Hi,
no errors occured on ComboFix run. Here's the log:
ComboFix 08-06-01.6 - Robbani 2008-06-03 1:07:13.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1053.18.569 [GMT 3:00]
Running from: C:\Documents and Settings\Robbani\Skrivbord\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-05-02 to 2008-06-02 )))))))))))))))))))))))))))))))
.
2008-06-01 16:49 . 2008-06-01 16:49 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-01 16:48 . 2008-06-01 16:48 <KAT> d-------- C:\Program\Delade filer\Wise Installation Wizard
2008-06-01 16:33 . 2008-06-01 16:33 <KAT> d-------- C:\Documents and Settings\Robbani\Application Data\Lavasoft
2008-05-31 00:34 . 2008-05-31 00:34 12,371 --a------ C:\is154890.exe
2008-05-29 23:01 . 2008-05-29 23:01 <KAT> d--h----- C:\$AVG8.VAULT$
2008-05-20 18:35 . 2008-05-20 18:31 1,572 --a------ C:\PlexTools Professional XL.lnk
2008-05-20 18:33 . 2008-05-20 18:33 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\element5
2008-05-20 18:32 . 2008-05-20 18:32 <KAT> d-------- C:\Program\Delade filer\element5 Shared
2008-05-20 16:02 . 2008-05-20 16:02 <KAT> d-------- C:\Program\CDBurnerXP
2008-05-20 15:47 . 2008-05-20 15:47 <KAT> d-------- C:\Documents and Settings\Robbani\Application Data\Publish Providers
2008-05-20 15:43 . 2008-05-20 15:43 <KAT> d-------- C:\Documents and Settings\Robbani\Application Data\Sony
2008-05-20 15:40 . 2008-05-20 15:40 <KAT> d-------- C:\Program\Sony
2008-05-20 15:39 . 2008-05-20 15:39 <KAT> d-------- C:\Program\Sony Setup
2008-05-20 14:16 . 2008-05-20 14:16 <KAT> d-------- C:\Documents and Settings\Robbani\Application Data\CDBurnerXP_Soft
2008-05-20 14:12 . 2008-05-20 14:12 0 --a------ C:\WINDOWS\Irremote.ini
2008-05-20 13:58 . 2008-05-20 13:58 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-05-20 13:43 . 2008-05-20 13:43 <KAT> d-------- C:\Documents and Settings\Robbani\Application Data\Nero
2008-05-20 13:41 . 2008-05-20 13:41 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-05-19 19:19 . 2008-05-19 19:19 952 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-05-16 13:59 . 2008-05-16 13:59 <KAT> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-16 13:59 . 2008-05-16 13:59 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-16 13:59 . 2008-05-16 13:59 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-16 13:59 . 2008-05-16 13:59 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-05-16 13:59 . 2008-05-16 13:59 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-16 12:39 . 2008-05-16 12:39 <KAT> d-------- C:\Program\AVG
2008-05-16 12:26 . 2008-05-16 12:26 <KAT> d-------- C:\Program\Antivirus
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
2008-05-13 15:05 . 2004-08-04 05:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-05-13 13:27 . 2007-03-08 02:51 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-05-13 13:27 . 2007-03-08 02:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-05-13 13:27 . 2007-03-08 02:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-05-05 22:04 . 2008-05-05 22:04 <KAT> d-------- C:\Program\Alcohol Soft
2008-05-03 22:59 . 2008-06-03 01:08 12 --a------ C:\WINDOWS\bthservsdp.dat
2008-05-03 13:02 . 2004-08-04 05:00 274,304 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-05-03 13:02 . 2004-08-04 05:00 274,304 --a------ C:\WINDOWS\system32\dllcache\bthport.sys
2008-05-03 13:02 . 2004-08-04 05:00 100,992 --a------ C:\WINDOWS\system32\drivers\bthpan.sys
2008-05-03 13:02 . 2004-08-04 05:00 100,992 --a------ C:\WINDOWS\system32\dllcache\bthpan.sys
2008-05-03 13:02 . 2004-08-04 05:00 59,648 --a------ C:\WINDOWS\system32\drivers\rfcomm.sys
2008-05-03 13:02 . 2004-08-04 05:00 59,648 --a------ C:\WINDOWS\system32\dllcache\rfcomm.sys
2008-05-03 13:02 . 2004-08-04 05:00 18,944 --a------ C:\WINDOWS\system32\drivers\BTHUSB.SYS
2008-05-03 13:02 . 2004-08-04 05:00 18,944 --a------ C:\WINDOWS\system32\dllcache\bthusb.sys
2008-05-03 13:02 . 2004-08-04 05:00 17,024 --a------ C:\WINDOWS\system32\drivers\BthEnum.sys
2008-05-03 13:02 . 2004-08-04 05:00 17,024 --a------ C:\WINDOWS\system32\dllcache\bthenum.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-29 18:41 --------- d-----w C:\Documents and Settings\Robbani\Application Data\vlc
2008-04-29 08:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 08:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 08:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-21 22:57 --------- d-----w C:\Program\Java
2008-04-21 22:56 --------- d-----w C:\Program\Delade filer\Java
2008-04-19 19:28 --------- d-----w C:\Documents and Settings\Robbani\Application Data\Samsung
2008-04-17 10:52 5,632 ----a-w C:\WINDOWS\system32\drivers\StarOpen.sys
2008-04-17 10:43 --------- d-----w C:\Program\Samsung
2008-04-16 12:04 --------- d-----w C:\Program\Microsoft Works
2008-04-16 12:03 --------- d-----w C:\Program\Microsoft.NET
2008-04-16 12:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-16 11:05 --------- d-----w C:\Documents and Settings\Robbani\Application Data\DAEMON Tools
2008-04-16 10:45 --------- d-----w C:\Documents and Settings\Robbani\Application Data\AdobeUM
2008-04-16 10:38 --------- d-----w C:\Program\Delade filer\Adobe
2008-04-16 03:44 --------- d-----w C:\Program\Registry Genius
2008-04-16 03:17 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-04-16 03:03 --------- d-----w C:\Program\Codec Pack - All In 1
2008-04-16 03:02 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-04-16 02:52 --------- d-----w C:\Documents and Settings\Robbani\Application Data\{27ABEAD9-B7C4-4994-891F-48F5F48861FA}
2008-04-16 02:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-04-16 02:27 --------- d-----w C:\Program\Delade filer\Corel
2008-04-16 02:27 --------- d-----w C:\Program\Corel
2008-04-16 02:27 --------- d-----w C:\Documents and Settings\Robbani\Application Data\Corel
2008-04-16 01:20 107,134 ----a-w C:\WINDOWS\UninstallFirefox.exe
2008-04-16 01:17 --------- d-----w C:\Program\Firefox
2008-04-16 01:11 --------- d-----w C:\Documents and Settings\Robbani\Application Data\CyberLink
2008-04-16 00:56 --------- d-----w C:\Program\Canon
2008-04-16 00:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Canon
2008-04-16 00:01 --------- d-----w C:\Program\MSXML 4.0
2008-04-15 20:26 --------- d-----w C:\Program\Microsoft SQL Server Compact Edition
2008-04-15 20:15 --------- d-sh--w C:\Program\Delade filer\WindowsLiveInstaller
2008-04-15 20:15 --------- d-----w C:\Program\Windows Live
2008-04-15 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-15 20:02 --------- d-----w C:\Program\MSN Apps
2008-04-15 19:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-04-15 19:25 --------- d-----w C:\Program\acer
2008-04-15 19:23 17,119 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-04-15 19:21 --------- d-----w C:\Program\WinPCap
2008-04-15 19:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-04-15 19:20 --------- d-----w C:\Program\ATI Technologies
2008-03-25 04:52 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:52 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
2008-03-25 04:52 162,592 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 04:52 162,592 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-20 08:10 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:10 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MsnMsgr"="C:\Program\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:35 5724184]
"AlcoholAutomount"="C:\Program\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-02-22 18:58 217544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-07 19:36 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-07 19:32 126976]
"SynTPLpr"="C:\Program\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 23:44 98394]
"SynTPEnh"="C:\Program\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 23:43 688218]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"ATIPTA"="C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-08 21:05 339968]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-03-28 18:04 188416]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [2005-03-24 09:13 2880512]
"eRecoveryService"="C:\Windows\System32\Check.exe" [2005-03-23 10:01 245760]
"PWRISOVM.EXE"="D:\Program\PowerISO\PWRISOVM.EXE" [2008-03-15 02:50 233472]
"SunJavaUpdateSched"="C:\Program\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"AVG8_TRAY"="C:\Program\AVG\AVG8\avgtray.exe" [2008-05-16 13:59 1177368]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program\\Messenger\\msmsgs.exe"=
"C:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program\\Torrent Storm\\Downloader\\Tor032\\tor032.exe"=
"C:\\Program\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program\\AVG\\AVG8\\avgnsx.exe"=
"C:\\Program\\Firefox\\firefox.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-05-16 13:59]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-16 13:59]
R2 avg8emc;AVG8 E-mail Scanner;C:\Program\AVG\AVG8\avgemc.exe [2008-05-16 13:59]
R2 avg8wd;AVG8 WatchDog;C:\Program\AVG\AVG8\avgwdsvc.exe [2008-05-16 13:59]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-16 13:59]
R2 cis1284;cis1284;C:\WINDOWS\system32\drivers\cis1284.sys [2001-09-03 11:02]
R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 13:10]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-03-24 16:54]
R2 NMSAccessU;NMSAccessU;C:\Program\CDBurnerXP\NMSAccessU.exe [2008-03-09 11:20]
R3 int15.sys;int15.sys;C:\Program\acer\eRecovery\int15.sys [2005-01-13 14:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1df50c70-2e90-11dd-b1b8-00c09fdcb5b7}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-03 01:10:34
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\PROGRAM\INTEL\WIRELESS\BIN\EVTENG.EXE
C:\PROGRAM\INTEL\WIRELESS\BIN\S24EVMON.EXE
C:\PROGRAM\ANTIVIRUS\AD-AWARE\AAWSERVICE.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\Acer\eManager\anbmServ.exe
C:\Program\AVG\AVG8\avgam.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\AVG\AVG8\avgnsx.exe
C:\PROGRAM\INTEL\WIRELESS\BIN\REGSRVC.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program\acer\eRecovery\Monitor.exe
C:\Program\AVG\AVG8\avgrsx.exe
C:\Program\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-06-03 1:12:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-02 22:12:02
Pre-Run: 9,566,912,512 byte ledigt
Post-Run: 9,496,805,376 byte ledigt
201 --- E O F --- 2008-05-29 12:20:28
Malware-log:
Malwarebytes' Anti-Malware 1.14
Databasversion: 815
02:38:09 2008-06-03
mbam-log-6-3-2008 (02-38-09).txt
Skanningstyp: Fullständig skanning (C:\|D:\|M:\|)
Antal skannade objekt: 102789
Förfluten tid: 1 hour(s), 14 minute(s), 53 second(s)
Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 0
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 4
Infekterade minnesprocesser:
(Inga illasinnade poster hittades)
Infekterade minnesmoduler:
(Inga illasinnade poster hittades)
Infekterade registernycklar:
(Inga illasinnade poster hittades)
Infekterade registervärden:
(Inga illasinnade poster hittades)
Infekterade registerdataposter:
(Inga illasinnade poster hittades)
Infekterade mappar:
(Inga illasinnade poster hittades)
Infekterade filer:
C:\System Volume Information\_restore{C657EDC9-34A1-4ECA-ABE3-5B715D06C4E9}\RP92\A0014602.dll (Spyware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C657EDC9-34A1-4ECA-ABE3-5B715D06C4E9}\RP92\A0014604.dll (Spyware.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\packet.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\wpcap.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully.
Hijack log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:39:58, on 2008-06-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Intel\Wireless\Bin\EvtEng.exe
C:\Program\Intel\Wireless\Bin\S24EvMon.exe
C:\Program\Antivirus\Ad-aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program\Synaptics\SynTP\SynTPLpr.exe
C:\Program\AVG\AVG8\avgwdsvc.exe
C:\Program\Synaptics\SynTP\SynTPEnh.exe
C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\acer\epm\epm-dm.exe
D:\Program\PowerISO\PWRISOVM.EXE
C:\Program\Java\jre1.6.0_05\bin\jusched.exe
C:\Program\AVG\AVG8\avgam.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\AVG\AVG8\avgnsx.exe
C:\Program\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\CDBurnerXP\NMSAccessU.exe
C:\Program\Intel\Wireless\Bin\RegSrvc.exe
C:\Program\AVG\AVG8\avgemc.exe
C:\Program\Windows Live\Messenger\MsnMsgr.Exe
C:\Program\acer\eRecovery\Monitor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program\AVG\AVG8\avgrsx.exe
C:\Program\AVG\AVG8\avgrsx.exe
C:\Program\Firefox\firefox.exe
C:\Program\Antivirus\Hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.kvevlaxsb.fi/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program\MSN Apps\MSN Toolbar1.02.5000.1021\sv\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program\MSN Apps\MSN Toolbar1.02.5000.1021\sv\msntb.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AVG8_TRAY] C:\Program\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Program\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blogga detta - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blogga detta i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program\Antivirus\Ad-aware\aawservice.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program\AVG\AVG8\avgwdsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: MpService - Canon Inc - C:\Program\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: NMSAccessU - Unknown owner - C:\Program\CDBurnerXP\NMSAccessU.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program\Intel\Wireless\Bin\S24EvMon.exe
--
End of file - 7483 bytes