Avatar billede smedenhba Nybegynder
23. juli 2008 - 19:22 Der er 17 kommentarer og
1 løsning

Virus og langsom pcér

Er der en som kan hjælpe med en log fra hijackthis har fået noget virus som jeg ikke kan slippe af med.Også er den utrolig langsom køre helt oppe på 100 % i cpuén.

På forhånd Tak
smedenhba

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:16:52, on 23-07-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\domino.exe
C:\WINDOWS\VMSnap1.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programmer\SPAMfighter\SFAgent.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\TomTom HOME 2\HOMERunner.exe
C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmer\SPAMfighter\sfus.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\Programmer\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\BullGuard Ltd\BullGuard\BullGuard.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\Programmer\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [domino] C:\WINDOWS\domino.exe
O4 - HKLM\..\Run: [VMSnap1] C:\WINDOWS\VMSnap1.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Programmer\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe
O4 - HKLM\..\Run: [BullGuard] "C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe" -boot
O4 - HKLM\..\Run: [muBlinder] D:\Download fra nettet\Mublinder 3,54\muBlinder.exe -startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Programmer\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programmer\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191597533583
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191597512573
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: 
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
O23 - Service: BGRaSvc - BullGuard - C:\Programmer\BullGuard Ltd\BullGuard\support\bgrasvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Programmer\SPAMfighter\sfus.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe

--
End of file - 9156 bytes
Avatar billede smedenhba Nybegynder
23. juli 2008 - 19:27 #1
Glemte lige har fået et ikon ligende i højre hjørne som popér op med at min pcér er infected.windows has detcted spyware infection.og jeg så skal klikke her for at instaler spyware fjerner.tør jeg ikke.
Avatar billede resist Nybegynder
23. juli 2008 - 19:55 #2
Hej :-)

Følg venligst hele vejledningen i denne artikel: http://www.eksperten.dk/artikler/1123
Avatar billede smedenhba Nybegynder
24. juli 2008 - 16:03 #3
Så er det prøvet vedhæfter logérne
ComboFix 08-07-23.4 - Mor 2008-07-24 15:18:23.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1030.18.117 [GMT 2:00]
Running from: C:\Documents and Settings\Mor\Skrivebord\Div til brug på eksperten\combofix\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\g32.txt
C:\WINDOWS\gs32.txt
C:\WINDOWS\s32.txt
C:\WINDOWS\ws386.ini

.
(((((((((((((((((((((((((((((((((((((((  Drivers/Services  )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASPIMGR
-------\Service_aspimgr


(((((((((((((((((((((((((  Files Created from 2008-06-24 to 2008-07-24  )))))))))))))))))))))))))))))))
.

2008-07-24 12:15 . 2008-07-24 12:15    <DIR>    d--------    C:\Programmer\SUPERAntiSpyware
2008-07-24 12:15 . 2008-07-24 12:15    <DIR>    d--------    C:\Documents and Settings\Mor\Application Data\SUPERAntiSpyware.com
2008-07-24 12:15 . 2008-07-24 12:15    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-24 12:02 . 2008-07-24 12:03    <DIR>    d--------    C:\Programmer\CCleaner
2008-07-24 10:21 . 2008-07-24 10:23    <DIR>    d--------    C:\Documents and Settings\Oliver\Application Data\BullGuard
2008-07-23 19:15 . 2008-07-23 19:15    <DIR>    d--------    C:\Program Files
2008-07-23 09:31 . 2008-07-23 09:29    102,664    --a------    C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-23 09:29 . 2008-07-23 11:40    <DIR>    d--------    C:\Documents and Settings\Mor\.housecall6.6
2008-07-23 09:08 . 2008-06-19 17:24    28,544    --a------    C:\WINDOWS\system32\drivers\pavboot.sys
2008-07-22 22:46 . 2008-07-24 12:19    288    --a------    C:\WINDOWS\system32\drivers\fwdrv.err
2008-07-21 19:26 . 2008-07-24 15:42    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\BullGuard
2008-07-21 19:25 . 2008-07-21 19:37    <DIR>    d--------    C:\Documents and Settings\Mor\Application Data\BullGuard
2008-07-21 19:24 . 2008-07-21 19:24    <DIR>    d--------    C:\Programmer\BullGuard Ltd
2008-07-21 19:24 . 2008-06-12 12:17    52,560    --a------    C:\WINDOWS\system32\drivers\BdFileSpy.sys
2008-07-21 17:12 . 2008-07-21 17:12    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
2008-07-21 17:12 . 2008-07-21 17:12    1,409    --a------    C:\WINDOWS\QTFont.for
2008-07-21 14:47 . 2008-07-21 14:47    <DIR>    d--------    C:\Documents and Settings\Mor\Application Data\TomTom
2008-07-21 14:42 . 2008-07-21 14:42    <DIR>    d--------    C:\Programmer\TomTom HOME 2
2008-07-01 14:30 . 2008-07-01 14:30    19,784    --a------    C:\WINDOWS\system32\BgOutlookHook.dll
2008-07-01 14:26 . 2008-07-01 14:26    14,152    --a------    C:\WINDOWS\system32\lccl.dll
2008-07-01 14:26 . 2008-07-01 14:26    14,152    --a------    C:\WINDOWS\system32\client_cc.dll
2008-06-27 17:26 . 2008-06-27 17:26    <DIR>    d--------    C:\WINDOWS\system32\LogFiles
2008-06-24 15:27 . 2008-06-24 15:27    <DIR>    d--------    C:\Documents and Settings\Mor\Application Data\GARMIN
2008-06-24 15:21 . 2008-06-24 15:21    <DIR>    d--------    C:\Programmer\Garmin

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-24 12:24    ---------    d-----w    C:\Programmer\SPAMfighter
2008-07-24 10:15    ---------    d-----w    C:\Programmer\Fælles filer\Wise Installation Wizard
2008-07-23 14:52    ---------    d-----w    C:\Programmer\Lavasoft
2008-07-23 14:38    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-23 07:08    ---------    d-----w    C:\Programmer\Panda Security
2008-07-21 14:54    ---------    d-----w    C:\Documents and Settings\Mor\Application Data\HPAppData
2008-07-21 12:47    ---------    d-----w    C:\Documents and Settings\Mor\Application Data\Uniblue
2008-07-19 09:32    ---------    d-----w    C:\Documents and Settings\Oliver\Application Data\HPAppData
2008-07-09 14:42    ---------    d-----w    C:\Programmer\Java
2008-06-13 14:27    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-24 15:15    ---------    d-----w    C:\Documents and Settings\Mor\Application Data\gtk-2.0
2008-05-24 14:46    ---------    d-----w    C:\Programmer\GIMP-2.0
2008-05-16 09:58    12,632    ----a-w    C:\WINDOWS\system32\lsdelete.exe
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 18:05 15360]
"TomTomHOME.exe"="C:\Programmer\TomTom HOME 2\HOMERunner.exe" [2008-05-06 10:42 202088]
"BullGuard"="C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe" [2008-07-21 19:32 304456]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
"PC Suite Tray"="C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12 695808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"muBlinder"="D:\Download fra nettet\Mublinder 3" [X]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-08-21 20:42 282624]
"domino"="C:\WINDOWS\domino.exe" [2006-07-04 08:16 49152]
"VMSnap1"="C:\WINDOWS\VMSnap1.exe" [2006-07-17 05:27 49152]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 04:06 40048]
"Share-to-Web Namespace Daemon"="C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 11:42 69632]
"SPAMfighter Agent"="C:\Programmer\SPAMfighter\SFAgent.exe" [2008-02-26 12:10 317072]
"GrooveMonitor"="C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"BullGuard"="C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe" [2008-07-21 19:32 304456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 18:05 15360]
"Nokia.PCSync"="C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
BTTray.lnk - C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe [2003-11-20 13:11:56 503869]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BgMainSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmer\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=

R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 11:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 11:21]
R2 BdFileSpy;BullGuard File Monitor Driver;C:\WINDOWS\system32\drivers\BdFileSpy.sys [2008-06-12 12:17]
R2 BsFileScan;BullGuard File Scan Service;C:\WINDOWS\System32\svchost.exe [2008-04-14 18:06]
R2 BsFire;BullGuard Firewall Service;C:\WINDOWS\System32\svchost.exe [2008-04-14 18:06]
R2 SPAMfighter Update Service;SPAMfighter Update Service;C:\Programmer\SPAMfighter\sfus.exe [2008-02-26 12:10]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 11:21]
R3 afw;Agnitum firewall driver;C:\WINDOWS\system32\DRIVERS\afw.sys [2007-11-28 12:42]
R3 Reconn;BullGuard Email Monitor;C:\Programmer\BullGuard Ltd\BullGuard\Reconn.sys [2007-10-29 10:08]
S3 BGRaSvc;BGRaSvc;C:\Programmer\BullGuard Ltd\BullGuard\support\bgrasvc.exe [2008-07-01 14:30]
S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-05-02 16:24]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 15:17]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard    REG_MULTI_SZ      BgMainSvc BsFileScan BsMailProxy BsFire
.
Contents of the 'Scheduled Tasks' folder
"2008-06-20 10:40:07 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Programmer\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-06-20 10:40:04 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Programmer\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
- - - - ORPHANS REMOVED - - - -

Notify-WgaLogon - (no file)
MSConfigStartUp-MsnMsgr - C:\Programmer\MSN Messenger\MsnMsgr.Exe


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 -: Send To &Bluetooth - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O16 -: {029FDBA6-3547-11D7-AA4C-0050BF051A00} - hxxp://downol.dr.dk/download/netradio/Rawflow.cab
C:\WINDOWS\Downloaded Program Files\Rawflow.ocx

O16 -: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-24 15:41:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\Programmer\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclUSBSrv.exe
.
**************************************************************************
.
Completion time: 2008-07-24 15:53:42 - machine was rebooted
ComboFix-quarantined-files.txt  2008-07-24 13:53:02

Pre-Run: 13,733,617,664 byte ledig
Post-Run: 14,247,190,528 byte ledig

179

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:58:26, on 24-07-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmer\SPAMfighter\sfus.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\domino.exe
C:\WINDOWS\VMSnap1.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programmer\SPAMfighter\SFAgent.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Programmer\TomTom HOME 2\HOMERunner.exe
C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\Programmer\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [domino] C:\WINDOWS\domino.exe
O4 - HKLM\..\Run: [VMSnap1] C:\WINDOWS\VMSnap1.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Programmer\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [BullGuard] "C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe" -boot
O4 - HKLM\..\Run: [muBlinder] D:\Download fra nettet\Mublinder 3,54\muBlinder.exe -startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Programmer\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programmer\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191597533583
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191597512573
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: 
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
O23 - Service: BGRaSvc - BullGuard - C:\Programmer\BullGuard Ltd\BullGuard\support\bgrasvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Programmer\SPAMfighter\sfus.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe

--
End of file - 9204 bytes


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/24/2008 at 01:38 PM

Application Version : 4.15.1000

Core Rules Database Version : 3513
Trace Rules Database Version: 1504

Scan type      : Complete Scan
Total Scan Time : 01:15:51

Memory items scanned      : 172
Memory threats detected  : 0
Registry items scanned    : 6143
Registry threats detected : 5
File items scanned        : 18141
File threats detected    : 321

Trojan.Downloader-Gen
    [braviax] C:\WINDOWS\SYSTEM32\BRAVIAX.EXE
    C:\WINDOWS\SYSTEM32\BRAVIAX.EXE
    [braviax] C:\WINDOWS\SYSTEM32\BRAVIAX.EXE
    [braviax] C:\WINDOWS\SYSTEM32\BRAVIAX.EXE

Trojan.Unclassified/BraviaX
    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#braviax [ C:\WINDOWS\system32\braviax.exe ]
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#braviax [ C:\WINDOWS\system32\braviax.exe ]

Adware.Tracking Cookie
    C:\Documents and Settings\Mor\Cookies\mor@www2.addfreestats[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.sexlir[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@amateurporndump[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@borsen.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@adserver.easyad[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.sextop[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@indexstats[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@adserver.banneradministration[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@spamfighter.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@adserver.banneradministration[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@spamfighter.112.2o7[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@counter9.sextracker[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@youporns[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@sexyandfunny[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@sexyandfunny[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@sexdebut[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@counter9.sextracker[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@pro-market[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@likecrack[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@counter9.sextracker[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@falckdanmark.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.xxxmsncam[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.adgoto[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.adgoto[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad.ofir[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@bonnier.banneradministration[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.theporndoc[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@sextracker[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@sextracker[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@sextracker[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@adbrite[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@sexmummy[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@media.mtvnservices[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.kinxxx[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@casalemedia[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@youramateurporn[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@youramateurporn[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@specificclick[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@statse.webtrendslive[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@statse.webtrendslive[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@revsci[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@serving-sys[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@tracking.3gnet[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@serving-sys[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@dk-sex[5].txt
    C:\Documents and Settings\Mor\Cookies\mor@dk-sex[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@dk-sex[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@coopdev.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.mediamayhemcorp[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@mediaprovider.adservinginternational[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@serving-sys[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@fastclick[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@livestats.diewebdesigner[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@livestats.diewebdesigner[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.sk-discount[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@findvej[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@questionmarket[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@mediaonenetwork[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads2.jubii[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads2.jubii[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads2.jubii[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@atdmt[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@socialmedia[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad.yieldmanager[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.sexyandfunny[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.sexyandfunny[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.sexyandfunny[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad.yieldmanager[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad.zanox[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.sexmummy[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@atdmt[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@tradedoubler[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@tradedoubler[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad.yieldmanager[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.cracks[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@interclick[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@adultfriendfinder[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@interclick[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@trafficinfo[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@mediaplex[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.fuckaroo[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@adultfriendfinder[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@Trying_to_fuck_a_pussy_as_big_as_a_country[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.cnn[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.sexdating[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.skdiscount[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.googleadservices[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.googleadservices[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.googleadservices[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.sun[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@indextools[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@indextools[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@sterlingairlines.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.dandiscount[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@kinxxx[5].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.skdiscount[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.skdiscount[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@partners.webmasterplan[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@mediaservices.myspace[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.googleadservices[6].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.googleadservices[5].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.googleadservices[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@track.adform[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.pornoamateurs[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@eas.apm.emediate[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@eas.apm.emediate[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@dollarwarez[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@adultadworld[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@statcounter[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@sex-video[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@server.iad.liveperson[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@date.ventivmedia[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.nakedonthestreets[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.nakedonthestreets[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@server.iad.liveperson[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@tribalfusion[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@statcounter[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@server.iad.liveperson[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad1.emediate[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad1.clickhype[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@adserver.adservinginternational[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@hitbox[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@hitbox[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@adserver.adservinginternational[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@stats.stuenings-medien[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@secretxxxvideo[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.find[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@hitcount[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@mycounter.tinycounter[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@pornhost[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@free-sex[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.rejsestart[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@tdc.112.2o7[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@hitbox[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@stat.onestat[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@stat.onestat[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@tdc.112.2o7[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@realteenpictureclub[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.addynamix[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.addynamix[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.multimediaworld[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.crakmedia[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.adbrite[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.multimediaworld[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.addynamix[4].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.crakmedia[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ehg-nokiafin.hitbox[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.gamers-globe[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@tele2as.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.24porn7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@freeadultmedia[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@freeadultmedia[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@adtech[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@viaatomvideo.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.findvej[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad1.doublepimp[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@skdiscount[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.findalt[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.macromedia[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.pointroll[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@pulz.banneradministration[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@server.cpmstar[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@advertising[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@pornhub[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@partypoker[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@partypoker[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@adfair[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ehg-eset.hitbox[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@justsexyvideos[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@www.fpctraffic2[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad2.doublepimp[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ehg-eset.hitbox[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@skdiscount[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@008.free-counter.co[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@2.adbrite[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@24porn7[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@3.adbrite[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@4.adbrite[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@4.adbrite[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@ad1.clickhype[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ads.as4x.tmcs[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@aller.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@apmebf[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@as1.falkag[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@atwola[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@audit.median[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@banner2.fynskemedier[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@bannere.fyens[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@banners.netcraft[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@cassava[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@clicksor[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@cracks[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@cz3.clickzs[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@dk-sex[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@doubleclick[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@doubleclick[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@dtftravel.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@dtftravel.112.2o7[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@e2.emediate[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@e2.emediate[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@eas.apm.emediate[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@eas4.emediate[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@edcgruppen.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ehg-dig.hitbox[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ehg-dig.hitbox[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ehg-nokiafin.hitbox[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@elkjop.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ero-advertising[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@eroticlick[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@exchange.ggmedia[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@eyewonder[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@fastclick[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@fuckaroo[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@geo.precisionclick[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@gostats[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@gratis-porno[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@heavycom.122.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@hitcount[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ilead.itrack[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@ilead.itrack[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@image.masterstats[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@imrworldwide[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@oddcast[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@justsexyvideos[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@kinxxx[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@mediaprovider.adservinginternational[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@msnportal.112.2o7[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@multimediaworld[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@nakedonthestreets[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@nakedonthestreets[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@ncom.banneradministration[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@ncom.banneradministration[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@overture[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@overture[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@partygaming.122.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@pornoamateurs[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@pornoamateurs[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@porn[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@questionpro[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@qxl.adservinginternational[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@qxl.banneradministration[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@s1.trafficmaxx[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@sexmummy[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@sexyandfunny[3].txt
    C:\Documents and Settings\Mor\Cookies\mor@siba.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@skdiscount[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@smileycentral[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@sonofon.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@tdc.112.2o7[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@theporndoc[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@toplist[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@tracking.notabenestats[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@trackalyzer[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@vhost.oddcast[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@usenext[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@warez411[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@warlog[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@xiti[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@xtendmedia[1].txt
    C:\Documents and Settings\Mor\Cookies\mor@zedo[2].txt
    C:\Documents and Settings\Mor\Cookies\mor@zbox.zanox[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@bs.serving-sys[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@eas.apm.emediate[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@myroitracking[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@revsci[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@4.adbrite[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@eas.apm.emediate[3].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ilead.itrack[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@statcounter[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@counter2.hitslink[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@msnportal.112.2o7[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@adultadworld[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@xiti[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.clicksor[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@server.cpmstar[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@image.masterstats[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@mediaplex[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@rotator.adjuggler[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@advert.runescape[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@atdmt[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.addynamix[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.as4x.tmcs[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@apmebf[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@adfair[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.habbogroup[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@fastclick[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@fastclick[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@msnaccountservices.112.2o7[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.adbrite[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@oddcast[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@atwola[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@adtech[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.gamesbannernet[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@2o7[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@serving-sys[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@toplist[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@track.adform[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@track.adform[3].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@2o7[3].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@yadro[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ad.yieldmanager[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@vhost.oddcast[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@advertising[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@advertising[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@server.iad.liveperson[3].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@server.iad.liveperson[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.habbohotel[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.habbohotel[3].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.neodelight[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.gamers-globe[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@adserver.easyad[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@trackseven[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@adbrite[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@doubleclick[3].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@doubleclick[1].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@ads.freeonlinegames[2].txt
    C:\Documents and Settings\Oliver\Cookies\oliver@yieldmanager[1].txt


Tag dig god tid slukker nu og tænder først op igen om 10 dages tid.
God sommer
smedenhba
Avatar billede resist Nybegynder
24. juli 2008 - 21:37 #4
Hvorfor er muBlinder installeret?

Umiddelbart tyder det på, at du har en ulovlig version af Windows installeret.
Avatar billede smedenhba Nybegynder
24. juli 2008 - 21:54 #5
Mublinder? Hvad er det?Hvad gør jeg ved det?
Avatar billede resist Nybegynder
24. juli 2008 - 22:32 #6
Findes her: D:\Download fra nettet\Mublinder 3,54\muBlinder.exe –startup - dette program tyder på en ulovlig Windows?

http://www.bleepingcomputer.com/startups/muBlinder.exe-16771.html
Avatar billede smedenhba Nybegynder
04. august 2008 - 18:27 #7
Hej Igen
det må du meget undskylde blev jeg ikke meget kloger af?
Hvad gør jeg?
Er det Farligt?
04. august 2008 - 20:07 #8
Pointen er at hvis man har en P**** udgave af XP så ka' man ikke få lov til at bruge Microsoft WindowsUpdate for at få diverse (vigtige) opdateringer til din XP. Men ved brug af denne [Mublinder 3,54] 'snyder' man Microsoft til at tro at det er en 'ægte' version. Men der følger tit lidt extra med i pakken fra denne Mublinder ...

Samt her på Eksperten.dk støtter vi _ikke_ P**** udgaver af diverse programmer...

Hvor kommer din PC / XP fra ?
Du bør måske liiiige checke/kontakte vedkommende ?

---------------------------------------

Afinstaller (hvis det er der?)
* SpeedUpMyPC
via
[Start][Indstilninger][Kontrolpanel][Tilføj/fjern programmer]

Genstart for at fuldføre afinstalationen...

---------------------------------------

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er (foreløbig) denne, som skal fixes:

O4 - HKLM\..\Run: [muBlinder] D:\Download fra nettet\Mublinder 3,54\muBlinder.exe -startup

Genstart normalt...

---------------------------------------

Gennemfør denne procedure ->

Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
Lad programmer foretage en oprydning...

--------

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...
04. august 2008 - 20:08 #9
<resist>: Undskyld - så først nu at det principielt er din 'tråd' *S* ...
Avatar billede resist Nybegynder
05. august 2008 - 10:48 #10
karise_larry >>> Det er ok. Du overtager bare ;-)
05. august 2008 - 21:06 #11
*S* Afventer <smedenhba> ...
Avatar billede smedenhba Nybegynder
07. august 2008 - 17:35 #12
Ja undskyld vente tiden.Dette er ikke min pcér men min kærstes så er ikke på hverdag.
Avatar billede smedenhba Nybegynder
07. august 2008 - 20:04 #13
Malwarebytes' Anti-Malware 1.24
Database version: 1030
Windows 5.1.2600 Service Pack 3

19:56:32 07-08-2008
mbam-log-8-7-2008 (19-56-32).txt

Skan type: Fuldstændig skanning (C:\|D:\|)
Objekter skannet: 87649
Tid tilbagelagt: 1 hour(s), 46 minute(s), 5 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 0
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 0
Inficerede Filer: 0

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
(Ingen mistænkelige filer fundet)

Inficerede Filer:
(Ingen mistænkelige filer fundet)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:01:59, on 07-08-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\domino.exe
C:\WINDOWS\VMSnap1.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programmer\SPAMfighter\SFAgent.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\TomTom HOME 2\HOMERunner.exe
C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmer\SPAMfighter\sfus.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\Programmer\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [domino] C:\WINDOWS\domino.exe
O4 - HKLM\..\Run: [VMSnap1] C:\WINDOWS\VMSnap1.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programmer\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Programmer\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [BullGuard] "C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe" -boot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Programmer\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Ltd\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programmer\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191597533583
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191597512573
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: 
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
O23 - Service: BGRaSvc - BullGuard - C:\Programmer\BullGuard Ltd\BullGuard\support\bgrasvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Programmer\SPAMfighter\sfus.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe

--
End of file - 9229 bytes
07. august 2008 - 20:54 #14
Nydeligt - hvordan kører PC'en så nu ?

PS: Kan du godt gå på WindowsUpdate UDEN at den brokker sig ?
Avatar billede smedenhba Nybegynder
07. august 2008 - 21:49 #15
Køre Helt fint.Det har jeg Ikke prøvet.Hvis det er en kopi hun har fået hvad sker der så? Takker for hjælpen ind til nu.
08. august 2008 - 06:59 #16
Det ska' Microsoft nok fortælle ved lejlighed *S* - ved visse WindowsUpdate bliver der indlæst en lille util "Windows Genuine Advantage" -> http://www.microsoft.com/genuine/ProgramInfo.aspx?displaylang=en&sGuid=c85d0c86-2901-4b98-8ec3-835dd5a865ca som 'validere' din XP licenskode mod en eller anden database ting. Hvis den bliver konstateret 'ulovlig' skal du nok få det at vide på skærmen... Nej det er ikke sådan at M$ så pludselig står foran din gadedør for at ...

Så ka' du ikke få lov til at bruge WindowsUpdate...
08. august 2008 - 06:59 #17
Der er ikke mere 'snavs' ifølge din Log...

Du er velkommen en anden gang...

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Safe Surfing...

--------------

Registreringsdatabase oprydning kan anbefales ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Register]...)
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller NEJ til den.

--------------
08. august 2008 - 16:09 #18
Takker for P.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester