
Uzywam ZoneAlarma i McAfee.
W ciągu tygodnia złapałem Puper.dll przejawiający się w mssearchnet.exe i nvctrl.exe ale dałem sobie z nim radę. W trybie awaryjnym NOD32 go wykasował do tego hijackthis zafixował parę wersów. Komp chodził mi przez dwa dni jak burza.... NEIESTETY postanowiłem pokusić się o cracka do SpyHuntera 2.0 przez eMule. Złapałem cos co McAfee nazwało najpierw W32/Tibic.d!p2p zrestartował sie komp i McAfee pokazało mi W32/Generic.d!p2p a teraz po prostu wyskakuje mi Puper (bez dll?) tworzy sobie plik w system32 np: ld589.tmp który znika jak sie chce go ręcznie odszukać. (Przy poprzednim trojanie Mcafee znajdował mi chociaż źródło trojana w postaci wspomnianego mssearchnet.exe teraz nie wiem co tworzy tego nowego). Czy to wszytko to jeden trojan czy kilka na raz. Znalazłem stronkę na http://castlecops.com/print-1-138969.html gdzie jest instrukcja jak postępować. Podobnie jak w tamtej historii przy skanowaniu czy to Spy Sweaperem (który juz nie ma opcji na kasowanie wirusów w trial wersji) czy Ewido - wirus wyłączał mi sam kompa. Zrobiłem to dopiero w trybie awaryjnym poniżej daje Logi. Spy Sweaper nazywa go Downloader.zolb.kt ;Ewido pokasował mi cos ale ponowne sprawdzenie przez Spy Sweapa dało te same rezultaty... Teraz pisze z trybu normalnego, zaczeło sie od tego ze mozilla nie reagowała na pasku startu na prawy klawisz myszy no i sie wolniej niz zwykle właczyła... teraz ViewMgr coś próbuje łaczyć sie z netem....
Proszę o radę bo ta łamigłówka już mnie wykańcza wklejam logi.
Logfile of HijackThis v1.99.1
Scan saved at 06:50:33, on 2006-04-15
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Dit.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Gigabyte\ET5\GUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TrojanHunter 4.5\THGuard.exe
C:\Program Files\Common Files\AOL\1125333730\ee\AOLHostManager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1125333730\ee\AOLServiceHost.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Pulpit\HijackThis1991.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.vobis.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [DTemp] C:\SysPrep\Test\DTemp\DTemp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KEWelcomeReBoot] D:\welcome.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] "C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125333730\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.vobis.pl/
O15 - Trusted Zone: http://*.mks.com.pl
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103531480250
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37380.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4468/mcfscan.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
*******
04:15: | Start of Session, 15 kwiecień 2006 |
04:15: Spy Sweeper started
04:15: Sweep initiated using definitions version 658
04:15: Found Trojan Horse: trojan-downloader-zlob
04:15: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || wininet.dll (ID = 1052561)
04:15: dfrgsrv.exe (ID = 1052561)
04:15: Found Adware: psguard components
04:15: HKCR\clsid\{736b5468-bdad-41be-92d0-22ae2ddf7bcb}\inprocserver32\ (2 subtraces) (ID = 1219075)
04:15: Security Toolbar.dll (ID = 1219075)
04:15: Starting Memory Sweep
04:16: Memory Sweep Complete, Elapsed Time: 00:01:30
04:16: Starting Registry Sweep
04:16: Found Adware: security2k hijacker
04:16: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objecta\ (2 subtraces) (ID = 735573)
04:16: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || kernel32.dll (ID = 796421)
04:16: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || wininet.dll (ID = 797671)
04:16: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || nvctrl.exe (ID = 797753)
04:16: HKCR\clsid\{736b5468-bdad-41be-92d0-22ae2ddf7bcb}\ (6 subtraces) (ID = 1034913)
04:16: Found Adware: security toolbar
04:16: HKLM\software\microsoft\windows\currentversion\uninstall\security toolbar\ (2 subtraces) (ID = 1035010)
04:16: HKLM\software\classes\clsid\{736b5468-bdad-41be-92d0-22ae2ddf7bcb}\ (6 subtraces) (ID = 1035080)
04:16: HKU\S-1-5-21-3794943921-1926355880-1220886193-1006\software\microsoft\internet explorer\toolbar\webbrowser\ || {736b5468-bdad-41be-92d0-22ae2ddf7bcb} (ID = 1070479)
04:17: Registry Sweep Complete, Elapsed Time:00:00:20
04:17: Starting Cookie Sweep
04:17: Found Spy Cookie: 2o7.net cookie
04:17: user@2o7[2].txt (ID = 1957)
04:17: Found Spy Cookie: tradedoubler cookie
04:17: user@tradedoubler[2].txt (ID = 3575)
04:17: Cookie Sweep Complete, Elapsed Time: 00:00:00
04:17: Starting File Sweep
04:17: c:\program files\security toolbar (2 subtraces) (ID = -2147462697)
04:34: uninstall.bat (ID = 202688)
04:34: File Sweep Complete, Elapsed Time: 00:17:38
04:34: Full Sweep has completed. Elapsed time 00:19:40
04:34: Traces Found: 36
********
20:32: | Start of Session, 14 kwiecień 2006 |
20:32: Spy Sweeper started
20:32: Sweep initiated using definitions version 658
20:32: Found Trojan Horse: trojan-downloader-zlob
20:32: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || wininet.dll (ID = 1052561)
20:32: dfrgsrv.exe (ID = 1052561)
20:32: Found Adware: psguard components
20:32: HKCR\clsid\{736b5468-bdad-41be-92d0-22ae2ddf7bcb}\inprocserver32\ (2 subtraces) (ID = 1219075)
20:32: Security Toolbar.dll (ID = 1219075)
20:32: Starting Memory Sweep
03:59: Hosts file is too large.
04:03: Hosts file is too large.
04:14: Program Version 4.5.9 (Build 711) Using Spyware Definitions 658
04:15: | End of Session, 15 kwiecień 2006 |
********
20:31: | Start of Session, 14 kwiecień 2006 |
20:31: Spy Sweeper started
20:32: Hosts file is too large.
20:32: Your spyware definitions have been updated.
20:32: | End of Session, 14 kwiecień 2006 |
--------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 05:12:47, 2006-04-15
+ Report-Checksum: EA6A32DF
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB} -> Adware.Generic : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.69:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
:mozilla.70:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
:mozilla.82:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.83:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.84:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.85:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.86:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.87:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.88:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.89:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.90:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.91:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.92:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.114:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
:mozilla.115:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
:mozilla.130:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
:mozilla.131:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
:mozilla.174:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.175:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.176:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.212:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
:mozilla.213:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
:mozilla.231:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.232:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.233:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.234:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.235:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.329:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.330:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.331:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.332:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.333:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.334:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.335:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.336:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.337:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.338:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.339:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.340:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.341:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.420:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.443:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup
:mozilla.445:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup
:mozilla.446:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup
:mozilla.454:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.484:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.485:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.532:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.538:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.559:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.570:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.571:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.572:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.589:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned with backup
:mozilla.632:C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\37xge8uj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\WINDOWS\system32\dfrgsrv.exe -> Trojan.Small : Cleaned with backup
::Report End
wielkie dzięki i jak ktoś z będzie w stolicy to zapraszam w zamian za pomoc na lekcję tenisa.
Artur.