Avatar billede rasmusbl Nybegynder
02. juli 2006 - 18:34 Der er 6 kommentarer og
2 løsninger

Hijackthis log - Hjælp til hvilke processor jeg kan sørge for ikk

Computeren bruger hele tiden næsten 100% CPU og kører derfor sindsygt langsomt. Der er vel noget der ikke behøves at starte ved opstart. Er der spyware/virus?

Logfile of HijackThis v1.99.1
Scan saved at 18:30:58, on 02-07-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\Dit.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\NETGEAR\WG311T\wlancfg5.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
c:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\taskmgr.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Navn\Lokale indstillinger\Temp\Midlertidig mappe 2 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programmer\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "c:\Programmer\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmer\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Programmer\Fælles filer\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Programmer\NETGEAR\WG311T\wlancfg5.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: Yahoo! Bridge - http://download.games.yahoo.com/games/clients/y/bt1_x.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} - http://www.miniclip.com/bestfriends/retro64_loader.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA02F8A1-C953-402D-B758-1848F5110144}: NameServer = 62.61.130.1,62.61.131.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\System32\msctl32.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Avatar billede arlet Juniormester
02. juli 2006 - 18:37 #1
kigger
Avatar billede arlet Juniormester
02. juli 2006 - 18:41 #2
1. Hent Look2Me-Destroyer herfra:

http://www.atribune.org/ccount/click.php?id=7
Gem værktøjet på dit Skrivebord.

2. Luk alle åbne programvinduer - inklusiv Internet Explorer.

3. Dobbeltklik på Look2Me-Destroyer, sæt et flueben i "Run this program as a task". Du får en meddelelse om, at Look2Me-Destroyer vil lukke og åbne efter 10 sekunder - klik på OK.

4. Hvis din firewall vil blokere Look2Me-Destroyers adgang til nettet, så skal du lade programmet få adgang.
Hvis du får en runtime error 339, så skal du hente MSWINSCK.OCX herfra:
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
Læg den ned i mappen C:\Windows\System32.

5. Når Look2Me-Destroyer genåbner - klik på "Scan for L2M" - dine ikoner forsvinder - klik "Remove L2M". Klik OK når du får meddelelsen "Done scanning". Nu får du meddelelsen "Done removing infected files!. Programmet vil lukke din computer - klik OK.

Kopier Look2Me-Destroyer´s log her ind.


Bagefter foreslår jeg, at du kører disse to scannere:


Hent denne scanner ned til skrivebordet ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe Vent med at aktivere den.


Hent denne scanner http://www.superantispyware.com/downloads/SUPERAntiSpyware1241.exe

Installer, og opdater scanneren manuelt. OBS, ved installationen bliver det foreslået at du registrerer med din email. Det behøver du ikke at gøre.


Start op i fejlsikret tilstand (tast f8 flere gange under opstart)


Dobbeltklik på drweb-cureit.exe. Den vil køre en expressscan, og det siger du ja til.

Når den skriver "Select object for scanning" nederst til venstre, skal du klikke på Options->Change settings.

Skift til fanebladet SCAN, og fjern fluebenet ved "Heuristic analysis".

Skift til fanebladet Actions. Under ADWARE indstiller du til DELETE. Alle andre punkter under MALWARE sættes til MOVE. Fjern fluebenet ved PROMPT ON ACTION. Klik ANVEND og OK.

Klik på det de drev du vil have scannet. Der kommer en rød prik, som viser at de er valgt.

Klik på den grønne pil ovre til højre på siden, for at starte scanningen.


Når scanningen er færdig, så find mappen Dr Web som ligger på dit hoveddrev, typisk C drevet, og find CUREIT.LOG. Scroll helt ned i bunden af loggen, hvor der står SCAN PATH og SCAN STATISTICS (KUN de nederste) og kopier det her ind. 


Start SuperAntiSpyware, klik "Scan your computer", sæt flueben i dine drev, ovre til venstre i vinduet. Ovre til højre i vinduet, sætter du prik i "Perform Complete Scan". Klik "næste", nu scanner den. Når den er færdig, så markerer du det den finder, og lader scannereren fjerne det.

Genstart til normal tilstand (scanneren tilbyder måske at gøre det).

Åbn scanneren igen, og klik "preferences"-> "stastics/logs". Marker loggen, og klik "View log". Kopier loggen her ind i tråden, sammen med CUREIT loggen, og en frisk HijackThis log.
Avatar billede rasmusbl Nybegynder
02. juli 2006 - 20:23 #3
Takker, gør alt det nævnte og vender tilbage ;-)
Avatar billede rasmusbl Nybegynder
04. juli 2006 - 21:19 #4
Look2Me-Destroyer V1.0.12

Scanning for infected files.....
Scan started at 02-07-2006 20:39:35


Attempting to delete infected files...

Making registry repairs.


Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administratorer - Succeeded
----------------------

Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 89590
Infected objects found: 28
Objects with modifications found: 0
Suspicious objects found: 0
Adware programs found: 13
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 0
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 28
Objects renamed: 13
Objects moved: 0
Objects ignored: 0
Scan speed: 98 Kb/s
Scan time: 01:36:24


-------------------------
SUPERAntiSpyware Scan Log
Generated 07/04/2006 at 01:09 PM

Core Rules Database Version : 3002
Trace Rules Database Version: 1079

Memory threats detected  : 0
Registry threats detected : 4
File threats detected    : 446

Trojan.BXProxy
    [bxproxy] C:\WINDOWS\bxproxy.exe
    C:\WINDOWS\bxproxy.exe
    [bxproxy] C:\WINDOWS\bxproxy.exe
    [bxproxy] C:\WINDOWS\bxproxy.exe
    [bxproxy] C:\WINDOWS\bxproxy.exe

Adware.Tracking Cookie
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkisjc5edp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfloajdjgdo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnywlcpoco.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@LPplayersonly[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlyqmdjsfp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.xxxcenter[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@focalex[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1ocpwe.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@425[3].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkoagcpmcp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfl4ogdjedq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@image.masterstats[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@cz11.clickzs[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnycmdjeep.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@fixionmedia[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyunczcao.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@partypoker[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyskajggp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnychdzclo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@1[3].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlyulcpabo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyeoczsco.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmywpczceo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1jd5kl.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkycocpsbq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@atwola[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyopd5wko.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnywhdjmfq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@adopt.hbmediapro[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@revsci[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.realcastmedia[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@krombacher[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@rightmedia[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyopcpwho.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@cz3.clickzs[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkykncjsho.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfliegcpcco.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjloalcjwbq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkouhdzaep.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1kcjgd.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmiqpc5mfq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wflikndpwcq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4eiazaep.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkoqjcjahq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4gmazabo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@a[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@xiti[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@belnk[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wflosodjweq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@a.websponsors[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@adopt.specificclick[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@globalstat[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfl4wncpocp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@track.effiliation[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkygldpcep.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@888[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@track.adform[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@cassava[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjloqpc5gbp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4kgczogq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@azjmp[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wgmykid5sko.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyciazglo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlysmazgap.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wflighd5iko.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyggd5ilo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliskcjmkpwwdj6x9ny-1seq-2-2.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@zedo[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@burstnet[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlosgdjelp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkognazggq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@exitexchange[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.belstat[3].txt
    C:\Documents and Settings\Navn\Cookies\navn@banner.cdpoker[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4qkdjcdo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkocnc5kko.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@webstats.thefa[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlysicjigo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyonajagq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlysjczogpqqdj6x9ny-1seq-2-2.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlocgazodo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkookcpgho.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@realmedia[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkogodjelq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@2[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkywjazeho.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.belstat[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@indextools[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjl4eld5cfq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@651[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@cz5.clickzs[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@ad.yieldmanager[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1sazkl.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1odzce.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@ad1.emediate[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfl4olc5iep.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1icjek.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@partypoker.touchclarity[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlogpdzacq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkiegajgcp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@tradedoubler[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1id5sh.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@roiservice[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjl4gocjagq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.mystats[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjloold5ibo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@dist.belnk[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ad.ofir[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnysjdzsbo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ad.reunion[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlikncziao.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@http.edge.vru4[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@649[3].txt
    C:\Documents and Settings\Navn\Cookies\navn@a-1shz2prbmdj6wvny-1sez2pra2dj6wjkyogd5ohog-1dj6x9ny-1seq-2-2.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1kd5ak.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e2.emediate[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycndpmboq2dj6x9ny-1seq-2-2.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@472[3].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlysgdjaeo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnycpdzkdo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmikjc5afo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyglajsap.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyqic5kgo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@715[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlokkc5wbo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmyold5ekp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4kgcpgep.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkycpcjabp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyapcpieo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlyggdpmlq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyopd5mlp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnygldjeco.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyehdpilp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnywhdzmkp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjliqpdjclp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlyaoazglp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfl4woc5adp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@i.screensavers[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@admarketplace[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@cz7.clickzs[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkykicpkfo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@st[5].txt
    C:\Documents and Settings\Navn\Cookies\navn@cz6.clickzs[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjl4codjklp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnywlajoao.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfmiwjdjido.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkocpdjwgo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnychdpedo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@stats1.reliablestats[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjliqodzaaq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@dealtime.co[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1jazmc.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkocodzklo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkyohaziko.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@adopt.euroclick[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmysgajabo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@ath.belnk[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.as4x.tmcs[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ad1.hardware[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjloehczmlq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkykocpkko.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkyghajshq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4apajgbp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyuocpkap.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@cz9.clickzs[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlysgcpwdo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmyuidjolp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@interclick[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@aa[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.webstat[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@microsofteup.112.2o7[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@postclicktracking[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnywldzwbo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkoamcjcdo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wflioocpgfp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyejazakp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnysgd5klp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkowod5ifq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wflokldpceo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@vip2.clickzs[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@server.cpmstar[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlywkcjodp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@i[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfliokcpsaq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@clickability[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkocpd5mhp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnycmdpgco.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkosgdpagp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjliqidpgdq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlockcpkfo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyogczebq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@den[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1sajsd.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlygoazkao.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfl4kgdpego.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@rotator.adjuggler[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@tripod.lycos[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkoeldzglo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkoskdpcfp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@43035569[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmisjcjmgp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wgmyqjd5wkq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkysmczadp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@adecn[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkokmcjego.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.screensavers[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4giajsco.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmygldjmbp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wgkoqhcjakq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.accelerator-media[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkocmcjweo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@warlog[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4uidjifp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyakd5kcp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjloeodjgco.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkoekc5gfp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyeidpgfp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnycgd5oeo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmisldzeco.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmyqjcjslp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.web-stat[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnygnczkho.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfmisldjadp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@creativeby.viewpoint[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyamdziho.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjloqidjwko.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@82743606[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyokcjocp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlickcpsgp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlysncpoap.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@hurricanedigitalmedia[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnygpczsdp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@stat.dealtime[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@tracking[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlogidzodo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1pc5gb.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfligmczaeo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@adfair[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@statebay.dealtime[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@mogs[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjl4ehdzeaq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@wrigley.122.2o7[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wgkysmazsgq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyupcjcko.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnysldpglo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkoggdpeaq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@tacoda[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyoicjiep.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkysjczakp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyomdjskp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4ujczoao.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1kdzgd.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@eboz[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@ebookers[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkoqocpwfo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfl4uodpkfo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@ad.cibleclick[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyemczkeo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyaicjgep.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjliencpohp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.us.e-planning[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.sextasya[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfk4ugcjcfo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@adv.surinter[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyakd5sho.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4cmd5kap.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkocgd5meq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkyenczoeo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkyundzaao.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfmyghdjwcp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4upcpghp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjliqhdzodo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1gajsa.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1scpek.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@1070148968[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfloggd5ikq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkysoc5waq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkyupazaep.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlyahdzcho.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjny-1pczob.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlishcpsbo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnyohd5sap.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@yieldmanager[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlygpcjico.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkoeiajoao.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfl4aiajwbp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkywoazelp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.exitexchange[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@adknowledge[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkoumdpego.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wgkiohczago.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmyald5wcp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4gkdzcgq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkiwhcpslo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wgkygjajgbo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.longxxxclips[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.cnn[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@clickthrough.wegcash[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@cnn.122.2o7[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlicidjwap.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@c.enhance[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@1072508508[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkywlcjslq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnycgajmeq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@banner[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.easyclicktravel[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkoshcjgap.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@webstat[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.realtechnetwork[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjnygiajcdq.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@dealtime[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyelcjklp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkysjdzweo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.countercentral[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.starware[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@stats[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkiuhdzkhp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@click-fr[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.winfixer[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkoenazodq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wflosicpifp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkyapczcko.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@stat.postdanmark[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlyapc5ggp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@adlegend[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjl4kldjkbo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@h.starware[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.hveruge[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@1071596268[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkyklczaho.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkookazkao.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@toplist[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wglicpd5seo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmyqkcjklo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@1070336364[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmyulczkhq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.myfreestats[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads2.jubii[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfl4ohczklo.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@bannere.fyens[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkieodzidq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmywkdjiap.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@1071952017[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@programs.wegcash[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjmiaic5mgp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@keywordmax[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@metareward[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfloaidjsfq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfkoulczwcp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4opajaep.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjk4kkdjelp.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@adtech[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@winfixer[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@m1.webstats4u[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjkysldpibq.stats.esomniture[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@www.burstnet[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@flashstat.jubii[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@112.2o7[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@advert.runescape[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@free.wegcash[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wjlyclc5oho.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@tribalfusion[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@59207812[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@1069651066[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wfmywmc5slo.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.arto[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@cgi-bin[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@e-2dj6wgloaid5elp.stats.esomniture[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@impse.tradedoubler[1].txt
    C:\Documents and Settings\Navn\Cookies\navn@ads.arto[2].txt
    C:\Documents and Settings\Navn\Cookies\navn@counter[2].txt
    C:\Documents and Settings\Navn\Lokale indstillinger\Temp\Cookies\navn@stat.postdanmark[1].txt

Trojan.SpySheriff
    C:\Program Files\SpySheriff

Adware.ZToolbar
    C:\WINDOWS\azesearch.bmp
    C:\WINDOWS\system32\azebar.xml

Browser Hijacker.Favorites
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Cars.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Domain Names.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Finance.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Games.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Humor.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Movies.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies\Albums.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies\Artists.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies\AudioBooks.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies\Collections.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies\Mp3 Search.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies\New releases.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies\Ratings.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Music and Movies\Soundtracks.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Online Pharmacy.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Sex Personals.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Sports.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Spyware Removers
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Spyware Removers\Raze Spyware.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Spyware Removers\Reg Freeze.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Viagra.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Weather.url
    C:\Documents and Settings\Navn\Foretrukne\Favorites\Web Hosting.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Carnival Casino.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Club Dice Casino.url
    C:\Documents and Settings\Navn\Foretrukne\Games\New York Casino.url
    C:\Documents and Settings\Navn\Foretrukne\Games\USA Casino.url
    C:\Documents and Settings\Navn\Foretrukne\Games\You Bingo.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Aces & Faces.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Baccarat.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Black Jack.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Caribbean Poker.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Casino War.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Cinerama.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Craps.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Deuces Wild.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Diamond Valley.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Fruit Mania.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Gold Rally.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Jacks or Better.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Magic Slots.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Mega Jacks.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Pai Gow Poker.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Red Dog Poker.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Roulette.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\SafeCracer.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Sic Bo.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Gambling\Wall St. Fever.url
    C:\Documents and Settings\Navn\Foretrukne\Games\Monaco Gold Casino.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Adventure Travel.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Air Travel.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Business Travel.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Discount Travel.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Food.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Hawaii Travel.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Lodging.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\London Travel.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Travel Agent.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Travel Insurance.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Travel package.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Travel Reservation.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Travel Spain.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Travel Web site.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Vacation Cruises.url
    C:\Documents and Settings\Navn\Foretrukne\Travel\Vacations.url

Adware.TrustInCash
    C:\WINDOWS\adult.ico
    C:\WINDOWS\casino.ico
    C:\WINDOWS\spywareremoval.ico

-----------------------

Logfile of HijackThis v1.99.1
Scan saved at 21:18:27, on 04-07-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
C:\Programmer\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\Dit.exe
C:\Programmer\Fælles filer\Ulead Systems\AutoDetector\monitor.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmer\NETGEAR\WG311T\wlancfg5.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\msiexec.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\Navn\Lokale indstillinger\Temp\Midlertidig mappe 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programmer\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [HP Software Update] "c:\Programmer\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmer\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Programmer\Fælles filer\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Programmer\NETGEAR\WG311T\wlancfg5.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} - http://www.miniclip.com/bestfriends/retro64_loader.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA02F8A1-C953-402D-B758-1848F5110144}: NameServer = 62.61.130.1,62.61.131.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\System32\msctl32.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Avatar billede arlet Juniormester
04. juli 2006 - 21:23 #5
--------------------------------------------------------------------

Åbn en tilfældig mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".
(Når du er erklæret ren igen, skal du huske at sætte indstillingerne tilbage)

--------------------------------------------------------------------

Hent denne bats fil og kør den :
http://www.spywareinfo.dk/download/cleantempxp2k.bat
den sletter alt i din temp mappe.


Genstart computeren i fejlsikret tilstand(Du skal klikke på f8 tasten under genstarten (ca. lige når der er talt ram), og så vælge fejlsikret tilstand. Er du i tvivl, så klik bare på f8 flere gange.)


Du skal nu til at i gang med at fixe:
Kør Hijackthis, scan, sæt flueben ved linien/linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked, luk hijackthis igen.

O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)

O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\System32\msctl32.dll (file missing)

Find og slet den/disse manuelt:

C:\WINDOWS\System32\msctl32.dll

Genstart normalt og kom med en ny hijackthis log
Avatar billede rasmusbl Nybegynder
05. juli 2006 - 17:54 #6
Er der ikke flere processor der kan lukkes ned som ikke behøves at starte op hver gang?
Kunne ikke finde filen C:\WINDOWS\System32\msctl32.dll, hverken når jeg søgte på den eller gik ind i stien.


Logfile of HijackThis v1.99.1
Scan saved at 17:47:15, on 05-07-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Navn\Lokale indstillinger\Temp\Midlertidig mappe 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programmer\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [HP Software Update] "c:\Programmer\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmer\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Programmer\Fælles filer\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Programmer\NETGEAR\WG311T\wlancfg5.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} - http://www.miniclip.com/bestfriends/retro64_loader.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA02F8A1-C953-402D-B758-1848F5110144}: NameServer = 62.61.130.1,62.61.131.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Avatar billede arlet Juniormester
06. juli 2006 - 16:56 #7
Hvis du vil vide om du har noget overflødigt kørende under opstart, så vil jeg anbefale at du downloader programmet Windows Startup Inspector.
Kør programmet og tryk "Consult" - i det højre vindue får du nu en forklaring på hvad hver enkelt linie gør og om den er nødvendig eller ej.
Du vil herefter selv kunne tage stilling til, om du vil fjerne programmer fra din opstart eller ej.
Programmet finder du her:

http://www.windowsstartup.com/

Loggen er ren..

Efter sådan en tur er det altid en god ide og rydde op i dine systemgendannelses filerne.
Deaktiver systemgendannelse ( http://www.arlet.dk/systemgendannelsen.htm ) - genstart din computer - aktiver systemgendannelse.

Generel oprydning: http://www.arlet.dk/oprydning.htm

For at beskytte dig mod snavs har jeg lavet en sikkerhedspakke,
som du kan se her : www.arlet.dk/pakke.htm
Avatar billede rasmusbl Nybegynder
07. juli 2006 - 15:12 #8
Rigtig god hjælp Arlet. Takker :)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester



IT-JOB

A/S Bryggeriet Vestfyen

IT-Architect /Administrator

Udviklings- og Forenklingsstyrelsen

Konsulenter til strategi-implementering i nyt PMO-kontor

Udviklings- og Forenklingsstyrelsen

Data Engineers til bekæmpelse af skatteunddragelse

Udviklings- og Forenklingsstyrelsen

Business Analyst med drive og gåpåmod

Nitor Energy A/S

IT Infrastructure Specialist