Avatar billede sirus Nybegynder
25. december 2007 - 20:58 Der er 34 kommentarer

Doctor Watson Postmortem Debugger - nu er min computer ustabil

Hej.

Indtil for to dage siden, kørte min computer fejlfrit.

Medens at jeg sad på nettet kom der pludseligt en besked indeholdende ordene "Doctor Watson Postmortem Debugger" og siden da har min computer været ustabil i alle faser (under opstart hvor det til tider slet ikke lykkedes at komme på nettet, når jeg er på nettet er det helt sikkert at min computer fryser efter at jeg har åbnet ca. 2-3 websteder, når jeg skal lukke ned tager det en evighed).

Jeg har ingen forstand på fejlfinding overhovedet; men vil i den grad være taknemmelig, hvis jeg kunne få hjælp fra Jer.

Jeg vedlægger loggen fra "Hijackthis" ... har én eller anden fornemmelse af, at I evt. skal bruge den.

De venligste tanker,
Sirus

-----------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 20:32:12, on 25-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Ultimate Defender\UltimateDefender  .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ultimate Cleaner\UltimateCleaner.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon .exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray .exe
C:\Program Files\Ultimate Defender\UltimateDefender  .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\Ultimate Cleaner\UltimateCleaner .exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\MotionBased\Agent\MBAgent.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Zapu\Zapu\wDivi.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
R3 - URLSearchHook: AstroburnBar Toolbar - {e802027b-1f2b-40bd-b307-0bd96d036835} - C:\Program Files\AstroburnBar\tbAst0.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AstroburnBar Toolbar - {e802027b-1f2b-40bd-b307-0bd96d036835} - C:\Program Files\AstroburnBar\tbAst0.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp        .exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask          .exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [xahebmtk] rundll32.exe "C:\Program Files\hqhqlavm\pcbkfaxw.dll",Init
O4 - HKLM\..\Run: [shcluheb] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\shcluheb.dll"
O4 - HKLM\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\UltimateDefender  .exe" hide
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr          .Exe" /background
O4 - HKCU\..\Run: [] 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Ultimate Cleaner] "C:\Program Files\Ultimate Cleaner\UltimateCleaner.exe" hide
O4 - HKCU\..\Run: [Forbrugerpenge] "C:\Program Files\The Internet Marketing Center\Desktop Marketer 3\Readers\438\519\Forbrugerpenge.exe"
O4 - Startup: .protected
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: MotionBased Agent.lnk = C:\Program Files\MotionBased\Agent\MBAgent.exe
O4 - Startup: Zapu Acceleration Engine.lnk = C:\Program Files\Zapu\Zapu\wincm.exe
O4 - Startup: Zapu.lnk = C:\Program Files\Zapu\Zapu\wDivi.exe
O4 - Global Startup: .protected
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6452e9228ac0414ab1ac7481f2350f0d
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6452e9228ac0414ab1ac7481f2350f0d
O9 - Extra button: (no name) - SOFTWARE - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bl103fd.blu103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
25. december 2007 - 21:12 #1
Jo tak - den er også gal !!!

... Nu er der ikke alle (u)ønskede elementer som viser sig med en HiJackThis Log; hvis du har 'mod' på det så gennemfør proceduren herfra -> http://www.eksperten.dk/artikler/1123
25. december 2007 - 21:13 #2
Velkommen til Eksperten.dk
Generelt > http://expfaq.dk/
Avatar billede sirus Nybegynder
25. december 2007 - 23:44 #3
Hej.

Først og fremmest tusind tak, fordi du har tagettid til at hjælpe mig.

Jeg har gjort som foresagt - og log-filerne ser ud som følger:

Logfile of HijackThis v1.99.1
Scan saved at 23:38:21, on 25-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp          .exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp          .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\Windows Live\Messenger\MsnMsgr            .Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon .exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
C:\Program Files\Windows Live\Messenger\MsnMsgr            .Exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\MotionBased\Agent\MBAgent.exe
C:\Program Files\Zapu\Zapu\wDivi.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp          .exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask              .exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [shcluheb] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\shcluheb.dll"
O4 - HKLM\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\UltimateDefender    .exe" hide
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr            .Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Ultimate Cleaner] "C:\Program Files\Ultimate Cleaner\UltimateCleaner.exe" hide
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: .protected
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: MotionBased Agent.lnk = C:\Program Files\MotionBased\Agent\MBAgent.exe
O4 - Startup: Zapu Acceleration Engine.lnk = C:\Program Files\Zapu\Zapu\wincm.exe
O4 - Startup: Zapu.lnk = C:\Program Files\Zapu\Zapu\wDivi.exe
O4 - Global Startup: .protected
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6452e9228ac0414ab1ac7481f2350f0d
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6452e9228ac0414ab1ac7481f2350f0d
O9 - Extra button: (no name) - SOFTWARE - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bl103fd.blu103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

---------------------------

********************************* ROOTCHK-(5-12-07)-LOG, by ejvindh
25-12-2007 23:40:38,90

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 23:40:41
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...

scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:2d,23,e9,65,f4,ec,f7,cd,c1,64,e2,07,a2,91,8d,42,f1,6b,f1,44,3b,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:2d,23,e9,65,f4,ec,f7,cd,c1,64,e2,07,a2,91,8d,42,f1,6b,f1,44,3b,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:4fc02f53
"s2"=dword:cd2fcb2c
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:2d,23,e9,65,f4,ec,f7,cd,c1,64,e2,07,a2,91,8d,42,f1,6b,f1,44,3b,..

scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000284

scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0

----------------------------

Jeg sender log-filen fra COMBOFIX om lidt (når jeg har kørt programmet).

P.S: Der fremkom ikke umiddelbart nogen log-fil fra SuperAntiSpyware...

Mvh.
Sirus
Avatar billede sirus Nybegynder
26. december 2007 - 00:03 #4
Hej igen.

Her kommer logfilen fra COMBOFIX:

----------------------

ComboFix 07-12-21.4 - HP_Administrator 2007-12-25 23:47:10.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.500 [GMT 1:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\December 2007\ComboFix.exe
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\.protected
C:\Documents and Settings\All Users\Start Menu\Programs.\Ultimate Defender
C:\Documents and Settings\All Users\Start Menu\Programs.\Ultimate Defender\Ultimate Defender.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender.lnk
C:\Documents and Settings\HP_Administrator\Application Data\microsoft\internet explorer\quick launch\Start UltimateCleaner 2007.lnk
C:\Documents and Settings\HP_Administrator\Desktop\Ultimate Cleaner 2007.lnk
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\.protected
C:\WINDOWS\.protected
C:\WINDOWS\PerfInfo
C:\WINDOWS\system32\_000003_.tmp.dll
C:\WINDOWS\system32\_000004_.tmp.dll
C:\WINDOWS\system32\_000005_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\_000011_.tmp.dll
C:\WINDOWS\system32\_000012_.tmp.dll
C:\WINDOWS\system32\drivers\etc\.protected
C:\WINDOWS\system32\prqss.ini
C:\WINDOWS\system32\prqss.ini2
C:\WINDOWS\system32\ssqrp.dll
D:\Autorun.inf

.
(((((((((((((((((((((((((  Files Created from 2007-11-25 to 2007-12-25  )))))))))))))))))))))))))))))))
.

2007-12-25 23:14 . 2007-12-25 23:14    326,656    --a------    C:\WINDOWS\system32\RCX33.tmp
2007-12-25 21:59 . 2007-12-25 23:47    <DIR>    d--------    C:\Program Files\SUPERAntiSpyware
2007-12-25 21:59 . 2007-12-25 21:59    <DIR>    d--------    C:\Documents and Settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2007-12-25 21:59 . 2007-12-25 21:59    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-25 21:58 . 2007-12-25 21:58    <DIR>    d--------    C:\Program Files\Common Files\Wise Installation Wizard
2007-12-25 21:20 . 2007-12-25 21:20    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-25 21:11 . 2007-12-25 21:11    <DIR>    d--------    C:\Program Files\Yahoo!
2007-12-25 21:11 . 2007-12-25 21:11    <DIR>    d--------    C:\Program Files\CCleaner
2007-12-25 20:41 . 2007-12-25 20:41    326,656    --a------    C:\WINDOWS\system32\RCX48.tmp
2007-12-25 20:16 . 2007-12-25 20:16    326,656    --a------    C:\WINDOWS\system32\RCX70.tmp
2007-12-25 13:24 . 2007-12-25 13:24    326,656    --a------    C:\WINDOWS\system32\RCX6D.tmp
2007-12-23 21:45 . 2007-12-23 21:45    143    --a------    C:\WINDOWS\system32\mcrh.tmp
2007-12-23 21:14 . 2007-12-23 21:14    326,656    --a------    C:\WINDOWS\system32\RCX66.tmp
2007-12-23 21:14 . 2007-12-25 22:17    15,360    --a------    C:\WINDOWS\system32\ctfmon .exe
2007-12-23 20:59 . 2007-12-24 09:34    <DIR>    d--------    C:\VIRUSfighter
2007-12-23 20:41 . 2007-12-23 20:49    <DIR>    d--------    C:\Program Files\RegistryFix
2007-12-23 19:18 . 2007-10-11 00:55    6,065,664    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-23 19:18 . 2007-07-01 04:31    2,455,488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-23 19:18 . 2007-07-01 04:36    991,232    ---------    C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-23 19:18 . 2007-10-11 00:55    459,264    ---------    C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-23 19:18 . 2007-10-11 00:55    383,488    ---------    C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-23 19:18 . 2007-10-11 00:55    267,776    ---------    C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-23 19:18 . 2007-10-11 00:55    63,488    ---------    C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-23 19:18 . 2007-10-11 00:55    52,224    ---------    C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-23 19:18 . 2007-10-10 11:59    13,824    ---------    C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-23 17:37 . 2007-12-25 21:36    155,648    --a------    C:\WINDOWS\system32\NeroCheck .exe
2007-12-23 17:25 . 2007-12-25 23:47    326,656    --a------    C:\WINDOWS\system32\ssqrp.exe
2007-12-23 17:23 . 2007-12-23 17:23    <DIR>    d--------    C:\WINDOWS\ppqvmpqr
2007-12-23 17:23 . 2007-12-23 21:19    <DIR>    d--------    C:\Program Files\Extaanhg
2007-12-23 17:06 . 2007-12-24 09:20    <DIR>    d--------    C:\Program Files\hqhqlavm
2007-12-14 20:58 . 2007-12-14 20:58    <DIR>    d--------    C:\Program Files\Microsoft SQL Server Compact Edition
2007-12-14 20:58 . 2007-12-14 20:58    268    --ah-----    C:\sqmdata19.sqm
2007-12-14 20:58 . 2007-12-14 20:58    244    --ah-----    C:\sqmnoopt19.sqm
2007-12-14 20:57 . 2007-12-14 20:57    268    --ah-----    C:\sqmdata18.sqm
2007-12-14 20:57 . 2007-12-14 20:57    244    --ah-----    C:\sqmnoopt18.sqm
2007-12-14 20:51 . 2007-12-14 21:00    <DIR>    d--------    C:\Program Files\Windows Live
2007-12-14 20:51 . 2007-12-14 20:54    <DIR>    d--hsc---    C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-14 20:50 . 2007-12-14 20:50    <DIR>    d--------    C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-11 16:47 . 2007-12-11 18:29    <DIR>    d--------    C:\Program Files\GameShadow
2007-12-11 16:42 . 2007-12-11 18:30    <DIR>    d--------    C:\Program Files\Turtle Games
2007-11-28 17:48 . 2007-11-28 17:48    268    --ah-----    C:\sqmdata17.sqm
2007-11-28 17:48 . 2007-11-28 17:48    244    --ah-----    C:\sqmnoopt17.sqm
2007-11-26 17:43 . 2006-11-29 13:06    3,426,072    --a------    C:\WINDOWS\system32\d3dx9_32.dll
2007-11-26 17:43 . 2006-12-08 12:02    251,672    --a------    C:\WINDOWS\system32\xactengine2_5.dll
2007-11-26 17:41 . 2007-11-26 19:43    <DIR>    d--------    C:\Program Files\Agent Hugo - Operation Lemoon Twist

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 22:47    ---------    d-----w    C:\Program Files\QuickTime
2007-12-25 22:47    ---------    d-----w    C:\Program Files\iTunes
2007-12-25 22:47    ---------    d-----w    C:\Program Files\HP DigitalMedia Archive
2007-12-25 20:47    ---------    d-----w    C:\Program Files\Ubisoft
2007-12-25 20:47    ---------    d-----w    C:\Program Files\AstroburnBar
2007-12-25 20:44    ---------    d-----w    C:\Program Files\Dvd-to-dvdr
2007-12-25 20:37    ---------    d-----w    C:\Program Files\Ahead
2007-12-25 20:35    ---------    d--h--w    C:\Program Files\InstallShield Installation Information
2007-12-25 20:35    ---------    d-----w    C:\Program Files\Pixeline
2007-12-25 20:35    ---------    d-----w    C:\Program Files\Magnus & Myggen - På skattesjov
2007-12-25 20:33    ---------    d-----w    C:\Program Files\Game-Cloner
2007-12-25 20:33    ---------    d-----w    C:\Program Files\Activision
2007-12-25 20:30    ---------    d-----w    C:\Program Files\Cute CD DVD Burner
2007-12-25 20:29    ---------    d-----w    C:\Program Files\BitLord
2007-12-25 20:29    ---------    d-----w    C:\Program Files\Azureus
2007-12-25 20:26    ---------    d-----w    C:\Program Files\Alcohol Toolbar
2007-12-23 20:13    ---------    d-----w    C:\Program Files\Norton AntiVirus
2007-12-23 20:13    ---------    d-----w    C:\Program Files\Common Files\Symantec Shared
2007-12-23 20:13    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-23 19:56    ---------    d-----w    C:\Program Files\Symantec
2007-12-23 16:48    ---------    d-----w    C:\Program Files\Norton Security Scan
2007-12-23 16:17    ---------    d-----w    C:\Documents and Settings\HP_Administrator\Application Data\Azureus
2007-12-01 09:36    ---------    d-----w    C:\Program Files\Windows Live Toolbar
2007-11-13 10:25    20,480    ----a-w    C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 15:52    ---------    d-----w    C:\Program Files\LEGO Media
2007-11-10 15:48    ---------    d-----w    C:\Program Files\Elaborate Bytes
2007-11-10 15:44    ---------    d-----w    C:\Program Files\MagicDisc
2007-11-10 15:38    ---------    d-----w    C:\Documents and Settings\HP_Administrator\Application Data\Astroburn
2007-11-10 15:34    685,816    ----a-w    C:\WINDOWS\system32\drivers\sptd.sys
2007-10-28 16:55    ---------    d-----w    C:\Program Files\Diego`s Dinosaur Adventure
2007-10-23 16:49    586,240    ----a-w    C:\WINDOWS\WLXPGSS.SCR
2007-10-21 23:00    13,195    ----a-w    C:\zguicfgw.dat
2007-06-12 20:45    47,344    ----a-w    C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2007-06-04 16:46    166    ----a-w    C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{52B50F01-24B6-4806-9AA9-F5DFA7900209}]
2007-12-25 23:57    323072    --a------    C:\WINDOWS\system32\ssqrp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-25 23:58]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr            .exe" [2007-12-25 23:58]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 22:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-12-25 23:58]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ftutil2"="ftutil2.dll" [2004-06-07 15:05 C:\WINDOWS\system32\ftutil2.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 17:56 C:\WINDOWS\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 01:19 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-09 22:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2006-06-20 18:06 C:\WINDOWS\system32\nwiz.exe]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2007-12-25 23:14]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2007-12-25 23:58]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp          .exe" [2007-12-25 23:14]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2007-12-25 23:14]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-25 23:58]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-12-25 23:14]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-12-25 22:15]
"QuickTime Task"="C:\Program Files\QuickTime\qttask              .exe" [2007-12-25 23:59]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-25 23:14]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-25 23:14]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-12-25 23:14]
"VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2007-12-25 23:14]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-11-10 16:03:29]
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-11-10 16:03:29]

C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2007-11-10 16:43:54]
MotionBased Agent.lnk - C:\Program Files\MotionBased\Agent\MBAgent.exe [2006-12-30 09:18:46]
Zapu Acceleration Engine.lnk - C:\Program Files\Zapu\Zapu\wincm.exe [2007-04-20 21:26:54]
Zapu.lnk - C:\Program Files\Zapu\Zapu\wDivi.exe [2007-04-20 21:26:54]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Hurtigstart.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
"{2B3CBDC2-8AB6-45B1-B59E-7B0DEE595917}"= C:\WINDOWS\system32\ljjijii.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winccf32]
winccf32.dll

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\ssqrp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages    REG_MULTI_SZ      msv1_0 C:\WINDOWS\system32\ssqrp

R0 ndisrd;ndisrd;C:\WINDOWS\system32\drivers\ndisrd.sys [2005-04-04 16:25]
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-04-11 21:36]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 11:44]
S2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-12 18:27]

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 11:51:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-14 14:08:47 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-12-25 22:34:01 C:\WINDOWS\Tasks\Søg efter opdateringer til Windows Live Toolbar.job"
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 23:57:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\WINDOWS\system32\prqss.ini 319 bytes
C:\WINDOWS\system32\prqss.ini2 319 bytes
C:\WINDOWS\system32\ssqrp.dll 323072 bytes executable

scan completed successfully
hidden files: 3

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\ssqrp.dll
.
Completion time: 2007-12-26  0:01:17 - machine was rebooted
.
2007-12-25 12:31:53    --- E O F --- 

-------------------------

Mvh.
Sirus
Avatar billede sirus Nybegynder
26. december 2007 - 00:41 #5
Jeg håber at du kan guide mig videre herfra ... slettede en del programmer efter at have læst ../artikler/1123

Mvh.
Sirus
26. december 2007 - 00:47 #6
ComboFix har allerede fixet nogle elementer...

-------------------------

Afinstaller
* Azereus - Fildelingsprogram
* Bitlord - Fildelingsprogram
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=40284
* [Ultimate Defender]
* [Ultimate Cleaner]
* [RegistryFix]
* [Zapu Acceleration] (Hvis den er der?)
via
[Start][Indstilninger][Kontrolpanel][Tilføj/fjern programmer]

Genstart for at fuldføre afinstalationen...

