Poprosil bych o kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
pompeus50
Level 2.5
Level 2.5
Příspěvky: 263
Registrován: duben 07
Pohlaví: Muž
Stav:
Offline

Poprosil bych o kontrolu

Příspěvekod pompeus50 » 12 lis 2010 18:41

Předem děkuji

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:37:40, on 12.11.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\PROGRA~1\KYE\ERGOME~1\SyTray.exe
C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE
C:\windows\system32\RunDll32.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\windows\CTHELPER.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\windows\system32\CTsvcCDA.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\windows\System32\svchost.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\oodag.exe
C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\windows\system32\svchost.exe
C:\windows\system32\wuauclt.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\windows\system32\slidebar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Administrator\Dokumenty\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qip.ru/search?query=%s&from=IE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: hip hop Toolbar - {e646d4b1-fd71-4495-8a2e-566f93504fbe} - C:\Program Files\hip_hop\tbhip0.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\Program Files\Steam\UnDead.Injector.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\windows\WebIE.dll
O2 - BHO: UrlHelper Class - {6D023EBF-70B8-45A6-9ED5-556515FA0FE4} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: hip hop Toolbar - {e646d4b1-fd71-4495-8a2e-566f93504fbe} - C:\Program Files\hip_hop\tbhip0.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: hip hop Toolbar - {e646d4b1-fd71-4495-8a2e-566f93504fbe} - C:\Program Files\hip_hop\tbhip0.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\windows\WebIE.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BSMediaBar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [ErgoMedia] C:\PROGRA~1\KYE\ERGOME~1\SyTray.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [Zástupce stránky vlastností sběrnice High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TNOD UP] "C:\Program Files\TNod User & Password Finder\TNODUP.exe" /i
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Startup: zip.exe.lnk = C:\WINDOWS\system32\zip.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Administrator\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Administrator\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Přeložit - {230D1201-7607-4CF6-A11F-9E4BF0A333E0} - C:\Program Files\Verdict Free\etnxp.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Verdict Free\etnxp.dll
O9 - Extra 'Tools' menuitem: Internetový překladač... - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Verdict Free\etnxp.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\windows\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\windows\system32\shdocvw.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\windows\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\windows\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\windows\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\windows\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\windows\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\windows\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/ ... .2.100.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... b56986.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\windows\system32\CTsvcCDA.EXE
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 17010 bytes

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod memphisto » 12 lis 2010 19:25

No,není toho málo :smile:
odinstaluj:
Ask Toolbar
ICQ Toolbar
Hip hop Toolbar
Yahoo Toolbar
SWEET IM Toolbar
BearShare Media Bar
Spyware Terminátor


v logu fixni:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qip.ru/search?query=%s&from=IE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: hip hop Toolbar - {e646d4b1-fd71-4495-8a2e-566f93504fbe} - C:\Program Files\hip_hop\tbhip0.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\Program Files\Steam\UnDead.Injector.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: UrlHelper Class - {6D023EBF-70B8-45A6-9ED5-556515FA0FE4} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: hip hop Toolbar - {e646d4b1-fd71-4495-8a2e-566f93504fbe} - C:\Program Files\hip_hop\tbhip0.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: hip hop Toolbar - {e646d4b1-fd71-4495-8a2e-566f93504fbe} - C:\Program Files\hip_hop\tbhip0.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BSMediaBar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/ ... .2.100.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... b56986.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab


dej start - spustit - services.msc -najdi a ukonči/zakaž tyto služby:
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)


Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Vypni si rez.ochrany i firewall.
Stáhni si Dr. Web CureIt
dej update , po aktualizaci dej start.
Tlacitky dole muzeš soubor léčit(systémové soubory), smazat, přesunout nebo přejmenovat



Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
pompeus50
Level 2.5
Level 2.5
Příspěvky: 263
Registrován: duben 07
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod pompeus50 » 13 lis 2010 13:31

s počítačem se taky dlouho nic nedělalo :evil:

Log Malwarebytes' Anti-Malware


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 5102

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

13.11.2010 13:26:36
mbam-log-2010-11-13 (13-26-36).txt

Typ skenu: Rychlý sken
Skenované objekty: 155228
Uplynulý čas: 9 minuta(y), 25 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 51
Infikované hodnoty registru: 4
Infikované datové položky registru: 2
Infikované složky: 30
Infikované soubory: 329

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
HKEY_CLASSES_ROOT\Interface\{15fd8424-d12a-4c51-8c6c-d5d57b80f781} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2447e305-5e90-42a8-bd1e-0bc333b807e1} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2557dd3f-23a0-477c-bcd8-90fd0aecc4b8} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2893116c-a176-42b1-8794-da8c9fc45564} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3ceb04ab-08af-45f4-81b4-70d13c1f7b85} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{40ca90f3-4098-4877-ae87-23eb612b18c7} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{4c3b62af-ca25-4fba-8405-32e44f83bb6f} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{50d2fdcc-2707-49cb-8223-7fe0424909aa} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{5a635a91-c303-45c9-8db9-f759d98a3b9d} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{67b3becf-7b6f-42b2-99f0-f7656f89cffa} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{715ffd42-4e05-4eab-9513-c8daa5395ae2} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{759d6f7c-8d30-45b6-abea-fa51c190eed5} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7e335d04-2e6e-4d0e-a921-c3d9192e7121} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{878ce013-7ba9-4650-a78c-b2234c0c1648} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{8ee46f55-1ce1-4db9-811a-68938ec7f3dd} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{99ccfb8c-6380-4a14-8fdd-ef3e7e95335d} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{99fdca0c-7380-4e9c-8d99-5dc4750334ef} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{9a4a64a4-a2fb-48fa-9bba-1ac50267695d} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{a7213d71-47e1-4832-92d7-d61dfe9f231f} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{a87dfd99-cf81-4241-85ce-881e0026b686} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{b1d9f4b1-b9ff-463f-bf15-ab9cb26160f7} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{b20d7add-989c-4bc0-a797-f6fe7998efd7} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{bfc20a15-b0ac-44cc-a25a-a7039014ba9f} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{c96b9fae-a032-4100-bb47-32ef05e28be4} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{cf82f350-e1c4-4916-ac12-ba73db60afb7} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{f019aec4-4c95-46de-a107-e302473e3b9a} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8c788aa2-7530-43be-97b7-4d491f13bea3} (Adware.Softomate) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{03d7ff6e-9781-40b5-bb7f-94291a361604} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{0729f461-8054-47dc-8d39-a31b61cc0119} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{148e1447-c728-48fd-beec-a7d06c5fff58} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{8292078f-f6e9-412b-8eb1-360c05c5ece5} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{c62a9e79-2b52-439b-af57-2e60bb06e86c} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eddbb5ee-bb64-4bfc-9dbe-e7c85941335b} (Adware.Zango) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{69725738-cd68-4f36-8d02-8c43722ee5da} (Adware.Hotbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Zango (Adware.Zango) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\zangosa (Adware.Zango) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\zango (Adware.180Solutions) -> No action taken.

Infikované hodnoty registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\zango 10.3.65.0 (Adware.Zango) -> No action taken.

Infikované datové položky registru:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Infikované složky:
C:\Documents and Settings\All Users\Data aplikací\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\db (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\dwld (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\report (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\res1 (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\Data aplikací (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA (Adware.Hotbar) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA\Weather (Adware.Hotbar) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA\Weather\WeatherDPA (Adware.Hotbar) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA\Weather\WeatherDPA\Weather_XML (Adware.Hotbar) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\IESkins (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\HostOI (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\HostOI\dynamic (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\HostOL (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\HostOL\dynamic (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\ustat (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2) (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\ustat (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad (Adware.Zango) -> No action taken.

Infikované soubory:
C:\WINDOWS\system32\zip.exe (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\res1\WhiteList.dbs (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA\Weather\WeatherStartup.xml (Adware.Hotbar) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\1.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\218563.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\29527.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\3894588.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\675070.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\993316.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\domains.txt (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\1000029613 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\1000031138 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\1000048356 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\13562 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\148338 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\15473 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\20365 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\23352 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\242516 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\26656 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\282887 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\29115 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\30320 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\30438 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\306791 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\30710 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\31262 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\32122 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\32242 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\35150 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\388251 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\41225 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\41980 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\43220 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\44228 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\44458 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\460342 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\47468 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\482360 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\491899 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\496386 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\50730 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\50887 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\53481 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\54473 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\56258 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\592052 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\599520 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\6301 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\63770 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\64701 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\6580 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\67464 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\67466 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\6873 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\69635 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\737665 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\77468 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\90008 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\93899 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\93997 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\94430 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\94469 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\97900 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\99163 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\99586 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\ustat\36de.dat (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\1.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\218563.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\3340762.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\3852296.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\3894588.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\993316.sdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\domains.txt (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\1000031530 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\1000047588 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\1000048356 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\10587 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\13562 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\1491 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\162365 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\168167 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\18383 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\20304 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\22335 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\23352 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\24296 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\247895 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\250993 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\26656 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\26913 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\29115 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\29216 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\297534 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\32122 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\32242 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\32290 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\34374 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\35006 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\359772 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\403305 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\42208 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\43719 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\44228 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\44458 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\46385 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\4763 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\482360 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\484453 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\496386 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\51495 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\52335 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\53481 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\540152 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\54473 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\557574 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\585345 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\592052 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\608 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\61642 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6304 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6546 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6580 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\67215 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6873 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6915 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\69635 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\71340 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\73514 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\737665 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\738022 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\744478 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\744922 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\745254 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\745269 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\745313 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\746529 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\746883 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\748368 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\748685 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\748880 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\7492 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753300 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753309 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753350 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753356 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753360 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\79246 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\800 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\80663 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\81995 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\88578 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\93899 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\94430 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\95825 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\99163 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\998 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\9994 (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\ustat\36aa.dat (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\avatar.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\btntrans.idx (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\btntrans1.dat (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\buttondir.txt (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\components.cdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\cursors.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\default.cdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_511745-514279.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-ca.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-us.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_categorize.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_comparison.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_explorer-Mails.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_explorer-people.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_favorites.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_Games.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_Hide.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_hotbarcom.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_Hotmail.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_hsskin.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_jemster.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_jemsterie.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_jemsteruk.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_jobsearch.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_Mails.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_MobileSidewalk.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_new.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_premium.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_reun.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_ringtones.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_SearchBoxTrapper.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_searchfor.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_searchgo.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_weather.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_yellowpages.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_1000.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_2000.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_3000.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_bar.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_bbar1.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_logos.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_other.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_weather.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\editblbuttons.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\email-def-511724-548964.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\email-def-511724-9595.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\email-t1-bg.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\icons2.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\ie_games_icon.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\ie_video.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\keywords.idx (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\keywords1.dat (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\layout.cdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\linkpathlegal.txt (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\progress.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\sales_buttons.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\sdfmodifier.xml (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\s_icons_buttons.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\t2_bg.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\theweb.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\top7.cdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Top7_theweb.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\tsd_bg.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\zango_btn.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\zango_ie_menu.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\avatar.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\btntrans.idx (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\btntrans1.dat (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\buttondir.txt (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\components.cdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\cursors.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\default.cdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_511745-514279.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_bidzC_ZT_IE-ca.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_bidzC_ZT_IE-us.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_categorize.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_comparison.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_explorer-Mails.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_explorer-people.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_favorites.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_Games.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_Hide.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_hotbarcom.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_Hotmail.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_hsskin.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_jemster.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_jemsterie.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_jemsteruk.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_jobsearch.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_Mails.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_MobileSidewalk.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_new.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_premium.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_reun.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_ringtones.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_SearchBoxTrapper.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_searchfor.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_searchgo.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_weather.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_yellowpages.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_1000.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_2000.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_3000.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_bar.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_bbar1.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_logos.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_other.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_weather.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\editblbuttons.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\email-def-511724-548964.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\email-def-511724-9595.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\email-t1-bg.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\icons2.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\ie_games_icon.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\ie_video.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\keywords.idx (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\keywords1.dat (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\layout.cdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\linkpathlegal.txt (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\progress.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\sales_buttons.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\sdfmodifier.xml (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\s_icons_buttons.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\t2_bg.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\theweb.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\top7.cdf (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Top7_theweb.mnu (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\tsd_bg.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\zango_btn.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\zango_ie_menu.res (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\avatar.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\buttondir.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\cursors.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\default.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\icons2.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\ie_video.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\keywords.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\keywords1.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\layout.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\progress.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\samplegroups2.txt (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\top7.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip (Adware.Zango) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip (Adware.Zango) -> No action taken.
C:\WINDOWS\system32\8_exception.nls (Trojan.Tibs) -> No action taken.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod jaro3 » 13 lis 2010 14:18

. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit

Můžeš sem pak vložit nový log z MbAM.

Stáhni si TDSSKiller

Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
pompeus50
Level 2.5
Level 2.5
Příspěvky: 263
Registrován: duben 07
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod pompeus50 » 13 lis 2010 16:15

log z MbAM
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 5102

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

13.11.2010 15:49:45
mbam-log-2010-11-13 (15-49-45).txt

Typ skenu: Rychlý sken
Skenované objekty: 155462
Uplynulý čas: 13 minuta(y), 25 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 51
Infikované hodnoty registru: 4
Infikované datové položky registru: 2
Infikované složky: 30
Infikované soubory: 329

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
HKEY_CLASSES_ROOT\Interface\{15fd8424-d12a-4c51-8c6c-d5d57b80f781} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2447e305-5e90-42a8-bd1e-0bc333b807e1} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2557dd3f-23a0-477c-bcd8-90fd0aecc4b8} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2893116c-a176-42b1-8794-da8c9fc45564} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3ceb04ab-08af-45f4-81b4-70d13c1f7b85} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{40ca90f3-4098-4877-ae87-23eb612b18c7} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4c3b62af-ca25-4fba-8405-32e44f83bb6f} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{50d2fdcc-2707-49cb-8223-7fe0424909aa} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5a635a91-c303-45c9-8db9-f759d98a3b9d} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{67b3becf-7b6f-42b2-99f0-f7656f89cffa} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{715ffd42-4e05-4eab-9513-c8daa5395ae2} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{759d6f7c-8d30-45b6-abea-fa51c190eed5} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7e335d04-2e6e-4d0e-a921-c3d9192e7121} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{878ce013-7ba9-4650-a78c-b2234c0c1648} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8ee46f55-1ce1-4db9-811a-68938ec7f3dd} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{99ccfb8c-6380-4a14-8fdd-ef3e7e95335d} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{99fdca0c-7380-4e9c-8d99-5dc4750334ef} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9a4a64a4-a2fb-48fa-9bba-1ac50267695d} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a7213d71-47e1-4832-92d7-d61dfe9f231f} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a87dfd99-cf81-4241-85ce-881e0026b686} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b1d9f4b1-b9ff-463f-bf15-ab9cb26160f7} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b20d7add-989c-4bc0-a797-f6fe7998efd7} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bfc20a15-b0ac-44cc-a25a-a7039014ba9f} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c96b9fae-a032-4100-bb47-32ef05e28be4} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf82f350-e1c4-4916-ac12-ba73db60afb7} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f019aec4-4c95-46de-a107-e302473e3b9a} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8c788aa2-7530-43be-97b7-4d491f13bea3} (Adware.Softomate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{03d7ff6e-9781-40b5-bb7f-94291a361604} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{0729f461-8054-47dc-8d39-a31b61cc0119} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{148e1447-c728-48fd-beec-a7d06c5fff58} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8292078f-f6e9-412b-8eb1-360c05c5ece5} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c62a9e79-2b52-439b-af57-2e60bb06e86c} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eddbb5ee-bb64-4bfc-9dbe-e7c85941335b} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{69725738-cd68-4f36-8d02-8c43722ee5da} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Zango (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\zangosa (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\zango (Adware.180Solutions) -> Quarantined and deleted successfully.

Infikované hodnoty registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\zango 10.3.65.0 (Adware.Zango) -> Quarantined and deleted successfully.

Infikované datové položky registru:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infikované složky:
C:\Documents and Settings\All Users\Data aplikací\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\db (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\dwld (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\report (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\res1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\Data aplikací (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA\Weather (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA\Weather\WeatherDPA (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA\Weather\WeatherDPA\Weather_XML (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\IESkins (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\HostOI (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\HostOI\dynamic (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\HostOL (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\HostOL\dynamic (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\ustat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2) (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\ustat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad (Adware.Zango) -> Quarantined and deleted successfully.

Infikované soubory:
C:\WINDOWS\system32\zip.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\ShoppingReport\cs\res1\WhiteList.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\WeatherDPA\Weather\WeatherStartup.xml (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\1.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\218563.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\29527.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\3894588.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\675070.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\993316.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\domains.txt (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\1000029613 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\1000031138 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\1000048356 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\13562 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\148338 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\15473 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\20365 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\23352 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\242516 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\26656 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\282887 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\29115 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\30320 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\30438 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\306791 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\30710 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\31262 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\32122 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\32242 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\35150 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\388251 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\41225 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\41980 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\43220 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\44228 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\44458 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\460342 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\47468 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\482360 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\491899 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\496386 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\50730 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\50887 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\53481 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\54473 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\56258 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\592052 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\599520 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\6301 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\63770 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\64701 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\6580 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\67464 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\67466 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\6873 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\69635 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\737665 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\77468 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\90008 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\93899 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\93997 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\94430 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\94469 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\97900 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\99163 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\TooltipXML\99586 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic\ustat\36de.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\1.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\218563.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\3340762.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\3852296.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\3894588.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\993316.sdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\domains.txt (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\1000031530 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\1000047588 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\1000048356 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\10587 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\13562 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\1491 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\162365 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\168167 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\18383 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\20304 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\22335 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\23352 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\24296 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\247895 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\250993 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\26656 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\26913 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\29115 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\29216 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\297534 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\32122 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\32242 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\32290 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\34374 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\35006 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\359772 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\403305 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\42208 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\43719 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\44228 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\44458 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\46385 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\4763 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\482360 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\484453 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\496386 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\51495 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\52335 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\53481 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\540152 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\54473 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\557574 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\585345 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\592052 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\608 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\61642 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6304 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6546 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6580 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\67215 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6873 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\6915 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\69635 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\71340 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\73514 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\737665 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\738022 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\744478 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\744922 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\745254 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\745269 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\745313 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\746529 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\746883 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\748368 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\748685 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\748880 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\7492 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753300 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753309 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753350 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753356 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\753360 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\79246 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\800 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\80663 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\81995 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\88578 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\93899 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\94430 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\95825 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\99163 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\998 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\TooltipXML\9994 (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\dynamic(2)\ustat\36aa.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\avatar.res (Adware.Zango) -> Quarantined and deleted successfully.

Uživatelský avatar
pompeus50
Level 2.5
Level 2.5
Příspěvky: 263
Registrován: duben 07
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod pompeus50 » 13 lis 2010 16:15

C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\btntrans.idx (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\btntrans1.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\buttondir.txt (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\components.cdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\cursors.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\default.cdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_511745-514279.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-ca.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-us.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_categorize.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_comparison.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_explorer-Mails.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_explorer-people.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_favorites.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_Games.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_Hide.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_hotbarcom.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_Hotmail.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_hsskin.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_jemster.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_jemsterie.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_jemsteruk.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_jobsearch.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_Mails.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_MobileSidewalk.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_new.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_premium.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_reun.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_ringtones.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_SearchBoxTrapper.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_searchfor.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_searchgo.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_weather.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Default_yellowpages.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_1000.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_2000.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_3000.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_bar.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_bbar1.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_logos.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_buttons_other.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\d_icons_weather.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\editblbuttons.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\email-def-511724-548964.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\email-def-511724-9595.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\email-t1-bg.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\icons2.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\ie_games_icon.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\ie_video.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\keywords.idx (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\keywords1.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\layout.cdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\linkpathlegal.txt (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\progress.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\sales_buttons.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\sdfmodifier.xml (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\s_icons_buttons.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\t2_bg.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\theweb.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\top7.cdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\Top7_theweb.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\tsd_bg.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\zango_btn.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\1\zango_ie_menu.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\avatar.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\btntrans.idx (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\btntrans1.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\buttondir.txt (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\components.cdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\cursors.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\default.cdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_511745-514279.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_bidzC_ZT_IE-ca.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_bidzC_ZT_IE-us.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_categorize.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_comparison.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_explorer-Mails.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_explorer-people.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_favorites.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_Games.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_Hide.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_hotbarcom.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_Hotmail.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_hsskin.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_jemster.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_jemsterie.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_jemsteruk.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_jobsearch.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_Mails.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_MobileSidewalk.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_new.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_premium.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_reun.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_ringtones.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_SearchBoxTrapper.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_searchfor.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_searchgo.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_weather.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Default_yellowpages.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_1000.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_2000.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_3000.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_bar.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_bbar1.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_logos.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_buttons_other.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\d_icons_weather.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\editblbuttons.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\email-def-511724-548964.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\email-def-511724-9595.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\email-t1-bg.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\icons2.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\ie_games_icon.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\ie_video.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\keywords.idx (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\keywords1.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\layout.cdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\linkpathlegal.txt (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\progress.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\sales_buttons.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\sdfmodifier.xml (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\s_icons_buttons.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\t2_bg.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\theweb.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\top7.cdf (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\Top7_theweb.mnu (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\tsd_bg.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\zango_btn.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\2\zango_ie_menu.res (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\avatar.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\buttondir.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\cursors.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\default.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\icons2.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\ie_video.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\keywords.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\keywords1.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\layout.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\progress.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\samplegroups2.txt (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\top7.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip (Adware.Zango) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\8_exception.nls (Trojan.Tibs) -> Quarantined and deleted successfully.

Uživatelský avatar
pompeus50
Level 2.5
Level 2.5
Příspěvky: 263
Registrován: duben 07
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod pompeus50 » 13 lis 2010 16:16

log z TDSSKiller

2010/11/13 16:02:56.0062 TDSS rootkit removing tool 2.4.7.0 Nov 8 2010 10:52:22
2010/11/13 16:02:56.0062 ================================================================================
2010/11/13 16:02:56.0062 SystemInfo:
2010/11/13 16:02:56.0062
2010/11/13 16:02:56.0062 OS Version: 5.1.2600 ServicePack: 2.0
2010/11/13 16:02:56.0062 Product type: Workstation
2010/11/13 16:02:56.0062 ComputerName: LADISLAV
2010/11/13 16:02:56.0062 UserName: Administrator
2010/11/13 16:02:56.0062 Windows directory: C:\windows
2010/11/13 16:02:56.0062 System windows directory: C:\windows
2010/11/13 16:02:56.0062 Processor architecture: Intel x86
2010/11/13 16:02:56.0062 Number of processors: 2
2010/11/13 16:02:56.0062 Page size: 0x1000
2010/11/13 16:02:56.0062 Boot type: Normal boot
2010/11/13 16:02:56.0062 ================================================================================
2010/11/13 16:02:57.0031 Initialize success
2010/11/13 16:03:03.0953 ================================================================================
2010/11/13 16:03:03.0953 Scan started
2010/11/13 16:03:03.0953 Mode: Manual;
2010/11/13 16:03:03.0953 ================================================================================
2010/11/13 16:03:04.0750 ACPI (fa2fbcda96d2385f773b059fe5a125a6) C:\windows\system32\DRIVERS\ACPI.sys
2010/11/13 16:03:04.0796 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\windows\system32\drivers\ACPIEC.sys
2010/11/13 16:03:04.0859 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\windows\system32\drivers\adfs.sys
2010/11/13 16:03:04.0937 aec (1ee7b434ba961ef845de136224c30fec) C:\windows\system32\drivers\aec.sys
2010/11/13 16:03:04.0984 Afc (fe3ea6e9afc1a78e6edca121e006afb7) C:\windows\system32\drivers\Afc.sys
2010/11/13 16:03:05.0031 AFD (55e6e1c51b6d30e54335750955453702) C:\windows\System32\drivers\afd.sys
2010/11/13 16:03:05.0218 AsyncMac (02000abf34af4c218c35d257024807d6) C:\windows\system32\DRIVERS\asyncmac.sys
2010/11/13 16:03:05.0281 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\windows\system32\DRIVERS\atapi.sys
2010/11/13 16:03:05.0453 ati2mtag (15b2fe76e2eceb98c49ed52311a6f26f) C:\windows\system32\DRIVERS\ati2mtag.sys
2010/11/13 16:03:05.0609 ATIAVAIW (fed003fd00011946b0e4f8fb7a8b4307) C:\windows\system32\DRIVERS\atinavt2.sys
2010/11/13 16:03:05.0687 atinevxx (0587c82711ca059ff71e040a4c028551) C:\windows\system32\DRIVERS\atinevxx.sys
2010/11/13 16:03:05.0750 atksgt (3c4b9850a2631c2263507400d029057b) C:\windows\system32\DRIVERS\atksgt.sys
2010/11/13 16:03:05.0875 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\windows\system32\DRIVERS\atmarpc.sys
2010/11/13 16:03:05.0937 audstub (d9f724aa26c010a217c97606b160ed68) C:\windows\system32\DRIVERS\audstub.sys
2010/11/13 16:03:05.0968 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\windows\system32\drivers\Beep.sys
2010/11/13 16:03:06.0015 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\windows\system32\drivers\cbidf2k.sys
2010/11/13 16:03:06.0046 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\windows\system32\DRIVERS\CCDECODE.sys
2010/11/13 16:03:06.0093 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\windows\system32\drivers\Cdaudio.sys
2010/11/13 16:03:06.0109 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\windows\system32\drivers\Cdfs.sys
2010/11/13 16:03:06.0156 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\windows\system32\DRIVERS\cdrom.sys
2010/11/13 16:03:06.0265 cmudax (d7fcada6833a0e243ca89c03bd559bd9) C:\windows\system32\drivers\cmudax.sys
2010/11/13 16:03:06.0390 ctac32k (fb06bb39860340c6fa84867f0288d1dd) C:\windows\system32\drivers\ctac32k.sys
2010/11/13 16:03:06.0546 ctaud2k (b810fa12cf726b200e057834eaebb1ac) C:\windows\system32\drivers\ctaud2k.sys
2010/11/13 16:03:06.0656 ctdvda2k (c4333325d325efa668888d0d3177c6ff) C:\windows\system32\drivers\ctdvda2k.sys
2010/11/13 16:03:06.0734 ctprxy2k (1fa95c8cf34b9911e352a07ea7a200fc) C:\windows\system32\drivers\ctprxy2k.sys
2010/11/13 16:03:06.0765 ctsfm2k (400cb754b91f73bee2655686a57269d2) C:\windows\system32\drivers\ctsfm2k.sys
2010/11/13 16:03:06.0890 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\windows\system32\DRIVERS\disk.sys
2010/11/13 16:03:06.0953 dmboot (e1968edec81c430108feb23ab07bdb14) C:\windows\system32\drivers\dmboot.sys
2010/11/13 16:03:07.0078 dmio (1b1520a82e396e46b9ae9fa6b03ff6c6) C:\windows\system32\drivers\dmio.sys
2010/11/13 16:03:07.0125 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\windows\system32\drivers\dmload.sys
2010/11/13 16:03:07.0156 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\windows\system32\drivers\DMusic.sys
2010/11/13 16:03:07.0203 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\windows\system32\drivers\drmkaud.sys
2010/11/13 16:03:07.0265 eamon (ba3bb79c859292c3ff2a21b05e64696f) C:\windows\system32\DRIVERS\eamon.sys
2010/11/13 16:03:07.0406 ehdrv (3c747a0d8ce29720302972ac6ed09733) C:\windows\system32\DRIVERS\ehdrv.sys
2010/11/13 16:03:07.0468 emupia (7bb488ec082d40645936d9e583f560dc) C:\windows\system32\drivers\emupia2k.sys
2010/11/13 16:03:07.0578 enodpl (b4556f3d468c8dcb0b259d9d866cd4c4) C:\windows\system32\drivers\enodpl.sys
2010/11/13 16:03:07.0671 ENTECH (fd9fc82f134b1c91004ffc76a5ae494b) C:\WINDOWS\system32\DRIVERS\ENTECH.sys
2010/11/13 16:03:07.0718 epfwtdir (c24fae2e95936bb8f0d4941c329cc663) C:\windows\system32\DRIVERS\epfwtdir.sys
2010/11/13 16:03:07.0765 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\windows\system32\drivers\Fastfat.sys
2010/11/13 16:03:07.0796 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\windows\system32\DRIVERS\fdc.sys
2010/11/13 16:03:07.0843 FileDisk (0694585d54bf46379ce41aee2b6864aa) C:\windows\system32\drivers\FileDisk.sys
2010/11/13 16:03:07.0859 Fips (266dab58619b17bdf37fabbd48d875ca) C:\windows\system32\drivers\Fips.sys
2010/11/13 16:03:07.0906 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\windows\system32\DRIVERS\flpydisk.sys
2010/11/13 16:03:07.0937 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\windows\system32\DRIVERS\fltMgr.sys
2010/11/13 16:03:07.0984 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\windows\system32\drivers\Fs_Rec.sys
2010/11/13 16:03:08.0031 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\windows\system32\DRIVERS\ftdisk.sys
2010/11/13 16:03:08.0187 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\Drivers\GEARAspiWDM.sys
2010/11/13 16:03:08.0265 genmcmnUSB (eefdac90ad97953e40d9c6df09bdd998) C:\windows\system32\DRIVERS\gflmouhid.sys
2010/11/13 16:03:08.0296 gHidUsbF (9cf80399391b39683f2c81bbb21f6edc) C:\windows\system32\Drivers\gHidUsbF.Sys
2010/11/13 16:03:08.0312 Gpc (c0f1d4a21de5a415df8170616703debf) C:\windows\system32\DRIVERS\msgpc.sys
2010/11/13 16:03:08.0375 ha10kx2k (9bb84b1dff8bce7fdddea746f6819fcf) C:\windows\system32\drivers\ha10kx2k.sys
2010/11/13 16:03:08.0484 hamachi (7929a161f9951d173ca9900fe7067391) C:\windows\system32\DRIVERS\hamachi.sys
2010/11/13 16:03:08.0515 hap16v2k (1418833169b29780fbdab127623b8767) C:\windows\system32\drivers\hap16v2k.sys
2010/11/13 16:03:08.0562 hap17v2k (8b3148391dc121d96d513785d588e75b) C:\windows\system32\drivers\hap17v2k.sys
2010/11/13 16:03:08.0625 HdAudAddService (2a013e7530beab6e569faa83f517e836) C:\windows\system32\drivers\HdAudio.sys
2010/11/13 16:03:08.0656 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\windows\system32\DRIVERS\HDAudBus.sys
2010/11/13 16:03:08.0703 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\windows\system32\DRIVERS\hidusb.sys
2010/11/13 16:03:08.0750 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\windows\system32\Drivers\HTTP.sys
2010/11/13 16:03:08.0828 i8042prt (0f42de9909b5dbf2c48dd1a79d491af5) C:\windows\system32\DRIVERS\i8042prt.sys
2010/11/13 16:03:08.0875 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\windows\system32\DRIVERS\imapi.sys
2010/11/13 16:03:09.0046 IntelIde (ef4fda4841001a4b98c411797db8894a) C:\windows\system32\DRIVERS\intelide.sys
2010/11/13 16:03:09.0125 intelppm (10a3ac0f0df720ad3c3fd13861d50eb9) C:\windows\system32\DRIVERS\intelppm.sys
2010/11/13 16:03:09.0187 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\windows\system32\DRIVERS\ipfltdrv.sys
2010/11/13 16:03:09.0218 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\windows\system32\DRIVERS\ipinip.sys
2010/11/13 16:03:09.0265 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\windows\system32\DRIVERS\ipnat.sys
2010/11/13 16:03:09.0343 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\windows\system32\DRIVERS\ipsec.sys
2010/11/13 16:03:09.0390 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\windows\system32\DRIVERS\irenum.sys
2010/11/13 16:03:09.0421 isapnp (1091528512e4dd7ed5fddcc4df1c53d7) C:\windows\system32\DRIVERS\isapnp.sys
2010/11/13 16:03:09.0437 Kbdclass (6f877bf8dc01a550cd666f3bedb2213c) C:\windows\system32\DRIVERS\kbdclass.sys
2010/11/13 16:03:09.0484 kbdhid (065b5a83aa78c0c7047bf22e0ab5c821) C:\windows\system32\DRIVERS\kbdhid.sys
2010/11/13 16:03:09.0531 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\windows\system32\drivers\kmixer.sys
2010/11/13 16:03:09.0578 KSecDD (674d3e5a593475915dc6643317192403) C:\windows\system32\drivers\KSecDD.sys
2010/11/13 16:03:09.0765 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\windows\system32\DRIVERS\lirsgt.sys
2010/11/13 16:03:09.0812 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\windows\system32\drivers\mnmdd.sys
2010/11/13 16:03:09.0906 Modem (60210deb037846afe521ebf349964f6b) C:\windows\system32\drivers\Modem.sys
2010/11/13 16:03:09.0937 Mouclass (b160ec94114715675509115986400fd9) C:\windows\system32\DRIVERS\mouclass.sys
2010/11/13 16:03:09.0968 mouhid (bb269eba740737ab749b214d568b6812) C:\windows\system32\DRIVERS\mouhid.sys
2010/11/13 16:03:09.0984 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\windows\system32\drivers\MountMgr.sys
2010/11/13 16:03:10.0031 MPE (55a9a7e6bb297bf0f5b144029dcb79cc) C:\windows\system32\DRIVERS\MPE.sys
2010/11/13 16:03:10.0125 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\windows\system32\DRIVERS\mrxdav.sys
2010/11/13 16:03:10.0171 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\windows\system32\DRIVERS\mrxsmb.sys
2010/11/13 16:03:10.0250 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\windows\system32\drivers\Msfs.sys
2010/11/13 16:03:10.0281 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\windows\system32\drivers\MSKSSRV.sys
2010/11/13 16:03:10.0312 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\windows\system32\drivers\MSPCLOCK.sys
2010/11/13 16:03:10.0328 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\windows\system32\drivers\MSPQM.sys
2010/11/13 16:03:10.0375 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\windows\system32\DRIVERS\mssmbios.sys
2010/11/13 16:03:10.0390 MSTEE (bf13612142995096ab084f2db7f40f77) C:\windows\system32\drivers\MSTEE.sys
2010/11/13 16:03:10.0515 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\windows\system32\DRIVERS\ASACPI.sys
2010/11/13 16:03:10.0562 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\windows\system32\drivers\Mup.sys
2010/11/13 16:03:10.0625 MVDCODEC (e8cd09352958d84869a6cbf2e4b50111) C:\windows\system32\DRIVERS\atinmdxx.sys
2010/11/13 16:03:10.0718 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\windows\system32\DRIVERS\NABTSFEC.sys
2010/11/13 16:03:10.0812 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\windows\system32\drivers\NDIS.sys
2010/11/13 16:03:10.0859 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\windows\system32\DRIVERS\NdisIP.sys
2010/11/13 16:03:10.0890 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\windows\system32\DRIVERS\ndistapi.sys
2010/11/13 16:03:10.0953 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\windows\system32\DRIVERS\ndisuio.sys
2010/11/13 16:03:11.0000 NdisWan (0b90e255a9490166ab368cd55a529893) C:\windows\system32\DRIVERS\ndiswan.sys
2010/11/13 16:03:11.0046 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\windows\system32\drivers\NDProxy.sys
2010/11/13 16:03:11.0062 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\windows\system32\DRIVERS\netbios.sys
2010/11/13 16:03:11.0109 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\windows\system32\DRIVERS\netbt.sys
2010/11/13 16:03:11.0187 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\windows\system32\drivers\Npfs.sys
2010/11/13 16:03:11.0234 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\windows\system32\drivers\Ntfs.sys
2010/11/13 16:03:11.0390 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\windows\system32\drivers\Null.sys
2010/11/13 16:03:11.0437 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\windows\system32\DRIVERS\nwlnkflt.sys
2010/11/13 16:03:11.0468 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\windows\system32\DRIVERS\nwlnkfwd.sys
2010/11/13 16:03:11.0531 ossrv (01e1ab8249f9dde5978c6b4af18eda7c) C:\windows\system32\drivers\ctoss2k.sys
2010/11/13 16:03:11.0609 ovt530 (71cffb1e06aa8978a7b4a346c191f8ba) C:\windows\system32\Drivers\ov530vid.sys
2010/11/13 16:03:11.0687 Parport (76a18caa2fefb28a4ced38d76837e86e) C:\windows\system32\DRIVERS\parport.sys
2010/11/13 16:03:11.0718 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\windows\system32\drivers\PartMgr.sys
2010/11/13 16:03:11.0765 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\windows\system32\drivers\ParVdm.sys
2010/11/13 16:03:11.0828 PCI (b7979f37bb7b9df2230046134955e6e7) C:\windows\system32\DRIVERS\pci.sys
2010/11/13 16:03:11.0875 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\windows\system32\DRIVERS\pciide.sys
2010/11/13 16:03:11.0921 Pcmcia (90505755634407d4ef4c6dea60fc1df9) C:\windows\system32\drivers\Pcmcia.sys
2010/11/13 16:03:11.0968 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\windows\system32\Drivers\pcouffin.sys
2010/11/13 16:03:12.0125 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\windows\system32\DRIVERS\raspptp.sys
2010/11/13 16:03:12.0156 prodrv06 (f0801ae96bf679a3dba23d48ba74a98f) C:\windows\System32\drivers\prodrv06.sys
2010/11/13 16:03:12.0203 prohlp02 (2409b32e691cb5dda39ea40bd154a50b) C:\windows\system32\drivers\prohlp02.sys
2010/11/13 16:03:12.0328 PSched (48671f327553dcf1d27f6197f622a668) C:\windows\system32\DRIVERS\psched.sys
2010/11/13 16:03:12.0359 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\windows\system32\DRIVERS\ptilink.sys
2010/11/13 16:03:12.0484 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\windows\system32\DRIVERS\rasacd.sys
2010/11/13 16:03:12.0515 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\windows\system32\DRIVERS\rasl2tp.sys
2010/11/13 16:03:12.0562 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\windows\system32\DRIVERS\raspppoe.sys
2010/11/13 16:03:12.0578 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\windows\system32\DRIVERS\raspti.sys
2010/11/13 16:03:12.0625 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\windows\system32\DRIVERS\rdbss.sys
2010/11/13 16:03:12.0687 RDPCDD (4912d5b403614ce99c28420f75353332) C:\windows\system32\DRIVERS\RDPCDD.sys
2010/11/13 16:03:12.0750 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\windows\system32\DRIVERS\rdpdr.sys
2010/11/13 16:03:12.0812 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\windows\system32\drivers\RDPWD.sys
2010/11/13 16:03:12.0859 redbook (aba13d33e1f888c9a68599a48a8840d6) C:\windows\system32\DRIVERS\redbook.sys
2010/11/13 16:03:12.0937 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\DRIVERS\secdrv.sys
2010/11/13 16:03:13.0000 Ser2pl (b490ad520257dda26c1d587a71e527b5) C:\windows\system32\DRIVERS\ser2pl.sys
2010/11/13 16:03:13.0031 serenum (a2d868aeeff612e70e213c451a70cafb) C:\windows\system32\DRIVERS\serenum.sys
2010/11/13 16:03:13.0046 Serial (c1ddbc85251551a840212999da3d95f3) C:\windows\system32\DRIVERS\serial.sys
2010/11/13 16:03:13.0109 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\windows\system32\drivers\sfdrv01.sys
2010/11/13 16:03:13.0140 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\windows\system32\drivers\sfhlp01.sys
2010/11/13 16:03:13.0265 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\windows\system32\drivers\sfhlp02.sys
2010/11/13 16:03:13.0296 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\windows\system32\drivers\Sfloppy.sys
2010/11/13 16:03:13.0343 sfsync02 (798d918d8f20380008277ce3ce5319d1) C:\windows\system32\drivers\sfsync02.sys
2010/11/13 16:03:13.0437 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) C:\windows\system32\drivers\sfvfs02.sys
2010/11/13 16:03:13.0515 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\windows\system32\DRIVERS\SLIP.sys
2010/11/13 16:03:13.0609 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\windows\system32\drivers\splitter.sys
2010/11/13 16:03:13.0718 sptd (d390675b8ce45e5fb359338e5e649329) C:\windows\system32\Drivers\sptd.sys
2010/11/13 16:03:13.0718 Suspicious file (NoAccess): C:\windows\system32\Drivers\sptd.sys. md5: d390675b8ce45e5fb359338e5e649329
2010/11/13 16:03:13.0718 sptd - detected Locked file (1)
2010/11/13 16:03:13.0765 sp_rsdrv2 (ccd6e6c387e3efa3ba5fe0e7883821c1) C:\windows\system32\drivers\sp_rsdrv2.sys
2010/11/13 16:03:13.0828 sr (a74035ea526db97d9d50d2143a55f5cf) C:\windows\system32\DRIVERS\sr.sys
2010/11/13 16:03:13.0906 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\windows\system32\DRIVERS\srv.sys
2010/11/13 16:03:14.0046 streamip (284c57df5dc7abca656bc2b96a667afb) C:\windows\system32\DRIVERS\StreamIP.sys
2010/11/13 16:03:14.0093 swenum (03c1bae4766e2450219d20b993d6e046) C:\windows\system32\DRIVERS\swenum.sys
2010/11/13 16:03:14.0125 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\windows\system32\drivers\swmidi.sys
2010/11/13 16:03:14.0296 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\windows\system32\drivers\sysaudio.sys
2010/11/13 16:03:14.0312 tandpl (126d7b3b4c7b724491c604060e1f4e14) C:\windows\system32\drivers\tandpl.sys
2010/11/13 16:03:14.0375 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\windows\system32\DRIVERS\tcpip.sys
2010/11/13 16:03:14.0421 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\windows\system32\drivers\TDPIPE.sys
2010/11/13 16:03:14.0484 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\windows\system32\drivers\TDTCP.sys
2010/11/13 16:03:14.0531 TermDD (a540a99c281d933f3d69d55e48727f47) C:\windows\system32\DRIVERS\termdd.sys
2010/11/13 16:03:14.0640 Udfs (12f70256f140cd7d52c58c7048fde657) C:\windows\system32\drivers\Udfs.sys
2010/11/13 16:03:14.0703 Update (ced744117e91bdc0beb810f7d8608183) C:\windows\system32\DRIVERS\update.sys
2010/11/13 16:03:14.0750 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\windows\system32\Drivers\usbaapl.sys
2010/11/13 16:03:14.0890 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\windows\system32\drivers\usbaudio.sys
2010/11/13 16:03:14.0906 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\windows\system32\DRIVERS\usbccgp.sys
2010/11/13 16:03:14.0953 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\windows\system32\DRIVERS\usbehci.sys
2010/11/13 16:03:15.0031 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\windows\system32\DRIVERS\usbhub.sys
2010/11/13 16:03:15.0078 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\windows\system32\DRIVERS\usbscan.sys
2010/11/13 16:03:15.0125 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\windows\system32\DRIVERS\USBSTOR.SYS
2010/11/13 16:03:15.0187 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\windows\system32\DRIVERS\usbuhci.sys
2010/11/13 16:03:15.0250 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\windows\System32\drivers\vga.sys
2010/11/13 16:03:15.0312 VolSnap (cd8cce067f7e9cbd762c00bdddecaa34) C:\windows\system32\drivers\VolSnap.sys
2010/11/13 16:03:15.0359 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\windows\system32\DRIVERS\wanarp.sys
2010/11/13 16:03:15.0437 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\windows\system32\drivers\wdmaud.sys
2010/11/13 16:03:15.0546 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\windows\system32\DRIVERS\wpdusb.sys
2010/11/13 16:03:15.0609 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\windows\System32\drivers\ws2ifsl.sys
2010/11/13 16:03:15.0750 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\windows\system32\DRIVERS\WSTCODEC.SYS
2010/11/13 16:03:15.0796 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\windows\system32\DRIVERS\WudfPf.sys
2010/11/13 16:03:15.0828 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\windows\system32\DRIVERS\wudfrd.sys
2010/11/13 16:03:15.0937 YiRuanUSB (facac3b0c14d0d4980a7eaac5362535e) C:\windows\system32\DRIVERS\yrtumdriver.sys
2010/11/13 16:03:15.0984 yukonwxp (e279c4e1287751dffa0a1f3ec4097491) C:\windows\system32\DRIVERS\yk51x86.sys
2010/11/13 16:03:16.0187 ================================================================================
2010/11/13 16:03:16.0187 Scan finished
2010/11/13 16:03:16.0187 ================================================================================
2010/11/13 16:03:16.0203 Detected object count: 1
2010/11/13 16:03:23.0140 Locked file(sptd) - User select action: Skip


uff je toho moc :roll: :D

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod jaro3 » 14 lis 2010 09:50

TDSSKiller---smaž.

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
pompeus50
Level 2.5
Level 2.5
Příspěvky: 263
Registrován: duben 07
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod pompeus50 » 14 lis 2010 13:38

rezidentní ochrany už sem zapl

ComboFix 10-11-12.06 - Administrator 14.11.2010 13:12:22.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.420 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Outpost Firewall Pro *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\regedit.com
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\BReWErS.dll
c:\windows\system32\taskmgr.com

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-10-14 do 2010-11-14 )))))))))))))))))))))))))))))))
.

2010-11-12 19:11 . 2010-11-12 19:11 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Malwarebytes
2010-11-12 19:11 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-12 19:11 . 2010-11-12 19:11 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-11-12 19:11 . 2010-11-12 19:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-12 19:11 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2004-08-18 12:00 60416 -csha-w- c:\windows\BricoPacks\SysFiles\80_msimn.exe
2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 216064 --sh--r- c:\windows\system32\nbDX.dll
.

------- Sigcheck -------

[-] 2008-04-14 . 27AFD587C462E280EE046B8CCA3C2CD1 . 1034240 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\explorer.exe
[-] 2007-06-13 . 70192AA0FB59996148038B671EB5ADE1 . 975872 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2007-06-13 . 70192AA0FB59996148038B671EB5ADE1 . 975872 . . [6.00.2900.3156] . . c:\windows\system32\dllcache\explorer.exe
[7] 2007-06-13 . 9B32416BD5988C97B6397CE0B02CAF97 . 1033728 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe

.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e646d4b1-fd71-4495-8a2e-566f93504fbe}"= "c:\program files\hip_hop\tbhip0.dll" [2009-11-10 2166296]

[HKEY_CLASSES_ROOT\clsid\{e646d4b1-fd71-4495-8a2e-566f93504fbe}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e646d4b1-fd71-4495-8a2e-566f93504fbe}]
2009-11-10 16:58 2166296 -c--a-w- c:\program files\hip_hop\tbhip0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e646d4b1-fd71-4495-8a2e-566f93504fbe}"= "c:\program files\hip_hop\tbhip0.dll" [2009-11-10 2166296]

[HKEY_CLASSES_ROOT\clsid\{e646d4b1-fd71-4495-8a2e-566f93504fbe}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E646D4B1-FD71-4495-8A2E-566F93504FBE}"= "c:\program files\hip_hop\tbhip0.dll" [2009-11-10 2166296]

[HKEY_CLASSES_ROOT\clsid\{e646d4b1-fd71-4495-8a2e-566f93504fbe}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 219520]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2009-01-31 3399727]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [2009-11-21 2011205]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2007-01-05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"ErgoMedia"="c:\progra~1\KYE\ERGOME~1\SyTray.exe" [2005-06-28 1855488]
"CTSysVol"="c:\program files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe" [2005-02-15 57344]
"CTDVDDET"="c:\program files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE" [2003-06-17 45056]
"Zástupce stránky vlastností sběrnice High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]
"SpywareTerminator"="c:\progra~1\SPYWAR~1\SpywareTerminatorShield.exe" [2008-05-05 1817600]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"CTHelper"="CTHELPER.EXE" [2006-08-11 17920]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 18944]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-05-20 111928]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
"TNOD UP"="c:\program files\TNod User & Password Finder\TNODUP.exe" [2010-04-01 1811968]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]

c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-18 630784]
Y'z Shadow.lnk - c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-21 155648]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mouseElf]
2005-07-15 06:25 208896 ----a-w- c:\progra~1\GAMING~1\MouseElf.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2007-05-11 00:08 2512392 -c--a-w- c:\windows\system32\oodtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Documents and Settings\\Administrator\\temp\\TeamViewer3\\TeamViewer.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3.9.2006 17:50 685816]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [7.4.2010 20:07 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [7.4.2010 20:08 95872]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [3.8.2007 18:38 141312]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [7.4.2010 20:07 810120]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [7.8.2006 20:52 1287296]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [11.7.2006 15:05 7808]
R3 gHidUsbF;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidUsbF.sys [11.7.2006 15:05 12800]
R3 YiRuanUSB;YiRuan device driver for 4d;c:\windows\system32\drivers\yrtumdriver.sys [25.8.2006 15:21 5760]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe --> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe --> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S3 ovt530;Hercules Webcam Deluxe;c:\windows\system32\drivers\ov530vid.sys [15.8.2007 14:49 161792]
.
Obsah adresáře 'Naplánované úlohy'

2010-11-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

2010-11-14 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mWindow Title = Microsoft Internet Explorer
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Administrator\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Administrator\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} - c:\program files\Verdict Free\etnxp.dll
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} - c:\program files\Verdict Free\etnxp.dll
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-ICQ Lite - c:\program files\ICQLite\ICQLite.exe
MSConfigStartUp-MsnMsgr - c:\program files\MSN Messenger\msnmsgr.exe
AddRemove-L4D2SP - c:\documents and settings\Administrator\Plocha\Nová složka (4)\Left 4 Dead 2\uninstall.exe
AddRemove-{B77C6FD0-770A-489A-81CA-1BFEEF7CEA85} - c:\program files\InstallShield Installation Information\{B77C6FD0-770A-489A-81CA-1BFEEF7CEA85}\setup.exe
AddRemove-Verdict Free - c:\program files\Verdict Free\uninst.exe



**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1757981266-362288127-725345543-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1757981266-362288127-725345543-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b1,84,05,b7,46,b4,0b,7f,1f,cc,1d,8d,a1,17,c4,f9,97,83,70,a1,ba,6e,a3,
7a,af,1a,d9,9d,6c,1d,b1,22,d4,7d,53,b5,a5,d8,26,b6,32,9f,c4,54,60,a9,ee,a0,\
"??"=hex:7b,eb,12,ea,69,0b,35,37,9e,52,ec,ad,ab,1e,ec,bd

[HKEY_USERS\S-1-5-21-1757981266-362288127-725345543-500\Software\SecuROM\License information*]
"datasecu"=hex:a9,fc,24,e4,75,b1,3a,95,e8,f1,eb,df,df,8b,5a,66,42,5f,ed,42,7a,
6e,e5,a5,b0,34,b7,30,3e,77,f1,76,d4,ee,dd,ee,9a,58,a7,b1,32,cf,bc,81,b8,62,\
"rkeysecu"=hex:08,48,21,bc,a9,17,e1,38,41,69,da,ba,b6,5e,42,f0

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="0C7E4F525B73A4A97D0B6FE7E85B49709F0903DEE8AF31ED6D1C5E74017CBD5C1C880A97C64C6EEE7C0EA53ECA09A9712DDA9E4CEFF8DBEE1705347E13406370C19AC8708579CAC3F1C38C31535AD8D698ED69E25DEDE8A3998752EB41579CA9D3D54DBF9328557986CCDFA9624D7D4B0201BCB497FA2BB0A8274F1A173E8BC53A9C8B49408A9A86F88D9175AE62B29E9C9DA63958156CDC8CAA76C9F27BC325F297A838AFD11D041DAEFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933FEBC9E127BECC74CBA7FD869164D67948EDD5E5BE2F6E667D8BAC994C83C1A55DA5961DF75468FF3E6BB51C5ABB1302652CD997855D450FE9E40019B0BC21105154851A2925C3D07A0705D31A7697D13907ED8931F42D56F8FE584C64D0CF72E804624104101E2C42083C59B5BCB5341F9635DBD1CF20583AB41AA325BD2C3117D55F3F3BE26C9EEC0FE8B260CA5711208ADAB07BD2BB45D2C511D7BF57200329FDAB09EB8E2D10B1352836F76E42AAC67F72082EDD14AE47AF45D48D26DC8D8AE9F1E674EEE6D615B505720C81C65F97C3CE54509F3C3C43471BBBE9BE7CE1125D2D424982A227E932D0260278320A95959006ADC40B1EC2D6DDF8A6D2BD7ACB383BFB121150935678456DCA7F4E6ADC992C411AF8BB790EAF7C45D57233D3EBCA81F7264D6D21AB6D5774AD4EF5DBA4A11DB5C39CC0DA5A97F3869DF616B1ED89A07C8D538BF0617015F5A2F17BCCC0D5F4672A3A1FE675559DD65001AE5685318DEA05B28A896D04FD849A7314E20F6EBD27C91C86FD593BEAD8EA4283F7D2BC062E2CDB6F42D5FE887542829F2B8A10BA82C152650B438C97024AD86A202149B21027C9B23EDF4DDDDBD098D9C5BDAF341B1B7C12A894FFBC469F2D6CCDD76910073A8B0C7C1751FA6C81B12539224C1E9C3F3479AA096B99FA63A5D8EBCEC70B42E0AF208D67884FC42208DB1AC33F4469EBA07508801CC45A6C2044E8F4667CCB047059D9E4B4751754FFA683CF06F4A806F74901535DE53B9BCD70409888EA67A822CD64DEE066AB5D478B8177BF840AA6B28B3DC8D03B533CC083D23E75E78104AD396DC17C3DED6CEC97B57A43E4665F9DCA53B18AB30EA0D6B1C9953344779A6875389ADE51E33CFD49BDA70CDCD7BDAF3674F18325A3C0A79556B6752EF4611F99555CDB7E62A602618449A1A1CB9C1F08BFB04521F87C35032DC795C2383F6037D85C7E64E9B7AE904790FFB4C7357FABCE8062EBB30B1308F7790DC6348BB993E22A0073C6C0DF508256FAECA80B8DEB480FC48C31D3A7D6007674088AB34DD9B78910EEF887B40DD3312515ABAF20BC5F2FA0A1E3BBB42A79A6F5ABFCBAA10EF9A8655F75C1DE25559FE668F800D955232C63F067807AA"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Celkový čas: 2010-11-14 13:25:33
ComboFix-quarantined-files.txt 2010-11-14 12:25

Před spuštěním: Volných bajtů: 25 056 145 408
Po spuštění: Volných bajtů: 27 598 311 424

- - End Of File - - B16CC475B68C11B8E4E11CA5631AEFC6

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod jaro3 » 14 lis 2010 20:46

Odinstaluj:
Hip Hop Internet Radio Toolbar


Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

Driver::
ioloFileInfoList
ioloSystemService

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e646d4b1-fd71-4495-8a2e-566f93504fbe}"=-
[-HKEY_CLASSES_ROOT\clsid\{e646d4b1-fd71-4495-8a2e-566f93504fbe}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e646d4b1-fd71-4495-8a2e-566f93504fbe}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e646d4b1-fd71-4495-8a2e-566f93504fbe}"=-
[-HKEY_CLASSES_ROOT\clsid\{e646d4b1-fd71-4495-8a2e-566f93504fbe}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E646D4B1-FD71-4495-8A2E-566F93504FBE}"=-
[-HKEY_CLASSES_ROOT\clsid\{e646d4b1-fd71-4495-8a2e-566f93504fbe}]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\windows\explorer.exe

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
pompeus50
Level 2.5
Level 2.5
Příspěvky: 263
Registrován: duben 07
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu

Příspěvekod pompeus50 » 15 lis 2010 17:49

ComboFix 10-11-12.06 - Administrator 15.11.2010 17:06:13.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.447 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Outpost Firewall Pro *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_IOLOFILEINFOLIST
-------\Legacy_IOLOSYSTEMSERVICE
-------\Service_ioloFileInfoList
-------\Service_ioloSystemService


((((((((((((((((((((((((( Soubory vytvořené od 2010-10-15 do 2010-11-15 )))))))))))))))))))))))))))))))
.

2010-11-12 19:11 . 2010-11-12 19:11 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Malwarebytes
2010-11-12 19:11 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-12 19:11 . 2010-11-12 19:11 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-11-12 19:11 . 2010-11-12 19:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-12 19:11 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2004-08-18 12:00 60416 -csha-w- c:\windows\BricoPacks\SysFiles\80_msimn.exe
2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 216064 --sh--r- c:\windows\system32\nbDX.dll
.

------- Sigcheck -------

[-] 2008-04-14 . 27AFD587C462E280EE046B8CCA3C2CD1 . 1034240 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\explorer.exe
[-] 2007-06-13 . 70192AA0FB59996148038B671EB5ADE1 . 975872 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2007-06-13 . 70192AA0FB59996148038B671EB5ADE1 . 975872 . . [6.00.2900.3156] . . c:\windows\system32\dllcache\explorer.exe
[7] 2007-06-13 . 9B32416BD5988C97B6397CE0B02CAF97 . 1033728 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe

.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 219520]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2009-01-31 3399727]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [2009-11-21 2011205]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2007-01-05 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-18 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"ErgoMedia"="c:\progra~1\KYE\ERGOME~1\SyTray.exe" [2005-06-28 1855488]
"CTSysVol"="c:\program files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe" [2005-02-15 57344]
"CTDVDDET"="c:\program files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE" [2003-06-17 45056]
"Zástupce stránky vlastností sběrnice High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]
"SpywareTerminator"="c:\progra~1\SPYWAR~1\SpywareTerminatorShield.exe" [2008-05-05 1817600]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"CTHelper"="CTHELPER.EXE" [2006-08-11 17920]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 18944]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-05-20 111928]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
"TNOD UP"="c:\program files\TNod User & Password Finder\TNODUP.exe" [2010-04-01 1811968]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]

c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-18 630784]
Y'z Shadow.lnk - c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-21 155648]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mouseElf]
2005-07-15 06:25 208896 ----a-w- c:\progra~1\GAMING~1\MouseElf.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2007-05-11 00:08 2512392 -c--a-w- c:\windows\system32\oodtray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Documents and Settings\\Administrator\\temp\\TeamViewer3\\TeamViewer.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3.9.2006 17:50 685816]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [7.4.2010 20:07 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [7.4.2010 20:08 95872]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [3.8.2007 18:38 141312]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [7.4.2010 20:07 810120]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [7.8.2006 20:52 1287296]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [11.7.2006 15:05 7808]
R3 gHidUsbF;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidUsbF.sys [11.7.2006 15:05 12800]
R3 YiRuanUSB;YiRuan device driver for 4d;c:\windows\system32\drivers\yrtumdriver.sys [25.8.2006 15:21 5760]
S3 ovt530;Hercules Webcam Deluxe;c:\windows\system32\drivers\ov530vid.sys [15.8.2007 14:49 161792]
.
Obsah adresáře 'Naplánované úlohy'

2010-11-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

2010-11-15 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mWindow Title = Microsoft Internet Explorer
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Administrator\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Administrator\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} - c:\program files\Verdict Free\etnxp.dll
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} - c:\program files\Verdict Free\etnxp.dll
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-15 17:22
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1757981266-362288127-725345543-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1757981266-362288127-725345543-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b1,84,05,b7,46,b4,0b,7f,1f,cc,1d,8d,a1,17,c4,f9,97,83,70,a1,ba,6e,a3,
7a,af,1a,d9,9d,6c,1d,b1,22,d4,7d,53,b5,a5,d8,26,b6,32,9f,c4,54,60,a9,ee,a0,\
"??"=hex:7b,eb,12,ea,69,0b,35,37,9e,52,ec,ad,ab,1e,ec,bd

[HKEY_USERS\S-1-5-21-1757981266-362288127-725345543-500\Software\SecuROM\License information*]
"datasecu"=hex:a9,fc,24,e4,75,b1,3a,95,e8,f1,eb,df,df,8b,5a,66,42,5f,ed,42,7a,
6e,e5,a5,b0,34,b7,30,3e,77,f1,76,d4,ee,dd,ee,9a,58,a7,b1,32,cf,bc,81,b8,62,\
"rkeysecu"=hex:08,48,21,bc,a9,17,e1,38,41,69,da,ba,b6,5e,42,f0

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="0C7E4F525B73A4A97D0B6FE7E85B49709F0903DEE8AF31ED6D1C5E74017CBD5C1C880A97C64C6EEE7C0EA53ECA09A9712DDA9E4CEFF8DBEE1705347E13406370C19AC8708579CAC3F1C38C31535AD8D698ED69E25DEDE8A3998752EB41579CA9D3D54DBF9328557986CCDFA9624D7D4B0201BCB497FA2BB0A8274F1A173E8BC53A9C8B49408A9A86F88D9175AE62B29E9C9DA63958156CDC8CAA76C9F27BC325F297A838AFD11D041DAEFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933FEBC9E127BECC74CBA7FD869164D67948EDD5E5BE2F6E667D8BAC994C83C1A55DA5961DF75468FF3E6BB51C5ABB1302652CD997855D450FE9E40019B0BC21105154851A2925C3D07A0705D31A7697D13907ED8931F42D56F8FE584C64D0CF72E804624104101E2C42083C59B5BCB5341F9635DBD1CF20583AB41AA325BD2C3117D55F3F3BE26C9EEC0FE8B260CA5711208ADAB07BD2BB45D2C511D7BF57200329FDAB09EB8E2D10B1352836F76E42AAC67F72082EDD14AE47AF45D48D26DC8D8AE9F1E674EEE6D615B505720C81C65F97C3CE54509F3C3C43471BBBE9BE7CE1125D2D424982A227E932D0260278320A95959006ADC40B1EC2D6DDF8A6D2BD7ACB383BFB121150935678456DCA7F4E6ADC992C411AF8BB790EAF7C45D57233D3EBCA81F7264D6D21AB6D5774AD4EF5DBA4A11DB5C39CC0DA5A97F3869DF616B1ED89A07C8D538BF0617015F5A2F17BCCC0D5F4672A3A1FE675559DD65001AE5685318DEA05B28A896D04FD849A7314E20F6EBD27C91C86FD593BEAD8EA4283F7D2BC062E2CDB6F42D5FE887542829F2B8A10BA82C152650B438C97024AD86A202149B21027C9B23EDF4DDDDBD098D9C5BDAF341B1B7C12A894FFBC469F2D6CCDD76910073A8B0C7C1751FA6C81B12539224C1E9C3F3479AA096B99FA63A5D8EBCEC70B42E0AF208D67884FC42208DB1AC33F4469EBA07508801CC45A6C2044E8F4667CCB047059D9E4B4751754FFA683CF06F4A806F74901535DE53B9BCD70409888EA67A822CD64DEE066AB5D478B8177BF840AA6B28B3DC8D03B533CC083D23E75E78104AD396DC17C3DED6CEC97B57A43E4665F9DCA53B18AB30EA0D6B1C9953344779A6875389ADE51E33CFD49BDA70CDCD7BDAF3674F18325A3C0A79556B6752EF4611F99555CDB7E62A602618449A1A1CB9C1F08BFB04521F87C35032DC795C2383F6037D85C7E64E9B7AE904790FFB4C7357FABCE8062EBB30B1308F7790DC6348BB993E22A0073C6C0DF508256FAECA80B8DEB480FC48C31D3A7D6007674088AB34DD9B78910EEF887B40DD3312515ABAF20BC5F2FA0A1E3BBB42A79A6F5ABFCBAA10EF9A8655F75C1DE25559FE668F800D955232C63F067807AA"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(2092)
c:\windows\system32\SHDOCVW.dll
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Hercules\WebCam Station\PhotoImpression\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\oodag.exe
c:\progra~1\SPYWAR~1\sp_rsser.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Celkový čas: 2010-11-15 17:29:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-11-15 16:29
ComboFix2.txt 2010-11-14 12:25

Před spuštěním: Volných bajtů: 27 130 253 312
Po spuštění: Volných bajtů: 27 009 777 664

- - End Of File - - 6FDB92C8036FF9A06F91EB7D6BF3C1EC


HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:34:08, on 15.11.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\system32\CTsvcCDA.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\windows\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\oodag.exe
C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\windows\system32\svchost.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\PROGRA~1\KYE\ERGOME~1\SyTray.exe
C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\system32\ctfmon.exe
C:\windows\explorer.exe
C:\windows\system32\notepad.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Administrator\Dokumenty\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\windows\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\windows\WebIE.dll
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [ErgoMedia] C:\PROGRA~1\KYE\ERGOME~1\SyTray.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [Zástupce stránky vlastností sběrnice High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TNOD UP] "C:\Program Files\TNod User & Password Finder\TNODUP.exe" /i
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Startup: zip.exe.lnk = C:\WINDOWS\system32\zip.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Administrator\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Administrator\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Přeložit - {230D1201-7607-4CF6-A11F-9E4BF0A333E0} - C:\Program Files\Verdict Free\etnxp.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Verdict Free\etnxp.dll
O9 - Extra 'Tools' menuitem: Internetový překladač... - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Verdict Free\etnxp.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\windows\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\windows\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\windows\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\windows\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\windows\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\windows\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\windows\system32\CTsvcCDA.EXE
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 11559 bytes


http://www.virustotal.com/file-scan/report.html?id=032f6a7fe65fb9627c5ebf78044c17837a0134971d13f48bd02f946a458ab2eb-1289839078

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Poprosil bych o kontrolu  Vyřešeno

Příspěvekod jaro3 » 15 lis 2010 19:57

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)



ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

vyčisti systém CCleanerem

a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš


Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 7 hostů