Avatar billede trold Nybegynder
29. august 2006 - 18:28 Der er 21 kommentarer og
1 løsning

Hjælp Jeg er blevet hijacket

Så skete det - for første gang nogensinde er min browser hijacket - jeg har prøvet alle mulige forslag på spywarefri.dk uden held.

Min browser starter c:\windows\local.htm for så at redirecte til http://www.syssecuritypage.net/ - ligeledes har jeg et ? ikon der bliver i statusbaren der fører til
http://www.spywarequake.com/?aff=252

Jeg har set at man skal installere hijackthis og køre en scan og smide logfilen her - og så håbe på en ekspert vil frelse mig for mine problemer - here it goes

Logfile of HijackThis v1.99.1
Scan saved at 18:23:31, on 29-08-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\Mixer.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\Programmer\Winamp\Winampa.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ismon.exe
C:\WINDOWS\system32\19176963.exe
C:\WINDOWS\StartupMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Programmer\WinTV\Ir.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Programmer\BHODemon 2\BHODemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\local.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://192.168.49.33/dk/schneider.php3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer leveret af Cybercity Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgrammer%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Henrik\Application Data\Mozilla\Profiles\default\86ckjere.slt\prefs.js)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmer\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Programmer\Safety Bar\Safety Bar.dll
O3 - Toolbar: TrustIn Bar - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\Programmer\trustin bar\trustin.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Programmer\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [19176963.exe] C:\WINDOWS\system32\19176963.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Trust Cleaner] "C:\Programmer\Trust Cleaner\Trust Cleaner.exe"
O4 - HKCU\..\Run: [19176963.exe] C:\Documents and Settings\Henrik\Lokale indstillinger\Application Data\19176963.exe
O4 - Startup: BHODemon 2.0.lnk = C:\Programmer\BHODemon 2\BHODemon.exe
O4 - Global Startup: Acrobat-assistenten.lnk = C:\Programmer\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Programmer\WinTV\Ir.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmer\Fælles filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://192.168.49.33/dk/schneider.php3
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Programmer\Dantz\Retrospect\retrorun.exe

Kan i se hvad der er galt - nu poppede der også en eller anden spyware remover reklame op i dette øjeblik - damn
Avatar billede fazli Nybegynder
29. august 2006 - 18:43 #1
Tjekker den nu ;)
Avatar billede trold Nybegynder
29. august 2006 - 19:02 #2
venter spændt :-)
Avatar billede fazli Nybegynder
29. august 2006 - 19:09 #3
Lad os nu se, det bliver en lang omgang  :)

Download Roguescanfix til dit skrivebord:
http://users.telenet.be/Beamerke/tools/roguescanfix_setup.exe

Dobble klik på roguescanfix_setup.exe, Efter installationen vil den spørge om du vil køre fixet nu sig ja til dette."
OBS! Dette program kræver internetforbindelse så hvis din firewall popper op skal du give programmet adgang til internettet. Hvis den kommer med en fejl om "BFU.exe is not present" så download BFU herfra:
http://www.merijn.org/files/bfu.zip udpak den og gem den i mappen Roguescanfix.
efter fixet vil notepad åbne kopier indholdet herind :)

Genstart

Hent Smitfraudfix:
http://www.bleepingcomputer.com/resources/link243.html

Udpak det og klik på smitfraudfix.bat
Når den er startet trykker du på "2" og så starter fixet, efter fixet vil notesblok åbne. Kopier indholdet herind.

Download FixSQ.reg:
http://download.bleepingcomputer.com/reg/FixSQ.reg

Gem den på skrivebordet. Åbn den og sig ja til at den skal føje sig til registering basen.

Genstart

Naviger til:
Start > Kontrolpanel > Tilføj/Fjern Programmer
Fjern følgende programmer:

Safety Bar
TrustIn Bar
Trust Cleaner

Genstart
Åbn Hijackthis og sæt et flueben ved disse linier:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\local.html
O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Programmer\Safety Bar\Safety Bar.dll
O3 - Toolbar: TrustIn Bar - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\Programmer\trustin bar\trustin.dll (file
O4 - HKLM\..\Run: [19176963.exe] C:\WINDOWS\system32\19176963.exe
O4 - HKCU\..\Run: [Trust Cleaner] "C:\Programmer\Trust Cleaner\Trust Cleaner.exe"
O4 - HKCU\..\Run: [19176963.exe] C:\Documents and Settings\Henrik\Lokale indstillinger\Application Data\19176963.exe

Luk alle vinduer og browsere undtagen HijackThis og klik Fix checked

Genstart

Find og slet disse mapper/filer:
C:\WINDOWS\local.html < Filen
C:\Programmer\Safety Bar < Mappen
C:\Programmer\trustin bar < Mappen
C:\WINDOWS\system32\19176963.exe < Filen
C:\Programmer\Trust Cleaner < Mappen
C:\Documents and Settings\Henrik\Lokale indstillinger\Application Data\19176963.exe < Filen

Genstart

Ewido kan du downloade her
Klik på Download now. Installer og kør Ewido. Opdater straks efter installationen programmet, (men lad være med at scanne endnu). Genstart i fejlsikret tilstand. Du skal klikke på f8 tasten under genstarten (ca. lige når der er talt ram), og så vælge fejlsikret tilstand. Er du i tvivl, så klik bare på f8 flere gange. Kør nu en fuld scanning med Ewido. Når den er færdig trykker du save report og kopier den report herind sammen med en log fra hijackthis.

Håber du kunne følge med ;)
Hvis ikke så bare spørg ;)
Avatar billede trold Nybegynder
29. august 2006 - 19:41 #4
Så langt er jeg nået
Hent Smitfraudfix:
http://www.bleepingcomputer.com/resources/link243.html

Udpak det og klik på smitfraudfix.bat

Denne fil findes ikke der findes en
SmitfraudFix.cmd
Avatar billede trold Nybegynder
29. august 2006 - 19:46 #5
Der sker intet når jeg klikker på smitfraudfix.bat
Avatar billede fazli Nybegynder
29. august 2006 - 19:55 #6
klik du på:

SmitfraudFix.cmd

Det er bare mig som har lavet lidt ged i den ;)
Avatar billede trold Nybegynder
29. august 2006 - 20:34 #7
1) Når jeg klikker på SMitFrauFix.cmd - åbner et dos/kommando vindue i et split sekund - jeg når ikke at se hvad der står - ellers sker der intet - hvad går galt ??

2) er i gnag med en fuld skanning med ewido
Avatar billede fazli Nybegynder
29. august 2006 - 20:39 #8
gå du bare videre med mine instrukser ..
Avatar billede fazli Nybegynder
29. august 2006 - 20:41 #9
du kan prøve dette med smitfraud:

start > kør skriv cmd

skriv derefter:

cd skrivebord

derefter

cd smitfraudfix

derefter

smitfraudfix.cmd

så burde den gerne åbne ;)
Avatar billede trold Nybegynder
29. august 2006 - 20:46 #10
da skriver den
'find' blev ikke genkendt som en intern eller ekstern kommando et program eller batchfil
Avatar billede fazli Nybegynder
29. august 2006 - 20:48 #11
find?

kan du lige fortælle mig den sti som du har gemt smitfraud i?

fx:

C:/ .....
Avatar billede trold Nybegynder
29. august 2006 - 20:49 #12
Vælger jeg en af de andre filer i dir er der ingen problemer med at eksekvere
Avatar billede trold Nybegynder
29. august 2006 - 20:50 #13
Jeg prøvede først på skrivebord - det virkede ikke - dernæst lagde jeg den i roden af C lavede en cd smitfraudfix - dernæst en dir - der korrekt gav mig indholdet af folderen smitfraudfix

dernæst kørte jeg kommandoen c:\SmitfraudFix\SmitFraudfix.cmd så fik jeg ovenstående fejl
Avatar billede fazli Nybegynder
29. august 2006 - 20:53 #14
okay hør her.

Download denne fil:
http://rapidshare.de/files/31225410/_bn.bat.html

og læg den i mappen Smitfraudfix og kør filen Åbn.bat

så burde det virke.. hvis ikke.. så gå videre med vejledningen ;=)
Avatar billede trold Nybegynder
29. august 2006 - 21:09 #15
Desværre sker der det samme - det er som om der er noget der forhindrer filen i at eksekvere
Avatar billede trold Nybegynder
29. august 2006 - 21:10 #16
Så blev evido færdig med en full scan

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at:    21:07:28 29-08-2006

+ Scan result:   



HKLM\SOFTWARE\Microsoft\VisualStudio\Analyzer\Events\{6C736D71-BCBF-11D0-8A23-00AA00B58E10} -> Adware.CoolWebSearch : No action taken.
HKLM\SOFTWARE\Classes\CLSID\{052b12f7-86fa-4921-8482-26c42316b522} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Classes\CLSID\{873eb32d-ae1a-4183-89bd-45a77f761be4} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Classes\Interface\{636FF82A-830A-42EA-938B-6DC78B2AC30C} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Classes\Interface\{A55C3BA7-DB1E-4652-867E-055CEAFE8018} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Classes\Interface\{C28EB22A-6966-4E4B-8592-E84C28D38402} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Classes\TypeLib\{42FC3840-020C-4E93-A34C-4DF1A6330FBB} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Classes\TypeLib\{B1C54189-72F0-4353-987B-18FA221BEF09} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{873eb32d-ae1a-4183-89bd-45a77f761be4} -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{052B12F7-86FA-4921-8482-26C42316B522} -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{873EB32D-AE1A-4183-89BD-45A77F761BE4} -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1000adultpersonals.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1000flowers.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1000traveltips.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\100best-free-web-space.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\123-reg.co.uk -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\123adultpersonals.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\123greetings.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\123india.santabanta.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\15on1.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1800flowers.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1800mobiles.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\18eighteen.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\18inchesofpain.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\18teenlive.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\18yearsold.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1and1.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1autocarloancalculators.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1freepornfinder.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1loansusa.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1stinflowers.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1stlesbianexperience.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\1travelinsurance.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2.joyourself.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2.livejasmin.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2.liveprivates.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\200cash.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\21sexturycash.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\21st.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\24inchesofpain.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\24ktgoldcasino.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2bigtobetrue.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2buycars.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2chicks1dick.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2crazybitches.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2dplay.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2flashgames.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\2muslims.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\30somethingmag.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\360financialliteracy.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\3d2f.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\40inchplus.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\40somethingmag.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\43things.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\4carinsurancequotes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\4shared.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\500nations.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\50megs.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\50states.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckanal.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckasians.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckcum.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckebony.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckhardcore.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6bucklesbians.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckmodels.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckorgy.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckteens.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\6buckvideos.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\800florals.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\888.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\89.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\8minutedating.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\8thstreetlatinas.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\911cheats.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\Sharerent.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\a1wireless.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aaafamilysites.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aahp.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aaomr.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aardvarktravel.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aarp.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aarp.thehartford.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\abby-cheat.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aboutflowers.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aboutmadrid.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aboutslots.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\abqtrib.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\absolute-playstation.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\absoluteasia.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\absolutely-free-hosting.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\absolutepoker.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\abt-travel.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.amberathome.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.bangingthebiway.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.cockasaurus.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.completeamateur.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.crissy-moran.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.dakotaraepatrick.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.flashergirls.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.hotindianbabe.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.jenakayricci.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.kelly-e.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.maliyah-madison.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.mandirosefanelli.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.poweredpussy.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.rachelaziani.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.rearendhim.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.shellydepalma.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.squirterz.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.suzannewinters.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.tawny-roberts.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.taylorgianni.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.tcbabes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\access.twistedpass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\accessamerica.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\accessfreeporn.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\acebusinesstravel.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\acerentacar.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\acesolitaire.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\acid-play.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\acli.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\acq.osd.mil -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\active-domain.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\activegamer.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\actorschecklist.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\actx.edu -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\addictinggames.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\addictionrecov.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\addictive247.co.uk -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adorablelegs.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adpayout.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adquest3d.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adriannaphyllis.carookee.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adshq.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adult-kingdom.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adult-personal.cptv.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adult-personalss.blogspot.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adult-profit.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adult.find.fm -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adult.freejavachat.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adult.netpond.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultalchemy.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultassociate.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultcams.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultclassified.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultclickfinder.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultdvdlist.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultflics.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultfriendfinder.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultlinkpost.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultlovecompass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultmatchdoctor.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultmoviemax.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultmovienetwork.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultpaymaster.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultpersonals.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultrealitypass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultrental.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultsmeetlocal.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultswim.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultvideonetwork.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultwebfind.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultwebmasterempire.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adultxxxpornstars.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\advanceautoparts.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\advancingwomen.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\advantageoneinsurance.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\advantageplayer.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adventureseeq.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\advnt03.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\adwareremovergold.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aegisdebtconsolidation.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aegtrackandfield.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aeroadvance.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aetna.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\affiliate.sapphiccash.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\affordablepoland.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\affordabletours.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\affordabletravel.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aft.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ag.state.il.us -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\agameaday.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\agedladies.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ago.state.nm.us -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\agonswim.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\agorics.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ahip.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ahirc.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ahrq.gov -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aigdirect.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ailife.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\airdiscounter.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\airfarestore.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\airporthomes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\airsaver.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\airtech.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\airtkt.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\airtreks.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aish.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aisinsurance.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aitdomains.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\akirashentai.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aladdincasino.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alamo.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alamonationalbonaire.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alexa.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alienmoon.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\all-hotels.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\all-internet-security.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allaboutblackjack.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allaccessadult.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allamateurmovies.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allasianpass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allbusiness.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allfloyd.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allgangbang.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allgayrealitypass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allhandjobpass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allinternal.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alljackpots.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allmales.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allnetworkpass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allpornsitespass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allrealitypass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allrealityxxxpass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allsitesaccess.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allstarporngirls.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allstarstuds.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allstate.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allstudentloan.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\allteens.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alltravelspain.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alltripprotection.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alphahentai.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alt.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alt.tnt.tv -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\altrec.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\alumniabroad.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aluriasoftware.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aly-abbara.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateur-beaver.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateur.imlive.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateurbangers.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateurbignaturals.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateurblowout.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateurerotica.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateurgirls.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateurmatch.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateurpie.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amateursgonebad.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amazingpass.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amberathome.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americancasinoguide.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americandaydreams.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americandebtco.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americanexpress.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americanhomeguides.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americanmortgagefundingcorp.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americansingles.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americanunsecured.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americaoneunsecured.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\americashadvance.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ameriquestmortgage.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ameristar.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ameritas.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amica.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amigos.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amo-mortgage.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\amorelist.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\anal-assult.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analblowout.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analcravings.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analfuckthrills.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analmaids.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analmatureorgies.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analog-pussy.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analsexlessons.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analsexvirgin.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analurges.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analvalley.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\analwishes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\andale.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\andycandice.carookee.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\angel2slut.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\angelsofporn.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\animeecstasy.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\anitaagni.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ansearch.com.au -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\answerfinancial.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\answers.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\anthem.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\antispywarecoalition.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\anz.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aoncollectorcar.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\apex-personal-loans.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aplus.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\apluscheats.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aplusmath.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\appleinsider.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\approvedcarfinance.co.uk -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\apps.nasd.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\arac.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\arago.fel.vanderbilt.edu:8200 -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\arcadetown.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\archet.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\archive.salon.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\argentinalove.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\articledashboard.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\articles.pointshop.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\artoftravel.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\as.wvu.edu:8000 -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asbdc-us.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asha.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ashleysextoys.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asia-discovery.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiafriendfinder.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiahotels.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asian.imlive.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asianallure.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asianblowout.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiancream.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asianerotics.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asianfetish.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiankitty.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiannudes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asianparade.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiansexqueens.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiansexthrills.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiarooms.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiatoursandtravel.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiatravel.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asiatraveltips.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\askalison.us -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\askmen.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aspe.hhs.gov -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aspfree.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aspinalls.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\assgrinders.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\assmasterpiece.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\assparade.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\assplundering.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asspoundinghunks.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\assthenmouth.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\asstraffic.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\athealth.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\atl.org.uk -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\atlanta-airport.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\atlantabesthomes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\atlanticcitynj.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\atlasdirect.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\atomfilms.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\atsearch.autotrader.co.uk -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\att.sbc.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\attitudetravel.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\attractwomennow.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\attu.blogspot.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\atyourservice.ucop.edu -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\au.pfinance.yahoo.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auction-warehouse.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auction.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auction.mlb.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctionarms.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctionbytes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctionfire.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctionguide.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctionpatrol.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctions.amazon.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctions.indiatimes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctions.lycos.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctions.nba.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctions.overstock.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctions.samsclub.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctions.yahoo.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctionsniper.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auctionwatch.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\audiosparx.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\audiovisual.kelkoo.co.uk -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auditmypc.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aufeminin.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\aul.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auntjudys.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auriton.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\austinpatrick.mabulle.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\austintexashomes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auto-loan.interest.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auto-owners.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auto.howstuffworks.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auto.indiatimes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\auto.progressive.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoapproved.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoassault.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoblog.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autobytel.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autocreditapproved.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autocreditfinders.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoebid.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoeurope.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoextra.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autofx.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autohausaz.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoinsuranceindepth.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoinsuranceplanners.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoinsurancetips.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoloanwarehouse.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\automotive.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autonetfinancial.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autop.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autopartsauthority.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autopartscorner.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autopartsgo.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autopartsplace.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autopartswarehouse.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autos.yahoo.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoshowny.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autosite.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autosonthe.net -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autotrader.ca -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autotrader.co.nz -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autotrader.co.uk -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autotrader.co.za -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autotrader.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autotrader.com.au -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autotrader.ie -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autotrader.nl -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoweb.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoweek.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autoworld.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autozone.co.za -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autozone.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autozone.cool-biznes.be -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autozone.isg2.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autozoneinc.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autozoneracing.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\autumn-jade.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\avert.org -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\avis.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\avvenu.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\away.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\axispaydayloan.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\azcentral.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\azcentral.gon.gannettonline.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\b-p.k7.pl -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\babygotboobs.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\babylon-x.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\babyonboard.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\babysfirstsite.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\backdoormoms.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\backseatbangers.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bad-credit-advisor.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\badblackbabes.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\badblue.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\badboys.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\badlesbiangirls.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\baitbus.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bajabound.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ballhoneys.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\ballparkreviews.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\baltimoresun.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\baltlife.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangamidget.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangboat.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangbrosnetwork.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangbrosonline.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangbrosworldwide.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangedbyagang.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangindahood.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangingmachines.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangingthebiway.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangkokbangers.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangmatch.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\bangmyhotwife.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\banner.24ktgoldcasino.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\banner.aspinallsonlinecasino.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\banner.flamingoclub.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\banner.goldenpalace.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\banner.goldenpalacebingo.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\banner.grandonline.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\banner.onlinecasino.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\barbarareevesrealtor.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\barebackbottoms.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\barebackway.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\barefootbadgirls.com -> Adware.Generic : No action taken.
HKU\S-1-5-21-1426590395-670792205-3813086739-1005\Software\TrustIn\URL Changer\barefootfuckers.com -> Adware.Generic : No action taken.
HKU\S-
Avatar billede trold Nybegynder
29. august 2006 - 21:12 #17
Hijack this giver nu følgende

Logfile of HijackThis v1.99.1
Scan saved at 21:12:00, on 29-08-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\ewido anti-spyware 4.0\guard.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Mixer.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\Programmer\Winamp\Winampa.exe
C:\Programmer\QuickTime\qttask.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\StartupMonitor.exe
C:\Programmer\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Programmer\WinTV\Ir.exe
C:\Programmer\Netscape\Netscape\Netscp.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer leveret af Cybercity Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgrammer%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Henrik\Application Data\Mozilla\Profiles\default\86ckjere.slt\prefs.js)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmer\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Programmer\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [!ewido] "C:\Programmer\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: BHODemon 2.0.lnk = C:\Programmer\BHODemon 2\BHODemon.exe
O4 - Global Startup: Acrobat-assistenten.lnk = C:\Programmer\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Programmer\WinTV\Ir.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmer\Fælles filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programmer\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Programmer\Dantz\Retrospect\retrorun.exe
Avatar billede trold Nybegynder
29. august 2006 - 21:19 #18
Sikke en masse entries - jeg er lost, håber snart at få bugt med dette
Avatar billede trold Nybegynder
29. august 2006 - 21:20 #19
Desværre er MSIE stadigvæk "besat" - den åbner stadigvæk på http://www.syssecuritypage.net/
Avatar billede trold Nybegynder
29. august 2006 - 21:28 #20
Kun med MSIE åben

Logfile of HijackThis v1.99.1
Scan saved at 21:27:34, on 29-08-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\Mixer.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\Programmer\Winamp\Winampa.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\WINDOWS\StartupMonitor.exe
C:\Programmer\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Programmer\WinTV\Ir.exe
C:\Programmer\Dantz\Retrospect\retrorun.exe
C:\Programmer\BHODemon 2\BHODemon.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer leveret af Cybercity Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgrammer%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Henrik\Application Data\Mozilla\Profiles\default\86ckjere.slt\prefs.js)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmer\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Programmer\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [!ewido] "C:\Programmer\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: BHODemon 2.0.lnk = C:\Programmer\BHODemon 2\BHODemon.exe
O4 - Global Startup: Acrobat-assistenten.lnk = C:\Programmer\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Programmer\WinTV\Ir.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmer\Fælles filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programmer\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Programmer\Dantz\Retrospect\retrorun.exe
Avatar billede fazli Nybegynder
29. august 2006 - 22:06 #21
Jeg vil have du kører ewido igen. og denne gang skal du slette hvad den finder.. Du har nemlig ikke valgt noget :/
Avatar billede trold Nybegynder
30. august 2006 - 16:58 #22
Jeg lukker spm - og starter et nyt da jeg har mistet overblikket - tak for hjælpen
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester