Bardzo wolne łacze


(vito corleone) #1

ostatnio mój net mocno szwankuje :confused:

przeskanowanie ad aware i spybotem nic nie dało (poza jakimis tam robakami), ale chyba coś mi siedzi w systemie :confused:

załaczam logi

hijack

Logfile of HijackThis v1.99.1

Scan saved at 14:37:59, on 2006-12-27

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

e:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

e:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\Program Files\D-Link AirPlus\AirPlus.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

e:\Program Files\Alwil Software\Avast4\ashWebSv.exe

G:\Program Files\Mozilla Firefox\firefox.exe

G:\Program Files\Tlen.pl\tlen.exe

E:\Program Files\Winamp\winamp.exe

C:\DOCUME~1\admin\USTAWI~1\Temp\Rar$EX01.024\HijackThis.exe

C:\Program Files\WinRAR\WinRAR.exe

C:\DOCUME~1\admin\USTAWI~1\Temp\Rar$EX00.369\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - G:\PROGRA~1\FlashGet\jccatch.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - G:\PROGRA~1\FlashGet\getflash.dll

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\fgiebar.dll

O4 - HKLM\..\Run: [avast!] e:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - Global Startup: D-Link AirPlus.lnk = ?

O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - G:\Program Files\FlashGet\jc_link.htm

O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - G:\Program Files\FlashGet\jc_all.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game11.zylom.com/activex/zylomgamesplayer.cab

O20 - Winlogon Notify: rpcc - C:\WINDOWS\

O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - e:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - e:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Web Scanner - Unknown owner - e:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: lxcg_device - - C:\WINDOWS\System32\lxcgcoms.exe

i Silent Runners

"Silent Runners.vbs", revision 49, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by "{++}"



Startup items buried in registry:

---------------------------------


HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]

"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

"SpybotSD TeaTimer" = "F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" ["Safer Networking Limited"]


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"avast!" = "e:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "AcroIEHlprObj Class"

                   \InProcServer32\(Default) = "G:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]

{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "IeCatch5 Class"

                   \InProcServer32\(Default) = "G:\PROGRA~1\FlashGet\jccatch.dll" ["FlashGet"]

{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "F:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "SSVHelper Class"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]

{F156768E-81EF-470C-9057-481BA8380DBA}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "gFlash Class"

                   \InProcServer32\(Default) = "G:\PROGRA~1\FlashGet\getflash.dll" [null data]


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

                   \InProcServer32\(Default) = "*_" (unwritable string) [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"

                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]

"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "g:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "e:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "e:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "e:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "g:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "g:\Program Files\Unlocker\UnlockerCOM.dll" [null data]



Group Policies {GPedit.msc branch and setting}:

-----------------------------------------------


Note: detected settings may not have any effect.


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\


"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Shutdown: Allow system to be shut down without having to log on}


"undockwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Devices: Allow undock without having to log on}



Active Desktop and Wallpaper:

-----------------------------


Active Desktop may be disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

HKCU\Software\Microsoft\Internet Explorer\Desktop\General\

"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

HKCU\Control Panel\Desktop\

"Wallpaper" = "C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Tapeta pulpitu.bmp"



Enabled Screen Saver:

---------------------


HKCU\Control Panel\Desktop\

"SCRNSAVE.EXE" = "C:\WINDOWS\system32\sstext3d.scr" [MS]



Startup items in "admin" & "All Users" startup folders:

-------------------------------------------------------


C:\Documents and Settings\All Users\Menu Start\Programy\Autostart

"D-Link AirPlus" -> shortcut to: "C:\Program Files\D-Link AirPlus\AirPlus.exe" ["D-Link"]



Winsock2 Service Provider DLLs:

-------------------------------


Namespace Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


Transport Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 16

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05



Toolbars, Explorer Bars, Extensions:

------------------------------------


Toolbars


HKLM\Software\Microsoft\Internet Explorer\Toolbar\

"{E0E899AB-F487-11D5-8D29-0050BA6940E3}" = "FlashGet Bar"

  -> {HKLM...CLSID} = "FlashGet Bar"

                   \InProcServer32\(Default) = "G:\PROGRA~1\FlashGet\fgiebar.dll" ["Amaze Soft"]


Extensions (Tools menu items, main toolbar menu buttons)


HKLM\Software\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\

"MenuText" = "Sun Java Console"

"CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"

  -> {HKCU...CLSID} = "Java Plug-in"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]

  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_06"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."]


{D6E814A0-E0C5-11D4-8D29-0050BA6940E3}\

"ButtonText" = "FlashGet"

"MenuText" = "&FlashGet"

"Exec" = "G:\PROGRA~1\FlashGet\flashget.exe" ["FlashGet.com"]


{FB5F1910-F110-11D2-BB9E-00C04F795683}\

"ButtonText" = "Messenger"

"MenuText" = "Windows Messenger"

"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]



Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------


avast! Antivirus, avast! Antivirus, ""e:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]

avast! iAVS4 Control Service, aswUpdSv, ""e:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]

avast! Web Scanner, avast! Web Scanner, ""e:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]



Print Monitors:

---------------


HKLM\System\CurrentControlSet\Control\Print\Monitors\

2300 Series Port\Driver = "lxcglmpm.DLL" [" "]



----------

+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

  launch it from a command prompt or a shortcut with the -all parameter.

+ To search all directories of local fixed drives for DESKTOP.INI

  DLL launch points, use the -supp parameter or answer "No" at the

  first message box and "Yes" at the second message box.

---------- (total run time: 224 seconds, including 10 seconds for message boxes)

(adam9870) #2

usuń w hjt.

Jakie masz łącze ?? Może przekroczyłeś limit pobierania danych o ile takowy jest ??

Możesz przeskanować http://www.ewido.net/en/ i pokazać raport.


(vito corleone) #3

ale w jaki sposób skoro jak usune i uruchomie ponownie system to znowu jest :confused:

mam radiowe łacze bez żadnego limitu

raport?

mam nadzieje ze o taki chodzi

---------------------------------------------------------

AVG Anti-Spyware - Scan Report

---------------------------------------------------------


 + Created at:	17:54:00 2006-12-27


 + Scan result:	




G:\Program Files\Tlen.pl\plugins\DozaKultury.tpl -> Adware.Doza : Ignored.

G:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Ignored.

:mozilla.122:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.203:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.204:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.205:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.206:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.207:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.208:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.209:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.210:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.234:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

:mozilla.235:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

:mozilla.605:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.606:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.607:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.608:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.609:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.

:mozilla.215:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adbrite : Error during cleaning.

:mozilla.216:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adbrite : Error during cleaning.

:mozilla.217:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adbrite : Error during cleaning.

:mozilla.218:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adbrite : Error during cleaning.

:mozilla.268:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.

:mozilla.269:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.

:mozilla.102:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.103:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.103:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.104:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.13:C:\Documents and Settings\admin\Moje dokumenty\Firefox 1.0.7 (pl-PL) - 2005-11-18.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.13:F:\MOJE\moje dane\Moje dokumenty\Firefox 1.0.7 (pl-PL) - 2005-11-18.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.14:C:\Documents and Settings\admin\Moje dokumenty\Firefox 1.0.7 (pl-PL) - 2005-11-18.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.14:F:\MOJE\moje dane\Moje dokumenty\Firefox 1.0.7 (pl-PL) - 2005-11-18.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.170:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.171:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.196:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.197:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.269:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.270:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.329:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.330:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.337:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.338:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.338:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.339:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.339:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.340:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.35:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.36:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.420:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.421:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.42:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.43:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.47:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.489:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.48:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.490:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.491:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.492:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.528:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.529:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.536:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.537:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.555:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.556:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.614:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.615:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.653:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.654:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.

:mozilla.707:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.708:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.76:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.77:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Adocean : Error during cleaning.

:mozilla.118:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Adtech : Error during cleaning.

:mozilla.119:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Adtech : Error during cleaning.

:mozilla.224:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adtech : Error during cleaning.

:mozilla.225:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Adtech : Error during cleaning.

:mozilla.228:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adtech : Error during cleaning.

:mozilla.229:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adtech : Error during cleaning.

:mozilla.315:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.

:mozilla.316:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.

:mozilla.230:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Adtiger : Error during cleaning.

:mozilla.404:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Adtiger : Cleaned.

:mozilla.601:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.

:mozilla.602:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.

:mozilla.603:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.

:mozilla.604:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.

:mozilla.298:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Atdmt : Error during cleaning.

:mozilla.641:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Bfast : Error during cleaning.

:mozilla.272:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Burstnet : Error during cleaning.

:mozilla.432:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.

:mozilla.639:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Burstnet : Error during cleaning.

:mozilla.640:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Burstnet : Error during cleaning.

:mozilla.132:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.133:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.137:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.138:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.139:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.487:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.488:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.489:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.490:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.491:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.492:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.82:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.

:mozilla.344:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.

:mozilla.345:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.

:mozilla.811:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Coremetrics : Error during cleaning.

:mozilla.272:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Doubleclick : Error during cleaning.

:mozilla.589:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Falkag : Error during cleaning.

:mozilla.590:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Falkag : Error during cleaning.

:mozilla.591:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Falkag : Error during cleaning.

:mozilla.592:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Falkag : Error during cleaning.

:mozilla.728:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Falkag : Error during cleaning.

:mozilla.729:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Falkag : Error during cleaning.

:mozilla.730:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Falkag : Error during cleaning.

:mozilla.731:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Falkag : Error during cleaning.

:mozilla.800:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.

:mozilla.801:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.

:mozilla.129:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning.

:mozilla.130:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning.

:mozilla.131:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning.

:mozilla.210:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.

:mozilla.211:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.

:mozilla.481:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning.

:mozilla.482:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning.

:mozilla.85:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning.

:mozilla.86:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning.

:mozilla.194:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

:mozilla.859:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning.

:mozilla.860:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning.

:mozilla.306:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning.

:mozilla.307:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning.

:mozilla.308:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning.

:mozilla.593:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning.

:mozilla.904:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning.

:mozilla.905:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning.

:mozilla.123:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hitslink : Error during cleaning.

:mozilla.857:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hitslink : Error during cleaning.

:mozilla.132:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Hotlog : Error during cleaning.

:mozilla.381:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Hotlog : Error during cleaning.

:mozilla.530:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.

:mozilla.709:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Itrack : Error during cleaning.

:mozilla.710:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Itrack : Error during cleaning.

:mozilla.422:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Ivwbox : Error during cleaning.

:mozilla.725:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Ivwbox : Error during cleaning.

:mozilla.851:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Komtrack : Error during cleaning.

:mozilla.852:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Komtrack : Error during cleaning.

:mozilla.610:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Mediaplex : Error during cleaning.

:mozilla.789:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Onestat : Error during cleaning.

:mozilla.790:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Onestat : Error during cleaning.

:mozilla.791:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Onestat : Error during cleaning.

:mozilla.845:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.

:mozilla.846:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.

:mozilla.235:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Qksrv : Error during cleaning.

:mozilla.236:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Qksrv : Error during cleaning.

:mozilla.545:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Qksrv : Error during cleaning.

:mozilla.546:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Qksrv : Error during cleaning.

:mozilla.660:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.

:mozilla.661:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.

:mozilla.913:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.

:mozilla.914:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.

:mozilla.915:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.

:mozilla.916:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.

:mozilla.917:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.

:mozilla.350:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.

:mozilla.559:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Spylog : Error during cleaning.

:mozilla.84:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Spylog : Error during cleaning.

:mozilla.460:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.

:mozilla.461:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.

:mozilla.462:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.

:mozilla.611:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Tacoda : Error during cleaning.

:mozilla.612:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Tacoda : Error during cleaning.

:mozilla.712:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.

:mozilla.713:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.

:mozilla.759:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Tacoda : Error during cleaning.

:mozilla.760:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Tacoda : Error during cleaning.

:mozilla.293:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.

:mozilla.294:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.

:mozilla.21:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.22:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.22:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.23:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.24:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.25:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.26:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.44:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.

:mozilla.45:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.

:mozilla.45:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.46:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning.

:mozilla.620:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Trafic : Error during cleaning.

:mozilla.718:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.

:mozilla.757:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Trafic : Error during cleaning.

:mozilla.272:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.

:mozilla.483:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning.

:mozilla.621:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning.

:mozilla.557:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.558:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.559:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.560:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.561:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.670:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.

:mozilla.671:C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\cvquf24c.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.

:mozilla.752:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.753:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.754:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.755:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.756:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.758:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Valuead : Error during cleaning.

:mozilla.80:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Webtrendslive : Error during cleaning.

:mozilla.131:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Yadro : Error during cleaning.

:mozilla.86:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Yadro : Error during cleaning.

:mozilla.116:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.117:G:\kopia firefoxa\Firefox 1.5 (pl) - 2006-12-22.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.56:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.57:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.58:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.59:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.60:G:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dg3.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.83:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.85:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.86:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.87:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.88:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.89:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.

:mozilla.484:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Zedo : Error during cleaning.

:mozilla.485:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Zedo : Error during cleaning.

:mozilla.486:C:\RECYCLER\S-1-5-21-583907252-2077806209-1177238915-1003\Dc273.pcv/cookies.txt -> TrackingCookie.Zedo : Error during cleaning.



::Report end

(Joan Sunshine) #4

Dltego, że włączony jest TeaTimer Spybota i blokuje usuwanie, wyłącz go na czas kasowania wpisów :slight_smile:

Fix w HJT.

Zrób jeszcze raz pełen skan AVG, użyj też następujących programów:

Spysweeper

http://www.webroot.com

Adaware

:slight_smile:


(vito corleone) #5

ani wyłaczenie ani w trybie awaryjnym nic nie daje :confused:

po restarcie dalej jest

sam plik skasowałem już dawno dawno ale wpis zostaje ;/


(Bbieniol) #6

Otwórz notatnik i wklej w nim to:

Plik -> zapisz jako -> zmień rozszerzenie na wszystkie pliki -> zapisz pod nazwą FIX.REG

Odpal plik FIX.REG i potwierdź dodanie do rejestru i reset kompa :slight_smile:


(vito corleone) #7

wczesniej mi taki sposob nie działał :stuck_out_tongue:

i tak dalej mam te 55.161 Kbps (IP: 6.9 KB/sec - ATM: 8.62 KB/sec) :confused:


(Bbieniol) #8

Według mnie pli nadal siedzi, tak więc:

Uruchamiasz narzędzie KillBox, zaznaczasz Delete on reboot , w polu full path of file wklej ścieżkę:

C:\WINDOWS\system32\rpcc.dll

Klikasz X i restart kompa :slight_smile:

Następnie usuwasz wpis i wklejasz nowe logi :slight_smile:


(vito corleone) #9

nie było pliku

hijack

Logfile of HijackThis v1.99.1

Scan saved at 16:13:03, on 2006-12-28

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

e:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

e:\Program Files\Alwil Software\Avast4\ashServ.exe

E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Messenger\msmsgs.exe

g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\D-Link AirPlus\AirPlus.exe

C:\WINDOWS\system32\wscntfy.exe

e:\Program Files\Alwil Software\Avast4\ashWebSv.exe

G:\Program Files\Tlen.pl\tlen.exe

G:\Program Files\Mozilla Firefox\firefox.exe

E:\Program Files\Winamp\winamp.exe

C:\Documents and Settings\admin\Pulpit\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - G:\PROGRA~1\FlashGet\jccatch.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - G:\PROGRA~1\FlashGet\getflash.dll

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\fgiebar.dll

O4 - HKLM\..\Run: [avast!] e:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: D-Link AirPlus.lnk = ?

O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - G:\Program Files\FlashGet\jc_link.htm

O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - G:\Program Files\FlashGet\jc_all.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - e:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - e:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Web Scanner - Unknown owner - e:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: lxcg_device - - C:\WINDOWS\System32\lxcgcoms.exe

Silent

"Silent Runners.vbs", revision 49, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by "{++}"



Startup items buried in registry:

---------------------------------


HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]

"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"avast!" = "e:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "AcroIEHlprObj Class"

                   \InProcServer32\(Default) = "G:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]

{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "IeCatch5 Class"

                   \InProcServer32\(Default) = "G:\PROGRA~1\FlashGet\jccatch.dll" ["FlashGet"]

{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "F:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "SSVHelper Class"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]

{F156768E-81EF-470C-9057-481BA8380DBA}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "gFlash Class"

                   \InProcServer32\(Default) = "G:\PROGRA~1\FlashGet\getflash.dll" [null data]


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

                   \InProcServer32\(Default) = "*g" (unwritable string) [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"

                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]

"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "g:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "e:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\

<> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"

  -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"

                   \InProcServer32\(Default) = "g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "e:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"

  -> {HKLM...CLSID} = "CContextScan Object"

                   \InProcServer32\(Default) = "g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"

  -> {HKLM...CLSID} = "CContextScan Object"

                   \InProcServer32\(Default) = "g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "e:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "g:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "g:\Program Files\Unlocker\UnlockerCOM.dll" [null data]



Group Policies {GPedit.msc branch and setting}:

-----------------------------------------------


Note: detected settings may not have any effect.


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"NoSaveSettings" = (REG_DWORD) hex:0x00000000

{User Configuration|Administrative Templates|Desktop|

Don't save settings at exit}


"ClearRecentDocsOnExit" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"NoRemoteRecursiveEvents" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


"ClearRecentDocsOnExit" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\


"DisableRegistryTools" = (REG_DWORD) hex:0x00000000

{User Configuration|Administrative Templates|System|

Prevent access to registry editing tools}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\


"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Shutdown: Allow system to be shut down without having to log on}


"undockwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Devices: Allow undock without having to log on}



Active Desktop and Wallpaper:

-----------------------------


Active Desktop may be disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

HKCU\Software\Microsoft\Internet Explorer\Desktop\General\

"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

HKCU\Control Panel\Desktop\

"Wallpaper" = "C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Tapeta pulpitu.bmp"



Enabled Screen Saver:

---------------------


HKCU\Control Panel\Desktop\

"SCRNSAVE.EXE" = "C:\WINDOWS\system32\sstext3d.scr" [MS]



Startup items in "admin" & "All Users" startup folders:

-------------------------------------------------------


C:\Documents and Settings\All Users\Menu Start\Programy\Autostart

"D-Link AirPlus" -> shortcut to: "C:\Program Files\D-Link AirPlus\AirPlus.exe" ["D-Link"]



Winsock2 Service Provider DLLs:

-------------------------------


Namespace Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


Transport Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 16

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05



Toolbars, Explorer Bars, Extensions:

------------------------------------


Toolbars


HKLM\Software\Microsoft\Internet Explorer\Toolbar\

"{E0E899AB-F487-11D5-8D29-0050BA6940E3}" = "FlashGet Bar"

  -> {HKLM...CLSID} = "FlashGet Bar"

                   \InProcServer32\(Default) = "G:\PROGRA~1\FlashGet\fgiebar.dll" ["Amaze Soft"]


Extensions (Tools menu items, main toolbar menu buttons)


HKLM\Software\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\

"MenuText" = "Sun Java Console"

"CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"

  -> {HKCU...CLSID} = "Java Plug-in"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]

  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_06"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."]


{D6E814A0-E0C5-11D4-8D29-0050BA6940E3}\

"ButtonText" = "FlashGet"

"MenuText" = "&FlashGet"

"Exec" = "G:\PROGRA~1\FlashGet\flashget.exe" ["FlashGet.com"]


{FB5F1910-F110-11D2-BB9E-00C04F795683}\

"ButtonText" = "Messenger"

"MenuText" = "Windows Messenger"

"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]



Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------


avast! Antivirus, avast! Antivirus, ""e:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]

avast! iAVS4 Control Service, aswUpdSv, ""e:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]

avast! Web Scanner, avast! Web Scanner, ""e:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]

AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."]



Print Monitors:

---------------


HKLM\System\CurrentControlSet\Control\Print\Monitors\

2300 Series Port\Driver = "lxcglmpm.DLL" [" "]



----------

<>: Suspicious data at a malware launch point.


+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

  launch it from a command prompt or a shortcut with the -all parameter.

+ To search all directories of local fixed drives for DESKTOP.INI

  DLL launch points, use the -supp parameter or answer "No" at the

  first message box and "Yes" at the second message box.

---------- (total run time: 175 seconds, including 11 seconds for message boxes)

(adam9870) #10

Już jest ok.

Możesz zajrzeć: Optymalizacja i odchudzanie Windowsa XP.


(vito corleone) #11

a tan plik rpcc.dll i wpis to od jakiego syfu był?

już tam byłem :stuck_out_tongue:


(adam9870) #12

Od RPCC.Payload.

Plik zazwyczaj powoduje rozsyłanie linków z syfem do innych użytkowników GG.