Avatar billede papirklip Nybegynder
27. februar 2008 - 20:37 Der er 13 kommentarer og
2 løsninger

irc virus

Hej, jeg var så dum her for et par dage siden at trykke på et link på irc, der linked til noget der lignede nogen jpg filer.
texten jeg fik på irc hed noget i stil med "spawN busted for cheating in wstc" og så et link. jeg downloade en fil derfra og kørte den.
Nu spammer jeg konstant i mine irc channels med forskellige beskeder ( og jeg kan ikke selv se jeg skriver beskeden) f.eks er det her den nyeste:
http://CounterStrike******* - Counter-Strike Radio! Dj Stone on the air ! LIVE INTERVIEW With: Emil "HeatoN" Christensen SpawN And more !
og alle links indenholder den samme virus jeg fik. jeg har prøvet alt symatec antivirus, avg, nod32 og diveres online scanners intet fanger og fjerne den. Jeg har slette alt mirc relateret og geninstalleret men intet har hjulpet. plz hjælp mig af med det her bæst..

Mvh Papirsklip
Avatar billede levich Nybegynder
27. februar 2008 - 22:05 #1
Hent http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php.
Kør HijackThis, klik på scan, kopier loggens tekst og smidt den herind.
27. februar 2008 - 22:06 #2
... for en go' ordens skyld; stik os/mig en HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis.exe

(Jooo - jeg har 'virus' på hjernen...)

------------------
27. februar 2008 - 22:06 #3
(Hovsa - det var vi enige om *S* - <levich> kører bare videre ...)
Avatar billede papirklip Nybegynder
28. februar 2008 - 16:09 #4
okay. det var hvad jeg fik..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:07:56, on 28-02-2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Windows\system32\conime.exe
C:\Program Files\UltraVNC\winvnc.exe
C:\Program Files\Steam\steam.exe
C:\Windows\system32\rdpclip.exe
C:\Windows\system32\mssvcs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\SL\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [Microsoft Corporation Svchost Services] mssvcs.exe
O4 - HKLM\..\RunServices: [Microsoft Corporation Svchost Services] mssvcs.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Microsoft Corporation Svchost Services] mssvcs.exe
O4 - HKCU\..\RunServices: [Microsoft Corporation Svchost Services] mssvcs.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 7549 bytes
Avatar billede levich Nybegynder
28. februar 2008 - 20:59 #5
Læs alle punkterne inden du gør noget.

(1)
Hent AVG Anti-Spyware her: http://www.grisoft.com/doc/downloads-products/us/crp/0?prd=triasw
Installer programmer og opdater det, men vent med at scanne.

(2)
Hent AFT-cleaner her: http://www.geekstogo.com/forum/index.php?autocom=downloads&showfile=21
Start programmet og vælg "select all" og derefter "empty all".
Hvis du har Firefox skal du først vælge det i menuen og derefter "select all" og "empty all".

(3)
Genstart computeren i fejlsikret tilstand (tryk F8 når Windows starter op) og Fix følgende linjer med HijackThis:
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [Microsoft Corporation Svchost Services] mssvcs.exe
O4 - HKLM\..\RunServices: [Microsoft Corporation Svchost Services] mssvcs.exe
O4 - HKCU\..\Run: [Microsoft Corporation Svchost Services] mssvcs.exe
O4 - HKCU\..\RunServices: [Microsoft Corporation Svchost Services] mssvcs.exe

(4)
Start AVG Anti-Spyware, vælg fanebladet "scanner" og klik på "complete system scan".
Bagefter klik "apply all actions", "save report", "save report as" og gem logfil, f.eks. på skrivebordet.

(5)
Åbn "denne computer", i menuen skal du klikke på Funktioner -> Mappeindstillinger -> Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler" og ved "Skjul filtypenavne for kendte filtyper", sæt prik i "Vis skjulte filer og mapper". Husk at trykke på knappen "Anvend på alle mapper" i stedet for "ok".

søg efter og slet følgende fil(er):
C:\Program Files\Winamp\wianmpa.exe
mssvcs.exe

(6)
Genstart computeren normalt. Lav en ny log med HijackThis, og send den herind sammen med loggen fra AVG Anti-Spyware.
Avatar billede papirklip Nybegynder
29. februar 2008 - 14:05 #6
okay tak det prøver jeg lige på søndag sidder remote lige nu så kan ikke genstarte i fejlsikrettilstand. go weekend indtil da
Avatar billede papirklip Nybegynder
01. marts 2008 - 17:32 #7
-------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:    17:19:06 01-03-2008

+ Scan result:   



HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj -> Adware.CoolWebSearch : Cleaned.
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1 -> Adware.CoolWebSearch : Cleaned.
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer -> Adware.CoolWebSearch : Cleaned.
HKU\S-1-5-21-128820045-1994359826-1973713287-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE7C3CF0-4B15-11D1-ABED-709549C10000} -> Adware.Generic : Cleaned.
C:\Program Files\Sony Setup\Sound Forge Audio Studio 9.0\sony.sound.forge.audio.studio.9.0a.build.131-NoPE.exe -> Dropper.Agent.dlj : Cleaned.
D:\apps\Sony.Sound.Forge.Audio.Studio.9.0a.Build.131.Winall.Cracked-NoPE\crack\sony.sound.forge.audio.studio.9.0a.build.131-NoPE.exe -> Dropper.Agent.dlj : Cleaned.
D:\apps\Sony.Sound.Forge.Audio.Studio.9.0a.Build.131.Winall.Cracked-NoPE\npssf1.r08/crack\sony.sound.forge.audio.studio.9.0a.build.131-NoPE.exe -> Dropper.Agent.dlj : Cleaned.
D:\apps\Sony.Sound.Forge.Audio.Studio.9.0a.Build.131.Winall.Cracked-NoPE\npssf110.zip/npssf1.r08/crack\sony.sound.forge.audio.studio.9.0a.build.131-NoPE.exe -> Dropper.Agent.dlj : Cleaned.
:mozilla.314:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.315:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.316:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.317:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.318:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.319:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.320:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.321:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.322:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.323:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.324:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.325:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.326:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.327:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.328:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.329:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.330:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.331:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.332:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.333:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.334:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.335:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.336:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.337:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.338:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.339:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.340:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.341:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.406:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.422:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.598:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.780:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\SL\AppData\Roaming\Microsoft\Windows\Cookies\Low\sl@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.72:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.73:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.746:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.74:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.360:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.361:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.362:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.363:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.364:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.365:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.366:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.367:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.368:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.29:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.30:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.31:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.32:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.40:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
C:\Users\SL\AppData\Roaming\Microsoft\Windows\Cookies\Low\sl@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.56:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.57:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.58:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.62:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.63:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.288:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.347:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.348:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.349:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.350:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.354:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.355:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.356:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.357:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.358:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.359:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.445:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.762:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.191:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.207:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.208:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.209:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.210:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.563:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.71:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Users\SL\AppData\Roaming\Microsoft\Windows\Cookies\Low\sl@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.811:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.800:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Etracker : Cleaned.
:mozilla.344:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.345:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.346:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.353:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.27:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.41:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.42:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.43:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.44:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
C:\Users\SL\AppData\Roaming\Microsoft\Windows\Cookies\Low\sl@hit.gemius[1].txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.416:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.446:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.727:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.747:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.758:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.294:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.295:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.299:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.300:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.369:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.312:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.313:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.439:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Itrack : Cleaned.
:mozilla.440:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Itrack : Cleaned.
:mozilla.47:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.48:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.12:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.13:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.14:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.684:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.838:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.839:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.840:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.841:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.842:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.843:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.844:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.738:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Pstats : Cleaned.
:mozilla.536:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.537:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.121:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.123:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.124:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.125:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.126:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.127:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.128:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.129:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.130:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.914:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.915:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.706:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.707:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.708:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.709:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.710:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.711:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.712:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.713:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.714:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.715:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.716:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.28:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Statistik-gallup : Cleaned.
C:\Users\SL\AppData\Roaming\Microsoft\Windows\Cookies\Low\sl@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Cleaned.
:mozilla.813:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.815:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.816:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.136:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.137:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.139:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.140:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.141:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.465:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.385:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Users\SL\AppData\Roaming\Microsoft\Windows\Cookies\Low\sl@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.150:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.80:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.81:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.82:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.83:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.84:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.775:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.776:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.777:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.778:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.779:C:\Users\SL\AppData\Roaming\Mozilla\Firefox\Profiles\l7a3a7tl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\Eset\nod32fix.reg -> Trojan.Hack.Vg : Cleaned.

________________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:28:46, on 01-03-2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\SL\Desktop\HiJackThis.exe
C:\Users\SL\AppData\Local\Microsoft\Windows Sidebar\Gadgets\SteamServers.gadget\SteamServerInfo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 7108 bytes


så fik jeg gjort det. jeg er godt nok overrasket over hvor meget den fandt. håber det her er enden nu
Avatar billede levich Nybegynder
01. marts 2008 - 19:31 #8
Bare rolig - det er helt normalt at der er mange linjer i sådan en log-fil. Hijackthis-log'en ser fin ud. Jeg regner med at din computer kører fint nu?
Avatar billede papirklip Nybegynder
01. marts 2008 - 21:07 #9
der er gået 4 timer siden jeg loggede på irc og jeg har ikke spammet en eneste besked jeg ikke selv mente skulle afsted. så det ser sådan ud. + min pc bruger ca 15% mindre ram. så alt i alt ser det rigtig lovende ud.
1000 tak for hjælpen var virkeligt på herrens mark
Avatar billede levich Nybegynder
01. marts 2008 - 21:21 #10
Pefekt.
Falder der lidt point af til lille mig?
Avatar billede levich Nybegynder
01. marts 2008 - 21:37 #11
Forresten - det her "nulstiller" windows mht. systemgendannelse:

(1)
Deaktiver systemgendannelse, ved at Højreklikke på "Denne Computer" på skrivebordet -> egenskaber -> Systemgendannelse -> sæt flueben i "Deaktiver systemgendannelse" -> Klik OK.

(2)
Genstart normalt og aktiver systemgendannelse igen.
Avatar billede papirklip Nybegynder
02. marts 2008 - 08:51 #12
ja hvis du fortæller mig hvordan jeg afgiver pointene til dig hehe
Avatar billede levich Nybegynder
02. marts 2008 - 11:14 #13
Det gør du ved at markere mit navn i boksen til venstre (lige over hvor du skriver dine indlæg), og klikke på enten Accepter.
Avatar billede papirklip Nybegynder
02. marts 2008 - 15:25 #14
sådan tror jeg, fik du dem
Avatar billede levich Nybegynder
02. marts 2008 - 15:38 #15
Jeps. Held og lykke med at holde computeren ren fremover
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester