stl_s
jeg kunne desværre ikke køre programmet i fejlsikret tilstand så det blev en log på alm vis
på forhånd tak
RemoveIT Pro XT2c - SE (Buld date: 23.10.2006) full information log file.
Generated at: 21-11-2006 on 18:24:05
Microsoft Windows XP Professional (Build 2600)
Author: Damjan Irgolic
http://www.incodesolutions.com
support@incodesolutions.com
You have some viruses in your computer.
Please Scan your computer with RemoveIT Pro to remove discovered viruses.
Virus list:
Infected with Win32.Tilebot.HW - File lsass.exe
Infected with Win32.Trojan.WowPWS.F - File lsass.exe
Running processes: (29)
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Programmer\RivaTuner v2.0 RC 15.7\RivaTuner.exe
C:\Programmer\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\Programmer\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\lsass.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\FLLESF~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programmer\InCode Solutions\RemoveIT Pro XT2 - SE\removeit.exe
C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
Startup files:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\CTFMON.EXE
[C:\WINDOWS\System32\ctfmon.exe]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\TransTask
[]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Tweak-XP
[]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\TransparentIcons
[]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\MsnMsgr
["C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Tweak-XP Pro
["C:\Programmer\Tweak-XP Pro\Tweak-xp.exe" -ex]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Steam
["d:\installerede spil\hl2\steam.exe" -silent]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\LogitechSoftwareUpdate
[C:\Programmer\Logitech\Video\ManifestEngine.exe boot]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Skype
["C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\PcSync
[C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ccApp
["C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ccRegVfy
["C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe"]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\GhostStartTrayApp
[C:\Programmer\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\NvCplDaemon
[RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\nwiz
[nwiz.exe /install]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Symantec NetDriver Monitor
[C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\NeroFilterCheck
[C:\WINDOWS\system32\NeroCheck.exe]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\SSBkgdUpdate
["C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\PaperPort PTD
[C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\IndexSearch
[C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\SetDefPrt
[C:\Programmer\Brother\Brmfl04a\BrStDvPt.exe]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ControlCenter2.0
[C:\Programmer\Brother\ControlCenter2\brctrcen.exe /autorun]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\TkBellExe
["C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\DAEMON Tools-1033
["C:\Programmer\D-Tools\daemon.exe" -lang 1033]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\LVCOMSX
[C:\WINDOWS\system32\LVCOMSX.EXE]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\LogitechVideoRepair
[C:\Programmer\Logitech\Video\ISStart.exe ]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\LogitechVideoTray
[C:\Programmer\Logitech\Video\LogiTray.exe]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\IAAnotif
[C:\Programmer\Intel\Intel Matrix Storage Manager\iaanotif.exe]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\RivaTuner
["C:\Programmer\RivaTuner v2.0 RC 15.7\RivaTuner.exe" /T]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\RivaTunerStatisticsServer
["C:\Programmer\RivaTuner v2.0 RC 15.7\Tools\RivaTunerStatisticsServer\RivaTunerStatisticsServer.exe" /s]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\PCSuiteTrayApplication
[C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\SunJavaUpdateSched
["C:\Programmer\Java\jre1.5.0_09\bin\jusched.exe"]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Cmaudio
[RunDll32 cmicnfg.cpl,CMICtrlWnd]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Arovax Shield
[C:\Programmer\Arovax Shield\ArovaxShield.exe -tray]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\PrevxOne
["C:\Programmer\Prevx1\PXConsole.exe"]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\SoundMan
[SOUNDMAN.EXE]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\NvMediaCenter
[RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit]
Detail report: (116)
Clsid C:\WINDOWS\System32\crypt32.dll[e7e6076b6d8e490577c8422c6a6fe02d][557568]
Clsid C:\WINDOWS\System32\cryptnet.dll[3fa2d95cad421bbd6bd188eea4eabb25][53248]
Clsid C:\WINDOWS\System32\cscdll.dll[f462f3dd1c2fb11d0b5347efcd0ca178][89600]
Clsid C:\WINDOWS\System32\sclgntfy.dll[65093fffb24f104bf8e47d074e2a877e][19968]
Clsid c:\windows\system32\stobject.dll[758b9219b1a8040b9171f46c3fa363a4][117760]
Clsid C:\WINDOWS\System32\wlnotify.dll[01dcbd00e66ab42400d256016a9a0e8f][86528]
Proc C:\PROGRA~1\FLLESF~1\Nokia\MPAPI\MPAPI3s.exe[8b63faf88f529a14092a01bfa53d4e2f][471040]
Proc C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe[305365a42f7d38d8d10b233ece1c84c6][172065]
Proc C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE[bc9c77fac763d84bfdf09b55d4b41afa][200704]
Proc C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe[bf1adc427620e14f45bc00447524a1dc][176640]
Proc C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe[77ed13fd3196ebc7311ccd6899c7488c][180269]
Proc C:\Programmer\InCode Solutions\RemoveIT Pro XT2 - SE\removeit.exe[114aeb2c324d207077406a2b06118816][548864]
Proc C:\Programmer\Intel\Intel Matrix Storage Manager\iaanotif.exe[6ca4cc14fda11978617057e73d588475][139264]
Proc C:\Programmer\Intel\Intel Matrix Storage Manager\iaantmon.exe[d43e91e271c041bb86a6223462a41d28][86140]
Proc C:\Programmer\Java\jre1.5.0_09\bin\jusched.exe[409c45da1cfbc3fc19eec7cbfe9b2786][49263]
Proc C:\Programmer\Logitech\Video\FxSvr2.exe[70b68620c41c40580886b808fd7265da][192512]
Proc C:\Programmer\Logitech\Video\LogiTray.exe[fe6e15cc578c3278755cddff70c2787d][217088]
Proc C:\Programmer\MSN Messenger\MsnMsgr.Exe[6f616289da6c949147661bf88f081136][7094272]
Proc C:\Programmer\RivaTuner v2.0 RC 15.7\RivaTuner.exe[9bb98461106359a61969d2beeb7dffb5][2195456]
Proc C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe[59572c7838043b69562c55dfbba0349d][57393]
Proc C:\Programmer\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe[45725ce2a9bd68cf1526728fcffcc24e][94208]
Proc C:\WINDOWS\Explorer.EXE[9c8604e0a3ec6e29a4a2f978e1167315][1001984]
Proc C:\WINDOWS\lsass.exe[5545a0218859dacf7abfa15cd1db3837][53675]
Proc C:\WINDOWS\system32\Brmfrmps.exe[bb192385661daf7f3d48b586f6e1d166][65536]
Proc C:\WINDOWS\System32\brss01a.exe[9e646cd378d4d0c996baf9bcb18237c7][45056]
Proc C:\WINDOWS\System32\brsvc01a.exe[d3facb34fff5db91adb70987838f8ba7][57344]
Proc C:\WINDOWS\System32\ctfmon.exe[aa49ffa6a35931bed7bfe3b3d8e08649][13312]
Proc C:\WINDOWS\system32\lsass.exe[5ac2f1869c1eef4a1b41e245e668328e][11776]
Proc C:\WINDOWS\system32\LVCOMSX.EXE[f0431c490f124a8cc874163e6a38dd28][221184]
Proc C:\WINDOWS\System32\RUNDLL32.EXE[5db152abc7200ddcebe032f988741e70][31744]
Proc C:\WINDOWS\system32\services.exe[f0616b86f44c8fe4fc2db2953f49ab83][101376]
Proc C:\WINDOWS\system32\spoolsv.exe[1c0ab1f20565c71bdd0ab5bf754cf4cc][51200]
Proc C:\WINDOWS\system32\svchost.exe[cc25dca889ff3ab2bd4cf74bbc862e80][12800]
RegRun c:\progra~1\nokia\nokiap~1\launch~1.exe [47fe14fd96648ef07957b8cabf992313][237568]
RegRun c:\progra~1\symnet~1\sndmon.exe [f9418981ee4d7e995d359833adab59d5][100056]
RegRun c:\programmer\arovax shield\arovaxshield.exe [86c7b8fd3e523bc8d0c783c4b781406f][1183744]
RegRun c:\programmer\brother\brmfl04a\brstdvpt.exe[129b277c10339efe2907834e9295d16d][49152]
RegRun c:\programmer\brother\controlcenter2\brctrcen.exe [7c280ebdf43724636289d50cf26f2ab0][851968]
RegRun c:\programmer\d-tools\daemon.exe [d4a75928bcf18a6ed3bf9fc732ae609f][73728]
RegRun c:\programmer\fælles filer\real\update_ob\realsched.exe [77ed13fd3196ebc7311ccd6899c7488c][180269]
RegRun c:\programmer\fælles filer\scansoft shared\ssbkgdupdate\ssbkgdupdate.exe [1c3ca3e7807f915933bb4e08e599ddab][155648]
RegRun c:\programmer\fælles filer\symantec shared\ccapp.exe[ace91f1db4e08fa62c758adf2390c07e][54296]
RegRun c:\programmer\fælles filer\symantec shared\ccregvfy.exe[8ab27947c7c2b3388f15ce7c3d595050][58392]
RegRun c:\programmer\intel\intel matrix storage manager\iaanotif.exe[6ca4cc14fda11978617057e73d588475][139264]
RegRun c:\programmer\java\jre1.5.0_09\bin\jusched.exe[409c45da1cfbc3fc19eec7cbfe9b2786][49263]
RegRun c:\programmer\logitech\video\isstart.exe [b5652e4b805e404a0d5d8177b401802a][458752]
RegRun c:\programmer\logitech\video\logitray.exe[fe6e15cc578c3278755cddff70c2787d][217088]
RegRun c:\programmer\logitech\video\manifestengine.exe [423c24b558d69ac9b6c53c41f65b0b91][196608]
RegRun c:\programmer\msn messenger\msnmsgr.exe [6f616289da6c949147661bf88f081136][7094272]
RegRun c:\programmer\nokia\nokia pc suite 6\pcsync2.exe [00f235bd50efee4d98ad7da6dbf510c9][1409024]
RegRun c:\programmer\prevx1\pxconsole.exe[42f978da6526fc0d3edbdca8dac22084][1490944]
RegRun c:\programmer\rivatuner v2.0 rc 15.7\rivatuner.exe [9bb98461106359a61969d2beeb7dffb5][2195456]
RegRun c:\programmer\rivatuner v2.0 rc 15.7\tools\rivatunerstatisticsserver\rivatunerstatisticsserver.exe [4acb1de963c42fe2bb3c17b480e4022c][49152]
RegRun c:\programmer\scansoft\paperport\indexsearch.exe[fd6d1d96f3ca1a7c571e5377c86f94f1][40960]
RegRun c:\programmer\scansoft\paperport\pptd40nt.exe[59572c7838043b69562c55dfbba0349d][57393]
RegRun c:\programmer\skype\phone\skype.exe [9bb317f9aad3aefba0c5c70b03c354ff][18577448]
RegRun c:\programmer\symantec\norton ghost 2003\ghoststarttrayapp.exe[45725ce2a9bd68cf1526728fcffcc24e][94208]
RegRun c:\programmer\tweak-xp pro\tweak-xp.exe [a4824228611ad82d861b86200c97c2ad][992256]
RegRun C:\WINDOWS\soundman.exe[ed8da2697f1c720ef26ae4b291a04497][577536]
RegRun c:\windows\system32\ctfmon.exe[aa49ffa6a35931bed7bfe3b3d8e08649][13312]
RegRun c:\windows\system32\lvcomsx.exe[f0431c490f124a8cc874163e6a38dd28][221184]
RegRun c:\windows\system32\nerocheck.exe[3e4c03cefad8de135263236b61a49c90][155648]
RegRun c:\windows\system32\nvcpl.dll[86e8b780980eebd164b6683d4198652f][5562368]
RegRun c:\windows\system32\nvmctray.dll[47d0e84172db0caff3d4d1dcc71a24d3][86016]
RegRun d:\installerede spil\hl2\steam.exe [cde5895db998d361a2d95647d1da4bbf][1249280]
Service c:\progra~1\fllesf~1\symant~1\script~1\sbserv.exe[3db0459e2661531bfe88ae0a182d019a][54408]
Service c:\progra~1\norton~1\speedd~1\nopdb.exe[305365a42f7d38d8d10b233ece1c84c6][172065]
Service c:\progra~1\symantec\norton~1\ghosts~2.exe[bc9c77fac763d84bfdf09b55d4b41afa][200704]
Service c:\programmer\fælles filer\pcsuite\services\servicelayer.exe[bf1adc427620e14f45bc00447524a1dc][176640]
Service c:\programmer\fælles filer\symantec shared\ccevtmgr.exe[edc5c2342e91f7a8870e17ac5a87d6ec][317128]
Service c:\programmer\fælles filer\symantec shared\ccpwdsvc.exe[cf2a5fcde371bbefbd59e9d3fc9f925c][99352]
Service c:\programmer\fælles filer\symantec shared\security center\symwsc.exe[67c5af84809468061121fbcbecb19285][316544]
Service c:\programmer\fælles filer\symantec shared\sndsrvc.exe[443e397643965e08c5ab6a6caa732b97][206552]
Service c:\programmer\intel\intel matrix storage manager\iaantmon.exe[d43e91e271c041bb86a6223462a41d28][86140]
Service c:\programmer\norton internet security\ccpxysvc.exe[8b8241298229de4f7b72046a61940aee][34040]
Service c:\programmer\norton internet security\nisum.exe[cb8a83cde6575d834b571466677437d4][140536]
Service c:\programmer\norton systemworks\norton antivirus\navapsvc.exe[00ff9f38a83706e7605f83852171197a][116336]
Service c:\programmer\norton systemworks\norton utilities\nprotect.exe[4914a155f9b73317b14f94bba4a79639][135168]
Service c:\programmer\prevx1\pxagent.exe [51500d5cdc4b38fffdcdbc7f474d0f35][139264]
Service c:\windows\lsass.exe[5545a0218859dacf7abfa15cd1db3837][53675]
Service c:\windows\microsoft.net\framework\v1.1.4322\aspnet_state.exe[a986fcfdac587e68478db51547b90800][32768]
Service c:\windows\system32\alg.exe[bdcb49a99c21fa9bf9491fbac1398b16][40960]
Service c:\windows\system32\brmfrmps.exe [bb192385661daf7f3d48b586f6e1d166][65536]
Service c:\windows\system32\brsvc01a.exe[d3facb34fff5db91adb70987838f8ba7][57344]
Service c:\windows\system32\cisvc.exe[dc639244a9640654766f6dcb8c524576][5120]
Service c:\windows\system32\clipsrv.exe[ff8a1ec5e253be4d2358bcf02098f46d][30720]
Service c:\windows\system32\dllhost.exe [d1fa32685a96d2cdbf202cecdd4073e9][4608]
Service c:\windows\system32\dmadmin.exe [c4d881dd53ca070415bc52e0d04f45dc][205312]
Service c:\windows\system32\imapi.exe[02c7d75925e2dd56f25ccaac9d830272][118784]
Service c:\windows\system32\locator.exe[9572f9e453849faaaeebba28564a8ad1][68096]
Service c:\windows\system32\lsass.exe[5ac2f1869c1eef4a1b41e245e668328e][11776]
Service c:\windows\system32\mnmsrvc.exe[922c9ddb47b14cf77e8ab09b2f84c295][32768]
Service c:\windows\system32\msdtc.exe[1b4bb5f84ead0037f8e141601deebecb][6144]
Service c:\windows\system32\msiexec.exe [2b2ba4cd380774930dd5bbd4b569a429][63488]
Service c:\windows\system32\netdde.exe[f185303b63b9fc7297d2e1d1011b1322][107520]
Service c:\windows\system32\nvsvc32.exe[f5ca5a3e07fe3fefa48b620a25be5863][127043]
Service c:\windows\system32\rsvp.exe[72309905945d7eaab911b376f86b95e6][132608]
Service c:\windows\system32\scardsvr.exe[6e4e124706e457e128c0ff1ed4da20f6][94720]
Service c:\windows\system32\services.exe[f0616b86f44c8fe4fc2db2953f49ab83][101376]
Service c:\windows\system32\sessmgr.exe[2af1c87bed19360631c85b1a447bd080][130560]
Service c:\windows\system32\smlogsvc.exe[268c4f5353547a8133077dcf05dcbe5c][87040]
Service c:\windows\system32\spoolsv.exe[1c0ab1f20565c71bdd0ab5bf754cf4cc][51200]
Service c:\windows\system32\svchost.exe [cc25dca889ff3ab2bd4cf74bbc862e80][12800]
Service c:\windows\system32\tlntsvr.exe[ef1b4b4f1de6bfc37efa8c93171c2e32][61952]
Service c:\windows\system32\ups.exe[6bbae5df1d10909f67c4ff2205418573][16384]
Service c:\windows\system32\vssvc.exe[67ae877232afeec75ad98e227f34028c][276480]
Service c:\windows\system32\wbem\wmiapsrv.exe[c219288ee752038477a5dffeee19227a][117248]
Service c:\windows\system32\wdfmgr.exe[c81b8635dee0d3ef5f64b3dd643023a5][38912]
Startup c:\documents and settings\all users\menuen start\programmer\start\desktop.ini[d6a6856702e3f0953e7246a9b4a9fe35][84]
Startup c:\documents and settings\kim jensen\menuen start\programmer\start\desktop.ini[d6a6856702e3f0953e7246a9b4a9fe35][84]
Startup c:\programmer\avertv\quicktv.exe[fc22b26ecdaac0114a8594c284dda006][253952]
Startup c:\programmer\brother\brmfcmon\brmfcwnd.exe[01b036128cd786b8b2644b624cc9e7cd][819200]
Startup c:\programmer\metacafe\metacafeagent.exe[afae754e4146a58d08e4a180597db3ed][112760]
Startup c:\programmer\microsoft office\office10\osa.exe[5bc65464354a9fd3beaa28e18839734a][83360]
Startup c:\programmer\xfire\xfire.exe[1bbae0a98bbaeb1c4708dede45db5b78][2303056]
System.ini c:\windows\system32\vssvc.exe[67ae877232afeec75ad98e227f34028c][276480]
Startup folder: (8)
Startup name: desktop.ini
Command: C:\Documents and Settings\kim jensen\Menuen Start\Programmer\Start\desktop.ini
Startup name: MetaCafe.lnk
Command: C:\Programmer\Metacafe\MetacafeAgent.exe
Startup name: Xfire.lnk
Command: C:\Programmer\Xfire\Xfire.exe
Startup name: desktop.ini
Command: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\desktop.ini
Startup name: MetaCafe.lnk
Command: C:\Programmer\Metacafe\MetacafeAgent.exe
Startup name: Microsoft Office.lnk
Command: C:\Programmer\Microsoft Office\Office10\OSA.EXE
Startup name: QuickTV.lnk
Command: C:\Programmer\AVerTV\QuickTV.exe
Startup name: Status Monitor.lnk
Command: C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe
Win.ini Startup: (1)
Path: No additional driver found!
Win.ini Startup: (1)
Path: No additional driver found!
Keyboard drivers: (1)
Name: No Keyboard Filter driver found!
Services: (100)
Service Name: Adgang til brugerstyrede inputenheder (HID) [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Alerter [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k LocalService
Service Name: Alternativt logon [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Arbejdsstation [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: ASP.NET State Service [Stopped],
Path: C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
Service Name: Automatisk konfiguration af trådløse enheder [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Automatiske opdateringer [Stopped],
Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Service Name: Beskyttet lager [Running],
Path: C:\WINDOWS\system32\lsass.exe
Service Name: Brother Popup Suspend service for Resource manager [Running],
Path: "C:\WINDOWS\system32\Brmfrmps.exe" -service
Service Name: BrSplService [Running],
Path: C:\WINDOWS\System32\brsvc01a.exe
Service Name: Chipkort [Stopped],
Path: C:\WINDOWS\System32\SCardSvr.exe
Service Name: Chipkort Hjælp [Stopped],
Path: C:\WINDOWS\System32\SCardSvr.exe
Service Name: COM+-hændelsessystem [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: COM+-systemprogram [Stopped],
Path: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Service Name: Computerbrowser [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: COM-tjenesten IMAPI cd-skrivning [Stopped],
Path: C:\WINDOWS\System32\imapi.exe
Service Name: DHCP-klientprogram [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Distributed Link Tracking Client [Running],
Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Service Name: DNS-klient [Running],
Path: C:\WINDOWS\System32\svchost.exe -k NetworkService
Service Name: DTC (Distributed Transaction Coordinator) [Stopped],
Path: C:\WINDOWS\System32\msdtc.exe
Service Name: Firewall til Internetforbindelse / Deling af Internetforbindelse [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Flytbare lagermedier [Stopped],
Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Service Name: Gatewaytjeneste til programlaget [Stopped],
Path: C:\WINDOWS\System32\alg.exe
Service Name: GhostStartService [Running],
Path: C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
Service Name: Hardwaregenkendelse på brugergrænsefladen [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Hjælp og support [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Hjælp til Sessionsstyring til Fjernskrivebord [Stopped],
Path: C:\WINDOWS\system32\sessmgr.exe
Service Name: HTTP SSL [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k HTTPFilter
Service Name: Hurtigt brugerskift-kompatibilitet [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Hændelseslog [Running],
Path: C:\WINDOWS\system32\services.exe
Service Name: Indekseringstjeneste [Stopped],
Path: C:\WINDOWS\system32\cisvc.exe
Service Name: Infrarød overvågning [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Intel(R) Matrix Storage Event Monitor [Running],
Path: C:\Programmer\Intel\Intel Matrix Storage Manager\iaantmon.exe
Service Name: IPSEC Policy Agent [Running],
Path: C:\WINDOWS\System32\lsass.exe
Service Name: Kryptografiske tjenester [Running],
Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Service Name: Logical Disk Manager [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Logical Disk Manager Administrative Service [Stopped],
Path: C:\WINDOWS\System32\dmadmin.exe /com
Service Name: LSA Shel (Export Version) [Running],
Path: "C:\WINDOWS\lsass.exe"
Service Name: Messenger [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: MS Software Shadow Copy Provider [Stopped],
Path: C:\WINDOWS\System32\dllhost.exe /Processid:{7B7DCCB7-8D20-4B90-87C3-EE1B771C1A9D}
Service Name: Netlogon [Stopped],
Path: C:\WINDOWS\System32\lsass.exe
Service Name: NetMeeting - Deling af fjernskrivebord [Stopped],
Path: C:\WINDOWS\System32\mnmsrvc.exe
Service Name: Netværksforbindelser [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Network DDE [Stopped],
Path: C:\WINDOWS\system32\netdde.exe
Service Name: Network DDE DSDM [Stopped],
Path: C:\WINDOWS\system32\netdde.exe
Service Name: NLA (Network Location Awareness) [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Norton AntiVirus Auto Protect Service [Stopped],
Path: "C:\Programmer\Norton SystemWorks\Norton AntiVirus\navapsvc.exe"
Service Name: Norton Internet Security Accounts Manager [Stopped],
Path: C:\Programmer\Norton Internet Security\NISUM.EXE
Service Name: Norton Unerase Protection [Stopped],
Path: "C:\Programmer\Norton SystemWorks\Norton Utilities\NPROTECT.EXE"
Service Name: NT LM Security Support Provider [Stopped],
Path: C:\WINDOWS\System32\lsass.exe
Service Name: NVIDIA Display Driver Service [Stopped],
Path: C:\WINDOWS\system32\nvsvc32.exe
Service Name: Opgavestyring [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Performance Logs and Alerts [Stopped],
Path: C:\WINDOWS\system32\smlogsvc.exe
Service Name: Plug and Play [Running],
Path: C:\WINDOWS\system32\services.exe
Service Name: Portable Media Serial Number Service [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Prevx Agent [Stopped],
Path: "C:\Programmer\Prevx1\PXAgent.exe" -f
Service Name: Print Spooler [Running],
Path: C:\WINDOWS\system32\spoolsv.exe
Service Name: Programadministration [Stopped],
Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Service Name: QoS RSVP [Stopped],
Path: C:\WINDOWS\System32\rsvp.exe
Service Name: Remote Access Auto Connection Manager [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Remote Access Connection Manager [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Remote Procedure Call (RPC) [Running],
Path: C:\WINDOWS\system32\svchost -k rpcss
Service Name: Remote Procedure Call (RPC) Locator [Stopped],
Path: C:\WINDOWS\System32\locator.exe
Service Name: Remote Registry [Running],
Path: C:\WINDOWS\system32\svchost.exe -k LocalService
Service Name: Routing og Remote Access [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: SAM (Security Accounts Manager) [Running],
Path: C:\WINDOWS\system32\lsass.exe
Service Name: ScriptBlocking Service [Stopped],
Path: C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
Service Name: Serienummer for bærbart medie [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Server [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: ServiceLayer [Running],
Path: "C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe"
Service Name: Speed Disk service [Running],
Path: C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
Service Name: SSDP-genkendelsestjeneste [Running],
Path: C:\WINDOWS\System32\svchost.exe -k LocalService
Service Name: Symantec Event Manager [Stopped],
Path: "C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe"
Service Name: Symantec Network Drivers Service [Stopped],
Path: "C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe"
Service Name: Symantec Password Validation Service [Stopped],
Path: "C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe"
Service Name: Symantec Proxy Service [Stopped],
Path: C:\Programmer\Norton Internet Security\ccPxySvc.exe
Service Name: SymWMI Service [Stopped],
Path: C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
Service Name: System Event Notification [Running],
Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Service Name: Telekommunikation [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Telnet [Stopped],
Path: C:\WINDOWS\System32\tlntsvr.exe
Service Name: Temaer [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Terminal Services [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Tjenesten Background Intelligent Transfer [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Tjenesten Fejlrapportering [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Tjenesten Systemgendannelse [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Tjenesten TCP/IP NetBIOS Helper [Running],
Path: C:\WINDOWS\System32\svchost.exe -k LocalService
Service Name: Udklipsbog [Stopped],
Path: C:\WINDOWS\system32\clipsrv.exe
Service Name: Upload Manager [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: UPS (Uninterruptible Power Supply) [Stopped],
Path: C:\WINDOWS\System32\ups.exe
Service Name: Vært for Universal Plug and Play-enhed [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k LocalService
Service Name: Webklient [Running],
Path: C:\WINDOWS\System32\svchost.exe -k LocalService
Service Name: Windows Audio [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Windows Installer [Stopped],
Path: C:\WINDOWS\System32\msiexec.exe /V
Service Name: Windows Management Instrumentation [Running],
Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Service Name: Windows Management Instrumentation-driverudvidelser [Stopped],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Windows Time [Running],
Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
Service Name: Windows User Mode Driver Framework [Stopped],
Path: C:\WINDOWS\System32\wdfmgr.exe
Service Name: Windows-billedscanning [Running],
Path: C:\WINDOWS\System32\svchost.exe -k imgsvc
Service Name: WMI-ydelseskort [Stopped],
Path: C:\WINDOWS\System32\wbem\wmiapsrv.exe
Service Name: Øjebliksbillede af diskenhed [Stopped],
Path: C:\WINDOWS\System32\vssvc.exe
Finished...