Everything requested is done. Here is the combofix log and below it is the new hijackthis log
Cheers again
ComboFix 07-12-20.1 - Cam&Emm 2007-12-20 13:37:56.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.536 [GMT 10:00]
Running from: C:\Documents and Settings\Cam&Emm\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-20 to 2007-12-20 )))))))))))))))))))))))))))))))
.
2007-12-18 13:11 . 2007-12-18 13:11 <DIR> d-------- C:\Program Files\Red Kawa
2007-12-18 13:11 . 2007-12-18 13:11 <DIR> d-------- C:\Program Files\AviSynth 2.5
2007-12-18 13:09 . 2007-12-18 13:09 <DIR> d-------- C:\Program Files\DVD Shrink
2007-12-18 13:09 . 2007-12-18 13:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-17 18:21 . 2007-12-17 18:38 <DIR> d-------- C:\Program Files\Tweak Manager
2007-12-17 17:41 . 2007-12-17 17:41 8,286 --a------ C:\WINDOWS\system32\mljjh.dll
2007-12-17 00:56 . 2007-12-17 00:56 8,286 --a------ C:\WINDOWS\system32\pmnnn.dll
2007-12-15 14:33 . 2007-12-15 14:33 8,286 --a------ C:\WINDOWS\system32\sstqr.dll
2007-12-14 17:25 . 2007-12-14 17:25 8,286 --a------ C:\WINDOWS\system32\awtsq.dll
2007-12-14 16:25 . 2007-12-14 16:25 8,286 --a------ C:\WINDOWS\system32\ssqro.dll
2007-12-14 01:34 . <DIR> C:\Documents and Settings\Cam2007-12-14 01:34 <DIR> Emm\gate5
2007-12-14 01:10 . 2005-10-21 11:47 30,592 --a------ C:\WINDOWS\system32\drivers\rndismpx.sys
2007-12-14 01:10 . 2005-10-21 11:47 12,800 --a------ C:\WINDOWS\system32\drivers\usb8023x.sys
2007-12-13 23:55 . 2007-12-13 23:55 8,286 --a------ C:\WINDOWS\system32\vtsqo.dll
2007-12-13 21:41 . 2007-12-13 21:41 8,286 --a------ C:\WINDOWS\system32\ssttr.dll
2007-12-13 15:32 . 2007-12-13 15:32 8,286 --a------ C:\WINDOWS\system32\ssqrp.dll
2007-12-12 16:15 . 2007-12-12 16:15 8,286 --a------ C:\WINDOWS\system32\ddayw.dll
2007-12-12 13:30 . 2007-12-12 13:30 8,286 --a------ C:\WINDOWS\system32\vtutu.dll
2007-12-11 14:52 . 2006-04-10 18:05 104,576 --a------ C:\WINDOWS\system32\drivers\wceusbsh.sys
2007-12-11 14:52 . 2006-04-10 18:05 104,576 --a--c--- C:\WINDOWS\system32\dllcache\wceusbsh.sys
2007-12-11 14:05 . 2007-12-11 14:05 8,286 --a------ C:\WINDOWS\system32\awvvt.dll
2007-12-10 00:35 . 2007-12-10 00:35 8,286 --a------ C:\WINDOWS\system32\pmkhh.dll
2007-12-09 23:35 . 2007-12-09 23:35 8,286 --a------ C:\WINDOWS\system32\jkhfd.dll
2007-12-09 02:06 . 2007-12-09 02:06 8,286 --a------ C:\WINDOWS\system32\awtqn.dll
2007-12-08 01:20 . 2007-12-08 01:20 8,286 --a------ C:\WINDOWS\system32\mljge.dll
2007-12-08 00:20 . 2007-12-19 14:42 8,286 --a------ C:\WINDOWS\system32\mllmj.dll
2007-12-07 00:22 . 2007-12-07 00:22 8,286 --a------ C:\WINDOWS\system32\gebcd.dll
2007-12-06 00:17 . <DIR> C:\Documents and Settings\Cam2007-12-06 00:17 <DIR> Emm\Application Data\skypePM
2007-12-06 00:17 . 2007-12-06 00:17 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-12-06 00:14 . 2007-12-06 00:14 <DIR> d-------- C:\Program Files\Skype
2007-12-06 00:14 . <DIR> C:\Documents and Settings\Cam2007-12-06 00:14 <DIR> Emm\Application Data\Skype
2007-12-06 00:13 . 2007-12-06 00:14 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-12-06 00:13 . 2007-12-06 00:13 8,286 --a------ C:\WINDOWS\system32\mljgg.dll
2007-12-06 00:12 . 2007-12-06 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2007-12-06 00:09 . 2007-12-20 13:18 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-06 00:09 . 2007-12-06 00:09 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-06 00:06 . 2007-12-06 00:06 268 --ah----- C:\sqmdata10.sqm
2007-12-06 00:06 . 2007-12-06 00:06 244 --ah----- C:\sqmnoopt10.sqm
2007-12-05 23:17 . 2007-12-05 23:17 8,286 --a------ C:\WINDOWS\system32\mlljg.dll
2007-12-05 16:53 . 2007-12-05 16:53 268 --ah----- C:\sqmdata09.sqm
2007-12-05 16:53 . 2007-12-05 16:53 244 --ah----- C:\sqmnoopt09.sqm
2007-12-05 16:12 . 2007-12-05 16:12 268 --ah----- C:\sqmdata08.sqm
2007-12-05 16:12 . 2007-12-05 16:12 244 --ah----- C:\sqmnoopt08.sqm
2007-12-05 00:21 . 2007-12-05 00:21 268 --ah----- C:\sqmdata07.sqm
2007-12-05 00:21 . 2007-12-05 00:21 244 --ah----- C:\sqmnoopt07.sqm
2007-12-04 16:36 . 2007-12-04 16:36 268 --ah----- C:\sqmdata06.sqm
2007-12-04 16:36 . 2007-12-04 16:36 244 --ah----- C:\sqmnoopt06.sqm
2007-12-04 00:05 . 2007-12-04 00:05 268 --ah----- C:\sqmdata05.sqm
2007-12-04 00:05 . 2007-12-04 00:05 244 --ah----- C:\sqmnoopt05.sqm
2007-12-03 21:31 . <DIR> C:\Documents and Settings\Cam2007-12-03 21:31 <DIR> Emm\Application Data\WinRAR
2007-12-03 21:30 . 2007-12-03 21:30 268 --ah----- C:\sqmdata04.sqm
2007-12-03 21:30 . 2007-12-03 21:30 244 --ah----- C:\sqmnoopt04.sqm
2007-12-03 20:59 . 2007-12-03 20:59 268 --ah----- C:\sqmdata03.sqm
2007-12-03 20:59 . 2007-12-03 20:59 244 --ah----- C:\sqmnoopt03.sqm
2007-12-03 20:48 . 2007-12-03 20:48 268 --ah----- C:\sqmdata02.sqm
2007-12-03 20:48 . 2007-12-03 20:48 244 --ah----- C:\sqmnoopt02.sqm
2007-12-03 20:40 . 2007-12-03 20:40 268 --ah----- C:\sqmdata01.sqm
2007-12-03 20:40 . 2007-12-03 20:40 244 --ah----- C:\sqmnoopt01.sqm
2007-12-03 17:19 . 2007-12-03 17:19 268 --ah----- C:\sqmdata00.sqm
2007-12-03 17:19 . 2007-12-03 17:19 244 --ah----- C:\sqmnoopt00.sqm
2007-11-25 14:10 . 2006-03-19 07:02 196,608 --a------ C:\WINDOWS\ResEnu.RIM.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-20 03:33 --------- d-----w C:\Program Files\Telstra Turbo Card Manager
2007-12-19 05:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-12-19 05:21 --------- d-----w C:\Program Files\Nokia
2007-12-19 05:14 --------- d-----w C:\Documents and Settings\Cam&Emm\Application Data\Skype
2007-12-19 05:03 --------- d-----w C:\Documents and Settings\Cam&Emm\Application Data\skypePM
2007-12-17 08:05 --------- d-----w C:\Program Files\Trend Micro
2007-12-13 15:10 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-12-05 14:43 --------- d-----w C:\Program Files\Microsoft LifeCam
2007-12-04 12:03 22,224 ----a-w C:\Documents and Settings\Cam&Emm\Application Data\GDIPFONTCACHEV1.DAT
2007-12-03 05:19 --------- d-----w C:\Documents and Settings\Cam&Emm\Application Data\toshiba
2007-11-25 04:57 --------- d-----w C:\Program Files\MySpace
2007-11-17 01:06 --------- d-----w C:\Documents and Settings\Cam&Emm\Application Data\Nokia Multimedia Player
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 04:19 --------- d-----w C:\Documents and Settings\Cam&Emm\Application Data\Apple Computer
2007-11-07 07:47 --------- d-----w C:\Program Files\iTunes
2007-11-07 07:46 --------- d-----w C:\Program Files\iPod
2007-11-07 07:45 --------- d-----w C:\Program Files\QuickTime
2007-11-07 07:42 --------- d-----w C:\Program Files\Common Files\Apple
2007-11-07 07:42 --------- d-----w C:\Program Files\Apple Software Update
2007-10-31 04:09 30,464 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 07:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-21 04:00 --------- d-----w C:\Program Files\MSXML 6.0
2007-10-20 04:48 --------- d-----w C:\Documents and Settings\Cam&Emm\Application Data\Nokia
2007-10-20 04:44 --------- d-----w C:\Program Files\Nokia Map Loader
2007-10-20 04:42 --------- d-----w C:\Program Files\MSBuild
2007-10-20 04:39 --------- d-----w C:\Program Files\Reference Assemblies
2007-10-20 03:26 --------- d-----w C:\Documents and Settings\Cam&Emm\Application Data\Sony
2007-10-20 03:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony
2007-10-20 03:19 --------- d-----w C:\Program Files\Sony
2007-10-20 03:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-20 03:04 --------- d-----w C:\Documents and Settings\Cam&Emm\Application Data\Sony Setup
2007-10-20 03:02 --------- d-----w C:\Program Files\Sony Setup
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 17:32]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" []
"H/PC Connection Agent"="C:\PROGRA~1\MI3AA1~1\wcescomm.exe" [2006-06-26 16:13]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-23 14:05]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-02 11:03]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 10:59]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 22:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-04-15 08:18 C:\WINDOWS\system32\nwiz.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2004-03-24 00:40]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-30 14:06]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-04-06 09:25]
"NDSTray.exe"="NDSTray.exe" []
"TPSMain"="TPSMain.exe" [2004-12-29 09:02 C:\WINDOWS\system32\TPSMain.exe]
"ZoomingHook"="ZoomingHook.exe" [2004-05-01 16:03 C:\WINDOWS\system32\ZoomingHook.exe]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-16 09:51]
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 16:02]
"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2005-02-23 06:51]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-01-14 18:05]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-26 08:59]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-08 07:03]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 03:10 C:\WINDOWS\agrsmmsg.exe]
"LtMoh"="C:\\Program Files\\ltmoh\\Ltmoh.exe" [2003-09-06 12:16]
"TCtryIOHook"="TCtrlIOHook.exe" [2004-05-01 14:03 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TFncKy"="TFncKy.exe" []
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-12-29 14:52]
"VX6000"="C:\WINDOWS\vVX6000.exe" [2006-10-13 17:04]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 19:21]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 17:01]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-30 14:11:03]
Exif Launcher S.lnk - C:\Program Files\FinePixViewerS\QuickDCF2.exe [2007-09-14 13:13:51]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
R1 SerTVOutCtlr;TOSHIBA Controls Driver -EPIOMngr;C:\WINDOWS\system32\drivers\EPIOMngr.sys [2004-07-30 15:05]
R1 SrvcEKIOMngr;SrvcEKIOMngr;C:\WINDOWS\system32\Drivers\EKIoMngr.sys [2005-04-21 12:59]
R1 SrvcSSIOMngr;SrvcSSIOMngr;C:\WINDOWS\system32\Drivers\SSIoMngr.sys [2005-04-21 12:59]
R1 TPwSav;Common Driver;C:\WINDOWS\system32\Drivers\TPwSav.sys [2005-02-26 12:22]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-10-13 17:01]
R3 ZTEusbmdm6k;ZTE Proprietary USB Driver;C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys [2006-11-14 09:08]
R3 ZTEusbnmea;ZTE NMEA Port;C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys [2006-11-14 09:08]
R3 ZTEusbser6k;ZTE Diagnostic Port;C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys [2006-11-14 09:08]
S1 StickyMesger;StickyMesger;C:\Program Files\TOSHIBA\Accessibility\StickyMesger.sys []
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2007-10-31 14:09]
S3 VX6000;Microsoft LifeCam VX-6000;C:\WINDOWS\system32\DRIVERS\VX6000Xp.sys [2006-10-13 17:04]
.
Contents of the 'Scheduled Tasks' folder
"2007-11-21 02:20:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-20 13:41:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-20 13:43:16
C:\ComboFix2.txt ... 2007-12-20 13:19
.
2007-12-12 03:09:23 --- E O F ---
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:51:31 PM, on 20/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\WINDOWS\vVX6000.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccVScan.exe
C:\Program Files\Telstra Turbo Card Manager\Telstra Turbo Card Manager.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bigpond.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Exif Launcher S.lnk = C:\Program Files\FinePixViewerS\QuickDCF2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCC3D735-18B0-4DC8-B520-F200301980F0}: NameServer = 203.50.2.71 139.130.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
--
End of file - 8421 bytes