Prosím o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

šnek
nováček
Příspěvky: 6
Registrován: červenec 06
Pohlaví: Nespecifikováno
Stav:
Offline

Prosím o kontrolu logu

Příspěvekod šnek » 21 úno 2007 22:29

Log po akci z:
po únor 19, 2007 11:43 pm

1. Secureprocs32.exe jsem nenašel (zobrazení systémových a skrytých souborů zapnuto)

2. Služby jsem zastavil

3. Log MWAV:

Tue Feb 20 23:11:23 2007 => Module C:\WINDOWS\system32\pmnnk.dll found running in Memory...
Tue Feb 20 23:11:23 2007 => Parent Process: C:\WINDOWS\SYSTEM32\WINLOGON.EXE
Tue Feb 20 23:11:23 2007 => Parent Process: C:\WINDOWS\Explorer.EXE
Tue Feb 20 23:11:23 2007 => List of all Processes Sharing [pmnnk.dll] : C:\WINDOWS\SYSTEM32\WINLOGON.EXE,C:\WINDOWS\Explorer.EXE
Tue Feb 20 23:11:24 2007 => *** Killing Infected Process C:\WINDOWS\SYSTEM32\WINLOGON.EXE,C:\WINDOWS\Explorer.EXE...
Tue Feb 20 23:11:27 2007 => *** Killing Successful.
Tue Feb 20 23:11:31 2007 => Unregistering file C:\WINDOWS\system32\pmnnk.dll...
Tue Feb 20 23:11:31 2007 => File C:\WINDOWS\system32\pmnnk.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.fp". Action Taken: File Deleted.


Tue Feb 20 23:11:32 2007 => Module C:\WINDOWS\system32\hggfcbb.dll found running in Memory...
Tue Feb 20 23:11:32 2007 => Parent Process: C:\WINDOWS\SYSTEM32\WINLOGON.EXE
Tue Feb 20 23:11:32 2007 => Parent Process: C:\WINDOWS\Explorer.EXE
Tue Feb 20 23:11:32 2007 => List of all Processes Sharing [hggfcbb.dll] : C:\WINDOWS\SYSTEM32\WINLOGON.EXE,C:\WINDOWS\Explorer.EXE
Tue Feb 20 23:11:32 2007 => Unregistering file C:\WINDOWS\system32\hggfcbb.dll...
Tue Feb 20 23:11:32 2007 => File C:\WINDOWS\system32\hggfcbb.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.gl". Action Taken: File Deleted.


Tue Feb 20 23:14:05 2007 => Deleting Registry Key: HKLM\Software\magnet
Tue Feb 20 23:14:05 2007 => Offending Key found: HKLM\Software\magnet !!!
Tue Feb 20 23:14:05 2007 => Object "grokster Spyware/Adware" found in File System! Action Taken: Entries Removed.


Tue Feb 20 23:59:08 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Tue Feb 20 23:59:09 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 00:15:24 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\VV\qc3wx4mz.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 00:40:25 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\X\i044c2zy.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 01:05:02 2007 => File C:\Installer\PLANETLUCKINSTALLER.EXE tagged as "not-a-virus:AdWare.Win32.Casino.i". Action Taken: File Deleted.

Wed Feb 21 01:28:54 2007 => File C:\Program Files\ESET\infected\LBLMPPCA.NQF//PE-Crypt.XorPE tagged as "not-a-virus:AdWare.Win32.Virtumonde.gl". Action Taken: File Deleted.

C:\RECYCLER\S-1-5-21-861567501-484763869-1343024091-1000\Dc9\backup-20070218-194202-197.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.fp". Action Taken: File Deleted.

C:\RECYCLER\S-1-5-21-861567501-484763869-1343024091-1000\Dc9\backup-20070218-194202-802.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.gl". Action Taken: File Deleted.

Wed Feb 21 02:29:33 2007 => File C:\VundoFix Backups\hggfcbb.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.gl". Action Taken: File Deleted.

Wed Feb 21 02:29:34 2007 => File C:\VundoFix Backups\pmnnk.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.fp". Action Taken: File Deleted.

D:\Downloads\Instalace\recorder.exe//data0006//WhAgent.exe tagged as "not-a-virus:AdWare.Win32.F1Organizer.h". Action Taken: File Deleted.

Wed Feb 21 03:03:09 2007 => File D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash
Wed Feb 21 03:03:09 2007 => File D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 03:46:52 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 03:46:53 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 03:55:07 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\VV\qc3wx4mz.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 04:04:28 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\VV\qc3wx4mz.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Data\Mozilla\Profiles\X\i044c2zy.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Files\ESET\infected\LBLMPPCA.NQF//PE-Crypt.XorPE tagged as "not-a-virus:AdWare.Win32.Virtumonde.gl". Action Taken: File Deleted.

Wed Feb 21 06:16:54 2007 => File D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 06:16:54 2007 => File D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 06:17:04 2007 => ***** Scanning complete. *****

Wed Feb 21 06:17:04 2007 => Total Objects Scanned: 229793
Wed Feb 21 06:17:04 2007 => Total Critical Objects: 24
Wed Feb 21 06:17:04 2007 => Total Disinfected Objects: 0
Wed Feb 21 06:17:04 2007 => Total Objects Renamed: 0
Wed Feb 21 06:17:04 2007 => Total Deleted Objects: 1233
Wed Feb 21 06:17:04 2007 => Total Errors: 1233
Wed Feb 21 06:17:04 2007 => Time Elapsed: 07:04:48
Wed Feb 21 06:17:04 2007 => Virus Database Date: 2/19/2007
Wed Feb 21 06:17:04 2007 => Virus Database Count: 268451

Wed Feb 21 06:17:04 2007 => Scan Completed.


4. Log HJT:

Logfile of HijackThis v1.99.1
Scan saved at 22:16:25, on 21.2. 2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Personal Firewall\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\Program Files\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\mdm.exe
D:\Downloads\Instalace\Antiviry\Hijackthis\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\PROGRAM FILES\ICQTOOLBAR\TOOLBAR.DLL/SEARCH.HTML
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (NOXLATE) - file://C:\Program Files\AutoCAD LT 2000i Cz\InstFred.ocx
O16 - DPF: {52A2AAAE-085D-4187-97EA-8C30DB990436} (HHCtrl Object) - http://localhost/iisHelp/common/i386.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file://C:\Program Files\AutoCAD LT 2000i Cz\AcDcToday.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file://C:\Program Files\AutoCAD LT 2000i Cz\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{1487642D-8033-4290-B924-583D099BB9D1}: NameServer = 194.228.41.65 194.228.41.113
O17 - HKLM\System\CS1\Services\Tcpip\..\{1487642D-8033-4290-B924-583D099BB9D1}: NameServer = 194.228.41.65 194.228.41.113
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Personal Firewall\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)

Děkuji za pomoc.
Šnek

Reklama
Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod fredik » 22 úno 2007 21:19

V logu HJT fixni tyto drobnosti:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Akorát ti asi nesmazal to co máš v Mozille v Mailu.

Tue Feb 20 23:59:08 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Tue Feb 20 23:59:09 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 00:15:24 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\VV\qc3wx4mz.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 00:40:25 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\X\i044c2zy.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 03:03:09 2007 => File D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash
Wed Feb 21 03:03:09 2007 => File D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 03:46:52 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 03:46:53 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 03:55:07 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\VV\qc3wx4mz.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 04:04:28 2007 => File C:\Documents and Settings\Vlasta\Application Data\Mozilla\Profiles\VV\qc3wx4mz.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 06:16:54 2007 => File D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Inbox//[From "Autostop.cz" <info@autostop.cz>][Date Wed, 24 Nov 2004 19:14:38 +0100 (CET)]/mail.pif//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Wed Feb 21 06:16:54 2007 => File D:\Profiles\default\spy2wgoj.slt\Mail\pop3.iol.cz\Trash//[From info@jabulanirr.com][Date Tue, 21 Dec 2004 19:26:06 +0000 (GMT)]/auto__mail.jabulanirr_4055.bat//UPX infected by "Email-Worm.Win32.Sober.i" Virus! Action Taken: No Action Taken.

Zkus to ještě jednou projet Mwavem pokud tam budou tak si ty infikované emaily smaž ručně.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 115 hostů