/ Forside/ Teknologi / Hardware / Pc'er / Spørgsmål
Login
Glemt dit kodeord?
Brugernavn

Kodeord


Reklame
Top 10 brugere
Pc'er
#NavnPoint
Klaudi 48441
o.v.n. 40523
refi 29114
Fijala 19253
molokyle 16243
webnoob 14995
Brassovit.. 12463
peet49 11383
EXTERMINA.. 10755
10  severino 10622
går hele tiden ud
Fra : Broderpivert
Vist : 520 gange
50 point
Dato : 15-10-06 20:40

Hey. Jeg har et mega problem, når jeg sidder og spiller et spil går min com. automatisk ud til windows. Og det er som regl internet sider der kommer op. Men hvorfor går den bare ud i windows???? Håber på hjælp

 
 
Kommentar
Fra : Jorgen_ros


Dato : 15-10-06 20:49

Du trykker måske på en genvejstastekombination under spillet?

Kommentar
Fra : Broderpivert


Dato : 15-10-06 20:53

Nej. Det havde jeg nemlig også i tankerne, men det gør jeg ikke. Den går automatisk ud

Kommentar
Fra : severino


Dato : 15-10-06 20:53

Hvilken internetsider går den ud på???
Måske er det noget snavs ???
Det kan du selv bedømme ud fra internetsidernes indhold!

Kommentar
Fra : Broderpivert


Dato : 15-10-06 20:55

Jamen jeg går da rundt hist og pist. Men hvilket program skal jeg bruge for at fjerne eller stoppe at de bare popper op? Og hvor kan jeg finde det?

Kommentar
Fra : stl_s


Dato : 15-10-06 23:24

Lad os få fjernet det skidt fra din maskine:

Hent denne scanner http://www.superantispyware.com/downloads/SUPERAntiSpyware1241.exe

Installer, og opdater scanneren manuelt. OBS, ved installationen bliver det foreslået at du registrerer med din email. Det behøver du ikke at gøre.


Start op i fejlsikret tilstand (tast f8 flere gange under opstart). Hvis du ikke kan det, så se her
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=110&PN=1


Start SuperAntiSpyware, klik "Scan your computer", sæt flueben i dine drev, ovre til venstre i vinduet. Ovre til højre i vinduet, sætter du prik i "Perform Complete Scan". Klik "næste", nu scanner den. Når den er færdig, så markerer du det den finder, og lader scannereren fjerne det.

Genstart til normal tilstand (scanneren tilbyder måske at gøre det).

Åbn scanneren igen, og klik "preferences"-> "stastics/logs". Marker loggen, og klik "View log". Kopier loggen her ind i tråden, sammen med en frisk HijackThis log.

Og bagefter:

Hent HijackThis her http://www.sitecenter.dk/secure/nss-folder/mappe/hjtspecial.exe Opret en selvstændig mappe til HijackThis, kald den f,eks HJT. Kør Hijackthis, klik "Do a systemscan and save a logfile". Kopier loggen og sæt den her ind i tråden, så kigger jeg på den. Du må ikke slette noget selv med HijackThis. Jeg skal nok give dig en vejledning til hvad du skal gøre.






Kommentar
Fra : Broderpivert


Dato : 16-10-06 11:53

SUPERAntiSpyware Scan Log
Generated 10/16/2006 at 11:21 AM

Core Rules Database Version : 3104
Trace Rules Database Version: 1130

Memory threats detected : 4
Registry threats detected : 670
File threats detected : 373

Adware.DeluxeCommunications
   C:\WINDOWS\SYSTEM32\DXCLIB303562752.DLL
   C:\WINDOWS\SYSTEM32\DXCLIB303562752.DLL
   C:\PROGRAMMER\DELUXECOMMUNICATIONS\DXCBHO.DLL
   C:\PROGRAMMER\DELUXECOMMUNICATIONS\DXCBHO.DLL
   [DeluxeCommunications] C:\Programmer\DeluxeCommunications\Dxc.exe
   C:\Programmer\DeluxeCommunications\Dxc.exe
   [DeluxeCommunications] C:\Programmer\DeluxeCommunications\Dxc.exe
   HKLM\Software\Classes\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA}
   HKCR\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA}
   HKCR\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA}\InprocServer32
   HKCR\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA}\InprocServer32#ThreadingModel
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\Microsoft\Internet Explorer\URLSearchHooks#{A8BD6820-6ED7-423E-9558-2D1486B0FEEA}
   HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks#{A8BD6820-6ED7-423E-9558-2D1486B0FEEA}
   HKCR\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA}
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\DeluxeCommunications
   HKLM\Software\DeluxeCommunications
   HKLM\Software\DeluxeCommunications\Internet Explorer
   HKLM\Software\DeluxeCommunications\Internet Explorer#PInfo
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DeluxeCommunications
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DeluxeCommunications#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DeluxeCommunications#UninstallString
   HKLM\Software\Microsoft\Windows\CurrentVersion\Run#DeluxeCommunications [ C:\Programmer\DeluxeCommunications\Dxc.exe ]
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Run#DeluxeCommunications [ C:\Programmer\DeluxeCommunications\Dxc.exe ]
   C:\Programmer\DeluxeCommunications\DxcCore.dll
   C:\Programmer\DeluxeCommunications
   C:\Documents and Settings\Lasse Lauritsen\Application Data\Dxcknwrd.dll
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temp\i90.tmp
   C:\Programmer\Common Files\misc002\DXC.exe
   C:\WINDOWS\system32\bkd.exe
   C:\WINDOWS\Prefetch\DXC.EXE-1A399A1F.pf
   C:\WINDOWS\Prefetch\DXC.EXE-2D209BA8.pf

Unclassified.Unknown Origin/System
   C:\WINDOWS\SYSTEM32\SSTQR.DLL
   C:\WINDOWS\SYSTEM32\SSTQR.DLL
   [Windows update] C:\WINDOWS\system32\wudupdate.exe
   C:\WINDOWS\system32\wudupdate.exe
   Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\sstqr

Trojan.Mezzia/Resident
   C:\WINDOWS\SYSTEM32\WINMFU32.DLL
   C:\WINDOWS\SYSTEM32\WINMFU32.DLL

Adware.eZula
   [Client Server Runtime Process] C:\WINDOWS\system32\smmss.exe
   C:\WINDOWS\system32\smmss.exe
   [Web Offer] C:\WINDOWS\system32\smmss.exe
   C:\WINDOWS\system32\ezstub.exe
   C:\WINDOWS\eZinstall.exe
   HKCR\EZulaAgent.eZulaCtrlHost
   HKCR\EZulaAgent.eZulaCtrlHost\CLSID
   HKCR\EZulaAgent.eZulaCtrlHost\CurVer
   HKCR\EZulaAgent.eZulaCtrlHost.1
   HKCR\EZulaAgent.eZulaCtrlHost.1\CLSID
   HKCR\eZulaAgent.IEObject
   HKCR\eZulaAgent.IEObject\CLSID
   HKCR\eZulaAgent.IEObject\CurVer
   HKCR\eZulaAgent.IEObject.1
   HKCR\eZulaAgent.IEObject.1\CLSID
   HKCR\EZulaAgent.PlugProt
   HKCR\EZulaAgent.PlugProt\CLSID
   HKCR\EZulaAgent.PlugProt\CurVer
   HKCR\EZulaAgent.PlugProt.1
   HKCR\EZulaAgent.PlugProt.1\CLSID
   HKCR\eZulaAgent.ToolBarBand
   HKCR\eZulaAgent.ToolBarBand\CLSID
   HKCR\eZulaAgent.ToolBarBand.1
   HKCR\eZulaAgent.ToolBarBand.1\CLSID
   HKCR\EZulaBootExe.InstallCtrl
   HKCR\EZulaBootExe.InstallCtrl\CLSID
   HKCR\EZulaBootExe.InstallCtrl\CurVer
   HKCR\EZulaBootExe.InstallCtrl.1
   HKCR\EZulaBootExe.InstallCtrl.1\CLSID
   HKCR\EZulaFSearchEng.eZulaCode
   HKCR\EZulaFSearchEng.eZulaCode\CLSID
   HKCR\EZulaFSearchEng.eZulaCode\CurVer
   HKCR\EZulaFSearchEng.eZulaCode.1
   HKCR\EZulaFSearchEng.eZulaCode.1\CLSID
   HKCR\EZulaFSearchEng.eZulaHash
   HKCR\EZulaFSearchEng.eZulaHash\CLSID
   HKCR\EZulaFSearchEng.eZulaHash\CurVer
   HKCR\EZulaFSearchEng.eZulaHash.1
   HKCR\EZulaFSearchEng.eZulaHash.1\CLSID
   HKCR\EZulaFSearchEng.eZulaSearch
   HKCR\EZulaFSearchEng.eZulaSearch\CLSID
   HKCR\EZulaFSearchEng.eZulaSearch\CurVer
   HKCR\EZulaFSearchEng.eZulaSearch.1
   HKCR\EZulaFSearchEng.eZulaSearch.1\CLSID
   HKCR\EZulaFSearchEng.PopupDisplay
   HKCR\EZulaFSearchEng.PopupDisplay\CLSID
   HKCR\EZulaFSearchEng.PopupDisplay\CurVer
   HKCR\EZulaFSearchEng.PopupDisplay.1
   HKCR\EZulaFSearchEng.PopupDisplay.1\CLSID
   HKCR\EZulaFSearchEng.ResultHelper
   HKCR\EZulaFSearchEng.ResultHelper\CLSID
   HKCR\EZulaFSearchEng.ResultHelper\CurVer
   HKCR\EZulaFSearchEng.ResultHelper.1
   HKCR\EZulaFSearchEng.ResultHelper.1\CLSID
   HKCR\EZulaFSearchEng.SearchHelper
   HKCR\EZulaFSearchEng.SearchHelper\CLSID
   HKCR\EZulaFSearchEng.SearchHelper\CurVer
   HKCR\EZulaFSearchEng.SearchHelper.1
   HKCR\EZulaFSearchEng.SearchHelper.1\CLSID
   HKCR\EZulaMain.eZulaSearchPipe
   HKCR\EZulaMain.eZulaSearchPipe\CLSID
   HKCR\EZulaMain.eZulaSearchPipe\CurVer
   HKCR\EZulaMain.eZulaSearchPipe.1
   HKCR\EZulaMain.eZulaSearchPipe.1\CLSID
   HKCR\EZulaMain.TrayIConM
   HKCR\EZulaMain.TrayIConM\CLSID
   HKCR\EZulaMain.TrayIConM\CurVer
   HKCR\EZulaMain.TrayIConM.1
   HKCR\EZulaMain.TrayIConM.1\CLSID
   HKCR\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}
   HKCR\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}\InprocServer32
   HKCR\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}\InprocServer32#ThreadingModel
   HKCR\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}\ProgID
   HKCR\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}\Programmable
   HKCR\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib
   HKCR\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}\VersionIndependentProgID
   HKCR\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}
   HKCR\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}\InprocServer32
   HKCR\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}\InprocServer32#ThreadingModel
   HKCR\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}\ProgID
   HKCR\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}\Programmable
   HKCR\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib
   HKCR\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}\VersionIndependentProgID
   HKCR\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}
   HKCR\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}\InprocServer32
   HKCR\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}\InprocServer32#ThreadingModel
   HKCR\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}\ProgID
   HKCR\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}\Programmable
   HKCR\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}\TypeLib
   HKCR\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}\VersionIndependentProgID
   HKCR\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE}
   HKCR\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE}\InprocServer32
   HKCR\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE}\InprocServer32#ThreadingModel
   HKCR\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE}\ProgID
   HKCR\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE}\TypeLib
   HKCR\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE}\VersionIndependentProgID
   HKCR\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}
   HKCR\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}\InprocServer32
   HKCR\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}\InprocServer32#ThreadingModel
   HKCR\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}\ProgID
   HKCR\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}\Programmable
   HKCR\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}\TypeLib
   HKCR\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}\VersionIndependentProgID
   HKCR\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}
   HKCR\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}#AppID
   HKCR\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}\LocalServer32
   HKCR\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}\ProgID
   HKCR\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}\Programmable
   HKCR\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}\TypeLib
   HKCR\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}\VersionIndependentProgID
   HKCR\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}
   HKCR\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}\InprocServer32
   HKCR\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}\InprocServer32#ThreadingModel
   HKCR\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}\ProgID
   HKCR\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}\Programmable
   HKCR\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}\TypeLib
   HKCR\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}\VersionIndependentProgID
   HKCR\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}
   HKCR\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}\InprocServer32
   HKCR\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}\InprocServer32#ThreadingModel
   HKCR\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}\ProgID
   HKCR\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}\Programmable
   HKCR\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}\TypeLib
   HKCR\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}\VersionIndependentProgID
   HKCR\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}
   HKCR\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}#AppID
   HKCR\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}\LocalServer32
   HKCR\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}\ProgID
   HKCR\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}\Programmable
   HKCR\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}\TypeLib
   HKCR\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}\VersionIndependentProgID
   HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}
   HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}#AppID
   HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\LocalServer32
   HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\ProgID
   HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\Programmable
   HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\TypeLib
   HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\VersionIndependentProgID
   HKCR\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}
   HKCR\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}\InprocServer32
   HKCR\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}\InprocServer32#ThreadingModel
   HKCR\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}\ProgID
   HKCR\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}\Programmable
   HKCR\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}\TypeLib
   HKCR\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}\VersionIndependentProgID
   HKCR\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}
   HKCR\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}\InprocServer32
   HKCR\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}\InprocServer32#ThreadingModel
   HKCR\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}\ProgID
   HKCR\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}\Programmable
   HKCR\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}\TypeLib
   HKCR\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}\VersionIndependentProgID
   HKCR\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
   HKCR\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}\1.0
   HKCR\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}\1.0\0
   HKCR\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}\1.0\0\win32
   HKCR\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}\1.0\FLAGS
   HKCR\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}\1.0\HELPDIR
   HKCR\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE}
   HKCR\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE}\1.0
   HKCR\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE}\1.0\0
   HKCR\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE}\1.0\0\win32
   HKCR\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE}\1.0\FLAGS
   HKCR\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE}\1.0\HELPDIR
   HKCR\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE}
   HKCR\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE}\1.0
   HKCR\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE}\1.0\0
   HKCR\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE}\1.0\0\win32
   HKCR\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE}\1.0\FLAGS
   HKCR\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE}\1.0\HELPDIR
   HKCR\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376}
   HKCR\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376}\1.0
   HKCR\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376}\1.0\0
   HKCR\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376}\1.0\0\win32
   HKCR\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376}\1.0\FLAGS
   HKCR\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376}\1.0\HELPDIR
   HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}
   HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0
   HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0\0
   HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0\0\win32
   HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0\FLAGS
   HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0\HELPDIR
   HKCR\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE}
   HKCR\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE}\ProxyStubClsid
   HKCR\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE}\ProxyStubClsid32
   HKCR\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib
   HKCR\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib#Version
   HKCR\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE}
   HKCR\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE}\ProxyStubClsid
   HKCR\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE}\ProxyStubClsid32
   HKCR\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib
   HKCR\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib#Version
   HKCR\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136}
   HKCR\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136}\ProxyStubClsid
   HKCR\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136}\ProxyStubClsid32
   HKCR\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136}\TypeLib
   HKCR\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136}\TypeLib#Version
   HKCR\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376}
   HKCR\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376}\ProxyStubClsid
   HKCR\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376}\ProxyStubClsid32
   HKCR\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376}\TypeLib
   HKCR\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376}\TypeLib#Version
   HKCR\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE}
   HKCR\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE}\ProxyStubClsid
   HKCR\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE}\ProxyStubClsid32
   HKCR\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE}\TypeLib
   HKCR\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE}\TypeLib#Version
   HKCR\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE}
   HKCR\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE}\ProxyStubClsid
   HKCR\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE}\ProxyStubClsid32
   HKCR\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE}\TypeLib
   HKCR\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE}\TypeLib#Version
   HKCR\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB}
   HKCR\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB}\ProxyStubClsid
   HKCR\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB}\ProxyStubClsid32
   HKCR\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB}\TypeLib
   HKCR\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB}\TypeLib#Version
   HKCR\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE}
   HKCR\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE}\ProxyStubClsid
   HKCR\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE}\ProxyStubClsid32
   HKCR\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE}\TypeLib
   HKCR\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE}\TypeLib#Version
   HKCR\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376}
   HKCR\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376}\ProxyStubClsid
   HKCR\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376}\ProxyStubClsid32
   HKCR\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376}\TypeLib
   HKCR\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376}\TypeLib#Version
   HKCR\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376}
   HKCR\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376}\ProxyStubClsid
   HKCR\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376}\ProxyStubClsid32
   HKCR\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376}\TypeLib
   HKCR\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376}\TypeLib#Version
   HKCR\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE}
   HKCR\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE}\ProxyStubClsid
   HKCR\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE}\ProxyStubClsid32
   HKCR\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE}\TypeLib
   HKCR\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE}\TypeLib#Version
   HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}
   HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\ProxyStubClsid
   HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\ProxyStubClsid32
   HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\TypeLib
   HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\TypeLib#Version
   HKCR\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE}
   HKCR\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE}\ProxyStubClsid
   HKCR\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE}\ProxyStubClsid32
   HKCR\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE}\TypeLib
   HKCR\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE}\TypeLib#Version
   HKCR\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376}
   HKCR\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376}\ProxyStubClsid
   HKCR\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376}\ProxyStubClsid32
   HKCR\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376}\TypeLib
   HKCR\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376}\TypeLib#Version
   HKCR\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376}
   HKCR\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376}\ProxyStubClsid
   HKCR\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376}\ProxyStubClsid32
   HKCR\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376}\TypeLib
   HKCR\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376}\TypeLib#Version
   HKCR\AppId\eZulaBootExe.EXE
   HKCR\AppId\eZulaBootExe.EXE#AppID
   HKCR\AppId\eZulaMain.EXE
   HKCR\AppId\eZulaMain.EXE#AppID
   HKCR\AppId\{8A044397-5DA2-11D4-B185-0050DAB79376}
   HKCR\AppId\{C0335198-6755-11D4-8A73-0050DA2EE1BE}
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\eZula
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eZula
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eZula#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eZula#UninstallString
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}#OmJuslzbUz
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}#lhfnTowPJUg
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}#szAk
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}#bfiirpvhtxu
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}#jarlhtezgIjIg
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}#iFrelnhhqaqs
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}#uclWcjzgpyd
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}#azdolwPH
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\azdolwPH
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\bfiirpvhtxu
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\iFrelnhhqaqs
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\InprocServer32
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\InprocServer32#ThreadingModel
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\jarlhtezgIjIg
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\lhfnTowPJUg
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\OmJuslzbUz
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\szAk
   HKCR\CLSID\{0288B94B-0288-B94B-0288-B94B0288B94B}\uclWcjzgpyd
   HKCR\EZulaMain.eZulaPopSearchPipe
   HKCR\EZulaMain.eZulaPopSearchPipe\CLSID
   HKCR\EZulaMain.eZulaPopSearchPipe\CurVer
   HKCR\EZulaMain.eZulaPopSearchPipe.1
   HKCR\EZulaMain.eZulaPopSearchPipe.1\CLSID
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\Web Offer
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Offer
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Offer#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Offer#UninstallString
   HKCR\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}
   HKCR\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\InprocServer32
   HKCR\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\InprocServer32#ThreadingModel
   HKCR\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\ProgID
   HKCR\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\Programmable
   HKCR\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\TypeLib
   HKCR\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\VersionIndependentProgID
   HKCR\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}
   HKCR\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\InprocServer32
   HKCR\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\InprocServer32#ThreadingModel
   HKCR\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\ProgID
   HKCR\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\Programmable
   HKCR\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\TypeLib
   HKCR\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\VersionIndependentProgID
   HKCR\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8}
   HKCR\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8}#AppID
   HKCR\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8}\LocalServer32
   HKCR\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8}\ProgID
   HKCR\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8}\Programmable
   HKCR\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8}\VersionIndependentProgID
   HKCR\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}
   HKCR\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\InprocServer32
   HKCR\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\InprocServer32#ThreadingModel
   HKCR\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\ProgID
   HKCR\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\Programmable
   HKCR\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\TypeLib
   HKCR\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\VersionIndependentProgID
   HKCR\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}
   HKCR\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}\InprocServer32
   HKCR\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}\InprocServer32#ThreadingModel
   HKCR\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}\ProgID
   HKCR\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}\Programmable
   HKCR\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}\TypeLib
   HKCR\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}\VersionIndependentProgID
   HKCR\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
   HKCR\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\InprocServer32
   HKCR\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\InprocServer32#ThreadingModel
   HKCR\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\ProgID
   HKCR\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\Programmable
   HKCR\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\TypeLib
   HKCR\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\VersionIndependentProgID
   HKCR\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}
   HKCR\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}#AppID
   HKCR\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\LocalServer32
   HKCR\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\ProgID
   HKCR\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\Programmable
   HKCR\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\TypeLib
   HKCR\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\VersionIndependentProgID
   HKCR\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}
   HKCR\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\InprocServer32
   HKCR\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\InprocServer32#ThreadingModel
   HKCR\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\ProgID
   HKCR\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\Programmable
   HKCR\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\TypeLib
   HKCR\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\VersionIndependentProgID
   HKCR\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}
   HKCR\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\1.0
   HKCR\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\1.0\0
   HKCR\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\1.0\0\win32
   HKCR\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\1.0\FLAGS
   HKCR\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\1.0\HELPDIR
   HKCR\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA}
   HKCR\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA}\1.0
   HKCR\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA}\1.0\0
   HKCR\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA}\1.0\0\win32
   HKCR\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA}\1.0\FLAGS
   HKCR\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA}\1.0\HELPDIR
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}\Implemented Categories
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}\InprocServer32
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}\InprocServer32#ThreadingModel
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}\Instance
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}\Instance#CLSID
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}\Instance\InitPropertyBag
   HKCR\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}\Instance\InitPropertyBag#Url
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}\Implemented Categories
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}\Implemented Categories\{00021494-0000-0000-C000-000000000046}
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}\InprocServer32
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}\InprocServer32#ThreadingModel
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}\Instance
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}\Instance#CLSID
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}\Instance\InitPropertyBag
   HKCR\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}\Instance\InitPropertyBag#Url
   C:\Programmer\Ezula\backup.tmp
   C:\Programmer\Ezula\basis.dst
   C:\Programmer\Ezula\basis.kwd
   C:\Programmer\Ezula\basis.pu
   C:\Programmer\Ezula\basis.rst
   C:\Programmer\Ezula\CHCON.dll
   C:\Programmer\Ezula\eabh.dll
   C:\Programmer\Ezula\genun.ez
   C:\Programmer\Ezula\Images\arrow1.gif
   C:\Programmer\Ezula\Images\arrow2.gif
   C:\Programmer\Ezula\Images\button_small.gif
   C:\Programmer\Ezula\Images\icon.gif
   C:\Programmer\Ezula\Images\Layer_Bottom.gif
   C:\Programmer\Ezula\Images\Layer_Center.gif
   C:\Programmer\Ezula\Images\Layer_Top.gif
   C:\Programmer\Ezula\Images\new.gif
   C:\Programmer\Ezula\Images\PopUp_Follow_divider.gif
   C:\Programmer\Ezula\Images\PopUp_Follow_Left.gif
   C:\Programmer\Ezula\Images\PopUp_Follow_Off.gif
   C:\Programmer\Ezula\Images\PopUp_Follow_On.gif
   C:\Programmer\Ezula\Images\PopUp_Follow_Right.gif
   C:\Programmer\Ezula\Images\PopUp_Top.gif
   C:\Programmer\Ezula\Images\PopUp_Top_Bottom.gif
   C:\Programmer\Ezula\Images\Side_B.gif
   C:\Programmer\Ezula\Images\Side_L.gif
   C:\Programmer\Ezula\Images\Side_R.gif
   C:\Programmer\Ezula\Images\Side_Top.gif
   C:\Programmer\Ezula\Images\spacer.gif
   C:\Programmer\Ezula\Images
   C:\Programmer\Ezula\INSTALL.LOG
   C:\Programmer\Ezula\legend.lgn
   C:\Programmer\Ezula\mmod.exe
   C:\Programmer\Ezula\param.ez
   C:\Programmer\Ezula\rwds.rst
   C:\Programmer\Ezula\search.src
   C:\Programmer\Ezula\seng.dll
   C:\Programmer\Ezula\UNWISE.EXE
   C:\Programmer\Ezula\upgrade.vrn
   C:\Programmer\Ezula\version.vrn
   C:\Programmer\Ezula\wndbannn.src
   C:\Programmer\Ezula
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\TopText iLookup\Feedback.url
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\TopText iLookup\Help.url
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\TopText iLookup\My Keywords.lnk
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\TopText iLookup\My Preferences.lnk
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\TopText iLookup\ReadMe.url
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\TopText iLookup\TopText Button Show - Hide.lnk
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\TopText iLookup
   C:\Programmer\Web Offer\apev.exe
   C:\Programmer\Web Offer\basisp.dst
   C:\Programmer\Web Offer\basisp.kwd
   C:\Programmer\Web Offer\basisp.pu
   C:\Programmer\Web Offer\basisp.rst
   C:\Programmer\Web Offer\CHPON.dll
   C:\Programmer\Web Offer\eapbh.dll
   C:\Programmer\Web Offer\gendis.ez
   C:\Programmer\Web Offer\INSTALL.LOG
   C:\Programmer\Web Offer\paramp.ez
   C:\Programmer\Web Offer\rwdsp.rst
   C:\Programmer\Web Offer\sepng.dll
   C:\Programmer\Web Offer\UNWISE.EXE
   C:\Programmer\Web Offer\upgradep.vrn
   C:\Programmer\Web Offer\versionp.vrn
   C:\Programmer\Web Offer\wndbannnp.src
   C:\Programmer\Web Offer\wo.exe
   C:\Programmer\Web Offer
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Run#eZmmod [ C:\PROGRA~1\ezula\mmod.exe ]
   C:\WINDOWS\system32\ezPopStub.exe
   C:\WINDOWS\woinstall.exe

BearShare File Sharing Client
   [BearShare] C:\Programmer\BearShare\BearShare.exe
   C:\Programmer\BearShare\BearShare.exe
   C:\Documents and Settings\All Users\Menuen Start\Programmer\BearShare.lnk
   C:\Documents and Settings\Lasse Lauritsen\Skrivebord\BearShare.lnk
   C:\WINDOWS\Prefetch\BEARSHARE.EXE-1F7FB804.pf

Trojan.Poka
   [System service79] C:\WINDOWS\\\etb\\pokapoka79.exe
   C:\WINDOWS\\\etb\\pokapoka79.exe

Malware.SpywareQuake
   [SpyQuake2.com] C:\Programmer\SpyQuake2.com\Spy-Quake2.exe
   C:\Programmer\SpyQuake2.com\Spy-Quake2.exe
   HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\Spy-Quake2.exe
   C:\Programmer\SpyQuake2.com\blacklist.txt
   C:\Programmer\SpyQuake2.com\ignored.lst
   C:\Programmer\SpyQuake2.com\Lang\English.ini
   C:\Programmer\SpyQuake2.com\Lang
   C:\Programmer\SpyQuake2.com\Logs
   C:\Programmer\SpyQuake2.com\msvcp71.dll
   C:\Programmer\SpyQuake2.com\msvcr71.dll
   C:\Programmer\SpyQuake2.com\Quarantine
   C:\Programmer\SpyQuake2.com\ref.dat
   C:\Programmer\SpyQuake2.com\SpyQuake2.com.url
   C:\Programmer\SpyQuake2.com\sq.ini
   C:\Programmer\SpyQuake2.com\uninst.exe
   C:\Programmer\SpyQuake2.com
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\SpyQuake2.com\SpyQuake2.com 2.3 Website.lnk
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\SpyQuake2.com\SpyQuake2.com 2.3.lnk
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\SpyQuake2.com\Uninstall SpyQuake2.com 2.3.lnk
   C:\Documents and Settings\Lasse Lauritsen\Menuen Start\Programmer\SpyQuake2.com
   HKLM\Software\Microsoft\Windows\CurrentVersion\Run#SpyQuake2.com [ C:\Programmer\SpyQuake2.com\Spy-Quake2.exe /h ]
   HKLM\Software\SpyQuake2.com
   HKLM\Software\SpyQuake2.com#refid
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyQuake2.com
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyQuake2.com#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyQuake2.com#UninstallString
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyQuake2.com#DisplayIcon
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyQuake2.com#DisplayVersion
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyQuake2.com#NSIS:StartMenuDir
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyQuake2.com#URLInfoAbout
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyQuake2.com#Publisher
   HKCR\TypeLib\{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}
   HKCR\TypeLib\{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}\1.0
   HKCR\TypeLib\{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}\1.0\0
   HKCR\TypeLib\{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}\1.0\0\win32
   HKCR\TypeLib\{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}\1.0\FLAGS
   HKCR\TypeLib\{5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9}\1.0\HELPDIR
   HKCR\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}
   HKCR\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}\ProxyStubClsid
   HKCR\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}\ProxyStubClsid32
   HKCR\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}\TypeLib
   HKCR\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}\TypeLib#Version
   HKCR\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}
   HKCR\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}\ProxyStubClsid
   HKCR\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}\ProxyStubClsid32
   HKCR\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}\TypeLib
   HKCR\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}\TypeLib#Version
   HKCR\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}
   HKCR\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}\ProxyStubClsid
   HKCR\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}\ProxyStubClsid32
   HKCR\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}\TypeLib
   HKCR\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}\TypeLib#Version
   HKCR\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}
   HKCR\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}\ProxyStubClsid
   HKCR\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}\ProxyStubClsid32
   HKCR\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}\TypeLib
   HKCR\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}\TypeLib#Version
   HKCR\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}
   HKCR\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}\ProxyStubClsid
   HKCR\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}\ProxyStubClsid32
   HKCR\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}\TypeLib
   HKCR\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}\TypeLib#Version
   HKCR\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}
   HKCR\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}\ProxyStubClsid
   HKCR\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}\ProxyStubClsid32
   HKCR\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}\TypeLib
   HKCR\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}\TypeLib#Version
   HKCR\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}
   HKCR\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}\ProxyStubClsid
   HKCR\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}\ProxyStubClsid32
   HKCR\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}\TypeLib
   HKCR\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}\TypeLib#Version
   HKCR\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}
   HKCR\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}\ProxyStubClsid
   HKCR\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}\ProxyStubClsid32
   HKCR\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}\TypeLib
   HKCR\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}\TypeLib#Version
   HKCR\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}
   HKCR\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}\ProxyStubClsid
   HKCR\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}\ProxyStubClsid32
   HKCR\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}\TypeLib
   HKCR\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}\TypeLib#Version
   HKCR\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}
   HKCR\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}\ProxyStubClsid
   HKCR\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}\ProxyStubClsid32
   HKCR\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}\TypeLib
   HKCR\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}\TypeLib#Version
   HKCR\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}
   HKCR\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}\ProxyStubClsid
   HKCR\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}\ProxyStubClsid32
   HKCR\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}\TypeLib
   HKCR\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}\TypeLib#Version
   HKCR\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}
   HKCR\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}\ProxyStubClsid
   HKCR\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}\ProxyStubClsid32
   HKCR\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}\TypeLib
   HKCR\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}\TypeLib#Version
   HKCR\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}
   HKCR\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}\ProxyStubClsid
   HKCR\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}\ProxyStubClsid32
   HKCR\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}\TypeLib
   HKCR\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}\TypeLib#Version
   HKCR\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}
   HKCR\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}\ProxyStubClsid
   HKCR\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}\ProxyStubClsid32
   HKCR\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}\TypeLib
   HKCR\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}\TypeLib#Version
   HKCR\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}
   HKCR\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}\ProxyStubClsid
   HKCR\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}\ProxyStubClsid32
   HKCR\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}\TypeLib
   HKCR\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}\TypeLib#Version
   HKCR\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}
   HKCR\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}\ProxyStubClsid
   HKCR\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}\ProxyStubClsid32
   HKCR\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}\TypeLib
   HKCR\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}\TypeLib#Version
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\edsdafgiAoztn
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\InProcServer32
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\InProcServer32#ThreadingModel
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\mgpPxSfNypP
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\MNtspdnylf
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\naQQ
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\paPrfsaucnb
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\vXvrEn
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\YvdDw
   HKCR\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}\ztyoHLzweq
   C:\Documents and Settings\Lasse Lauritsen\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyQuake2.com 2.3.lnk

Adware.IPWins
   [IpWins] C:\Programmer\ipwins\ipwins.exe
   C:\Programmer\ipwins\ipwins.exe
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\IpWins
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IpWins
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IpWins#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IpWins#UninstallString
   C:\Programmer\ipwins\pop80.tmp
   C:\Programmer\ipwins\Services.dll
   C:\Programmer\ipwins\Uninst.exe
   C:\Programmer\ipwins

Adware.eZula/TopText iLookup
   [eZWO] C:\PROGRA~1\Web Offer\wo.exe
   C:\PROGRA~1\Web Offer\wo.exe

Trojan.CUpdater
   [cprocsvc] C:\WINDOWS\system32\crunner\cproc.exe
   C:\WINDOWS\system32\crunner\cproc.exe
   C:\WINDOWS\system32\crunner\cproc.exe.config
   C:\WINDOWS\system32\crunner\cupdater.exe
   C:\WINDOWS\system32\crunner\cupdater.exe.config
   C:\WINDOWS\system32\crunner\ICSharpCode.SharpZipLib.dll
   C:\WINDOWS\system32\crunner\Version.txt
   C:\WINDOWS\system32\crunner

Adware.MyWay
   HKLM\Software\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
   HKCR\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
   HKCR\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
   HKCR\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}\InprocServer32
   C:\Programmer\MyGlobalSearch\bar\1.bin\MGSBAR.DLL

Malware.Safety Bar
   HKLM\Software\Classes\CLSID\{052b12f7-86fa-4921-8482-26c42316b522}
   HKCR\CLSID\{052b12f7-86fa-4921-8482-26c42316b522}
   HKCR\CLSID\{052b12f7-86fa-4921-8482-26c42316b522}
   HKCR\CLSID\{052b12f7-86fa-4921-8482-26c42316b522}\Implemented Categories
   HKCR\CLSID\{052b12f7-86fa-4921-8482-26c42316b522}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
   HKCR\CLSID\{052b12f7-86fa-4921-8482-26c42316b522}\InprocServer32
   HKCR\CLSID\{052b12f7-86fa-4921-8482-26c42316b522}\InprocServer32#ThreadingModel
   C:\Programmer\Safety Bar\SafetyBar.dll
   HKLM\Software\Microsoft\Internet Explorer\Toolbar#{052b12f7-86fa-4921-8482-26c42316b522}
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafetyBar
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafetyBar#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafetyBar#UninstallString
   C:\Programmer\Safety Bar\Uninstall.bat
   C:\Programmer\Safety Bar

Unclassified.Unknown Origin
   HKLM\Software\Classes\CLSID\{1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}
   HKCR\CLSID\{1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}
   HKCR\CLSID\{1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}\InprocServer32
   HKCR\CLSID\{1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}\InprocServer32#ThreadingModel
   C:\WINDOWS\system32\wtamdtyb.dll
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}
   HKCR\CLSID\{1DAEFCB9-06C8-47C6-8F20-3FB54B244DAA}

Adware.MyGlobalSearchBar
   HKLM\Software\Classes\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\InprocServer32
   HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\InprocServer32#ThreadingModel
   HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\Programmable
   HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\TypeLib
   HKLM\Software\Classes\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\InprocServer32
   HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\InprocServer32#ThreadingModel
   HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\Programmable
   HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\TypeLib
   HKLM\Software\Classes\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\Control
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\InprocServer32
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\InprocServer32#ThreadingModel
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\MiscStatus
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\MiscStatus\1
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\ProgID
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\Programmable
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\TypeLib
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\Version
   HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\VersionIndependentProgID
   HKLM\Software\Classes\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}
   HKCR\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}
   HKCR\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}
   HKCR\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}\InprocServer32
   HKCR\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}\InprocServer32#ThreadingModel
   HKCR\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}\ProgID
   HKCR\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}\Programmable
   HKCR\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}\TypeLib
   HKCR\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}\VersionIndependentProgID
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37B85A21-692B-4205-9CAD-2626E4993404}
   HKLM\Software\Microsoft\Internet Explorer\Toolbar#{37B85A29-692B-4205-9CAD-2626E4993404}
   HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}
   HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0
   HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0\0
   HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0\0\win32
   HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0\FLAGS
   HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0\HELPDIR
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{37B85A29-692B-4205-9CAD-2626E4993404}

Adware.EZula/TopText
   HKLM\Software\Classes\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB}
   HKCR\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB}
   HKCR\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB}
   HKCR\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB}\InprocServer32
   HKCR\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB}\InprocServer32#ThreadingModel
   HKCR\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB}\ProgID
   HKCR\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB}\VersionIndependentProgID
   C:\PROGRA~1\eZula\eabh.dll

Adware.VSToolbar
   HKLM\Software\Classes\CLSID\{821F87FF-8245-4972-9E28-732E92EC2F51}
   HKCR\CLSID\{821F87FF-8245-4972-9E28-732E92EC2F51}
   HKCR\CLSID\{821F87FF-8245-4972-9E28-732E92EC2F51}
   HKCR\CLSID\{821F87FF-8245-4972-9E28-732E92EC2F51}\InProcServer32
   HKCR\CLSID\{821F87FF-8245-4972-9E28-732E92EC2F51}\InProcServer32#ThreadingModel
   C:\Programmer\VSToolbar\VSToolBar.dll
   HKLM\Software\Microsoft\Internet Explorer\Toolbar#{821F87FF-8245-4972-9E28-732E92EC2F51}
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{821F87FF-8245-4972-9E28-732E92EC2F51}
   HKU\S-1-5-21-1715567821-1336601894-1417001333-1004\Software\Search Toolbar Corp
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{821F87FF-8245-4972-9E28-732E92EC2F51}
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{821F87FF-8245-4972-9E28-732E92EC2F51}#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{821F87FF-8245-4972-9E28-732E92EC2F51}#UninstallString
   C:\Programmer\VSToolbar
   C:\Documents and Settings\Lasse Lauritsen\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
   C:\Documents and Settings\Lasse Lauritsen\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
   C:\Documents and Settings\Lasse Lauritsen\Application Data\SearchToolbarCorp\Toolbar Vision
   C:\Documents and Settings\Lasse Lauritsen\Application Data\SearchToolbarCorp

Browser Hijacker.BestSafetyGuide
   HKLM\Software\Classes\CLSID\{a43385f0-7113-496d-96d7-b9b550e3fcca}
   HKCR\CLSID\{a43385f0-7113-496d-96d7-b9b550e3fcca}
   HKCR\CLSID\{a43385f0-7113-496d-96d7-b9b550e3fcca}
   HKCR\CLSID\{a43385f0-7113-496d-96d7-b9b550e3fcca}\InprocServer32
   HKCR\CLSID\{a43385f0-7113-496d-96d7-b9b550e3fcca}\InprocServer32#ThreadingModel
   C:\WINDOWS\system32\ixt0.dll
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a43385f0-7113-496d-96d7-b9b550e3fcca}

Adware.ToolBar888
   HKLM\Software\Classes\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}
   HKCR\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}
   HKCR\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}
   HKCR\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\InprocServer32
   HKCR\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\InprocServer32#ThreadingModel
   HKCR\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\ProgID
   HKCR\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\Programmable
   HKCR\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\TypeLib
   HKCR\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\VersionIndependentProgID
   C:\Programmer\Fælles filer\{3880C324-044C-1030-0720-04021704002d}\MyToolBar.dll
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C004DEC2-2623-438e-9CA2-C9043AB28508}
   HKLM\Software\Microsoft\Internet Explorer\Toolbar#{C004DEC2-2623-438e-9CA2-C9043AB28508}
   HKCR\MyToolBar.MyToolBarObj.1
   HKCR\MyToolBar.MyToolBarObj.1\CLSID
   HKCR\MyToolBar.MyToolBarObj
   HKCR\MyToolBar.MyToolBarObj\CLSID
   HKCR\MyToolBar.MyToolBarObj\CurVer
   HKCR\TypeLib\{ED0FB633-C311-4bcd-824A-4D345386BE64}
   HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}
   HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0
   HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0
   HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32
   HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS
   HKCR\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR
   HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}
   HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid
   HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32
   HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib
   HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ToolBar888
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ToolBar888#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ToolBar888#UninstallString
   HKLM\Software\Classes\MyToolBar.MyToolBarObj
   HKLM\Software\Classes\MyToolBar.MyToolBarObj\CLSID
   HKLM\Software\Classes\MyToolBar.MyToolBarObj\CurVer
   HKLM\Software\Classes\MyToolBar.MyToolBarObj.1
   HKLM\Software\Classes\MyToolBar.MyToolBarObj.1\CLSID

Adware.Tracking Cookie
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.isohunt[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@kwpop.gamecracks[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@den[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@questionmarket[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@weborama[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@tacoda[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@advertising[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@media.adrevolver[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@doubleclick[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@82763522[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad1.emediate[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.epilot[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@bannere.fyens[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@tradedoubler[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@hitbox[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@realmedia[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@mb[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@warlog[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@perf.overture[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@maxserving[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@spylog[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adopt.hbmediapro[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.mystats[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@globalstat[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@bs.serving-sys[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@atwola[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@emediate[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.mininova[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@fastclick[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@dist.belnk[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@atdmt[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@revsci[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@data2.perf.overture[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cgi-bin[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@xiti[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.crack[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@certified-safe-downloads[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@keywordmax[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@casalemedia[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@kwpop.crack[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@tribalfusion[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@image.masterstats[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@clicktorrent[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@server.iad.liveperson[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@revenue[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cams[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cs.sexcounter[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@partypoker[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@serving-sys[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adopt.specificclick[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.pointroll[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adtech[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cgi-bin[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@gamecracks[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@emarketmakers[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@z1.adserver[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@statcounter[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@data3.perf.overture[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@advertstream[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@888[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adopt.euroclick[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@i[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@yieldmanager[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.yieldmanager[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@edge.ru4[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adserver.adremedy[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@usenext[3].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@sonycorporate.122.2o7[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@click.cashengines[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@bluestreak[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@e2.emediate[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adrevolver[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@track.adform[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.estart[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@reduxads.valuead[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.arto[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@partygaming.122.2o7[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@indextools[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adfair[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@indexstats[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@crack[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ehg-superwarehouse.hitbox[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@yadro[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.addynamix[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@stats1.reliablestats[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@pr.valueclick[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.beamfile[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.gamecracks[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@web-stat[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@zedo[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@burstnet[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@sel.as-us.falkag[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.realcastmedia[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@stat.mthojgaard[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@belnk[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@2o7[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@mediaplex[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@server2.bkvtrack[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adv.noblepoker[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@xml.bravenetmedianetwork[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@banner.32vegas[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cgi-bin[3].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@clicks[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@http.edge.vru4[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.cdfreaks[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@list[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.gamershell[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.itrack24[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adserver.mybittorrent[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.sex-sex-sex[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@crackserver[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cgi-bin[6].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@etc804-wavp6[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@usenext[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.eyemedia[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@track.effiliation[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@estat[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@winfixer[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.drivecleaner[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@clicksor[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@as1.falkag[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cgi-bin[8].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adserver.banneradministration[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@pacificpoker[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adrevolver[3].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@hotlog[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cgi-bin[7].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adv.surinter[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@valuead[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@campaign.indieclick[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@tracking.publicidees[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cassava[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@stat.onestat[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@optimost[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@web-stats[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad1.clickhype[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adrevolver[4].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@247realmedia[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@metacafe.122.2o7[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@valueclick[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@banner.monacogoldcasino[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ilead.itrack[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@webstat[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adserver[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@banner.cdpoker[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@dcs4n0o1s2l207yupjlkoumuc_6c6q[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ehg-sonyesolutions.hitbox[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@valueclick[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@1065674632[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@1069444132[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@stat.postdanmark[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.0stats[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@intaclick[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@c5.zedo[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@overture[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ehg-nokiafin.hitbox[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.text-ent.tbn[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@85337527[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@etype.adbureau[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ebookers[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@fcstats.bcentral[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@tripod[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@stats.drivecleaner[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@tracker.affistats[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@dk.winantivirus[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@go.winantivirus[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@statse.webtrendslive[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@qnsr[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad1.hardware[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@48940962[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@toplist[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cpvfeed[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@server.cpmstar[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.webstat[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@countus.get.kadserver[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.heias[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.e240.tbn[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.etracker[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@drivecleaner[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@rambler[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ehg-ubisoft.hitbox[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@msnportal.112.2o7[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@admarketplace[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@go.drivecleaner[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads2.jubii[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@mb[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@m1.webstats4u[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.smartadserver[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adbrite[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@as-eu.falkag[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@partner2profit[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@dxcdirect[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ex=1_[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.winfixer[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adservervv.geizkragen[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ehg-alt64.hitbox[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ads.as4x.tmcs[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.amaena[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adsrevenue[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.winantivirus[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@malwarewipe[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@winantivirus[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.cibleclick[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@adultfriendfinder[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.adition[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@flixbanner.bearshare[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.zanox[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@ad.ent.tbn[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@www.cibleclick[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Cookies\lasse lauritsen@cracks[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temp\Cookies\lasse lauritsen@advertising[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temp\Cookies\lasse lauritsen@atdmt[2].txt
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temp\Cookies\lasse lauritsen@mediaplex[1].txt
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temp\Cookies\lasse lauritsen@track.adform[1].txt

Adware.WhenU
   HKCR\WUSN.1
   HKCR\WUSN.1#WUSN_Id
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temp\VVSNInst.exe

Trojan.Unknown Origin
   HKLM\SOFTWARE\Microsoft\MSSMGR
   HKLM\SOFTWARE\Microsoft\MSSMGR#Data
   HKLM\SOFTWARE\Microsoft\MSSMGR#LSTV
   HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
   HKLM\SOFTWARE\Microsoft\MSSMGR#MSLIST
   HKLM\SOFTWARE\Microsoft\MSSMGR#PID
   HKLM\SOFTWARE\Microsoft\MSSMGR#Rid
   HKLM\SOFTWARE\Microsoft\MSSMGR#LID
   HKLM\SOFTWARE\Microsoft\MSSMGR#SCLIST
   HKLM\SOFTWARE\Microsoft\MSSMGR#SSLIST
   HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
   HKLM\SOFTWARE\Microsoft\MSSMGR#BPTV
   HKLM\SOFTWARE\Microsoft\MSSMGR#PSTV
   HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV
   C:\WINDOWS\system32\ot.ico
   C:\WINDOWS\system32\ts.ico

Trojan.Security Toolbar
   C:\Documents and Settings\Lasse Lauritsen\Foretrukne\Antivirus Test Online.url

Adware.ClickSpring/Yazzle
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#DisplayName
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#UninstallString
   C:\Programmer\Fælles filer\Yazzle1122OinAdmin.exe
   C:\Programmer\Fælles filer\Yazzle1122OinUninstaller.exe
   C:\Programmer\Fælles filer\Yazzle1162OinAdmin.exe
   C:\Programmer\Fælles filer\Yazzle1162OinUninstaller.exe

Trojan.AtmClk
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#kernel32.dll [ C:\WINDOWS\system32\isnotify.exe ]

Malware.Notifier
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#ishost.exe [ ishost.exe ]
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#issearch.exe [ issearch.exe ]
   C:\WINDOWS\system32\ishost.exe
   C:\WINDOWS\system32\isnotify.exe
   C:\WINDOWS\system32\issearch.exe
   C:\WINDOWS\Prefetch\ISHOST.EXE-38143B6A.pf

Trojan.Incestuously
   HKCR\CLSID\{03413bf7-e34c-445b-bfc0-a2b127255871}
   HKCR\CLSID\{03413bf7-e34c-445b-bfc0-a2b127255871}\InProcServer32
   HKCR\CLSID\{03413bf7-e34c-445b-bfc0-a2b127255871}\InProcServer32#ThreadingModel
   HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#incestuously [ {03413bf7-e34c-445b-bfc0-a2b127255871} ]
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#incestuously [ {03413bf7-e34c-445b-bfc0-a2b127255871} ]

Adware.ClickSpring
   C:\Documents and Settings\Lasse Lauritsen\Dokumenter\WNSXS~1\alg.exe
   C:\WINDOWS\system32\eptuzgvt.dll

Trojan.Freeprod
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temp\winB7.tmp.exe
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temporary Internet Files\Content.IE5\6HSB6T25\wlzip32[1].exe

Trojan.Downloader-LargeInterest
   C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temporary Internet Files\Content.IE5\U51QFM90\anti4[1].exe
   C:\WINDOWS\system32\pmnopnn.dll

Trojan.Flx/Conhook
   C:\WINDOWS\system32\components\flx7.dll

Worm.Rbot Variant
   C:\WINDOWS\system32\ismini.exe

Trojan.Downloader-VSToolbar
   C:\WINDOWS\system32\nadftdpd.exe

Trojan.SpyFalcon
   C:\WINDOWS\system32\urroxtl.dll

Adware.ClickSpring/PuritySCAN
   C:\WINDOWS\system32\wnsintit.exe


Kommentar
Fra : Broderpivert


Dato : 16-10-06 11:54

Logfile of HijackThis v1.99.1
Scan saved at 11:42:26, on 16-10-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Lasse Lauritsen\Lokale indstillinger\Temporary Internet Files\Content.IE5\WD83SNCF\hjtspecial[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Programmer\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {6043C9C5-0A2B-7DD1-2FC3-0595C0838A9A} - C:\WINDOWS\system32\eptuzgvt.dll (file missing)
O2 - BHO: (no name) - {9EFDC867-EE8F-4D61-BBF6-1D96B38B6362} - C:\WINDOWS\system32\sstqr.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Programmer\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [shell32] C:\WINDOWS\system32\wuauclt10.exe
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P and now I post my Hijack log whining] C:\WINDOWS\system32\Fifa Soccer 2006 crack.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BearShare] "C:\Programmer\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [DirectXs] C:\WINDOWS\system32\directxs.exe
O4 - HKLM\..\Run: [eSnips] "C:\Programmer\eSnips\ClientGW.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Programmer\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmer\Fælles filer\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BandwidthMonitor.exe -CFG0] C:\Programmer\Idyle Software\Bandwidth Monitor\BandwidthMonitor.exe -CFG0
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Programmer\BlazeVideo\BlazeDVD4 Professional\MediaDetector.exe"
O4 - HKCU\..\Run: [PcSync] C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Pese] "C:\DOCUME~1\LASSEL~1\APPLIC~1\PPATCH~1\ati2evxx.exe" -vt yazb
O4 - HKCU\..\Run: [Plwcyfoi] C:\Documents and Settings\Lasse Lauritsen\Dokumenter\W?nSxS\alg.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programmer\eMule\emule.exe -AutoStart
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Programmer\DeluxeCommunications\Dxc.exe
O4 - Startup: BitTorrent.lnk = C:\Programmer\BitTorrent\bittorrent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Download with BitKinex - C:\Programmer\BitKinex\ieext_cp.htm
O8 - Extra context menu item: &Register in BitKinex - C:\Programmer\BitKinex\ieext_reg.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/download/2006/cabs/ErrorSafeFreeInstall_dk.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: winmfu32 - winmfu32.dll (file missing)
O23 - Service: BitKinex File Transfer Service (BitKinex) - Unknown owner - C:\Programmer\BitKinex\bitkinexsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
O23 - Service: Bandwidth Monitor Service (srvBWMNT) - Idyle Software - C:\PROGRA~1\IDYLES~1\BANDWI~1\BWMNT.exe



Kommentar
Fra : stl_s


Dato : 16-10-06 15:26

Der er godt med snavs på din maskine, så jeg forstår godt dine problemer. Alt sammen er "sidegevinster" fra downloads med Bearshare og Emule, så undlad venligst at bruge de programmer imens vi renser maskinen. Allerbedst, afinstaller programmerne imens.

Lad os prøve at få skidtet væk. Det kommer til at tage noget tid.


Hent denne uninstaller http://www.outerinfo.com/OiUninstaller.exe

Kør den, og genstart maskinen.


----------------------------------------------------------------


1. Hent og pak SmitfraudFix.zip ud til dit Skrivebord.

http://siri.urz.free.fr/Fix/SmitfraudFix.zip

Programmet pakker sig ud i en mappe, der hedder SmitfraudFix.


2. Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:

http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1


3. Åbn mappen SmitfraudFix som du fik på Skrivebordet, og dobbeltklik på SmitfraudFix.cmd og tast 2 - svar ja til at rense (y=yes). Lad programmet gennemføre en rensning. Fixet genstarter muligvis computeren.


SmitfraudFix laver også en lille tekstfil (log). Kopier den her ind, sammen med din næste HijackThis log.


----------------------------------------------------------------

Hent Combofix, og gem den på dit skrivebord:
http://download.bleepingcomputer.com/sUBs/combofix.exe

Kør så combofix.exe, og følg anvisningerne.

Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt som kan findes her-C:\combofix.txt


-----------------------------------------------------------------


Hent denne fil, og pak den ud til en mappe på skrivebordet:
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip

Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

Gå så ind i mappen SDFix, som du hentede tidligere. Dobbeltklik på filen RunThis.bat, for at starte værktøjet. Tryk "y" for at bekræfte, at du kører værktøjet på egen risiko. Så vil værktøjet gå i gang med at fjerne trojanservicen, og lave et par reparationer af registreringsdatabasen. På et tidspunkt vil det bede dig om at trykke en taste for at genstarte computeren. Det skal du gøre, hvorefter computeren vil genstarte efter 15 sekunder.

Genstarten vil tage lidt længere end sædvanligt, idet værktøjet skal have tid til at udføre sit arbejde. Når skrivebordet dukker op, vil værktøjet skrive "Finished". Tryk herefter en taste for at indlæse dine skrivebordsikoner igen.

Åben så SDFix-mappen, find filen Report.txt, og kopier indholdet af denne fil herind.


------------------------------------------------------------------


Hent og installer RemoveIT PRO her http://www.incodesolutions.com/downloads/removeit_pro.exe

Kør en scanning med den i fejlsikret tilstand, og lad programmet fixe hvad det finder. Bagefter klik på "Full report log". Vent på at loggen åbner i notesblok, og kopier den her ind i tråden.


-------------------------------------------------------------------


Kom med diverse logs, og en frisk HijackThis log.

Kommentar
Fra : Broderpivert


Dato : 16-10-06 15:59

SmitFraudFix v2.110

Scan done at 15:46:38,64, 16-10-2006
Run from C:\Documents and Settings\Lasse Lauritsen\Skrivebord\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End



Kommentar
Fra : Broderpivert


Dato : 16-10-06 16:12


SDFix: Version 1.28
-------------------

Scan run on:
16-10-2006

Time:
15:52


Microsoft Windows XP [version 5.1.2600]

Running from: C:\Documents and Settings\Lasse Lauritsen\Dokumenter\SDFix

Stage One...

Checking Services...

Name:
-----


Path:
----





Repairing Registry...

Restoring Default Hosts File...

Stage One Complete

Rebooting!

Stage Two...

Registry Cleaning Finished...

Checking For Malware Files:
--------------------------


Backing Up and Removing any Files Found...

Final Check:

Remaining Services:
------------------

Remaining Files:
--------------



*Any removed Files are saved in the SDFix\backups Folder*

*FINISHED*


Du har følgende muligheder
Dette spørgsmål er blevet annulleret, det er derfor ikke muligt for at tilføje flere kommentarer.
Søg
Reklame
Statistik
Spørgsmål : 177428
Tips : 31962
Nyheder : 719565
Indlæg : 6407944
Brugere : 218877

Månedens bedste
Årets bedste
Sidste års bedste