Morjens! Olen tässä lähiaikoina huomannut koneeni turhia hidasteluja normaaleissa ohjelmissa vaikka resursseja on ihan tarpeeksi. Luulen että ongelmat voisivat löytyä tämän avulla... Logfile of HijackThis v1.99.1 Scan saved at 22:27:43, on 31.1.2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\System32\Ati2evxx.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\ccProxy.exe D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe D:\Program Files\Norton Internet Security\ISSVC.exe D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe D:\WINDOWS\system32\spoolsv.exe D:\WINDOWS\SYSTEM32\GEARSEC.EXE D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\Explorer.EXE D:\Program Files\Common Files\Symantec Shared\ccApp.exe D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe D:\Program Files\Logitech\MouseWare\system\em_exec.exe D:\Program Files\Mozilla Firefox\firefox.exe D:\Program Files\Alarm Clock\Alarm Clock.exe D:\Program Files\MSN Messenger\msnmsgr.exe D:\Program Files\Winamp\Winamp.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hoztlgxelzs.com/kEut9cTBUd2n6gebnuHhDIpo_fZ/E1B4JlrhKMZhZQYHSXxPn2OpaCkptfOjWZ4V.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wrdsbllelxaumvmdb.com/kEut9cTBUd3btOu56w6HS/NpInE9smcgHI/5SssuS7o.php R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [corn new else intra] D:\Documents and Settings\All Users\Application Data\Coal Plan Corn New\soapshow.exe O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\RunServices: [blah service] msnmsgrr.exe O4 - HKLM\..\RunServices: [Microsoft media services] winmplayer.exe O4 - HKLM\..\RunServices: [Windows Compliant] foaxga.exe O4 - HKLM\..\RunServices: [Msbb.exe] Msbb.exe O4 - HKLM\..\RunServices: [Patches Value] WinGamed.exe O4 - HKLM\..\RunServices: [WSSAConfiguration] wmmon32.exe O4 - HKLM\..\RunServices: [MicrosoftUpdate] syshelper.exe O4 - HKLM\..\RunServices: [svhost32] svhost.exe O4 - HKLM\..\RunServices: [Microsoft DirectX] PDSched.exe O4 - HKLM\..\RunServices: [issEnc32Svr] issEnc32.exe O4 - HKCU\..\Run: [rdrburn] D:\DOCUME~1\Roni\APPLIC~1\FINDMA~1\aim bags.exe O4 - HKCU\..\Run: [LDM] D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe O4 - HKCU\..\Run: [FreeRAM XP] "D:\Documents and Settings\Roni\Omat tiedostot\Ronin Kansio\-=== Muu P@sk@ ===-\FreeRAM XP(Pro)\FreeRAM XP Pro 1.40.exe" -win O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {30355649-0000-0010-8000-00AA00389B71} - http://activex.microsoft.com/objects/ocget.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097852316609 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132498147711 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E779A430-5BDF-4A0D-B1BB-A79D1BE93113}: NameServer = 212.50.131.153 213.139.190.3 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WB - D:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: GEARSecurity - GEAR Software - D:\WINDOWS\SYSTEM32\GEARSEC.EXE O23 - Service: ISSvc (ISSVC) - Symantec Corporation - D:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: QuicktimeMngr - Unknown owner - D:\WINDOWS\System32\QuicktimeMngr.exe" -netsvcs (file missing) O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Fixaa nämä HjT:lla R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hoztlgxelzs.com/kEut9cTBUd2n6gebnuHhDIpo_fZ/E1B4JlrhKM... R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wrdsbllelxaumvmdb.com/kEut9cTBUd3btOu56w6HS/NpInE9smcg... O4 - HKLM\..\Run: [corn new else intra] D:\Documents and Settings\All Users\Application Data\Coal Plan Corn New\soapshow.exe O4 - HKLM\..\RunServices: [blah service] msnmsgrr.exe O4 - HKLM\..\RunServices: [Microsoft media services] winmplayer.exe O4 - HKLM\..\RunServices: [Windows Compliant] foaxga.exe O4 - HKLM\..\RunServices: [Msbb.exe] Msbb.exe O4 - HKLM\..\RunServices: [Patches Value] WinGamed.exe O4 - HKLM\..\RunServices: [WSSAConfiguration] wmmon32.exe O4 - HKLM\..\RunServices: [MicrosoftUpdate] syshelper.exe O4 - HKLM\..\RunServices: [svhost32] svhost.exe O4 - HKLM\..\RunServices: [Microsoft DirectX] PDSched.exe O4 - HKLM\..\RunServices: [issEnc32Svr] issEnc32.exe O4 - HKCU\..\Run: [rdrburn] D:\DOCUME~1\Roni\APPLIC~1\FINDMA~1\aim bags.exe O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab O23 - Service: QuicktimeMngr - Unknown owner - D:\WINDOWS\System32\QuicktimeMngr.exe" -netsvcs (file missing) Käynnistä > suorita > services.msc > etsi listalta "QuicktimeMngr", tuplaklikkaa sitä valitse seis, ja käynnistystavaksi ei käytössä Hae Ewido -> http://keskustelu.afterdawn.com/thread_view.cfm/269186 Asenna ja päivitä se, mutta älä tee vielä muuta Käynnistä vikasietotilaan ( F8 käynnistyksen yhteydessä ) Poista nämä, jos löytyy D:\Documents and Settings\All Users\Application Data\==>Coal Plan Corn New<=== Kansio D:\DOCUME~1\Roni\APPLIC~1\===>FINDMA~1<====Kansio Skannaa Ewidolla vikasietotilassa, tuon linkittämäni asetusten ,mukaisesti, ja tallenna raportti Käynnistä kone uudelleen, ja laita uusi loki, ja Ewidon raportti
Ookei. Tässä on uus HTJ loki. Logfile of HijackThis v1.99.1 Scan saved at 16:28:33, on 2.2.2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\System32\Ati2evxx.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\ccProxy.exe D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe D:\Program Files\Norton Internet Security\ISSVC.exe D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe D:\WINDOWS\system32\spoolsv.exe D:\Program Files\ewido anti-malware\ewidoctrl.exe D:\Program Files\ewido anti-malware\ewidoguard.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\SYSTEM32\GEARSEC.EXE D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe D:\Program Files\Logitech\MouseWare\system\em_exec.exe D:\Program Files\Common Files\Symantec Shared\ccApp.exe D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe D:\Program Files\Mozilla Firefox\firefox.exe D:\Program Files\ewido anti-malware\securitysuite.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hoztlgxelzs.com/kEut9cTBUd2n6gebnuHhDIpo_fZ/E1B4JlrhKMZhZQYHSXxPn2OpaCkptfOjWZ4V.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wrdsbllelxaumvmdb.com/kEut9cTBUd3btOu56w6HS/NpInE9smcgHI/5SssuS7o.php R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [corn new else intra] D:\Documents and Settings\All Users\Application Data\Coal Plan Corn New\soapshow.exe O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\RunServices: [blah service] msnmsgrr.exe O4 - HKLM\..\RunServices: [Microsoft media services] winmplayer.exe O4 - HKLM\..\RunServices: [Windows Compliant] foaxga.exe O4 - HKLM\..\RunServices: [Msbb.exe] Msbb.exe O4 - HKLM\..\RunServices: [Patches Value] WinGamed.exe O4 - HKLM\..\RunServices: [WSSAConfiguration] wmmon32.exe O4 - HKLM\..\RunServices: [MicrosoftUpdate] syshelper.exe O4 - HKLM\..\RunServices: [svhost32] svhost.exe O4 - HKLM\..\RunServices: [Microsoft DirectX] PDSched.exe O4 - HKLM\..\RunServices: [issEnc32Svr] issEnc32.exe O4 - HKCU\..\Run: [rdrburn] D:\DOCUME~1\Roni\APPLIC~1\FINDMA~1\aim bags.exe O4 - HKCU\..\Run: [LDM] D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe O4 - HKCU\..\Run: [FreeRAM XP] "D:\Documents and Settings\Roni\Omat tiedostot\Ronin Kansio\-=== Muu P@sk@ ===-\FreeRAM XP(Pro)\FreeRAM XP Pro 1.40.exe" -win O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {30355649-0000-0010-8000-00AA00389B71} - http://activex.microsoft.com/objects/ocget.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097852316609 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132498147711 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E779A430-5BDF-4A0D-B1BB-A79D1BE93113}: NameServer = 212.50.131.153 213.139.190.3 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WB - D:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - D:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: GEARSecurity - GEAR Software - D:\WINDOWS\SYSTEM32\GEARSEC.EXE O23 - Service: ISSvc (ISSVC) - Symantec Corporation - D:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe Ja tässä ewido. --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 16:17:00, 2.2.2006 + Report-Checksum: FB804097 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F} -> Spyware.ISTBar : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{205FF73A-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{339D8AFF-0B42-4260-AD82-78CE605A9543} -> Spyware.SideFind : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{59EBB576-CEB0-42FA-9917-DA6254A275AD} -> Spyware.VX2 : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{AA4939C3-DECA-4A48-A454-97CD587C0EF5} -> Spyware.ISTBar : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{EEE4A2E5-9F56-432F-A6ED-F6F625B551E0} -> Dialer.Generic : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{205FF72E-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{58634367-D62B-4C2C-86BE-5AAC45CDB671} -> Spyware.SideFind : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429} -> Spyware.ISTBar : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{8E0D8965-B97B-468D-8306-A05929E439C1} -> Spyware.VX2 : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{D0288A41-9855-4A9B-8316-BABE243648DA} -> Spyware.SideFind : Cleaned with backup HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup HKLM\SOFTWARE\Policies\Avenue Media -> Spyware.InternetOptimizer : Cleaned with backup HKU\.DEFAULT\Software\IST -> Spyware.ISTBar : Cleaned with backup HKU\.DEFAULT\Software\ISTbar -> Spyware.ISTBar : Cleaned with backup HKU\.DEFAULT\Software\ISTbar\ISTbar -> Spyware.ISTBar : Cleaned with backup HKU\.DEFAULT\Software\ISTbar\ISTbar\Historyfiles -> Spyware.ISTBar : Cleaned with backup HKU\.DEFAULT\Software\ISTbar\ISTbar\Historys1 -> Spyware.ISTBar : Cleaned with backup HKU\.DEFAULT\Software\LocalNRD -> Spyware.BetterInternet : Cleaned with backup HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} -> Spyware.SideFind : Cleaned with backup HKU\.DEFAULT\Software\PowerScan -> Spyware.PowerScan : Cleaned with backup HKU\S-1-5-21-1715567821-1592454029-725345543-1003\Software\Policies\Avenue Media -> Spyware.InternetOptimizer : Cleaned with backup HKU\S-1-5-18\Software\IST -> Spyware.ISTBar : Cleaned with backup HKU\S-1-5-18\Software\ISTbar -> Spyware.ISTBar : Cleaned with backup HKU\S-1-5-18\Software\ISTbar\ISTbar -> Spyware.ISTBar : Cleaned with backup HKU\S-1-5-18\Software\ISTbar\ISTbar\Historyfiles -> Spyware.ISTBar : Cleaned with backup HKU\S-1-5-18\Software\ISTbar\ISTbar\Historys1 -> Spyware.ISTBar : Cleaned with backup HKU\S-1-5-18\Software\LocalNRD -> Spyware.BetterInternet : Cleaned with backup HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Explorer Bars\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} -> Spyware.SideFind : Cleaned with backup HKU\S-1-5-18\Software\PowerScan -> Spyware.PowerScan : Cleaned with backup D:\Documents and Settings\LocalService\Cookies\system@install.xxxtoolbar[1].txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup D:\Documents and Settings\LocalService\Cookies\system@xxxtoolbar[1].txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup :mozilla.82:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.93:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.97:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.98:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.99:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.100:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.101:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.102:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.103:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.105:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.183:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.186:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.187:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.188:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.189:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.190:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.191:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.192:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.193:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.194:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.197:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.199:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.200:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.201:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.202:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.203:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.204:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.205:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.210:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.211:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.219:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.220:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.221:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.222:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.223:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.224:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.240:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.241:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.242:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.243:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.244:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.263:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.264:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.265:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.274:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.277:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.297:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.301:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.302:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.303:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.304:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.305:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.306:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.307:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.308:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.309:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.310:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.311:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.312:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.313:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.314:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.315:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.318:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.335:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.336:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.337:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.342:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.343:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.344:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.345:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.346:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.347:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.348:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.349:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.350:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.352:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.353:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.354:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.355:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.356:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.357:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.358:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.359:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.360:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.361:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.362:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.363:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.364:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.384:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Estat : Cleaned with backup :mozilla.394:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.409:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.410:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.414:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.415:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup :mozilla.418:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Trafic : Cleaned with backup :mozilla.431:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.468:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.470:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.471:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.472:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.473:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.474:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.480:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.481:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.482:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.483:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.491:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.492:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.493:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.494:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.509:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.510:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.511:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.512:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.523:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.532:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup :mozilla.535:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.536:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.537:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.538:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.539:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.540:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.541:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.543:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup :mozilla.549:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.560:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup :mozilla.577:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.578:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.579:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.585:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.604:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup :mozilla.609:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.610:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.613:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup :mozilla.626:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.627:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.628:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.629:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.638:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hotlog : Cleaned with backup :mozilla.639:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup :mozilla.640:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup :mozilla.654:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup :mozilla.660:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.661:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.662:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.663:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.699:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.700:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.723:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.731:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.732:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.769:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.808:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.846:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.900:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup :mozilla.901:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup :mozilla.902:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup :mozilla.923:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.924:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.961:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup :mozilla.962:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\dsxudnb6.Roni\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup :mozilla.7:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.8:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.9:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.10:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.11:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.12:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.13:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.14:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.15:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.16:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.51:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.52:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.54:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.57:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.63:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup :mozilla.70:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.71:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.72:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.73:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.74:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.75:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.76:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.81:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.82:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.83:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.84:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.85:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.86:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.87:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.94:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup :mozilla.95:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup :mozilla.96:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.97:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.98:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.109:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.110:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.112:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.113:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.114:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.115:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.116:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.117:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.118:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.119:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.120:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.121:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.122:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.123:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.124:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.125:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.126:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.127:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.128:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.129:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.130:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.131:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.132:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.133:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.134:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.135:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.136:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.137:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.138:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.139:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.140:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.141:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.142:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.143:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.144:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.145:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.146:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.147:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.148:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.149:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.150:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.151:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.152:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.153:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.154:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.155:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.156:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.157:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.158:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.161:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup :mozilla.194:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup :mozilla.195:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup :mozilla.200:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.201:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup :mozilla.214:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.216:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.217:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.219:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup :mozilla.221:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup :mozilla.222:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.230:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.231:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.253:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.272:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.273:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.288:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.289:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.290:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.295:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.296:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.297:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.298:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.299:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.300:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.301:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.302:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.305:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup :mozilla.306:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup :mozilla.317:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup :mozilla.320:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup :mozilla.321:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup :mozilla.322:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.323:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.324:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.325:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.332:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.333:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.344:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.348:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.349:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.350:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.351:\Documents and Settings\Roni\Application Data\Mozilla\Firefox\Profiles\tjiznc9n.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@a.as-eu.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@ad.adocean[1].txt -> Spyware.Cookie.Adocean : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@ads.addynamix[2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@as-eu.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@as1.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@cz6.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@edge.ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@isg04.casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@isg05.casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@sel.as-eu.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@trafic[1].txt -> Spyware.Cookie.Trafic : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@www.burstbeacon[2].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@www.sidefind[2].txt -> Spyware.Cookie.Sidefind : Cleaned with backup D:\Documents and Settings\Roni\Cookies\roni@www10.paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup D:\Documents and Settings\Roni\Käynnistä-valikko\Ohjelmat\Power Scan -> Spyware.PowerScan : Cleaned with backup D:\Documents and Settings\Roni\Käynnistä-valikko\Ohjelmat\Power Scan\Power Scan.lnk -> Spyware.PowerScan : Cleaned with backup D:\Documents and Settings\Roni\Omat tiedostot\Ronin Kansio\-=== DC++ ===-\Ladatut\Norton Internet Security 2005 Fin\norton 2005 crack +ohjeet\Norton Internet Security 2005 finnish Keygen.exe -> Dropper.Delf.fd : Cleaned with backup D:\Documents and Settings\Roni\Omat tiedostot\Ronin Kansio\-=== DC++ ===-\Ladatut\Norton Internet Security 2005 Fin\Norton Internet Security 2005 finnish Keygen.exe -> Dropper.Delf.fd : Cleaned with backup D:\Documents and Settings\Roni\Omat tiedostot\Ronin Kansio\-=== Muu P@sk@ ===-\-=== Ohjelmat ===-\keygen\KGNIS.EXE -> Dropper.Delf.fd : Cleaned with backup D:\Documents and Settings\Roni\Omat tiedostot\Ronin Kansio\-=== Muu P@sk@ ===-\-=== Ohjelmat ===-\keygen\SYMANTEC.NORTON.INTERNET.SECURITY.2005.PROPER.Keygen.Only-SSG.rar/KGNIS.EXE -> Dropper.Delf.fd : Error during cleaning D:\WINDOWS\system32\config\systemprofile\Cookies\system@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup D:\WINDOWS\system32\config\systemprofile\Cookies\system@xxxtoolbar[2].txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup ::Report End en vielä poistanut mitään skannauksen jälkeen..
Nämä ei tunnu lähtevän: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hoztlgxelzs.com/kEut9cTBUd2n6gebnuHhDIpo_fZ/E1B4JlrhKM... R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wrdsbllelxaumvmdb.com/kEut9cTBUd3btOu56w6HS/NpInE9smcg... Kokeile fixata vikasietotilassa. (F8 käynnistyksen yhteydessä)
Ewidon loki on ok. Fixaa nuo spertin pyytämät HjT:llä (do a system scan only, merkkaa ja paina fix checked). Jolleivat lähde, niin sitten vikasietotilassa. Käynnistä uudelleen ja lähetä uusi HjT-loki.
Logfile of HijackThis v1.99.1 Scan saved at 17:55:36, on 2.2.2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\System32\Ati2evxx.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\ccProxy.exe D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe D:\Program Files\Norton Internet Security\ISSVC.exe D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe D:\WINDOWS\system32\spoolsv.exe D:\Program Files\ewido anti-malware\ewidoctrl.exe D:\Program Files\ewido anti-malware\ewidoguard.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\SYSTEM32\GEARSEC.EXE D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe D:\Program Files\Logitech\MouseWare\system\em_exec.exe D:\Program Files\Common Files\Symantec Shared\ccApp.exe D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe D:\Program Files\Mozilla Firefox\firefox.exe D:\Program Files\ewido anti-malware\securitysuite.exe D:\Program Files\MSN Messenger\msnmsgr.exe D:\Program Files\Internet Explorer\iexplore.exe D:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [corn new else intra] D:\Documents and Settings\All Users\Application Data\Coal Plan Corn New\soapshow.exe O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\RunServices: [blah service] msnmsgrr.exe O4 - HKLM\..\RunServices: [Microsoft media services] winmplayer.exe O4 - HKLM\..\RunServices: [Windows Compliant] foaxga.exe O4 - HKLM\..\RunServices: [Msbb.exe] Msbb.exe O4 - HKLM\..\RunServices: [Patches Value] WinGamed.exe O4 - HKLM\..\RunServices: [WSSAConfiguration] wmmon32.exe O4 - HKLM\..\RunServices: [MicrosoftUpdate] syshelper.exe O4 - HKLM\..\RunServices: [svhost32] svhost.exe O4 - HKLM\..\RunServices: [Microsoft DirectX] PDSched.exe O4 - HKLM\..\RunServices: [issEnc32Svr] issEnc32.exe O4 - HKCU\..\Run: [rdrburn] D:\DOCUME~1\Roni\APPLIC~1\FINDMA~1\aim bags.exe O4 - HKCU\..\Run: [LDM] D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe O4 - HKCU\..\Run: [FreeRAM XP] "D:\Documents and Settings\Roni\Omat tiedostot\Ronin Kansio\-=== Muu P@sk@ ===-\FreeRAM XP(Pro)\FreeRAM XP Pro 1.40.exe" -win O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {30355649-0000-0010-8000-00AA00389B71} - http://activex.microsoft.com/objects/ocget.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097852316609 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132498147711 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E779A430-5BDF-4A0D-B1BB-A79D1BE93113}: NameServer = 212.50.131.153 213.139.190.3 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WB - D:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - D:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: GEARSecurity - GEAR Software - D:\WINDOWS\SYSTEM32\GEARSEC.EXE O23 - Service: ISSvc (ISSVC) - Symantec Corporation - D:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Fixaa nämä: R3 - Default URLSearchHook is missing O4 - HKLM\..\Run: [corn new else intra] D:\Documents and Settings\All Users\Application Data\Coal Plan Corn New\soapshow.exe O4 - HKLM\..\RunServices: [blah service] msnmsgrr.exe O4 - HKLM\..\RunServices: [Microsoft media services] winmplayer.exe O4 - HKLM\..\RunServices: [Windows Compliant] foaxga.exe O4 - HKLM\..\RunServices: [Msbb.exe] Msbb.exe O4 - HKLM\..\RunServices: [Patches Value] WinGamed.exe O4 - HKLM\..\RunServices: [WSSAConfiguration] wmmon32.exe O4 - HKLM\..\RunServices: [MicrosoftUpdate] syshelper.exe O4 - HKLM\..\RunServices: [svhost32] svhost.exe O4 - HKLM\..\RunServices: [Microsoft DirectX] PDSched.exe O4 - HKLM\..\RunServices: [issEnc32Svr] issEnc32.exe O4 - HKCU\..\Run: [rdrburn] D:\DOCUME~1\Roni\APPLIC~1\FINDMA~1\aim bags.exe O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone Poista: D:\Documents and Settings\All Users\Application Data\==>Coal Plan Corn New<=== D:\DOCUME~1\Roni\APPLIC~1\===>FINDMA~1<==== Käynnistä uudelleen ja lähetä uusi HjT-loki.
Logfile of HijackThis v1.99.1 Scan saved at 18:21:40, on 2.2.2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\System32\Ati2evxx.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\ccProxy.exe D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe D:\Program Files\Norton Internet Security\ISSVC.exe D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe D:\WINDOWS\system32\spoolsv.exe D:\Program Files\ewido anti-malware\ewidoctrl.exe D:\Program Files\ewido anti-malware\ewidoguard.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\SYSTEM32\GEARSEC.EXE D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe D:\Program Files\Common Files\Symantec Shared\ccApp.exe D:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe D:\WINDOWS\System32\wuauclt.exe D:\Program Files\Mozilla Firefox\firefox.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\RunServices: [blah service] msnmsgrr.exe O4 - HKCU\..\Run: [LDM] D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe O4 - HKCU\..\Run: [FreeRAM XP] "D:\Documents and Settings\Roni\Omat tiedostot\Ronin Kansio\-=== Muu P@sk@ ===-\FreeRAM XP(Pro)\FreeRAM XP Pro 1.40.exe" -win O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {30355649-0000-0010-8000-00AA00389B71} - http://activex.microsoft.com/objects/ocget.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1097852316609 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132498147711 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E779A430-5BDF-4A0D-B1BB-A79D1BE93113}: NameServer = 212.50.131.153 213.139.190.3 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WB - D:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - D:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: GEARSecurity - GEAR Software - D:\WINDOWS\SYSTEM32\GEARSEC.EXE O23 - Service: ISSvc (ISSVC) - Symantec Corporation - D:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe