ComboFix 08-09-24.11 - Christer 2008-10-05 9:39:19.8 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1044.18.583 [GMT 2:00] Running from: C:\Documents and Settings\Christer\Skrivebord\ComboFix.exe [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . - REDUCED FUNCTIONALITY MODE - . ((((((((((((((((((((((((( Files Created from 2008-09-05 to 2008-10-05 ))))))))))))))))))))))))))))))) . 2008-09-24 21:13 . 2008-09-24 21:13 d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-09-24 20:55 . 2008-09-25 15:49 dr-h----- C:\Documents and Settings\Christer\Siste 2008-09-22 19:25 . 2008-09-22 19:25 d-------- C:\NEW 2008-09-20 22:37 . 2008-09-20 22:37 d-------- C:\Documents and Settings\Christer\Programdata\Ashampoo 2008-09-20 22:33 . 2008-09-20 22:33 d-------- C:\Documents and Settings\All Users\Programdata\ashampoo 2008-09-19 16:45 . 2008-09-19 16:55 d-------- C:\Nexon 2008-09-19 16:45 . 2008-09-19 16:45 d-------- C:\Documents and Settings\All Users\Programdata\NexonUS 2008-09-16 17:27 . 2008-09-16 17:30 565 --ah----- C:\WINDOWS\system32\ws341274.ocx 2008-09-16 17:27 . 2008-09-16 17:30 565 --ah----- C:\os501435.bin 2008-09-16 17:21 . 2008-09-16 17:21 d-------- C:\WINDOWS\Vbox 2008-09-16 17:21 . 2008-09-16 19:34 d-------- C:\DfW5Trial 2008-09-15 18:21 . 2008-09-15 18:21 d--h----- C:\WINDOWS\PIF 2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\system32\no 2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\system32\bits 2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\l2schemas 2008-09-12 22:42 . 2008-09-12 22:46 d-------- C:\WINDOWS\ServicePackFiles 2008-09-12 22:34 . 2008-09-12 22:34 d-------- C:\WINDOWS\EHome 2008-09-12 17:25 . 2004-08-04 00:54 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys 2008-09-12 16:31 . 2008-09-12 16:33 d-------- C:\Programfiler\CamStudio 2008-09-11 17:08 . 2008-09-11 17:10 d-------- C:\Programfiler\Malwarebytes' Anti-Malware 2008-09-11 17:08 . 2008-09-11 17:08 d-------- C:\Documents and Settings\Christer\Programdata\Malwarebytes 2008-09-11 17:08 . 2008-09-11 17:08 d-------- C:\Documents and Settings\All Users\Programdata\Malwarebytes 2008-09-11 17:08 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-09-11 17:08 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-09-10 22:13 . 2008-09-10 22:13 118 --a------ C:\WINDOWS\system32\MRT.INI 2008-09-09 21:02 . 2008-09-09 21:02 d-------- C:\Programfiler\Lavasoft 2008-09-09 21:02 . 2008-09-09 21:03 d-------- C:\Documents and Settings\All Users\Programdata\Lavasoft 2008-09-09 20:54 . 2008-09-09 20:54 268 --ah----- C:\sqmdata02.sqm 2008-09-09 20:54 . 2008-09-09 20:54 244 --ah----- C:\sqmnoopt02.sqm 2008-09-09 20:48 . 2008-09-09 20:48 268 --ah----- C:\sqmdata01.sqm 2008-09-09 20:48 . 2008-09-09 20:48 244 --ah----- C:\sqmnoopt01.sqm 2008-09-09 20:38 . 2008-09-09 20:38 d-------- C:\Documents and Settings\Reidun\Programdata\Nero 2008-09-08 17:24 . 2008-09-08 17:24 d-------- C:\Programfiler\NCH Software 2008-09-08 17:24 . 2008-09-08 17:24 d-------- C:\Documents and Settings\All Users\Programdata\NCH Software 2008-09-06 16:36 . 2008-09-22 18:30 d-------- C:\Documents and Settings\Christer\Programdata\BitTorrent 2008-09-06 16:35 . 2008-09-18 14:25 d-------- C:\Programfiler\DNA 2008-09-06 16:35 . 2008-09-06 16:35 d-------- C:\Programfiler\BitTorrent 2008-09-06 16:35 . 2008-09-25 21:32 d-------- C:\Documents and Settings\Christer\Programdata\DNA 2008-09-06 16:15 . 2008-09-15 20:14 d-------- C:\Programfiler\Ahead 2008-09-06 15:37 . 2008-09-06 16:40 d-------- C:\Programfiler\FrostWire 2008-09-06 15:37 . 2008-09-06 16:41 d-------- C:\Documents and Settings\Christer\Programdata\FrostWire . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-05 07:34 --------- d-----w C:\Programfiler\LogMeIn 2008-09-26 12:38 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec 2008-09-25 16:29 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared 2008-09-22 19:33 --------- d-----w C:\Programfiler\Dl_cats 2008-09-22 16:42 --------- d-----w C:\Documents and Settings\All Users\Programdata\DVD Shrink 2008-09-10 20:11 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help 2008-09-09 14:03 --------- d-----w C:\Documents and Settings\Christer\Programdata\dvdcss 2008-09-06 14:17 --------- d-----w C:\Programfiler\Fellesfiler\Nero 2008-09-02 12:56 --------- d-----w C:\Programfiler\Microsoft Silverlight 2008-09-02 12:44 --------- d--h--w C:\Programfiler\InstallShield Installation Information 2008-09-01 18:44 --------- d-----w C:\Programfiler\Cyanide 2008-09-01 18:41 --------- d-----w C:\Programfiler\Screamer Radio 2008-09-01 18:40 --------- d-----w C:\Programfiler\Yahoo! 2008-09-01 18:32 --------- d-----w C:\Programfiler\OpenOffice.org 2.3 2008-09-01 18:30 --------- d-----w C:\Documents and Settings\Christer\Programdata\OpenOffice.org2 2008-09-01 18:21 --------- d-----w C:\Programfiler\JLC's Software 2008-09-01 18:19 --------- d-----w C:\Programfiler\Gekko Mahjongg (Xmas edition) 2008-09-01 18:19 --------- d-----w C:\Programfiler\EA SPORTS 2008-09-01 18:18 --------- d-----w C:\Programfiler\AviSynth 2.5 2008-09-01 15:30 --------- d-----w C:\Documents and Settings\Tore\Programdata\OpenOffice.org2 2008-08-30 09:32 --------- d-----w C:\Programfiler\LimeWire 2008-08-30 09:32 --------- d-----w C:\Documents and Settings\Christer\Programdata\LimeWire 2008-08-30 09:15 --------- d-----w C:\Programfiler\Java 2008-08-29 17:04 --------- d-----w C:\Documents and Settings\Christer\Programdata\Azureus 2008-08-29 16:48 --------- d-----w C:\Documents and Settings\All Users\Programdata\Azureus 2008-08-27 19:24 --------- d-----w C:\Documents and Settings\Christer\Programdata\Xilisoft Corporation 2008-08-25 18:18 --------- d-----w C:\Programfiler\GeoGebra 2008-08-25 18:16 --------- d--h--w C:\Programfiler\Zero G Registry 2008-08-25 15:06 --------- d-----w C:\Programfiler\Handbrake 2008-08-25 15:05 --------- d-----w C:\Programfiler\NCH Swift Sound 2008-08-25 15:04 --------- d-----w C:\Programfiler\Elaborate Bytes 2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll 2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll 2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe 2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe 2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll 2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll 2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll 2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll 2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll 2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll 2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll 2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll 2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll 2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll 2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll 2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll 2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll 2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll 2008-07-07 20:29 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll 2007-12-17 08:35 60,968 ----a-w C:\Documents and Settings\Christer\GoToAssistDownloadHelper.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360] "MsnMsgr"="C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "swg"="C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-02 68856] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872] "WMPNSCFG"="C:\Programfiler\Windows Media Player\WMPNSCFG.exe" [2006-11-15 204288] "BitTorrent DNA"="C:\Programfiler\DNA\btdna.exe" [2008-09-18 289088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "ATIPTA"="C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064] "DVDLauncher"="C:\Programfiler\filer\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248] "DMXLauncher"="C:\Programfiler\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016] "ISUSPM Startup"="C:\PROGRA~1\FELLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184] "ISUSScheduler"="C:\Programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" [2004-07-27 81920] "DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 69632] "dlccmon.exe"="C:\Programfiler\Dell Photo AIO Printer 924\dlccmon.exe" [2005-07-22 425984] "ecc"="C:\Programfiler\Telenor\ecc\ecc.exe" [2005-12-14 286720] "LogMeIn GUI"="C:\Programfiler\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048] "CamMonitor"="C:\Programfiler\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 90112] "Share-to-Web Namespace Daemon"="C:\Programfiler\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 122941] "ccApp"="C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe" [2007-01-09 115816] "osCheck"="C:\Programfiler\Norton Internet Security\osCheck.exe" [2006-10-16 26248] "NBKeyScan"="C:\Programfiler\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160] "Adobe Reader Speed Launcher"="C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "AppleSyncNotifier"="C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040] "QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2008-05-27 413696] "iTunesHelper"="C:\Programfiler\iTunes\iTunesHelper.exe" [2008-07-30 289064] "Symantec PIF AlertEng"="C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 C:\WINDOWS\stsystra.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360] C:\Documents and Settings\Tore\Start-meny\Programmer\Oppstart\ OneNote 2007 Screen Clipper og Launcher.lnk - C:\Programfiler\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] C:\Documents and Settings\Christer\Start-meny\Programmer\Oppstart\ OneNote 2007 Screen Clipper og Launcher.lnk - C:\Programfiler\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2007-12-17 10:35 10792 C:\Programfiler\Citrix\GoToAssist\480\g2awinlogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] 2008-05-28 12:32 87352 C:\WINDOWS\system32\LMIinit.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "MSACM.CEGSM"= mobilev.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programfiler\\BitTorrent\\bittorrent.exe"= "C:\\Programfiler\\EA GAMES\\Battlefield 2\\BF2.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Programfiler\\Messenger\\msmsgs.exe"= "C:\\Programfiler\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Programfiler\\Bonjour\\mDNSResponder.exe"= "C:\\Programfiler\\iTunes\\iTunes.exe"= "C:\\Programfiler\\DNA\\btdna.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"= "C:\\Documents and Settings\\All Users\\Programdata\\NexonUS\\NGM\\NGM.exe"= R2 Automatisk LiveUpdate-planlegging;Automatisk LiveUpdate-planlegging;C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-10-16 198336] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Programfiler\LogMeIn\x86\RaInfo.sys [2008-02-28 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-03-07 45848] S3 Boonty Games;Boonty Games;C:\Programfiler\Fellesfiler\BOONTY Shared\Service\Boonty.exe [2007-03-09 69120] S3 GoToAssist;GoToAssist;C:\Programfiler\Citrix\GoToAssist\480\g2aservice.exe Start=service [ ] S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2008-07-22 32000] S3 w550bus;Sony Ericsson W550 driver (WDM);C:\WINDOWS\system32\DRIVERS\w550bus.sys [ ] S3 w550mdfl;Sony Ericsson W550 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w550mdfl.sys [ ] S3 w550mdm;Sony Ericsson W550 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\w550mdm.sys [ ] S3 w550mgmt;Sony Ericsson W550 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\w550mgmt.sys [ ] S3 w550obex;Sony Ericsson W550 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\w550obex.sys [ ] *Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder . . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.online.no/ R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore R1 -: HKCU-Internet Settings,ProxyOverride = *.local R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s O8 -: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O16 -: {358DFA15-D48C-4296-8D16-7405F918333B} - hxxps://fronter.com/fredrikstadgs/links/fronter_oes2.cab C:\WINDOWS\Downloaded Program Files\fronter_oes2.inf C:\WINDOWS\Downloaded Program Files\Fronter_oes_prj.ocx C:\WINDOWS\Downloaded Program Files\fronter_oes2.exe C:\WINDOWS\Downloaded Program Files\fronter_oes2.dll O16 -: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} - hxxp://www.mpw.no/TvNorge/KooPlayer.ocx C:\WINDOWS\Downloaded Program Files\KooPlayer.ocx . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-10-05 09:42:51 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCCCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\agp440] "ImagePath"="\SystemRoot\system32\DRIVERS\agp440.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\agpCPQ] "ImagePath"="\SystemRoot\system32\DRIVERS\agpCPQ.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Aha154x] "ImagePath"="\SystemRoot\system32\DRIVERS\aha154x.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78u2] "ImagePath"="\SystemRoot\system32\DRIVERS\aic78u2.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78xx] "ImagePath"="\SystemRoot\system32\DRIVERS\aic78xx.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Alerter] "ServiceDll"="%SystemRoot%\system32\alrsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALG] "ImagePath"="%SystemRoot%\System32\alg.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AliIde] "ImagePath"="\SystemRoot\system32\DRIVERS\aliide.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\alim1541] "ImagePath"="\SystemRoot\system32\DRIVERS\alim1541.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\amdagp] "ImagePath"="\SystemRoot\system32\DRIVERS\amdagp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\amsint] "ImagePath"="\SystemRoot\system32\DRIVERS\amsint.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Apple Mobile Device] "ImagePath"="\"C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppMgmt] "ServiceDll"="%SystemRoot%\System32\appmgmts.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc] "ImagePath"="\SystemRoot\system32\DRIVERS\asc.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3350p] "ImagePath"="\SystemRoot\system32\DRIVERS\asc3350p.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3550] "ImagePath"="\SystemRoot\system32\DRIVERS\asc3550.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_1.1.4322] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_2.0.50727] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Aspi32] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aspnet_state] "ImagePath"="%SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AsyncMac] "ImagePath"="system32\DRIVERS\asyncmac.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\atapi] "ImagePath"="system32\DRIVERS\atapi.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atdisk] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ati HotKey Poller] "ImagePath"="%SystemRoot%\system32\Ati2evxx.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ATI Smart] "ImagePath"="C:\WINDOWS\system32\ati2sgag.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ati2mtag] "ImagePath"="system32\DRIVERS\ati2mtag.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atierecord] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atmarpc] "ImagePath"="system32\DRIVERS\atmarpc.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv] "ServiceDll"="%SystemRoot%\System32\audiosrv.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\audstub] "ImagePath"="system32\DRIVERS\audstub.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Automatisk LiveUpdate-planlegging] "ImagePath"="\"C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BattC] "MofImagePath"="System32\Drivers\battc.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Beep] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BITS] "ServiceDll"="%systemroot%\system32\qmgr.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Bonjour Service] "ImagePath"="C:\Programfiler\Bonjour\mDNSResponder.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Boonty Games] "ImagePath"="\"C:\Programfiler\Fellesfiler\BOONTY Shared\Service\Boonty.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Browser] "ServiceDll"="%SystemRoot%\System32\browser.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme] "ImagePath"="\??\C:\ComboFix\catchme.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cbidf] "ImagePath"="\SystemRoot\system32\DRIVERS\cbidf2k.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cbidf2k] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr] "ImagePath"="\"C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe\" /h ccCommon" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccSetMgr] "ImagePath"="\"C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe\" /h ccCommon" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cd20xrnt] "ImagePath"="\SystemRoot\system32\DRIVERS\cd20xrnt.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdaudio] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdrom] "ImagePath"="system32\DRIVERS\cdrom.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Changer] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CiSvc] "ImagePath"="%SystemRoot%\system32\cisvc.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ClipSrv] "ImagePath"="%SystemRoot%\system32\clipsrv.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\clr_optimization_v2.0.50727_32] "ImagePath"="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CLTNetCnService] "ImagePath"="\"C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe\" /h ccCommon" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmdIde] "ImagePath"="\SystemRoot\system32\DRIVERS\cmdide.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\comHost] "ImagePath"="\"C:\Programfiler\Fellesfiler\Symantec Shared\VAScanner\comHost.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\COMSysApp] "ImagePath"="C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentFilter] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentIndex] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cpqarray] "ImagePath"="\SystemRoot\system32\DRIVERS\cpqarray.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CryptSvc] "ServiceDll"="%SystemRoot%\System32\cryptsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac2w2k] "ImagePath"="\SystemRoot\system32\DRIVERS\dac2w2k.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac960nt] "ImagePath"="\SystemRoot\system32\DRIVERS\dac960nt.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DcomLaunch] "ServiceDll"="%SystemRoot%\system32\rpcss.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dhcp] "ServiceDll"="%SystemRoot%\System32\dhcpcsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Disk] "ImagePath"="system32\DRIVERS\disk.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dlcc_device] "ImagePath"="C:\WINDOWS\system32\dlcccoms.exe -service" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmadmin] "ImagePath"="%SystemRoot%\System32\dmadmin.exe /com" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmboot] "ImagePath"="System32\drivers\dmboot.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmio] "ImagePath"="System32\drivers\dmio.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmload] "ImagePath"="System32\drivers\dmload.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmserver] "ServiceDll"="%SystemRoot%\System32\dmserver.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DMusic] "ImagePath"="system32\drivers\DMusic.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dnscache] "ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dot3svc] "ServiceDll"="%SystemRoot%\System32\dot3svc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dpti2o] "ImagePath"="\SystemRoot\system32\DRIVERS\dpti2o.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drmkaud] "ImagePath"="system32\drivers\drmkaud.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drvmcdb] "ImagePath"="system32\drivers\drvmcdb.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drvncdb] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drvnddm] "ImagePath"="system32\drivers\drvnddm.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\E100B] "ImagePath"="system32\DRIVERS\e100b325.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EagleNT] "ImagePath"="\??\C:\WINDOWS\system32\drivers\EagleNT.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EapHost] "ServiceDll"="%SystemRoot%\System32\eapsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eeCtrl] "ImagePath"="\??\C:\Programfiler\Fellesfiler\Symantec Shared\EENGINE\eeCtrl.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EL90XBC] "ImagePath"="system32\DRIVERS\el90xbc5.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EraserUtilRebootDrv] "ImagePath"="\??\C:\Programfiler\Fellesfiler\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ERSvc] "ServiceDll"="%SystemRoot%\System32\ersvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog] "ImagePath"="%SystemRoot%\system32\services.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EventSystem] "ServiceDll"="C:\WINDOWS\system32\es.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fastfat] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FastUserSwitchingCompatibility] "ServiceDll"="%SystemRoot%\System32\shsvcs.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fax] "ImagePath"="%systemroot%\system32\fxssvc.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fdc] "ImagePath"="system32\DRIVERS\fdc.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fips] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Flpydisk] "ImagePath"="system32\DRIVERS\flpydisk.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FltMgr] "ImagePath"="system32\drivers\fltmgr.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fs_Rec] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ftdisk] "ImagePath"="system32\DRIVERS\ftdisk.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GEARAspiWDM] "ImagePath"="System32\Drivers\GEARAspiWDM.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GoToAssist] "ImagePath"="\"C:\Programfiler\Citrix\GoToAssist\480\g2aservice.exe\" Start=service" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Gpc] "ImagePath"="system32\DRIVERS\msgpc.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\grmnusb] "ImagePath"="system32\drivers\grmnusb.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gusvc] "ImagePath"="\"C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HDAudBus] "ImagePath"="system32\DRIVERS\HDAudBus.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\helpsvc] "ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ] "ServiceDll"="%SystemRoot%\System32\hidserv.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidUsb] "ImagePath"="system32\DRIVERS\hidusb.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hkmsvc] "ServiceDll"="%SystemRoot%\System32\kmsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpn] "ImagePath"="\SystemRoot\system32\DRIVERS\hpn.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTP] "ImagePath"="System32\Drivers\HTTP.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter] "ServiceDll"="%SystemRoot%\System32\w3ssl.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omgmt] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omp] "ImagePath"="\SystemRoot\system32\DRIVERS\i2omp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt] "ImagePath"="system32\DRIVERS\i8042prt.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IDriverT] "ImagePath"="\"C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ILADFtmi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Imapi] "ImagePath"="system32\DRIVERS\imapi.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ImapiService] "ImagePath"="%systemroot%\system32\imapi.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\inetaccs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ini910u] "ImagePath"="\SystemRoot\system32\DRIVERS\ini910u.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Inport] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntelIde] "ImagePath"="\SystemRoot\system32\DRIVERS\intelide.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\intelppm] "ImagePath"="system32\DRIVERS\intelppm.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ip6Fw] "ImagePath"="system32\drivers\ip6fw.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpFilterDriver] "ImagePath"="system32\DRIVERS\ipfltdrv.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpInIp] "ImagePath"="system32\DRIVERS\ipinip.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpNat] "ImagePath"="system32\DRIVERS\ipnat.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iPod Service] "ImagePath"="C:\Programfiler\iPod\bin\iPodService.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IPSec] "ImagePath"="system32\DRIVERS\ipsec.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IRENUM] "ImagePath"="system32\DRIVERS\irenum.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISAPISearch] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\isapnp] "ImagePath"="system32\DRIVERS\isapnp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISPwdSvc] "ImagePath"="\"C:\Programfiler\Norton Internet Security\isPwdSvc.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Kbdclass] "ImagePath"="system32\DRIVERS\kbdclass.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbdhid] "ImagePath"="system32\DRIVERS\kbdhid.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kmixer] "ImagePath"="system32\drivers\kmixer.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KSecDD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanserver] "ServiceDll"="%SystemRoot%\System32\srvsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanworkstation] "ServiceDll"="%SystemRoot%\System32\wkssvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lbrtfdc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ldap] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LicenseService] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LiveUpdate] "ImagePath"="\"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LiveUpdate Notice Ex] "ImagePath"="\"C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe\" /h ccCommon" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LiveUpdate Notice Service] "ImagePath"="\"C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe\" /m \"C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LmHosts] "ServiceDll"="%SystemRoot%\System32\lmhsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LMIInfo] "ImagePath"="\??\C:\Programfiler\LogMeIn\x86\RaInfo.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LMIMaint] "ImagePath"="\"C:\Programfiler\LogMeIn\x86\RaMaint.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LMImirr] "ImagePath"="system32\DRIVERS\LMImirr.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LMIRfsClientNP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LMIRfsDriver] "ImagePath"="\??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LogMeIn] "ImagePath"="\"C:\Programfiler\LogMeIn\x86\LogMeIn.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MDM] "ImagePath"="\"C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Messenger] "ServiceDll"="%SystemRoot%\System32\msgsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmdd] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmsrvc] "ImagePath"="C:\WINDOWS\system32\mnmsrvc.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Modem] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mouclass] "ImagePath"="system32\DRIVERS\mouclass.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mouhid] "ImagePath"="system32\DRIVERS\mouhid.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MountMgr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mraid35x] "ImagePath"="\SystemRoot\system32\DRIVERS\mraid35x.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxDAV] "ImagePath"="system32\DRIVERS\mrxdav.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxSmb] "ImagePath"="system32\DRIVERS\mrxsmb.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSDTC] "ImagePath"="C:\WINDOWS\system32\msdtc.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Msfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSIServer] "ImagePath"="%systemroot%\system32\msiexec.exe /V" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSKSSRV] "ImagePath"="system32\drivers\MSKSSRV.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPCLOCK] "ImagePath"="system32\drivers\MSPCLOCK.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPQM] "ImagePath"="system32\drivers\MSPQM.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mssmbios] "ImagePath"="system32\DRIVERS\mssmbios.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mup] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\napagent] "ServiceDll"="%SystemRoot%\System32\qagentrt.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVENG] "ImagePath"="\??\C:\PROGRA~1\FELLES~1\SYMANT~1\VIRUSD~1\20080925.003\NAVENG.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVEX15] "ImagePath"="\??\C:\PROGRA~1\FELLES~1\SYMANT~1\VIRUSD~1\20080925.003\NAVEX15.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDIS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisTapi] "ImagePath"="system32\DRIVERS\ndistapi.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ndisuio] "ImagePath"="system32\DRIVERS\ndisuio.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisWan] "ImagePath"="system32\DRIVERS\ndiswan.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDProxy] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBIOS] "ImagePath"="system32\DRIVERS\netbios.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBT] "ImagePath"="system32\DRIVERS\netbt.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDE] "ImagePath"="%SystemRoot%\system32\netdde.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDEdsdm] "ImagePath"="%SystemRoot%\system32\netdde.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netlogon] "ImagePath"="%SystemRoot%\system32\lsass.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netman] "ServiceDll"="%SystemRoot%\System32\netman.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetSvc] "ImagePath"="C:\Programfiler\Intel\PROSetWired\NCS\Sync\NetSvc.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Nla] "ServiceDll"="%SystemRoot%\System32\mswsock.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Npfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ntfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtLmSsp] "ImagePath"="%SystemRoot%\system32\lsass.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc] "ServiceDll"="%SystemRoot%\system32\ntmssvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Null] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nv] "ImagePath"="system32\DRIVERS\nv4_mini.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFlt] "ImagePath"="system32\DRIVERS\nwlnkflt.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFwd] "ImagePath"="system32\DRIVERS\nwlnkfwd.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\odserv] "ImagePath"="\"C:\Programfiler\Fellesfiler\Microsoft Shared\OFFICE12\ODSERV.EXE\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ose] "ImagePath"="\"C:\Programfiler\Fellesfiler\Microsoft Shared\Source Engine\OSE.EXE\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Outlook] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Parport] "ImagePath"="system32\DRIVERS\parport.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PartMgr] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ParVdm] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCI] "ImagePath"="system32\DRIVERS\pci.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIDump] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIIde] "ImagePath"="system32\DRIVERS\pciide.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pcmcia] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCTINDIS5] "ImagePath"="\??\C:\WINDOWS\system32\PCTINDIS5.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDCOMP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDFRAME] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRELI] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRFRAME] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2] "ImagePath"="\SystemRoot\system32\DRIVERS\perc2.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2hib] "ImagePath"="\SystemRoot\system32\DRIVERS\perc2hib.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfDisk] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfNet] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfOS] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfProc] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PlugPlay] "ImagePath"="%SystemRoot%\system32\services.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PolicyAgent] "ImagePath"="%SystemRoot%\system32\lsass.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PptpMiniport] "ImagePath"="system32\DRIVERS\raspptp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Processor] "ImagePath"="system32\DRIVERS\processr.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ProtectedStorage] "ImagePath"="%SystemRoot%\system32\lsass.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSched] "ImagePath"="system32\DRIVERS\psched.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ptilink] "ImagePath"="system32\DRIVERS\ptilink.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PxHelp20] "ImagePath"="System32\Drivers\PxHelp20.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1080] "ImagePath"="\SystemRoot\system32\DRIVERS\ql1080.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ql10wnt] "ImagePath"="\SystemRoot\system32\DRIVERS\ql10wnt.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql12160] "ImagePath"="\SystemRoot\system32\DRIVERS\ql12160.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1240] "ImagePath"="\SystemRoot\system32\DRIVERS\ql1240.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1280] "ImagePath"="\SystemRoot\system32\DRIVERS\ql1280.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAcd] "ImagePath"="system32\DRIVERS\rasacd.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAuto] "ServiceDll"="%SystemRoot%\System32\rasauto.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rasl2tp] "ImagePath"="system32\DRIVERS\rasl2tp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasMan] "ServiceDll"="%SystemRoot%\System32\rasmans.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasPppoe] "ImagePath"="system32\DRIVERS\raspppoe.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Raspti] "ImagePath"="system32\DRIVERS\raspti.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rdbss] "ImagePath"="system32\DRIVERS\rdbss.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPCDD] "ImagePath"="System32\DRIVERS\RDPCDD.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPDD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rdpdr] "ImagePath"="system32\DRIVERS\rdpdr.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPNP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPWD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDSessMgr] "ImagePath"="C:\WINDOWS\system32\sessmgr.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\redbook] "ImagePath"="system32\DRIVERS\redbook.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteAccess] "ServiceDll"="%SystemRoot%\System32\mprdim.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcLocator] "ImagePath"="%SystemRoot%\system32\locator.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcSs] "ServiceDll"="%SystemRoot%\System32\rpcss.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RSVP] "ImagePath"="%SystemRoot%\system32\rsvp.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SamSs] "ImagePath"="%SystemRoot%\system32\lsass.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SCardSvr] "ImagePath"="%SystemRoot%\System32\SCardSvr.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Schedule] "ServiceDll"="%SystemRoot%\system32\schedsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ScsiPort] "ImagePath"="%SystemRoot%\system32\drivers\scsiport.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Secdrv] "ImagePath"="system32\DRIVERS\secdrv.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seclogon] "ServiceDll"="%SystemRoot%\System32\seclogon.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SENS] "ServiceDll"="%SystemRoot%\system32\sens.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\serenum] "ImagePath"="system32\DRIVERS\serenum.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Serial] "ImagePath"="system32\DRIVERS\serial.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sfdrv01] "ImagePath"="System32\drivers\sfdrv01.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sfhlp02] "ImagePath"="System32\drivers\sfhlp02.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sfloppy] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sfsync04] "ImagePath"="System32\drivers\sfsync04.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sfvfs02] "ImagePath"="System32\drivers\sfvfs02.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess] "ServiceDll"="%SystemRoot%\System32\ipnathlp.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ShellHWDetection] "ServiceDll"="%SystemRoot%\System32\shsvcs.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Simbad] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sisagp] "ImagePath"="\SystemRoot\system32\DRIVERS\sisagp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sparrow] "ImagePath"="\SystemRoot\system32\DRIVERS\sparrow.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SPBBCDrv] "ImagePath"="\??\C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCDrv.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\splitter] "ImagePath"="system32\drivers\splitter.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Spooler] "ImagePath"="%SystemRoot%\system32\spoolsv.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sr] "ImagePath"="system32\DRIVERS\sr.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srservice] "ServiceDll"="C:\WINDOWS\system32\srsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SRTSP] "ImagePath"="System32\Drivers\SRTSP.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SRTSPL] "ImagePath"="System32\Drivers\SRTSPL.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SRTSPX] "ImagePath"="System32\Drivers\SRTSPX.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Srv] "ImagePath"="system32\DRIVERS\srv.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sscdbhk5] "ImagePath"="system32\drivers\sscdbhk5.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SSDPSRV] "ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ssrtln] "ImagePath"="system32\drivers\ssrtln.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\StarWindService] "ImagePath"="C:\Programfiler\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\STHDA] "ImagePath"="system32\drivers\sthda.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\stisvc] "ServiceDll"="%SystemRoot%\system32\wiaservc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swenum] "ImagePath"="system32\DRIVERS\swenum.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swmidi] "ImagePath"="system32\drivers\swmidi.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SwPrv] "ImagePath"="C:\WINDOWS\system32\dllhost.exe /Processid:{34DDD0A4-7D2C-4D9C-9E6E-D51BAA6AF810}" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swwd] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Symantec Core LC] "ImagePath"="\"C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymAppCore] "ImagePath"="\"C:\Programfiler\Fellesfiler\Symantec Shared\AppCore\AppSvc32.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symc810] "ImagePath"="\SystemRoot\system32\DRIVERS\symc810.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symc8xx] "ImagePath"="\SystemRoot\system32\DRIVERS\symc8xx.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMDNS] "ImagePath"="\SystemRoot\System32\Drivers\SYMDNS.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymEvent] "ImagePath"="\??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMFW] "ImagePath"="\SystemRoot\System32\Drivers\SYMFW.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMIDS] "ImagePath"="\SystemRoot\System32\Drivers\SYMIDS.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMIDSCO] "ImagePath"="\??\C:\PROGRA~1\FELLES~1\SYMANT~1\SymcData\idsdefs\20080924.001\SymIDSCo.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMNDIS] "ImagePath"="\SystemRoot\System32\Drivers\SYMNDIS.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMREDRV] "ImagePath"="\SystemRoot\System32\Drivers\SYMREDRV.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI] "ImagePath"="\SystemRoot\System32\Drivers\SYMTDI.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sym_hi] "ImagePath"="\SystemRoot\system32\DRIVERS\sym_hi.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sym_u3] "ImagePath"="\SystemRoot\system32\DRIVERS\sym_u3.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sysaudio] "ImagePath"="system32\drivers\sysaudio.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SysmonLog] "ImagePath"="%SystemRoot%\system32\smlogsvc.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TapiSrv] "ServiceDll"="%SystemRoot%\System32\tapisrv.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip] "ImagePath"="system32\DRIVERS\tcpip.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDPIPE] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDTCP] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TermDD] "ImagePath"="system32\DRIVERS\termdd.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TermService] "ServiceDll"="%SystemRoot%\System32\termsrv.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsnboio] "ImagePath"="system32\dla\tfsnboio.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsncofs] "ImagePath"="system32\dla\tfsncofs.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsndrct] "ImagePath"="system32\dla\tfsndrct.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsndres] "ImagePath"="system32\dla\tfsndres.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsnifs] "ImagePath"="system32\dla\tfsnifs.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsnopio] "ImagePath"="system32\dla\tfsnopio.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsnpool] "ImagePath"="system32\dla\tfsnpool.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsnudf] "ImagePath"="system32\dla\tfsnudf.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tfsnudfa] "ImagePath"="system32\dla\tfsnudfa.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Themes] "ServiceDll"="%SystemRoot%\System32\shsvcs.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tmcomm] "ImagePath"="\??\C:\WINDOWS\system32\drivers\tmcomm.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TosIde] "ImagePath"="\SystemRoot\system32\DRIVERS\toside.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TrkWks] "ServiceDll"="%SystemRoot%\system32\trkwks.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TSDDD] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Udfs] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ultra] "ImagePath"="\SystemRoot\system32\DRIVERS\ultra.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Update] "ImagePath"="system32\DRIVERS\update.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\upnphost] "ServiceDll"="%SystemRoot%\System32\upnphost.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UPS] "ImagePath"="%SystemRoot%\System32\ups.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\USBAAPL] "ImagePath"="System32\Drivers\usbaapl.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbccgp] "ImagePath"="system32\DRIVERS\usbccgp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbehci] "ImagePath"="system32\DRIVERS\usbehci.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbhub] "ImagePath"="system32\DRIVERS\usbhub.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbprint] "ImagePath"="system32\DRIVERS\usbprint.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbscan] "ImagePath"="system32\DRIVERS\usbscan.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\USBSTOR] "ImagePath"="system32\DRIVERS\USBSTOR.SYS" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbuhci] "ImagePath"="system32\DRIVERS\usbuhci.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usnjsvc] "ImagePath"="\"C:\Programfiler\Windows Live\Messenger\usnsvc.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vax347b] "ImagePath"="system32\DRIVERS\vax347b.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vax347s] "ImagePath"="System32\Drivers\vax347s.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VgaSave] "ImagePath"="\SystemRoot\System32\drivers\vga.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\viaagp] "ImagePath"="\SystemRoot\system32\DRIVERS\viaagp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ViaIde] "ImagePath"="\SystemRoot\system32\DRIVERS\viaide.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VolSnap] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VSS] "ImagePath"="%SystemRoot%\System32\vssvc.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\w32time] "ServiceDll"="%systemroot%\system32\w32time.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\W3SVC] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\w550bus] "ImagePath"="system32\DRIVERS\w550bus.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\w550mdfl] "ImagePath"="system32\DRIVERS\w550mdfl.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\w550mdm] "ImagePath"="system32\DRIVERS\w550mdm.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\w550mgmt] "ImagePath"="system32\DRIVERS\w550mgmt.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\w550obex] "ImagePath"="system32\DRIVERS\w550obex.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wanarp] "ImagePath"="system32\DRIVERS\wanarp.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wceusbsh] "ImagePath"="system32\DRIVERS\wceusbsh.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WDICA] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wdmaud] "ImagePath"="system32\drivers\wdmaud.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebClient] "ServiceDll"="%SystemRoot%\System32\webclnt.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\winmgmt] "ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winsock] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinSock2] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinTrust] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WLSetupSvc] "ImagePath"="\"C:\Programfiler\Windows Live\installer\WLSetupSvc.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmBEnum] "ImagePath"="system32\drivers\WmBEnum.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmdmPmSN] "ServiceDll"="C:\WINDOWS\system32\MsPMSNSv.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmFilter] "ImagePath"="system32\drivers\WmFilter.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmHidLo] "ImagePath"="system32\drivers\WmHidLo.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wmi] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiApRpl] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiApSrv] "ImagePath"="C:\WINDOWS\system32\wbem\wmiapsrv.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WMPNetworkSvc] "ImagePath"="\"C:\Programfiler\Windows Media Player\WMPNetwk.exe\"" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmVirHid] "ImagePath"="system32\drivers\WmVirHid.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmXlCore] "ImagePath"="system32\drivers\WmXlCore.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WS2IFSL] [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wscsvc] "ServiceDll"="%SYSTEMROOT%\system32\wscsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wuauserv] "ServiceDll"="C:\WINDOWS\system32\wuauserv.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf] "ImagePath"="system32\DRIVERS\WudfPf.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd] "ImagePath"="system32\DRIVERS\wudfrd.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc] "ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WZCSVC] "ServiceDll"="%SystemRoot%\System32\wzcsvc.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xmlprov] "ServiceDll"="%SystemRoot%\System32\xmlprov.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{E548342B-51AD-4EDE-84B6-B4625D65E543}] . Completion time: 2008-10-05 9:48:53 ComboFix-quarantined-files.txt 2008-10-05 07:48:46 ComboFix2.txt 2008-09-25 13:01:29 ComboFix3.txt 2008-09-11 17:34:38 Pre-Run: 92 777 390 080 byte ledig Post-Run: 92,821,311,488 byte ledig 907 --- E O F --- 2008-09-16 12:39:04