Documents and Settings\Tomas\Cookies\tomas@burstnet[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@tripod[2].txt
C:\Documents and Settings\Tomas\Cookies\tomas@ads.netrealit[1].txt

Browser Hijacker.Deskbar
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 09 pro 2007 08:44

Ten soubor je v poště v Outlooku.

Pro lepší zabezpečení by bylo dobré si doinstalovat firewall, můžeš si vybrat některý zde uvedený nebo některý jiný z odkazu: Přehled osobních firewallů
Firewally zdarma:
Comodo - kvalitní, pokročilý, s mnoha funkcemi, originálně v angličtině
Kerio - přehledný, větší možnosti nastavení, náročnější na systémové prostředky, v češtině
ZoneAlarm - jednoduchý, kompatibilní, nenáročný na systémové prostředky, málo možností nastavení, v angličtině

Máš ještě problémy?

007tom
nováček
Příspěvky: 3
Registrován: prosinec 07
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod 007tom » 09 pro 2007 19:28

Je to v pořádku,děkuji mnohokrát


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 4 hosti