It will be great in the end
Hi you are my hero,m My new logs. Do seem bad still, but I am thrilled to receive some help.
"Victor" - 2007-08-09 2:11:59 [GMT 2:00] - ComboFix 07-07-24 - Service Pack 2 NTFS
Command switches used :: H:\Documents and Settings\Victor\Skrivbord\CFFIX.TXT
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
H:\WINDOWS\system32\jkhhf.exe
H:\WINDOWS\system32\erstuf.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
H:\WINDOWS\system32\dne43ea740.dat
((((((((((((((((((((((((( Files Created from 2007-07-09 to 2007-08-09 )))))))))))))))))))))))))))))))
2007-08-09 02:14 105,385 --a------ H:\WINDOWS\system32\vtstu.exe
2007-08-07 20:24 99,080 -ra------ H:\WINDOWS\system32\drivers\s116unic.sys
2007-08-07 20:24 98,696 -ra------ H:\WINDOWS\system32\drivers\s116obex.sys
2007-08-07 20:24 23,176 -ra------ H:\WINDOWS\system32\drivers\s116nd5.sys
2007-08-07 20:24 11,016 -ra------ H:\WINDOWS\system32\drivers\s116cr.sys
2007-08-07 20:24 100,488 -ra------ H:\WINDOWS\system32\drivers\s116mgmt.sys
2007-08-07 20:23 15,112 -ra------ H:\WINDOWS\system32\drivers\s116mdfl.sys
2007-08-07 20:23 12,424 -ra------ H:\WINDOWS\system32\drivers\s116cmnt.sys
2007-08-07 20:23 12,424 -ra------ H:\WINDOWS\system32\drivers\s116cm.sys
2007-08-07 20:23 108,680 -ra------ H:\WINDOWS\system32\drivers\s116mdm.sys
2007-08-07 20:08 83,336 -ra------ H:\WINDOWS\system32\drivers\s116bus.sys
2007-08-07 20:08 12,424 -ra------ H:\WINDOWS\system32\drivers\s116whnt.sys
2007-08-07 20:08 12,424 -ra------ H:\WINDOWS\system32\drivers\s116wh.sys
2007-08-06 22:20 <KAT> d-------- H:\WINDOWS\ERUNT
2007-08-06 22:03 24,576 --a------ H:\WINDOWS\system32\VundoFixSVC.exe
2007-08-06 21:21 1,132 --a------ H:\WINDOWS\mozver.dat
2007-08-06 20:27 <KAT> d-------- H:\WINDOWS\CSC
2007-08-06 20:22 131,421 --a------ H:\WINDOWS\efdeec.dll
2007-08-06 07:05 <KAT> d-------- H:\DOCUME~1\Victor\APPLIC~1\Talkback
2007-08-06 07:04 0 --a------ H:\WINDOWS\nsreg.dat
2007-08-06 07:02 131,382 --a------ H:\WINDOWS\vtrqqp.dll
2007-08-06 00:16 118,784 --a------ H:\WINDOWS\system32\MSSTDFMT.DLL
2007-08-06 00:16 <KAT> d-------- H:\Program\SpywareBlaster
2007-08-05 23:42 131,433 --a------ H:\WINDOWS\hgfgee.dll
2007-08-05 22:09 131,433 --a------ H:\WINDOWS\khijjj.dll
2007-08-05 22:06 131,433 --a------ H:\WINDOWS\byyvur.dll
2007-08-05 22:02 131,433 --a------ H:\WINDOWS\gebayw.dll
2007-08-05 21:49 131,433 --a------ H:\WINDOWS\wvvsqp.dll
2007-08-05 21:48 131,433 --a------ H:\WINDOWS\geebca.dll
2007-08-05 19:50 131,433 --a------ H:\WINDOWS\opqpmk.dll
2007-08-05 16:37 10,872 --a------ H:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-05 16:33 <KAT> d-------- H:\Program\Lavasoft
2007-08-05 16:33 <KAT> d-------- H:\Program\Delade filer\Wise Installation Wizard
2007-08-05 16:33 <KAT> d-------- H:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-05 16:18 51,200 --a------ H:\WINDOWS\nircmd.exe
2007-08-05 15:58 2,598 --a------ H:\WINDOWS\system32\tmp.reg
2007-08-05 15:56 <KAT> d-------- H:\VundoFix Backups
2007-08-05 06:15 524,288 --ah----- H:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-05 06:15 <KAT> dr------- H:\DOCUME~1\ADMINI~1\Start-meny
2007-08-05 06:15 <KAT> d--h----- H:\DOCUME~1\ADMINI~1\Skrivare
2007-08-05 06:15 <KAT> d--h----- H:\DOCUME~1\ADMINI~1\N„tverket
2007-08-05 06:15 <KAT> d--h----- H:\DOCUME~1\ADMINI~1\Mallar
2007-08-05 06:15 <KAT> d--h----- H:\DOCUME~1\ADMINI~1\Lokala inst„llningar
2007-08-05 06:15 <KAT> d-------- H:\DOCUME~1\ADMINI~1\Skrivbord
2007-08-05 06:15 <KAT> d-------- H:\DOCUME~1\ADMINI~1\Mina dokument
2007-08-05 06:15 <KAT> d-------- H:\DOCUME~1\ADMINI~1\Favoriter
2007-08-05 05:32 131,448 --a------ H:\WINDOWS\mlklii.dll
2007-08-04 23:36 13,380 --------- H:\WINDOWS\system32\vturopn.dll
2007-08-04 20:20 68,888 --a------ H:\WINDOWS\system32\xinput1_3.dll
2007-08-04 20:20 62,744 --a------ H:\WINDOWS\system32\xinput1_2.dll
2007-08-04 20:20 3,426,072 --a------ H:\WINDOWS\system32\d3dx9_32.dll
2007-08-04 20:20 255,848 --a------ H:\WINDOWS\system32\xactengine2_6.dll
2007-08-04 20:20 251,672 --a------ H:\WINDOWS\system32\xactengine2_5.dll
2007-08-04 20:20 237,848 --a------ H:\WINDOWS\system32\xactengine2_4.dll
2007-08-04 20:20 236,824 --a------ H:\WINDOWS\system32\xactengine2_3.dll
2007-08-04 20:20 2,414,360 --a------ H:\WINDOWS\system32\d3dx9_31.dll
2007-08-04 20:20 15,128 --a------ H:\WINDOWS\system32\x3daudio1_1.dll
2007-08-04 20:19 2,297,552 --a------ H:\WINDOWS\system32\d3dx9_26.dll
2007-08-04 20:09 <KAT> d--hs---- H:\WINDOWS\ftpcache
2007-08-02 23:01 <KAT> d-------- H:\DOCUME~1\Victor\APPLIC~1\GlobalSCAPE
2007-08-02 23:01 <KAT> d-------- H:\DOCUME~1\ALLUSE~1\APPLIC~1\GlobalSCAPE
2007-08-02 23:00 <KAT> d-------- H:\Program\GlobalSCAPE
2007-07-29 10:42 <KAT> d-------- H:\Program\IZArc
2007-07-28 03:00 <KAT> d-------- H:\Program\MSXML 4.0
2007-07-26 12:39 <KAT> d-------- H:\DOCUME~1\Victor\APPLIC~1\Teleca
2007-07-26 12:37 <KAT> d-------- H:\Program\Sony Ericsson
2007-07-26 12:37 <KAT> d-------- H:\Program\Delade filer\Teleca Shared
2007-07-26 12:37 <KAT> d-------- H:\Program\Delade filer\Sony Ericsson Shared
2007-07-26 12:37 <KAT> d-------- H:\DOCUME~1\Victor\APPLIC~1\Sony Ericsson
2007-07-26 12:37 <KAT> d-------- H:\DOCUME~1\ALLUSE~1\APPLIC~1\Teleca
2007-07-26 12:37 <KAT> d-------- H:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
2007-07-24 17:20 <KAT> d-------- H:\Program\Personal
2007-07-24 17:20 <KAT> d-------- H:\DOCUME~1\Victor\cbt
2007-07-24 17:20 <KAT> d-------- H:\DOCUME~1\Victor\APPLIC~1\Personal
2007-07-24 17:20 <KAT> d-------- H:\DOCUME~1\Victor\APPLIC~1\Netscape
2007-07-24 15:23 <KAT> d-------- H:\DOCUME~1\Victor\APPLIC~1\dvdcss
2007-07-24 12:59 <KAT> d-------- H:\DOCUME~1\Victor\Incomplete
2007-07-24 12:59 <KAT> d-------- H:\DOCUME~1\Victor\APPLIC~1\LimeWire
2007-07-24 12:58 <KAT> d-------- H:\Program\LimeWire
2007-07-24 11:13 2,368 --a------ H:\WINDOWS\system32\STEC3.sys
2007-07-23 18:27 <KAT> d-------- H:\Program\Spybot
2007-07-23 18:27 <KAT> d-------- H:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-07 18:35:22 -------- d-----w H:\DOCUME~1\Victor\APPLIC~1\Azureus
2007-08-04 18:19:41 -------- d--h--w H:\Program\InstallShield Installation Information
2007-07-04 20:13:01 -------- d-----w H:\Program\Azureus
2007-07-03 01:00:53 -------- d-----w H:\Program\Messenger
2007-07-02 21:36:48 -------- d-----w H:\Program\MSN Messenger
2007-07-02 20:01:19 -------- d-----w H:\Program\Delade filer\EZB Systems
2007-07-02 19:25:54 -------- d-----w H:\DOCUME~1\Victor\APPLIC~1\Help
2007-07-02 19:24:17 -------- d-----w H:\Program\Delade filer\InstallShield
2007-07-02 01:13:36 47,784 ----a-w H:\WINDOWS\system32\perfc01D.dat
2007-07-02 01:13:36 315,006 ----a-w H:\WINDOWS\system32\perfh01D.dat
2007-06-30 18:52:13 -------- d-----w H:\DOCUME~1\Victor\APPLIC~1\vlc
2007-06-30 18:47:49 -------- d-----w H:\Program\VideoLAN
2007-06-30 18:21:12 -------- d-----w H:\Program\Delade filer\ODBC
2007-06-30 18:21:08 -------- d-----w H:\Program\Delade filer\SpeechEngines
2007-06-30 17:20:48 -------- d-----w H:\Program\ASUS
2007-06-30 17:18:32 -------- d-----w H:\Program\Intel
2007-06-30 17:15:56 -------- d-----w H:\Program\Analog Devices
2007-06-30 16:33:56 -------- d-----w H:\Program\microsoft frontpage
2007-06-30 16:32:30 -------- d--h--w H:\Program\WindowsUpdate
2007-06-30 16:32:27 -------- d-----w H:\Program\Onlinetjänster
2007-06-30 16:31:23 -------- d-----w H:\Program\Delade filer\MSSoap
2007-06-30 16:31:11 -------- d-----w H:\Program\Movie Maker
2007-06-30 16:30:14 21,700 ----a-w H:\WINDOWS\system32\emptyregdb.dat
2007-06-30 16:29:48 -------- d-----w H:\Program\MSN Gaming Zone
2007-06-30 16:29:36 -------- d-----w H:\Program\Windows NT
2007-06-13 19:50:17 43,152 ----a-w H:\WINDOWS\system32\drivers\ativvpxx.vp
2007-06-13 19:25:36 339,968 ----a-w H:\WINDOWS\system32\ATIDEMGX.dll
2007-06-13 19:24:32 268,288 ----a-w H:\WINDOWS\system32\ati2dvag.dll
2007-06-13 19:24:13 2,155,520 ----a-w H:\WINDOWS\system32\drivers\ati2mtag.sys
2007-06-13 19:23:23 307,200 ----a-w H:\WINDOWS\system32\atiiiexx.dll
2007-06-13 19:17:37 139,264 ----a-w H:\WINDOWS\system32\atipdlxx.dll
2007-06-13 19:17:26 118,784 ----a-w H:\WINDOWS\system32\Oemdspif.dll
2007-06-13 19:17:18 26,112 ----a-w H:\WINDOWS\system32\Ati2mdxx.exe
2007-06-13 19:17:12 42,496 ----a-w H:\WINDOWS\system32\ati2edxx.dll
2007-06-13 19:16:59 118,784 ----a-w H:\WINDOWS\system32\ati2evxx.dll
2007-06-13 19:15:39 483,328 ----a-w H:\WINDOWS\system32\ati2evxx.exe
2007-06-13 19:14:51 53,248 ----a-w H:\WINDOWS\system32\ATIDDC.DLL
2007-06-13 19:10:33 8,097,792 ----a-w H:\WINDOWS\system32\atioglx2.dll
2007-06-13 19:07:26 2,922,208 ----a-w H:\WINDOWS\system32\ati3duag.dll
2007-06-13 18:57:21 1,512,960 ----a-w H:\WINDOWS\system32\ativvaxx.dll
2007-06-13 18:57:04 972,072 ----a-w H:\WINDOWS\system32\ativva6x.dat
2007-06-13 18:57:04 3,107,788 ----a-w H:\WINDOWS\system32\ativvaxx.dat
2007-06-13 18:57:04 3,107,788 ----a-w H:\WINDOWS\system32\ativva5x.dat
2007-06-13 18:46:28 5,431,296 ----a-w H:\WINDOWS\system32\atioglxx.dll
2007-06-13 18:43:53 262,144 ----a-w H:\WINDOWS\system32\atikvmag.dll
2007-06-13 18:42:29 17,408 ----a-w H:\WINDOWS\system32\atitvo32.dll
2007-06-13 18:41:46 49,152 ----a-w H:\WINDOWS\system32\drivers\ati2erec.dll
2007-06-13 18:41:06 50,176 ----a-w H:\WINDOWS\system32\atiok3x2.dll
2007-06-13 18:36:45 368,640 ----a-w H:\WINDOWS\system32\ati2cqag.dll
2007-06-13 12:29:00 520,192 ------w H:\WINDOWS\system32\ati2sgag.exe
2007-05-16 15:20:05 683,520 ----a-w H:\WINDOWS\system32\inetcomm.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="H:\Program\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
"PRONoMgr.exe"="H:\Program\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 16:24]
"SoundMAXPnP"="H:\Program\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 16:28]
"SoundMAX"="H:\Program\Analog Devices\SoundMAX\Smax4.exe" [2003-05-30 09:42]
"ASUS Probe"="H:\Program Files\ASUS\Probe\AsusProb.exe" [2002-12-06 16:07]
"DAEMON Tools-1033"="C:\Program\D-Tools\daemon.exe" [2004-08-22 17:05]
"SunJavaUpdateSched"="H:\Program\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Adobe Reader Speed Launcher"="H:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"Sony Ericsson PC Suite"="H:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-05-28 10:14]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="H:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:34]
H:\Documents and Settings\All Users\Start-meny\Program\Autostart\
Personal.lnk - H:\Program\Personal\bin\Personal.exe [2007-07-24 17:20:42]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\c_1iag]
c_1iag.dll 2007-08-09 02:15 92709 H:\WINDOWS\system32\c_1iag.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=h:\windows\system32\vturopn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
R0 hotcore3;hotcore3;H:\WINDOWS\system32\drivers\hotcore3.sys
R1 ISODrive;ISO DVD/CD-ROM Device Driver;\??\C:\Program\UltraISO\drivers\ISODrive.sys
R1 mnmdd;mnmdd;H:\WINDOWS\system32\drivers\mnmdd.sys
R2 aslm75;aslm75;\??\H:\WINDOWS\system32\drivers\aslm75.sys
R2 lanmanserver;Server;H:\WINDOWS\system32\svchost.exe -k netsvcs
R2 lanmanworkstation;Workstation;H:\WINDOWS\system32\svchost.exe -k netsvcs
R2 SoundMAX Agent Service (default);SoundMAX Agent Service;H:\Program\Analog Devices\SoundMAX\SMAgent.exe
R2 STEC3;STEC3;\??\H:\WINDOWS\system32\STEC3.sys
R2 winmgmt;Windows Management Instrumentation;H:\WINDOWS\system32\svchost.exe -k netsvcs
R3 E1000;Intel(R) PRO/1000 Adapter Driver;H:\WINDOWS\system32\DRIVERS\e1000325.sys
R3 wdmaud;Drivrutin f”r Microsoft WINMM WDM-ljudkompatibilitet;H:\WINDOWS\system32\drivers\wdmaud.sys
S3 MidiSyn;MidiSyn;H:\WINDOWS\system32\drivers\MidiSyn.sys
S3 mnmsrvc;NetMeeting Remote Desktop Sharing;H:\WINDOWS\system32\mnmsrvc.exe
S3 nm;Network Monitor Driver;H:\WINDOWS\system32\DRIVERS\NMnt.sys
S3 s116bus;Sony Ericsson Device 116 driver (WDM);H:\WINDOWS\system32\DRIVERS\s116bus.sys
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter;H:\WINDOWS\system32\DRIVERS\s116mdfl.sys
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver;H:\WINDOWS\system32\DRIVERS\s116mdm.sys
S3 s116mgmt;Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM);H:\WINDOWS\system32\DRIVERS\s116mgmt.sys
S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS);H:\WINDOWS\system32\DRIVERS\s116nd5.sys
S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface;H:\WINDOWS\system32\DRIVERS\s116obex.sys
S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM);H:\WINDOWS\system32\DRIVERS\s116unic.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-09 02:14:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
H:\WINDOWS\system32\c_1iag.dll
H:\WINDOWS\system32\dne43ea740.dat
scan completed successfully
hidden files: 2
**************************************************************************
Completion time: 2007-08-09 2:15:57 - machine was rebooted
H:\ComboFix-quarantined-files.txt ... 2007-08-09 02:15
H:\ComboFix2.txt ... 2007-08-07 21:15
H:\ComboFix3.txt ... 2007-08-07 20:44
--- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:17:03, on 2007-08-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
H:\Program\Grisoft\AVG Anti-Spyware 7.5\guard.exe
H:\Program\Analog Devices\SoundMAX\SMAgent.exe
H:\WINDOWS\system32\wscntfy.exe
H:\Program\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
H:\Program\Analog Devices\SoundMAX\Smax4.exe
C:\Program\D-Tools\daemon.exe
H:\Program\Java\jre1.6.0_02\bin\jusched.exe
H:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe
H:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program\Personal\bin\Personal.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\RunDll32.exe
H:\Program\Delade filer\Teleca Shared\Generic.exe
H:\Program\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
H:\WINDOWS\system32\wuauclt.exe
H:\HijackThis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {f28a74ab-0fa5-47a0-aef4-1aa86c6c80b5} - H:\WINDOWS\system32\c_1iag.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "H:\Program\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PRONoMgr.exe] H:\Program\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SoundMAXPnP] H:\Program\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "H:\Program\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ASUS Probe] H:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "H:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKCU\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Personal.lnk = H:\Program\Personal\bin\Personal.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program\Messenger\msmsgs.exe
O20 - AppInit_DLLs: h:\windows\system32\vturopn.dll
O20 - Winlogon Notify: c_1iag - H:\WINDOWS\SYSTEM32\c_1iag.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - H:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - H:\Program\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - H:\Program\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - H:\Program\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 3972 bytes