Avatar billede mariasander Nybegynder
15. juli 2008 - 09:26 Der er 17 kommentarer og
1 løsning

Hvordan får jeg fjernet li6txyqu application?

Hej

Jeg har opdaget en lille applikation, der ligger og kører sammen med mine andre processer. Den hedder li6txyqu.exe. Normalt kan jeg få hjælp ved blot at søge på processens navn i Google, men ikke denne gang. Er der nogen, der har nogen ideer, til hvordan jeg skal få den væk?
Den gør IE ustabil på den måde, at vinduet pludselig lukker ned, eller der popper en stor reklame frem, med Windows egen phishingfilter skærmbillede foran. Jeg har både kørt Norton og Spybot, men de finder ikke noget. Mit bud er, at jeg på en eller anden vis har erhvervet programmet gennem Facebook.
Der ligger en PF fil i WINDOWS/prefetch og selve applicationen og en A_A fil ligger i WINDOWS/system32. Det er selvsagt ikke nok bare at fjerne dem herfra, da de kort efter er tilbage igen. Jeg kører med XP Pro.
Avatar billede ebea Ekspert
15. juli 2008 - 11:04 #1
Hvad hvis du starter "msconfig" fra "Start / kør" og ind i den menu der kommer frem, går ind i fanebladet start, og ser om du kan se programmet i den liste, og så fjerner fluebenet der hvis du kan se programmet.
15. juli 2008 - 11:16 #2
... for en go' ordens skyld; stik os/mig en HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

(Jooo - jeg har 'virus' på hjernen...)

Mht.: Vista - HøjreMusseTast på *.EXE filen - Kør som Administrator...

------------------
15. juli 2008 - 11:16 #3
Velkommen til Eksperten.dk
Generelt -> http://expfaq.dk/
Avatar billede mariasander Nybegynder
15. juli 2008 - 13:51 #4
Hej

ebea: Programmet fremgår ikke ved brug af msconfig.

Hermed en HiJackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:49:04, on 15-07-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\slserv.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~2\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\LI6tXyQu.exe
C:\Documents and Settings\Maria Schmidt Sander\Desktop\alternativ.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Maria Schmidt Sander\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Vis Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [bait soft test boob] C:\Documents and Settings\All Users.WINDOWS\Application Data\Nurbsendbaitsoft\Bags Fast.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - https://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) -  - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 8105 bytes
15. juli 2008 - 15:07 #5
-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip

-- Pak Avenger-programmet ud og dobbeltklik på avenger.exe

-- Der dukker et vindue op, hvor du skal kopiere indholdet mellem ~~~ skrift ind:

~~~~~~~~~~~~~~~~~~
Files to delete:
C:\Documents and Settings\All Users.WINDOWS\Application Data\Nurbsendbaitsoft\

Folders to delete:
~~~~~~~~~~~~~~~~~~

-- Klik på EXECUTE - og la' PC'en selv genstarte.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

-- Kør Hijackthis, vælg "Do a system scan only", sæt flueben ved linierne listet her, luk alle vinduer undtaget Hijackthis, klik på fix checked.

O4 - HKLM\..\Run: [bait soft test boob] C:\Documents and Settings\All Users.WINDOWS\Application Data\Nurbsendbaitsoft\Bags Fast.exe

O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

Genstart computeren...

--------------------

... Nu er det ikke alle (u)ønskede elementer som viser sig med en HiJackThis Log; hvis du har 'mod' på det så gennemfør proceduren herfra -> http://www.eksperten.dk/artikler/1123
PS: Brug stadig denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

--------------------

PS:
Jeg har nu ikke meget fidus til denne
[Uniblue RegistryBooster 2]
vil anbefale afinstall den...
Avatar billede mariasander Nybegynder
15. juli 2008 - 16:10 #6
Her er logfilen fra avenger:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: "C:\Documents and Settings\All Users.WINDOWS\Application Data\Nurbsendbaitsoft\" is a folder, not a file!
Deletion of file "C:\Documents and Settings\All Users.WINDOWS\Application Data\Nurbsendbaitsoft\" failed!
Status: 0xc00000ba (STATUS_FILE_IS_A_DIRECTORY)
  --> use "Folders to delete:" instead of "Files to delete:" to delete a directory


Completed script processing.

*******************

Finished!  Terminate.

Jeg tænker at det måske ikke var helt det du ville eller hvordan? Du har tabt mig undervejs, og jeg er ikke helt klar over, hvad vi er i færd med:-). Hvordan har du knyttet forbindelse mellem LI6tyxqu.exe og Nurbsendbaitsoft\Bags Fast.exe?
15. juli 2008 - 16:19 #7
Under alle omstændigheder så er nævnte "Nurbsendbaitsoft\Bags Fast.exe" noget 'snavs' !!!

Derefter henviser jeg til nævnte http://www.eksperten.dk/artikler/1123 ...

-------

Jeg gjorde forkert mht Avenger:

Sådan ->

-- Der dukker et vindue op, hvor du skal kopiere indholdet mellem ~~~ skrift ind:

~~~~~~~~~~~~~~~~~~
Files to delete:

Folders to delete:
C:\Documents and Settings\All Users.WINDOWS\Application Data\Nurbsendbaitsoft\
~~~~~~~~~~~~~~~~~~

-- Klik på EXECUTE - og la' PC'en selv genstarte.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.
Avatar billede mariasander Nybegynder
15. juli 2008 - 16:59 #8
Så ser det mere rigtigt ud, nu er det spændende om det var det, der skulle til:-):
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

Folder "C:\Documents and Settings\All Users.WINDOWS\Application Data\Nurbsendbaitsoft" deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.
15. juli 2008 - 18:12 #9
Derefter henviser jeg til nævnte http://www.eksperten.dk/artikler/1123 ...
Avatar billede mariasander Nybegynder
15. juli 2008 - 20:32 #10
Okay, nu har jeg gennemgået alle steps i  http://www.eksperten.dk/artikler/1123 ...
Hermed logfilerne:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/15/2008 at 06:23 PM

Application Version : 4.0.1154

Core Rules Database Version : 3504
Trace Rules Database Version: 1404

Scan type      : Complete Scan
Total Scan Time : 00:39:04

Memory items scanned      : 231
Memory threats detected  : 0
Registry items scanned    : 7035
Registry threats detected : 0
File items scanned        : 22140
File threats detected    : 415

Adware.Tracking Cookie
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@doubleclick[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@adtech[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@bizrate[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjlyqmajcko.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnysmdpcfp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@apmebf[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjl4ggczmao.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjny-1kd5og.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@statcounter[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4kgcpghp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjlokgd5chq.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnywlcpodp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjmyapdzmhp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnychdzclo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfkigicpmao.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkoaiajacp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkycpczcfp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfkowncjolp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnyalcpohp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfkyumdpsfo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjlyelazkao.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4wgdzskp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4qhc5okp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfk4ukazgfp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfliqiajwbq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4cndpwdq.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4gjdjsfo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@windowsmedia[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjliqkdjahp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjlocpajodp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@mediaplex[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@adserver.promokant[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjliqkajodo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjlouhcjcdo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wflishcpklo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4wod5eaq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4qidjshp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@stat.dealtime[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@2o7[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkyahd5efp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnyancpmcp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4eidjwlq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnyohd5alp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkockcpkkp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkoaocpcfq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4elcjkep.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnyugd5mbo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnycmdjgfo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnycmcpiao.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjlould5afo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkokjdjebp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@adtech[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjmicmcpsap.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjloklc5mlo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjlyskd5mgp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjl4ggdzkho.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4cgazefo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@server.iad.liveperson[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4ogajofo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@tradedoubler[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnysidzwgo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjloemdpabp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfkycmcjedp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjmiqodpmap.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkogidjmdq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@qksrv[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnywjc5cgp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkokidpskp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@atdmt[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjlyglcpwap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjl4encjwdo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@dealtime[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfkoqiajwfp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfliqjc5mbp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@findwhat[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkouldpcko.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnyqoajalp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjliqodpkkp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjloolazcfp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjny-1sczek.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnysid5sdo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjmiskdjekp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkyomd5kco.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjnyakcpwbp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4omdpgap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjl4smdpgao.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjk4qmdzgbo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@track.adform[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@doubleclick[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e2.emediate[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjloekcpedo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjny-1pd5sf.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wfkoslcjecp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria\Cookies\maria@ad1.emediate[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkyqpd5kep.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjmyapc5keq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@e-2dj6wjkyunajagp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@as1.falkag[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@cxoadfarm.dyndns[2].txt
    C:\Documents and Settings\Maria\Cookies\maria@stat.onestat[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkokgdpieo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@valueclick[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjk4kidjmlp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@amznshopbop.122.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wbkokodjafo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkikhdpegq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@eas.apm.emediate[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkoqiajwfp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgk4ahazckq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@media.adrevolver[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@dyrefinder[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@atdmt[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@media.adrevolver[3].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[10].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkiukcpsbo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfk4cmdpmgq.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkyunczilp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ads.planetactive[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@realmedia[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfliomc5igp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@optimize.indieclick[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@2o7[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgmyglc5chp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@overture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjmyeod5sgo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@freegaysex[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjl4okc5wdo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@apmebf[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjmyomajokp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkiklc5mhq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkyqod5aeq.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wbmiwhajcao.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjloklc5mlo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@e-2dj6wjmyopajolo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfmicoczocp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@fastclick[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wbk4skc5cfp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@hundefinder[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgmyagdjceo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ads2.jubii[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@ads.pointroll[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@eb.adbureau[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@link.mercent[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@sonyeurope.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@anad.tacoda[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@collective-media[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@nycomed.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@clicks.pangora[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@questionmarket[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ice.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wcmiwgajskp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@magasindn.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@specificclick[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@m1.webstats.motigo[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjlicpcjklq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@atwola[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wcmyqodzggp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfmykocziep.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@richmedia.yahoo[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgk4sjcpabq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@justsexyvideos[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@stat.postdanmark[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@indextools[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@sexuality.about[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@gyldendalbogklub.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@adtech[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@popularscreensavers[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ad2.pl.mediainter[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@qxl.banneradministration[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@e-2dj6wgkislcpohp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjk4kgcpghp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@adidascanada.122.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wbkyskcjadp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjmyapc5keq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjk4ogajofo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkygoajgcp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wbkicpcjifp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wakishcjedo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@nykredit.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@www.findalt[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wdk4kkczalo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@trafficmp[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjk4qodpsho.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgmigld5wap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkyakdjocq.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjliagdzwlo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ad2.pl.mediainter[3].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@tdstats[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@elkjop.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wdligpd5kep.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjloaoc5ggo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjliood5gco.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjmyaic5ekp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjl4wgd5ccp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfloond5kep.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkigoazgfo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkywlazakq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@adbrite[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@amazonbebe.122.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wflyghd5cfq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@outrider.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@shoptracker[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www5.addfreestats[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnyancpmcp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnyamcjwep.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@pacificpoker[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@eboks.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkyamc5kcq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkyokd5eap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@microsoftwlmessengermkt.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@troldeshop.mediaworkers[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wckiwpd5wfp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@perf.overture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@mediaprovider.adservinginternational[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@homedk.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@stats2.clicktracks[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfmygjdpwcq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@videoegg.adbureau[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ads.us.e-planning[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@serving-sys[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6whl4wodzego.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6whlyuhajgfo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@marketlive.122.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@mediamac.comon[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgk4uhajebp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@122.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ia.adserving[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@stat.onestat[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wcmioidzako.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@politiken.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ad.zanox[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@tribalfusion[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@keywordmax[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@traffictracker[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@edsa.122.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ncom.banneradministration[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@15minutesfree.nakedsword[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjk4uiajkgq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkoakcjodp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wakookdpkdp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@paypal.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.3dstats[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkyohdzadp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@track.adform[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@banner2.fynskemedier[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@adinterax[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgkoojdzoap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjk4gjdjsfo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkyukazalo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@date.ventivmedia[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@eas4.emediate[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wglogmc5wbp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@e-2dj6wfl4oldpshq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnyomajwbo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@bizrate[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkyondzwhq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@sonofon.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@rocku.adbureau[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@qksrv[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@stat.katalysatormedia[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@stat.dealtime[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgkookc5iep.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjmiugdjgco.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@tradedoubler[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@e-2dj6wjnywmczelo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@track.trackads[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfk4gmc5ego.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@tacoda[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@dealtime[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@3.adbrite[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@login.tracking101[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wcloupdpmgq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@adserver.adservinginternational[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjloupdpoap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkyumd5sgp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@revsci[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[4].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[8].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfl4eldzgkp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ads.revsci[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@saxocom.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@e-2dj6wcliglczmfo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@netsundhedsplejerske.advertserve[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnysid5sdo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[5].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[9].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnyskd5ccp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@advertising[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wbl4epdpaep.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@ilovebisexuals[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfl4eldjago.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[6].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@nextag[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@imrworldwide[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjl4oicjggo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[3].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.googleadservices[7].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wflogkcpmao.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@www.bisex101[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@247realmedia[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e2.emediate[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkowhcziap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkyumdpsfo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@mycounter.tinycounter[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wclokjazmgo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@bizrate.co[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@dynamic.media.adrevolver[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ad1.emediate[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjlicnazegp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@hotlog[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ad.yieldmanager[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@indexstats[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@roiservice[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkyukdpmbq.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@usatoday1.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@track[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@doubleclick[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@go.globaladsales[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkoohcpofp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@oasc08.247realmedia[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ad.yoyo[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wdlicnd5sgp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@nordea.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfkoggczghq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnysgdjgbo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wgkycoazmfo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjlocjd5ceo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@www.burstbeacon[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@e-2dj6wflocgd5eep.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@betaling.wannafind[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@edcgruppen.112.2o7[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@socialmedia[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnyencjado.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@dealtime.co[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@msnaccountservices.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjkocjazgfp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@qxl.adservinginternational[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6walyehc5gbo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@e-2dj6wjnysidzwgo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@telmore.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@ilead.itrack[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@bs.serving-sys[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfmiuicpkkp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@wTracker[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjmiukcjgap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@adserver.easyad[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjmyugcjsbo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfmialajkeo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@clickshift[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6whkokpd5adp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjk4kmd5slp.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@adserver.banneradministration[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@kattefinder[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjk4chd5slo.stats.esomniture[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wdlyelc5gho.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@mathworks.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjlicldjsap.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjmicpdzmkq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnyogc5keq.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wfmyspdzkkp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@www.palsteen[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@nextag.co[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wflicidpkeo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wdlikndpkdo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wjnywmc5acp.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wcmyqnazglo.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@tripod[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@revenue[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@e-2dj6wflisldjado.stats.esomniture[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@lookfantastic.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@rakuten.112.2o7[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria schmidt sander@adfair[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\maria_schmidt_sander@banner.32vegas[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\system@advertising[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\system@adtech[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\system@ad.yieldmanager[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\system@adserver.easyad[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\system@doubleclick[1].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\system@go.globaladsales[2].txt
    C:\Documents and Settings\Maria Schmidt Sander\Cookies\system@tradedoubler[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@adecn[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@atdmt[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@2o7[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@adtech[1].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@apmebf[1].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@dynamic.media.adrevolver[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@uniblue.112.2o7[1].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@adbrite[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@date.ventivmedia[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@media.adrevolver[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@ad.yieldmanager[1].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@go.globaladsales[1].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@fastclick[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@tribalfusion[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@adsby.aim4media[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@track.adform[2].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@media.adrevolver[3].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@tradedoubler[1].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@adopt.euroclick[1].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@adserver.easyad[1].txt
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@doubleclick[1].txt

Trojan.Unknown Origin
    C:\DOCUMENTS AND SETTINGS\MARIA SCHMIDT SANDER\DESKTOP\NEW FOLDER\LI6TXYQU.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{B59A7010-B5A0-41BE-A5A3-FA74735CAA9D}\RP710\A0046011.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{B59A7010-B5A0-41BE-A5A3-FA74735CAA9D}\RP711\A0046035.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{B59A7010-B5A0-41BE-A5A3-FA74735CAA9D}\RP711\A0046074.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{B59A7010-B5A0-41BE-A5A3-FA74735CAA9D}\RP714\A0046092.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{B59A7010-B5A0-41BE-A5A3-FA74735CAA9D}\RP718\A0046100.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{B59A7010-B5A0-41BE-A5A3-FA74735CAA9D}\RP719\A0046159.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{B59A7010-B5A0-41BE-A5A3-FA74735CAA9D}\RP719\A0046375.EXE
    C:\WINDOWS\SYSTEM32\LI6TXYQU.EXE
    C:\WINDOWS\Prefetch\LI6TXYQU.EXE-0ACBF50F.pf

Trojan.Fake-Drop/Gen
    C:\WINDOWS\SYSTEM32\OLE2SYS2.DLL


Logfile of HijackThis v1.99.1
Scan saved at 20:15:17, on 15-07-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\slserv.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~2\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Maria Schmidt Sander\Desktop\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Vis Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - https://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) -  - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


ComboFix 08-07-14.2 - Maria Schmidt Sander 2008-07-15 20:17:32.1 - NTFSx86
Running from: C:\Documents and Settings\Maria Schmidt Sander\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\eWebControl.dll

.
(((((((((((((((((((((((((  Files Created from 2008-06-15 to 2008-07-15  )))))))))))))))))))))))))))))))
.

2008-07-15 17:15 . 2008-07-15 17:15    <DIR>    d--------    C:\Program Files\SUPERAntiSpyware
2008-07-15 17:15 . 2008-07-15 17:15    <DIR>    d--------    C:\Documents and Settings\Maria Schmidt Sander\Application Data\SUPERAntiSpyware.com
2008-07-15 17:15 . 2008-07-15 17:15    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-07-15 17:07 . 2008-07-15 17:07    <DIR>    d--------    C:\Program Files\CCleaner
2008-07-14 21:51 . 2008-07-14 21:51    0    --a------    C:\WINDOWS\system32\LI6tXyQu.exe.a_a
2008-07-14 20:00 . 2008-07-14 20:42    <DIR>    d--------    C:\Program Files\Security Task Manager
2008-07-14 20:00 . 2008-07-14 21:56    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan
2008-07-14 09:41 . 2008-07-14 22:17    <DIR>    d-a------    C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-07-14 09:40 . 2008-07-14 09:40    <DIR>    d--------    C:\Program Files\Common Files\eSellerate
2008-07-14 09:40 . 2008-07-14 09:40    <DIR>    d--------    C:\Program Files\AnswersThatWork
2008-07-14 09:40 . 2007-06-08 13:53    1,753,088    --a------    C:\WINDOWS\system32\ExGrid.dll
2008-07-14 09:40 . 2007-04-03 16:51    614,400    --a------    C:\WINDOWS\system32\ExButton.dll
2008-07-14 09:40 . 2007-06-05 10:20    602,112    --a------    C:\WINDOWS\system32\ExMenu.dll
2008-07-14 09:40 . 2007-06-05 10:19    516,096    --a------    C:\WINDOWS\system32\ExTab.dll
2008-07-14 09:40 . 1998-04-24 00:00    368,912    --a------    C:\WINDOWS\system32\vbar332.dll
2008-07-14 09:40 . 2005-10-11 14:40    356,352    --a------    C:\WINDOWS\system32\eSellerateEngine.dll
2008-07-14 09:40 . 2007-04-03 16:51    307,200    --a------    C:\WINDOWS\system32\ExPMenu.dll
2008-07-14 09:40 . 2001-03-13 14:49    140,288    --a------    C:\WINDOWS\system32\COMDLG32.OCX
2008-07-14 09:40 . 2004-03-09 01:00    124,688    --a------    C:\WINDOWS\system32\MSWinSck.ocx
2008-07-14 09:10 . 2008-07-14 09:10    <DIR>    d--------    C:\Documents and Settings\Maria Schmidt Sander\Application Data\Uniblue
2008-07-11 20:04 . 2008-07-11 20:05    <DIR>    d--------    C:\Program Files\Zattoo
2008-07-11 12:42 . 2008-07-11 12:42    29,760    --a------    C:\WINDOWS\system32\t5JUM1S7.exe
2008-07-09 07:27 . 2008-07-09 07:27    <DIR>    d--------    C:\WINDOWS\SQLTools9_KB948109_ENU
2008-07-09 07:24 . 2008-07-09 07:24    <DIR>    d--------    C:\WINDOWS\SQL9_KB948109_ENU
2008-06-19 08:23 . 2008-06-19 08:23    <DIR>    d--------    C:\Documents and Settings\All Users.WINDOWS\Application Data\Last.fm
2008-06-19 08:22 . 2008-06-19 08:22    <DIR>    d--------    C:\Program Files\Last.fm

.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-15 15:15    ---------    d-----w    C:\Program Files\Common Files\Wise Installation Wizard
2008-07-15 15:10    ---------    d-----w    C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-07-15 13:02    ---------    d-----w    C:\Program Files\Common Files\Symantec Shared
2008-07-15 08:51    ---------    d-----w    C:\Program Files\Norton 360
2008-07-11 15:26    ---------    d-----w    C:\Program Files\Spybot - Search & Destroy
2008-07-09 05:27    ---------    d-----w    C:\Program Files\Microsoft SQL Server
2008-06-20 17:41    245,248    ----a-w    C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45    360,320    ----a-w    C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44    138,368    ----a-w    C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52    225,920    ----a-w    C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10    272,128    ------w    C:\WINDOWS\system32\drivers\bthport.sys
2008-05-20 04:57    ---------    d-----w    C:\Documents and Settings\Maria Schmidt Sander\Application Data\AdobeUM
2008-05-07 05:18    1,287,680    ----a-w    C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16    826,368    ----a-w    C:\WINDOWS\system32\wininet.dll
2006-02-11 20:05    421,122    ------w    C:\Documents and Settings\Maria Schmidt Sander\OmikronTheNomadSoulv1.0NoCDUS.zip
.

(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 11:49 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 11:49 536576]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 22:10 339968]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-24 01:26 217088]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 14:27 222208]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 18:15 1634304]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-05 21:35:36 618557]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2004-02-12 02:18]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2004-01-28 00:00]
S2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2008-02-21 16:02]

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-07-15 18:00:00 C:\WINDOWS\Tasks\A9953999915AABE9.job"
- c:\docume~1\marias~1\applic~1\creati~1\remotegriddog.exe
"2008-07-11 10:42:42 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 07:00:01 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 08:00:01 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 09:00:01 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-12 10:00:01 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 11:00:01 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 12:00:01 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 13:00:01 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 14:00:03 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 15:00:03 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-13 16:00:03 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-11 10:42:42 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 17:00:04 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 18:00:03 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-14 19:00:02 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-14 20:00:01 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-14 21:00:02 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-11 10:55:30 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-11 10:55:30 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-11 10:55:30 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-11 10:55:30 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-11 10:55:30 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-11 10:42:42 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-11 10:55:30 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-11 10:55:30 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 05:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 06:00:10 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 08:40:45 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 08:00:10 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 09:00:10 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-12 10:00:10 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 13:49:39 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 12:00:10 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-11 10:42:42 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 13:00:10 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 14:02:42 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 15:05:47 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-13 16:11:10 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 17:00:02 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-15 18:00:02 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-14 19:00:00 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-14 20:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-14 21:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\LI6tXyQu.exe
"2008-07-11 10:42:42 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-11 10:42:42 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-11 10:42:42 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 05:00:03 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
"2008-07-15 06:00:02 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\t5JUM1S7.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-15 20:23:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-07-15 20:25:11
ComboFix-quarantined-files.txt  2008-07-15 18:25:05

Pre-Run: 39,008,284,672 bytes free
Post-Run: 39,346,372,608 bytes free

222    --- E O F ---    2008-07-09 05:31:05

:-)
15. juli 2008 - 20:54 #11
-- Dobbeltklik på avenger.exe som tidligere

-- Der dukker et vindue op, hvor du skal kopiere indholdet mellem ~~~ skrift ind:

~~~~~~~~~~~~~~~~~~
Files to delete:
C:\WINDOWS\Tasks\A9953999915AABE9.job
c:\docume~1\marias~1\applic~1\creati~1\remotegriddog.exe
C:\WINDOWS\system32\LI6tXyQu.exe
C:\WINDOWS\system32\t5JUM1S7.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job

Folders to delete:

~~~~~~~~~~~~~~~~~~

-- Klik på EXECUTE - og la' PC'en selv genstarte.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge ind i dit næste svar.

-- Kør en frisk Hijackthis, brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

----------------

Kender du selv noget til denne ->
C:\Program Files\Common Files\eSellerate
C:\WINDOWS\system32\eSellerateEngine.dll
Avatar billede mariasander Nybegynder
15. juli 2008 - 21:47 #12
Hermed logfilen fra avenger:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "C:\WINDOWS\Tasks\A9953999915AABE9.job" deleted successfully.

Error:  file "c:\docume~1\marias~1\applic~1\creati~1\remotegriddog.exe" not found!
Deletion of file "c:\docume~1\marias~1\applic~1\creati~1\remotegriddog.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist

File "C:\WINDOWS\system32\LI6tXyQu.exe" deleted successfully.
File "C:\WINDOWS\system32\t5JUM1S7.exe" deleted successfully.
File "C:\WINDOWS\Tasks\At1.job" deleted successfully.
File "C:\WINDOWS\Tasks\At10.job" deleted successfully.
File "C:\WINDOWS\Tasks\At11.job" deleted successfully.
File "C:\WINDOWS\Tasks\At12.job" deleted successfully.
File "C:\WINDOWS\Tasks\At13.job" deleted successfully.
File "C:\WINDOWS\Tasks\At14.job" deleted successfully.
File "C:\WINDOWS\Tasks\At15.job" deleted successfully.
File "C:\WINDOWS\Tasks\At16.job" deleted successfully.
File "C:\WINDOWS\Tasks\At17.job" deleted successfully.
File "C:\WINDOWS\Tasks\At18.job" deleted successfully.
File "C:\WINDOWS\Tasks\At19.job" deleted successfully.
File "C:\WINDOWS\Tasks\At2.job" deleted successfully.
File "C:\WINDOWS\Tasks\At20.job" deleted successfully.
File "C:\WINDOWS\Tasks\At21.job" deleted successfully.
File "C:\WINDOWS\Tasks\At22.job" deleted successfully.
File "C:\WINDOWS\Tasks\At23.job" deleted successfully.
File "C:\WINDOWS\Tasks\At24.job" deleted successfully.
File "C:\WINDOWS\Tasks\At25.job" deleted successfully.
File "C:\WINDOWS\Tasks\At26.job" deleted successfully.
File "C:\WINDOWS\Tasks\At27.job" deleted successfully.
File "C:\WINDOWS\Tasks\At28.job" deleted successfully.
File "C:\WINDOWS\Tasks\At29.job" deleted successfully.
File "C:\WINDOWS\Tasks\At3.job" deleted successfully.
File "C:\WINDOWS\Tasks\At30.job" deleted successfully.
File "C:\WINDOWS\Tasks\At31.job" deleted successfully.
File "C:\WINDOWS\Tasks\At32.job" deleted successfully.
File "C:\WINDOWS\Tasks\At33.job" deleted successfully.
File "C:\WINDOWS\Tasks\At34.job" deleted successfully.
File "C:\WINDOWS\Tasks\At35.job" deleted successfully.
File "C:\WINDOWS\Tasks\At36.job" deleted successfully.
File "C:\WINDOWS\Tasks\At37.job" deleted successfully.
File "C:\WINDOWS\Tasks\At38.job" deleted successfully.
File "C:\WINDOWS\Tasks\At39.job" deleted successfully.
File "C:\WINDOWS\Tasks\At4.job" deleted successfully.
File "C:\WINDOWS\Tasks\At40.job" deleted successfully.
File "C:\WINDOWS\Tasks\At41.job" deleted successfully.
File "C:\WINDOWS\Tasks\At42.job" deleted successfully.
File "C:\WINDOWS\Tasks\At43.job" deleted successfully.
File "C:\WINDOWS\Tasks\At44.job" deleted successfully.
File "C:\WINDOWS\Tasks\At45.job" deleted successfully.
File "C:\WINDOWS\Tasks\At46.job" deleted successfully.
File "C:\WINDOWS\Tasks\At47.job" deleted successfully.
File "C:\WINDOWS\Tasks\At48.job" deleted successfully.
File "C:\WINDOWS\Tasks\At5.job" deleted successfully.
File "C:\WINDOWS\Tasks\At6.job" deleted successfully.
File "C:\WINDOWS\Tasks\At7.job" deleted successfully.
File "C:\WINDOWS\Tasks\At8.job" deleted successfully.
File "C:\WINDOWS\Tasks\At9.job" deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.

Jeg kender ikke noget til eSellerate
Avatar billede mariasander Nybegynder
15. juli 2008 - 21:50 #13
Her er loggen fra HiJackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:49:21, on 15-07-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~2\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\slserv.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Maria Schmidt Sander\Local Settings\Temporary Internet Files\Content.IE5\IWGA2YJM\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Vis Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - https://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) -  - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 7567 bytes
15. juli 2008 - 22:00 #14
BINGO!

Hvordan kører PC'en så nu ?
Avatar billede mariasander Nybegynder
16. juli 2008 - 09:01 #15
Det ser ud til at den kører perfekt. Tusind tak for hjælpen:-). Nu finder jeg lige ud af det der pointgivning.
Avatar billede mariasander Nybegynder
16. juli 2008 - 09:14 #16
Er det sådan at du skal skrive et svar og ikke en kommentar, før end jeg kan uddele point?
16. juli 2008 - 13:48 #17
Der er ikke mere 'snavs' ifølge din Log...

Du er velkommen en anden gang...

Du bør rense temp med denne fil, det tager kun få sek.
http://www.spywareinfo.dk/download/cleantempxp2k.bat

Efter sådan en tur er det altid en god ide og rydde op i systemgendannelsesfilerne.
Deaktiver systemgendannelse -> http://www.spywareinfo.dk/#/tip-og-tricks/deaktiver_systemgendannelse.htm
Genstart din computer - aktiver systemgendannelse. Dette gøres samme sted, hvor du deaktiverede, denne gang skal du blot aktivere.
Det vil også være en god idé manuelt at oprette et nyt punkt, som du kan navngive, og vende tilbage til, hvis du skulle få problemer af nogen art.

Safe Surfing...

--------------

Registreringsdatabase oprydning kan anbefales ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Register]...)
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller NEJ til den.

--------------

Husk M$ ServicePack3 til XP -> http://www.microsoft.com/downloads/details.aspx?FamilyID=5b33b5a8-5e76-401f-be08-1e1555d4f3d4&displaylang=da
16. juli 2008 - 22:08 #18
Takker for P.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester