Jump to content

Премахват ли се вирусите при преинсталиране на компютъра?


Препоръчан пост

Ето лога от Anti-malware,а krni32drv.dll не го откривам

 

 

Malwarebytes' Anti-Malware 1.31

Database version: 1565

Windows 5.1.2600 Service Pack 2

 

29.12.2008 18:46:09

mbam-log-2008-12-29 (18-46-09).txt

 

Scan type: Quick Scan

Objects scanned: 75426

Time elapsed: 32 minute(s), 2 second(s)

Log - Show

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 117

Registry Values Infected: 0

Registry Data Items Infected: 1

Folders Infected: 1

Files Infected: 4

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{08b0e5c0-4fcb-11cf-aax5-00401c608512} (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCONSOL.EXE (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EGHOST.EXE (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.EXE (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVwsc.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.EXE (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVmon.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVmonD.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SCAN32.EXE (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VSSTAT.EXE (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WEBSCANX.EXE (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFWSvc.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRepair.COM (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvReport.kxp (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVStub.kxp (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loaddll.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RfwMain.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.EXE (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQKav.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScan.kxp (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icesword.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AST.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upiea.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBCleaner.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FYFireWall.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP_1.kxp (Security.Hijack) -> Quarantined and deleted successfully.

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

 

Folders Infected:

C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 (Trojan.Agent) -> Quarantined and deleted successfully.

 

Files Infected:

C:\WINDOWS\Setup1.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\vamsoft.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\sexit.dat (Trojan.Agent) -> Quarantined and deleted successfully.

Link to comment
Сподели другаде

  • Отговори 31
  • Създадена
  • Последен отговор

ТОП потребители в тази тема

ТОП потребители в тази тема

Здравейте!

Ами,ако имаш 3 дяло примерно(C,E,D) като мен и Vista(аз съм с нея) е на C:\ обаче вируса се самокопира и на D,E то ако преинсталирам няма ли понеже Е,D не са форматирани пак да се заразя?

Link to comment
Сподели другаде

Ако нямаш какво да губиш от другите два дяла ги форматирай , а и до колкото знам Виста може да форматира дисковете (дяловете)още по време на инсталацията. Когато ти се появи прозореца с дисковете ,не бързай да инсталираш Вистата а форматирай всеки дял по отделно и тогава избери дял С: и инсталирай на него. Същото може и с ХР ,но за да форматираш дяловете трябва първо да ги изтриеш и да направиш create - създадеш отново и след приключване инсталацията на XP-то дори и да си забравил да ги форматираш ( другите два дяла ) при опит за отварянето им Windows сам ще ти поиска форматиране!!!

Ако пък не ти се преинсталира и нямаш какво да губиш от съдържанието на другите два дяла форматирай само тях и тогава се занимавай с вредителя на дял C: в който ти е Windows-а ( ако там ти е инсталиран разбира се )!!! А ко не успяваш да се справиш пиши !!! :computer:

Link to comment
Сподели другаде

  • 6 months later...

Logfile of HijackThis v1.99.1

Scan saved at 12:10:00 PM, on 8/5/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Log - Show

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

E:\Programs\Skype\Phone\Skype.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\WINDOWS\Datecs\Flex2K.exe

C:\WINDOWS\system32\nvsvc32.exe

c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\ThuG LiFe\Desktop\alabala.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bg

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install

O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"

O4 - HKLM\..\Run: [skyTel] "SkyTel.EXE"

O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"

O4 - HKLM\..\Run: [Alcmtr] "ALCMTR.EXE"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S

O4 - HKCU\..\Run: [skype] "E:\Programs\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: FlexType 2K.lnk = ?

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O18 - Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\Common Files\A&W\MidRadio.ocx

O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

 

 

 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ Adobe Reader Speed Launcher Adobe Acrobat SpeedLauncher Adobe Systems Incorporated c:\program files\adobe\reader 9.0\reader\reader_sl.exe

+ Alcmtr Realtek Azalia Audio - Event Monitor Realtek Semiconductor Corp. c:\windows\alcmtr.exe

+ avgnt Antivirus System Tray Tool Avira GmbH c:\program files\avira\antivir desktop\avgnt.exe

+ NeroFilterCheck NeroCheck Ahead Software Gmbh c:\windows\system32\nerocheck.exe

+ NvCplDaemon NVIDIA Display Properties Extension NVIDIA Corporation c:\windows\system32\nvcpl.dll

+ NvMediaCenter NVIDIA Media Center Library NVIDIA Corporation c:\windows\system32\nvmctray.dll

+ nwiz NVIDIA nView Wizard, Version 111.22 NVIDIA Corporation c:\windows\system32\nwiz.exe

+ RTHDCPL Realtek HD Audio Control Panel Realtek Semiconductor Corp. c:\windows\rthdcpl.exe

+ SkyTel Realtek Voice Manager Realtek Semiconductor Corp. c:\windows\skytel.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

+ FlexType 2K.lnk c:\windows\datecs\flex2k.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ Skype Skype. Take a deep breath Skype Technologies S.A. e:\programs\skype\phone\skype.exe

+ SUPERAntiSpyware SUPERAntiSpyware Application SUPERAntiSpyware.com c:\program files\superantispyware\superantispyware.exe

+ swg GoogleToolbarNotifier Google Inc. c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe

+ Uniblue RegistryBooster 2009 File not found: C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S

HKLM\SOFTWARE\Classes\Protocols\Filter

+ text/x-mrml YAMAHA MidRadio Control YAMAHA CORPORATION c:\program files\common files\a&w\midradio.ocx

+ text/xml Microsoft Office XML MIME Filter Microsoft Corporation c:\program files\common files\microsoft shared\office11\msoxmlmf.dll

+ x-sdch Fast Search Google Inc. c:\program files\google\google toolbar\component\fastsearch_a8904fb862bd9564.dll

HKLM\SOFTWARE\Classes\Protocols\Handler

+ mso-offdap Microsoft Office XP Web Components Microsoft Corporation c:\program files\common files\microsoft shared\web components\10\owc10.dll

+ mso-offdap11 Microsoft Office Web Components 2003 Microsoft Corporation c:\program files\common files\microsoft shared\web components\11\owc11.dll

HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components

+ 0 File not found: About:Home

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ Address Book 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Microsoft Outlook Express 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ SABShellExecuteHook Class ShellExecuteHook SuperAdBlocker.com c:\program files\superantispyware\sasseh.dll

HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers

+ SASContextMenu Class SUPERAntiSpyware Context Menu Extension SUPERAntiSpyware.com c:\program files\superantispyware\sasctxmn.dll

+ Shell Extension for Malware scanning AntiVirus context menu Avira GmbH c:\program files\avira\antivir desktop\shlext.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers

+ MBAMShlExt Malwarebytes' Anti-Malware Malwarebytes Corporation c:\program files\malwarebytes' anti-malware\mbamext.dll

HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers

+ SASContextMenu Class SUPERAntiSpyware Context Menu Extension SUPERAntiSpyware.com c:\program files\superantispyware\sasctxmn.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Directory\Shellex\DragDropHandlers

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ PDF Shell Extension PDF Shell Extension Adobe Systems, Inc. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll

HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers

+ MBAMShlExt Malwarebytes' Anti-Malware Malwarebytes Corporation c:\program files\malwarebytes' anti-malware\mbamext.dll

+ Shell Extension for Malware scanning AntiVirus context menu Avira GmbH c:\program files\avira\antivir desktop\shlext.dll

+ WinRAR c:\program files\winrar\rarext.dll

HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers

+ 00nView NVIDIA Desktop Explorer, Version 111.22 NVIDIA Corporation c:\windows\system32\nvshell.dll

+ NvCplDesktopContext NVIDIA Display Properties Extension NVIDIA Corporation c:\windows\system32\nvcpl.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Desktop Explorer NVIDIA Desktop Explorer, Version 111.22 NVIDIA Corporation c:\windows\system32\nvshell.dll

+ Desktop Explorer Menu NVIDIA Desktop Explorer, Version 111.22 NVIDIA Corporation c:\windows\system32\nvshell.dll

+ Display Panning CPL Extension File not found: deskpan.dll

+ For &People... Find People Microsoft Corporation c:\program files\outlook express\wabfind.dll

+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\windows\system32\hticons.dll

+ Microsoft Data Link Microsoft Data Access - OLE DB Core Services Microsoft Corporation c:\program files\common files\system\ole db\oledb32.dll

+ Microsoft Office HTML Icon Handler Microsoft Office 2003 component Microsoft Corporation c:\program files\microsoft office\office11\msohev.dll

+ Microsoft Office Outlook Custom Icon Handler Outlook Shell Hook for Start/Find Microsoft Corporation c:\program files\microsoft office\office11\olkfstub.dll

+ Microsoft Office Outlook Desktop Icon Handler Microsoft Shell Extension Library Microsoft Corporation c:\program files\microsoft office\office11\mlshext.dll

+ NvCpl DesktopContext Class NVIDIA Display Properties Extension NVIDIA Corporation c:\windows\system32\nvcpl.dll

+ nView Desktop Context Menu NVIDIA Desktop Explorer, Version 111.22 NVIDIA Corporation c:\windows\system32\nvshell.dll

+ Play on my TV helper NVIDIA Display Properties Extension NVIDIA Corporation c:\windows\system32\nvcpl.dll

+ Shell Extension for Malware scanning AntiVirus context menu Avira GmbH c:\program files\avira\antivir desktop\shlext.dll

+ Web Folders Microsoft Web Folders Microsoft Corporation c:\program files\common files\microsoft shared\web folders\msonsext.dll

+ WinRAR shell extension c:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ Adobe PDF Link Helper Adobe PDF Helper for Internet Explorer Adobe Systems Incorporated c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll

+ Google Dictionary Compression sdch Fast Search Google Inc. c:\program files\google\google toolbar\component\fastsearch_a8904fb862bd9564.dll

+ Google Toolbar Helper Google Toolbar Google Inc. c:\program files\google\google toolbar\googletoolbar.dll

+ Google Toolbar Notifier BHO GoogleToolbarNotifier Google Inc. c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll

+ Yahoo! Companion BHO Yahoo! Toolbar 5.6 for Internet Explorer Yahoo! Inc. c:\program files\yahoo!\companion\installs\cpn\ycomp5_6_2_0.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ &Yahoo! Companion Yahoo! Toolbar 5.6 for Internet Explorer Yahoo! Inc. c:\program files\yahoo!\companion\installs\cpn\ycomp5_6_2_0.dll

+ Google Toolbar Google Toolbar Google Inc. c:\program files\google\google toolbar\googletoolbar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ Windows Messenger Windows Messenger Microsoft Corporation c:\program files\messenger\msmsgs.exe

HKLM\System\CurrentControlSet\Services

+ AntiVirSchedulerService Service to schedule Avira AntiVir Personal - Free Antivirus jobs and updates. Avira GmbH c:\program files\avira\antivir desktop\sched.exe

+ AntiVirService Offers permanent protection against viruses and malware with the AntiVir search engine. Avira GmbH c:\program files\avira\antivir desktop\avguard.exe

+ gusvc Google Updater keeps your Google software up to date. If Google Updater Service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. Google c:\program files\google\common\google updater\googleupdaterservice.exe

+ IDriverT Provides support for the Running Object Table for InstallShield Drivers Macrovision Corporation c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe

+ NVSvc Provides system and desktop level support to the NVIDIA display driver NVIDIA Corporation c:\windows\system32\nvsvc32.exe

+ ose Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports. Microsoft Corporation c:\program files\common files\microsoft shared\source engine\ose.exe

+ PSI_SVC_2 This service provides Protexis licensing functionalty. Protexis Inc. c:\program files\common files\protexis\license service\psiservice_2.exe

HKLM\System\CurrentControlSet\Services

+ avgio Avira AntiVir Support for Minifilter Avira GmbH c:\program files\avira\antivir desktop\avgio.sys

+ avgntflt Avira files mini-filter driver Avira GmbH c:\windows\system32\drivers\avgntflt.sys

+ avipbb Avira's Driver for RootKit Detection Avira GmbH c:\windows\system32\drivers\avipbb.sys

+ BlueletAudio File not found: system32\DRIVERS\blueletaudio.sys

+ BlueletSCOAudio File not found: system32\DRIVERS\BlueletSCOAudio.sys

+ BT File not found: system32\DRIVERS\btnetdrv.sys

+ Btcsrusb File not found: System32\Drivers\btcusb.sys

+ BtHidBus Bluetooth HID BUS Driver IVT Corporation. c:\windows\system32\drivers\bthidbus.sys

+ BTHidEnum File not found: System32\Drivers\vbtenum.sys

+ BTHidMgr File not found: System32\Drivers\BTHidMgr.sys

+ btnetBUs c:\windows\system32\drivers\btnetbus.sys

+ Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys

+ gdrv GIGABYTE Tools Windows ® 2000 DDK provider c:\windows\gdrv.sys

+ HDAudBus High Definition Audio Bus Driver v1.0a Windows ® Server 2003 DDK provider c:\windows\system32\drivers\hdaudbus.sys

+ i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys

+ IntcAzAudAddService Realtek® High Definition Audio Function Driver Realtek Semiconductor Corp. c:\windows\system32\drivers\rtkhdaud.sys

+ IvtBtBUs IVT Bluetooth Bus Device Driver IVT Corporation. c:\windows\system32\drivers\ivtbtbus.sys

+ lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys

+ nv NVIDIA Compatible Windows 2000 Miniport Driver, Version 163.75 NVIDIA Corporation c:\windows\system32\drivers\nv4_mini.sys

+ NVENETFD NVIDIA Networking Function Driver. NVIDIA Corporation c:\windows\system32\drivers\nvenetfd.sys

+ NVHDA NVIDIA HDMI Audio Driver NVIDIA Corporation c:\windows\system32\drivers\nvhda32.sys

+ nvnetbus NVIDIA Networking Bus Driver. NVIDIA Corporation c:\windows\system32\drivers\nvnetbus.sys

+ PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys

+ PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys

+ PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys

+ PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys

+ PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys

+ Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\windows\system32\drivers\ptilink.sys

+ PxHelp20 Px Engine Device Driver for Windows 2000/XP Sonic Solutions c:\windows\system32\drivers\pxhelp20.sys

+ SASDIFSV SASDIFSV.SYS SUPERAdBlocker.com and SUPERAntiSpyware.com c:\program files\superantispyware\sasdifsv.sys

+ SASENUM SASENUM.SYS SUPERAdBlocker.com and SUPERAntiSpyware.com c:\program files\superantispyware\sasenum.sys

+ SASKUTIL SASKUTIL.SYS SUPERAdBlocker.com and SUPERAntiSpyware.com c:\program files\superantispyware\saskutil.sys

+ Secdrv SafeDisc driver Macrovision Europe Ltd c:\windows\system32\drivers\secdrv.sys

+ sfdrv01 StarForce Protection Environment Driver Protection Technology c:\windows\system32\drivers\sfdrv01.sys

+ sfhlp02 StarForce Protection Helper Driver Protection Technology c:\windows\system32\drivers\sfhlp02.sys

+ sfsync02 StarForce Protection Synchronization Driver Protection Technology c:\windows\system32\drivers\sfsync02.sys

+ sptd c:\windows\system32\drivers\sptd.sys

+ ssmdrv Avira Snapshot Driver Avira GmbH c:\windows\system32\drivers\ssmdrv.sys

+ VComm File not found: system32\DRIVERS\VComm.sys

+ VcommMgr File not found: System32\Drivers\VcommMgr.sys

+ WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32

+ msacm.ac3filter c:\windows\system32\ac3filter.acm

+ msacm.iac2 Indeo® audio software Intel Corporation c:\windows\system32\iac25_32.ax

+ msacm.l3acm MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltungen IIS c:\windows\system32\l3codeca.acm

+ msacm.l3fhg MPEG Audio Layer-3 Codec for MSACM Fraunhofer Institut Integrierte Schaltungen IIS c:\windows\system32\mp3fhg.acm

+ msacm.lameacm Lame MP3 codec engine http://www.mp3dev.org/ c:\windows\system32\lameacm.acm

+ MSACM.NSPAC Netscape ACM wrapper for elemediaTM AX24000P music codec Netscape Communications c:\windows\system32\nspac32.acm

+ MSACM.NSX723 File not found: sx5363s.acm

+ MSACM.NSX83 Lucent Technologies SX8300P speech codec Lucent Technologies c:\windows\system32\nsx83p32.acm

+ msacm.sl_anet Audio codec for MS ACM Sipro Lab Telecom Inc. c:\windows\system32\sl_anet.acm

+ msacm.trspch DSP Group TrueSpeech Audio Codec for MSACM V3.50 DSP GROUP, INC. c:\windows\system32\tssoft32.acm

+ msacm.vorbis Ogg Vorbis CODEC for MSACM HMS http://hp.vector.co.jp/authors/VA012897/ c:\windows\system32\vorbis.acm

+ MSACM.VOXACM118 Voxware 32 bit ACM Driver for Windows Voxware c:\windows\system32\vdk32118.acm

+ VIDC.ACDV File not found: ACDV.dll

+ vidc.cvid Cinepak® Codec Radius Inc. c:\windows\system32\iccvid.dll

+ VIDC.DIVX DivX DivX, Inc. c:\windows\system32\divx.dll

+ VIDC.FFDS c:\windows\system32\ff_vfw.dll

+ VIDC.HFYU Huffyuv lossless video codec Disappearing Inc. c:\windows\system32\huffyuv.dll

+ vidc.i263 Intel I.263 Video Driver 2.55.012 Intel Corporation c:\windows\system32\i263_32.drv

+ vidc.I420 Helix I420 YUV Codec www.helixcommunity.org c:\windows\system32\i420vfw.dll

+ vidc.iv31 c:\windows\system32\ir32_32.dll

+ vidc.iv32 c:\windows\system32\ir32_32.dll

+ vidc.iv41 Intel Indeo® Video 4.5 Intel Corporation c:\windows\system32\ir41_32.ax

+ vidc.iv50 Intel Indeo® video 5.10 Intel Corporation c:\windows\system32\ir50_32.dll

+ VIDC.VP60 VP6 VIDEO FOR WINDOWS CODEC On2.com c:\windows\system32\vp6vfw.dll

+ VIDC.VP61 VP6 VIDEO FOR WINDOWS CODEC On2.com c:\windows\system32\vp6vfw.dll

+ VIDC.VP62 VP6 VIDEO FOR WINDOWS CODEC On2.com c:\windows\system32\vp6vfw.dll

+ VIDC.VP70 VP70 VIDEO FOR WINDOWS CODEC On2.com c:\windows\system32\vp7vfw.dll

+ VIDC.X264 c:\windows\system32\x264vfw.dll

+ VIDC.XVID c:\windows\system32\xvidvfw.dll

+ vidc.yv12 Helix YV12 YUV Codec www.helixcommunity.org c:\windows\system32\yv12vfw.dll

HKLM\Software\Classes\Filter

+ Indeo® video 4.4 Compression Filter Intel Indeo® Video 4.5 Intel Corporation c:\windows\system32\ir41_32.ax

+ Indeo® video 4.4 Decompression Filter Intel Indeo® Video 4.5 Intel Corporation c:\windows\system32\ir41_32.ax

HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance

+ 9x8Resize Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ AC3File c:\program files\k-lite codec pack\filters\ac3file.ax

+ AC3Filter ac3filter c:\program files\k-lite codec pack\filters\ac3filter.ax

+ ACELP.net Audio Decoder ACELP.net Audio Decoder Sipro Lab Telecom Inc. c:\windows\system32\acelpdec.ax

+ Allocator Fix Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ Bitmap Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ CDDA Reader CDDA Reader Filter Gabest c:\program files\k-lite codec pack\filters\cddareader.ax

+ CDXA Reader CDXA Reader Filter Gabest c:\program files\k-lite codec pack\filters\cdxareader.ax

+ CoreAVC Video Decoder CoreAVC DirectShow Video Decoder CoreCodec, Inc. c:\program files\k-lite codec pack\filters\coreavcdecoder.ax

+ CoreVorbis Audio Decoder CoreVorbis - c:\program files\k-lite codec pack\filters\corevorbis.ax

+ DC-Bass Source DirectShow™ Audio Decoder http://www.dsp-worx.de c:\program files\k-lite codec pack\filters\dcbasssource.ax

+ DirectVobSub VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth Gabest c:\program files\k-lite codec pack\filters\vsfilter.dll

+ DirectVobSub (auto-loading version) VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth Gabest c:\program files\k-lite codec pack\filters\vsfilter.dll

+ DivX Decoder Filter DivX® Decoder Filter DivX, Inc. c:\program files\k-lite codec pack\filters\divxdec.ax

+ ffdshow Audio Decoder DirectShow and VFW video and audio decoding/encoding/processing filter c:\program files\k-lite codec pack\ffdshow\ffdshow.ax

+ ffdshow Audio Processor DirectShow and VFW video and audio decoding/encoding/processing filter c:\program files\k-lite codec pack\ffdshow\ffdshow.ax

+ ffdshow raw video filter DirectShow and VFW video and audio decoding/encoding/processing filter c:\program files\k-lite codec pack\ffdshow\ffdshow.ax

+ ffdshow Video Decoder DirectShow and VFW video and audio decoding/encoding/processing filter c:\program files\k-lite codec pack\ffdshow\ffdshow.ax

+ FLV Source FLV Splitter Gabest c:\program files\k-lite codec pack\filters\flvsplitter.ax

+ FLV Splitter FLV Splitter Gabest c:\program files\k-lite codec pack\filters\flvsplitter.ax

+ FLV Video Decoder FLV Splitter Gabest c:\program files\k-lite codec pack\filters\flvsplitter.ax

+ Frame Eater Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ Gretech ASF Source Filter c:\program files\gretech\gomplayer\gsfu.ax

+ Gretech AsfEx Source Filter c:\program files\gretech\gomplayer\gsfu.ax

+ Gretech Audio Filter c:\program files\gretech\gomplayer\gaf.ax

+ Gretech AVI Source Filter c:\program files\gretech\gomplayer\gsfu.ax

+ Gretech FLV Source Filter c:\program files\gretech\gomplayer\gsfu.ax

+ Gretech MKV Source Filter c:\program files\gretech\gomplayer\gsfu.ax

+ Gretech MP4 Source Filter c:\program files\gretech\gomplayer\gsfu.ax

+ Gretech MPEG Source Filter c:\program files\gretech\gomplayer\gsfu.ax

+ Gretech Network(AVI) Filter c:\program files\gretech\gomplayer\gnf.ax

+ Gretech Network(GOM) Filter c:\program files\gretech\gomplayer\gnf.ax

+ Gretech Network(OGG) Filter c:\program files\gretech\gomplayer\gnf.ax

+ Gretech Network(SHOUTcast) Filter c:\program files\gretech\gomplayer\gnf.ax

+ Gretech OGG Source Filter c:\program files\gretech\gomplayer\gsfu.ax

+ Gretech Video Filter c:\program files\gretech\gomplayer\gvf.ax

+ Haali Matroska Muxer Haali Media Splitter c:\program files\k-lite codec pack\filters\haali\splitter.ax

+ Haali Media Splitter Haali Media Splitter c:\program files\k-lite codec pack\filters\haali\splitter.ax

+ Haali Simple Media Splitter Haali Media Splitter c:\program files\k-lite codec pack\filters\haali\splitter.ax

+ Haali Video Renderer c:\program files\k-lite codec pack\filters\haali\dxr.dll

+ Haali Video Sink Haali Media Splitter c:\program files\k-lite codec pack\filters\haali\splitter.ax

+ Indeo Video ® 5.1 Progressive Download Source Intel Indeo® video IVF Source Filter 5.10 Intel Corporation c:\windows\system32\ivfsrc.ax

+ Indeo® audio software Indeo® audio software Intel Corporation c:\windows\system32\iac25_32.ax

+ Indeo® video 5.10 Compression Filter Intel Indeo® video 5.10 Intel Corporation c:\windows\system32\ir50_32.dll

+ Indeo® video 5.10 Decompression Filter Intel Indeo® video 5.10 Intel Corporation c:\windows\system32\ir50_32.dll

+ MP4 Source MP4 Splitter Gabest c:\program files\k-lite codec pack\filters\mp4splitter.ax

+ MP4 Splitter MP4 Splitter Gabest c:\program files\k-lite codec pack\filters\mp4splitter.ax

+ MPEG Layer-3 Decoder MPEG Layer-3 Audio Decoder Fraunhofer Institut Integrierte Schaltungen IIS c:\program files\k-lite codec pack\filters\l3codecx.ax

+ MPEG4 Video Source MP4 Splitter Gabest c:\program files\k-lite codec pack\filters\mp4splitter.ax

+ MPEG4 Video Splitter MP4 Splitter Gabest c:\program files\k-lite codec pack\filters\mp4splitter.ax

+ Nero Audio CD Filter Nero Audio CD Source Filter Nero AG c:\program files\common files\ahead\dsfilter\neaudcd.ax

+ Nero Audio Processor Nero Audio Processor Nero AG c:\program files\common files\ahead\dsfilter\neaudioconv.ax

+ Nero Audio Source Nero Library Nero AG c:\program files\common files\ahead\dsfilter\nerender.ax

+ Nero Audio Stream Renderer Nero Library Nero AG c:\program files\common files\ahead\dsfilter\nerender.ax

+ Nero Audio Stream Renderer Nero Library Nero AG c:\program files\common files\ahead\dsfilter\nerender.ax

+ Nero Digital Audio Decoder Nero Audio Decoder Nero AG c:\program files\common files\ahead\dsfilter\neaudio.ax

+ Nero Digital AVC Audio Encoder AAC LC/HE Audio Encoder Nero AG c:\program files\common files\ahead\dsfilter\nendaud.ax

+ Nero Digital AVC File Writer NeroDigital File Format Muxer Nero AG c:\program files\common files\ahead\dsfilter\nendmux.ax

+ Nero Digital AVC Muxer NeroDigital File Format Muxer Nero AG c:\program files\common files\ahead\dsfilter\nendmux.ax

+ Nero Digital AVC Null Renderer NeroDigital File Format Muxer Nero AG c:\program files\common files\ahead\dsfilter\nendmux.ax

+ Nero Digital Parser NeroDigital / mp4 / avi / mov parser Nero AG c:\program files\common files\ahead\dsfilter\ndparser.ax

+ Nero DV Splitter DV Splitter Filter Nero AG c:\program files\common files\ahead\dsfilter\nedvsplitter.ax

+ Nero DVD Decoder MPEG-1/2/4 & AVC video decoder w/ DxVA Nero AG c:\program files\common files\ahead\dsfilter\nevideo.ax

+ Nero DVD Navigator DVD Navigator Filter Nero AG c:\program files\common files\ahead\dsfilter\nedvd.ax

+ Nero ES Video Reader NeroDigital / mp4 / avi / mov parser Nero AG c:\program files\common files\ahead\dsfilter\ndparser.ax

+ Nero File Source Nero SVCD source filter Nero AG c:\program files\common files\ahead\dsfilter\nefilesrc.ax

+ Nero File Source (Async.) NeFileSourceAsync Ahead Software AG c:\program files\common files\ahead\dsfilter\nefilesourceasync.ax

+ Nero File Source / Splitter Push Mode VOB Source Filter Nero AG c:\program files\common files\ahead\dsfilter\nefsource.ax

+ Nero Format Converter Frame rate / Color space converter Nero AG c:\program files\common files\ahead\dsfilter\neroformatconv.ax

+ Nero Frame Capture Direct Show frame grabber filter Nero AG c:\program files\common files\ahead\dsfilter\necapture.ax

+ Nero Mpeg2 Encoder MPEG 1/2 Video Encoder Nero AG c:\program files\common files\ahead\dsfilter\nevcr.ax

+ Nero Photo Source NePhotoSource Ahead Software AG c:\program files\common files\ahead\dsfilter\nephotosource.ax

+ Nero PS Muxer c:\program files\common files\ahead\dsfilter\nepsmuxer.ax

+ Nero QuickTime Audio Decoder QuickTime Decoder Wrapper Nero AG c:\program files\common files\ahead\dsfilter\neqtdec.ax

+ Nero QuickTime Video Decoder QuickTime Decoder Wrapper Nero AG c:\program files\common files\ahead\dsfilter\neqtdec.ax

+ Nero Resize Nero Resizing Filter Nero AG c:\program files\common files\ahead\dsfilter\neresize.ax

+ Nero Scene Change Detector Scene Change Detector Nero AG c:\program files\common files\ahead\dsfilter\nescenedetector.ax

+ Nero Scene Change Detector Scene Change Detector Nero AG c:\program files\common files\ahead\dsfilter\nescenedetector.ax

+ Nero Splitter Splitter Filter Nero AG c:\program files\common files\ahead\dsfilter\nesplitter.ax

+ Nero Vcd Navigator Nero Vcd Navigator Filter Nero AG c:\program files\common files\ahead\dsfilter\nevcd.ax

+ Nero Video Analyzer Nero Video Analyzer Nero AG c:\program files\common files\ahead\dsfilter\nevideoanalyzer.ax

+ Nero Video Decoder MPEG-1/2/4 & AVC video decoder w/ DxVA Nero AG c:\program files\common files\ahead\dsfilter\nevideo.ax

+ Nero Video Processor c:\program files\common files\ahead\dsfilter\nerovideoproc.ax

+ Nero Video Source Nero Library Nero AG c:\program files\common files\ahead\dsfilter\nerender.ax

+ Orb RTSP Source Filter File not found: C:\Program Files\Winamp Remote\bin\OrbRTSPSource.ax

+ RadLight MPC DirectShow Filter RLMPCDec RadLight c:\program files\k-lite codec pack\filters\rlmpcdec.ax

+ RadLight OptimFROG DirectShow Filter RLOFRDec RadLight c:\program files\k-lite codec pack\filters\rlofrdec.ax

+ RealAudio Decoder File not found: C:\Program Files\Winamp Remote\bin\RealMediaSplitter.ax

+ RealMedia Source File not found: C:\Program Files\Winamp Remote\bin\RealMediaSplitter.ax

+ RealMedia Splitter File not found: C:\Program Files\Winamp Remote\bin\RealMediaSplitter.ax

+ RealVideo Decoder File not found: C:\Program Files\Winamp Remote\bin\RealMediaSplitter.ax

+ Record Queue Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ ShotDetect Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ Stetch Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ T VP6 Decompression Filter On2.com Inc. c:\program files\k-lite codec pack\filters\vp6dec.ax

+ T VP7 Decompression Filter On2.com Inc. c:\program files\k-lite codec pack\filters\vp7dec.ax

+ WavPack Audio Decoder WavPack Audio DirectShow Decoder - c:\program files\k-lite codec pack\filters\wavpackdsdecoder.ax

+ WavPack Audio Splitter WavPack Audio DirectShow Splitter - c:\program files\k-lite codec pack\filters\wavpackdssplitter.ax

+ WIA Stream Snapshot Filter WIA Stream Snapshot Filter MyCompanyName c:\windows\system32\wiasf.ax

+ WM VIH2 Fix Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Audio Analyzer Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Black Frame Generator Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT DirectX Transform Wrapper Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT DV Extract Filter Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT FormatConversion Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Import Filter Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Interlacer Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Log Filter Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT MuxDeMux Filter Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Sample Info Filter Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Screen capture Filter Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Switch Filter Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Virtual Renderer Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Virtual Source Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

+ WMT Volume Movie Maker Filters Microsoft Corporation c:\program files\movie maker\wmm2filt.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ !SASWinLogon SUPERAntiSpyware WinLogon Processor SUPERAntiSpyware.com c:\program files\superantispyware\saswinlo.dll

Link to comment
Сподели другаде

  • 1 year later...

Здравейте мисля че и аз имам проблем с компютъра понеже е прекалено бавен дали трябва да го преинсталирам ако може по някакъв начин да ми помогнете да разбера?

 

Logfile of HijackThis v1.99.1

Scan saved at 17:10:16, on 15.3.2011 г.

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Log - Show

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe

C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe

C:\WINDOWS\VM305_STI.EXE

C:\Program Files\LogMeIn\x86\LogMeInSystray.exe

C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe

C:\Program Files\LogMeIn\x86\RaMaint.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

C:\Program Files\LogMeIn\x86\LogMeIn.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Alwil Software\Avast5\avastUI.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Winamp\winampa.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\DAEMON Tools Lite\DTLite.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\PROGRA~1\Webshots\webshots.scr

C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Skype\Plugin Manager\skypePM.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SR3F3J13\alabala[1].exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.homepage.bg/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common

 

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google

 

Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program

 

Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file)

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [bigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)

O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"

O4 - HKLM\..\Run: [btTray] "C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui

O4 - HKLM\..\Run: [iMBooster] C:\Program Files\Iminent\IMBooster\IMBooster.exe /warmup

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - HKCU\..\Run: [ASH24SXZ9S] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Kwr.exe

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [CE8SIIFGSU] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Kwr.exe

O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe

O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google

 

Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html

O8 - Extra context menu item: Send by Bluetooth - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm

O8 - Extra context menu item: Send via &Message... - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm

O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)

O9 - Extra button: Преведи - {60237576-b24c-4ba9-9740-c9f3ec9db557} - C:\PROGRA~1\SkyCode\WEBTRA~1\wt2ie.dll

O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

 

(file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

 

(file missing)

O11 - Options group: [iNTERNATIONAL] International

O13 - Gopher Prefix:

O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} -

 

http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.64.0.cab

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -

 

http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/PopularScreenSaversInitialSetup1.0.1.1.cab

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) -

 

http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) -

 

http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab

O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) -

 

http://games.bigfishgames.com/en_cinematycoon/online/cinematycoon.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://193.68.124.87/activex/AMC.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) -

 

https://secure.logmein.com/activex/ractrl.cab?lmi=100

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: BlueSoleilCS - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe

O23 - Service: BsHelpCS - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe

O23 - Service: BsMobileCS - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file

 

missing)

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel

 

32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config

 

"C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe

O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe

O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corp

Link to comment
Сподели другаде

Сканирай с Malwarebytes' Anti-Malware и SUPERAntiSpyware Free. Ако вече имаш програмите, провери дали имаш последните версии и ако нямаш, премахни твоите и инсталирай най-новите. Ако тепърва инсталираш програмите, след инсталацията те ще предложат да се обновят автоматично, съгласи се. В противен случай обнови дефинициите им ръчно.

 

За Malwarebytes' Anti-Malware:

- стартирай програмата;

- избери Perform quick scan (Бързо сканиране) и кликни бутон Scan (Сканиране);

- след като приключи сканирането, ако не са открити заплахи, ще се отвори автоматично текстов файл (който можеш да затвориш) и програмата ще те уведоми, че не е открила нищо, след което можеш да кликнеш бутон OK и да я затвориш;

- ако са открити заплахи, кликни бутон OK и после Show results (Покажи резултатите);

- кликни бутон Remove Selected (Премахни избраните);

- ще се появи текстов файл (дневник/лог), копирай съдържанието му тук.

 

За SUPERAntiSpyware:

- стартирай програмата;

- кликни бутон Scan your Computer (Сканиране на компютъра);

- вляво избери само дял C:, а вдясно избери Perform Complete Scan (Извърши пълно сканиране);

- кликни Next и изчакай програмата да сканира;

- кликни OK на съобщението;

- ако има засечени заплахи, кликни Next, за да се премахнат гадинките, OK на потвърждението и накрая Finish;

- кликни бутон Preferences... (Настройки) и иди на подпрозорец Statistics/Logs (Дневници), маркирай последния лог по дата и кликни бутон View Log... (Покажи дневника);

- копирай съдържанието му тук.

 

Ако е нужен рестарт при някое от сканиранията, се съгласи и рестартирай веднага.

Link to comment
Сподели другаде

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

 

Database version: 6073

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

16.3.2011 г. 08:50:49

mbam-log-2011-03-16 (08-50-49).txt

 

Scan type: Quick scan

Objects scanned: 137361

Time elapsed: 52 minute(s), 34 second(s)

Log - Show

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 38

Registry Values Infected: 2

Registry Data Items Infected: 3

Folders Infected: 0

Files Infected: 0

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\ASH24SXZ9S (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\CE8SIIFGSU (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\VXEG3ZNNE5 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\HiSoft\CrackDownloader (CrackTool.Agent) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

 

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ASH24SXZ9S (Trojan.FakeAlert) -> Value: ASH24SXZ9S -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CE8SIIFGSU (Trojan.FakeAlert) -> Value: CE8SIIFGSU -> Quarantined and deleted successfully.

 

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

(No malicious items detected)

Link to comment
Сподели другаде

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 03/16/2011 at 10:12 AM

 

Application Version : 4.49.1000

 

Core Rules Database Version : 6605

Trace Rules Database Version: 4417

 

Scan type : Complete Scan

Total Scan Time : 01:11:01

Log - Show

Memory items scanned : 539

Memory threats detected : 0

Registry items scanned : 6824

Registry threats detected : 22

File items scanned : 14829

File threats detected : 690

 

Adware.Tracking Cookie

C:\Documents and Settings\Administrator\Cookies\administrator@ads.cartown[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@keygenguru[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media6degrees[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@lfstmedia[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@crackzone[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@legolas-media[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@m.adx[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[10].txt

C:\Documents and Settings\Administrator\Cookies\administrator@medialand[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.bgtop[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.sladur[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.track306[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hc2.humanclick[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.btv[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.thrillldrillls[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.exchange[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@sofiatraffic[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@delivery.usermedia[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tns-counter[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@e2.emediate[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@yadro[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@chitika[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.gamesbannernet[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adxpose[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.p2pbg[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@crackfound[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.mobango[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@CAS0DP25.txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.blogupp[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.zamunda[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@in.getclicky[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@keygens[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@weborama[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@big-boss-tracker[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.kickasstorrents[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hc2.humanclick[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.kaldata[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[10].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.mytech[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.gamerzhut[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@viasatsatelliteservices.112.2o7[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tracking.dc-storm[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@collective-media[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@CAHV088J.txt

C:\Documents and Settings\Administrator\Cookies\administrator@toplist[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@CA4A0YJM.txt

C:\Documents and Settings\Administrator\Cookies\administrator@yieldmanager[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.intergi[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rambler[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@openstat[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.neg[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click.mediadome[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@toplist[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.opensubtitles[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.energy-torrent[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@xm.xtendmedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.standartnews[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.ps3.ign[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@xiti[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@banners.bgmaps[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@CAEWEKKK.txt

C:\Documents and Settings\Administrator\Cookies\administrator@www2.adserverpub[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ookla[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.blitz[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@2o7[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.cenite[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.pop[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.tvtv[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rem.rezonmedia[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@at.atwola[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mucunki[8].txt

C:\Documents and Settings\Administrator\Cookies\administrator@invitemedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@atwola[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.media.framar[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.webmark[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@interclick[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rotator.adjuggler[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.cyberroot[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adscendmedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@microsoftmachinetranslation.112.2o7[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.sbb[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ar.atwola[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@liveperson[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.medicine[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.psp.ign[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@dhstat[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@findduplicatephotos[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ad4game[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.premiership[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adserver.strategyinformer[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@azjmp[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@popcapgames.122.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.etracker[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tacoda.at.atwola[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smileycentral[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@debenhams.122.2o7[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.inews[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@uk.at.atwola[3].txt

media.ign.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

media.khou.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

media.scanscout.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

multimedia.metacafe [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

naiadsystems.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

s0.2mdn.net [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

secure-it.imrworldwide.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

secure-us.imrworldwide.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

www.99counters.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

www.findringtones.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

www.naiadsystems.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

www.pornhub.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

www.sunporno.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

yield.audience.digitalmedia.bg [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\CZ88W6RP ]

C:\Documents and Settings\Administrator\Cookies\administrator@www6.addfreestats[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@e2.emediate[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@count.rbc[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@teenproblem[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adbureau[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.videofen[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media6degrees[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@liveperson[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@liveperson[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@yadro[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.serialshack[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@e2.emediate[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bluestreak[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.pornhub[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads2.zonastop[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media6degrees[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@software-kitchen.tripod[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@teenproblem[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@fidelity.rotator.hadj7.adjuggler[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@microsoftwindows.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hitbox[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hitbox[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.newfreescreensavers[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@azjmp[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@yadro[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@turski-seriali.blogspot[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media6degrees[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adfarm1.adition[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@insightexpressai[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@insightexpressai[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.crackedsoftwares[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@yadro[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads2.zonastop[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@d.c.d.cltomedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.mediafire[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[8].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.geek-tools[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.zamunda[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@patagonia.122.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clickaider[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clickaider[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clickaider[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.bulpress[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@server.cpmstar[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@themobiletracker[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@interclick[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@interclick[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.zamunda[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@account-co[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.pop1.adbn[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www8.addfreestats[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www4.addfreestats[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@delivery.trafficjunky[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@onlinemedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.zamunda[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.tita[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www5.addfreestats[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.auto.tbn[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www8.addfreestats[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www1.addfreestats[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@gigabitwarez[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@counter.search[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@dealtime[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.standartnews[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.sagabg[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[9].txt

C:\Documents and Settings\Administrator\Cookies\administrator@server.iad.liveperson[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@server.cpmstar[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.prizma-int[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.vkushti[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.energy-torrent[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.energy-torrent[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.energy-torrent[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@server.iad.liveperson[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@delivery.usermedia[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@delivery.usermedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@delivery.usermedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click.cashengines[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ogosta[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.maxlab[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ehg-foxmovies.hitbox[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@at.atwola[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@2o7[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads2.helpos[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ehg-techtarget.hitbox[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click.superpaysys[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tracker.p2pbg[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@stats.searchtrack[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@server.iad.liveperson[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ru4[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@cgm.adbureau[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@cgm.adbureau[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rts.pgmediaserve[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@keygenguru[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.superdns[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.ekk[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@n.pay-click[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.energy-torrent[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.exgfsextapes[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@b.h.d.cltomedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@toplist[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@elitefitness[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@flashtrackz[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.sbb[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.sbb[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.sbb[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.adultadvertising[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.elit-bg[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.tvtv[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@pornhub[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.tvtv[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.tvtv[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@crackloader[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@toplist[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@collective-media[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@collective-media[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.lzjl[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adtech[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adtech[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adtech[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bs.serving-sys[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ero-advertising[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bs.serving-sys[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bs.serving-sys[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bs.serving-sys[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@medialand.relax[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@spylog[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@spylog[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@crackedsoftwares[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@toplist[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.teenproblem[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.omarev[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@lfstmedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@v.a.d.cltomedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[8].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@122.2o7[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.pointroll[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@lfstmedia[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[8].txt

C:\Documents and Settings\Administrator\Cookies\administrator@122.2o7[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@trafficmp[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@legolas-media[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.tbn[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[9].txt

C:\Documents and Settings\Administrator\Cookies\administrator@trafficmp[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@legolas-media[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smileycentral[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@snapfish.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@lfstmedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adtech[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bs.serving-sys[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@xiti[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@xiti[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.pointroll[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.easyads[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@legolas-media[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.premiership[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.onmedia[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ad4game[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mywebsearch[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@debenhams.122.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.gamerzhut[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.famous[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.bgtop[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.premiership[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.pc.ign[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.pc.ign[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ad4game[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[10].txt

C:\Documents and Settings\Administrator\Cookies\administrator@v.c.d.cltomedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.gamerzhut[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@imrworldwide[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@imrworldwide[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@imrworldwide[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@philips.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@3.d.d.cltomedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.onmedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.intergi[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@uk.at.atwola[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.httpool[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.bpt.tbn[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ad4game[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.bgtop[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ad4game[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.bgtop[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@sonyeurope.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@zedo[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@zedo[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.windowsmedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.blitz[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@samsung.solution.weborama[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@v.e.d.cltomedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@banners.aris[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.blitz[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.nariba[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.psp.ign[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clicktorrent[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clicktorrent[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@imrworldwide[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad4.bannerbank[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@cltomedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@keygens[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.blitz[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@audience2media[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.lycos[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@counter.top[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@weefind[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ez-tracks[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@keygens[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.etracker[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.etracker[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bravenet[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bravenet[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@stat.dealtime[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[8].txt

C:\Documents and Settings\Administrator\Cookies\administrator@chitika[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[11].txt

C:\Documents and Settings\Administrator\Cookies\administrator@myroitracking[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@gostats[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@stat.dealtime[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[9].txt

C:\Documents and Settings\Administrator\Cookies\administrator@chitika[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@questionmarket[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@questionmarket[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.strict-2.tbn[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@myroitracking[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@overture[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@overture[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adxpose[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tracking.novem[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@gostats[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tripod[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tripod[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adserve.mizzenmedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@youserials[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.sendsmsnow[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click.yottacash[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mobilescreensavers5[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.gamesbannernet[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.gamesbannernet[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@dmtracker[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[10].txt

C:\Documents and Settings\Administrator\Cookies\administrator@myroitracking[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@advertising[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tns-counter[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@user.lucidmedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[8].txt

C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[8].txt

C:\Documents and Settings\Administrator\Cookies\administrator@stats.miikovci[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.mytech[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.mytech[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adultfriendfinder[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.s-bg[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.s-bg[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.burstnet[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[9].txt

C:\Documents and Settings\Administrator\Cookies\administrator@advertising[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@advertising[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.zanox[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@advertising[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tns-counter[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clicksor[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clicksor[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clicksor[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.zdravei[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@photobox.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.torrentreactor[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revsci[9].txt

C:\Documents and Settings\Administrator\Cookies\administrator@burstbeacon[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.burstnet[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@b.t.d.cltomedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.fulldls[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.bsplayer[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mobygames[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.fulldls[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@weborama[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.cenite[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.causes[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hairfinder[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@microsoftsto.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@gr.burstnet[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@pro-market[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click.onlinepaysys[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@pro-market[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@in.getclicky[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@in.getclicky[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[9].txt

C:\Documents and Settings\Administrator\Cookies\administrator@foxinteractivemedia.122.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@wsclick.infospace[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[8].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.track306[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.text.tbn[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rem.rezonmedia[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rem.rezonmedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rem.rezonmedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@clickbank[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rem.rezonmedia[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@newfreescreensavers[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adserver.adreactor[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adserver.adreactor[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@mediafire[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.youserials[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@eas.apm.emediate[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@advert.technews[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statse.webtrendslive[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@statse.webtrendslive[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.talknetwork[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tradedoubler[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tradedoubler[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@divx.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tracking.dc-storm[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@atwola[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@in.getclicky[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@casalemedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@1.r.d.cltomedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.mobango[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@videoegg.adbureau[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@casalemedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@revenue[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rem.rezonmedia[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bizrate[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ibox[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@videoegg.adbureau[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@casalemedia[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.240x400-1.adbn[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.neg[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@pointroll[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@banners.bgmaps[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@banners.bgmaps[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@banners.bgmaps[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@banners.bgmaps[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@banners.bgmaps[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@boursoramabanque.solution.weborama[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.neg[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@pointroll[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.lex[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.neg[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@rm.yieldmanager[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.burstbeacon[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@surveymonkey.122.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ehhaa[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.neg[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.ez-tracks[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.webvariant[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ehhaa[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@serials.vpg-bg[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.skybg[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.hapcheto[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.btv[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@login.tracking101[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.bus400-2.tbn[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@sexuragan[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.pop[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@sex-love-bg[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adserver.adtechus[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@banners.bgmaps[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ookla[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.kaldata[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.btv[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.kaldata[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adserver.adtechus[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ookla[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.btv[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.hairfinder[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.opensubtitles[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad1.advmaker[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@microsoftmachinetranslation.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.audience2media[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.kaldata[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@trackalyzer[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.pop[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adserver.adtechus[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ookla[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hit.topadvert[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.ireel[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.adsensedetective[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.oneclick[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.kaldata[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.beb4o[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[7].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mucunki[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mucunki[6].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[10].txt

C:\Documents and Settings\Administrator\Cookies\administrator@landing.hitfarm[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mucunki[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@economedia[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[11].txt

C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[10].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.googleadservices[11].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mucunki[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@warezmachine[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@popularscreensavers[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.exchange[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.exchange[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.cyberroot[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@viasatsatelliteservices.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adlegend[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adlegend[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mucunki[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mucunki[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hc2.humanclick[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@bikinimedia.blogspot[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.agava.tbn[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@media.pc.gamespy[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@dlfind[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@eaeacom.112.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adecn[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@socialmedia[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click.mediadome[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.p2pbg[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[5].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[4].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@kontera[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@foxfilmedentertainment.122.2o7[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@stats.mindcraft[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@linksynergy[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@elitezoom[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@adv.novinar[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@kontera[3].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hotlog[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.adopm[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click.filegranted[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ads.mebelcenter[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@hc2.humanclick[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[11].txt

C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[10].txt

C:\Documents and Settings\Administrator\Cookies\administrator@www.pxtrack[1].txt

C:\Documents and Settings\Administrator\Cookies\administrator@click.mediadome[2].txt

C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[1].txt

.doubleclick.net [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.2o7.net [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.feed.validclick.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.imrworldwide.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.imrworldwide.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.tradedoubler.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.tradedoubler.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

counter.search.bg [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.statcounter.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.adbrite.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.adbrite.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.revsci.net [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.revsci.net [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.invitemedia.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.invitemedia.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.revsci.net [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.revsci.net [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.adbrite.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.adbrite.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.interclick.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.interclick.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.invitemedia.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.smartadserver.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.smartadserver.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.smartadserver.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.smartadserver.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.smartadserver.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

delivery.usermedia.net [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

media.easyads.bg [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

media.easyads.bg [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

media.easyads.bg [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

media.easyads.bg [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.content.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.content.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.advertising.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.advertising.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.advertising.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.atdmt.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.tacoda.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.ar.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.atdmt.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.advertising.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.advertising.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.tacoda.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.tacoda.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.tacoda.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.tacoda.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.tacoda.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

.at.atwola.com [ C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

 

Adware.MyWebSearch/FunWebProducts

HKU\S-1-5-21-1085031214-162531612-1417001333-500\SOFTWARE\FunWebProducts

HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}

HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid

HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32

HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib

HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version

HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}

HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid

HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32

HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib

HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version

 

Trojan.Agent/Gen-SSHNAS

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS#NextInstance

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#Service

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#Legacy

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#ConfigFlags

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#Class

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#ClassGUID

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS\0000#DeviceDesc

 

Malware.Trace

HKU\.DEFAULT\Software\Microsoft\Handle

HKU\S-1-5-18\Software\Microsoft\Handle

 

Rogue.Agent/Gen-Nullo[DLL]

C:\WINDOWS\SYSTEM32\SYS2679B.DLL

Link to comment
Сподели другаде

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Гост
Отговори на тази тема

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   Не можете да качите директно снимка. Качете или добавете изображението от линк (URL)

Loading...

×
×
  • Създай ново...