Avatar billede rangerbs Nybegynder
24. november 2005 - 16:20 Der er 3 kommentarer og
1 løsning

Check denne log. Hjælp

Hej eksperter...

Min anden computer kan lige pludselig ikke gå på nettet.. Eller, Jeg kan godt se hvem der er online på msn osv.. kan også logge på steam, men kan ikke surfe på nettet og jeg kan heller ikke skrive til nogen på msn, selvom jeg kan se at de er på..

tror måske det kan være fordi der er så meget snavs på min computer.. Jeg bruger ikke det der poker noget og heller ikke msn 3 plus..

Håber i gider at checke den hurtigts muligt..
hilsen Jeppe


Logfile of HijackThis v1.99.1
Scan saved at 4:10:23 PM, on 24/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\Programmer\Fælles filer\EPSON\EBAPI\eEBSVC.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\VeriSign\NAVI\naviagent.exe
C:\Norman\bin\ZANDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Norman\bin\NJEEVES.EXE
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\VeriSign\NAVI\NAVICL~1.EXE
C:\WINDOWS\Explorer.EXE
C:\Norman\bin\ZLH.EXE
C:\Programmer\Norman Access Control Privacy\nrmenctb.exe
C:\Programmer\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Media Gateway\MediaGateway.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\blerp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\TopText\mmod.exe
C:\PROGRA~1\TopText\wo.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\NORMAN\nvc\BIN\NVCSCHED.EXE
C:\Norman\Nvc\BIN\NIP.EXE
c:\blerp.exe
C:\Documents and Settings\Jeppe og Jannik\Skrivebord\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.dk/
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Programmer\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Norman ACP] "C:\Programmer\Norman Access Control Privacy\nrmenctb.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmer\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [REGRUN] C:\blerp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmer\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\TopText\mmod.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\TopText\wo.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(3).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programmer\expektMPP\MPPoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: i-Nav Hjælp - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: i-Nav Hjælp - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O9 - Extra 'Tools' menuitem: i-Nav Indstillinger - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programmer\nordicbetMPP\MPPoker.exe
O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Menuen Start\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Menuen Start\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_adult/180solutions/ie/bridge-c10.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {E6A3C1E2-F792-483E-9133-596215172BE9} (AcceptLang Class) - http://runonce.msn.com/setacceptlang.cab
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.danskebank.dk/html/activex/danskesikker/DB/DanskeSikker.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programmer\Fælles filer\EPSON\EBAPI\eEBSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VeriSign Updater (navi) - VeriSign, Inc. - C:\Programmer\VeriSign\NAVI\naviagent.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\NORMAN\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\NORMAN\nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\NORMAN\nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: qtask (qtask.exe) - Unknown owner - C:\WINDOWS\qtask.exe
O23 - Service: Remote Procedure Call (RPC) Locator (RpcLocator) - Unknown owner - C:\WINDOWS\System32\locator.exe (file missing)
Avatar billede ejvindh Ekspert
25. november 2005 - 12:48 #1
Jeg kigger den igennem :-)
Avatar billede ejvindh Ekspert
25. november 2005 - 13:03 #2
Download og gem denne scanner på skrivebordet. Du skal ikke aktivere det endnu.
http://www.spywareinfo.dk/download/mwav.exe

Hent Ewido herfra (14 dages version af plus-versionen)
http://www.spywarefri.dk/downloads1/ewido-setup.exe
Installer og kør Ewido - opdater programmet.

Gå ind i kontrolpanel-tilføj/fjern programmer, og se om du kan få lov til at afinstallere følgende programmer:
Messenger+
Diverse poker-programmer
MediaGateway
MySearch/MyWeb

Tast ctrl-alt-delete, Klik på Jobliste/Taskmanager, Processer/Processes. Find nedenstående processer, højreklik på dem og vælg afslut proces.
C:\blerp.exe >>>>>>>>>>>> den er der måske flere gange. I givet fald skal de alle afsluttes.
mmod.exe
wo.exe

Kør Hijackthis, scan, sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Programmer\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmer\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [REGRUN] C:\blerp.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmer\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\TopText\mmod.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\TopText\wo.exe
O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programmer\expektMPP\MPPoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programmer\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programmer\nordicbetMPP\MPPoker.exe
O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Menuen Start\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Menuen Start\Programmer\Absolute Poker\Absolute Poker.lnk

Denne linie er jeg lidt i tvivl om. Ved du selv hvad det er?
O23 - Service: qtask (qtask.exe) - Unknown owner - C:\WINDOWS\qtask.exe

Sletning af filer og mapper:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

Genstart i fejlsikret (tryk på <F8> under opstarten), slet mapper og filer listet herunder (nogle af dem er muligvis allerede blevet slettet af Hijackthis).
-------------------
Mapper:
C:\Programmer\MySearch\
C:\Programmer\Messenger Plus! 3\
C:\Program Files\Media Gateway\
C:\Programmer\TopText\
C:\Programmer\expektMPP\
C:\Programmer\PartyPoker\
C:\Programmer\nordicbetMPP\
C:\Documents and Settings\All Users\Menuen Start\Programmer\Absolute Poker\

-------------------
Filer:
C:\blerp.exe

Jeg vil også gerne vide om du kan finde denne fil på din computer:
C:\WINDOWS\System32\locator.exe
---------------------------------------
Kør en fuld scanning med Ewido. Programmet laver en lille log, som du skal kopiere herind i dit næste svar.

Klik på mwav.exe som du hentede, programmet pakker sig selv ud og starter.
Sæt flueben i følgende:
Memory, Startup folders, drive, Registry, System folders og Services.
Sæt prik i følgende:
All local drives og Scan all files

Klik på scan clean. Det kan godt tage lang tid (nogle timer), men den er også meget effektiv.
Genstart til normal tilstand, lav en ny HJT-log, som du sender herind til check. Fungerer dit net bedre nu?
Avatar billede rangerbs Nybegynder
29. november 2005 - 12:27 #3
undskyld at det tog så lang tid.. her er log'erne..

Ewido:

---------------------------------------------------------
ewido security suite - Scanningsrapport
---------------------------------------------------------

+ Oprettet den:            4:47:09 PM, 27/11/2005
+ Rapport-Checksum:        7D4C2455

+ Scanningsresultat:
    HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE\\AppID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AppID\eZulaBootExe.EXE -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AppID\eZulaBootExe.EXE\\AppID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AppID\eZulaMain.EXE -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AppID\eZulaMain.EXE\\AppID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AppID\{0818D423-6247-11D1-ABEE-00D049C10000} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AppID\{8A044397-5DA2-11D4-B185-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AppID\{C0335198-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6C5-189F-421a-88CD-07CFE51CFF10} -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6C5-189F-421a-88CD-07CFE51CFF10}\TypeLib\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6C7-189F-421a-88CD-07CFE51CFF10} -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6C7-189F-421a-88CD-07CFE51CFF10}\TypeLib\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}\TypeLib\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6CB-189F-421a-88CD-07CFE51CFF10} -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{014DA6CB-189F-421a-88CD-07CFE51CFF10}\TypeLib\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}\\AppID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE} -> Spyware.TopText : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{53CBEE82-D747-11D3-9ED0-005004189684} -> Spyware.UCmore : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8}\\AppID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{9FF56D85-DB4F-4267-B669-8D05B0BF9A04}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}\\AppID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\\AppID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\\AppID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{ED8DB0FD-D8F4-4B2C-BB5B-9EF040FE104D} -> Spyware.UCmore : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.IEObject -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.IEObject\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.IEObject\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.IEObject\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.IEObject.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.IEObject.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM\CLSID -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM\CurVer -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM.1 -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM.1\CLSID\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{014DA6C4-189F-421A-88CD-07CFE51CFF10}\TypeLib\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{014DA6C6-189F-421A-88CD-07CFE51CFF10}\TypeLib\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{014DA6CA-189F-421A-88CD-07CFE51CFF10}\TypeLib\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{014DA6CC-189F-421A-88CD-07CFE51CFF10}\TypeLib\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{037C47A1-A5EB-4A81-82DD-7615EF5E7BEE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{241667A3-EC83-4885-84DD-C2DAAFC1C5EA} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{241667A3-EC83-4885-84DD-C2DAAFC1C5EA}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{2531390A-1AA6-4F8D-8224-82808F81406E}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{25630B50-53C6-4E66-A945-9D7B6B2171FF} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{25630B50-53C6-4E66-A945-9D7B6B2171FF}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{370F6353-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{370F6353-41C4-4FA6-A2DF-1BA57EE0FBB9}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{788C6F6E-C2EA-4A63-9C38-CE7D8F43BCE4} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{788C6F6E-C2EA-4A63-9C38-CE7D8F43BCE4}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{78BCF936-45B0-40A7-9391-DCC03420DB35} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{78BCF936-45B0-40A7-9391-DCC03420DB35}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{955CBF48-4313-4B1F-872B-254B7822CCF2} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{955CBF48-4313-4B1F-872B-254B7822CCF2}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{9CFA26C2-81DA-4C9D-A501-F144A4A000FA} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{9CFA26C2-81DA-4C9D-A501-F144A4A000FA}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910}\TypeLib\\ -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\MySearchToolBar.NetscapeShutdown\CLSID\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\MySearchToolBar.NetscapeShutdown.1\CLSID\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\MySearchToolBar.NetscapeStartup\CLSID\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\MySearchToolBar.NetscapeStartup.1\CLSID\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\MySearchToolBar.SettingsPlugin\CLSID\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\MySearchToolBar.SettingsPlugin.1\CLSID\\ -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\RunMSC.Loader\CLSID\\ -> Spyware.SaveNow : Renset med backup
    HKLM\SOFTWARE\Classes\RunMSC.Loader.1\CLSID\\ -> Spyware.SaveNow : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{014DA6C0-189F-421A-88CD-07CFE51CFF10} -> Spyware.BargainBuddy : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Renset med backup
    HKLM\SOFTWARE\Classes\WUSE.1 -> Spyware.SaveNow : Renset med backup
    HKLM\SOFTWARE\Classes\WUSN.1 -> Spyware.SaveNow : Renset med backup
    HKLM\SOFTWARE\Comsoft -> Dialer.Generic : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/ISTactivex.dll\\.Owner -> Spyware.ISTBar : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/ISTactivex.dll\\{EF86873F-04C2-4A95-A373-5703C08EFC7B} -> Spyware.ISTBar : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.2/ISTactivex.dll\\.Owner -> Spyware.ISTBar : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.2/ISTactivex.dll\\{12398DD6-40AA-4C40-A4EC-A42CFC0DE797} -> Spyware.ISTBar : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/HDPlugin1014.dll\\.Owner -> Spyware.Gator : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/HDPlugin1014.dll\\{DBAE7000-01EC-4162-8FEB-8A27AC937CA0} -> Spyware.Gator : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/mfc42.dll\\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} -> Spyware.MoneyTree : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/mfc42.dll\\{FC87A650-207D-4392-A6A1-82ADBC56FA64} -> Spyware.MoneyTree : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/msvcrt.dll\\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} -> Spyware.MoneyTree : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/msvcrt.dll\\{FC87A650-207D-4392-A6A1-82ADBC56FA64} -> Spyware.MoneyTree : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/olepro32.dll\\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} -> Spyware.MoneyTree : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/olepro32.dll\\{FC87A650-207D-4392-A6A1-82ADBC56FA64} -> Spyware.MoneyTree : Renset med backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClockSync -> Spyware.Clocksync : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Comsoft -> Dialer.Generic : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10} -> Spyware.eXact : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04079851-5845-4DEA-848C-3ECD647AA554} -> Spyware.MySearchBar : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -> Spyware.WinFavorites : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1678F7E1-C422-11D0-AD7D-00400515CAAA} -> Spyware.CometCursor : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{386A771C-E96A-421F-8BA7-32F1B706892F} -> Spyware.ISTBar : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} -> Spyware.YourSiteBar : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA2325ED-F9EB-4830-8FCE-0BC35B16969B} -> Spyware.SaveNow : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\WhenU -> Spyware.SaveNow : Renset med backup
    HKU\S-1-5-21-1214440339-152049171-1957994488-1003\Software\WhenU\ClockSync -> Spyware.SaveNow : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@2o7[2].txt -> Spyware.Cookie.2o7 : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@atdmt[2].txt -> Spyware.Cookie.Atdmt : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@cz4.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@cz7.clickzs[2].txt -> Spyware.Cookie.Clickzs : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@ehg-ads.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@revenue[1].txt -> Spyware.Cookie.Revenue : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@statcounter[1].txt -> Spyware.Cookie.Statcounter : Renset med backup
    C:\Documents and Settings\Jannik\Cookies\jannik@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\Jannik\Menuen Start\Programmer\WhenU -> Spyware.SaveNow : Renset med backup
    C:\Documents and Settings\Jannik\Menuen Start\Programmer\WhenU\Learn More About Save!.url -> Spyware.SaveNow : Renset med backup
    C:\Documents and Settings\Jannik\Menuen Start\Programmer\WhenU\Learn More About SaveNow.url -> Spyware.SaveNow : Renset med backup
    C:\Documents and Settings\Jannik\Menuen Start\Programmer\WhenU\WhenU.com Website.url -> Spyware.SaveNow : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Application Data\jsmlutwf.exe -> TrojanDownloader.Small.bp : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Application Data\lzjnenkq.exe -> TrojanDownloader.Small.bp : Renset med backup
    :mozilla.6:C:\Documents and Settings\Jeppe og Jannik\Application Data\Mozilla\Profiles\default\s8qjcy7n.slt\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.7:C:\Documents and Settings\Jeppe og Jannik\Application Data\Mozilla\Profiles\default\s8qjcy7n.slt\cookies.txt -> Spyware.Cookie.Adtech : Renset med backup
    :mozilla.11:C:\Documents and Settings\Jeppe og Jannik\Application Data\Mozilla\Profiles\default\s8qjcy7n.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Renset med backup
    :mozilla.12:C:\Documents and Settings\Jeppe og Jannik\Application Data\Mozilla\Profiles\default\s8qjcy7n.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.13:C:\Documents and Settings\Jeppe og Jannik\Application Data\Mozilla\Profiles\default\s8qjcy7n.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.14:C:\Documents and Settings\Jeppe og Jannik\Application Data\Mozilla\Profiles\default\s8qjcy7n.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.15:C:\Documents and Settings\Jeppe og Jannik\Application Data\Mozilla\Profiles\default\s8qjcy7n.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    :mozilla.17:C:\Documents and Settings\Jeppe og Jannik\Application Data\Mozilla\Profiles\default\s8qjcy7n.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Application Data\xtljhukb.exe -> TrojanDownloader.Small.bp : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Application Data\ypgueegl.exe -> TrojanDownloader.Small.bp : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Application Data\yvrbqxzb.exe -> TrojanDownloader.Small.bp : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@-1shz2prbmdj6wvny-1sez2pra2dj6wjkykgdjelqa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@2o7[2].txt -> Spyware.Cookie.2o7 : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ad.adition[1].txt -> Spyware.Cookie.Adition : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@as-eu.falkag[2].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@as-us.falkag[2].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@atdmt[2].txt -> Spyware.Cookie.Atdmt : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@banner.commissionpartner[1].txt -> Spyware.Cookie.Commissionpartner : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@bilbo.counted[2].txt -> Spyware.Cookie.Counted : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@c25838.bins.lop[1].txt -> Spyware.Cookie.Lop : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@cartoonnetwork.122.2o7[1].txt -> Spyware.Cookie.2o7 : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@cnn.122.2o7[2].txt -> Spyware.Cookie.2o7 : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@com[2].txt -> Spyware.Cookie.Com : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@counter1.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@counter15.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@counter3.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@counter7.sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@e-2dj6wgkokgazgbp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@e-2dj6wjkoohd5mbo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-ads.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-ati.hitbox[1].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-dgtlvision.hitbox[1].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-iwantoneofthose.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-ladbrokes.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-machinas.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-nokiafin.hitbox[1].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-nvidia.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-proflowers.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-sigames.hitbox[1].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-sonyeu.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg-tigerdirect2.hitbox[1].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@ehg.hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@estat[1].txt -> Spyware.Cookie.Estat : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@euniverseads[1].txt -> Spyware.Cookie.Euniverseads : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@hitbox[2].txt -> Spyware.Cookie.Hitbox : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@image.masterstats[2].txt -> Spyware.Cookie.Masterstats : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@mysearch[2].txt -> Spyware.Cookie.Mysearch : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@overture[1].txt -> Spyware.Cookie.Overture : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@paycounter[1].txt -> Spyware.Cookie.Paycounter : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@perf.overture[1].txt -> Spyware.Cookie.Overture : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@sales.liveperson[2].txt -> Spyware.Cookie.Liveperson : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@sel.as-eu.falkag[1].txt -> Spyware.Cookie.Falkag : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@server.iad.liveperson[1].txt -> Spyware.Cookie.Liveperson : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@sextracker[1].txt -> Spyware.Cookie.Sextracker : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@spylog[2].txt -> Spyware.Cookie.Spylog : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@stat.onestat[2].txt -> Spyware.Cookie.Onestat : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@statcounter[1].txt -> Spyware.Cookie.Statcounter : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@statse.webtrendslive[2].txt -> Spyware.Cookie.Webtrendslive : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@trafic[1].txt -> Spyware.Cookie.Trafic : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@vegasred[1].txt -> Spyware.Cookie.Vegasred : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@vip.clickzs[1].txt -> Spyware.Cookie.Clickzs : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Cookies\jeppe og jannik@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\180sainstallernusac.exe/clientax.dll -> Spyware.180Solutions : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\180sainstallernusac.exe/clientax.dll -> Spyware.180Solutions : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\Cookies\jeppe og jannik@adtech[2].txt -> Spyware.Cookie.Adtech : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\Cookies\jeppe og jannik@advertising[1].txt -> Spyware.Cookie.Advertising : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\Cookies\jeppe og jannik@bis.180solutions[1].txt -> Spyware.Cookie.180solutions : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\Cookies\jeppe og jannik@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\Cookies\jeppe og jannik@e-2dj6wjl4sgd5sfp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\Cookies\jeppe og jannik@e-2dj6wjnycmcjkdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\Cookies\jeppe og jannik@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\Cookies\jeppe og jannik@valueclick[1].txt -> Spyware.Cookie.Valueclick : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\installer.exe -> Spyware.PurityScan : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temp\upd30.tmp/ME.dll -> Spyware.MediaPops : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temporary Internet Files\Content.IE5\096VGTE7\MediaGateway[1].exe -> Spyware.WinAD : Renset med backup
    C:\Documents and Settings\Jeppe og Jannik\Lokale indstillinger\Temporary Internet Files\Content.IE5\E5O70LWX\bridge-c10[1].cab/MediaGatewayX.dll -> Spyware.WinAD : Renset med backup
    C:\Documents and Settings\Karsten og Majbritt\Cookies\karsten og majbritt@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Renset med backup
    C:\Documents and Settings\Karsten og Majbritt\Cookies\karsten og majbritt@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Renset med backup
    C:\Documents and Settings\Karsten og Majbritt\Cookies\karsten og majbritt@statcounter[1].txt -> Spyware.Cookie.Statcounter : Renset med backup
    C:\Documents and Settings\Karsten og Majbritt\Cookies\karsten og majbritt@trafic[1].txt -> Spyware.Cookie.Trafic : Renset med backup
    C:\Documents and Settings\Karsten og Majbritt\Cookies\karsten og majbritt@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Renset med backup
    C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\K92RWDIR\ldcsh[1].exe -> TrojanDropper.PurityScan.aa : Renset med backup
    C:\Music\iMesh patch.exe -> Worm.Krepper.c : Renset med backup
    C:\Music\Max Payne 2 NO CD Crack.exe -> Worm.Krepper.c : Renset med backup
    C:\Programmer\180searchassistant -> Spyware.180Solutions : Renset med backup
    C:\Programmer\ClockSync\Uninst.exe -> Adware.SaveNow : Renset med backup
    C:\WINDOWS\Downloaded Program Files\MediaGatewayX.dll -> Spyware.WinAD : Renset med backup
    C:\WINDOWS\NDNuninstall4_50.exe -> Spyware.NewDotNet : Renset med backup
    C:\WINDOWS\system32\rdriv.sys -> Trojan.Rootkit.k : Renset med backup
    C:\WINDOWS\Temp\Altnet -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\Altnet\atl.dll -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\Altnet\dmfiles.cab -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\Altnet\dminstall3.cab -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\Altnet\msvcirt.dll -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\Altnet\pmexe.cab -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\Altnet\pmfiles.cab -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\Altnet\pminstall.cab -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\Altnet\Setup.cab -> Spyware.Altnet : Renset med backup
    C:\WINDOWS\Temp\installer.exe -> Spyware.PurityScan : Renset med backup


::Rapport slut

Synes da at den er temmelig lang..


Og log'en fra HJT:

Logfile of HijackThis v1.97.6
Scan saved at 12:27:05 PM, on 29/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\Programmer\Fælles filer\EPSON\EBAPI\eEBSVC.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\ewido\security suite\ewidoguard.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\VeriSign\NAVI\naviagent.exe
C:\Norman\bin\ZANDA.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\PROGRA~1\VeriSign\NAVI\NAVICL~1.EXE
C:\Norman\bin\NJEEVES.EXE
C:\WINDOWS\System32\alg.exe
C:\NORMAN\nvc\BIN\NVCSCHED.EXE
C:\NORMAN\Nvc\BIN\nipsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Norman\bin\ZLH.EXE
C:\Programmer\Norman Access Control Privacy\nrmenctb.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Npf\BIN\npfmsg2.exe
C:\Programmer\Windows NT\Tilbehør\WORDPAD.EXE
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jeppe og Jannik\Skrivebord\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.dk/
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\Programmer\VeriSign\i-Nav\i-nav_4_2_1.dll
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Norman ACP] "C:\Programmer\Norman Access Control Privacy\nrmenctb.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(3).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O9 - Extra button: Expekt.com Poker (HKLM)
O9 - Extra button: PartyPoker.com (HKLM)
O9 - Extra 'Tools' menuitem: PartyPoker.com (HKLM)
O9 - Extra button: i-Nav Hjælp (HKLM)
O9 - Extra 'Tools' menuitem: i-Nav Hjælp (HKLM)
O9 - Extra 'Tools' menuitem: i-Nav Indstillinger (HKLM)
O9 - Extra button: NordicBet Poker (HKLM)
O9 - Extra button: AbsolutePoker.com (HKLM)
O9 - Extra 'Tools' menuitem: AbsolutePoker.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37556.4925925926
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E6A3C1E2-F792-483E-9133-596215172BE9} (AcceptLang Class) - http://runonce.msn.com/setacceptlang.cab
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.danskebank.dk/html/activex/danskesikker/DB/DanskeSikker.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
Avatar billede ejvindh Ekspert
29. november 2005 - 12:35 #4
Ja, den er lang, men det er jo bare et tegn på, at den har været effektiv ;-)

Du er kommet til at tage HJT-loggen med en gammel version af Hijackthis. Lav en ny log med det program, du brugte første gang. Derudover må du også gerne skrive om du kender denne entry:

O23 - Service: qtask (qtask.exe) - Unknown owner - C:\WINDOWS\qtask.exe
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester