Ok, here is the Combofix log followed by the new HJT log...
ComboFix 08-04-27.3 - Nixxer.Gixxer 2008-04-28 16:23:58.1 - NTFSx86
Running from: C:\Documents and Settings\Nixxer.Gixxer\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-28 )))))))))))))))))))))))))))))))
.
2008-04-23 18:42 . 2008-04-23 18:42 <DIR> d-------- C:\Program Files\FileASSASSIN
2008-04-23 18:27 . 2008-04-23 18:27 <DIR> d-------- C:\Program Files\Assassin G13
2008-04-23 18:25 . 2008-04-23 18:25 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-04-22 17:58 . 2007-08-13 18:52 66,048 --a------ C:\WINDOWS\ieResetIcons.exe
2008-04-22 17:58 . 2008-04-22 17:58 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-21 22:27 . 2008-04-21 22:44 <DIR> d-------- C:\Program Files\AIM6
2008-04-21 18:01 . 2008-04-21 18:01 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-21 18:01 . 2008-04-21 18:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-17 19:26 . 2008-04-22 18:02 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\skypePM
2008-04-17 19:26 . 2008-04-17 19:26 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-04-17 19:25 . 2008-04-22 22:32 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\Skype
2008-04-17 19:24 . 2008-04-17 19:24 <DIR> d-------- C:\Program Files\Skype
2008-04-17 19:24 . 2008-04-17 19:24 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-04-17 19:24 . 2008-04-17 19:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-04-17 19:20 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-04-17 19:20 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-04-17 19:20 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-17 19:20 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-16 21:49 . 2008-04-16 21:49 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-04-16 21:49 . 2008-04-16 21:50 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\Media Player Classic
2008-04-16 21:49 . 2007-09-04 09:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-04-16 18:15 . 2008-04-27 19:38 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\MxBoost
2008-04-16 18:13 . 2008-04-16 18:16 <DIR> d-------- C:\Program Files\Maxthon2
2008-04-15 23:29 . 2008-04-15 23:29 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-04-15 20:25 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-04-15 20:25 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-04-15 18:25 . 2008-04-15 18:25 33,412 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-04-15 17:33 . 2008-04-28 16:12 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-15 17:33 . 2008-04-15 17:33 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-15 17:32 . 2008-04-15 17:32 <DIR> d-------- C:\Program Files\iTunes
2008-04-15 17:32 . 2008-04-15 17:32 <DIR> d-------- C:\Program Files\iPod
2008-04-15 17:32 . 2008-04-15 18:16 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\Apple Computer
2008-04-15 17:31 . 2008-04-15 17:31 <DIR> d-------- C:\Program Files\Bonjour
2008-04-15 17:30 . 2008-04-15 17:31 <DIR> d-------- C:\Program Files\QuickTime
2008-04-15 17:30 . 2008-04-15 17:30 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-15 17:30 . 2008-04-15 17:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-15 17:30 . 2008-02-18 11:16 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-04-15 17:29 . 2008-04-15 17:29 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-04-15 17:29 . 2008-04-15 17:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-15 17:19 . 2008-04-15 17:20 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\WildTangent
2008-04-15 17:18 . 2008-04-15 17:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WildTangent
2008-04-15 16:46 . 2008-04-15 16:46 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-04-15 16:28 . 2008-04-15 16:28 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\acccore
2008-04-15 16:26 . 2008-04-15 16:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-04-15 16:08 . 2007-12-04 11:38 550,912 -----c--- C:\WINDOWS\system32\dllcache\oleaut32.dll
2008-04-15 15:46 . 2008-03-01 06:06 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-15 15:46 . 2007-06-30 20:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-15 15:46 . 2007-06-30 20:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-15 15:46 . 2008-03-01 06:06 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-15 15:46 . 2008-03-01 06:06 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-15 15:46 . 2008-03-01 06:06 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-15 15:46 . 2008-03-01 06:06 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-15 15:46 . 2008-03-01 06:06 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-15 15:46 . 2008-02-22 03:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-15 15:36 . 2006-06-03 04:40 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-04-15 02:05 . 2008-04-15 02:05 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-15 01:06 . 2006-08-21 02:14 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-04-15 01:06 . 2006-08-21 02:14 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-04-15 01:06 . 2006-08-21 05:21 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-04-15 00:56 . 2008-04-15 00:56 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-15 00:16 . 2007-07-09 06:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-04-14 23:44 . 2006-03-20 20:23 23,040 --------- C:\WINDOWS\kb913800.exe
2008-04-14 23:33 . 2008-04-14 23:33 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-14 23:33 . 2008-04-14 23:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-14 23:31 . 2008-04-14 23:31 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-14 23:30 . 2008-04-14 23:30 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-14 23:30 . 2008-04-28 16:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-14 23:10 . 2008-02-15 23:39 138,384 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-04-14 23:10 . 2008-02-15 23:39 52,496 --a------ C:\WINDOWS\system32\drivers\tmactmon.sys
2008-04-14 23:10 . 2008-02-15 23:39 52,240 --a------ C:\WINDOWS\system32\drivers\tmevtmgr.sys
2008-04-14 23:09 . 2008-04-14 23:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-04-14 22:59 . 2008-04-14 22:59 2 --a------ C:\WINDOWS\msoffice.ini
2008-04-14 22:45 . 2008-04-21 19:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 22:45 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-04-14 22:45 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-04-14 22:45 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-04-14 22:45 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-04-14 22:35 . 2008-04-14 22:35 <DIR> d---s---- C:\Documents and Settings\Nixxer.Gixxer\UserData
2008-04-14 22:34 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-04-14 22:33 . 2006-03-02 17:03 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\You've Got Pictures Screensaver
2008-04-14 22:33 . 2006-03-02 17:29 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\toshiba
2008-04-14 22:33 . 2006-03-02 16:54 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\Intuit
2008-04-14 22:33 . 2006-03-03 11:22 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\InterVideo
2008-04-14 22:33 . 2008-04-14 22:32 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\Intel
2008-04-14 22:33 . 2008-04-14 22:59 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer\Application Data\AOL
2008-04-14 22:33 . 2008-04-28 00:10 <DIR> d-------- C:\Documents and Settings\Nixxer.Gixxer
2008-04-14 22:33 . 2008-04-28 16:28 1,024 --ah----- C:\Documents and Settings\Nixxer.Gixxer\ntuser.dat.LOG
2008-04-14 22:32 . 2006-03-02 17:03 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2008-04-14 22:32 . 2006-03-02 17:29 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\toshiba
2008-04-14 22:32 . 2006-03-02 16:54 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Intuit
2008-04-14 22:32 . 2006-03-03 11:22 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\InterVideo
2008-04-14 22:32 . 2008-04-14 22:32 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-04-14 22:32 . 2006-03-02 17:16 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\AOL
2008-04-14 22:32 . 2008-04-14 22:32 <DIR> d-------- C:\Program Files\AVerMedia
2008-04-14 22:32 . 2008-04-14 22:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Intel
2008-04-14 22:32 . 2008-04-14 22:32 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-04-14 22:32 . 2008-04-14 22:32 21,275 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-04-14 22:32 . 2008-04-28 16:14 1,024 --ah----- C:\Documents and Settings\All Users\NTUSER.DAT.LOG
2008-04-14 22:31 . 2008-04-15 17:30 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-04-14 22:31 . 2008-04-14 22:32 1,024 --ah----- C:\Documents and Settings\Default User\ntuser.dat.LOG
2008-04-14 22:25 . 2005-11-03 15:21 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-22 05:36 --------- d-----w C:\Program Files\Viewpoint
2008-04-22 05:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-04-22 05:35 --------- d-----w C:\Program Files\Common Files\AOL
2008-04-22 05:08 --------- d-----w C:\Program Files\Common Files\Nullsoft
2008-04-17 13:53 --------- d-----w C:\Program Files\Google
2008-04-16 00:13 --------- d-----w C:\Program Files\Toshiba
2008-04-15 23:55 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-15 23:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-04-15 06:17 --------- d-----w C:\Program Files\Metamail Inc
2008-04-15 06:03 --------- d-----w C:\Program Files\Pure Networks
2008-04-15 05:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AOL
2008-04-15 05:32 --------- d-----w C:\Program Files\Intel
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-01-29 19:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 01:32 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:56 64512]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2005-12-29 15:21 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 17:32 761945]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 17:13 122880]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 06:20 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 18:37 151552]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-03 15:25 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 15:22 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 15:26 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 12:37 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 11:41 602182]
"CleanUp"="C:\PROGRA~1\McAfee.com\Shared\mcappins.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Toshiba Hotkey Utility"="c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= C:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-16 00:30:27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-28 16:27:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-28 16:30:01
ComboFix-quarantined-files.txt 2008-04-28 23:29:37
Pre-Run: 85,876,527,104 bytes free
Post-Run: 85,941,911,552 bytes free
205 --- E O F --- 2008-04-23 05:19:00
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:30:51 PM, on 4/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1208244371718
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 7863 bytes