Avatar billede dytti Novice
01. september 2006 - 09:47 Der er 9 kommentarer og
1 løsning

WinAntivirusPro 2006

Kender nogen dette program?
Jeg har været så dum at indstallere det.
En efterfølgende scanning med et andet program, viste at ovenstående indeholdt (hold nu fast) 384 trojan's.
Det andet program slettede Winantivirus - også kunne jeg ikke komme på nettet mere.
Jeg lavede en "restore" og kunne nu komme på nettet igen.

Men nu er spørgsmålet - Hvordan F... slipper jeg af med det lo... program?

Det kan ikke fjernes på almindelig vis, og alle forsøg på at fjerne det med andre antivirusprogrammer, resultere i at jeg ikke kan logge på nettet.
Avatar billede ejvindh Ekspert
01. september 2006 - 10:09 #1
Download Alternativ:
http://danborg.org/spy1/HJT/alternativ.exe

Kør Alternativ.exe fra en mappe som du opretter til formålet:
Klik på "Do a systemscan and save a logfile". Efter kort tid åbnes et notepad-vindue med en logfil. Kopiér indholdet af denne logfil herind i denne tråd. Jeg vil fraråde at du selv begynder at fixe noget.

Så skal jeg kigge loggen igennem, og give nogle råd til at komme af med skidtet.
Avatar billede dytti Novice
01. september 2006 - 10:13 #2
den er så her

Logfile of HijackThis v1.99.1
Scan saved at 10:11:52, on 01-09-2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\LEXPPS.EXE
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\CTHELPER.EXE
D:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Common Files\Companion Wizard\compwiz.exe
D:\Program Files\Common Files\{20431EB9-01D2-1030-0605-00102000002d}\Update.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Messenger\msmsgs.exe
D:\DOCUME~1\mp\APPLIC~1\ASKS~1\MHTA~1.EXE
D:\WINDOWS\SSTEM3~1\services.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\System32\wuauclt.exe
D:\My Downloads\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.signon.stofanet.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: CIEIntegrator Object - {2178F3FB-2560-458F-BDEE-631E2FE0DFE4} - D:\Program Files\WinAntiVirus Pro 2006\winpgi.dll
O2 - BHO: (no name) - {86E3F16B-30D2-4A52-F2FF-611345AF6C9D} - D:\WINDOWS\System32\nav.dll
O2 - BHO: IEFW Object - {B5141620-C2B2-4D95-9F0F-134D99C87AB0} - D:\Program Files\WinAntiVirus Pro 2006\iefwbho.dll
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] D:\drivers\blaster\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CompanionWizard] "D:\Program Files\Common Files\Companion Wizard\compwiz.exe" /silent
O4 - HKLM\..\Run: [WinAntiVirusPro2006] D:\Program Files\WinAntiVirus Pro 2006\winav.exe /min
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TClock.exe] D:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [Slxzgq] D:\DOCUME~1\mp\APPLIC~1\ASKS~1\MHTA~1.EXE
O4 - HKCU\..\Run: [Psrs] "D:\WINDOWS\SSTEM3~1\services.exe" -vt tzt
O4 - HKCU\..\Run: [ErrorSafe] "D:\Program Files\Error Safe Free\ERS.exe" /scan
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - D:\Program Files\ladbrokesMPP\MPPoker.exe
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153725582808
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153725565944
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.ladbrokes.com/instant-play-en/FlashAX.cab
O20 - AppInit_DLLs:  arpa.dll
O20 - Winlogon Notify: Reliability - D:\WINDOWS\system32\l8p20i7oe8.dll (file missing)
O20 - Winlogon Notify: Syncmgr - D:\WINDOWS\
O23 - Service: Firewall service (FWSvc) - WinSoftware, Ltd. - D:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
Avatar billede ejvindh Ekspert
01. september 2006 - 10:44 #3
Ja, jeg forstår godt, at du mister internetforbindelsen, hvis du bare sletter WinantivirusPro. Og jeg forstår også godt, at du har problemer. Du har hverken opdateret dit styresystem, eller noget antivirus på din computer. Så beder man om problemer! Du har rigtig mange forskellige infektioner inde, og i bund og grund, vil jeg egentlig anbefale at nyinstallere computeren, og straks få den opdateret med ServicePack2, som du forinden har hentet ned på en CD herfra:
http://intern.sdu.dk/it-service/tjenester/ftphotel/ftpindhold/

Men vil du prøve at rense computeren, så gør følgende:

-- Hent Dr. Web, og gem det på skrivebordet:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

-- Hent "SuperAntiSpyware free" herfra:
http://www.spywarefri.dk/downloads1.htm
Installer, og opdater scannereren. Men vent med at scanne.

Fuld vejledning til superantispyware finder du her:
http://www.spywarefri.dk/manualer/superantispyware-manual.htm

-- Hent disse programmer:
http://cexx.org/lspfix.htm - http://cexx.org/lspfix.zip
http://danborg.org/spy/Newnet/winsockxpfix.exe

-- Hent NoLop.exe og gem den på skrivebordet:
http://www.spywareedge.net/nolop/NoLop.exe

-- Gå ind i kontrolpanel-tilføj/fjern programmer, og se om du kan få lov til at afinstallere følgende programmer:
PuritySCAN By OIN
OIN
OuterInfo
(el. lignende)
WinAntivirusPro
ErrorSafe
Tclock
Messenger+

-- Pak lspfix ud, og kør det. Sæt flueben i "I know what I am doing". I venstre side (Keep) finder du alle instanser af "mailscan.dll", markerer dem, og klikker på pil til venstre, for at flytte dem over i "Remove". Klik på finish.

-- Kør NoLop.exe. Tryk på "Search and Destroy"-knappen. Hvis den finder noget, bliver du bedt om at trykke på Reboot-knappen. Dette skal du så gøre.

-- Klik på Start-kør. Skriv: Services.msc, og klik på OK.
Find følgende services, højreklik på dem og vælg egenskaber. Under starttype vælger du deaktiveret. Klik også på Stop:
Firewall service

-- Klik Start-kør, skriv cmd, og klik på OK. I det sorte billede skriver du:
sc delete "FWSvc" <efterfulgt af Enter>
Luk det sorte billede.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked (nogle af dem er muligvis forsvundet allerede).

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: CIEIntegrator Object - {2178F3FB-2560-458F-BDEE-631E2FE0DFE4} - D:\Program Files\WinAntiVirus Pro 2006\winpgi.dll
O2 - BHO: (no name) - {86E3F16B-30D2-4A52-F2FF-611345AF6C9D} - D:\WINDOWS\System32\nav.dll
O2 - BHO: IEFW Object - {B5141620-C2B2-4D95-9F0F-134D99C87AB0} - D:\Program Files\WinAntiVirus Pro 2006\iefwbho.dll
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [WinAntiVirusPro2006] D:\Program Files\WinAntiVirus Pro 2006\winav.exe /min
O4 - HKCU\..\Run: [TClock.exe] D:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [Slxzgq] D:\DOCUME~1\mp\APPLIC~1\ASKS~1\MHTA~1.EXE
O4 - HKCU\..\Run: [Psrs] "D:\WINDOWS\SSTEM3~1\services.exe" -vt tzt
O4 - HKCU\..\Run: [ErrorSafe] "D:\Program Files\Error Safe Free\ERS.exe" /scan
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - D:\Program Files\ladbrokesMPP\MPPoker.exe
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O10 - Unknown file in Winsock LSP: d:\program files\winantivirus pro 2006\mailscan.dll
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.ladbrokes.com/instant-play-en/FlashAX.cab
O20 - AppInit_DLLs:  arpa.dll
O20 - Winlogon Notify: Reliability - D:\WINDOWS\system32\l8p20i7oe8.dll (file missing)
O20 - Winlogon Notify: Syncmgr - D:\WINDOWS\

-- Genstart i fejlsikret, hvis du ikke ved hvordan så kig her:
http://www.ctrlaltdel.dk/forum/forum_posts.asp?TID=23&PN=1

-- Du skal nu til at slette. Som indledning hertil skal du have slået "Udvidet filvisning" til:
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".

-- Slet herefter følgende (hvis du kan finde dem):
Mapper:
D:\Program Files\WinAntiVirus Pro 2006\
D:\Program Files\TClock\
D:\Program Files\Error Safe Free\
D:\Program Files\ladbrokesMPP\
D:\DOCUMENTS AND SETTINGS\mp\APPLICATION DATA\ASKS~1\ >>>>>> (bemærk at sidste mappenavnet er forkortet her)

Filer:
D:\WINDOWS\System32\nav.dll
D:\WINDOWS\SSTEM3~1\services.exe
D:\WINDOWS\system32\l8p20i7oe8.dll

-- Dobbeltklik på drweb-cureit.exe, den vil køre en expressscan, det siger du ja til. Lad den slette hvad den finder (say Yes to all)
Når den skriver "Select object for Scanning" nederst til venstre, skal du klikke på Options->Change settings.
Skift til fanebladet Scan, fjern fluebenet ved Heuristic analysis.
Skift til fanebladet - File Types, prik i - All Files
Skift til fanebladet Actions, her skal alle punkter under Malware sættes til Move.
Fjern flueben ved "Prompt on action"
Ved "Move path", skriver du i tekstboksen "c:\" Så der kommer til at stå "c:\infected".
Skift til fanbladet Log File. Der fjerner du flueben ved: "Scanned objects" og "Archivers name".
Tryk på Anvend

Klik så på det eller de drev du vil have scannet, der kommer en rød prik for at vise det/de er valgt.
Tryk så på den grønne pil nederst til højre, så scanner den.
Lad den slette/move hvad den finder (Say yes to all)

Når scanningen er færdig, gå op i file – Tryk på- Save Report list.

Så ligger der en en fil der her hedder "drweb.csv" på skrivebordet. Luk Programmet

-- Start SuperAntispyware, klik "Scan your computer", sæt flueben i dine drev, ovre til venstre i vinduet. Ovre til højre i vinduet, sætter du prik i "Perform Complete Scan". Klik "næste", nu scanner den. Når den er færdig, så markerer du det den finder, og lader scannereren fjerne det.

-- Genstart til normal tilstand. Åbn SuperAntispyware-scannereren igen, og klik "preferences"-> "stastics/logs". Marker loggen, og klik "View log". Kopier loggen her ind i tråden, sammen med en ny HijackThis log. Kopiér også indholdet af drweb.csv herind. Og indholdet af denne fil: C:\NoLop.txt
Avatar billede dytti Novice
01. september 2006 - 11:01 #4
hold da op!
Hvordan kunne du skrive alt det så hurtigt?

Min første tanke var at geninstallere, men jeg prøver at rense først.

Respekt for så hurtigt svar
Avatar billede dytti Novice
01. september 2006 - 11:23 #5
Hov - hvilken services?

-- Klik på Start-kør. Skriv: Services.msc, og klik på OK.
Find følgende services, højreklik på dem og vælg egenskaber. Under starttype vælger du deaktiveret. Klik også på Stop:
Firewall service
Avatar billede ejvindh Ekspert
01. september 2006 - 11:49 #6
Firewall service
Avatar billede dytti Novice
01. september 2006 - 15:50 #7
Superantivirus:
SUPERAntiSpyware Scan Log
Generated 09/01/2006 at 03:32 PM

Core Rules Database Version : 3070
Trace Rules Database Version: 1110

Memory threats detected  : 0
Registry threats detected : 349
File threats detected    : 170

Adware.Tracking Cookie
    D:\Documents and Settings\mp\Cookies\mp@tribalfusion[1].txt
    D:\Documents and Settings\mp\Cookies\mp@adtech[2].txt
    D:\Documents and Settings\mp\Cookies\mp@tradedoubler[2].txt
    D:\Documents and Settings\mp\Cookies\mp@revsci[2].txt
    D:\Documents and Settings\mp\Cookies\mp@www.jackpotmadness[1].txt
    D:\WINDOWS\system32\config\systemprofile\Cookies\mp@banner.commissionpartner[2].txt
    D:\Documents and Settings\mp\Cookies\mp@www.burstbeacon[1].txt
    D:\Documents and Settings\mp\Cookies\mp@ad.ofir[2].txt
    D:\Documents and Settings\mp\Cookies\mp@ilead.itrack[1].txt
    D:\Documents and Settings\mp\Cookies\mp@ientry[2].txt
    D:\Documents and Settings\mp\Cookies\mp@xiti[1].txt
    D:\Documents and Settings\mp\Cookies\mp@cassava[1].txt
    D:\Documents and Settings\mp\Cookies\mp@adinterax[1].txt
    D:\Documents and Settings\mp\Cookies\mp@partypoker[2].txt
    D:\Documents and Settings\mp\Cookies\mp@partypoker.touchclarity[1].txt
    D:\Documents and Settings\mp\Cookies\mp@track.adform[2].txt
    D:\Documents and Settings\mp\Cookies\mp@burstnet[2].txt
    D:\Documents and Settings\mp\Cookies\mp@banner.commissionpartner[1].txt
    D:\Documents and Settings\mp\Cookies\mp@dist.belnk[1].txt
    D:\Documents and Settings\mp\Cookies\mp@stats1.reliablestats[2].txt

Trojan.WinAntiSpyware/WinAntiVirus 2006
    HKCR\AntiVirusCOM.AVOfficeProtect
    HKCR\AntiVirusCOM.AVOfficeProtect\CLSID
    HKCR\AntiVirusCOM.AVOfficeProtect.1
    HKCR\AntiVirusCOM.AVOfficeProtect.1\CLSID
    HKCR\AVExplorer.ShellExtension
    HKCR\AVExplorer.ShellExtension\CLSID
    HKCR\AVExplorer.ShellExtension\CurVer
    HKCR\AVExplorer.ShellExtension.2
    HKCR\AVExplorer.ShellExtension.2\CLSID
    HKCR\WAP6.PCheck
    HKCR\WAP6.PCheck\CLSID
    HKCR\WAP6.PCheck\CurVer
    HKCR\WAP6.PCheck.1
    HKCR\WAP6.PCheck.1\CLSID
    HKCR\WinPGIntegrator.IEIntegrator
    HKCR\WinPGIntegrator.IEIntegrator\CLSID
    HKCR\WinPGIntegrator.IEIntegrator\CurVer
    HKCR\WinPGIntegrator.IEIntegrator.1
    HKCR\WinPGIntegrator.IEIntegrator.1\CLSID
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}#AppID
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\InprocServer32
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\InprocServer32#ThreadingModel
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\ProgID
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\Programmable
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\TypeLib
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\VersionIndependentProgID
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\Implemented Categories
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\Implemented Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\InprocServer32
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\InprocServer32#ThreadingModel
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\ProgID
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\Programmable
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\TypeLib
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\VersionIndependentProgID
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\0
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\0\win32
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\FLAGS
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\HELPDIR
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\0
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\0\win32
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\FLAGS
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\HELPDIR
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\ProxyStubClsid
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\ProxyStubClsid32
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\TypeLib
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\TypeLib#Version
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version
    HKCR\AppId\WinPGI.DLL
    HKCR\AppId\WinPGI.DLL#AppID
    HKCR\AppId\{367A86A5-D048-4785-86BE-4E2706AAFDD9}
    HKU\S-1-5-21-1390067357-484763869-854245398-1003\Software\WinAntiVirus Pro 2006
    HKLM\Software\WinAntiVirus Pro 2006
    HKLM\Software\WinAntiVirus Pro 2006#EulUWA6PK_0001_N91M2107
    HKLM\Software\WinAntiVirus Pro 2006#ProductCode
    HKLM\Software\WinAntiVirus Pro 2006#InstallPath
    HKLM\Software\WinAntiVirus Pro 2006#Abbr
    HKLM\Software\WinAntiVirus Pro 2006#ActivationCode
    HKLM\Software\WinAntiVirus Pro 2006#Suspicious
    HKLM\Software\WinAntiVirus Pro 2006#ProductName
    HKLM\Software\WinAntiVirus Pro 2006#OID
    HKLM\Software\WinAntiVirus Pro 2006#CustomerName
    HKLM\Software\WinAntiVirus Pro 2006#CustomerEmail
    HKLM\Software\WinAntiVirus Pro 2006#ActivatorInfo
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: Setup Version
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: App Path
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#InstallLocation
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: Icon Group
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: User
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: Selected Tasks
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: Deselected Tasks
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#DisplayName
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#UninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#QuietUninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Publisher
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#URLInfoAbout
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#HelpLink
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#URLUpdateInfo
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#NoModify
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#NoRepair
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Type
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Start
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#ErrorControl
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Tag
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#ImagePath
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#DisplayName
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Group
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Overflow
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMP\NDR55.TMP.HTML
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\HISTORY\HISTORY.IE5
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\RECYCLED
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMP\RARSFX1
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\DOCTORWEB
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\GJRVIC9L
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\MY DOWNLOADS\BACKUPS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SUPERANTISPYWARE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\APPLICATION DATA\SUPERANTISPYWARE.COM\SUPERANTISPYWARE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\APPLICATION DATA\MICROGAMING\MPG
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\SUPERANTISPYWARE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\CATROOT2
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\CATROOT2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\INSTALLER\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SUPERANTISPYWARE\PLUGINS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP175
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\SNAPSHOT\REPOSITORY
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\SNAPSHOT\REPOSITORY\FS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP175
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\SNAPSHOT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\LADBROKESMPP\LOGGER
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\LADBROKESMPP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\MCAFEE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\COOKIES
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\WBEM\PERFORMANCE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\DRIVERS\ETC
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O92FOLYN
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\B20NJTG5
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMP\NSS48.TMP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\8LMRCPIB
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O9ARC1YF
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\YLF4LONM
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP175\SNAPSHOT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\RESTORE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\APPLICATION DATA\?ASKS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\ACCESSORIES\SYSTEM TOOLS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\S?STEM32
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\??\VOLUME{4D191E04-AEF4-11D7-9863-806D6172696F}\WINDOWS\SYSTEM32
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\??\VOLUME{4D191E04-AEF4-11D7-9863-806D6172696F}\PROGRAM FILES\WINANTIVIRUS PRO 2006
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\RECENT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\APPLICATION DATA\ADOBE\PHOTOSHOP\7.0\ADOBE PHOTOSHOP 7.0 SETTINGS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\??\VOLUME{4D191E04-AEF4-11D7-9863-806D6172696F}\CONFIG.MSI
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\DRIVERS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\COMMON FILES\WINANTIVIRUS PRO 2006
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\WINANTIVIRUS PRO 2006
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\??\VOLUME{4D191E04-AEF4-11D7-9863-806D6172696F}\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\SUPERADBLOCKER.COM\SUPER AD BLOCKER
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\??\VOLUME{4D191E04-AEF4-11D7-9863-806D6172696F}\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\CONFIG.MSI
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\??\VOLUME{4D191E04-AEF4-11D7-9863-806D6172696F}\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\??\VOLUME{4D191E04-AEF4-11D7-9863-806D6172696F}\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\PLUGINS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MSN6
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\INF
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\PLUGINS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\SUPERADBLOCKER.COM\SUPER AD BLOCKER
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\NETWORK\CONNECTIONS\PBK
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\COMMON FILES
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\INCINERATE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\MY DOWNLOADS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\ADMINISTRATIVE TOOLS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\GROUPPOLICY
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\MSAGENT\CHARS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\ERROR SAFE FREE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\COMMON FILES\WISE INSTALLATION WIZARD
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\INSTALLER
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\F8BA8B13856D4DFBA28F7EC868142453.TMP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\URTTEMP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\INSTALLER\{F8BA8B13-856D-4DFB-A28F-7EC868142453}
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\QUARANTINE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\UDPAK\DD
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\DESKTOP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP162\SNAPSHOT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SOFTWAREDISTRIBUTION\DATASTORE\LOGS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SOFTWAREDISTRIBUTION\DATASTORE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\SNAPSHOT\REPOSITORY
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\SNAPSHOT\REPOSITORY\FS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\SNAPSHOT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\NETWORKSERVICE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\LOCALSERVICE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\SNAPSHOT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\S?STEM32\SSTEM3~1
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\WO4T0JKF
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CAN0D2RS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\EBN7YVR0
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CTK9Y3GH
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\PNRBLDOE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\PREFETCH
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMP\TAOT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\TEMP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\APPLICATION DATA\MICROSOFT\PROTECT\S-1-5-21-1390067357-484763869-854245398-1003
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\S-1-5-21-1390067357-484763869-854245398-1003
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\L780AKUV
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\COMMON FILES\COMPANION WIZARD
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\APPLICATION DATA\MICROSOFT\CREDENTIALS\S-1-5-21-1390067357-484763869-854245398-1003
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\DEBUG\USERMODE
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\WBEM\REPOSITORY\FS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{D7A2A21A-91A4-48C3-A16F-2D674A054774}
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\TASKS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\WBEM\LOGS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\CONFIG
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\DOCUMENTS AND SETTINGS\MP\APPLICATION DATA\WINANTIVIRUS PRO 2006\LOGS
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\WINANTIVIRUS PRO 2006
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Security
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Security#Security
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Enum
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Enum#0
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Enum#Count
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Enum#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#DeviceDesc
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Capabilities
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000\LogConf
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000\Control
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#DeviceDesc
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Capabilities
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000\LogConf
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000\Control
    HKLM\SYSTEM\CurrentControlSet\Services\vspf
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#Type
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#Start
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#ErrorControl
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#Tag
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#ImagePath
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#DisplayName
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#Group
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#DependOnService
    HKLM\SYSTEM\CurrentControlSet\Services\vspf#DependOnGroup
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Security
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Security#Security
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#0
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#Count
    HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Type
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Start
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#ErrorControl
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Tag
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#ImagePath
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#DisplayName
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Group
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Security
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Security#Security
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#0
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#Count
    HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#NextInstance
    HKCR\IEFWBHO.IEFW
    HKCR\IEFWBHO.IEFW\CLSID
    HKCR\IEFWBHO.IEFW\CurVer
    HKCR\IEFWBHO.IEFW.2
    HKCR\IEFWBHO.IEFW.2\CLSID
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\0
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\0\win32
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\FLAGS
    HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\HELPDIR
    D:\WINDOWS\system32\av.cpl
    D:\WINDOWS\system32\drivers\FOPN.sys
    D:\WINDOWS\system32\stera.exe
    D:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll
    D:\Program Files\Common Files\WinAntiVirus Pro 2006\WAPPChk.dll
    D:\Program Files\Common Files\WinAntiVirus Pro 2006
    D:\Program Files\WinAntiVirus Pro 2006\AVKERNEL.DLL
    D:\Program Files\WinAntiVirus Pro 2006\WAV6COM.dll
    D:\Program Files\WinAntiVirus Pro 2006\avcom.log
    D:\Program Files\WinAntiVirus Pro 2006
    D:\Documents and Settings\mp\Application Data\WinAntiVirus Pro 2006\Logs\winav.log
    D:\Documents and Settings\mp\Application Data\WinAntiVirus Pro 2006\Logs
    D:\Documents and Settings\mp\Application Data\WinAntiVirus Pro 2006
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Brugeranvisning.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Henvend til kundehjælpeafdeling.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Afinstallér WinAntiVirus Pro 2006.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Manual.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Knowledge base.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Report Software Defect.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Request for Instructions.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Share Your Suggestions.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Feedback on Support Quality.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Uninstall WinAntiVirus Pro 2006.lnk
    D:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006
    D:\Documents and Settings\mp\Local Settings\Temp\temp.fr7BF6\manual.exe
    D:\Documents and Settings\mp\Local Settings\Temp\temp.fr7BF6\VAExt.exe
    D:\Documents and Settings\mp\Local Settings\Temp\temp.fr7BF6\fat.exe
    D:\Documents and Settings\mp\Local Settings\Temp\temp.fr7BF6\Activate.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP164\A0036502.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP164\A0036503.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP164\A0036506.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP168\A0039929.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP168\A0039933.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP168\A0039934.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP171\A0040204.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP171\A0040205.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP171\A0040209.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP171\A0040215.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\A0040219.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040405.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040409.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040410.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040525.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040620.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040621.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040639.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040640.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040644.exe
    D:\My Downloads\WinAntiVirusPro2006FreeInstall_dk.exe
    D:\Recycled\Dd133.exe
    D:\Recycled\Dd142.exe
    D:\Recycled\Dd147.exe
    D:\Recycled\Dd151.dll
    D:\Recycled\Dd161.exe
    D:\WINDOWS\Prefetch\STERA.EXE-1D49DB7C.pf

Trojan.NetMon/DNSChange
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#DeviceDesc

Trojan.cmdService
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#DeviceDesc

Adware.ClickSpring/Yazzle
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#DisplayName
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#UninstallString
    D:\WINDOWS\Prefetch\YAZZLE1122OINADMIN.EXE-0F198A06.pf
    D:\WINDOWS\Prefetch\YAZZLEBUNDLE-1122.EXE-0A70446A.pf
    D:\Program Files\Common Files\Yazzle1122OinAdmin.exe
    D:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP171\A0040160.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040503.exe

Trojan.ErrorSafe
    HKCR\ESSPChck.ESSPChck
    HKCR\ESSPChck.ESSPChck\CLSID
    HKCR\ESSPChck.ESSPChck\CurVer
    HKCR\ESSPChck.ESSPChck.1
    HKCR\ESSPChck.ESSPChck.1\CLSID
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\InprocServer32#ThreadingModel
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\ProgID
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\Programmable
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\TypeLib
    HKCR\clsid\{647b8364-79e0-48e2-a4ca-233abada0c2d}\VersionIndependentProgID
    HKCR\typelib\{1b197c22-561f-455f-8511-35b1a45c5c9f}
    HKCR\typelib\{1b197c22-561f-455f-8511-35b1a45c5c9f}\1.0
    HKCR\typelib\{1b197c22-561f-455f-8511-35b1a45c5c9f}\1.0\0
    HKCR\typelib\{1b197c22-561f-455f-8511-35b1a45c5c9f}\1.0\0\win32
    HKCR\typelib\{1b197c22-561f-455f-8511-35b1a45c5c9f}\1.0\FLAGS
    HKCR\typelib\{1b197c22-561f-455f-8511-35b1a45c5c9f}\1.0\HELPDIR
    D:\WINDOWS\Downloaded Program Files\UERSK_0001_N91M2407NetInstaller.exe
    D:\WINDOWS\Prefetch\UERSK_0001_N91M2407NETINSTALL-0F2F9F29.pf

Adware.ClickSpring/PuritySCAN
    D:\WINDOWS\system32\wnsintsv.exe

Adware.NicTech Networks
    D:\WINDOWS\system32\m0ls0a37ed.dll
    D:\WINDOWS\system32\q2nulc591f.dll
    D:\WINDOWS\system32\i0nmla511d.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP143\A0033692.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP144\A0033792.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP144\A0033889.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP144\A0033985.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP144\A0033993.DLL
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP145\A0034143.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP145\A0034154.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP145\A0034165.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP145\A0034199.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP145\A0034203.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP145\A0034233.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP146\A0034268.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP147\A0034283.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP147\A0034293.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP147\A0034336.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040610.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040728.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040729.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040730.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040731.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040732.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040733.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040734.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040735.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040736.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040737.DLL
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040738.dll

Trojan.Unknown Origin
    D:\WINDOWS\bXA\vrE.vbs
    D:\Program Files\Common Files\{20431EB9-01D2-1030-0605-00102000002d}\services.dll
    D:\Program Files\winupdate\winupdate.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP143\A0033596.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP144\A0033809.DLL
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP145\A0034116.vbs
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP164\A0036698.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP165\A0037739.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP166\A0037819.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP171\A0040159.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP171\A0040185.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\A0040224.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\A0040365.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040367.exe

Unclassified.Unknown Origin
    D:\WINDOWS\bXA\command.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP166\A0037818.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\A0040262.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040612.exe

Adware.Adservs
    D:\WINDOWS\bXA\asappsrv.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040611.dll

Adware.WhenU
    D:\Documents and Settings\mp\Local Settings\Temp\saveinstwm.exe

Adware.ClickSpring
    D:\Documents and Settings\mp\Local Settings\Temp\!update.exe
    D:\Documents and Settings\mp\Application Data\ASKS~1\MHTA~1.EXE
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP164\A0036697.EXE
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP168\A0039916.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP168\A0039917.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP168\A0039966.DLL
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\A0040225.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\A0040278.EXE
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\A0040357.DLL
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP172\A0040364.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040368.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040369.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040393.EXE
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP173\A0040528.DLL
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040593.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040619.DLL
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040711.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040739.DLL
    D:\My Downloads\backups\backup-20060901-113330-730.dll
    D:\Recycled\Dd163.EXE

Trojan.WinSoftware/WinFixer
    D:\Documents and Settings\mp\Local Settings\Temp\temp.fr7BF6\fopn.exe
    D:\Documents and Settings\mp\Local Settings\Temp\temp.fr7BF6\InstHelp.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040613.exe
    D:\Recycled\Dd144.exe

Adware.ClickSpring/Outer Info Network
    D:\Program Files\Common Files\Y1220OU.exe

Adware.Director
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP144\A0033808.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP144\A0033811.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP144\A0033878.exe
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040720.exe

Adware.Pushow
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP174\A0040609.dll
    D:\System Volume Information\_restore{D7A2A21A-91A4-48C3-A16F-2D674A054774}\RP176\A0040740.dll

Adware.TargetSavers
    D:\stub_113_4_0_4_0newer.exe
    D:\A0040607.exe
    D:\A0040723.exe

HIJACK:
Logfile of HijackThis v1.99.1
Scan saved at 15:39:59, on 01-09-2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\LEXPPS.EXE
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\CTHELPER.EXE
D:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Common Files\Companion Wizard\compwiz.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\wuauclt.exe
D:\My Downloads\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.signon.stofanet.dk/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] D:\drivers\blaster\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CompanionWizard] "D:\Program Files\Common Files\Companion Wizard\compwiz.exe" /silent
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153725582808
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153725565944
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab
O20 - Winlogon Notify: SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe

NOLOP:
NoLop! Log by Skate_Punk_21

Fix running from: D:\Documents and Settings\mp\Desktop
[01-09-2006]
[11:13:58]

---Infection Files Found/Removed---
NO INFECTION FILES FOUND - Cleaning Aborted.

---Listing AppData sub directories---

D:\Documents and Settings\Default User\Application Data\Microsoft
D:\Documents and Settings\All Users\Application Data\Microsoft
D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
D:\Documents and Settings\All Users\Application Data\Nview_profiles  -- EMPTY Directory
D:\Documents and Settings\All Users\Application Data\Msn6
D:\Documents and Settings\All Users\Application Data\Adobe
D:\Documents and Settings\All Users\Application Data\Bitstream Font Navigator
D:\Documents and Settings\All Users\Application Data\Ahead
D:\Documents and Settings\All Users\Application Data\Avery
D:\Documents and Settings\All Users\Application Data\Quicktime
D:\Documents and Settings\All Users\Application Data\Winantivirus Pro 2006
D:\Documents and Settings\All Users\Application Data\Winsoftware
D:\Documents and Settings\Networkservice\Application Data\Microsoft
D:\Documents and Settings\Localservice\Application Data\Microsoft
D:\Documents and Settings\Mp\Application Data\Microsoft
D:\Documents and Settings\Mp\Application Data\Identities
D:\Documents and Settings\Mp\Application Data\Macromedia
D:\Documents and Settings\Mp\Application Data\Sun
D:\Documents and Settings\Mp\Application Data\Syntrillium
D:\Documents and Settings\Mp\Application Data\Msn6
D:\Documents and Settings\Mp\Application Data\Spweng  -- EMPTY Directory
D:\Documents and Settings\Mp\Application Data\Globalscape
D:\Documents and Settings\Mp\Application Data\Adobe
D:\Documents and Settings\Mp\Application Data\Adobeum  -- EMPTY Directory
D:\Documents and Settings\Mp\Application Data\Help  -- EMPTY Directory
D:\Documents and Settings\Mp\Application Data\Corel
D:\Documents and Settings\Mp\Application Data\Mobileaction
D:\Documents and Settings\Mp\Application Data\Pokeracademy
D:\Documents and Settings\Mp\Application Data\Ahead
D:\Documents and Settings\Mp\Application Data\Microgaming
D:\Documents and Settings\Mp\Application Data\Smartftp
D:\Documents and Settings\Mp\Application Data\Ibp
D:\Documents and Settings\Mp\Application Data\Visicom Media
D:\Documents and Settings\Mp\Application Data\Allume Systems
D:\Documents and Settings\Mp\Application Data\Lpc
D:\Documents and Settings\Mp\Application Data\?asks
D:\Documents and Settings\Mp\Application Data\Google
D:\Documents and Settings\Mp\Application Data\Pc Tools
D:\Documents and Settings\Mp\Application Data\Superadblocker.com
D:\Documents and Settings\Mp\Application Data\Winantivirus Pro 2006
D:\Documents and Settings\Mp\Application Data\?racle
D:\Documents and Settings\Mp\Application Data\F?nts
D:\Documents and Settings\Mp\Application Data\Lavasoft
D:\Documents and Settings\Mp\Application Data\Winantivirus Pro 2006(2)
D:\Documents and Settings\Mp\Application Data\Superantispyware.com
Avatar billede ejvindh Ekspert
01. september 2006 - 16:01 #8
Det ser rigtig fornuftigt ud, idet logsene nu er rene. Kører din computer også tilfredsstillende?

Lidt oprydning mangler dog stadigvæk:

Find følgende mapper, og slet dem:
D:\Documents and Settings\All Users\Application Data\Winantivirus Pro 2006
D:\Documents and Settings\Mp\Application Data\Spweng
D:\Documents and Settings\Mp\Application Data\Adobeum
D:\Documents and Settings\Mp\Application Data\Help
D:\Documents and Settings\Mp\Application Data\?asks
D:\Documents and Settings\Mp\Application Data\Winantivirus Pro 2006
D:\Documents and Settings\Mp\Application Data\?racle
D:\Documents and Settings\Mp\Application Data\F?nts
D:\Documents and Settings\Mp\Application Data\Winantivirus Pro 2006(2)

Det kan være en god ide og rydde op i systemgendannelses filerne. Deaktiver systemgendannelse (http://www.spywarefri.dk/virusscannere.htm#alle) - genstart din computer - aktiver systemgendannelse.
Og så kan det også være en god ide at skjule dine systemfiler og -mapper igen, så du ikke ved en fejl kommer til at slette en vigtig fil. Det gør du samme sted, hvor du satte det til at vise alle filer, denne gang vælger du bare: Vis ikke skjulte filer og mapper.

Det kan også være en god ide at få renset ud i dine midlertidige filer. Det kan gøres på en hurtig og nem måde med denne fil
www.spywareinfo.dk/download/cleantempxp2k.bat
---------------------------

For at forhindre gentagelser, vil jeg anbefale dig at lægge nogle små programmer ind, som forhindrer spyware i at komme ind i første omgang. Du finder links og gode råd her:
http://www.spywarefri.dk/manualer/sikkerhedspakke.htm

Jeg vil også foreslå, at du læser denne artikel om hvordan du kan undgå at blive inficeret i fremtiden:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Specielt vil jeg anbefale at du bider mærke i det, der står om at holde Windows opdateret -- ved at få installeret ServicePack2 på din computer. Ellers kommer du hurtigt i problemer igen. Og det er ikke sikkert at det kan renses næste gang.
Avatar billede dytti Novice
01. september 2006 - 16:21 #9
Tusind tak.
Skidtet virker nu, og jeg er ved at hente servicepack2.

Den vil jeg så kigge på i morgen (er på vej på arbejde)

Endnu en gang tak for hjælpen.
Avatar billede ejvindh Ekspert
01. september 2006 - 16:41 #10
Du er velkommen :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester