Avatar billede jimjimjam Nybegynder
26. marts 2007 - 20:08 Der er 20 kommentarer og
1 løsning

Hijackthis log. Rigtig meget inficeret.

Har en maskine her der er UTROLIG inficeret. Der kommer 2 - 4 "virus" programmer der scanner når man tænder maskinen (Ved godt det er spyware). En der vil kigge på den ? Tak!



Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 20:04:33, on 26-03-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Video ActiveX Object\isamntr.exe
C:\Programmer\Video ActiveX Object\pmsnrr.exe
C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Programmer\Video ActiveX Object\pmmnt.exe
C:\Programmer\Video ActiveX Object\isamini.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Programmer\AntiVermeans\AntiVermeans.exe
C:\Programmer\Error Safe Free\ers.exe
C:\Programmer\ErrorSafe Free\uerscw.exe
C:\Programmer\DriveCleaner 2006 Free\UDC2006.exe
C:\Programmer\DriveCleaner 2006 Free\udc6cw.exe
C:\Programmer\SpyHeals\SpyHeals.exe
C:\Programmer\Fælles filer\WinAntiVirus Pro 2006\uwa6pcw.exe
C:\Programmer\Error Safe Free\WASmon.exe
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\Program Files\PestCapture\PestCapture.exe
C:\Programmer\Video ActiveX Object\isamini.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
E:\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CIEIntegrator Object - {2178F3FB-2560-458F-BDEE-631E2FE0DFE4} - C:\Programmer\WinAntiVirus Pro 2006\winpgi.dll
O2 - BHO: (no name) - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - (no file)
O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Programmer\Video ActiveX Object\isadd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll (file missing)
O2 - BHO: IEFW Object - {B5141620-C2B2-4D95-9F0F-134D99C87AB0} - C:\Programmer\WinAntiVirus Pro 2006\IEFWBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll (file missing)
O3 - Toolbar: Protection Bar - {84938242-5C5B-4A55-B6B9-A1507543B418} - C:\Programmer\Video ActiveX Object\iesplugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NI.UERSK_0001_N86M1207] "C:\Documents and Settings\John  Lauridsen\Dokumenter\ErrorSafeFreeInstall_dk.exe" -nag
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [AntiVermeans] C:\Programmer\AntiVermeans\AntiVermeans.exe /h
O4 - HKLM\..\Run: [Error Safe] C:\Programmer\Error Safe Free\ers.exe /scan
O4 - HKLM\..\Run: [uerscw] C:\Programmer\ErrorSafe Free\uerscw.exe -c
O4 - HKLM\..\Run: [DriveCleaner 2006 Free] "C:\Programmer\DriveCleaner 2006 Free\UDC2006.exe" /min
O4 - HKLM\..\Run: [udc6cw] "C:\Programmer\DriveCleaner 2006 Free\udc6cw.exe" -c
O4 - HKLM\..\Run: [SpyHeals] C:\Programmer\SpyHeals\SpyHeals.exe /h
O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Programmer\WinAntiVirus Pro 2006\WinAV.exe" /min
O4 - HKLM\..\Run: [uwa6pcw] "C:\Programmer\Fælles filer\WinAntiVirus Pro 2006\uwa6pcw.exe" -c
O4 - HKLM\..\Run: [was_check] C:\Programmer\Error Safe Free\WASmon.exe
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Software\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [PestCapture] C:\Program Files\PestCapture\PestCapture.exe
O4 - HKCU\..\Run: [ErrorSafe] "C:\Programmer\Error Safe Free\ers.exe" /scan
O4 - HKCU\..\Run: [updateMgr] "C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ErrorSafeFree] C:\Programmer\ErrorSafe Free\uers.exe /scan
O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Programmer\Video ActiveX Object\isamntr.exe
O4 - HKLM\..\Policies\Explorer\Run: [rare] C:\Programmer\Video ActiveX Object\pmsnrr.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://kn.bar.need2find.com/KN/menusearch.html?p=KN
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155461855156
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155461847156
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Programmer\RXToolBar\sfcont.dll
O21 - SSODL: exemplars - {2acf3add-34a1-4f2f-99cf-cc69785d1e90} - C:\WINDOWS\system32\cwgppb.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: exemplars - {2acf3add-34a1-4f2f-99cf-cc69785d1e90} - C:\WINDOWS\system32\cwgppb.dll
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Boonty Games - BOONTY - C:\Programmer\Fælles filer\BOONTY Shared\Service\Boonty.exe
O23 - Service: Firewall service (FWSvc) - WinSoftware, Ltd. - C:\Programmer\WinAntiVirus Pro 2006\FWSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 9415 bytes
Avatar billede jimjimjam Nybegynder
26. marts 2007 - 21:19 #1
Ingen der kan hjælpe? :(
26. marts 2007 - 22:02 #2
StandBy ...

WinAntiVirus Pro 2006
Video ActiveX Object
ErrorSafe
DriveCleaner 2006 Free
PestCapture

*SUK* Hvad har du dog haft gang i ???
26. marts 2007 - 22:11 #3
1. Runde ->

Download http://siri.urz.free.fr/Fix/SmitfraudFix.exe (by S!Ri)
Til roden af C:drevet

Genstart i fejlsikret tilstand, hvis du ikke ved hvordan så kig her:
http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm

Dobbeltklik på C:\Smitfraud exe. Vælg punkt [2]. Lad programmet gennemføre en rensning. Det vil også checke om systemfilen wininet.dll er inficeret. Hvis den er det, vil du blive bedt om tilladelse til at erstatte den med en anden. Her skal du vælge "Yes", ved at taste "y".

Programmet bliver muligvis nødt til at genstarte undervejs. Herefter vil der dukke en liste med resultaterne af rensningen op . Kopiér denne liste ind i tråden.

Genstart og læg loggen fra SmitfraudFix (C:\rapport.txt) her i tråden...

NB: Filen "process.exe" som ligger i dette værktøj bliver af visse antivirus-programmer identificeret som "RiskTool". Det har dog ikke noget på sig!

-----------------

2. Runde ->
Afinstaller (hvis de er der?)
* Winantiviruspro2006
* DriveCleaner 2006 Free
* PestCapture
* Errorsafe
* AntiVermeans
* Boonty Games
* SpyHeals
via
[Start][Indstilninger][Kontrolpanel][Tilføj/fjern programmer]

Genstart for at fuldføre afinstalationen...

---------------------------------------

Og en efterfølgende frisk HiJackThis Log ... som lægges i denne tråd ... som sagt/skrevet sammen med ovenstående C:\rapport.txt

---------------------------------------
Avatar billede jimjimjam Nybegynder
26. marts 2007 - 22:14 #4
dr1 --> Jeg vil lige gøre opmærksom på at jeg laver den for en af min families kammerater :pp så har ikke noget med det at gøre ;)

Jeg går i gang nu!
26. marts 2007 - 22:22 #5
PS: Her er historien om [Errorsafe] og den famillie -> http://www.grineflip.dk/support/errorsafe - *S*
Avatar billede jimjimjam Nybegynder
26. marts 2007 - 22:28 #6
1 log til dig:

SmitFraudFix v2.157

Scan done at 22:22:32,90, ma 26-03-2007
Run from C:\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{2acf3add-34a1-4f2f-99cf-cc69785d1e90}"="exemplars"

[HKEY_CLASSES_ROOT\CLSID\{2acf3add-34a1-4f2f-99cf-cc69785d1e90}\InProcServer32]
@="C:\WINDOWS\system32\cwgppb.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2acf3add-34a1-4f2f-99cf-cc69785d1e90}\InProcServer32]
@="C:\WINDOWS\system32\cwgppb.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1      localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\cwgppb.dll -> Hoax.Win32.Renos.gen.i
C:\WINDOWS\system32\cwgppb.dll -> Deleted


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOCUME~1\ALLUSE~1\MENUEN~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\MENUEN~1\Security Troubleshooting.url Deleted
C:\DOCUME~1\ALLUSE~1\SKRIVE~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\SKRIVE~1\Security Troubleshooting.url Deleted
C:\Programmer\AntiVermeans\ Deleted
C:\Programmer\SpyHeals\ Deleted
C:\Programmer\Video ActiveX Object\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
Avatar billede jimjimjam Nybegynder
26. marts 2007 - 22:34 #7
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:33:22, on 26-03-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Programmer\WinAntiVirus Pro 2006\WinAV.exe
C:\Programmer\Fælles filer\WinAntiVirus Pro 2006\uwa6pcw.exe
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\Program Files\PestCapture\PestCapture.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
E:\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CIEIntegrator Object - {2178F3FB-2560-458F-BDEE-631E2FE0DFE4} - C:\Programmer\WinAntiVirus Pro 2006\winpgi.dll
O2 - BHO: (no name) - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll (file missing)
O2 - BHO: IEFW Object - {B5141620-C2B2-4D95-9F0F-134D99C87AB0} - C:\Programmer\WinAntiVirus Pro 2006\IEFWBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NI.UERSK_0001_N86M1207] "C:\Documents and Settings\John  Lauridsen\Dokumenter\ErrorSafeFreeInstall_dk.exe" -nag
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Programmer\WinAntiVirus Pro 2006\WinAV.exe" /min
O4 - HKLM\..\Run: [uwa6pcw] "C:\Programmer\Fælles filer\WinAntiVirus Pro 2006\uwa6pcw.exe" -c
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Software\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [PestCapture] C:\Program Files\PestCapture\PestCapture.exe
O4 - HKCU\..\Run: [ErrorSafe] "C:\Programmer\Error Safe Free\ers.exe" /scan
O4 - HKCU\..\Run: [updateMgr] "C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ErrorSafeFree] C:\Programmer\ErrorSafe Free\uers.exe /scan
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://kn.bar.need2find.com/KN/menusearch.html?p=KN
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155461855156
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155461847156
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Programmer\RXToolBar\sfcont.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Boonty Games - BOONTY - C:\Programmer\Fælles filer\BOONTY Shared\Service\Boonty.exe
O23 - Service: Firewall service (FWSvc) - WinSoftware, Ltd. - C:\Programmer\WinAntiVirus Pro 2006\FWSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 7832 bytes
26. marts 2007 - 22:43 #8
Tju hej hvor det går *S* - foreløbig som det skal *S*

3. Runde ->
---------------------------------------------------------------------

Hent denne engangsscanner:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe  (Gem programmet på skrivebordet, så du let kan finde det til senere brug)

Hvis din firewall blokerer for ftp adresser, kan du hente programmet her:
http://spywareinfo.dk/download/drweb-cureit.exe
(Du skal ikke aktivere den endnu)
---------------------------------------------------------------------

Download free Trial af SuperAntiSpyware Proff til Skrivebordet, http://www.superantispyware.com/downloads/SUPERAntiSpyware1241.exe
Installer den, og lad den opdatere med nyeste opdateringer.
Så vil den spørge om din mail adresse, det er op til dig selv om du vil udfylde det.Tryk så på Næste og Næste igen - Udfør.
Dansk vejledning  http://www.spywarefri.dk/manualer/superantispyware-manual.htm
(Du skal ikke aktivere den endnu)
---------------------------------------------------------------------

Genstart i fejlsikret tilstand http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm
---------------------------------------------------------------------

DrWeb - Dobbeltklik på cureit exe filen laver den en kort startup/express scan.
Lad den fixe hvad den finder (Say Yes to all)
Derefter skal du klikke på Options -> Change settings.
Skift til fanebladet Scan, fjern fluebenet ved Heuristic analysis.
Skift til fanebladet Actions, her skal alle punkter under Malware sættes til Move.
Fjern flueben ved - Prompt on action.
Ved Move Path sletter du hvad der står, og skriver: c:\infected
Tryk på Anvend og derefter på OK.

Klik så på det eller de drev du vil have scannet, der kommer en  rød prik  for at vise det/de er valgt.
Tryk så på den grønne pil  nederst  til højre, så scanner den, og fixer problemerne.

Når scanningen er færdig, gå op i file - Tryk på - Save Report list.
Så ligger der en en fil der her hedder drweb.csv (åbnes med Notebook/Notepad - på skrivebordet.
Luk Programmet
---------------------------------------------------------------------

Start superantispyware ved at højreklikke på den gule og sorte bille ved uret

Tryk på - Scan for, Adware,Malware - linjen
Tryk på - Preference - Knappen.
Fjern flueben ved - Start SuperAntiSpyware when Windows starts.

Tryk på Fanebladet - Scanning control.
Ved scanning options, skal der kun være flueben i de to nederste
Fanebladet - Real Time Protections. Fjerner du fluben ved - Enable Real Time Protection
Tryk så på Close

Tryk på - Scan Your computer - Knappen. sæt flueben ved de drev der skal scannes. Det er vigtigt at drev hvor Windows (systemdrevet) ligger, har et flueben.
Flyt så prikken ved - Perform quick Scan, ned til - Perform complete Scan.
Tryk på Næste, så går den i gang med at scanne.

Det kan godt tage lang tid hvis du har meget på computeren

Når scanninngen er færdig popper der en boks op, tryk OK.
Sæt flueben ved alt den har fundet - næste. Så vil den fixe/slette infektionerne.

Lad den genstarte.
---------------------------------------------------------------------

Efter genstart -

Åben SuperAntiSpyware igen
Tryk på Preferences, vælg Statistics/Logs
Marker loggen i det lille vindue og tryk på View Log.
Kopier teksten herind sammen med loggen fra DrWeb (drweb csv)

Sammen med en frisk Log fra HiJackThis...
Avatar billede jimjimjam Nybegynder
26. marts 2007 - 23:19 #9
Jeg kan ikke installere drweb-cureit fordi den mener at min licens nøgle er brugt op!?!
26. marts 2007 - 23:21 #10
(Så la' den hvile...)
Avatar billede jimjimjam Nybegynder
27. marts 2007 - 18:18 #11
SUPERAntiSpyware Scan Log
Generated 03/27/2007 at 02:20 AM

Application Version : 3.5.1016

Core Rules Database Version : 3207
Trace Rules Database Version: 1217

Scan type      : Complete Scan
Total Scan Time : 02:53:37

Memory items scanned      : 155
Memory threats detected  : 0
Registry items scanned    : 4900
Registry threats detected : 1143
File items scanned        : 33578
File threats detected    : 568

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007
    [WinAntiVirusPro2006] C:\PROGRAMMER\WINANTIVIRUS PRO 2006\WINAV.EXE
    C:\PROGRAMMER\WINANTIVIRUS PRO 2006\WINAV.EXE
    HKCR\AVExplorer.ShellExtension
    HKCR\AVExplorer.ShellExtension\CLSID
    HKCR\AVExplorer.ShellExtension\CurVer
    HKCR\AVExplorer.ShellExtension.2
    HKCR\AVExplorer.ShellExtension.2\CLSID
    HKCR\WAP6.PCheck
    HKCR\WAP6.PCheck\CLSID
    HKCR\WAP6.PCheck\CurVer
    HKCR\WAP6.PCheck.1
    HKCR\WAP6.PCheck.1\CLSID
    HKCR\WinPGIntegrator.IEIntegrator
    HKCR\WinPGIntegrator.IEIntegrator\CLSID
    HKCR\WinPGIntegrator.IEIntegrator\CurVer
    HKCR\WinPGIntegrator.IEIntegrator.1
    HKCR\WinPGIntegrator.IEIntegrator.1\CLSID
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}#AppID
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\InprocServer32
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\InprocServer32#ThreadingModel
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\ProgID
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\Programmable
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\TypeLib
    HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\VersionIndependentProgID
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}#AppID
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\InprocServer32
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\InprocServer32#ThreadingModel
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\ProgID
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\Programmable
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\TypeLib
    HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\VersionIndependentProgID
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable
    HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS
    HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\0
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\0\win32
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\FLAGS
    HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\HELPDIR
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\0
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\0\win32
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\FLAGS
    HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\HELPDIR
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\ProxyStubClsid
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\ProxyStubClsid32
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\TypeLib
    HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\TypeLib#Version
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib
    HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version
    HKCR\AppId\WinPGI.DLL
    HKCR\AppId\WinPGI.DLL#AppID
    HKCR\AppId\{367A86A5-D048-4785-86BE-4E2706AAFDD9}
    HKU\S-1-5-21-1844237615-1770027372-682003330-1004\Software\WinAntiVirus Pro 2006
    HKLM\Software\WinAntiVirus Pro 2006
    HKLM\Software\WinAntiVirus Pro 2006#EulUWA6PK_0001_N91M2107
    HKLM\Software\WinAntiVirus Pro 2006#ProductCode
    HKLM\Software\WinAntiVirus Pro 2006#InstallDate
    HKLM\Software\WinAntiVirus Pro 2006#InstallPath
    HKLM\Software\WinAntiVirus Pro 2006#Abbr
    HKLM\Software\WinAntiVirus Pro 2006#ActivationCode
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: Setup Version
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: App Path
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#InstallLocation
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: Icon Group
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: User
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#DisplayName
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#UninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#QuietUninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Publisher
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#URLInfoAbout
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#HelpLink
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#URLUpdateInfo
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#NoModify
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#NoRepair
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Type
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Start
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#ErrorControl
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Tag
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#ImagePath
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#DisplayName
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Group
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Overflow
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\WA6P
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[3].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[4].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[7].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[6].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[5].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[12].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[10].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[11].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[15].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[14].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[13].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[17].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[16].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[19].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[18].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[22].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[21].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[20].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[23].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[25].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[24].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[27].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[26].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[29].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[28].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[31].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[30].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[33].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[32].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[34].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[36].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[35].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[38].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[37].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[40].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[39].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[42].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[41].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[44].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[43].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[45].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[46].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[47].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[48].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[50].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[49].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[51].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[53].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[52].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[54].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[55].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[56].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[57].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[58].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[59].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[61].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[60].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[62].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[63].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[65].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[64].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[66].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[67].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[68].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[70].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[69].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[71].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[72].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[74].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[73].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[76].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[75].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[77].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[79].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[78].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[80].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[82].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[81].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[83].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[84].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[85].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[87].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[86].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[89].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[88].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[90].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[92].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[91].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[93].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[94].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[95].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[97].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[96].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[98].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA236XAP.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@ADVERTISING[99].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAOCWPKV.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASPQJ8N.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CALFFH8W.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA2DQNMH.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAI1SD0H.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWX6BS5.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA8VQDUF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUV89MV.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWD67CD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAXQNFD2.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CALO07P1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUF4LE7.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAGT6XBO.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAIVIRAT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA41UPD2.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWH2B4T.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAZQXSLV.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CATW6PXB.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA1GSVD9.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAEJK9UN.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAJKT1VC.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CATOXS91.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA4LQVS5.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CACQ8PGZ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CABQJA7X.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA291LGQ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAF583LD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA89CXE3.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA69E9OT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAY3OJYN.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAXH09J4.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA0FADMF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA0O0QIS.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUBK50F.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA27VB21.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMAW6BQ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA3QQDNF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAI0Y2PL.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAM7ELT3.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMBS5AF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CADBJJB0.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA0DAFSP.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA5HJB7F.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUJ4TEV.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUVGPZT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQVKXAF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASLIRG1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAA13UFR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA0EGVDQ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMSGTN6.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA8XV9DA.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAIAS23Q.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMVCPER.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKFOVI1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQMTL4W.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAZ79115.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAT01Y4W.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAJWWZOR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAC50UFR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAPOWB9T.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAIZOLIJ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAIIA4RD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAK5UBSD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA075VM6.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA3JH5KA.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAX1ZBYS.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA6ZC9YR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQ7CB56.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAPDFMC1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA4D278X.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAEZYNQ9.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAIWAVQT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASXU9R4.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CARX5UQ3.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQ9I7AT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAA63BP4.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAHY3ZLE.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAE9HDW6.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CATJB571.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAIFGH2V.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAGZUBA2.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAM0P8KU.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CACPUZO9.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWPYR0T.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CACLY2N7.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA6F0P6J.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMVWLML.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA5QGBG7.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKTYVSX.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQVQODP.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAOPENS1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA2BWXK9.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAFQ4FN9.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA6VGPAH.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA5YB3X6.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA5ZB935.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@HIT.GEMIUS[2].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@HIT.GEMIUS[1].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWXEN8T.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASALEMEDIA[1].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@FASTCLICK[3].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@FASTCLICK[2].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@FASTCLICK[1].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASALEMEDIA[5].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASALEMEDIA[4].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASALEMEDIA[3].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASALEMEDIA[2].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@AS1.FALKAG[3].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@AS1.FALKAG[2].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@AS1.FALKAG[1].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@STATSE.WEBTRENDSLIVE[1].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@STATSE.WEBTRENDSLIVE[2].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@STATSE.WEBTRENDSLIVE[3].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@HIT.GEMIUS[3].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAEZODAV.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAJV1T4I.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMF41IL.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKX6X5A.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAF2WFZ9.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAJUMHNJ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA1WJAFH.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA85UBGT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA12VVX2.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUX43MT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAK1I7CL.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA8PI30L.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQN05AN.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKHIPP2.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA6JG5UF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAL83A3Z.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAI705Y3.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA6NO16H.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA2TWPU3.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA7ARU3J.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAG3XJU6.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAFRLGU5.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUOYEHH.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAM363EH.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA766LZV.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA6RS3XU.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAI94NWR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAZQT4XL.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA09EZQZ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CALWMLPN.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKHUPVC.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA6VYF6H.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA6V4L6N.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAYJG338.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQJ4XQV.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA5876F9.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAIR01IF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAV6PKX3.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA81QTJW.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CATKWF9T.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@OVERTURE[3].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@OVERTURE[2].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@OVERTURE[1].TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKDIB8P.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWLELZ0.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CACFMTA5.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CABED4P3.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQNS1I7.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAGHMZC1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAL3F5CK.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKFJVI8.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKXQNOF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAU1154M.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA69UV6D.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAS5XQR2.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAW1UBG1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA7LDEAJ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA67W5UN.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKPE7KD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUV45AN.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA2AKYAR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAIJK1M1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CANAXWLP.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWDIVAF.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAS1Q38H.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CARZRDS4.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAJUX8HJ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAYBSH41.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQLGFYP.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAINGDM7.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\LOKALE INDSTILLINGER\TEMPORARY INTERNET FILES\CONTENT.IE5\SLO96781\XPLADV630[1].WMF
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAODYV8H.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAZJ9L82.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAHURTT2.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA9G0RTD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAN7P58Q.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA4XAVWH.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA2BK1AZ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA34DHZW.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASJA54N.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA51JBUK.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CARU1G5T.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAGDIFUR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAYJ018H.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAY3GFJ0.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMV4LQN.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMBW9I3.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASXMFAR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA492FK5.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAGXYRKZ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMF89AB.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKFYVSP.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAMVW16Z.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CACL2BSD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQJSTQJ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAM9YPK5.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA2BK1AX.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA8T8PKB.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA5J1142.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAF5NJIC.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAUFK5UB.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAVLXOCN.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA81C747.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CARN5LGE.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAOLE38L.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CABTHVX7.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA4LOBWB.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAFN5XKE.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAL8B2R1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA77D9XL.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAYTN14S.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAP2RJH6.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQB0DQB.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA674T2X.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWHU5HM.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAH53JUW.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CANMLO1P.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAEBWRF8.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAPZR5FD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAHCFIVJ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAYFWPU5.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA85QL9Y.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA5Z75R9.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAU8DB3I.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA2V09I7.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQAMRMD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAARWXIP.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA4DUXJW.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAYF0LYD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKVI50Z.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA0FTZUQ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA9T9JIY.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA2DM58T.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKLMBKT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA4XABCL.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA1W32NB.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAYFGX81.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAWXU7OH.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAQPTL0Q.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA8PIN0X.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CANXH7XZ.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAE8X7BI.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAI7S9WD.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAW72HQT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA8B6P0R.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA8PYNGT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CANBR1KO.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKVW3Y7.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAAJC527.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAHSREB1.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAI30TKX.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA7QCZZT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAW9U74P.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAW7UDQT.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CABMH85V.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAFST770.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAEEYFYX.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAOBUBOR.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAVXT72E.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CACZ6DAH.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CASBZJMS.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CA89A7W5.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAYZOL6B.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\JOHN  LAURIDSEN\COOKIES\JOHN  LAURIDSEN@CAKL6J0V.TXT
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AN
Avatar billede jimjimjam Nybegynder
27. marts 2007 - 18:21 #12
Det som om den ikke vil uppe hele loggen!

den er her : http://hybbe.dk/UL/updir/spy.txt
27. marts 2007 - 19:00 #13
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 18:17:22, on 27-03-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe
C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Programmer\Support.com\bin\tgcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\John  Lauridsen\Skrivebord\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Software\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [ErrorSafe] "C:\Programmer\Error Safe Free\ers.exe" /scan
O4 - HKCU\..\Run: [updateMgr] "C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ErrorSafeFree] C:\Programmer\ErrorSafe Free\uers.exe /scan
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://kn.bar.need2find.com/KN/menusearch.html?p=KN
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155461855156
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155461847156
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Boonty Games - BOONTY - C:\Programmer\Fælles filer\BOONTY Shared\Service\Boonty.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 7159 bytes
27. marts 2007 - 19:06 #14
Jooo - der blev ædt en del *S*

4. Runde ->

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: (no name) - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ErrorSafe] "C:\Programmer\Error Safe Free\ers.exe" /scan
O4 - HKCU\..\Run: [updateMgr] "C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ErrorSafeFree] C:\Programmer\ErrorSafe Free\uers.exe /scan
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://kn.bar.need2find.com/KN/menusearch.html?p=KN
O8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll

For at kunne se alle filer og mapper, så følg denne vejledning:
http://www.spywareinfo.dk/tip-og-tricks/mappeindstillinger.htm

Genstart i fejlsikret tilstand http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm

Søg og slet de markerede filer/mapper hvis de stadig findes. Ellers fortsætter du bare vejledningen. De kan være røget i fixet.

C:\Programmer\Yahoo!\ <- Hele mappen
C:\Programmer\Error Safe Free\ <- Hele mappen

Genstart, kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.

------------------------------------------------------------------------
Avatar billede jimjimjam Nybegynder
27. marts 2007 - 20:30 #15
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 20:30:02, on 27-03-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rmctrl.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LXSUPMON.EXE
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\John  Lauridsen\Skrivebord\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [hcenter] "C:\Programmer\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Software\BullGuard\bullguard.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155461855156
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155461847156
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Boonty Games - BOONTY - C:\Programmer\Fælles filer\BOONTY Shared\Service\Boonty.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 4347 bytes
28. marts 2007 - 07:45 #16
5. Runde ->

Så er du snart 'i hus'  *S*

Klik på Start->Kør skriv Services.msc og klik OK.
Find Tjenesten
* Boonty Games - BOONTY
stop den hvis den kører, højreklik på den og vælg Starttype Deaktiveret.

---------------------------------------------------------------

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er denne, som skal fixes:

O23 - Service: Boonty Games - BOONTY - C:\Programmer\Fælles filer\BOONTY Shared\Service\Boonty.exe

Genstart i fejlsikret tilstand

Søg og slet de markerede filer/mapper hvis de stadig findes. Ellers fortsætter du bare vejledningen. De kan være røget i fixet.

C:\Programmer\Fælles filer\BOONTY Shared\ <- Hele mappen

---------------------------------------------------------------

RegBase oprydning kan anbefales ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Problemer]...)

Fraklik Yahoo Toolbar under instalationen !!!

---------------------------------------------------------------

Slut af med en frisk HiJackThis Log...
Avatar billede jimjimjam Nybegynder
01. april 2007 - 14:41 #17
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 14:40:43, on 01-04-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rmctrl.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\sistray.exe
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\John  Lauridsen\Skrivebord\HiJackThis_v2.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Software\BullGuard\bullguard.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155461855156
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155461847156
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 4371 bytes
01. april 2007 - 19:28 #18
6 (sidste) Runde -> Oprydning ->

Du ka' lige 'fixe' disse via HiJackThis:

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe


Normal genstart...

Fortæl hvor PC'en så kører nu ?
08. april 2007 - 16:30 #19
???
Avatar billede jimjimjam Nybegynder
01. maj 2007 - 18:21 #20
Hej Dr1 ! Undskyld mange gange min sene udmelding ! Har haft ferie!

Jeg har afleveret maskinen efter din sidste log!

Den kører perfekt! TAK ! Tusind tak!

Læg et svar :)
02. maj 2007 - 02:05 #21
Ping...

Der er ikke mere 'snavs' ifølge din Log...

Du er velkommen en anden gang...

Åbn en mappe, klik på Funktioner >Mappeindstillinger >Vis.
Sæt flueben ved "Skjul beskyttede operativsystemfiler".
Sæt prik i "Vis ikke skjulte filer og mapper".

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Safe Surfing...
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester