Thanks
here's ComboFix.txt
ComboFix 08-02.05.3 - Joy 2008-02-13 1:34:59.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.874.66.1033.18.192 [GMT -5:00]
Running from: C:\Documents and Settings\Joy\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Joy\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-01-13 to 2008-02-13 )))))))))))))))))))))))))))))))
.
2008-02-11 23:33 . 2004-08-04 07:00 388,608 --a------ C:\kmd.exe
2008-02-10 22:47 . 2008-02-10 22:47 <DIR> d-------- C:\Program Files\Winkflash
2008-02-10 22:45 . 2008-02-10 22:44 55,296 --a------ C:\Program Files\setuptrans1.exe
2008-02-10 17:31 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-02-05 03:30 . 2008-02-05 08:07 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-04 12:28 . 2008-02-04 12:28 <DIR> d-------- C:\Program Files\Avira
2008-02-04 12:28 . 2008-02-04 12:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-04 01:43 . 2008-02-10 21:36 <DIR> d-------- C:\Program Files\a-squared Free
2008-02-04 01:27 . 2008-02-04 01:27 23,092,736 --a------ C:\Program Files\a2FreeSetup.exe
2008-02-03 09:23 . 2008-02-03 09:24 <DIR> d-------- C:\WINDOWS\ERUNT
2008-02-02 08:56 . 2008-02-02 08:56 <DIR> d-------- C:\Documents and Settings\Joy\Application Data\ESET
2008-02-02 08:51 . 2008-02-02 08:51 <DIR> d-------- C:\Program Files\ESET
2008-02-02 08:51 . 2008-02-02 08:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-02-02 08:05 . 2008-02-02 08:05 <DIR> d-------- C:\Documents and Settings\Joy\Application Data\Netscape
2008-02-02 08:03 . 2008-02-02 08:03 <DIR> d-------- C:\Program Files\Netscape
2008-02-01 15:50 . 2008-02-01 15:50 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-01-30 18:01 . 2008-02-03 17:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-30 18:01 . 2008-01-30 18:01 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-29 19:00 . 2008-01-29 19:00 <DIR> d-------- C:\Program Files\Streamload
2008-01-29 06:43 . 2008-01-29 06:43 52 --a------ C:\WINDOWS\system32\register.bat
2008-01-29 06:42 . 2008-02-03 17:24 <DIR> d-------- C:\idrivee
2008-01-29 06:42 . 2008-01-29 06:42 20,480 --a------ C:\WINDOWS\system32\IDriveEXceedCryReg.exe
2008-01-29 04:56 . 2008-01-29 11:25 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-01-29 03:32 . 2008-02-11 23:35 <DIR> d-------- C:\Program Files\IDrive
2008-01-28 08:08 . 2008-01-28 08:08 <DIR> d-------- C:\Program Files\AOL Pictures
2008-01-28 04:08 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-15 11:27 . 2006-10-04 21:42 2,560 --a------ C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-01-15 11:27 . 2006-10-04 21:42 2,432 --a------ C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-01-15 11:26 . 2008-01-15 11:26 <DIR> d-------- C:\WINDOWS\system32\IOSUBSYS
2008-01-15 11:23 . 2008-01-15 11:50 <DIR> d-------- C:\Program Files\Picasa2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-02-13 06:34 --------- d-----w C:\Program Files\QuickTime
2008-02-12 04:35 --------- d--h--w C:\Program Files\ltmoh
2008-02-12 04:35 --------- d--h--w C:\Program Files\Apoint2K
2008-02-05 00:17 --------- d-----w C:\Program Files\iTunes701
2008-02-03 14:08 155,648 ----a-w C:\WINDOWS\system32\NeroCheck.exe
2008-02-02 19:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-28 09:08 --------- d--h--w C:\Program Files\Java
2008-01-16 21:53 741,376 ----a-w C:\WINDOWS\system32\IDriveEService.dll
2008-01-15 14:56 118,784 ----a-w C:\WINDOWS\system32\igfxpers.exe
2008-01-03 05:48 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe
2008-01-03 04:15 98,304 ----a-w C:\WINDOWS\system32\igfxtray.exe
2008-01-03 04:15 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2008-01-02 22:23 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-30 09:00 15,196,432 ----a-w C:\Program Files\sdsetup.exe
2007-12-24 00:53 --------- d--h--w C:\Documents and Settings\Joy\Application Data\toshiba
2007-12-21 13:21 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2007-12-21 13:21 53,768 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2007-12-21 13:21 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2007-12-21 13:20 30,216 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 13:19 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-12-05 00:25 230 ----a-w C:\Documents and Settings\joy_2\Application Data\wklnhst.dat
2007-12-03 17:45 39,424 ----a-w C:\WINDOWS\zipinst.exe
2007-11-20 23:18 14,134 ---ha-w C:\Documents and Settings\Joy\Application Data\wklnhst.dat
2007-10-24 01:29 5,454,969 ---ha-w C:\Program Files\m-mp4-to-mp3-converter.exe
2007-10-23 14:56 715 ---ha-w C:\Program Files\WinRAR.lnk
2007-10-20 20:34 36,808,256 ---ha-w C:\Program Files\FIX_iTunesSetup701.exe
2007-10-07 15:17 1,829,362 ----a-w C:\Program Files\SWF setup.exe
2007-06-26 15:07 1,163,592 ---ha-w C:\Program Files\install_flash_player_macr.exe
2007-06-25 19:36 12,335,309 ---ha-w C:\Program Files\SetupSwishmax.exe
2007-06-25 19:00 1,274,768 ---ha-w C:\Program Files\flashplayer9_install_activex_061107.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2008-02-01 15:44 65536]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2007-12-28 11:15 204288]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2008-01-02 23:15 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2008-01-15 09:56 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2008-01-03 00:47 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2008-02-03 09:07 602182]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2008-02-03 09:07 122940]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2008-02-03 09:07 196608]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2008-02-03 09:07 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 09:29 88203 C:\WINDOWS\agrsmmsg.exe]
"NDSTray.exe"="NDSTray.exe" []
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2008-02-03 09:07 28672]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2008-02-03 09:07 65536]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2008-02-03 09:07 73728]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2008-02-03 09:07 671744]
"TPSMain"="TPSMain.exe" [2005-05-31 20:16 282624 C:\WINDOWS\system32\TPSMain.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2008-02-01 15:43 1077322]
"ZoomingHook"="ZoomingHook.exe" [2005-06-06 12:58 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2008-01-15 09:57 122880]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2008-02-03 09:07 53248]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-12-05 17:50 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TFncKy"="TFncKy.exe" []
"TDispVol"="TDispVol.exe" [2005-12-27 20:34 73728 C:\WINDOWS\system32\TDispVol.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-02-03 09:08 132496]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2008-02-03 09:08 151552]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2008-02-03 09:08 49152]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.e xe" [2008-02-03 09:08 155648]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-02-03 09:09 1443072]
"NodLogin"="C:\Program Files\ESET\ESET Smart Security\nodlogin.exe" [2008-02-03 09:09 298518]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-04 15:53 249896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2008-01-02 23:15 15360]
C:\Documents and Settings\Joy\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2005-03-17 15:06:14 59080]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-06-28 18:12:23 113664]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 06:21:22 288472]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-12-29 14:42:17 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-01-02 23:15 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\troy44 ]
C:\WINDOWS\troy44 .exe
R0 HFXP2;HFXP2;C:\WINDOWS\system32\DRIVERS\HFXP2.SYS [2007-01-23 01:26]
R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINDOWS\system32\Drivers\SSFS0BB8.SYS [2007-06-21 17:43]
R1 TPwSav;Common Driver;C:\WINDOWS\system32\Drivers\TPwSav.sys [2005-12-01 13:55]
R2 IDriveE Service;IDriveE Service;"C:\Program Files\IDrive\IDriveE Service.exe" [2008-01-16 16:56]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 03:35:53 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-04 07:10:03 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Rootkit scan 2008-02-13 01:42:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll
-> C:\WINDOWS\system32\TDispVol.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Streamload\MediaMax XL\StreamloadService.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
.
************************************************** ************************
.
Completion time: 2008-02-13 1:46:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-13 06:46:00
ComboFix2.txt 2008-02-12 04:48:04
ComboFix3.txt 2008-02-10 22:39:22
.
2008-02-01 17:29:55 --- E O F ---
HijackThis
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 1:47:19 AM, on 2/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\IDrive\IDriveE Service.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Streamload\MediaMax XL\StreamloadService.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Joy\Desktop\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
[Only Registered and Activated Users Can See Links. Click Here To Register...]
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] "C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] "C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" SVPwUTIL
O4 - HKLM\..\Run: [Tvs] "C:\Program Files\Toshiba\Tvs\TvsTray.exe"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe"
O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
O4 - HKLM\..\Run: [SmoothView] "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe"
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NodLogin] C:\Program Files\ESET\ESET Smart Security\nodlogin.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
[Only Registered and Activated Users Can See Links. Click Here To Register...]
O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) -
[Only Registered and Activated Users Can See Links. Click Here To Register...]
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
[Only Registered and Activated Users Can See Links. Click Here To Register...]
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) -
[Only Registered and Activated Users Can See Links. Click Here To Register...]
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) -
[Only Registered and Activated Users Can See Links. Click Here To Register...]
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) -
[Only Registered and Activated Users Can See Links. Click Here To Register...]
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsu****a Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: IDriveE Service - Pro Softnet Corporation - C:\Program Files\IDrive\IDriveE Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Streamload Service (StreamloadService) - Streamload - C:\Program Files\Streamload\MediaMax XL\StreamloadService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
--
End of file - 10525 bytes
Thank you again and again