Programvare Skrevet 17. april 2007 Del Skrevet 17. april 2007 Når jeg skrur på pc'en og windows har ladet seg så dukker system32-mappa opp av en eller annen merkelig grunn. Jeg har ikke tukla med noen innstillinger. Bare plutselig en dag jeg skrudde på maskina var det sånn. Merkelig Det er jo egentlig ikke noe problem, men det er fryktelig irriterende. Jeg har sjekka en såkalt startupmappe med alle tingene som dukker opp når man starter, men den var ikke der. Slik ser det ut når jeg starter. Ps. jeg sladda bort noen ikoner Lenke til kommentar
Xneon Skrevet 17. april 2007 Del Skrevet 17. april 2007 Hey. Har du sjekka oppstartsprogrammene? Skriv msconfig i kjørlinja på startmenyen og velg oppstart i den menyen du kommer i da( lengst til høyre) Sjekk om det står noe der som har med sys32 å gjøre. Hvis det er noe der krysser du av i boksen til venstre... Lenke til kommentar
Programvare Skrevet 17. april 2007 Forfatter Del Skrevet 17. april 2007 Jeg sjekka, men nei. Lenke til kommentar
norbat Skrevet 17. april 2007 Del Skrevet 17. april 2007 (endret) Man kan forsøke en systemgjenoppretting (tilbehør->systemverktøy->systemgjenoppretting) til en dato der ting og tang virket ok. Microsoft har sin løsning: http://support.microsoft.com/kb/170086 Om dette ikke hjalp, ville jeg nok tatt en liten sjekk: https://www.diskusjon.no/index.php?showtopic=691246 Endret 17. april 2007 av norbat Lenke til kommentar
Jarmo Skrevet 17. april 2007 Del Skrevet 17. april 2007 Endret dato: 11. april 2007. Kl. 16.50 Lenke til kommentar
Syar-2003 Skrevet 17. april 2007 Del Skrevet 17. april 2007 Dette skjer etter fjerning/avinstallering av en applikasjon som feilaktig lar register entry's bli igjen . Fixes med regedit slik : 1.Launch the Windows Registry Editor (regedit.exe). 2.Open this registry key: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run. 3.If the (Default) Name variable has a value of "" (an empty string), delete the Name variable. After the deletion, the value for (Default) should be "(value not set)". Lenke til kommentar
Programvare Skrevet 17. april 2007 Forfatter Del Skrevet 17. april 2007 Nå har jeg prøvd alle tipsene her, men den ondskapsfulle system32-mappa er der ennå når jeg starter opp HJELP? Lenke til kommentar
Jarmo Skrevet 17. april 2007 Del Skrevet 17. april 2007 Nå har jeg prøvd alle tipsene her, men den ondskapsfulle system32-mappa er der ennå når jeg starter opp HJELP? 8408249[/snapback] Har du prøvd systemgjenoppretting tilbake til datoen før sist endret? Lenke til kommentar
norbat Skrevet 17. april 2007 Del Skrevet 17. april 2007 (endret) Nå har jeg prøvd alle tipsene her, men den ondskapsfulle system32-mappa er der ennå når jeg starter opp HJELP? 8408249[/snapback] 1. Du har prøvd systemgjenoppretting til en dato der ting og tang virket OK? (I dette tilfellet er det antakelig snakk om før 11.april). Om du ikke får til å gjenopprette fra normal modus, starter du i sikker modus og prøver en gang til 2. Har du sjekke microsoft sin løsning? Det er snakk om to registeroppføringer, èn under HKEY_LOCAL_MACHINE og èn i HKEY_CURRENT_USER. 3. Har du kjørt en scan med et antispywareprog og kjørt en scan med HJT slik at du har fått noen logger vi kan titte på for å se om det kan være noe der som ikke bør være der. Endret 17. april 2007 av norbat Lenke til kommentar
Programvare Skrevet 18. april 2007 Forfatter Del Skrevet 18. april 2007 Ja, jeg har prøvd 1. Null resultat Ja, jeg har prøvd 2. Null resultat Nei, jeg skal prøve 3, beklager Lenke til kommentar
Programvare Skrevet 18. april 2007 Forfatter Del Skrevet 18. april 2007 Her er loggen etter HiuJackThis Logfile of HijackThis v1.99.1 Scan saved at 16:19:11, on 18.04.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Norman\bin\ZANDA.EXE C:\WINNT\system32\nvsvc32.exe C:\Programfiler\Wireless 802.11g Monitor\WLService.exe C:\Programfiler\Wireless 802.11g Monitor\WLanCfgG.exe C:\WINNT\System32\svchost.exe C:\Norman\bin\NJEEVES.EXE C:\WINNT\Explorer.EXE C:\Programfiler\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe C:\Programfiler\NavExcel\NavHelper\v2.0.4d\navapp.exe C:\Program Files\Vlwx\Nunf.exe C:\Programfiler\Java\jre1.5.0_11\bin\jusched.exe C:\Programfiler\Wireless 802.11g Monitor\InfoMyCa.exe C:\WINNT\system32\LVCOMSX.EXE C:\Programfiler\Logitech\Video\LogiTray.exe C:\Norman\bin\ZLH.EXE C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe C:\Programfiler\CyberLink\PowerDVD\PDVDServ.exe C:\Programfiler\iTunes\iTunesHelper.exe C:\Programfiler\iPod\bin\iPodService.exe C:\WINNT\system32\ctfmon.exe C:\WINNT\System32\svchost.exe C:\Programfiler\Logitech\Video\FxSvr2.exe C:\Programfiler\MSN Messenger\usnsvc.exe C:\Norman\Nvc\bin\nvcoas.exe C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Programfiler\DivX\DivX Player\DivX Player.exe C:\Norman\Nvc\bin\cclaw.exe C:\Programfiler\Microsoft Office\Office10\WINWORD.EXE C:\Programfiler\Microsoft Office\Office10\WINWORD.EXE C:\Programfiler\Opera\Opera.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dagbladet.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.nextel.no/proxy.pac R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=proxy.online.no:8080;http=proxy.online.no:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programfiler\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing) O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programfiler\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programfiler\MyWebSearch\bar\1.bin\MWSBAR.DLL (file missing) O2 - BHO: Search Relevancy - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~2.DLL (file missing) O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing) O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programfiler\BitComet\tools\BitCometBHO_1.1.3.19.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll (file missing) O2 - BHO: CSBHO Class - {D14D6793-9B65-11D3-80B6-00500487BDBA} - C:\PROGRA~1\Comet\Bin\csbho.dll (file missing) O2 - BHO: Helper Class - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - C:\Programfiler\NavExcel Search Toolbar\NavExcelBar.dll (file missing) O3 - Toolbar: Starware - {FE6BC4EF-5676-484B-88AE-883323913256} - C:\PROGRA~1\Comet\Bin\csietb.dll O3 - Toolbar: NavExcel Toolbar - {5AA06644-BC46-4220-A460-47A6EB47C96D} - C:\Programfiler\NavExcel Search Toolbar\NavExcelBar.dll (file missing) O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll (file missing) O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programfiler\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [anvshell] anvshell.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programfiler\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [navapp] C:\Programfiler\NavExcel\NavHelper\v2.0.4d\navapp.exe O4 - HKLM\..\Run: [Kttdcqkb] C:\Program Files\Vlwx\Nunf.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [infoMyCa.exe] C:\Programfiler\Wireless 802.11g Monitor\InfoMyCa.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programfiler\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programfiler\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programfiler\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [RemoteControl] C:\Programfiler\CyberLink\PowerDVD\PDVDServ.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe O4 - HKCU\..\Run: [RiskIISetup.exe] /r O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Programfiler\Ubisoft\Demo\Ghost Recon Advanced Warfighter Demo\Support\Register\RegistrationReminder.exe O4 - Global Startup: Date Manager.lnk = C:\Programfiler\Date Manager\DateManager.exe O4 - Global Startup: GStartup.lnk = C:\Programfiler\Fellesfiler\GMT\GMT.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Programfiler\MyWebSearch\bar\1.bin\MWSOEMON.EXE O4 - Global Startup: PC-søk i Windows.lnk = C:\Programfiler\Norsk Strek AS\MSN Toolbar Suite\DS\02.05.0000.1105\nb-no\bin\WindowsSearch.exe O4 - Global Startup: PrecisionTime.lnk = C:\Programfiler\PrecisionTime\PrecisionTime.exe O8 - Extra context menu item: &MSN Search - res://C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll/search.htm O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029YYNO_ZS O8 - Extra context menu item: Download all links using BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download all videos using BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: Download link using &BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Web Rebates - file://C:\Programfiler\Web_Rebates\Sy1150\Tp1150\scri1150a.htm O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\TAB\02.05.0000.1105\nb-no\msntabres.dll/229?66c49746326e4252b05ed7fdb2416ff O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\TAB\02.05.0000.1105\nb-no\msntabres.dll/230?66c49746326e4252b05ed7fdb2416ff O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php...d9d6f067011f31e O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.exe O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.com/images/uploader/ssi...ureUploader.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://creative.com/su/ocx/15021/CTPID.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: winstr32 - winstr32.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programfiler\iPod\bin\iPodService.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe O23 - Service: R54G Wireless Service - Unknown owner - C:\Programfiler\Wireless 802.11g Monitor\WLService.exe Lenke til kommentar
norbat Skrevet 18. april 2007 Del Skrevet 18. april 2007 Hei, Hent CCleaner. Start programmet. Gå til 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer......." Klikk på 'Renser' og deretter 'Kjør CCleaner'. Hent Combofix, og legg det på skrivebordet Kjør combofix.exe, og følg veiledningen. Du må ikke klikke på vinduet mens programmet kjører. Når programmet er ferdig åpnes en loggfil: combofix.txt Hent SAS, installer, oppdater og kjør en full (Complete) scan. Post en ny HJT-logg + loggen fra Combofix Lenke til kommentar
Programvare Skrevet 18. april 2007 Forfatter Del Skrevet 18. april 2007 (endret) Nå har jeg tatt Ccleaner og combofix her er combofix-loggen "Roger" - 07-04-18 18:27:12 Service Pack 2 ComboFix 07-04-18.2V - Running from: C:\Documents and Settings\Roger\ (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINNT\installer\12f56b.msi C:\WINNT\installer\6140a0.msi ((((((((((((((((((((((((((((((( Files Created from 2007-03-18 to 2007-04-18 )))))))))))))))))))))))))))))))))) 2007-04-18 18:24 <DIR> dr-h----- C:\DOCUME~1\Roger\Siste 2007-04-18 17:33 <DIR> d-------- C:\Programfiler\CCleaner 2007-04-18 16:22 <DIR> d-------- C:\Programfiler\MPD 2007-04-05 08:37 <DIR> d-------- C:\Programfiler\QuickTime 2007-04-04 20:47 <DIR> d-------- C:\Programfiler\Opera (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-04-10 20:16 -------- d-------- C:\Programfiler\msn messenger 2007-04-05 08:42 -------- d-------- C:\Programfiler\itunes 2007-04-05 08:42 -------- d-------- C:\Programfiler\ipod 2007-03-31 08:33 60326 --a------ C:\WINNT\system32\perfc014.dat 2007-03-31 08:33 384784 --a------ C:\WINNT\system32\perfh014.dat 2007-03-26 23:06 2560 --a--c--- C:\WINNT\system32\bitcometres.dll 2007-03-19 23:13 -------- d--h----- C:\Programfiler\installshield installation information 2007-03-17 15:45 292864 --a------ C:\WINNT\system32\winsrv.dll 2007-03-10 15:23 -------- d-------- C:\Programfiler\digital guitar tuner 2007-03-10 12:05 -------- d-------- C:\Programfiler\limewire 2007-03-08 17:39 577536 --a------ C:\WINNT\system32\user32.dll 2007-03-08 17:39 40960 --a------ C:\WINNT\system32\mf3216.dll 2007-03-08 17:39 281600 --a------ C:\WINNT\system32\gdi32.dll 2007-03-08 17:38 1843584 --a------ C:\WINNT\system32\win32k.sys 2007-03-06 16:42 -------- d-------- C:\Programfiler\tunatic 2007-03-03 23:43 -------- d-------- C:\Programfiler\google 2007-02-25 20:22 -------- d-------- C:\Programfiler\java 2007-02-06 20:01 100488 --a------ C:\DOCUME~1\Roger\PROGRA~1\gdipfontcachev1.dat 2007-02-05 22:19 185344 --a------ C:\WINNT\system32\upnphost.dll 2007-02-03 11:22 1164 --a------ C:\WINNT\mozver.dat 2007-02-03 11:07 0 --a------ C:\WINNT\nsreg.dat 2007-02-01 06:56 823296 --a------ C:\WINNT\system32\divx_xx0c.dll 2007-02-01 06:56 823296 --a------ C:\WINNT\system32\divx_xx07.dll 2007-02-01 06:56 802816 --a------ C:\WINNT\system32\divx_xx11.dll 2007-02-01 06:56 639066 --a------ C:\WINNT\system32\divx.dll 2007-01-31 23:27 524288 --a------ C:\WINNT\system32\divxsm.exe 2007-01-31 01:15 118784 --a------ C:\WINNT\system32\divxcodecupdatechecker.exe 2007-01-30 07:03 3596288 --a------ C:\WINNT\system32\qt-dx331.dll 2007-01-30 07:03 200704 --a------ C:\WINNT\system32\ssldivx.dll 2007-01-30 07:03 129784 --------- C:\WINNT\system32\pxafs.dll 2007-01-30 07:03 118520 --------- C:\WINNT\system32\pxinsi64.exe 2007-01-30 07:03 116472 --------- C:\WINNT\system32\pxcpyi64.exe 2007-01-30 07:03 1044480 --a------ C:\WINNT\system32\libdivx.dll 2007-01-30 06:56 73728 --a------ C:\WINNT\system32\dpl100.dll 2007-01-30 06:56 593920 --a------ C:\WINNT\system32\dpugui11.dll 2007-01-30 06:56 57344 --a------ C:\WINNT\system32\dpv11.dll 2007-01-30 06:56 53248 --a------ C:\WINNT\system32\dpugui10.dll 2007-01-30 06:56 344064 --a------ C:\WINNT\system32\dpus11.dll 2007-01-30 06:56 294912 --a------ C:\WINNT\system32\dpu11.dll 2007-01-30 06:56 294912 --a------ C:\WINNT\system32\dpu10.dll 2007-01-30 06:56 196608 --a------ C:\WINNT\system32\dtu100.dll 2007-01-19 12:53 51056 --a------ C:\WINNT\system32\sirenacm.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll {1D7E3B41-23CE-469B-BE1B-A64B877923E1} C:\PROGRA~1\SEARCH~1\SEARCH~2.DLL [x] {35E78239-811E-4c3f-B37D-F339AC16C2C0} C:\PROGRA~1\Comet\bin\autosearch.dll [x] {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} C:\Programfiler\BitComet\tools\BitCometBHO_1.1.3.19.dll {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll {AA58ED58-01DD-4d91-8333-CF10577473F7} c:\programfiler\google\googletoolbar4.dll {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll [x] {D14D6793-9B65-11D3-80B6-00500487BDBA} C:\PROGRA~1\Comet\Bin\csbho.dll [x] {D80C4E21-C346-4E21-8E64-20746AA20AEB} C:\Programfiler\NavExcel Search Toolbar\NavExcelBar.dll [x] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "NvCplDaemon"="RUNDLL32.EXE C:\\WINNT\\system32\\NvCpl.dll,NvStartup" "nwiz"="nwiz.exe /install" "anvshell"="anvshell.exe" "AdaptecDirectCD"="\"C:\\Programfiler\\Adaptec\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\"" "HPDJ Taskbar Utility"="C:\\WINNT\\System32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe" "navapp"="C:\\Programfiler\\NavExcel\\NavHelper\\v2.0.4d\\navapp.exe" "Kttdcqkb"="C:\\Program Files\\Vlwx\\Nunf.exe" "SunJavaUpdateSched"="\"C:\\Programfiler\\Java\\jre1.5.0_11\\bin\\jusched.exe\"" "InfoMyCa.exe"="C:\\Programfiler\\Wireless 802.11g Monitor\\InfoMyCa.exe" "LVCOMSX"="C:\\WINNT\\system32\\LVCOMSX.EXE" "LogitechVideoRepair"="C:\\Programfiler\\Logitech\\Video\\ISStart.exe " "LogitechVideoTray"="C:\\Programfiler\\Logitech\\Video\\LogiTray.exe" "Easy-PrintToolBox"="C:\\Programfiler\\Canon\\Easy-PrintToolBox\\BJPSMAIN.EXE /logon" "Norman ZANDA"="C:\\Norman\\bin\\ZLH.EXE /LOAD /SPLASH" "HP Software Update"="C:\\Programfiler\\HP\\HP Software Update\\HPWuSchd2.exe" "RemoteControl"="C:\\Programfiler\\CyberLink\\PowerDVD\\PDVDServ.exe" "NeroFilterCheck"="C:\\WINNT\\system32\\NeroCheck.exe" "QuickTime Task"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime" "iTunesHelper"="\"C:\\Programfiler\\iTunes\\iTunesHelper.exe\"" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "LDM"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\BackWeb-8876480.exe" "RiskIISetup.exe"=" /r" "Steam"="" "ctfmon.exe"="C:\\WINNT\\system32\\ctfmon.exe" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winstr32 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages REG_MULTI_SZ msv1_0\0\0 Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages REG_MULTI_SZ scecli\0\0 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Programmer^Oppstart^Exif Launcher.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Programmer\\Oppstart\\Exif Launcher.lnk" "backup"="C:\\WINNT\\pss\\Exif Launcher.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~2\\EXIFLA~1\\QuickDCF.exe " "item"="Exif Launcher" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="apdproxy" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Mixer" "hkey"="HKLM" "command"="Mixer.exe /startup" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_GTNDIS5 Contents of the 'Scheduled Tasks' folder C:\WINNT\tasks\AppleSoftwareUpdate.job ******************************************************************** catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-04-18 18:34:20 C:\ComboFix-quarantined-files.txt ... 07-04-18 18:34 HER ER EN NY HTJ-LOGG Logfile of HijackThis v1.99.1 Scan saved at 18:44:51, on 18.04.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Norman\bin\ZANDA.EXE C:\WINNT\system32\nvsvc32.exe C:\Programfiler\Wireless 802.11g Monitor\WLService.exe C:\Programfiler\Wireless 802.11g Monitor\WLanCfgG.exe C:\WINNT\System32\svchost.exe C:\Norman\bin\NJEEVES.EXE C:\WINNT\Explorer.EXE C:\Programfiler\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe C:\Programfiler\NavExcel\NavHelper\v2.0.4d\navapp.exe C:\Program Files\Vlwx\Nunf.exe C:\Programfiler\Java\jre1.5.0_11\bin\jusched.exe C:\Programfiler\Wireless 802.11g Monitor\InfoMyCa.exe C:\WINNT\system32\LVCOMSX.EXE C:\Programfiler\Logitech\Video\LogiTray.exe C:\Norman\bin\ZLH.EXE C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe C:\Programfiler\CyberLink\PowerDVD\PDVDServ.exe C:\Programfiler\iTunes\iTunesHelper.exe C:\Programfiler\iPod\bin\iPodService.exe C:\WINNT\system32\ctfmon.exe C:\WINNT\System32\svchost.exe C:\Programfiler\Logitech\Video\FxSvr2.exe C:\Programfiler\MSN Messenger\usnsvc.exe C:\Norman\Nvc\bin\nvcoas.exe C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\bin\cclaw.exe C:\Programfiler\Opera\Opera.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dagbladet.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.nextel.no/proxy.pac R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=proxy.online.no:8080;http=proxy.online.no:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Search Relevancy - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~2.DLL (file missing) O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing) O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programfiler\BitComet\tools\BitCometBHO_1.1.3.19.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll (file missing) O2 - BHO: CSBHO Class - {D14D6793-9B65-11D3-80B6-00500487BDBA} - C:\PROGRA~1\Comet\Bin\csbho.dll (file missing) O2 - BHO: Helper Class - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - C:\Programfiler\NavExcel Search Toolbar\NavExcelBar.dll (file missing) O3 - Toolbar: Starware - {FE6BC4EF-5676-484B-88AE-883323913256} - C:\PROGRA~1\Comet\Bin\csietb.dll O3 - Toolbar: NavExcel Toolbar - {5AA06644-BC46-4220-A460-47A6EB47C96D} - C:\Programfiler\NavExcel Search Toolbar\NavExcelBar.dll (file missing) O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll (file missing) O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programfiler\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [anvshell] anvshell.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programfiler\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [navapp] C:\Programfiler\NavExcel\NavHelper\v2.0.4d\navapp.exe O4 - HKLM\..\Run: [Kttdcqkb] C:\Program Files\Vlwx\Nunf.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [infoMyCa.exe] C:\Programfiler\Wireless 802.11g Monitor\InfoMyCa.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programfiler\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programfiler\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programfiler\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [RemoteControl] C:\Programfiler\CyberLink\PowerDVD\PDVDServ.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe O4 - HKCU\..\Run: [RiskIISetup.exe] /r O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Programfiler\Ubisoft\Demo\Ghost Recon Advanced Warfighter Demo\Support\Register\RegistrationReminder.exe O4 - Global Startup: Date Manager.lnk = C:\Programfiler\Date Manager\DateManager.exe O4 - Global Startup: GStartup.lnk = C:\Programfiler\Fellesfiler\GMT\GMT.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Programfiler\MyWebSearch\bar\1.bin\MWSOEMON.EXE O4 - Global Startup: PC-søk i Windows.lnk = C:\Programfiler\Norsk Strek AS\MSN Toolbar Suite\DS\02.05.0000.1105\nb-no\bin\WindowsSearch.exe O4 - Global Startup: PrecisionTime.lnk = C:\Programfiler\PrecisionTime\PrecisionTime.exe O8 - Extra context menu item: &MSN Search - res://C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll/search.htm O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029YYNO_ZS O8 - Extra context menu item: Download all links using BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download all videos using BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: Download link using &BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Web Rebates - file://C:\Programfiler\Web_Rebates\Sy1150\Tp1150\scri1150a.htm O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\TAB\02.05.0000.1105\nb-no\msntabres.dll/229?66c49746326e4252b05ed7fdb2416ff O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\TAB\02.05.0000.1105\nb-no\msntabres.dll/230?66c49746326e4252b05ed7fdb2416ff O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php...d9d6f067011f31e O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.exe O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.com/images/uploader/ssi...ureUploader.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://creative.com/su/ocx/15021/CTPID.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: winstr32 - winstr32.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programfiler\iPod\bin\iPodService.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe O23 - Service: R54G Wireless Service - Unknown owner - C:\Programfiler\Wireless 802.11g Monitor\WLService.exe Endret 18. april 2007 av chryzsh Lenke til kommentar
norbat Skrevet 18. april 2007 Del Skrevet 18. april 2007 Fint. Da kjører du en 'complete scan' med SAS. Post deretter en ny HJT-logg + loggen fra SAS (preferences->statistics/logs). Resten tar vi manuelt Lenke til kommentar
Programvare Skrevet 18. april 2007 Forfatter Del Skrevet 18. april 2007 Fint. Da kjører du en 'complete scan' med SAS. Post deretter en ny HJT-logg + loggen fra SAS (preferences->statistics/logs). Resten tar vi manuelt 8415374[/snapback] Jeg kjører complete scan nå. Jeg har ca. 55 gb fylt opp på datan. Hvor lang tid vil det ta? Lenke til kommentar
norbat Skrevet 18. april 2007 Del Skrevet 18. april 2007 Kommer litt an på. Rundt 1 time, kanskje Lenke til kommentar
Programvare Skrevet 18. april 2007 Forfatter Del Skrevet 18. april 2007 Hva gjør jeg nå? Lenke til kommentar
norbat Skrevet 18. april 2007 Del Skrevet 18. april 2007 Sett også merke framfor Gator og MyWebSearch og klikk deretter 'Neste'. Lenke til kommentar
Programvare Skrevet 18. april 2007 Forfatter Del Skrevet 18. april 2007 Nå har jeg gjort alle tipsene, men den fordømte mappa er der ennå når jeg restarta! Her ere loggen for SAS SUPERAntiSpyware Scan Log Generated 04/18/2007 at 08:17 PM Application Version : 3.6.1000 Core Rules Database Version : 3220 Trace Rules Database Version: 1230 Scan type : Complete Scan Total Scan Time : 01:18:50 Memory items scanned : 435 Memory threats detected : 2 Registry items scanned : 6756 Registry threats detected : 7902 File items scanned : 53448 File threats detected : 12 NavExcel/NavHelper Application C:\PROGRAMFILER\NAVEXCEL\NAVHELPER\V2.0.4D\NAVAPP.EXE C:\PROGRAMFILER\NAVEXCEL\NAVHELPER\V2.0.4D\NAVAPP.EXE [navapp] C:\PROGRAMFILER\NAVEXCEL\NAVHELPER\V2.0.4D\NAVAPP.EXE C:\WINNT\Prefetch\NAVAPP.EXE-12B5F9F2.pf Adware.Avenue Media C:\PROGRAM FILES\VLWX\NUNF.EXE C:\PROGRAM FILES\VLWX\NUNF.EXE [Kttdcqkb] C:\PROGRAM FILES\VLWX\NUNF.EXE Adware.MyWebSearch HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D} HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D} HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32 HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\Programmable C:\PROGRAMFILER\MYWEBSEARCH\SRCHASTT\1.BIN\MWSSRCAS.DLL HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32 HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\Programmable HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\TypeLib C:\PROGRAMFILER\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL Trojan.Search Variant HKLM\Software\Classes\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1} HKCR\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1} HKCR\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1} HKCR\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1}\InprocServer32 HKCR\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1}\InprocServer32#ThreadingModel HKCR\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1}\ProgID HKCR\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1}\Programmable HKCR\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1}\TypeLib HKCR\CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1}\VersionIndependentProgID C:\PROGRA~1\SEARCH~1\SEARCH~2.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1D7E3B41-23CE-469B-BE1B-A64B877923E1} Trojan.Comet/AutoSearch HKLM\Software\Classes\CLSID\{35E78239-811E-4c3f-B37D-F339AC16C2C0} HKCR\CLSID\{35E78239-811E-4C3F-B37D-F339AC16C2C0} HKCR\CLSID\{35E78239-811E-4C3F-B37D-F339AC16C2C0} HKCR\CLSID\{35E78239-811E-4C3F-B37D-F339AC16C2C0}\InprocServer32 HKCR\CLSID\{35E78239-811E-4C3F-B37D-F339AC16C2C0}\InprocServer32#ThreadingModel C:\PROGRA~1\COMET\BIN\AUTOSEARCH.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35E78239-811E-4c3f-B37D-F339AC16C2C0} NavExcel/NavHelper Adware Toolbar and Browser Helper Object HKLM\Software\Classes\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D} HKCR\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D} HKCR\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D} HKCR\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D}\InprocServer32 HKCR\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D}\InprocServer32#ThreadingModel HKCR\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D}\ProgID HKCR\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D}\Programmable HKCR\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D}\TypeLib HKCR\CLSID\{5AA06644-BC46-4220-A460-47A6EB47C96D}\VersionIndependentProgID C:\PROGRAMFILER\NAVEXCEL SEARCH TOOLBAR\NAVEXCELBAR.DLL HKLM\Software\Classes\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB} HKCR\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB} HKCR\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB} HKCR\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB}\InprocServer32 HKCR\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB}\InprocServer32#ThreadingModel HKCR\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB}\ProgID HKCR\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB}\Programmable HKCR\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB}\TypeLib HKCR\CLSID\{D80C4E21-C346-4E21-8E64-20746AA20AEB}\VersionIndependentProgID HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D80C4E21-C346-4E21-8E64-20746AA20AEB} HKLM\Software\Microsoft\Internet Explorer\Toolbar#{5AA06644-BC46-4220-A460-47A6EB47C96D} HKCR\NavExcelBar.NavExcelBarObj.1 HKCR\NavExcelBar.NavExcelBarObj HKCR\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945} Comet Cursor Explorer Bar HKLM\Software\Classes\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E} HKCR\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E} HKCR\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E} HKCR\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E}\Implemented Categories HKCR\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E}\Implemented Categories\{00021494-0000-0000-C000-000000000046} HKCR\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E}\InprocServer32 HKCR\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E}\InprocServer32#ThreadingModel C:\PROGRA~1\COMET\BIN\CSBAND.DLL HKLM\Software\Classes\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76} HKCR\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76} HKCR\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76} HKCR\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76}\Implemented Categories HKCR\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76}\Implemented Categories\{00021493-0000-0000-C000-000000000046} HKCR\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76}\InprocServer32 HKCR\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76}\InprocServer32#ThreadingModel HKU\S-1-5-21-1583818474-1631327491-465637648-1005\Software\Microsoft\Internet Explorer\Explorer Bars\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E} HKU\S-1-5-21-1583818474-1631327491-465637648-1005\Software\Microsoft\Internet Explorer\Explorer Bars\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76} NavExcel/NavHelper BHO HKLM\Software\Classes\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC}#AppID HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC}\InprocServer32 HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC}\InprocServer32#ThreadingModel HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC}\ProgID HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC}\Programmable HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC}\TypeLib HKCR\CLSID\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC}\VersionIndependentProgID C:\PROGRAMFILER\NAVEXCEL\NAVHELPER\V2.0.4D\NHELPER.DLL Comet Cursor BHO HKLM\Software\Classes\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA} HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA} HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA} HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\Implemented Categories HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\InprocServer32 HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\InprocServer32#ThreadingModel HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\ProgID HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\Programmable HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\TypeLib HKCR\CLSID\{D14D6793-9B65-11D3-80B6-00500487BDBA}\VersionIndependentProgID C:\PROGRA~1\COMET\BIN\CSBHO.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D14D6793-9B65-11D3-80B6-00500487BDBA} Comet Cursor Toolbar HKLM\Software\Classes\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256} HKCR\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256} HKCR\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256} HKCR\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256}\InprocServer32 HKCR\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256}\InprocServer32#ThreadingModel HKCR\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256}\ProgID HKCR\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256}\Programmable HKCR\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256}\TypeLib HKCR\CLSID\{FE6BC4EF-5676-484B-88AE-883323913256}\VersionIndependentProgID C:\PROGRA~1\COMET\BIN\CSIETB.DLL HKLM\Software\Microsoft\Internet Explorer\Toolbar#{FE6BC4EF-5676-484B-88AE-883323913256} HKCR\CometIEToolbar.CometToolbar.1 HKCR\CometIEToolbar.CometToolbar.1\CLSID HKCR\CometIEToolbar.CometToolbar HKCR\CometIEToolbar.CometToolbar\CLSID HKCR\CometIEToolbar.CometToolbar\CurVer HKCR\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215} HKCR\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0 HKCR\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0\0 HKCR\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0\0\win32 HKCR\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0\FLAGS HKCR\TypeLib\{878ACE1B-8DB0-4D75-9034-504756AD4215}\1.0\HELPDIR Adware.GAIN/Gator HKLM\Software\Gator.com HKLM\Software\Gator.com\AppInfo HKLM\Software\Gator.com\AppInfo\CME HKLM\Software\Gator.com\AppInfo\CME#event HKLM\Software\Gator.com\AppInfo\CME#timeout_secs_ui HKLM\Software\Gator.com\AppInfo\CME#timeout_secs_full HKLM\Software\Gator.com\AppInfo\CME#restart HKLM\Software\Gator.com\AppInfo\CME#lockfiles HKLM\Software\Gator.com\AppInfo\DateManager HKLM\Software\Gator.com\AppInfo\DateManager#event HKLM\Software\Gator.com\AppInfo\DateManager#timeout_secs_ui HKLM\Software\Gator.com\AppInfo\DateManager#timeout_secs_full HKLM\Software\Gator.com\AppInfo\DateManager#lockfiles HKLM\Software\Gator.com\AppInfo\DateManager#restart HKLM\Software\Gator.com\AppInfo\GMT HKLM\Software\Gator.com\AppInfo\GMT#event HKLM\Software\Gator.com\AppInfo\GMT#timeout_secs_ui HKLM\Software\Gator.com\AppInfo\GMT#timeout_secs_full HKLM\Software\Gator.com\AppInfo\GMT#restart HKLM\Software\Gator.com\AppInfo\PrecisionTime HKLM\Software\Gator.com\AppInfo\PrecisionTime#event HKLM\Software\Gator.com\AppInfo\PrecisionTime#timeout_secs_ui HKLM\Software\Gator.com\AppInfo\PrecisionTime#timeout_secs_full HKLM\Software\Gator.com\AppInfo\PrecisionTime#lockfiles HKLM\Software\Gator.com\AppInfo\PrecisionTime#restart HKLM\Software\Gator.com\CMEII HKLM\Software\Gator.com\CMEII#appPath HKLM\Software\Gator.com\CMEII#Uninstall HKLM\Software\Gator.com\CMEII#runcnt HKLM\Software\Gator.com\CMEII#lastrun HKLM\Software\Gator.com\CMEII#RunApps HKLM\Software\Gator.com\CMEII#firstRunSent HKLM\Software\Gator.com\CMEII#numInst HKLM\Software\Gator.com\CMEII\GSNInstalled HKLM\Software\Gator.com\Date Manager HKLM\Software\Gator.com\Date Manager#AppPath HKLM\Software\Gator.com\Date Manager#LastAutoupdateCall HKLM\Software\Gator.com\Gator HKLM\Software\Gator.com\Gator\dyn HKLM\Software\Gator.com\Gator\dyn#PdpFirstStart HKLM\Software\Gator.com\Gator\dyn#AppPath HKLM\Software\Gator.com\Gator\dyn#AppExe HKLM\Software\Gator.com\Gator\dyn#ResDll HKLM\Software\Gator.com\Gator\dyn\AutoUpdate HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#NextCheck HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#LastCheckTime HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#SeqHttpErrs HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#LastDnld HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#LastRun HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#AppletEndState HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#DefaultCheckIntervalHours HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#PatchHistory HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#TmpUpdaterApplet HKLM\Software\Gator.com\Gator\dyn\AutoUpdate#UpdaterApplet HKLM\Software\Gator.com\Gator\dyn\BannerManager HKLM\Software\Gator.com\Gator\dyn\BannerManager#LastHashDownload HKLM\Software\Gator.com\Gator\dyn\BannerManager#AELLastHashDownload HKLM\Software\Gator.com\Gator\dyn\BannerManager#MaxSiteHashAgeSecondsDef HKLM\Software\Gator.com\Gator\dyn\BannerManager#SKLLastHashDownload HKLM\Software\Gator.com\Gator\dyn\BK HKLM\Software\Gator.com\Gator\dyn\BK#GMTLastCheckTime HKLM\Software\Gator.com\Gator\dyn\EventLog HKLM\Software\Gator.com\Gator\dyn\EventLog\Msgs HKLM\Software\Gator.com\Gator\dyn\EventLog\Msgs#Next HKLM\Software\Gator.com\Gator\dyn\GCH HKLM\Software\Gator.com\Gator\dyn\GCH\BD HKLM\Software\Gator.com\Gator\dyn\GCH\BD#StartTime HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1093373784.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1093463483.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1093717777.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1094222475.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1094222681.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1094286283.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1094406704.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1094407429.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1094483534.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1094571584.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1094659477.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1095017371.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1095051209.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1095182003.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1095278060.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1095446387.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1095962672.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1096370802.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1096451545.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1096481657.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1096481777.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1096528929.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097064028.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097161512.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097234532.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097328521.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097328909.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097328909.1 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097611501.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097611610.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097779951.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097779959.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1097856622.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1098133796.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1098387371.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099048982.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099237940.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099323491.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099500869.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099500923.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099591666.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099591739.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099735175.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099736198.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1099840548.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100090736.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100177960.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100265711.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100265846.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100296230.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100296648.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100416589.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100442551.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1100727671.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101220808.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101220808.1 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101311221.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101576269.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101576634.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101826106.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101826336.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101828520.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101828521.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1101937932.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102079540.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102080424.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102150752.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102159693.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102159817.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102163348.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102265026.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102268358.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102268425.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102408450.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102509149.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102509467.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102510886.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102510891.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102513213.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102610794.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102685613.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102872715.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102872856.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1102873322.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103130331.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103182702.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103312172.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103312173.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103485028.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103485224.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103654667.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103657915.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103657951.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103658074.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103705153.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103705230.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103705232.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103705982.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103705988.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1103786852.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1104138021.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1104138023.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1104343754.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1104344148.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1104957722.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1104957815.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105102044.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105102186.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105102244.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105198126.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105254878.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105370346.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105425168.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105460200.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105532984.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105534207.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105605562.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105633282.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105633337.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105639180.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105639220.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105639356.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105639465.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105639520.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105639621.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105639925.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105705272.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105705301.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105705577.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105705859.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105705859.1 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105710792.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105711957.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105881699.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105882248.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105882251.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105882789.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105884297.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105885103.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1105889386.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106148696.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106163165.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106163350.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106164061.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106235489.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106239965.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106503879.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106510481.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106749439.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106810804.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1106814210.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107108676.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107370121.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107438590.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107438986.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107524812.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107532600.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107533404.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107625443.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107800732.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107882978.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107883302.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107952179.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1107957284.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108473032.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108497825.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108508860.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108656156.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108665360.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108665367.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108665446.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108715193.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108744655.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108745490.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108908577.0 HKLM\Software\Gator.com\Gator\dyn\GCH\BD#1108908616.0 HKLM\Software\Gator.com\Gator\dyn\GCH\EL HKLM\Software\Gator.com\Gator\dyn\GCH\EL#StartTime HKLM\Software\Gator.com\Gator\dyn\GCH\EL#1095581970.0 HKLM\Software\Gator.com\Gator\dyn\GCH\EL#1095582094.0 HKLM\Software\Gator.com\Gator\dyn\GCH\EL#1097062065.0 HKLM\Software\Gator.com\Gator\dyn\GCH\EL#1097409818.0 HKLM\Software\Gator.com\Gator\dyn\GCH\EL#1097409818.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#StartTime HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099735180.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099735181.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099735316.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099735531.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099735531.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099735532.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099735532.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099755140.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099755485.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840481.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840485.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840486.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840486.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840487.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840493.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840635.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840639.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840683.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840721.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1099840735.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100090652.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100090654.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100090655.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100090655.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100090656.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100090715.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100090716.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100097721.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100098358.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100098360.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100098360.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100099006.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100099874.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100177601.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100177603.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100177603.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100177604.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100177604.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100177676.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100179463.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100179464.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100179502.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100188231.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100188289.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100189496.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100189497.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100189542.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100190162.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100190232.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100263942.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100263943.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100263962.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100265700.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100265806.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100265808.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100265815.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100265816.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100265820.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100265847.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100265885.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100281258.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100281479.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100281485.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100281505.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100282536.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100288446.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100288837.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100288933.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100296244.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100296277.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416390.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416395.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416397.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416398.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416399.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416402.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416452.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416454.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416454.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416478.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100416527.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100424280.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100424351.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100426060.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100426119.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100426453.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100426472.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100426529.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100442577.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100727535.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100727548.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100727551.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100727557.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100727651.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100727652.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100727653.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100763366.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100763496.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100765596.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1100765698.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101220580.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101220586.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101220589.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101220591.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101220997.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101220997.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101311151.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101311166.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101311171.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101311175.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101311179.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101311210.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101311588.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101311589.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101488059.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101576244.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101576248.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101576252.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101576255.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101576258.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101576441.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101576442.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101576615.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101581331.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101589044.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101589050.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101589051.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101589076.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101589086.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101826046.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101826049.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101826050.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101826051.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101826099.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101826100.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101826109.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101828446.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101828529.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101828537.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101828592.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101828664.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101828710.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101834506.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101834542.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101845686.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101845727.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101912133.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101913857.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101913925.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101914623.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101914978.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101914979.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101914981.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101914985.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101915117.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101915133.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101915171.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101915263.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101915519.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101937941.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101937942.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101937952.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101937973.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101938145.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101971854.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101971856.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101971925.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101972787.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101975566.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101998617.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1101998621.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102079480.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102079487.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102079493.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102079497.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102079503.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102079689.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102079844.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102080139.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102080499.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102081448.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102081476.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102092021.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102092031.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102092031.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102092110.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102092113.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102092126.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102106545.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102150756.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102150762.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102150767.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102150774.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102150776.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102159594.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102159609.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102159701.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102159796.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102159841.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102163362.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102164455.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102164473.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102166194.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102166196.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102166197.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102166198.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102166203.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102166205.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102193226.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102264985.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102264987.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102264994.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102265344.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102267859.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102268168.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102401138.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102401143.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102401144.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102401144.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102401145.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102401205.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102408466.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102408770.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102498690.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102509030.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102509032.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102509034.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102509115.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102509134.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102509416.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102511387.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102511486.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102511494.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102511648.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102512886.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102512922.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102512923.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102512966.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102513134.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102610707.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102610712.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102610712.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102610712.2 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102610743.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102610745.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102610746.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102610746.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102686249.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102696606.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102696606.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102696624.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102697119.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102872666.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102872669.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102872760.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102873263.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102873264.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102873328.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1102876912.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103129960.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103129963.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103129963.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103129963.2 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103129964.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103129964.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103129964.2 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103130010.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103130015.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103130343.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103182458.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103182465.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103182467.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103182606.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103182929.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103182931.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103182932.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103182948.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103292083.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103292098.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103292098.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103292099.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103292100.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103292177.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103292177.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103379957.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103379959.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103380767.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103380770.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103386179.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103386179.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103386180.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103386182.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103386187.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103468015.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103468016.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103468189.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103468193.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103468205.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103468356.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103485018.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103485019.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103485020.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103485028.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103485069.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103485107.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103485176.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103485187.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103652300.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103652303.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103654329.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103654337.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103654494.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103654497.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103654502.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103654513.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103654689.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103654709.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103657343.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103657557.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103657582.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103657590.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103657758.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103657759.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103657924.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103657954.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103705163.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103705242.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103705442.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103706394.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103713840.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103714013.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103748730.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103748738.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103748738.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103748739.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103748739.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103786861.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103786862.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103795091.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103810691.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103810706.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103810720.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103810768.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103881236.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103881237.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103881237.1 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103881239.0 HKLM\Software\Gator.com\Gator\dyn\GCH\GBL#1103881239.1 HKLM\Software\Gator.com\Gator\dyn Lenke til kommentar
Programvare Skrevet 18. april 2007 Forfatter Del Skrevet 18. april 2007 Her er loggen for HJT Logfile of HijackThis v1.99.1 Scan saved at 20:57:02, on 18.04.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Norman\bin\ZANDA.EXE C:\WINNT\system32\nvsvc32.exe C:\Programfiler\Wireless 802.11g Monitor\WLService.exe C:\WINNT\System32\svchost.exe C:\Programfiler\Wireless 802.11g Monitor\WLanCfgG.exe C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\bin\nvcoas.exe C:\Norman\bin\NJEEVES.EXE C:\WINNT\Explorer.EXE C:\Programfiler\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe C:\Programfiler\Java\jre1.5.0_11\bin\jusched.exe C:\Programfiler\Wireless 802.11g Monitor\InfoMyCa.exe C:\WINNT\system32\LVCOMSX.EXE C:\Programfiler\Logitech\Video\LogiTray.exe C:\Norman\bin\ZLH.EXE C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe C:\Programfiler\CyberLink\PowerDVD\PDVDServ.exe C:\Programfiler\iTunes\iTunesHelper.exe C:\Norman\Nvc\bin\cclaw.exe C:\Programfiler\iPod\bin\iPodService.exe C:\WINNT\system32\ctfmon.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINNT\System32\svchost.exe C:\Programfiler\Logitech\Video\FxSvr2.exe C:\WINNT\system32\notepad.exe C:\Programfiler\Opera\Opera.exe C:\WINNT\system32\msiexec.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dagbladet.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.nextel.no/proxy.pac R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=proxy.online.no:8080;http=proxy.online.no:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programfiler\BitComet\tools\BitCometBHO_1.1.3.19.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar4.dll O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll (file missing) O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll (file missing) O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programfiler\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar4.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [anvshell] anvshell.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programfiler\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [infoMyCa.exe] C:\Programfiler\Wireless 802.11g Monitor\InfoMyCa.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programfiler\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programfiler\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programfiler\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [RemoteControl] C:\Programfiler\CyberLink\PowerDVD\PDVDServ.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe O4 - HKCU\..\Run: [RiskIISetup.exe] /r O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: Registration Ghost Recon Advanced Warfighter.LNK = C:\Programfiler\Ubisoft\Demo\Ghost Recon Advanced Warfighter Demo\Support\Register\RegistrationReminder.exe O4 - Global Startup: Date Manager.lnk = C:\Programfiler\Date Manager\DateManager.exe O4 - Global Startup: GStartup.lnk = C:\Programfiler\Fellesfiler\GMT\GMT.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Programfiler\MyWebSearch\bar\1.bin\MWSOEMON.EXE O4 - Global Startup: PC-søk i Windows.lnk = C:\Programfiler\Norsk Strek AS\MSN Toolbar Suite\DS\02.05.0000.1105\nb-no\bin\WindowsSearch.exe O4 - Global Startup: PrecisionTime.lnk = C:\Programfiler\PrecisionTime\PrecisionTime.exe O8 - Extra context menu item: &MSN Search - res://C:\Programfiler\MSN Toolbar Suite\TB\02.05.0000.1105\nb-no\msntb.dll/search.htm O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029YYNO_ZS O8 - Extra context menu item: Download all links using BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download all videos using BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: Download link using &BitComet - res://C:\Programfiler\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programfiler\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Web Rebates - file://C:\Programfiler\Web_Rebates\Sy1150\Tp1150\scri1150a.htm O8 - Extra context menu item: Åpne i ny bakgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\TAB\02.05.0000.1105\nb-no\msntabres.dll/229?66c49746326e4252b05ed7fdb2416ff O8 - Extra context menu item: Åpne i ny forgrunnsflik - res://C:\Programfiler\MSN Toolbar Suite\TAB\02.05.0000.1105\nb-no\msntabres.dll/230?66c49746326e4252b05ed7fdb2416ff O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php...d9d6f067011f31e O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.exe O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.com/images/uploader/ssi...ureUploader.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://creative.com/su/ocx/15021/CTPID.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: winstr32 - winstr32.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programfiler\iPod\bin\iPodService.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe O23 - Service: R54G Wireless Service - Unknown owner - C:\Programfiler\Wireless 802.11g Monitor\WLService.exe Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå