Jump to content

SUBIECTE NOI
« 1 / 5 »
RSS
Cum curat gletul de pe perete

Muzica trance

Soluție incalzire apartament...

Culori fire la boxele de jogger
 Autorizatie Birou Acte Auto

Parbriz defect

Ajutor cercetare lucrare de diser...

M-am culcat cu un tip și apo...
 Facultate din Bucuresti posibil o...

Eroare steering

Recomandare service pentru repara...

Premier Energy se listeaza la bursa
 Unde recomandati un CT cu Casa de...

Adaptare masina pentru o persoana...

Bios laptop Myria MY8315

Folie display laptop in Bucuresti?
 

HijackThis - alexxx21a

- - - - -
  • Please log in to reply
50 replies to this topic

#19
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010

 Official, on 17th August 2010, 18:18, said:

Nu uita sa inlocuiesti Nod32 si de pe acest sistem.  :)



si care dintre Avast si Avira sa-l pun ? care este mai simplu , sa nu foloseasca prea multe resurse si sa si detecteze virusii ?

#20
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Avira Free.

#21
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
salut baieti .Am revenit cu inca un calculator . De data aceasta este un laptop cu xp sp 3 . Pe acest calculator nu imi apareau erori ca pe celelalte 2 la pornirea calculatorului , dar merge foarte greu ( pe acesta am ca si antivirus AVG antivirus Free ).

Iata si primul log dupa rularea programului HiJackThis :

Quote

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:42:15 PM, on 8/21/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Join Air\AssistantServices.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Join Air\UIExec.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TRENDnet\TRENDnet TEW-421PC_TEW-423PI\WlanCU.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ro/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: TvOnline by WebDessign Toolbar - {77d0b2ea-9fb1-491c-bd40-04e2232bdd22} - C:\Program Files\TvOnline_by_WebDessign\tbTvOn.dll
R3 - URLSearchHook: RO-TV Toolbar - {4b74dfe1-d092-4433-8897-8d3729e20bc5} - C:\Program Files\RO-TV\tbRO-T.dll
O2 - BHO: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: RO-TV Toolbar - {4b74dfe1-d092-4433-8897-8d3729e20bc5} - C:\Program Files\RO-TV\tbRO-T.dll
O2 - BHO: TvOnline by WebDessign Toolbar - {77d0b2ea-9fb1-491c-bd40-04e2232bdd22} - C:\Program Files\TvOnline_by_WebDessign\tbTvOn.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Daemon Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: BS.Player ControlBar - {2C688203-7EB3-4327-9995-1CB417BA23F9} - C:\Program Files\BS.Player ControlBar\BSToolbar.dll
O3 - Toolbar: TvOnline by WebDessign Toolbar - {77d0b2ea-9fb1-491c-bd40-04e2232bdd22} - C:\Program Files\TvOnline_by_WebDessign\tbTvOn.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: RO-TV Toolbar - {4b74dfe1-d092-4433-8897-8d3729e20bc5} - C:\Program Files\RO-TV\tbRO-T.dll
O3 - Toolbar: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Detect] C:\Program Files\iNTERNET Turbo\iDetect.exe /auto
O4 - HKLM\..\Run: [UIExec] "C:\Program Files\Join Air\UIExec.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'Default user')
O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Program Files\TRENDnet\TRENDnet TEW-421PC_TEW-423PI\WlanCU.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} (Gif89 Lite Class) - http://195.47.194.200/xplugLite.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: UI Assistant Service - Unknown owner - C:\Program Files\Join Air\AssistantServices.exe

--
End of file - 8395 bytes


Va rog daca puteti sa ma ajutati si cu acesta. Multumesc mult

#22
MhG_51

MhG_51

    :)

  • Grup: Moderators
  • Posts: 3,320
  • Înscris: 04.05.2009
Bifeaza si da fix la:

Quote

O2 - BHO: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O3 - Toolbar: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)

Descarca

Malwarebytes Anti-Malware 1.46

si salveaza-l pe Desktop.

Instaleaza-l si la sfarsit asigura-te ca ai bifat urmatoarele: Update Malwarebytes' Anti-Malware si Launch Malwarebytes' Anti-Malware. Apoi apasa Finish.

Posted Image

Dupa lansarea programului, click pe tab-ul Update si apasa butonul Check for Updates pentru a verifica daca definitiile descarcate sunt ultimele.

Database version: 44xx

Posted Image

Click pe tab-ul Scanner, selecteaza Perform full scan si apoi apasa pe Scan.

Posted Image

La terminarea scanarii apasa OK si apoi Show Results.

Posted Image

Posted Image

Asigura-te ca e totul bifat si apoi apasa Remove Selected.

Posted Image

Posted Image

La final se va deschide un fisier in Notepad cu rezultatele scanarii. Posteaza continutul lui aici.

Posted Image

Daca ai dat restart pentru indepartare malware din PC, log-ul il gasesti in fereastra principala in cadrul tab-ului Logs. Verifica sa fie ultimul(dupa data din numele fisierului .txt.)

Posted Image

#23
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Inainte de acest pas nu trebuia sa fac pasul cu ComboFix ?

#24
MhG_51

MhG_51

    :)

  • Grup: Moderators
  • Posts: 3,320
  • Înscris: 04.05.2009

 alexxx21a, on 21st August 2010, 19:07, said:

Inainte de acest pas nu trebuia sa fac pasul cu ComboFix ?
Nu e nevoie de ComboFix.

#25
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010

Quote

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4457

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

8/21/2010 10:09:58 PM
mbam-log-2010-08-21 (22-09-58).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 188554
Time elapsed: 33 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\RelevantKnowledge (Spyware.MarketScore) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\RelevantKnowledge\rlservice.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
C:\Program Files\RelevantKnowledge\MSVCP71.DLL (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Program Files\RelevantKnowledge\MSVCR71.DLL (Spyware.MarketScore) -> Quarantined and deleted successfully.


#26
MhG_51

MhG_51

    :)

  • Grup: Moderators
  • Posts: 3,320
  • Înscris: 04.05.2009
Descarca

SUPERAntiSpyware 4.36.1006

si salveaza-l pe Desktop.

Instaleaza-l, apoi deschide fereasta principala si apasa Check for Updates...

Definition Database Version

Core: 4XXX

Posted Image

Dupa update, apasa Scan your Computer...

Asigura-te ca e bifat Perform Complete Scan si apasa Next.

Posted Image

Dupa scanare si afisarea rezultatelor, apasa Next.

Posted Image

Apoi Yes.

Posted Image

Posteaza apoi aici rezultatele scanarii.

#27
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Am facut si aceasta treaba, s-a dat restart , iar apoi am facut un printscreen caci nu am gasit log-ul , dar am gasit si acel log in cele din urma .

Quote

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/22/2010 at 01:34 PM

Application Version : 4.41.1000

Core Rules Database Version : 5390
Trace Rules Database Version: 3202

Scan type       : Complete Scan
Total Scan Time : 00:24:23

Memory items scanned      : 592
Memory threats detected   : 0
Registry items scanned    : 5945
Registry threats detected : 5
File items scanned        : 13714
File threats detected     : 310

Adware.HBHelper
HKU\S-1-5-19_Classes\Software\Microsoft\Internet Explorer\URLSearchHooks#{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKU\S-1-5-20_Classes\Software\Microsoft\Internet Explorer\URLSearchHooks#{CA3EB689-8F09-4026-AA10-B9534C691CE0}

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@clicksor[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@extremedogsex[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ero-advertising[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@lfstmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adtech[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bluestreak[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@porndad[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@xiti[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bravoteens[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@pornmoviestgp[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fuckbookdating[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@myroitracking[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@serialealese[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bravenet[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@revsci[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@sextracker[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@a-stat[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@trafficholder[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@yadro[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@youporn[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@triosex[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@gostats[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@chitika[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adultfriendfinder[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adultadworld[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@livefilmeporno[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@freeyouporn[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@3animalsex[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][7].txt
C:\Documents and Settings\Administrator\Cookies\administrator@imrworldwide[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bizarresextube[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@zooporn[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@toplist[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@sexlist[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@animalporntv[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@filmuletexxx[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@freebestialityporn[3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@porno-romania[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@filmeporno[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@crazyhomesex[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@filme-xxx[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@serialepe[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@homeanimalsex[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@filme-adult-tv[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@zoosextv[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@rawhomeporn[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bizarresextube[3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bxxxp[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@alphaporno[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@zedo[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediafire[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@toplist[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@yieldmanager[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@liveperson[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@countomat[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@freebestialityporn[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@hornyandhappy[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@sexytop[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@smartadserver[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@stimorolsex[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@pornstarspunishment[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@filmexxx[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@sexxxyteentube[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@sunporno[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@partypoker[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@tradedoubler[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][4].txt
C:\Documents and Settings\Administrator\Cookies\administrator@baymediagroup[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@hubporno[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@invitemedia[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@youngzoosex[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@seximus[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@topfuckmovies[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][5].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@porno-cu-babe[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@topfuckmovies[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@web-stat[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@xxxpower[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@momisnaked[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adinterax[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@roadvertising[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@aboutporno[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@sexmix[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@twelvefifteen[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@pornake[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
content.video.imedia.ro [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
core.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
ia.media-imdb.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
macromedia.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
media.myadevarul.ro [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
media.scanscout.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
s1.media.howtospendit.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
secure-us.imrworldwide.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
static.mediadirect.ro [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
vidii.hardsextube.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
www.alphaporno.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
www.filmexxx.cc [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
www.lust4porno.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
www.mediafax.ro [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
www.naiadsystems.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
www.porncy.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
www.sextvx.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
wwwstatic.megaporn.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\T6RM3RR5 ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.doubleclick.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.bravenet.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.count.brat-online.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.bs.serving-sys.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
statse.webtrendslive.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.myroitracking.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.collective-media.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.collective-media.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
ad1.clickhype.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
metroleap.rotator.hadj7.adjuggler.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
metroleap.rotator.hadj7.adjuggler.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.videoegg.adbureau.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.smartadserver.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.smartadserver.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.smartadserver.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.smartadserver.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.adinterax.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.adinterax.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.stanleybetv2.globalsportsmedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.stanleybetv2.globalsportsmedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
www.googleadservices.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.apmebf.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.mediaplex.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.bluestreak.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
www.googleadservices.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.avgtechnologies.112.2o7.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
www.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
www.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
www.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
www.casefaraintermediari.ro [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
adserver.mconet.hu [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.richmedia.yahoo.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
fr.sitestat.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
fr.sitestat.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.ehg-lexmark.hitbox.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.hitbox.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.content.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.chitika.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.smartadserver.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.xiti.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
www.googleadservices.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
.content.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\g2zlwq73.default\cookies.sqlite ]
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt
C:\Documents and Settings\LocalService\Cookies\system@interclick[1].txt
C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt
C:\Documents and Settings\LocalService\Cookies\system@fastclick[1].txt
C:\Documents and Settings\LocalService\Cookies\system@atdmt[1].txt

Malware.Trace
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon#Taskman [ G:\mirk\okitab.exe ]
HKU\S-1-5-21-1708537768-1993962763-1177238915-500\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL

Trojan.Agent/Gen-FakeAlert
C:\PROGRAM FILES\WINAMP\PLUGINS\IN_FLAC.DLL

Trojan.Agent/Gen-Backdoor
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D3C7E616-19D8-4319-B1CD-F4945FB74D11}\RP88\A0011368.EXE

Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D3C7E616-19D8-4319-B1CD-F4945FB74D11}\RP90\A0011550.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D3C7E616-19D8-4319-B1CD-F4945FB74D11}\RP90\A0011552.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D3C7E616-19D8-4319-B1CD-F4945FB74D11}\RP90\A0011553.DLL
E:\SYSTEM VOLUME INFORMATION\_RESTORE{D3C7E616-19D8-4319-B1CD-F4945FB74D11}\RP90\A0011551.EXE

Attached Files



#28
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Urme de malware si un backdoor. Curata infectiile. Restart.

Mai sunt probleme ?

#29
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
sincer mi se pare ca da. Cand misc mouse-ul merge putin se blocheaza, merge iara. In MyComputer cand si cum vrea el .

#30
MhG_51

MhG_51

    :)

  • Grup: Moderators
  • Posts: 3,320
  • Înscris: 04.05.2009
Posteza, te rog, un log nou cu HiJackThis.
http://forum.softped...t...t&p=8588576

#31
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010

Quote

Logfile of Trend Micro HiJackThis v2.0.4
Scan saved at 2:47:04 PM, on 8/22/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Join Air\AssistantServices.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Join Air\UIExec.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\TRENDnet\TRENDnet TEW-421PC_TEW-423PI\WlanCU.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Zoner\Photo Studio 12\Program\Zps.exe
C:\Program Files\Zoner\Photo Studio 12\Program\Zps.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ro/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: TvOnline by WebDessign Toolbar - {77d0b2ea-9fb1-491c-bd40-04e2232bdd22} - C:\Program Files\TvOnline_by_WebDessign\tbTvOn.dll
R3 - URLSearchHook: RO-TV Toolbar - {4b74dfe1-d092-4433-8897-8d3729e20bc5} - C:\Program Files\RO-TV\tbRO-T.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: RO-TV Toolbar - {4b74dfe1-d092-4433-8897-8d3729e20bc5} - C:\Program Files\RO-TV\tbRO-T.dll
O2 - BHO: TvOnline by WebDessign Toolbar - {77d0b2ea-9fb1-491c-bd40-04e2232bdd22} - C:\Program Files\TvOnline_by_WebDessign\tbTvOn.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Daemon Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: BS.Player ControlBar - {2C688203-7EB3-4327-9995-1CB417BA23F9} - C:\Program Files\BS.Player ControlBar\BSToolbar.dll
O3 - Toolbar: TvOnline by WebDessign Toolbar - {77d0b2ea-9fb1-491c-bd40-04e2232bdd22} - C:\Program Files\TvOnline_by_WebDessign\tbTvOn.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: RO-TV Toolbar - {4b74dfe1-d092-4433-8897-8d3729e20bc5} - C:\Program Files\RO-TV\tbRO-T.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Detect] C:\Program Files\iNTERNET Turbo\iDetect.exe /auto
O4 - HKLM\..\Run: [UIExec] "C:\Program Files\Join Air\UIExec.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'Default user')
O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Program Files\TRENDnet\TRENDnet TEW-421PC_TEW-423PI\WlanCU.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} (Gif89 Lite Class) - http://195.47.194.200/xplugLite.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - Invalid registry found
O20 - Winlogon Notify: avgrsstarter - Invalid registry found
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: UI Assistant Service - Unknown owner - C:\Program Files\Join Air\AssistantServices.exe

--
End of file - 8350 bytes


#32
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
AVG ruleaza ?

Raporteaza o intrare invalida in registry.

Descarca

Dr.Web CureIt! 6.00.2

Scoate cablul de Internet, opreste protectia real-time(scutul) a antivirus-ului instalat pe PC si scaneaza full cu acest utilitar.

Initial, la rulare, Dr.Web CureIt! incepe un Express Scan. Apasa butonul Stop in dreapta cand acesta are culoarea verde.

Posted Image

Bifeaza apoi in stanga Complete Scan si asa in dreapta pe butonul verde Play.

Posted Image

La terminarea scanarii dezinfecteaza/sterge toate fisierele detectate.

Restart, activeaza protectia antivirus, conecteaza cablul de internet.

#33
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Gata , dupa vreo 2 ore si ceva a terminat . A gasit doar un virus  - CMCOMService.dll;C:\Program Files\Join Air\Component;Adware.Siggen.8058;Deleted.;

Tot la fel mi se pare ca merge .

#34
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Curata registry cu CCleaner. Defragmenteaza HDD.

Edited by crysty2k5, 22 August 2010 - 18:11.


#35
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Salutare baieti , am revenit cu o noua problema. Pe calculatorul de acasa nu mai am nici o problema , merge lux , dar aici pe calculatorul unui prieten de-al meu am scos tot ce era de scos de pe hard am formatat tot HDD`ul si am reinstalat din nou windowsul ( Vezi poza ) . Am instalat toate programele ce le aveam de instalat si totul mergea bine . DUpa ce am inchis calculatorul si am incercat sa-l pornesc din nou , chiar dupa logare se blocheaza calculatorul. Raman toate beculetele de jos de la unitate pornite si blocate , mouse-ul se blocheaza si nu mai pot face nimic. Se repeta aceeasi faza timp de vreo 4-5 restarturi cat le dau pana sa mearga cum trebuie . In plus dupa perioade mai mari de functionare , sa zic de la 2-3 ore in sus daca ne uitam la ceva film sau jucam ceva jocuri pe el se blocheaza.

Sper sa ma puteti ajuta si de aceasta data . Multumesc !

Attached Files

  • Attached File  1.JPG   30.69K   17 downloads


#36
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Antivirus ai ?

Anunturi

Chirurgia cranio-cerebrală minim invazivă Chirurgia cranio-cerebrală minim invazivă

Tehnicile minim invazive impun utilizarea unei tehnologii ultramoderne.

Endoscoapele operatorii de diverse tipuri, microscopul operator dedicat, neuronavigația, neuroelectrofiziologia, tehnicile avansate de anestezie, chirurgia cu pacientul treaz reprezintă armamentarium fără de care neurochirurgia prin "gaura cheii" nu ar fi posibilă. Folosind tehnicile de mai sus, tratăm un spectru larg de patologii cranio-cerebrale.

www.neurohope.ro

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Forumul Softpedia foloseste "cookies" pentru a imbunatati experienta utilizatorilor Accept
Pentru detalii si optiuni legate de cookies si datele personale, consultati Politica de utilizare cookies si Politica de confidentialitate