-------------------------

Registreringsdatabase oprydning ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Register]...)
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller NEJ til den.

-------------------------

Jeg kan se at du - måske mere eller mindre mod din vilje - har installeret [Yahoo Toolbar] ?
Den er dog ikke 'farlig', men bare et irriterende program/toolbar som bare fylder op .
Hvis du vil slippe af med den kan du følge guiden herfra ->
http://support.microsoft.com/kb/303047

---------------------------------------

-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

-- Pak Avenger-programmet ud og dobbeltklik på avenger.exe

-- Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere indholdet mellem ~~~ skrift ind:

~~~~~~~~~~~~~~~~~~
Folders to delete:
C:\Program Files\Ultimate Cleaner\
C:\Program Files\RegistryFix
C:\Program Files\Zapu\
C:\Program Files\BitLord
C:\Program Files\Azureus
C:\Documents and Settings\HP_Administrator\Application Data\BitLord
C:\Documents and Settings\HP_Administrator\Application Data\Azureus
~~~~~~~~~~~~~~~~~~

-- Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask              .exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [shcluheb] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\shcluheb.dll"
O4 - HKLM\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\UltimateDefender    .exe" hide
O4 - HKCU\..\Run: [Ultimate Cleaner] "C:\Program Files\Ultimate Cleaner\UltimateCleaner.exe" hide
O4 - Startup: .protected
O4 - Startup: Zapu Acceleration Engine.lnk = C:\Program Files\Zapu\Zapu\wincm.exe
O4 - Startup: Zapu.lnk = C:\Program Files\Zapu\Zapu\wDivi.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

Genstart computeren, og lav en ny log med Hijackthis, som du lægger herind sammen med loggen fra Avenger.
26. december 2007 - 00:49 #7
Extra ->
Du skal også slette mappen
C:\Program Files\Zapu\
via Avenger listen...
Avatar billede sirus Nybegynder
26. december 2007 - 02:05 #8
Her kommer loggen fra Avenger:

------------------

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\txcugudk

*******************

Script file located at: \??\C:\WINDOWS\cxkpveht.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Folder C:\Program Files\Ultimate Cleaner not found!
Deletion of folder C:\Program Files\Ultimate Cleaner failed!

Could not process line:
C:\Program Files\Ultimate Cleaner
Status: 0xc0000034

Folder C:\Program Files\RegistryFix deleted successfully.
Folder C:\Program Files\Zapu deleted successfully.
Folder C:\Program Files\BitLord deleted successfully.
Folder C:\Program Files\Azureus deleted successfully.


Folder C:\Documents and Settings\HP_Administrator\Application Data\BitLord not found!
Deletion of folder C:\Documents and Settings\HP_Administrator\Application Data\BitLord failed!

Could not process line:
C:\Documents and Settings\HP_Administrator\Application Data\BitLord
Status: 0xc0000034

Folder C:\Documents and Settings\HP_Administrator\Application Data\Azureus deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.

---------------

Endnu engang, tusind tak for hjælpen.

Mvh.
Sirus
Avatar billede sirus Nybegynder
26. december 2007 - 02:27 #9
Og her kommer loggen fra Hijackthis:

-----------------------

Logfile of HijackThis v1.99.1
Scan saved at 02:20:31, on 26-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp          .exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp            .exe
C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
C:\Program Files\MotionBased\Agent\MBAgent.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
O2 - BHO: (no name) - {1CDB9428-656D-4A68-A459-5CF9DEF7E3DA} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {51EBD073-E497-433D-A19F-FCA817C56643} - (no file)
O2 - BHO: (no name) - {7BADB799-0210-419E-A6C2-EE708DA9E5AD} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {8731B124-D271-4BB8-A7E2-C1C619664AB8} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {A17A8C29-F750-433B-BD6C-7E1FB4C1B340} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {D5B78310-16F6-4F96-8469-7BDC6DF034C8} - (no file)
O2 - BHO: (no name) - {F4E0281E-358E-4F10-A375-8B19E20597E3} - (no file)
O2 - BHO: (no name) - {FCA4AA45-CB80-49D1-BDBA-ED57C901E44E} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp          .exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr              .Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: MotionBased Agent.lnk = C:\Program Files\MotionBased\Agent\MBAgent.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6452e9228ac0414ab1ac7481f2350f0d
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6452e9228ac0414ab1ac7481f2350f0d
O9 - Extra button: (no name) - SOFTWARE - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bl103fd.blu103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

-----------------------

P.S: Følgende linier var ikke listet i Hijackthis (bevirkende at jeg ikke kunne sætte et "hak" ved fluebenet:

O4 - HKLM\..\Run: [shcluheb] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\shcluheb.dll"
O4 - HKLM\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\UltimateDefender    .exe" hide
O4 - HKCU\..\Run: [Ultimate Cleaner] "C:\Program Files\Ultimate Cleaner\UltimateCleaner.exe" hide
O4 - Startup: .protected
O4 - Startup: Zapu Acceleration Engine.lnk = C:\Program Files\Zapu\Zapu\wincm.exe
O4 - Startup: Zapu.lnk = C:\Program Files\Zapu\Zapu\wDivi.exe

-----------------------

P.P.S: Der er kommet et hvidt vindue på ca. 10*10 cm, som bliver ved med at poppe op i nederste højre hjørne af skærmen. Vinduet er bart, men der er mulighed for at "klikke det væk oppe i højre hjørne" - men det dukker op igen ganske få sekunder efter.

Mvh.
Sirus
26. december 2007 - 13:44 #10
Godt gennemført!

------------------------------------------------------------------------

Jeg glemte/overså et par 'småting' (?) sidst... var lidt småsent *S*
Incl oprydning...

------------------------------------------------------------------------

-- Brug Avenger igen:

-- Sæt en prik i "Input Script Manually" og klik på Luppen - nu dukker der et lille vindue op, hvor du skal kopiere indholdet mellem ~~~ skrift ind:

~~~~~~~~~~~~~~~~~~
Files to delete:
C:\WINDOWS\system32\ssqrp.exe

Folders to delete:
C:\Program Files\Share_Accelerator_MM
~~~~~~~~~~~~~~~~~~

-- Klik på Trafiklyset i Avenger. Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
O2 - BHO: (no name) - {1CDB9428-656D-4A68-A459-5CF9DEF7E3DA} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {51EBD073-E497-433D-A19F-FCA817C56643} - (no file)
O2 - BHO: (no name) - {7BADB799-0210-419E-A6C2-EE708DA9E5AD} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {8731B124-D271-4BB8-A7E2-C1C619664AB8} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {A17A8C29-F750-433B-BD6C-7E1FB4C1B340} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {D5B78310-16F6-4F96-8469-7BDC6DF034C8} - (no file)
O2 - BHO: (no name) - {F4E0281E-358E-4F10-A375-8B19E20597E3} - (no file)
O2 - BHO: (no name) - {FCA4AA45-CB80-49D1-BDBA-ED57C901E44E} - (no file)
O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)

Genstart computeren, og lav en ny log med Hijackthis, som du lægger herind sammen med loggen fra Avenger.
Avatar billede sirus Nybegynder
26. december 2007 - 21:13 #11
Hej igen.

Endnu engang, mange tak for hjælpen igår.

De nye logfiler ser ud som følger:

-----------------------

Logfile of HijackThis v1.99.1
Scan saved at 21:09:30, on 26-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp            .exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp            .exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
C:\Program Files\MotionBased\Agent\MBAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\hijackthis.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp            .exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr                  .Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: MotionBased Agent.lnk = C:\Program Files\MotionBased\Agent\MBAgent.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6452e9228ac0414ab1ac7481f2350f0d
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6452e9228ac0414ab1ac7481f2350f0d
O9 - Extra button: (no name) - SOFTWARE - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bl103fd.blu103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

---------------------------

og

--------------------------

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\bsqsjwiq

*******************

Script file located at: \??\C:\ckfdlbiy.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\ssqrp.exe deleted successfully.
Folder C:\Program Files\Share_Accelerator_MM deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.

----------------------

Følgende linier var ikke at finde, da jeg lavede "Do a system scan only" og derfor er der heller ikke sat "hak ved fluebenene ud for disse linier":

O2 - BHO: (no name) - {1CDB9428-656D-4A68-A459-5CF9DEF7E3DA} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {51EBD073-E497-433D-A19F-FCA817C56643} - (no file)
O2 - BHO: (no name) - {7BADB799-0210-419E-A6C2-EE708DA9E5AD} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {8731B124-D271-4BB8-A7E2-C1C619664AB8} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {A17A8C29-F750-433B-BD6C-7E1FB4C1B340} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {D5B78310-16F6-4F96-8469-7BDC6DF034C8} - (no file)
O2 - BHO: (no name) - {F4E0281E-358E-4F10-A375-8B19E20597E3} - (no file)
O2 - BHO: (no name) - {FCA4AA45-CB80-49D1-BDBA-ED57C901E44E} - (no file)
O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)

Med venlig hilsen,
Sirus
26. december 2007 - 21:33 #12
Hmmm... Det ser ud at at linien
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
stadig spøger ?

Prøv lige at 'fixe' den igen med HiJackThis ...
Avatar billede sirus Nybegynder
26. december 2007 - 22:13 #13
Hej igen.

Her kommer så den nyeste log, efter at jeg har prøvet at fixe nedenstående linie igen:

F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe

Og tak for hjælpen.

----------------

Logfile of HijackThis v1.99.1
Scan saved at 22:09:51, on 26-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp            .exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr                  .Exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp            .exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon .exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Windows Live\Messenger\MsnMsgr                  .Exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\MotionBased\Agent\MBAgent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\HP\KBD\KBD.EXE
C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\hijackthis.exe
C:\WINDOWS\system32\rundll32.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp            .exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr                  .Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: MotionBased Agent.lnk = C:\Program Files\MotionBased\Agent\MBAgent.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6452e9228ac0414ab1ac7481f2350f0d
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6452e9228ac0414ab1ac7481f2350f0d
O9 - Extra button: (no name) - SOFTWARE - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bl103fd.blu103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

----------------------

Mvh.
Sirus
Avatar billede sirus Nybegynder
27. december 2007 - 15:30 #14
Hej igen.

Kan du se om denne log ser fornuftig ud eller ...

Mvh.
Sirus
27. december 2007 - 18:04 #15
Sorry - 'arbejdsramt' *S* - den er lidt speciel...

Find filen:
C:\WINDOWS\win.ini
Åbn den med Notepad
Søg efter linien:
load=C:\WINDOWS\system32\ssqrp.exe
og slet den del ...

Prøv lige at 'fixe' den igen med HiJackThis ...
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
Avatar billede sirus Nybegynder
27. december 2007 - 22:53 #16
Hej igen.

Jeg kan ikke finde den omtalte linie - min win.ini ser således ud:

; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1
CMC=1
CMCDLLNAME=mapi.dll
CMCDLLNAME32=mapi32.dll
MAPIX=1
MAPIXVER=1.0.0.1
OLEMessaging=1
[MCI Extensions.BAK]
wma=MPEGVideo
wax=MPEGVideo
wmv=MPEGVideo
wvx=MPEGVideo
asf=MPEGVideo
asx=MPEGVideo
wpl=MPEGVideo
wm=MPEGVideo
wmx=MPEGVideo
mp3=MPEGVideo
m3u=MPEGVideo
mpeg=MPEGVideo
mpg=MPEGVideo
mpe=MPEGVideo
m1v=MPEGVideo
m2v=MPEGVideo
mod=MPEGVideo
mp2=MPEGVideo
mpv2=MPEGVideo
mp2v=MPEGVideo
mpa=MPEGVideo
aif=MPEGVideo
aifc=MPEGVideo
aiff=MPEGVideo
au=MPEGVideo
snd=MPEGVideo

Skal jeg alligevel 'fixe' med HiJackThis?
28. december 2007 - 08:00 #17
Ja ...
Avatar billede sirus Nybegynder
28. december 2007 - 15:07 #18
Hej igen.

Loggen ser således ud nu:

Logfile of HijackThis v1.99.1
Scan saved at 15:03:44, on 28-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp              .exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon .exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\Windows Live\Messenger\MsnMsgr                    .Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr                    .Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
C:\Program Files\MotionBased\Agent\MBAgent.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\HP\KBD\KBD.EXE
C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\hijackthis.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
O2 - BHO: (no name) - {00D8C2D7-8088-4E17-8076-D68F1A621B8E} - (no file)
O2 - BHO: (no name) - {08A55639-952E-4F19-8866-B4252DFEBAF7} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {0DE01AE0-CEB1-42AC-9DB6-96B8B8E89239} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {13830DBA-C064-443F-85B0-207A16FA8A31} - (no file)
O2 - BHO: (no name) - {13A4F2C0-962C-43C7-A0BC-C66B3B0833F5} - (no file)
O2 - BHO: (no name) - {1E7928F6-D162-4810-B710-7425CF34B22A} - (no file)
O2 - BHO: (no name) - {1E883D9E-D800-4FDF-ADA0-31CE1AB55729} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {246BEF92-0628-40E5-879D-E5BA7EBD1586} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {294EA89D-88DB-4F15-9252-5FEB07F0E225} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {29EB40F5-5451-4FC7-A97F-B227953D09A9} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {2BA21421-744D-45EB-9DF4-5B37F80D2F6F} - (no file)
O2 - BHO: (no name) - {2FD2FA8C-49C2-4563-AE37-E4EDE5AD4EAD} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {353C8BD9-800B-4BC1-B25F-084FFFECD3FA} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {38ACBD99-F3E1-4F02-8B70-A18D20DC9A38} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {39A83846-F4B9-4ED2-9C99-665F18C0C6FC} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {3AE476E8-3617-4F7F-8711-67924013F928} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {3B09AC09-E24A-4FF1-80D9-92B0712DF494} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {44386F55-C058-4D87-A312-3F5C776C7581} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {44867D8D-6866-43C5-ABAE-15A7497DA72F} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {48E67CAF-6E5C-4590-B367-97DEA4E162B9} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {557C631F-8A15-480B-8032-6AFEDC69C13F} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {57A0B73D-81C9-46DF-86BE-C0E09F469A20} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {5C43DC7B-1483-43D0-BCD7-C6CEAEA8DF82} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {5DF2AB57-3646-48B6-B0D5-572958DD3FC4} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {6351DEDB-1905-4524-A960-9D528528D183} - (no file)
O2 - BHO: (no name) - {68AC1A41-78A5-48E3-A410-A101D2A6A027} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {6AC3E523-B9B2-4C19-8F10-70E93D730050} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {6BDFE35E-3D81-43FD-A209-93DC06589793} - (no file)
O2 - BHO: (no name) - {7DA81F41-8F33-4BE8-AEA3-92EECEF84985} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {7E7C1C85-1ED0-4EA8-8C17-E1BA0E9E58D8} - (no file)
O2 - BHO: (no name) - {8125DDE8-B371-4365-8DD5-4E2FFF74848D} - (no file)
O2 - BHO: (no name) - {85B9BC1D-2C08-4948-8BF7-7B4E79CDE88C} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {899830AB-9F65-4884-A9FD-1414CE220988} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {8C8D3DB1-714F-47F6-B853-6DB78B862592} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {944E4808-F66F-4954-A0FA-DC776DB42D7A} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {9EB0C333-4B00-44DC-AE00-35E65119814D} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {A0B9EEEC-B861-4221-87A3-2AE162AB9939} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {A17BF886-10B6-4911-BC8F-00B2362BE908} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {A1E86611-CFA1-4D2E-A690-80D88E010137} - (no file)
O2 - BHO: (no name) - {A88277DF-DC52-4D49-988A-EDF0F39BEE87} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {AAB0DAFC-7EAC-45E0-BE78-161489EEA200} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {AECAAF58-2D4E-470A-B3C0-FA2D584476BE} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {B5EF2653-B97A-4585-98C1-23AED7AAB783} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {B607FB23-B7DF-4859-869F-5B2B19EB2C83} - (no file)
O2 - BHO: (no name) - {BC33D530-368D-4E26-93E7-95B5554CF631} - (no file)
O2 - BHO: (no name) - {BC4505FA-1134-4A20-8CF6-9E50C4BE07A7} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {BCD33286-19D2-47CB-982B-EF9561469B1F} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {BD49266C-5567-4939-B619-B255C302EA1B} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {C0ABC03A-A5E5-4D77-976F-FF973DB6B516} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {C0AD4DC0-1190-4E68-8963-49DF0BC77F09} - (no file)
O2 - BHO: (no name) - {C26D5ABF-991F-4960-9214-E81BA6F245CF} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {C412FB3A-E97A-4ADA-8E18-6140948E542C} - (no file)
O2 - BHO: (no name) - {CA98591E-0C2E-4C18-836F-1FE45D71894B} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {CBED5F8A-99EC-47BC-A86A-8A7936006F3C} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {CDF15436-142A-4FAC-A9C4-DE4E4F365EB7} - (no file)
O2 - BHO: (no name) - {D36C879B-3223-4334-B132-54C473A07C73} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {D47C13BA-61FD-47B2-95FD-D2F3C20F35C7} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {D7B383EC-F477-4692-849F-CB11BBB4567A} - (no file)
O2 - BHO: (no name) - {D9E79E3D-A0D5-49D9-A9BF-73ECD77F6E5B} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {DBB041BF-B3C8-4BF4-AECF-87611FEACA19} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {DE9880EB-17E9-4831-B388-2499A85DC3BE} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {E2A00A26-39F2-49D1-8F23-E01525B2FB6A} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {E49008D9-E5AF-45FD-9FD9-1D4BE4180BD1} - (no file)
O2 - BHO: (no name) - {E7055888-322C-4DF4-8E28-1C0A4328E383} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {E927BC38-05C8-4905-8E86-419C30BE9019} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {F0F133FC-41E0-4C41-BA65-D19B24D1D239} - [SASInprocServer32] (file missing)
O2 - BHO: (no name) - {FC586D3D-1026-4C90-84F5-5EBAB1B45874} - (no file)
O2 - BHO: (no name) - {FDFBEDCC-0B12-46E3-8A97-173B224485E5} - [SASInprocServer32] (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp              .exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr                    .Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: MotionBased Agent.lnk = C:\Program Files\MotionBased\Agent\MBAgent.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6452e9228ac0414ab1ac7481f2350f0d
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6452e9228ac0414ab1ac7481f2350f0d
O9 - Extra button: (no name) - SOFTWARE - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bl103fd.blu103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

-----------------------

Er det rigtigt forstået, at det er filen ssqrp.exe som er "synderen"?

Mvh.
Sirus
Avatar billede sirus Nybegynder
28. december 2007 - 15:35 #19
Hej igen.

Når jeg søger på nettet, kan jeg få fornemmelsen af at folk tidligere har haft held med at fjerne filen med VundoFix.

http://forum.piriform.com/index.php?showtopic=13095&pid=89528&st=0&#entry89528

Er det et forsøg værd, eller???

Tak for din hjælp.

Mvh.
Sirus
29. december 2007 - 12:08 #20
Give' It A Try ->

Download dette fix til rodbiblioteket på din computer (som regel c:\):
http://www.atribune.org/ccount/click.php?id=4

Dobbeltklik på VundoFix.exe for at køre det. Klik på "Scan for Vundo"-knappen. Når programmet er færdig med at scanne, skal du klikke på "Remove Vundo"-knappen

Du vil så blive spurgt om du er sikker på, at du vil fjerne filerne. Her skal du klikke på "Yes". Herefter bliver dit skrivebord blankt, og fixet vil forsøge at fjerne Vundo. Når den er færdig, vil værktøjet have lov til at genstarte computeren. Det skal du acceptere.

Genstart herefter computeren, og lav en ny log med HJT, som du lægger herind. Læg også indholdet af denne fil herind: C:\vundofix.txt

Bemærk: Det er muligt at Vundofix ved første scanning finder en fil, som den ikke kan fjerne i første omgang. Så vil Vundofixet genstarte, og fortsætte efter genstarten. HVis dette sker, skal du bare følge instruktionerne ovenfor efter genstarten (startende med "Klik på Scan for Vundo-knappen")
Avatar billede sirus Nybegynder
29. december 2007 - 13:51 #21
Hej igen.

Her kommer de to log-filer:


VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 13:13:33 29-12-2007

Listing files found while scanning....

C:\WINDOWS\system32\prqss.ini
C:\WINDOWS\system32\prqss.ini2
C:\WINDOWS\system32\ssqrp.dll
C:\WINDOWS\system32\ssqrp.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\prqss.ini
C:\WINDOWS\system32\prqss.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\prqss.ini2
C:\WINDOWS\system32\prqss.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqrp.dll
C:\WINDOWS\system32\ssqrp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqrp.exe
C:\WINDOWS\system32\ssqrp.exe Has been deleted!

Performing Repairs to the registry.
Done!

--------------------------

Logfile of HijackThis v1.99.1
Scan saved at 13:49:56, on 29-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp              .exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr                      .Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp                .exe
C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\MotionBased\Agent\MBAgent.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr                      .Exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop .exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\hijackthis.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrp.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp              .exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask  .exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr                      .Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: MotionBased Agent.lnk = C:\Program Files\MotionBased\Agent\MBAgent.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6452e9228ac0414ab1ac7481f2350f0d
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6452e9228ac0414ab1ac7481f2350f0d
O9 - Extra button: (no name) - SOFTWARE - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bl103fd.blu103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

------------------------

Da jeg loggede ind, "brokkede" computeren sig over at den ikke kunne finde hhv. ssqrp.exe og ssqrp.dll - men det tager jeg som et positivt tegn.

Mvh.
Sirus
Avatar billede sirus Nybegynder
29. december 2007 - 13:54 #22
... men de er der stadig på hhv:

C:/WINDOWS/SYSTEM32/ssqrp.exe og
C:/WINDOWS/SYSTEM32/ssqrp.dll

Mvh.
Sirus
29. december 2007 - 14:53 #23
Lige en hurtig:
Dvs de er stadig placeret ved henholdsvis
C:\WINDOWS\system32\ssqrp.dll
C:\WINDOWS\system32\ssqrp.exe
???
selvom de står som deleted...
29. december 2007 - 14:59 #24
Du får lige hele 'pakken' ->

---------------------------------------------------------------------

Hent denne engangsscanner:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe (Gem programmet på skrivebordet, så du let kan finde det til senere brug)

Hvis din firewall blokerer for ftp adresser, kan du hente programmet her:
http://spywareinfo.dk/download/drweb-cureit.exe
(Du skal ikke aktivere den endnu)
---------------------------------------------------------------------

Hent AVG Antispyware:
http://www.spywarefri.dk/downloads1/avgas-setup-7.5.0.47.exe
Manual til Ewido: http://www.spywarefri.dk/manualer/ewido-manual.htm (AVG Antispyware hed tidligere Ewido. Du kan stadig bruge denne manual, men vi får snart tilpasset en ny manual til programmet).

Opdater straks efter installationen programmet. Lad være med at slette noget med AVG Antispyware fra normal tilstand. Vent til du kommer i fejlsikret tilstand. Du kan evt. højreklikke på ikonet E nede ved uret, og klikke på shutdown guard, så er du sikker på, at programmet venter med at fjerne snavs, til du er i fejlsikret tilstand.

---------------------------------------------------------------------

Download free Trial af SuperAntiSpyware Proff til Skrivebordet, http://www.superantispyware.com/downloads/SUPERAntiSpyware1241.exe
Installer den, og lad den opdatere med nyeste opdateringer.
Så vil den spørge om din mail adresse, det er op til dig selv om du vil udfylde det. Tryk så på Næste og Næste igen - Udfør.
Dansk vejledning http://www.spywarefri.dk/manualer/superantispyware-manual.htm
(Du skal ikke aktivere den endnu)
---------------------------------------------------------------------

Tøm dine TEMP mapper:
Hent den lille batfil, dobbeltklik på filen, og der går et split sek. Så er temp renset.
www.spywareinfo.dk/download/cleantempxp2k.bat
---------------------------------------------------------------------

Genstart i fejlsikret tilstand http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm
---------------------------------------------------------------------

Kør en fuld scanning med AVG Antispyware, og tillad programmet at fixe de ting, som det finder. Programmet laver en lille log, som du skal kopiere herind.
Programmet opretter en lille log, som du skal kopiere herind i dit næste svar. Du kan se hvordan du skal oprette og gemme rapporten her: http://www.spywarefri.dk/manualer/ewido-manual.htm Hvis du er i tvivl. Se punkt: 19 og 20
---------------------------------------------------------------------

DrWeb - Dobbeltklik på cureit exe filen laver den en kort startup/express scan.
Lad den fixe hvad den finder (Say Yes to all)
Derefter skal du klikke på Options -> Change settings.
Skift til fanebladet Scan, fjern fluebenet ved Heuristic analysis.
Skift til fanebladet Actions, her skal alle punkter under Malware sættes til Move.
Fjern flueben ved - Prompt on action.
Ved Move Path sletter du hvad der står, og skriver: c:\infected
Tryk på Anvend og derefter på OK.

Klik så på det eller de drev du vil have scannet, der kommer en rød prik for at vise det/de er valgt.
Tryk så på den grønne pil nederst  til højre, så scanner den, og fixer problemerne.

Når scanningen er færdig, gå op i file - Tryk på - Save Report list.
Så ligger der en en fil der her hedder drweb.csv (åbnes med Notebook/Notepad) - på skrivebordet.
Luk Programmet.
---------------------------------------------------------------------

Start superantispyware ved at højreklikke på den gule og sorte bille ved uret

Tryk på - Scan for, Adware,Malware - linjen
Tryk på - Preference - Knappen.
Fjern flueben ved - Start SuperAntiSpyware when Windows starts.

Tryk på Fanebladet - Scanning control.
Ved scanning options, skal der kun være flueben i de to nederste
Fanebladet - Real Time Protections. Fjerner du fluben ved - Enable Real Time Protection
Tryk så på Close

Tryk på - Scan Your computer - Knappen. sæt flueben ved de drev der skal scannes. Det er vigtigt at drev hvor Windows (systemdrevet) ligger, har et flueben.
Flyt så prikken ved - Perform quick Scan, ned til - Perform complete Scan.
Tryk på Næste, så går den i gang med at scanne.

Det kan godt tage lang tid hvis du har meget på computeren

Når scanninngen er færdig popper der en boks op, tryk OK.
Sæt flueben ved alt den har fundet - næste. Så vil den fixe/slette infektionerne.

Lad den genstarte normalt.
---------------------------------------------------------------------

Efter genstart -

Åben SuperAntiSpyware igen
Tryk på Preferences, vælg Statistics/Logs
Marker loggen i det lille vindue og tryk på View Log.
Kopier teksten herind sammen med loggen fra Ewido og loggen fra DrWeb (drweb.csv)

Sammen med en frisk Log fra HiJackThis...
Avatar billede sirus Nybegynder
30. december 2007 - 18:07 #25
SUPERAntiSpyware Scan Log
Generated 12/30/2007 at 01:20 PM

Application Version : 3.5.1016

Core Rules Database Version : 3370
Trace Rules Database Version: 1365

Scan type      : Complete Scan
Total Scan Time : 00:53:15

Memory items scanned      : 454
Memory threats detected  : 0
Registry items scanned    : 10192
Registry threats detected : 12509
File items scanned        : 52255
File threats detected    : 1

Adware.Vundo Variant
    HKLM\Software\Classes\CLSID\{002640EF-9292-4FE5-B34A-8FDEEB1685E2}
    HKCR\CLSID\{002640EF-9292-4FE5-B34A-8FDEEB1685E2}
    HKCR\CLSID\{002640EF-9292-4FE5-B34A-8FDEEB1685E2}\InprocServer32
    HKCR\CLSID\{002640EF-9292-4FE5-B34A-8FDEEB1685E2}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\SSQRP.DLL
    HKLM\Software\Classes\CLSID\{003BE95E-5719-46DF-90BB-2B3EBA0BD198}
    HKCR\CLSID\{003BE95E-5719-46DF-90BB-2B3EBA0BD198}
    HKCR\CLSID\{003BE95E-5719-46DF-90BB-2B3EBA0BD198}\InprocServer32
    HKCR\CLSID\{003BE95E-5719-46DF-90BB-2B3EBA0BD198}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0047D9FE-9D44-4C71-A362-94A71B55D5F3}
    HKCR\CLSID\{0047D9FE-9D44-4C71-A362-94A71B55D5F3}
    HKCR\CLSID\{0047D9FE-9D44-4C71-A362-94A71B55D5F3}\InprocServer32
    HKCR\CLSID\{0047D9FE-9D44-4C71-A362-94A71B55D5F3}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{005CD05E-C01B-4E7E-B3CF-CF1A7CFDC61B}
    HKCR\CLSID\{005CD05E-C01B-4E7E-B3CF-CF1A7CFDC61B}
    HKCR\CLSID\{005CD05E-C01B-4E7E-B3CF-CF1A7CFDC61B}\InprocServer32
    HKCR\CLSID\{005CD05E-C01B-4E7E-B3CF-CF1A7CFDC61B}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0064C43B-5EEB-46F5-B24B-B296A069CBEE}
    HKCR\CLSID\{0064C43B-5EEB-46F5-B24B-B296A069CBEE}
    HKCR\CLSID\{0064C43B-5EEB-46F5-B24B-B296A069CBEE}\InprocServer32
    HKCR\CLSID\{0064C43B-5EEB-46F5-B24B-B296A069CBEE}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0074555B-C9D5-4551-A6FB-98A9DFC50560}
    HKCR\CLSID\{0074555B-C9D5-4551-A6FB-98A9DFC50560}
    HKCR\CLSID\{0074555B-C9D5-4551-A6FB-98A9DFC50560}\InprocServer32
    HKCR\CLSID\{0074555B-C9D5-4551-A6FB-98A9DFC50560}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{007E33AA-11D7-4DE0-8FA8-4C7E26719019}
    HKCR\CLSID\{007E33AA-11D7-4DE0-8FA8-4C7E26719019}
    HKCR\CLSID\{007E33AA-11D7-4DE0-8FA8-4C7E26719019}\InprocServer32
    HKCR\CLSID\{007E33AA-11D7-4DE0-8FA8-4C7E26719019}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{00832667-3D82-4A0C-853F-571E49FBF496}
    HKCR\CLSID\{00832667-3D82-4A0C-853F-571E49FBF496}
    HKCR\CLSID\{00832667-3D82-4A0C-853F-571E49FBF496}\InprocServer32
    HKCR\CLSID\{00832667-3D82-4A0C-853F-571E49FBF496}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0096AE99-5F06-41B1-AFEA-658E51C9E837}
    HKCR\CLSID\{0096AE99-5F06-41B1-AFEA-658E51C9E837}
    HKCR\CLSID\{0096AE99-5F06-41B1-AFEA-658E51C9E837}\InprocServer32
    HKCR\CLSID\{0096AE99-5F06-41B1-AFEA-658E51C9E837}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{00B8AC50-C0F3-407D-B230-B7F5ED34F3F5}
    HKCR\CLSID\{00B8AC50-C0F3-407D-B230-B7F5ED34F3F5}
    HKCR\CLSID\{00B8AC50-C0F3-407D-B230-B7F5ED34F3F5}\InprocServer32
    HKCR\CLSID\{00B8AC50-C0F3-407D-B230-B7F5ED34F3F5}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{00CF52C0-4C16-4479-9B08-1A7067B45C0F}
    HKCR\CLSID\{00CF52C0-4C16-4479-9B08-1A7067B45C0F}
    HKCR\CLSID\{00CF52C0-4C16-4479-9B08-1A7067B45C0F}\InprocServer32
    HKCR\CLSID\{00CF52C0-4C16-4479-9B08-1A7067B45C0F}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{00F97515-AB27-4292-B483-4D5579C02F6D}
    HKCR\CLSID\{00F97515-AB27-4292-B483-4D5579C02F6D}
    HKCR\CLSID\{00F97515-AB27-4292-B483-4D5579C02F6D}\InprocServer32
    HKLM\Software\Classes\CLSID\{00FA34C6-114A-45EF-9987-5B0C6EB993AA}
    HKCR\CLSID\{00FA34C6-114A-45EF-9987-5B0C6EB993AA}
    HKCR\CLSID\{00FA34C6-114A-45EF-9987-5B0C6EB993AA}\InprocServer32
    HKCR\CLSID\{00FA34C6-114A-45EF-9987-5B0C6EB993AA}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{014038B6-CC80-4F1C-8BF7-7978FD1B9CCA}
    HKCR\CLSID\{014038B6-CC80-4F1C-8BF7-7978FD1B9CCA}
    HKCR\CLSID\{014038B6-CC80-4F1C-8BF7-7978FD1B9CCA}\InprocServer32
    HKCR\CLSID\{014038B6-CC80-4F1C-8BF7-7978FD1B9CCA}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{01529174-45EA-43B1-97D4-D560F0209E9C}
    HKCR\CLSID\{01529174-45EA-43B1-97D4-D560F0209E9C}
    HKCR\CLSID\{01529174-45EA-43B1-97D4-D560F0209E9C}\InprocServer32
    HKCR\CLSID\{01529174-45EA-43B1-97D4-D560F0209E9C}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0153CF79-A494-4B8C-98A2-4D5B390846FA}
    HKCR\CLSID\{0153CF79-A494-4B8C-98A2-4D5B390846FA}
    HKCR\CLSID\{0153CF79-A494-4B8C-98A2-4D5B390846FA}\InprocServer32
    HKCR\CLSID\{0153CF79-A494-4B8C-98A2-4D5B390846FA}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{015E89CA-2141-4ADF-964E-91BD4F806611}
    HKCR\CLSID\{015E89CA-2141-4ADF-964E-91BD4F806611}
    HKCR\CLSID\{015E89CA-2141-4ADF-964E-91BD4F806611}\InprocServer32
    HKCR\CLSID\{015E89CA-2141-4ADF-964E-91BD4F806611}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{018AE90A-EAA0-487C-B4E9-A546D2C80B83}
    HKCR\CLSID\{018AE90A-EAA0-487C-B4E9-A546D2C80B83}
    HKCR\CLSID\{018AE90A-EAA0-487C-B4E9-A546D2C80B83}\InprocServer32
    HKCR\CLSID\{018AE90A-EAA0-487C-B4E9-A546D2C80B83}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{01A38D9E-CD9B-4A70-B4BA-E62818F48422}
    HKCR\CLSID\{01A38D9E-CD9B-4A70-B4BA-E62818F48422}
    HKCR\CLSID\{01A38D9E-CD9B-4A70-B4BA-E62818F48422}\InprocServer32
    HKCR\CLSID\{01A38D9E-CD9B-4A70-B4BA-E62818F48422}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{01A8E977-E1CF-4459-BC8F-10639210D8E3}
    HKCR\CLSID\{01A8E977-E1CF-4459-BC8F-10639210D8E3}
    HKCR\CLSID\{01A8E977-E1CF-4459-BC8F-10639210D8E3}\InprocServer32
    HKCR\CLSID\{01A8E977-E1CF-4459-BC8F-10639210D8E3}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{01AFC766-786E-40D0-BB09-F0A3EE6B45B2}
    HKCR\CLSID\{01AFC766-786E-40D0-BB09-F0A3EE6B45B2}
    HKCR\CLSID\{01AFC766-786E-40D0-BB09-F0A3EE6B45B2}\InprocServer32
    HKCR\CLSID\{01AFC766-786E-40D0-BB09-F0A3EE6B45B2}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{01E69B40-B346-4727-A51B-30A2868C62B2}
    HKCR\CLSID\{01E69B40-B346-4727-A51B-30A2868C62B2}
    HKCR\CLSID\{01E69B40-B346-4727-A51B-30A2868C62B2}\InprocServer32
    HKCR\CLSID\{01E69B40-B346-4727-A51B-30A2868C62B2}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{01E80F33-1F02-42EA-9028-DC6A612311D3}
    HKCR\CLSID\{01E80F33-1F02-42EA-9028-DC6A612311D3}
    HKCR\CLSID\{01E80F33-1F02-42EA-9028-DC6A612311D3}\InprocServer32
    HKCR\CLSID\{01E80F33-1F02-42EA-9028-DC6A612311D3}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{01E8694E-E89B-4B57-ACFA-8C3FD55959E8}
    HKCR\CLSID\{01E8694E-E89B-4B57-ACFA-8C3FD55959E8}
    HKCR\CLSID\{01E8694E-E89B-4B57-ACFA-8C3FD55959E8}\InprocServer32
    HKCR\CLSID\{01E8694E-E89B-4B57-ACFA-8C3FD55959E8}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0204BE29-161D-47EF-8F58-91AB21BFD84A}
    HKCR\CLSID\{0204BE29-161D-47EF-8F58-91AB21BFD84A}
    HKCR\CLSID\{0204BE29-161D-47EF-8F58-91AB21BFD84A}\InprocServer32
    HKCR\CLSID\{0204BE29-161D-47EF-8F58-91AB21BFD84A}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{020DA212-84ED-4B50-AE27-8CD229D9E817}
    HKCR\CLSID\{020DA212-84ED-4B50-AE27-8CD229D9E817}
    HKCR\CLSID\{020DA212-84ED-4B50-AE27-8CD229D9E817}\InprocServer32
    HKCR\CLSID\{020DA212-84ED-4B50-AE27-8CD229D9E817}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{021E57AE-BE6B-408D-9A6B-11E3B024E058}
    HKCR\CLSID\{021E57AE-BE6B-408D-9A6B-11E3B024E058}
    HKCR\CLSID\{021E57AE-BE6B-408D-9A6B-11E3B024E058}\InprocServer32
    HKCR\CLSID\{021E57AE-BE6B-408D-9A6B-11E3B024E058}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02407AAC-DFF4-4CE7-AE32-43BBB1DF2828}
    HKCR\CLSID\{02407AAC-DFF4-4CE7-AE32-43BBB1DF2828}
    HKCR\CLSID\{02407AAC-DFF4-4CE7-AE32-43BBB1DF2828}\InprocServer32
    HKCR\CLSID\{02407AAC-DFF4-4CE7-AE32-43BBB1DF2828}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0243A7E4-E1C0-47A9-9ABB-CABB2CF98E09}
    HKCR\CLSID\{0243A7E4-E1C0-47A9-9ABB-CABB2CF98E09}
    HKCR\CLSID\{0243A7E4-E1C0-47A9-9ABB-CABB2CF98E09}\InprocServer32
    HKCR\CLSID\{0243A7E4-E1C0-47A9-9ABB-CABB2CF98E09}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02446235-8946-4914-9778-DB376B38FEB4}
    HKCR\CLSID\{02446235-8946-4914-9778-DB376B38FEB4}
    HKCR\CLSID\{02446235-8946-4914-9778-DB376B38FEB4}\InprocServer32
    HKCR\CLSID\{02446235-8946-4914-9778-DB376B38FEB4}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02647083-94A5-4D26-9DE4-CC4B023A062D}
    HKCR\CLSID\{02647083-94A5-4D26-9DE4-CC4B023A062D}
    HKCR\CLSID\{02647083-94A5-4D26-9DE4-CC4B023A062D}\InprocServer32
    HKCR\CLSID\{02647083-94A5-4D26-9DE4-CC4B023A062D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02674C3D-CAD7-4C3E-B48F-9CEFC82A0CDE}
    HKCR\CLSID\{02674C3D-CAD7-4C3E-B48F-9CEFC82A0CDE}
    HKCR\CLSID\{02674C3D-CAD7-4C3E-B48F-9CEFC82A0CDE}\InprocServer32
    HKCR\CLSID\{02674C3D-CAD7-4C3E-B48F-9CEFC82A0CDE}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0270A334-EE9E-4DBC-9A51-AF4F88F01F46}
    HKCR\CLSID\{0270A334-EE9E-4DBC-9A51-AF4F88F01F46}
    HKCR\CLSID\{0270A334-EE9E-4DBC-9A51-AF4F88F01F46}\InprocServer32
    HKCR\CLSID\{0270A334-EE9E-4DBC-9A51-AF4F88F01F46}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02772AB1-101C-4240-A3BF-00899B5DCC81}
    HKCR\CLSID\{02772AB1-101C-4240-A3BF-00899B5DCC81}
    HKCR\CLSID\{02772AB1-101C-4240-A3BF-00899B5DCC81}\InprocServer32
    HKCR\CLSID\{02772AB1-101C-4240-A3BF-00899B5DCC81}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{027B9FBC-CD38-4902-B22E-FC65664038EA}
    HKCR\CLSID\{027B9FBC-CD38-4902-B22E-FC65664038EA}
    HKCR\CLSID\{027B9FBC-CD38-4902-B22E-FC65664038EA}\InprocServer32
    HKCR\CLSID\{027B9FBC-CD38-4902-B22E-FC65664038EA}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{028BFD8E-D1B1-459C-829F-14B3FD35F697}
    HKCR\CLSID\{028BFD8E-D1B1-459C-829F-14B3FD35F697}
    HKCR\CLSID\{028BFD8E-D1B1-459C-829F-14B3FD35F697}\InprocServer32
    HKCR\CLSID\{028BFD8E-D1B1-459C-829F-14B3FD35F697}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02B68772-22A0-4FE3-B99E-DDB2C4EF880B}
    HKCR\CLSID\{02B68772-22A0-4FE3-B99E-DDB2C4EF880B}
    HKCR\CLSID\{02B68772-22A0-4FE3-B99E-DDB2C4EF880B}\InprocServer32
    HKCR\CLSID\{02B68772-22A0-4FE3-B99E-DDB2C4EF880B}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02B6DB58-84FF-4A93-8233-97A63A63FB94}
    HKCR\CLSID\{02B6DB58-84FF-4A93-8233-97A63A63FB94}
    HKCR\CLSID\{02B6DB58-84FF-4A93-8233-97A63A63FB94}\InprocServer32
    HKCR\CLSID\{02B6DB58-84FF-4A93-8233-97A63A63FB94}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02B88626-932E-41C8-96E4-3F04DB320B2A}
    HKCR\CLSID\{02B88626-932E-41C8-96E4-3F04DB320B2A}
    HKCR\CLSID\{02B88626-932E-41C8-96E4-3F04DB320B2A}\InprocServer32
    HKCR\CLSID\{02B88626-932E-41C8-96E4-3F04DB320B2A}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02CAD9B8-E886-4C4B-9244-DA7F0921E761}
    HKCR\CLSID\{02CAD9B8-E886-4C4B-9244-DA7F0921E761}
    HKCR\CLSID\{02CAD9B8-E886-4C4B-9244-DA7F0921E761}\InprocServer32
    HKCR\CLSID\{02CAD9B8-E886-4C4B-9244-DA7F0921E761}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02CE864A-7472-4332-8C7F-A4A2845E8C9D}
    HKCR\CLSID\{02CE864A-7472-4332-8C7F-A4A2845E8C9D}
    HKCR\CLSID\{02CE864A-7472-4332-8C7F-A4A2845E8C9D}\InprocServer32
    HKCR\CLSID\{02CE864A-7472-4332-8C7F-A4A2845E8C9D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{02F024B4-8648-497A-9B85-E66E2DC87845}
    HKCR\CLSID\{02F024B4-8648-497A-9B85-E66E2DC87845}
    HKCR\CLSID\{02F024B4-8648-497A-9B85-E66E2DC87845}\InprocServer32
    HKCR\CLSID\{02F024B4-8648-497A-9B85-E66E2DC87845}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0326F8D0-A26E-4071-BDB7-40E7A92E0FDE}
    HKCR\CLSID\{0326F8D0-A26E-4071-BDB7-40E7A92E0FDE}
    HKCR\CLSID\{0326F8D0-A26E-4071-BDB7-40E7A92E0FDE}\InprocServer32
    HKCR\CLSID\{0326F8D0-A26E-4071-BDB7-40E7A92E0FDE}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0336EFB2-FAC1-41E0-8ABB-C545BF40E009}
    HKCR\CLSID\{0336EFB2-FAC1-41E0-8ABB-C545BF40E009}
    HKCR\CLSID\{0336EFB2-FAC1-41E0-8ABB-C545BF40E009}\InprocServer32
    HKCR\CLSID\{0336EFB2-FAC1-41E0-8ABB-C545BF40E009}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{03546F7A-969B-429B-BB4C-0F1E3BC0C485}
    HKCR\CLSID\{03546F7A-969B-429B-BB4C-0F1E3BC0C485}
    HKCR\CLSID\{03546F7A-969B-429B-BB4C-0F1E3BC0C485}\InprocServer32
    HKCR\CLSID\{03546F7A-969B-429B-BB4C-0F1E3BC0C485}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{03919FDA-38A0-412E-A088-DE4378782F2E}
    HKCR\CLSID\{03919FDA-38A0-412E-A088-DE4378782F2E}
    HKCR\CLSID\{03919FDA-38A0-412E-A088-DE4378782F2E}\InprocServer32
    HKCR\CLSID\{03919FDA-38A0-412E-A088-DE4378782F2E}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{03B751B7-1077-4B72-87C7-20368F4CBCEB}
    HKCR\CLSID\{03B751B7-1077-4B72-87C7-20368F4CBCEB}
    HKCR\CLSID\{03B751B7-1077-4B72-87C7-20368F4CBCEB}\InprocServer32
    HKCR\CLSID\{03B751B7-1077-4B72-87C7-20368F4CBCEB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{03DB3BBA-B16F-43F2-AE08-9226CFDAF01B}
    HKCR\CLSID\{03DB3BBA-B16F-43F2-AE08-9226CFDAF01B}
    HKCR\CLSID\{03DB3BBA-B16F-43F2-AE08-9226CFDAF01B}\InprocServer32
    HKCR\CLSID\{03DB3BBA-B16F-43F2-AE08-9226CFDAF01B}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{03F1F7E2-5183-405B-886A-3BBFB8A798A8}
    HKCR\CLSID\{03F1F7E2-5183-405B-886A-3BBFB8A798A8}
    HKCR\CLSID\{03F1F7E2-5183-405B-886A-3BBFB8A798A8}\InprocServer32
    HKCR\CLSID\{03F1F7E2-5183-405B-886A-3BBFB8A798A8}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0406F501-2636-4153-B21C-7E703B6AD259}
    HKCR\CLSID\{0406F501-2636-4153-B21C-7E703B6AD259}
    HKCR\CLSID\{0406F501-2636-4153-B21C-7E703B6AD259}\InprocServer32
    HKCR\CLSID\{0406F501-2636-4153-B21C-7E703B6AD259}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0416E86A-4F48-4164-BBC5-2A7638ADD536}
    HKCR\CLSID\{0416E86A-4F48-4164-BBC5-2A7638ADD536}
    HKCR\CLSID\{0416E86A-4F48-4164-BBC5-2A7638ADD536}\InprocServer32
    HKCR\CLSID\{0416E86A-4F48-4164-BBC5-2A7638ADD536}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{041CC054-BBC9-4EB3-B430-A2A675CE9754}
    HKCR\CLSID\{041CC054-BBC9-4EB3-B430-A2A675CE9754}
    HKCR\CLSID\{041CC054-BBC9-4EB3-B430-A2A675CE9754}\InprocServer32
    HKCR\CLSID\{041CC054-BBC9-4EB3-B430-A2A675CE9754}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{042EEE70-6EE3-456A-8FD1-BE28AB9292BC}
    HKCR\CLSID\{042EEE70-6EE3-456A-8FD1-BE28AB9292BC}
    HKCR\CLSID\{042EEE70-6EE3-456A-8FD1-BE28AB9292BC}\InprocServer32
    HKCR\CLSID\{042EEE70-6EE3-456A-8FD1-BE28AB9292BC}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0461909A-E363-4796-8BF5-E9225F8B2DEB}
    HKCR\CLSID\{0461909A-E363-4796-8BF5-E9225F8B2DEB}
    HKCR\CLSID\{0461909A-E363-4796-8BF5-E9225F8B2DEB}\InprocServer32
    HKCR\CLSID\{0461909A-E363-4796-8BF5-E9225F8B2DEB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0478D762-0F62-4A18-8A38-6137647A1102}
    HKCR\CLSID\{0478D762-0F62-4A18-8A38-6137647A1102}
    HKCR\CLSID\{0478D762-0F62-4A18-8A38-6137647A1102}\InprocServer32
    HKCR\CLSID\{0478D762-0F62-4A18-8A38-6137647A1102}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0480D5A4-D9DF-48C6-97FF-ACA606DE894A}
    HKCR\CLSID\{0480D5A4-D9DF-48C6-97FF-ACA606DE894A}
    HKCR\CLSID\{0480D5A4-D9DF-48C6-97FF-ACA606DE894A}\InprocServer32
    HKCR\CLSID\{0480D5A4-D9DF-48C6-97FF-ACA606DE894A}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04865A6E-929E-4D2C-9D33-5D9F1C96784B}
    HKCR\CLSID\{04865A6E-929E-4D2C-9D33-5D9F1C96784B}
    HKCR\CLSID\{04865A6E-929E-4D2C-9D33-5D9F1C96784B}\InprocServer32
    HKCR\CLSID\{04865A6E-929E-4D2C-9D33-5D9F1C96784B}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04967550-C698-4241-910F-92BACB662335}
    HKCR\CLSID\{04967550-C698-4241-910F-92BACB662335}
    HKCR\CLSID\{04967550-C698-4241-910F-92BACB662335}\InprocServer32
    HKCR\CLSID\{04967550-C698-4241-910F-92BACB662335}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04B1CE52-9644-4591-9BDD-68CBC233E3CC}
    HKCR\CLSID\{04B1CE52-9644-4591-9BDD-68CBC233E3CC}
    HKCR\CLSID\{04B1CE52-9644-4591-9BDD-68CBC233E3CC}\InprocServer32
    HKCR\CLSID\{04B1CE52-9644-4591-9BDD-68CBC233E3CC}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04B3F401-0C41-4E06-AC0E-AD9CB45450FA}
    HKCR\CLSID\{04B3F401-0C41-4E06-AC0E-AD9CB45450FA}
    HKCR\CLSID\{04B3F401-0C41-4E06-AC0E-AD9CB45450FA}\InprocServer32
    HKCR\CLSID\{04B3F401-0C41-4E06-AC0E-AD9CB45450FA}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04C3524A-F749-4E1D-BC94-DAF08446C325}
    HKCR\CLSID\{04C3524A-F749-4E1D-BC94-DAF08446C325}
    HKCR\CLSID\{04C3524A-F749-4E1D-BC94-DAF08446C325}\InprocServer32
    HKCR\CLSID\{04C3524A-F749-4E1D-BC94-DAF08446C325}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04CB329B-CB9D-4C46-87F4-1EFE70949BCC}
    HKCR\CLSID\{04CB329B-CB9D-4C46-87F4-1EFE70949BCC}
    HKCR\CLSID\{04CB329B-CB9D-4C46-87F4-1EFE70949BCC}\InprocServer32
    HKCR\CLSID\{04CB329B-CB9D-4C46-87F4-1EFE70949BCC}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04D65C5E-4B25-49F8-B97A-DCFD8B7D84FB}
    HKCR\CLSID\{04D65C5E-4B25-49F8-B97A-DCFD8B7D84FB}
    HKCR\CLSID\{04D65C5E-4B25-49F8-B97A-DCFD8B7D84FB}\InprocServer32
    HKCR\CLSID\{04D65C5E-4B25-49F8-B97A-DCFD8B7D84FB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04E9AE9D-FE94-431E-A82A-0E8D817AC4B4}
    HKCR\CLSID\{04E9AE9D-FE94-431E-A82A-0E8D817AC4B4}
    HKCR\CLSID\{04E9AE9D-FE94-431E-A82A-0E8D817AC4B4}\InprocServer32
    HKCR\CLSID\{04E9AE9D-FE94-431E-A82A-0E8D817AC4B4}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{04FEFE6D-3CD0-466E-A7B5-121DC6D77047}
    HKCR\CLSID\{04FEFE6D-3CD0-466E-A7B5-121DC6D77047}
    HKCR\CLSID\{04FEFE6D-3CD0-466E-A7B5-121DC6D77047}\InprocServer32
    HKCR\CLSID\{04FEFE6D-3CD0-466E-A7B5-121DC6D77047}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{050CB723-473D-43B5-B324-29B80994A361}
    HKCR\CLSID\{050CB723-473D-43B5-B324-29B80994A361}
    HKCR\CLSID\{050CB723-473D-43B5-B324-29B80994A361}\InprocServer32
    HKCR\CLSID\{050CB723-473D-43B5-B324-29B80994A361}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0510CAE6-A8CD-4B01-9192-1B2811F74691}
    HKCR\CLSID\{0510CAE6-A8CD-4B01-9192-1B2811F74691}
    HKCR\CLSID\{0510CAE6-A8CD-4B01-9192-1B2811F74691}\InprocServer32
    HKCR\CLSID\{0510CAE6-A8CD-4B01-9192-1B2811F74691}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0539F9D7-D1CC-4432-8BE2-BF674D32190D}
    HKCR\CLSID\{0539F9D7-D1CC-4432-8BE2-BF674D32190D}
    HKCR\CLSID\{0539F9D7-D1CC-4432-8BE2-BF674D32190D}\InprocServer32
    HKCR\CLSID\{0539F9D7-D1CC-4432-8BE2-BF674D32190D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{053EFDC6-167A-49D4-AE97-56D150DD91EE}
    HKCR\CLSID\{053EFDC6-167A-49D4-AE97-56D150DD91EE}
    HKCR\CLSID\{053EFDC6-167A-49D4-AE97-56D150DD91EE}\InprocServer32
    HKCR\CLSID\{053EFDC6-167A-49D4-AE97-56D150DD91EE}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05568DC9-60B8-4B07-8633-050582AE5883}
    HKCR\CLSID\{05568DC9-60B8-4B07-8633-050582AE5883}
    HKCR\CLSID\{05568DC9-60B8-4B07-8633-050582AE5883}\InprocServer32
    HKCR\CLSID\{05568DC9-60B8-4B07-8633-050582AE5883}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0558012E-A587-484D-AD49-0C161F27F6C0}
    HKCR\CLSID\{0558012E-A587-484D-AD49-0C161F27F6C0}
    HKCR\CLSID\{0558012E-A587-484D-AD49-0C161F27F6C0}\InprocServer32
    HKCR\CLSID\{0558012E-A587-484D-AD49-0C161F27F6C0}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{056C2FF2-616C-42B6-900B-DF3D3E5A3C51}
    HKCR\CLSID\{056C2FF2-616C-42B6-900B-DF3D3E5A3C51}
    HKCR\CLSID\{056C2FF2-616C-42B6-900B-DF3D3E5A3C51}\InprocServer32
    HKCR\CLSID\{056C2FF2-616C-42B6-900B-DF3D3E5A3C51}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05947AEB-1C53-427B-9D30-A4590F5890FC}
    HKCR\CLSID\{05947AEB-1C53-427B-9D30-A4590F5890FC}
    HKCR\CLSID\{05947AEB-1C53-427B-9D30-A4590F5890FC}\InprocServer32
    HKCR\CLSID\{05947AEB-1C53-427B-9D30-A4590F5890FC}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05A02968-623F-424B-ACC7-E617C7FDF3D9}
    HKCR\CLSID\{05A02968-623F-424B-ACC7-E617C7FDF3D9}
    HKCR\CLSID\{05A02968-623F-424B-ACC7-E617C7FDF3D9}\InprocServer32
    HKCR\CLSID\{05A02968-623F-424B-ACC7-E617C7FDF3D9}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05B2D05F-DB6A-421D-AABE-517995E06BB5}
    HKCR\CLSID\{05B2D05F-DB6A-421D-AABE-517995E06BB5}
    HKCR\CLSID\{05B2D05F-DB6A-421D-AABE-517995E06BB5}\InprocServer32
    HKCR\CLSID\{05B2D05F-DB6A-421D-AABE-517995E06BB5}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05BA01FF-1C9E-4923-8990-0A7435AB56FB}
    HKCR\CLSID\{05BA01FF-1C9E-4923-8990-0A7435AB56FB}
    HKCR\CLSID\{05BA01FF-1C9E-4923-8990-0A7435AB56FB}\InprocServer32
    HKCR\CLSID\{05BA01FF-1C9E-4923-8990-0A7435AB56FB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05BF0B9A-00CD-45BD-A61B-B852A0600FD0}
    HKCR\CLSID\{05BF0B9A-00CD-45BD-A61B-B852A0600FD0}
    HKCR\CLSID\{05BF0B9A-00CD-45BD-A61B-B852A0600FD0}\InprocServer32
    HKCR\CLSID\{05BF0B9A-00CD-45BD-A61B-B852A0600FD0}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05D73E5B-F692-4E16-9A95-40C7BF9688C0}
    HKCR\CLSID\{05D73E5B-F692-4E16-9A95-40C7BF9688C0}
    HKCR\CLSID\{05D73E5B-F692-4E16-9A95-40C7BF9688C0}\InprocServer32
    HKCR\CLSID\{05D73E5B-F692-4E16-9A95-40C7BF9688C0}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05D7C780-E16C-4C4E-AA62-67A2A5847264}
    HKCR\CLSID\{05D7C780-E16C-4C4E-AA62-67A2A5847264}
    HKCR\CLSID\{05D7C780-E16C-4C4E-AA62-67A2A5847264}\InprocServer32
    HKCR\CLSID\{05D7C780-E16C-4C4E-AA62-67A2A5847264}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05DA84CB-009C-4A24-8E85-4939E30BF6C0}
    HKCR\CLSID\{05DA84CB-009C-4A24-8E85-4939E30BF6C0}
    HKCR\CLSID\{05DA84CB-009C-4A24-8E85-4939E30BF6C0}\InprocServer32
    HKCR\CLSID\{05DA84CB-009C-4A24-8E85-4939E30BF6C0}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05DE4FF0-1A82-41AB-9871-C8CF227547DA}
    HKCR\CLSID\{05DE4FF0-1A82-41AB-9871-C8CF227547DA}
    HKCR\CLSID\{05DE4FF0-1A82-41AB-9871-C8CF227547DA}\InprocServer32
    HKCR\CLSID\{05DE4FF0-1A82-41AB-9871-C8CF227547DA}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05DF01C3-A6BF-426F-9DAD-989CA7FC6150}
    HKCR\CLSID\{05DF01C3-A6BF-426F-9DAD-989CA7FC6150}
    HKCR\CLSID\{05DF01C3-A6BF-426F-9DAD-989CA7FC6150}\InprocServer32
    HKCR\CLSID\{05DF01C3-A6BF-426F-9DAD-989CA7FC6150}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05E11E40-CEEB-400C-8E08-B1E140FB06D4}
    HKCR\CLSID\{05E11E40-CEEB-400C-8E08-B1E140FB06D4}
    HKCR\CLSID\{05E11E40-CEEB-400C-8E08-B1E140FB06D4}\InprocServer32
    HKCR\CLSID\{05E11E40-CEEB-400C-8E08-B1E140FB06D4}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05F69CE8-F499-45F9-9F61-93A16BBDCE90}
    HKCR\CLSID\{05F69CE8-F499-45F9-9F61-93A16BBDCE90}
    HKCR\CLSID\{05F69CE8-F499-45F9-9F61-93A16BBDCE90}\InprocServer32
    HKCR\CLSID\{05F69CE8-F499-45F9-9F61-93A16BBDCE90}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{05FA31E5-12BB-4F89-81F4-7A3097B21B22}
    HKCR\CLSID\{05FA31E5-12BB-4F89-81F4-7A3097B21B22}
    HKCR\CLSID\{05FA31E5-12BB-4F89-81F4-7A3097B21B22}\InprocServer32
    HKCR\CLSID\{05FA31E5-12BB-4F89-81F4-7A3097B21B22}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06293B09-69E1-4843-94C2-60A1D16C2F96}
    HKCR\CLSID\{06293B09-69E1-4843-94C2-60A1D16C2F96}
    HKCR\CLSID\{06293B09-69E1-4843-94C2-60A1D16C2F96}\InprocServer32
    HKCR\CLSID\{06293B09-69E1-4843-94C2-60A1D16C2F96}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{062E6E46-2C26-4B99-B19D-6D22CA17FBC4}
    HKCR\CLSID\{062E6E46-2C26-4B99-B19D-6D22CA17FBC4}
    HKCR\CLSID\{062E6E46-2C26-4B99-B19D-6D22CA17FBC4}\InprocServer32
    HKCR\CLSID\{062E6E46-2C26-4B99-B19D-6D22CA17FBC4}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{064C0B97-7EF4-4C53-AFB3-9FB49742BC56}
    HKCR\CLSID\{064C0B97-7EF4-4C53-AFB3-9FB49742BC56}
    HKCR\CLSID\{064C0B97-7EF4-4C53-AFB3-9FB49742BC56}\InprocServer32
    HKCR\CLSID\{064C0B97-7EF4-4C53-AFB3-9FB49742BC56}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{065B5194-F5B6-478A-A490-1CFF235479B5}
    HKCR\CLSID\{065B5194-F5B6-478A-A490-1CFF235479B5}
    HKCR\CLSID\{065B5194-F5B6-478A-A490-1CFF235479B5}\InprocServer32
    HKCR\CLSID\{065B5194-F5B6-478A-A490-1CFF235479B5}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{065B9B24-8DC0-4C7A-8B65-7B54A9EC2255}
    HKCR\CLSID\{065B9B24-8DC0-4C7A-8B65-7B54A9EC2255}
    HKCR\CLSID\{065B9B24-8DC0-4C7A-8B65-7B54A9EC2255}\InprocServer32
    HKCR\CLSID\{065B9B24-8DC0-4C7A-8B65-7B54A9EC2255}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{066B062F-73D8-407A-9ED7-46FAB7C57239}
    HKCR\CLSID\{066B062F-73D8-407A-9ED7-46FAB7C57239}
    HKCR\CLSID\{066B062F-73D8-407A-9ED7-46FAB7C57239}\InprocServer32
    HKCR\CLSID\{066B062F-73D8-407A-9ED7-46FAB7C57239}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0683B735-49C5-47EF-AC4F-399D5E1A3860}
    HKCR\CLSID\{0683B735-49C5-47EF-AC4F-399D5E1A3860}
    HKCR\CLSID\{0683B735-49C5-47EF-AC4F-399D5E1A3860}\InprocServer32
    HKCR\CLSID\{0683B735-49C5-47EF-AC4F-399D5E1A3860}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{069CB848-579C-4AA7-96D8-E441B9D92E3C}
    HKCR\CLSID\{069CB848-579C-4AA7-96D8-E441B9D92E3C}
    HKCR\CLSID\{069CB848-579C-4AA7-96D8-E441B9D92E3C}\InprocServer32
    HKCR\CLSID\{069CB848-579C-4AA7-96D8-E441B9D92E3C}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{069D8B4F-96F5-440F-BF29-44A2089695B1}
    HKCR\CLSID\{069D8B4F-96F5-440F-BF29-44A2089695B1}
    HKCR\CLSID\{069D8B4F-96F5-440F-BF29-44A2089695B1}\InprocServer32
    HKCR\CLSID\{069D8B4F-96F5-440F-BF29-44A2089695B1}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06ACBB2E-FDF8-418E-A8EF-F3F84A1A0343}
    HKCR\CLSID\{06ACBB2E-FDF8-418E-A8EF-F3F84A1A0343}
    HKCR\CLSID\{06ACBB2E-FDF8-418E-A8EF-F3F84A1A0343}\InprocServer32
    HKCR\CLSID\{06ACBB2E-FDF8-418E-A8EF-F3F84A1A0343}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06ACE783-F1A6-4A81-A692-804CF5D84FAA}
    HKCR\CLSID\{06ACE783-F1A6-4A81-A692-804CF5D84FAA}
    HKCR\CLSID\{06ACE783-F1A6-4A81-A692-804CF5D84FAA}\InprocServer32
    HKCR\CLSID\{06ACE783-F1A6-4A81-A692-804CF5D84FAA}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06AD81B5-1F7F-4497-91BE-65101E32C017}
    HKCR\CLSID\{06AD81B5-1F7F-4497-91BE-65101E32C017}
    HKCR\CLSID\{06AD81B5-1F7F-4497-91BE-65101E32C017}\InprocServer32
    HKCR\CLSID\{06AD81B5-1F7F-4497-91BE-65101E32C017}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06B3273F-A318-48F3-A441-FB64C52B8EBB}
    HKCR\CLSID\{06B3273F-A318-48F3-A441-FB64C52B8EBB}
    HKCR\CLSID\{06B3273F-A318-48F3-A441-FB64C52B8EBB}\InprocServer32
    HKCR\CLSID\{06B3273F-A318-48F3-A441-FB64C52B8EBB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06B8CD78-67DD-40FE-B963-4FB2A1AF4BB2}
    HKCR\CLSID\{06B8CD78-67DD-40FE-B963-4FB2A1AF4BB2}
    HKCR\CLSID\{06B8CD78-67DD-40FE-B963-4FB2A1AF4BB2}\InprocServer32
    HKCR\CLSID\{06B8CD78-67DD-40FE-B963-4FB2A1AF4BB2}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06E1419E-010C-4756-979A-298E4245F6A3}
    HKCR\CLSID\{06E1419E-010C-4756-979A-298E4245F6A3}
    HKCR\CLSID\{06E1419E-010C-4756-979A-298E4245F6A3}\InprocServer32
    HKCR\CLSID\{06E1419E-010C-4756-979A-298E4245F6A3}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06F138DB-D815-4A36-9B37-93ADE0D2C991}
    HKCR\CLSID\{06F138DB-D815-4A36-9B37-93ADE0D2C991}
    HKCR\CLSID\{06F138DB-D815-4A36-9B37-93ADE0D2C991}\InprocServer32
    HKCR\CLSID\{06F138DB-D815-4A36-9B37-93ADE0D2C991}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{06FD6A6F-D848-4B67-8C91-24133B4AD810}
    HKCR\CLSID\{06FD6A6F-D848-4B67-8C91-24133B4AD810}
    HKCR\CLSID\{06FD6A6F-D848-4B67-8C91-24133B4AD810}\InprocServer32
    HKCR\CLSID\{06FD6A6F-D848-4B67-8C91-24133B4AD810}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{071E0CFE-7C53-40B4-B101-F5648AAAD96E}
    HKCR\CLSID\{071E0CFE-7C53-40B4-B101-F5648AAAD96E}
    HKCR\CLSID\{071E0CFE-7C53-40B4-B101-F5648AAAD96E}\InprocServer32
    HKCR\CLSID\{071E0CFE-7C53-40B4-B101-F5648AAAD96E}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{07315E0B-6A4E-4B43-9614-7F5A844E4443}
    HKCR\CLSID\{07315E0B-6A4E-4B43-9614-7F5A844E4443}
    HKCR\CLSID\{07315E0B-6A4E-4B43-9614-7F5A844E4443}\InprocServer32
    HKCR\CLSID\{07315E0B-6A4E-4B43-9614-7F5A844E4443}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{075CEE83-5E84-4E8C-B1ED-CBAA58AEA058}
    HKCR\CLSID\{075CEE83-5E84-4E8C-B1ED-CBAA58AEA058}
    HKCR\CLSID\{075CEE83-5E84-4E8C-B1ED-CBAA58AEA058}\InprocServer32
    HKCR\CLSID\{075CEE83-5E84-4E8C-B1ED-CBAA58AEA058}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{07758355-F363-4334-9D3A-96BF8F5CE459}
    HKCR\CLSID\{07758355-F363-4334-9D3A-96BF8F5CE459}
    HKCR\CLSID\{07758355-F363-4334-9D3A-96BF8F5CE459}\InprocServer32
    HKCR\CLSID\{07758355-F363-4334-9D3A-96BF8F5CE459}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{077845E9-5ED1-4D71-99A8-AEC71932FB7D}
    HKCR\CLSID\{077845E9-5ED1-4D71-99A8-AEC71932FB7D}
    HKCR\CLSID\{077845E9-5ED1-4D71-99A8-AEC71932FB7D}\InprocServer32
    HKCR\CLSID\{077845E9-5ED1-4D71-99A8-AEC71932FB7D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0787C239-DA3F-4B9D-87D2-716E47BDCEB4}
    HKCR\CLSID\{0787C239-DA3F-4B9D-87D2-716E47BDCEB4}
    HKCR\CLSID\{0787C239-DA3F-4B9D-87D2-716E47BDCEB4}\InprocServer32
    HKCR\CLSID\{0787C239-DA3F-4B9D-87D2-716E47BDCEB4}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0788780A-9B4F-498A-992E-3A17770A4A0D}
    HKCR\CLSID\{0788780A-9B4F-498A-992E-3A17770A4A0D}
    HKCR\CLSID\{0788780A-9B4F-498A-992E-3A17770A4A0D}\InprocServer32
    HKCR\CLSID\{0788780A-9B4F-498A-992E-3A17770A4A0D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{07894F91-557A-4E65-A46E-FE0DC670F558}
    HKCR\CLSID\{07894F91-557A-4E65-A46E-FE0DC670F558}
    HKCR\CLSID\{07894F91-557A-4E65-A46E-FE0DC670F558}\InprocServer32
    HKCR\CLSID\{07894F91-557A-4E65-A46E-FE0DC670F558}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{079BB492-88B5-4B58-BBB5-C5A76304CE9E}
    HKCR\CLSID\{079BB492-88B5-4B58-BBB5-C5A76304CE9E}
    HKCR\CLSID\{079BB492-88B5-4B58-BBB5-C5A76304CE9E}\InprocServer32
    HKCR\CLSID\{079BB492-88B5-4B58-BBB5-C5A76304CE9E}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{079C30F4-5ECC-4D46-A422-3469E3EC921D}
    HKCR\CLSID\{079C30F4-5ECC-4D46-A422-3469E3EC921D}
    HKCR\CLSID\{079C30F4-5ECC-4D46-A422-3469E3EC921D}\InprocServer32
    HKCR\CLSID\{079C30F4-5ECC-4D46-A422-3469E3EC921D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{07A49D2A-993E-4F16-8D64-A45D84BA4C03}
    HKCR\CLSID\{07A49D2A-993E-4F16-8D64-A45D84BA4C03}
    HKCR\CLSID\{07A49D2A-993E-4F16-8D64-A45D84BA4C03}\InprocServer32
    HKCR\CLSID\{07A49D2A-993E-4F16-8D64-A45D84BA4C03}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{07FAB381-6B6A-4AC5-8A92-EDE0E271F190}
    HKCR\CLSID\{07FAB381-6B6A-4AC5-8A92-EDE0E271F190}
    HKCR\CLSID\{07FAB381-6B6A-4AC5-8A92-EDE0E271F190}\InprocServer32
    HKCR\CLSID\{07FAB381-6B6A-4AC5-8A92-EDE0E271F190}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{083589E1-7727-464A-8D5E-D7E3F9ECE177}
    HKCR\CLSID\{083589E1-7727-464A-8D5E-D7E3F9ECE177}
    HKCR\CLSID\{083589E1-7727-464A-8D5E-D7E3F9ECE177}\InprocServer32
    HKCR\CLSID\{083589E1-7727-464A-8D5E-D7E3F9ECE177}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0861863F-5AAE-45A5-B575-380DADB93C64}
    HKCR\CLSID\{0861863F-5AAE-45A5-B575-380DADB93C64}
    HKCR\CLSID\{0861863F-5AAE-45A5-B575-380DADB93C64}\InprocServer32
    HKCR\CLSID\{0861863F-5AAE-45A5-B575-380DADB93C64}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0863E440-DAF5-468A-A70F-6329E5B6737B}
    HKCR\CLSID\{0863E440-DAF5-468A-A70F-6329E5B6737B}
    HKCR\CLSID\{0863E440-DAF5-468A-A70F-6329E5B6737B}\InprocServer32
    HKCR\CLSID\{0863E440-DAF5-468A-A70F-6329E5B6737B}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0874F2A1-9803-48CD-8897-CB02F520046B}
    HKCR\CLSID\{0874F2A1-9803-48CD-8897-CB02F520046B}
    HKCR\CLSID\{0874F2A1-9803-48CD-8897-CB02F520046B}\InprocServer32
    HKCR\CLSID\{0874F2A1-9803-48CD-8897-CB02F520046B}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{08A55639-952E-4F19-8866-B4252DFEBAF7}
    HKCR\CLSID\{08A55639-952E-4F19-8866-B4252DFEBAF7}
    HKCR\CLSID\{08A55639-952E-4F19-8866-B4252DFEBAF7}\InprocServer32
    HKCR\CLSID\{08A55639-952E-4F19-8866-B4252DFEBAF7}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{08AA18DE-8378-46FD-9771-23B24FD33C8D}
    HKCR\CLSID\{08AA18DE-8378-46FD-9771-23B24FD33C8D}
    HKCR\CLSID\{08AA18DE-8378-46FD-9771-23B24FD33C8D}\InprocServer32
    HKCR\CLSID\{08AA18DE-8378-46FD-9771-23B24FD33C8D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{08CF8623-F294-4600-BDCE-4488AE102F6E}
    HKCR\CLSID\{08CF8623-F294-4600-BDCE-4488AE102F6E}
    HKCR\CLSID\{08CF8623-F294-4600-BDCE-4488AE102F6E}\InprocServer32
    HKCR\CLSID\{08CF8623-F294-4600-BDCE-4488AE102F6E}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{090ACFAE-F5B3-4769-8292-6FD84B45C064}
    HKCR\CLSID\{090ACFAE-F5B3-4769-8292-6FD84B45C064}
    HKCR\CLSID\{090ACFAE-F5B3-4769-8292-6FD84B45C064}\InprocServer32
    HKCR\CLSID\{090ACFAE-F5B3-4769-8292-6FD84B45C064}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{09157280-8915-46F8-ABFD-07C443BF042F}
    HKCR\CLSID\{09157280-8915-46F8-ABFD-07C443BF042F}
    HKCR\CLSID\{09157280-8915-46F8-ABFD-07C443BF042F}\InprocServer32
    HKCR\CLSID\{09157280-8915-46F8-ABFD-07C443BF042F}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{09195339-2030-435D-A7D3-9BC35B4725FC}
    HKCR\CLSID\{09195339-2030-435D-A7D3-9BC35B4725FC}
    HKCR\CLSID\{09195339-2030-435D-A7D3-9BC35B4725FC}\InprocServer32
    HKCR\CLSID\{09195339-2030-435D-A7D3-9BC35B4725FC}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{091ACFC3-BD51-4D2A-966A-2D5D03E8F105}
    HKCR\CLSID\{091ACFC3-BD51-4D2A-966A-2D5D03E8F105}
    HKCR\CLSID\{091ACFC3-BD51-4D2A-966A-2D5D03E8F105}\InprocServer32
    HKCR\CLSID\{091ACFC3-BD51-4D2A-966A-2D5D03E8F105}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{091FEB5D-B0BD-41C3-9146-10C67097F04D}
    HKCR\CLSID\{091FEB5D-B0BD-41C3-9146-10C67097F04D}
    HKCR\CLSID\{091FEB5D-B0BD-41C3-9146-10C67097F04D}\InprocServer32
    HKCR\CLSID\{091FEB5D-B0BD-41C3-9146-10C67097F04D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0939FF96-98B4-4221-B1D6-B73442CB1A00}
    HKCR\CLSID\{0939FF96-98B4-4221-B1D6-B73442CB1A00}
    HKCR\CLSID\{0939FF96-98B4-4221-B1D6-B73442CB1A00}\InprocServer32
    HKCR\CLSID\{0939FF96-98B4-4221-B1D6-B73442CB1A00}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{096E152A-B387-4179-ACFB-F0AF9A6041A3}
    HKCR\CLSID\{096E152A-B387-4179-ACFB-F0AF9A6041A3}
    HKCR\CLSID\{096E152A-B387-4179-ACFB-F0AF9A6041A3}\InprocServer32
    HKCR\CLSID\{096E152A-B387-4179-ACFB-F0AF9A6041A3}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{098E9770-5C42-4585-840F-C9FB6B975739}
    HKCR\CLSID\{098E9770-5C42-4585-840F-C9FB6B975739}
    HKCR\CLSID\{098E9770-5C42-4585-840F-C9FB6B975739}\InprocServer32
    HKCR\CLSID\{098E9770-5C42-4585-840F-C9FB6B975739}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{099BDD28-204E-4E4A-8D64-AC778FDC2B98}
    HKCR\CLSID\{099BDD28-204E-4E4A-8D64-AC778FDC2B98}
    HKCR\CLSID\{099BDD28-204E-4E4A-8D64-AC778FDC2B98}\InprocServer32
    HKCR\CLSID\{099BDD28-204E-4E4A-8D64-AC778FDC2B98}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{09A3879A-098C-44E3-8EEF-835B500F6ADB}
    HKCR\CLSID\{09A3879A-098C-44E3-8EEF-835B500F6ADB}
    HKCR\CLSID\{09A3879A-098C-44E3-8EEF-835B500F6ADB}\InprocServer32
    HKCR\CLSID\{09A3879A-098C-44E3-8EEF-835B500F6ADB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{09C48A56-A6CE-4FD8-8358-9F43F68FFA55}
    HKCR\CLSID\{09C48A56-A6CE-4FD8-8358-9F43F68FFA55}
    HKCR\CLSID\{09C48A56-A6CE-4FD8-8358-9F43F68FFA55}\InprocServer32
    HKCR\CLSID\{09C48A56-A6CE-4FD8-8358-9F43F68FFA55}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{09CB6D6C-AB3E-4E80-8C3B-8B7DD78AB25E}
    HKCR\CLSID\{09CB6D6C-AB3E-4E80-8C3B-8B7DD78AB25E}
    HKCR\CLSID\{09CB6D6C-AB3E-4E80-8C3B-8B7DD78AB25E}\InprocServer32
    HKCR\CLSID\{09CB6D6C-AB3E-4E80-8C3B-8B7DD78AB25E}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{09DE6F6A-FB54-43A2-A294-C6F152EEE906}
    HKCR\CLSID\{09DE6F6A-FB54-43A2-A294-C6F152EEE906}
    HKCR\CLSID\{09DE6F6A-FB54-43A2-A294-C6F152EEE906}\InprocServer32
    HKCR\CLSID\{09DE6F6A-FB54-43A2-A294-C6F152EEE906}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{09F300B7-DACA-4CD8-A9A3-010D8E6A3F2E}
    HKCR\CLSID\{09F300B7-DACA-4CD8-A9A3-010D8E6A3F2E}
    HKCR\CLSID\{09F300B7-DACA-4CD8-A9A3-010D8E6A3F2E}\InprocServer32
    HKCR\CLSID\{09F300B7-DACA-4CD8-A9A3-010D8E6A3F2E}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A019AF6-4121-47DC-B82F-A14E89F9399F}
    HKCR\CLSID\{0A019AF6-4121-47DC-B82F-A14E89F9399F}
    HKCR\CLSID\{0A019AF6-4121-47DC-B82F-A14E89F9399F}\InprocServer32
    HKCR\CLSID\{0A019AF6-4121-47DC-B82F-A14E89F9399F}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A22E166-18E7-46A5-BC56-1B7DC830EDCD}
    HKCR\CLSID\{0A22E166-18E7-46A5-BC56-1B7DC830EDCD}
    HKCR\CLSID\{0A22E166-18E7-46A5-BC56-1B7DC830EDCD}\InprocServer32
    HKCR\CLSID\{0A22E166-18E7-46A5-BC56-1B7DC830EDCD}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A2DA81B-0C5C-4DDF-AC83-93B7AC5449CB}
    HKCR\CLSID\{0A2DA81B-0C5C-4DDF-AC83-93B7AC5449CB}
    HKCR\CLSID\{0A2DA81B-0C5C-4DDF-AC83-93B7AC5449CB}\InprocServer32
    HKCR\CLSID\{0A2DA81B-0C5C-4DDF-AC83-93B7AC5449CB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A2FB96A-FDB9-4FF0-A2DD-BD2F93C3F706}
    HKCR\CLSID\{0A2FB96A-FDB9-4FF0-A2DD-BD2F93C3F706}
    HKCR\CLSID\{0A2FB96A-FDB9-4FF0-A2DD-BD2F93C3F706}\InprocServer32
    HKCR\CLSID\{0A2FB96A-FDB9-4FF0-A2DD-BD2F93C3F706}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A3BCB59-22C3-4D3D-BFC8-49871C810D3D}
    HKCR\CLSID\{0A3BCB59-22C3-4D3D-BFC8-49871C810D3D}
    HKCR\CLSID\{0A3BCB59-22C3-4D3D-BFC8-49871C810D3D}\InprocServer32
    HKCR\CLSID\{0A3BCB59-22C3-4D3D-BFC8-49871C810D3D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A4A0980-5E96-4245-A840-6ED6E5CC2076}
    HKCR\CLSID\{0A4A0980-5E96-4245-A840-6ED6E5CC2076}
    HKCR\CLSID\{0A4A0980-5E96-4245-A840-6ED6E5CC2076}\InprocServer32
    HKCR\CLSID\{0A4A0980-5E96-4245-A840-6ED6E5CC2076}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A6414E8-1A94-491A-8D36-7BD5A9E63177}
    HKCR\CLSID\{0A6414E8-1A94-491A-8D36-7BD5A9E63177}
    HKCR\CLSID\{0A6414E8-1A94-491A-8D36-7BD5A9E63177}\InprocServer32
    HKCR\CLSID\{0A6414E8-1A94-491A-8D36-7BD5A9E63177}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A90EAB5-7913-4D7B-AEDE-7F8DDCA68142}
    HKCR\CLSID\{0A90EAB5-7913-4D7B-AEDE-7F8DDCA68142}
    HKCR\CLSID\{0A90EAB5-7913-4D7B-AEDE-7F8DDCA68142}\InprocServer32
    HKCR\CLSID\{0A90EAB5-7913-4D7B-AEDE-7F8DDCA68142}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0A99E858-9E5A-4BEF-BE73-1E8B53725007}
    HKCR\CLSID\{0A99E858-9E5A-4BEF-BE73-1E8B53725007}
    HKCR\CLSID\{0A99E858-9E5A-4BEF-BE73-1E8B53725007}\InprocServer32
    HKCR\CLSID\{0A99E858-9E5A-4BEF-BE73-1E8B53725007}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0AAC4CF0-3F2B-4FF0-97ED-B195D4A90D93}
    HKCR\CLSID\{0AAC4CF0-3F2B-4FF0-97ED-B195D4A90D93}
    HKCR\CLSID\{0AAC4CF0-3F2B-4FF0-97ED-B195D4A90D93}\InprocServer32
    HKCR\CLSID\{0AAC4CF0-3F2B-4FF0-97ED-B195D4A90D93}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B130860-5950-4A77-A23F-113CB850093C}
    HKCR\CLSID\{0B130860-5950-4A77-A23F-113CB850093C}
    HKCR\CLSID\{0B130860-5950-4A77-A23F-113CB850093C}\InprocServer32
    HKCR\CLSID\{0B130860-5950-4A77-A23F-113CB850093C}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B1AE338-8D82-4268-BFC6-9721084C5FB8}
    HKCR\CLSID\{0B1AE338-8D82-4268-BFC6-9721084C5FB8}
    HKCR\CLSID\{0B1AE338-8D82-4268-BFC6-9721084C5FB8}\InprocServer32
    HKCR\CLSID\{0B1AE338-8D82-4268-BFC6-9721084C5FB8}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B1CB3FA-E88C-462A-9CBF-DDCF80676F64}
    HKCR\CLSID\{0B1CB3FA-E88C-462A-9CBF-DDCF80676F64}
    HKCR\CLSID\{0B1CB3FA-E88C-462A-9CBF-DDCF80676F64}\InprocServer32
    HKCR\CLSID\{0B1CB3FA-E88C-462A-9CBF-DDCF80676F64}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B1EB155-0958-4EBF-A5B3-74A02C68530F}
    HKCR\CLSID\{0B1EB155-0958-4EBF-A5B3-74A02C68530F}
    HKCR\CLSID\{0B1EB155-0958-4EBF-A5B3-74A02C68530F}\InprocServer32
    HKCR\CLSID\{0B1EB155-0958-4EBF-A5B3-74A02C68530F}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B1F9D4D-4C09-4B8A-A2A9-5BF66E47C043}
    HKCR\CLSID\{0B1F9D4D-4C09-4B8A-A2A9-5BF66E47C043}
    HKCR\CLSID\{0B1F9D4D-4C09-4B8A-A2A9-5BF66E47C043}\InprocServer32
    HKCR\CLSID\{0B1F9D4D-4C09-4B8A-A2A9-5BF66E47C043}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B2A6584-C231-40DC-BF82-4C5EEAD6D3B3}
    HKCR\CLSID\{0B2A6584-C231-40DC-BF82-4C5EEAD6D3B3}
    HKCR\CLSID\{0B2A6584-C231-40DC-BF82-4C5EEAD6D3B3}\InprocServer32
    HKCR\CLSID\{0B2A6584-C231-40DC-BF82-4C5EEAD6D3B3}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B405CCA-EA88-43DC-A51F-AF82ECE5B273}
    HKCR\CLSID\{0B405CCA-EA88-43DC-A51F-AF82ECE5B273}
    HKCR\CLSID\{0B405CCA-EA88-43DC-A51F-AF82ECE5B273}\InprocServer32
    HKCR\CLSID\{0B405CCA-EA88-43DC-A51F-AF82ECE5B273}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B801C75-3E0C-49E4-8F2C-3CA96C87C4E3}
    HKCR\CLSID\{0B801C75-3E0C-49E4-8F2C-3CA96C87C4E3}
    HKCR\CLSID\{0B801C75-3E0C-49E4-8F2C-3CA96C87C4E3}\InprocServer32
    HKCR\CLSID\{0B801C75-3E0C-49E4-8F2C-3CA96C87C4E3}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0B8636DF-3D42-4293-8527-592C6015CD1E}
    HKCR\CLSID\{0B8636DF-3D42-4293-8527-592C6015CD1E}
    HKCR\CLSID\{0B8636DF-3D42-4293-8527-592C6015CD1E}\InprocServer32
    HKCR\CLSID\{0B8636DF-3D42-4293-8527-592C6015CD1E}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0BAA4C2A-BC77-4771-867D-E54582848C3F}
    HKCR\CLSID\{0BAA4C2A-BC77-4771-867D-E54582848C3F}
    HKCR\CLSID\{0BAA4C2A-BC77-4771-867D-E54582848C3F}\InprocServer32
    HKCR\CLSID\{0BAA4C2A-BC77-4771-867D-E54582848C3F}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0BB20BF0-D69B-4FB4-ABC1-F1C983F87945}
    HKCR\CLSID\{0BB20BF0-D69B-4FB4-ABC1-F1C983F87945}
    HKCR\CLSID\{0BB20BF0-D69B-4FB4-ABC1-F1C983F87945}\InprocServer32
    HKCR\CLSID\{0BB20BF0-D69B-4FB4-ABC1-F1C983F87945}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0BB8600F-5BE1-4DFB-8D65-3DB3BDC2D863}
    HKCR\CLSID\{0BB8600F-5BE1-4DFB-8D65-3DB3BDC2D863}
    HKCR\CLSID\{0BB8600F-5BE1-4DFB-8D65-3DB3BDC2D863}\InprocServer32
    HKCR\CLSID\{0BB8600F-5BE1-4DFB-8D65-3DB3BDC2D863}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0BC471F0-7320-4E28-9708-67DFAE711F19}
    HKCR\CLSID\{0BC471F0-7320-4E28-9708-67DFAE711F19}
    HKCR\CLSID\{0BC471F0-7320-4E28-9708-67DFAE711F19}\InprocServer32
    HKCR\CLSID\{0BC471F0-7320-4E28-9708-67DFAE711F19}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0BD32902-3859-4D89-ADB2-0025CCAA935D}
    HKCR\CLSID\{0BD32902-3859-4D89-ADB2-0025CCAA935D}
    HKCR\CLSID\{0BD32902-3859-4D89-ADB2-0025CCAA935D}\InprocServer32
    HKCR\CLSID\{0BD32902-3859-4D89-ADB2-0025CCAA935D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0BD69B52-2A3D-4BEB-9800-131FCE15EC01}
    HKCR\CLSID\{0BD69B52-2A3D-4BEB-9800-131FCE15EC01}
    HKCR\CLSID\{0BD69B52-2A3D-4BEB-9800-131FCE15EC01}\InprocServer32
    HKCR\CLSID\{0BD69B52-2A3D-4BEB-9800-131FCE15EC01}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0BFB6640-3B71-4711-9391-62985B26D87B}
    HKCR\CLSID\{0BFB6640-3B71-4711-9391-62985B26D87B}
    HKCR\CLSID\{0BFB6640-3B71-4711-9391-62985B26D87B}\InprocServer32
    HKCR\CLSID\{0BFB6640-3B71-4711-9391-62985B26D87B}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C071539-EF18-45CE-A545-01BABA4E9BAF}
    HKCR\CLSID\{0C071539-EF18-45CE-A545-01BABA4E9BAF}
    HKCR\CLSID\{0C071539-EF18-45CE-A545-01BABA4E9BAF}\InprocServer32
    HKCR\CLSID\{0C071539-EF18-45CE-A545-01BABA4E9BAF}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C099192-B71C-4B7B-8EDE-454FFC497915}
    HKCR\CLSID\{0C099192-B71C-4B7B-8EDE-454FFC497915}
    HKCR\CLSID\{0C099192-B71C-4B7B-8EDE-454FFC497915}\InprocServer32
    HKCR\CLSID\{0C099192-B71C-4B7B-8EDE-454FFC497915}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C09D1C1-C04B-4885-AA83-C2E19502C033}
    HKCR\CLSID\{0C09D1C1-C04B-4885-AA83-C2E19502C033}
    HKCR\CLSID\{0C09D1C1-C04B-4885-AA83-C2E19502C033}\InprocServer32
    HKCR\CLSID\{0C09D1C1-C04B-4885-AA83-C2E19502C033}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C1802A3-2F22-4277-A670-01DA823083DB}
    HKCR\CLSID\{0C1802A3-2F22-4277-A670-01DA823083DB}
    HKCR\CLSID\{0C1802A3-2F22-4277-A670-01DA823083DB}\InprocServer32
    HKCR\CLSID\{0C1802A3-2F22-4277-A670-01DA823083DB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C4A7646-5B34-46CB-A9F3-10E88F2DFDDC}
    HKCR\CLSID\{0C4A7646-5B34-46CB-A9F3-10E88F2DFDDC}
    HKCR\CLSID\{0C4A7646-5B34-46CB-A9F3-10E88F2DFDDC}\InprocServer32
    HKCR\CLSID\{0C4A7646-5B34-46CB-A9F3-10E88F2DFDDC}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C6E7C2F-4EEF-4B59-B42E-767759337587}
    HKCR\CLSID\{0C6E7C2F-4EEF-4B59-B42E-767759337587}
    HKCR\CLSID\{0C6E7C2F-4EEF-4B59-B42E-767759337587}\InprocServer32
    HKCR\CLSID\{0C6E7C2F-4EEF-4B59-B42E-767759337587}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C79888B-C024-457A-8696-CA207B14F414}
    HKCR\CLSID\{0C79888B-C024-457A-8696-CA207B14F414}
    HKCR\CLSID\{0C79888B-C024-457A-8696-CA207B14F414}\InprocServer32
    HKCR\CLSID\{0C79888B-C024-457A-8696-CA207B14F414}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C7B93FC-9690-44FD-B515-7535A5B032A6}
    HKCR\CLSID\{0C7B93FC-9690-44FD-B515-7535A5B032A6}
    HKCR\CLSID\{0C7B93FC-9690-44FD-B515-7535A5B032A6}\InprocServer32
    HKCR\CLSID\{0C7B93FC-9690-44FD-B515-7535A5B032A6}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C7F84BB-F9E3-4C04-A216-F56E0AD1E17F}
    HKCR\CLSID\{0C7F84BB-F9E3-4C04-A216-F56E0AD1E17F}
    HKCR\CLSID\{0C7F84BB-F9E3-4C04-A216-F56E0AD1E17F}\InprocServer32
    HKCR\CLSID\{0C7F84BB-F9E3-4C04-A216-F56E0AD1E17F}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0C818E9B-D4DC-4335-BED3-0E82E8A9F065}
    HKCR\CLSID\{0C818E9B-D4DC-4335-BED3-0E82E8A9F065}
    HKCR\CLSID\{0C818E9B-D4DC-4335-BED3-0E82E8A9F065}\InprocServer32
    HKCR\CLSID\{0C818E9B-D4DC-4335-BED3-0E82E8A9F065}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0CA4D6AD-EA4B-409A-BC1F-95093B998F97}
    HKCR\CLSID\{0CA4D6AD-EA4B-409A-BC1F-95093B998F97}
    HKCR\CLSID\{0CA4D6AD-EA4B-409A-BC1F-95093B998F97}\InprocServer32
    HKCR\CLSID\{0CA4D6AD-EA4B-409A-BC1F-95093B998F97}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0CA62528-41F4-4700-9804-9BB0217ECB19}
    HKCR\CLSID\{0CA62528-41F4-4700-9804-9BB0217ECB19}
    HKCR\CLSID\{0CA62528-41F4-4700-9804-9BB0217ECB19}\InprocServer32
    HKCR\CLSID\{0CA62528-41F4-4700-9804-9BB0217ECB19}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0CA99638-4414-43BF-8F00-EB268FDF37A6}
    HKCR\CLSID\{0CA99638-4414-43BF-8F00-EB268FDF37A6}
    HKCR\CLSID\{0CA99638-4414-43BF-8F00-EB268FDF37A6}\InprocServer32
    HKCR\CLSID\{0CA99638-4414-43BF-8F00-EB268FDF37A6}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0CBA1202-4F94-41C0-93A3-49ACB82A2033}
    HKCR\CLSID\{0CBA1202-4F94-41C0-93A3-49ACB82A2033}
    HKCR\CLSID\{0CBA1202-4F94-41C0-93A3-49ACB82A2033}\InprocServer32
    HKCR\CLSID\{0CBA1202-4F94-41C0-93A3-49ACB82A2033}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0CFA1ACD-8579-4C84-9EF8-0C5AE836C308}
    HKCR\CLSID\{0CFA1ACD-8579-4C84-9EF8-0C5AE836C308}
    HKCR\CLSID\{0CFA1ACD-8579-4C84-9EF8-0C5AE836C308}\InprocServer32
    HKCR\CLSID\{0CFA1ACD-8579-4C84-9EF8-0C5AE836C308}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0D33F978-6822-43E9-9413-5BCC4849D74F}
    HKCR\CLSID\{0D33F978-6822-43E9-9413-5BCC4849D74F}
    HKCR\CLSID\{0D33F978-6822-43E9-9413-5BCC4849D74F}\InprocServer32
    HKCR\CLSID\{0D33F978-6822-43E9-9413-5BCC4849D74F}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0D55D1F5-8E67-4D7C-8263-9EEB8260C398}
    HKCR\CLSID\{0D55D1F5-8E67-4D7C-8263-9EEB8260C398}
    HKCR\CLSID\{0D55D1F5-8E67-4D7C-8263-9EEB8260C398}\InprocServer32
    HKCR\CLSID\{0D55D1F5-8E67-4D7C-8263-9EEB8260C398}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0D5E3E3C-ABCD-4DD7-BD0F-24F90F6BFD5D}
    HKCR\CLSID\{0D5E3E3C-ABCD-4DD7-BD0F-24F90F6BFD5D}
    HKCR\CLSID\{0D5E3E3C-ABCD-4DD7-BD0F-24F90F6BFD5D}\InprocServer32
    HKCR\CLSID\{0D5E3E3C-ABCD-4DD7-BD0F-24F90F6BFD5D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0D755F04-2556-40CB-9B5B-5AB6C2C018BD}
    HKCR\CLSID\{0D755F04-2556-40CB-9B5B-5AB6C2C018BD}
    HKCR\CLSID\{0D755F04-2556-40CB-9B5B-5AB6C2C018BD}\InprocServer32
    HKCR\CLSID\{0D755F04-2556-40CB-9B5B-5AB6C2C018BD}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0D898F59-82F7-4BC7-ACE5-BDD5570769F9}
    HKCR\CLSID\{0D898F59-82F7-4BC7-ACE5-BDD5570769F9}
    HKCR\CLSID\{0D898F59-82F7-4BC7-ACE5-BDD5570769F9}\InprocServer32
    HKCR\CLSID\{0D898F59-82F7-4BC7-ACE5-BDD5570769F9}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0DA4E2E2-1D25-4E9C-A5B9-2E77048C5DDF}
    HKCR\CLSID\{0DA4E2E2-1D25-4E9C-A5B9-2E77048C5DDF}
    HKCR\CLSID\{0DA4E2E2-1D25-4E9C-A5B9-2E77048C5DDF}\InprocServer32
    HKCR\CLSID\{0DA4E2E2-1D25-4E9C-A5B9-2E77048C5DDF}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0DC9700B-3AD6-43D3-B31E-83849C93A954}
    HKCR\CLSID\{0DC9700B-3AD6-43D3-B31E-83849C93A954}
    HKCR\CLSID\{0DC9700B-3AD6-43D3-B31E-83849C93A954}\InprocServer32
    HKCR\CLSID\{0DC9700B-3AD6-43D3-B31E-83849C93A954}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0DE01AE0-CEB1-42AC-9DB6-96B8B8E89239}
    HKCR\CLSID\{0DE01AE0-CEB1-42AC-9DB6-96B8B8E89239}
    HKCR\CLSID\{0DE01AE0-CEB1-42AC-9DB6-96B8B8E89239}\InprocServer32
    HKCR\CLSID\{0DE01AE0-CEB1-42AC-9DB6-96B8B8E89239}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0DF1CA96-367F-4AEE-AFB4-6E6BC2E3E056}
    HKCR\CLSID\{0DF1CA96-367F-4AEE-AFB4-6E6BC2E3E056}
    HKCR\CLSID\{0DF1CA96-367F-4AEE-AFB4-6E6BC2E3E056}\InprocServer32
    HKCR\CLSID\{0DF1CA96-367F-4AEE-AFB4-6E6BC2E3E056}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0DFABC16-5255-44A4-A00B-07D7F9A8DCFB}
    HKCR\CLSID\{0DFABC16-5255-44A4-A00B-07D7F9A8DCFB}
    HKCR\CLSID\{0DFABC16-5255-44A4-A00B-07D7F9A8DCFB}\InprocServer32
    HKCR\CLSID\{0DFABC16-5255-44A4-A00B-07D7F9A8DCFB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0DFBC1E3-7B5E-401E-9040-249DF4D9AA2D}
    HKCR\CLSID\{0DFBC1E3-7B5E-401E-9040-249DF4D9AA2D}
    HKCR\CLSID\{0DFBC1E3-7B5E-401E-9040-249DF4D9AA2D}\InprocServer32
    HKCR\CLSID\{0DFBC1E3-7B5E-401E-9040-249DF4D9AA2D}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0E1468F0-CFCD-4A8A-9161-177917DD8599}
    HKCR\CLSID\{0E1468F0-CFCD-4A8A-9161-177917DD8599}
    HKCR\CLSID\{0E1468F0-CFCD-4A8A-9161-177917DD8599}\InprocServer32
    HKCR\CLSID\{0E1468F0-CFCD-4A8A-9161-177917DD8599}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0E1CC3F5-7123-461D-BBB9-4690BCD75726}
    HKCR\CLSID\{0E1CC3F5-7123-461D-BBB9-4690BCD75726}
    HKCR\CLSID\{0E1CC3F5-7123-461D-BBB9-4690BCD75726}\InprocServer32
    HKCR\CLSID\{0E1CC3F5-7123-461D-BBB9-4690BCD75726}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0E22574D-A9D1-46A2-8A0D-1595186D729A}
    HKCR\CLSID\{0E22574D-A9D1-46A2-8A0D-1595186D729A}
    HKCR\CLSID\{0E22574D-A9D1-46A2-8A0D-1595186D729A}\InprocServer32
    HKCR\CLSID\{0E22574D-A9D1-46A2-8A0D-1595186D729A}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0E507E4C-CF6B-409A-9981-6AA80384B508}
    HKCR\CLSID\{0E507E4C-CF6B-409A-9981-6AA80384B508}
    HKCR\CLSID\{0E507E4C-CF6B-409A-9981-6AA80384B508}\InprocServer32
    HKCR\CLSID\{0E507E4C-CF6B-409A-9981-6AA80384B508}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0E6BB172-F354-414A-81A3-8BFA319E3709}
    HKCR\CLSID\{0E6BB172-F354-414A-81A3-8BFA319E3709}
    HKCR\CLSID\{0E6BB172-F354-414A-81A3-8BFA319E3709}\InprocServer32
    HKCR\CLSID\{0E6BB172-F354-414A-81A3-8BFA319E3709}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0E6E3DB3-2322-4C5B-A60A-EBABCFD7C552}
    HKCR\CLSID\{0E6E3DB3-2322-4C5B-A60A-EBABCFD7C552}
    HKCR\CLSID\{0E6E3DB3-2322-4C5B-A60A-EBABCFD7C552}\InprocServer32
    HKCR\CLSID\{0E6E3DB3-2322-4C5B-A60A-EBABCFD7C552}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0E88174A-9CB7-40A4-8358-2E49B8CC3AAB}
    HKCR\CLSID\{0E88174A-9CB7-40A4-8358-2E49B8CC3AAB}
    HKCR\CLSID\{0E88174A-9CB7-40A4-8358-2E49B8CC3AAB}\InprocServer32
    HKCR\CLSID\{0E88174A-9CB7-40A4-8358-2E49B8CC3AAB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0E908A15-A9C2-4C2C-B70F-083747DCB3A8}
    HKCR\CLSID\{0E908A15-A9C2-4C2C-B70F-083747DCB3A8}
    HKCR\CLSID\{0E908A15-A9C2-4C2C-B70F-083747DCB3A8}\InprocServer32
    HKCR\CLSID\{0E908A15-A9C2-4C2C-B70F-083747DCB3A8}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0EA215D3-A6D0-4F81-B9D6-1288E125EBED}
    HKCR\CLSID\{0EA215D3-A6D0-4F81-B9D6-1288E125EBED}
    HKCR\CLSID\{0EA215D3-A6D0-4F81-B9D6-1288E125EBED}\InprocServer32
    HKCR\CLSID\{0EA215D3-A6D0-4F81-B9D6-1288E125EBED}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0EAF9305-F753-4D91-BDB2-75A3697DADC1}
    HKCR\CLSID\{0EAF9305-F753-4D91-BDB2-75A3697DADC1}
    HKCR\CLSID\{0EAF9305-F753-4D91-BDB2-75A3697DADC1}\InprocServer32
    HKCR\CLSID\{0EAF9305-F753-4D91-BDB2-75A3697DADC1}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0EC581A8-3622-4E23-B294-88EF3395B233}
    HKCR\CLSID\{0EC581A8-3622-4E23-B294-88EF3395B233}
    HKCR\CLSID\{0EC581A8-3622-4E23-B294-88EF3395B233}\InprocServer32
    HKCR\CLSID\{0EC581A8-3622-4E23-B294-88EF3395B233}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0EE06B4B-12B7-4504-B8D2-FD7A819C3E3F}
    HKCR\CLSID\{0EE06B4B-12B7-4504-B8D2-FD7A819C3E3F}
    HKCR\CLSID\{0EE06B4B-12B7-4504-B8D2-FD7A819C3E3F}\InprocServer32
    HKCR\CLSID\{0EE06B4B-12B7-4504-B8D2-FD7A819C3E3F}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0EE18C3C-2EA7-4E6A-B9BD-F9DB8C6460CE}
    HKCR\CLSID\{0EE18C3C-2EA7-4E6A-B9BD-F9DB8C6460CE}
    HKCR\CLSID\{0EE18C3C-2EA7-4E6A-B9BD-F9DB8C6460CE}\InprocServer32
    HKCR\CLSID\{0EE18C3C-2EA7-4E6A-B9BD-F9DB8C6460CE}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0EF0D8CF-FBD7-44AC-BCB8-463451E9C273}
    HKCR\CLSID\{0EF0D8CF-FBD7-44AC-BCB8-463451E9C273}
    HKCR\CLSID\{0EF0D8CF-FBD7-44AC-BCB8-463451E9C273}\InprocServer32
    HKCR\CLSID\{0EF0D8CF-FBD7-44AC-BCB8-463451E9C273}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F0A798B-1D05-40A8-94FC-5A33EC7E1772}
    HKCR\CLSID\{0F0A798B-1D05-40A8-94FC-5A33EC7E1772}
    HKCR\CLSID\{0F0A798B-1D05-40A8-94FC-5A33EC7E1772}\InprocServer32
    HKCR\CLSID\{0F0A798B-1D05-40A8-94FC-5A33EC7E1772}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F16610D-82C1-42BF-B8CE-D5B9E9EEEF77}
    HKCR\CLSID\{0F16610D-82C1-42BF-B8CE-D5B9E9EEEF77}
    HKCR\CLSID\{0F16610D-82C1-42BF-B8CE-D5B9E9EEEF77}\InprocServer32
    HKCR\CLSID\{0F16610D-82C1-42BF-B8CE-D5B9E9EEEF77}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F27A857-F9FC-489E-8908-FF047B969DEB}
    HKCR\CLSID\{0F27A857-F9FC-489E-8908-FF047B969DEB}
    HKCR\CLSID\{0F27A857-F9FC-489E-8908-FF047B969DEB}\InprocServer32
    HKCR\CLSID\{0F27A857-F9FC-489E-8908-FF047B969DEB}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F2BF602-B9CF-4F05-BC9C-FD4E8DD35985}
    HKCR\CLSID\{0F2BF602-B9CF-4F05-BC9C-FD4E8DD35985}
    HKCR\CLSID\{0F2BF602-B9CF-4F05-BC9C-FD4E8DD35985}\InprocServer32
    HKCR\CLSID\{0F2BF602-B9CF-4F05-BC9C-FD4E8DD35985}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F3E8679-8EB1-42B4-A994-D4C4AC26B605}
    HKCR\CLSID\{0F3E8679-8EB1-42B4-A994-D4C4AC26B605}
    HKCR\CLSID\{0F3E8679-8EB1-42B4-A994-D4C4AC26B605}\InprocServer32
    HKCR\CLSID\{0F3E8679-8EB1-42B4-A994-D4C4AC26B605}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F3EE5D2-8CA6-4CEA-A388-9A9926B0C751}
    HKCR\CLSID\{0F3EE5D2-8CA6-4CEA-A388-9A9926B0C751}
    HKCR\CLSID\{0F3EE5D2-8CA6-4CEA-A388-9A9926B0C751}\InprocServer32
    HKCR\CLSID\{0F3EE5D2-8CA6-4CEA-A388-9A9926B0C751}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F460711-008C-4628-97B0-C850789510B8}
    HKCR\CLSID\{0F460711-008C-4628-97B0-C850789510B8}
    HKCR\CLSID\{0F460711-008C-4628-97B0-C850789510B8}\InprocServer32
    HKCR\CLSID\{0F460711-008C-4628-97B0-C850789510B8}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F499062-6253-4B3C-81C6-9A79FD39B9BC}
    HKCR\CLSID\{0F499062-6253-4B3C-81C6-9A79FD39B9BC}
    HKCR\CLSID\{0F499062-6253-4B3C-81C6-9A79FD39B9BC}\InprocServer32
    HKCR\CLSID\{0F499062-6253-4B3C-81C6-9A79FD39B9BC}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F4D4DBF-2D3D-438D-95E2-3B1C0D9FC4A6}
    HKCR\CLSID\{0F4D4DBF-2D3D-438D-95E2-3B1C0D9FC4A6}
    HKCR\CLSID\{0F4D4DBF-2D3D-438D-95E2-3B1C0D9FC4A6}\InprocServer32
    HKCR\CLSID\{0F4D4DBF-2D3D-438D-95E2-3B1C0D9FC4A6}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F552733-EB64-4372-BC45-159918CE4111}
    HKCR\CLSID\{0F552733-EB64-4372-BC45-159918CE4111}
    HKCR\CLSID\{0F552733-EB64-4372-BC45-159918CE4111}\InprocServer32
    HKCR\CLSID\{0F552733-EB64-4372-BC45-159918CE4111}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F6D674D-4D07-46D6-9737-F75B2821790E}
    HKCR\CLSID\{0F6D674D-4D07-46D6-9737-F75B2821790E}
    HKCR\CLSID\{0F6D674D-4D07-46D6-9737-F75B2821790E}\InprocServer32
    HKCR\CLSID\{0F6D674D-4D07-46D6-9737-F75B2821790E}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0F98AE5B-7188-4CC3-BAA6-D5267D106689}
    HKCR\CLSID\{0F98AE5B-7188-4CC3-BAA6-D5267D106689}
    HKCR\CLSID\{0F98AE5B-7188-4CC3-BAA6-D5267D106689}\InprocServer32
    HKCR\CLSID\{0F98AE5B-7188-4CC3-BAA6-D5267D106689}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0FA3F300-B7E6-4771-9BBA-761AC9A0184B}
    HKCR\CLSID\{0FA3F300-B7E6-4771-9BBA-761AC9A0184B}
    HKCR\CLSID\{0FA3F300-B7E6-4771-9BBA-761AC9A0184B}\InprocServer32
    HKCR\CLSID\{0FA3F300-B7E6-4771-9BBA-761AC9A0184B}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0FE953CA-B635-4891-A708-CC33CE3385F4}
    HKCR\CLSID\{0FE953CA-B635-4891-A708-CC33CE3385F4}
    HKCR\CLSID\{0FE953CA-B635-4891-A708-CC33CE3385F4}\InprocServer32
    HKCR\CLSID\{0FE953CA-B635-4891-A708-CC33CE3385F4}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0FF62A3D-77B7-466B-AE66-7110D44388FF}
    HKCR\CLSID\{0FF62A3D-77B7-466B-AE66-7110D44388FF}
    HKCR\CLSID\{0FF62A3D-77B7-466B-AE66-7110D44388FF}\InprocServer32
    HKCR\CLSID\{0FF62A3D-77B7-466B-AE66-7110D44388FF}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{0FF8E497-7D7C-4D1E-9DDB-8987BC8858D9}
   
------------------------

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:    01:23:00 30-12-2007

+ Scan result:   



C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248\A0070289.exe -> Adware.180Solutions : No action taken.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244\A0063005.exe -> Adware.UltimateDefender : No action taken.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245\A0063070.exe -> Adware.UltimateDefender : No action taken.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245\A0063124.exe -> Adware.UltimateDefender : No action taken.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247\A0070187.exe -> Adware.UltimateDefender : No action taken.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248\A0070273.exe -> Adware.UltimateDefender : No action taken.
C:\WINDOWS\system32\Partizan.exe -> Downloader.Agent.bkw : No action taken.
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\ACROTRAY.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Common Files\Real\Update_OB\REALSCHED.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSVC.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDAEMON.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Google\Google Desktop Search\GOOGLEDESKTOP.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Google\GoogleToolbarNotifier\GOOGLETOOLBARNOTIFIER.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\HP DigitalMedia Archive\DMASCHEDULER.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\HP\HP Software Update\HPWUSCHD2.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP              .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP              .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP            .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP            .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP          .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP          .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP        .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP        .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP      .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP      .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP    .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP    .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP  .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP  .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBOOTOP.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Java\jre1.6.0_03\bin\JUSCHED.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK              .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK              .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK            .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK            .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK          .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK          .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK        .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK        .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK      .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK      .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK    .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK    .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK  .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK  .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\QuickTime\QTTASK.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR                      .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR                      .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR                    .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR                    .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR                  .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR                  .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR                .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR                .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR              .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR              .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR            .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files\Windows Live\Messenger\MSNMSGR            .0XE -> Dropper.Agent.dgo : No action taken.
C:\Program Files
Avatar billede sirus Nybegynder
30. december 2007 - 18:10 #26
Og her er HJT-loggen:

Logfile of HijackThis v1.99.1
Scan saved at 18:09:11, on 30-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\MotionBased\Agent\MBAgent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\msiexec.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Documents and Settings\HP_Administrator\Desktop\AntiVirus\hijackthis.exe

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp                .exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask    .exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr .exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: MotionBased Agent.lnk = C:\Program Files\MotionBased\Agent\MBAgent.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?6452e9228ac0414ab1ac7481f2350f0d
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Program Files\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?6452e9228ac0414ab1ac7481f2350f0d
O9 - Extra button: (no name) - SOFTWARE - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bl103fd.blu103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager-kontrol) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

----------

Det ser ud til at synderen er væk.

Hvis det er tilfældet, vil jeg gerne bruge anledningen til at sige tusind tak for din indsats, tålmodighed og hjælp.

Det er jeg dig meget taknemmelig for.

Mvh.
Sirus
30. december 2007 - 18:26 #27
Jeg vil gerne have at du ruller AVG Anti-Spyware igen og brug [Fjern] funktionen som her beskrevet...
http://www.spywarefri.dk/manualer/ewido-manual.htm
Hvis man 'bare' klasker [ENTER] vælges nemlig [No action taken.] og så er man ligevidt ...

Hvad sagde DrWeb ?
Avatar billede sirus Nybegynder
30. december 2007 - 18:55 #28
Dr Web:

369E1A6C.tmp;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.DownLoader.591;Deleted.;
3C8A0A4E.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert;Deleted.;
427523CA.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.nCase;Moved.;
427523CA.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.Winad;Moved.;
42794DC7.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.Winad.153;Moved.;
64FE7395.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Dialer.Star;Moved.;
CRACK.0XE;C:\Documents and Settings\HP_Administrator\Desktop\Gamez\Roms\Roms;Trojan.DownLoader.38044;Deleted.;
PATCH.0XE;C:\Documents and Settings\HP_Administrator\Desktop\Gamez\Roms\Roms;Trojan.Mezzia.83;Deleted.;
Setup.exe;C:\Documents and Settings\HP_Administrator\Shared\csi clean up serial key;Trojan.Click.4951;Deleted.;
KillWind.exe;C:\hp\bin;Tool.ProcessKill;Moved.;
ACROTRAY.0XE;C:\Program Files\Adobe\Acrobat 8.0\Acrobat;Trojan.MulDrop.10006;Deleted.;
REALSCHED.0XE;C:\Program Files\Common Files\Real\Update_OB;Trojan.MulDrop.10006;Deleted.;
PIFSVC.0XE;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08};Trojan.MulDrop.10006;Deleted.;
VCDDAEMON.0XE;C:\Program Files\Elaborate Bytes\VirtualCloneDrive;Trojan.MulDrop.10006;Deleted.;
GOOGLEDESKTOP.0XE;C:\Program Files\Google\Google Desktop Search;Trojan.MulDrop.10006;Deleted.;
GOOGLETOOLBARNOTIFIER.0XE;C:\Program Files\Google\GoogleToolbarNotifier;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP              .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP              .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP            .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP            .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP          .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP          .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP        .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP        .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP      .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP      .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP    .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP    .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP  .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP  .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP .0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPBOOTOP.0XE;C:\Program Files\Hewlett-Packard\HP Boot Optimizer;Trojan.MulDrop.10006;Deleted.;
HPWUSCHD2.0XE;C:\Program Files\HP\HP Software Update;Trojan.MulDrop.10006;Deleted.;
DMASCHEDULER.0XE;C:\Program Files\HP DigitalMedia Archive;Trojan.MulDrop.10006;Deleted.;
ITUNESHELPER.0XE;C:\Program Files\iTunes;Trojan.MulDrop.10006;Deleted.;
JUSCHED.0XE;C:\Program Files\Java\jre1.6.0_03\bin;Trojan.MulDrop.10006;Deleted.;
QTTASK              .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK              .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK            .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK            .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK          .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK          .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK        .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK        .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK      .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK      .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK    .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK    .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK  .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK  .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK .0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
QTTASK.0XE;C:\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.;
SUPERANTISPYWARE.0XE;C:\Program Files\SUPERAntiSpyware;Trojan.MulDrop.10006;Deleted.;
MSNMSGR                      .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR                      .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR                    .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR                    .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR                  .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR                  .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR                .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR                .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR              .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR              .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR            .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR            .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR          .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR          .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR        .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR        .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR      .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR      .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR    .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR    .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR  .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR  .0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
MSNMSGR.0XE;C:\Program Files\Windows Live\Messenger;Trojan.MulDrop.10006;Deleted.;
ssqrp.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.257;Deleted.;
A0059334.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059337.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059339.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059340.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059341.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059342.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059343.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059344.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059345.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059346.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059347.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059348.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059349.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059350.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059351.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059393.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059396.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059398.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059399.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059400.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059401.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059402.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059403.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059404.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059405.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059406.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059407.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059408.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059409.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059410.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP242;Trojan.MulDrop.10006;Deleted.;
A0059546.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059552.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059553.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059555.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059556.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059557.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059558.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059560.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059561.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059562.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059563.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059564.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0059579.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060489.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060495.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060496.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060497.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060498.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060499.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060500.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060501.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060503.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060504.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060505.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060506.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060507.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060532.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060538.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060539.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060541.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060542.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060543.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060544.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060546.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060547.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060548.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060549.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0060550.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061532.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061538.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061539.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061541.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061542.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061543.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061546.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061549.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061550.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061551.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061552.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061553.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061832.rbf;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0061875.rbf;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP243;Trojan.MulDrop.10006;Deleted.;
A0062689.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062694.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.Fakealert.origin;Incurable.Moved.;
A0062696.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062697.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062699.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062700.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062701.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062702.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062703.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062705.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062706.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062707.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062708.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062723.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062724.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062746.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.DownLoader.38415;Deleted.;
A0062754.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062759.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.DownLoader.38415;Deleted.;
A0062762.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062766.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062796.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062801.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062802.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062804.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062806.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062807.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062808.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062809.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062810.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062811.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062812.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062813.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062814.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062815.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062816.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062817.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062818.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062819.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062820.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062838.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.Fakealert.origin;Incurable.Moved.;
A0062984.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062988.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062991.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062992.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062994.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062995.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062996.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062997.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0062998.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0063000.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0063001.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0063002.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0063003.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0063018.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.Fakealert.origin;Incurable.Moved.;
A0063021.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0063022.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244;Trojan.MulDrop.10006;Deleted.;
A0063045.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063049.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063052.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063053.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063055.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063056.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063057.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063059.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063060.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063062.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063065.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063066.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063067.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063079.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.Fakealert.origin;Incurable.Moved.;
A0063085.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063086.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063104.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063108.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063111.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063112.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063114.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063115.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063116.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063117.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063118.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063120.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063121.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063122.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063123.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063138.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.Fakealert.origin;Incurable.Moved.;
A0063141.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063142.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245;Trojan.MulDrop.10006;Deleted.;
A0063588.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070162.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070166.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070168.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070170.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070172.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070173.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070175.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070178.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070181.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070183.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070185.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070186.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070190.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070192.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.Fakealert.origin;Incurable.Moved.;
A0070196.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247;Trojan.MulDrop.10006;Deleted.;
A0070215.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070218.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070220.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070221.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070222.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070223.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070225.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070227.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070228.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070229.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070232.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070236.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070237.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070239.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070240.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070244.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070246.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.Fakealert.origin;Incurable.Moved.;
A0070250.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070252.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070254.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070255.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070256.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070257.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070258.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070259.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070260.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070261.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070262.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070264.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070265.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070266.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070267.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070268.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070269.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070274.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070275.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070276.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070277.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0070283.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.Fakealert.origin;Incurable.Moved.;
A0070289.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Adware.Zango;Moved.;
A0070295.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.Mezzia.77;Deleted.;
A0071295.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.Mezzia.77;Deleted.;
A0071297.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.Virtumod.257;Deleted.;
A0072299.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072301.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072302.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072303.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072304.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072305.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072306.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072307.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072310.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072311.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072312.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072313.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072314.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072315.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072316.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072317.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072318.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072339.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072341.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072343.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072344.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072345.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072346.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072347.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072348.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072349.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072350.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072353.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072354.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072355.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072356.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248;Trojan.MulDrop.10006;Deleted.;
A0072378.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072380.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072381.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072382.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072383.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072384.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072385.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072386.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072387.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072389.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072390.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072391.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072394.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072395.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP249;Trojan.MulDrop.10006;Deleted.;
A0072414.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.Virtumod.257;Deleted.;
A0072429.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072437.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072438.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072439.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072441.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072442.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072443.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072444.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072445.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072448.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072450.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072451.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072452.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072453.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072454.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP250;Trojan.MulDrop.10006;Deleted.;
A0072492.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072493.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.Virtumod.257;Deleted.;
A0072503.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072506.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072513.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072514.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072515.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072518.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072519.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072520.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072521.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072523.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072525.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072526.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072527.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072528.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP251;Trojan.MulDrop.10006;Deleted.;
A0072555.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072565.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.Virtumod.257;Deleted.;
A0072576.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072590.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072591.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072592.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072593.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072594.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072595.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072597.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072598.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072600.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072601.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072602.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072604.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072605.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072626.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072635.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072637.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072639.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072640.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072641.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072642.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072643.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072644.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072645.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072646.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072648.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072652.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072658.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072664.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072666.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072684.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072689.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072690.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072691.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072692.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072693.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072694.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072695.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072696.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072697.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072711.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072714.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072719.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072720.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072721.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072723.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072724.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072725.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072728.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072729.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072730.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072740.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072747.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072751.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072752.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072754.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072755.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072756.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072757.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072758.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072759.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072760.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072761.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072777.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072789.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072791.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072795.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072796.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072797.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072798.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072799.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072800.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072802.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072803.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072817.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072820.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072824.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072825.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072826.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072827.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072828.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072829.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072830.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072831.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072832.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072833.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072849.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072859.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072860.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072862.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072863.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072864.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072865.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072866.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072867.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072868.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072870.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072889.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072891.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072893.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072894.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072895.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072896.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072897.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072898.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072899.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072900.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072901.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072902.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072915.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072923.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072926.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072927.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072930.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072931.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072932.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072933.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072934.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072935.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072936.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP252;Trojan.MulDrop.10006;Deleted.;
A0072945.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.Virtumod.257;Deleted.;
A0072955.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072962.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072963.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072964.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072965.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072966.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072967.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072968.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072969.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072970.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072971.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072987.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072988.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072994.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072995.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072996.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072998.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0072999.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073000.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073001.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073002.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073003.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073026.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073038.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073045.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073046.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073047.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073048.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073049.exe;C:\System Volume Information\_restore{1
Avatar billede sirus Nybegynder
30. december 2007 - 18:58 #29
Fortsat

<--

A0073049.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073050.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073051.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073052.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073053.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073056.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073065.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073068.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073077.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073078.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073080.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073081.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073082.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073083.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073084.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073085.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073086.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073088.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073106.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073107.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073113.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073114.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073115.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073117.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073118.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073119.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073120.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073121.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073132.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073139.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073141.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073143.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073144.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073145.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073146.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073147.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073148.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073149.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073150.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073151.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073153.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP253;Trojan.MulDrop.10006;Deleted.;
A0073165.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP254;Trojan.MulDrop.10006;Deleted.;
A0073167.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP254;Trojan.Virtumod.257;Deleted.;
A0073175.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073182.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073187.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073188.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073189.EXE;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073190.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073191.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073192.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073194.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073196.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073197.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073198.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073201.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073202.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073203.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073204.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073205.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073206.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073207.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073208.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073209.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073210.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073211.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073212.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073213.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073214.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073215.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073216.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073217.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073218.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073219.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073220.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073221.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073222.Exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073223.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073224.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073225.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073226.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073227.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073228.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073229.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073230.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073231.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073232.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073233.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073234.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073235.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073236.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073237.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073238.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073239.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073240.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073241.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073242.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073243.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073244.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073245.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073246.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073247.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073248.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073249.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073250.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073251.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073252.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073253.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073254.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073255.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.MulDrop.10006;Deleted.;
A0073256.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.DownLoader.38044;Deleted.;
A0073257.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.Mezzia.83;Deleted.;
A0073259.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.Virtumod.257;Deleted.;
A0073297.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.Fakealert;Deleted.;
A0073298.dll;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Adware.nCase;Moved.;
A0073299.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Adware.Winad;Moved.;
A0073300.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Adware.Winad.153;Moved.;
A0073301.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Dialer.Star;Moved.;
A0073302.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Trojan.Click.4951;Deleted.;
A0073303.exe;C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP255;Tool.ProcessKill;Moved.;
ssqrp.dll.bad;C:\VundoFix Backups;Trojan.Virtumod.257;Deleted.;
ssqrp.exe.bad;C:\VundoFix Backups;Trojan.MulDrop.10006;Deleted.;
ehtray.exe.tmp;C:\WINDOWS\ehome;Trojan.MulDrop.10006;Deleted.;
RECGUARD.0XE;C:\WINDOWS\SMINST;Trojan.MulDrop.10006;Deleted.;
ctfmon.exe.tmp;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.;
RCX33.tmp;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.;
RCX48.tmp;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.;
RCX66.tmp;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.;
RCX6D.tmp;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.;
RCX70.tmp;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.;
SSQRP.0XE;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.;

--------------

Mvh.
Sirus
30. december 2007 - 19:01 #30
(Jaaaa - BINGO - der kan jo gemme sig mange mere eller mindre usynlig elementer...)

AVG Anti-Spyware igen ???
Avatar billede sirus Nybegynder
30. december 2007 - 20:59 #31
Og her kommer AVG-loggen:

-----------

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:    20:56:46 30-12-2007

+ Scan result:   



C:\infected\A0070289.exe -> Adware.180Solutions : Ignored.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244\A0063005.exe -> Adware.UltimateDefender : Ignored.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245\A0063070.exe -> Adware.UltimateDefender : Ignored.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP245\A0063124.exe -> Adware.UltimateDefender : Ignored.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP247\A0070187.exe -> Adware.UltimateDefender : Ignored.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP248\A0070273.exe -> Adware.UltimateDefender : Ignored.
C:\WINDOWS\system32\Partizan.exe -> Downloader.Agent.bkw : Cleaned with backup (quarantined).
C:\avenger\backup.zip/avenger/ssqrp.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@edsa.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@adtech[1].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@connextra[3].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Cleaned.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP244\A0062741.exe -> Trojan.Wow : Cleaned with backup (quarantined).


::Report end

----------------

Mvh.
Sirus
30. december 2007 - 21:09 #32
Så er du ved at være i mål !!!

Hvordan kører putteren så nu ???
Avatar billede sirus Nybegynder
30. december 2007 - 22:23 #33
Den kører langt bedre - ja, vel egentligt som den skal.

Jeg vil i den forbindelse gerne høre, om der er et sted på siden, hvor jeg kan skrive mange tak for assistancen, eller om det bare er her at dette foregår?

Jeg er ihvertfald dybt taknemmelig for, at du har gidet at tage dig tid til at assistere mig rundt i dette "kaos".  :o)

Mange tak for det.

Med venlig hilsen,
Sirus
30. december 2007 - 22:29 #34
(Det er 'her' det foregår *S*)(Så meget 'kaos' var det nu heller ikke - denne gang..)

Der er ikke mere 'snavs' ifølge din Log...

Du er velkommen en anden gang...

Åbn en mappe, klik på Funktioner >Mappeindstillinger >Vis.
Sæt flueben ved "Skjul beskyttede operativsystemfiler".
Sæt prik i "Vis ikke skjulte filer og mapper".

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Et par artikler om sikker surfing finder du her:
http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=14414

Safe Surfing...
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester