Jeg har kørt programmerne, men kunne ikke få rootchk til at virke, så har kun følgende 3 logs:
Logfile of HijackThis v1.99.1
Scan saved at 14:37:55, on 23-08-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Nicolai\Anti-virus\SuperAntiSpywarePro\SUPERAntiSpyware.exe
C:\Nicolai\Anti-virus\CrapCleaner\CCleaner\CCleaner.exe
C:\WINDOWS\explorer.exe
C:\Nicolai\Firefox\firefox.exe
C:\Documents and Settings\Jan Bisgaard\Skrivebord\alternativ.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBRR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [JMB36X Configure] "C:\WINDOWS\system32\JMRaidTool.exe" boot
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Programmer\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmer\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Nicolai\Anti-virus\SuperAntiSpywarePro\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Nicolai\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search -
res://C:\Programmer\Windows Live Toolbar\msntb.dll/search.htm
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?LinkID=39204O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Nicolai\Anti-virus\SuperAntiSpywarePro\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Nicolai\Anti-virus\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Nicolai\Anti-virus\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Windows_Down (wmplayer) - Unknown owner - C:\WINDOWS\system32\wmplayer.exe
--------------------------------------------------------------------------------------
ComboFix 07-08-17.2 - "Jan Bisgaard" 2007-08-23 14:47:44.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.45.1030.18.1122 [GMT 2:00]
((((((((((((((((((((((((( Files Created from 2007-07-23 to 2007-08-23 )))))))))))))))))))))))))))))))
2007-08-23 14:29 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-23 14:26 <DIR> d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-23 14:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-22 11:44 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-21 11:55 82,248 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-21 11:55 57,672 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-21 11:55 40,264 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-21 11:55 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-08-21 11:55 <DIR> d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\PC Tools
2007-08-19 20:54 <DIR> d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\HouseCall 6.6
2007-08-19 18:57 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-08-19 18:55 <DIR> d-------- C:\DOCUME~1\JANBIS~1\.housecall6.6
2007-08-19 18:10 <DIR> d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\ErrorKiller
2007-08-17 16:02 <DIR> d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\Lavasoft
2007-08-17 16:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-16 13:26 2,724 --a------ C:\WINDOWS\system32\updat1.exe
2007-08-14 14:07 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-14 13:59 164 --a------ C:\install.dat
2007-08-14 13:49 <DIR> d-------- C:\WINDOWS\system32\GroupPolicy
2007-08-14 13:49 <DIR> d-------- C:\Programmer\Hitman Pro
2007-08-10 19:43 <DIR> d-------- C:\Programmer\My CeWe Photobook
2007-07-30 01:47 <DIR> d-------- C:\Incomplete
2007-07-30 01:46 <DIR> d-------- C:\DOCUME~1\JANBIS~1\Incomplete
2007-07-30 01:46 <DIR> d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\LimeWire
2007-07-27 20:03 33,824 --a------ C:\WINDOWS\system32\drivers\oreans32.sys
2007-07-27 20:03 112 --a------ C:\WINDOWS\build.bat
2007-07-27 20:03 1,326,080 --a------ C:\WINDOWS\make.exe
2007-07-27 20:03 1,326,080 ---hs---- C:\WINDOWS\system32\wmplayer.exe
2007-07-27 15:24 <DIR> d-------- C:\Programmer\Google
2007-07-27 15:24 <DIR> d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\Google
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-22 16:39 --------- d-------- C:\Programmer\Windows Live Toolbar
2007-08-21 18:34 --------- d-a------ C:\Programmer\Furnish Pro
2007-08-21 18:34 --------- d-------- C:\Programmer\Pixie
2007-08-21 15:22 --------- d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\Azureus
2007-08-19 18:52 --------- d-------- C:\Programmer\Norton AntiVirus
2007-08-19 18:49 --------- d-------- C:\Programmer\Symantec
2007-06-28 00:05 --------- d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\Skype
2007-06-26 20:35 --------- d-------- C:\DOCUME~1\JANBIS~1\APPLIC~1\WoWUploader
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 15:22 1034240 --a------ C:\WINDOWS\explorer.exe
2006-06-23 08:48 32768 -ra------ C:\WINDOWS\inf\UpdateUSB.exe
--------- C:\Programmer\Fælles filer\Wise Installation Wizard
--------- C:\Programmer\Fælles filer\Symantec Shared
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 10:45]
"nwiz"="nwiz.exe" [2006-03-09 09:29 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-27 14:00 C:\WINDOWS\system32\rundll32.exe]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-27 14:00 C:\WINDOWS\system32\rundll32.exe]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"SoundMAXPnP"="C:\Programmer\Analog Devices\Core\smax4pnp.exe" [2006-05-01 12:07]
"SoundMAX"="C:\Programmer\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 10:19]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-20 11:59]
"!AVG Anti-Spyware"="C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 18:24]
"SUPERAntiSpyware"="C:\Nicolai\Anti-virus\SuperAntiSpywarePro\SUPERAntiSpyware.exe" [2007-04-23 15:46]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Speed Launch.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26]
HP Digital Imaging Monitor.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 20:28:24]
HP Image Zone Hurtig start.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 20:50:52]
Microsoft Office.lnk - C:\Nicolai\Microsoft Office\Office\OSA9.EXE [2000-01-21 09:15:54]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Nicolai\Anti-virus\SuperAntiSpywarePro\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Nicolai\Anti-virus\SuperAntiSpywarePro\SASWINLO.dll 2007-04-19 13:41 294912 C:\Nicolai\Anti-virus\SuperAntiSpywarePro\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R0 JGOGO;JMicron Hot-Plug Driver;C:\WINDOWS\system32\DRIVERS\JGOGO.sys
R0 JRAID;JRAID;C:\WINDOWS\system32\DRIVERS\jraid.sys
R1 oreans32;oreans32;\??\C:\WINDOWS\system32\drivers\oreans32.sys
R3 SenFiltService;SenFilt Service;C:\WINDOWS\system32\drivers\Senfilt.sys
S2 wmplayer;Windows_Down;C:\WINDOWS\system32\wmplayer.exe
S2 zgpgtwhx;Network DDE ZGPGTWHX;C:\WINDOWS\system32\svchost.exe -k zgpgtwhx
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
zgpgtwhx zgpgtwhx
*Newly Created Service* - CATCHME
*Newly Created Service* - SASDIFSV
*Newly Created Service* - SASENUM
*Newly Created Service* - SASKUTIL
Contents of the 'Scheduled Tasks' folder
2007-04-05 14:28:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Programmer\Apple Software Update\SoftwareUpdate.exe
2007-08-20 01:30:01 C:\WINDOWS\Tasks\ErrorKiller Scheduled Scan.job - C:\Programmer\ErrorKiller\ErrorKiller.exe
2007-08-17 18:00:38 C:\WINDOWS\Tasks\Norton AntiVirus - Kør fuld systemskanning - Jan Bisgaard.job
2007-08-23 11:02:50 C:\WINDOWS\Tasks\Symantec NetDetect.job
2007-08-23 11:54:00 C:\WINDOWS\Tasks\Søg efter opdateringer til Windows Live Toolbar.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-08-23 14:48:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-23 14:48:47
--- E O F ---
---------------------------------------------------------------------------
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 08/23/2007 at 02:41 PM
Application Version : 3.7.1018
Core Rules Database Version : 3291
Trace Rules Database Version: 1302
Scan type : Quick Scan
Total Scan Time : 00:12:54
Memory items scanned : 172
Memory threats detected : 0
Registry items scanned : 722
Registry threats detected : 27
File items scanned : 14838
File threats detected : 20
Unclassified.Oreans32
HKLM\System\ControlSet001\Services\oreans32
C:\WINDOWS\SYSTEM32\DRIVERS\OREANS32.SYS
HKLM\System\ControlSet003\Services\oreans32
HKLM\System\CurrentControlSet\Services\oreans32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000#DeviceDesc
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000#Capabilities
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000\LogConf
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000\Control
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000\Control#ActiveService
HKLM\SYSTEM\CurrentControlSet\Services\oreans32#Type
HKLM\SYSTEM\CurrentControlSet\Services\oreans32#Start
HKLM\SYSTEM\CurrentControlSet\Services\oreans32#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\oreans32#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\oreans32#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\oreans32\Security
HKLM\SYSTEM\CurrentControlSet\Services\oreans32\Security#Security
HKLM\SYSTEM\CurrentControlSet\Services\oreans32\Enum
HKLM\SYSTEM\CurrentControlSet\Services\oreans32\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\oreans32\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\oreans32\Enum#NextInstance
Adware.Tracking Cookie
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@adfair[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@track.adform[2].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@www.googleadservices[3].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@www.googleadservices[2].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@www.googleadservices[5].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@ads.vg.basefarm[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@imrworldwide[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@image.masterstats[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@www3.addfreestats[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@tracking.notabenestats[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@ads.adbrite[2].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@atdmt[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@ad.bolddk[2].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@e2.emediate[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@stat.novasol[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@www.googleadservices[4].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@2.adbrite[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Jan Bisgaard\Cookies\jan_bisgaard@www.googleadservices[1].txt
---------------------------------------------------------------------------