It worked

! I rebooted and the error message did not come up. I'm going to try a couple more things to make sure its really gone (logging in and out, more reboots) but my hopes are up.
There is only one more problem, I meant to tell you earlier but when I picked up my "sledge hammer" and went through my C drive deleting files I messed up my computers Power options. I have a Toshiba laptop so it is defaulted to a program called "TOSHIBA Power Save Setup". The error comes up whenever I start the computer and it says it cannot start the Power Save program. It says it needs to be enabled it (Properties > Screensaver > Power Options) and I have to choose it from the drop down menu. It already is chosen from the menu but the error keeps coming up. I'm pretty sure I did this and not the virus. If you can help me with this I can give you the specifics of the error. If you can't does What the Tech have a forum for these kinds of bugs?
Anyways heres the log files, hope the problem doesn't return =)
=====Combo-Fix
ComboFix 08-03-10.1 - Daniel 2008-03-14 4:32:06.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Daniel\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-02-14 to 2008-03-14 )))))))))))))))))))))))))))))))
.
2008-03-10 07:27 . 2008-03-14 04:33 0 –a—— C:\WINDOWS\system.ini
2008-03-10 07:16 . 2008-03-10 07:16 d——– C:\Documents and Settings\Daniel\Application Data\Malwarebytes
2008-03-10 07:15 . 2008-03-10 07:17 d——– C:\Program Files\Anti-Malware
2008-03-10 07:15 . 2008-03-10 07:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-10 03:16 . 2008-03-10 03:21 d——– C:\Program Files\RegCure
2008-03-10 02:45 . 2008-03-10 03:09 d——– C:\Documents and Settings\David Dara.DARAFAMILYLATOP\Application Data\AVG7
2008-03-10 02:44 . 2006-02-16 02:18 d——– C:\Documents and Settings\David Dara.DARAFAMILYLATOP\WINDOWS
2008-03-10 02:44 . 2006-02-16 02:56 d——– C:\Documents and Settings\David Dara.DARAFAMILYLATOP\Application Data\You've Got Pictures Screensaver
2008-03-10 02:44 . 2006-02-16 02:18 d——– C:\Documents and Settings\David Dara.DARAFAMILYLATOP\Application Data\toshiba
2008-03-10 02:44 . 2008-02-02 09:38 d——– C:\Documents and Settings\David Dara.DARAFAMILYLATOP\Application Data\Intel
2008-03-10 02:44 . 2008-02-02 17:39 d——– C:\Documents and Settings\David Dara.DARAFAMILYLATOP\Application Data\AOL
2008-03-10 02:41 . 2008-03-10 02:41 d——– C:\Documents and Settings\Hannah\Application Data\AVG7
2008-03-10 02:40 . 2006-02-16 02:18 d——– C:\Documents and Settings\Hannah\WINDOWS
2008-03-10 02:40 . 2006-02-16 02:56 d——– C:\Documents and Settings\Hannah\Application Data\You've Got Pictures Screensaver
2008-03-10 02:40 . 2006-02-16 02:18 d——– C:\Documents and Settings\Hannah\Application Data\toshiba
2008-03-10 02:40 . 2008-02-02 09:38 d——– C:\Documents and Settings\Hannah\Application Data\Intel
2008-03-10 02:40 . 2008-02-02 17:39 d——– C:\Documents and Settings\Hannah\Application Data\AOL
2008-03-10 02:28 . 2008-03-10 02:28 d——– C:\WINDOWS\system32\CatRoot
2008-03-10 02:28 . 2008-03-10 02:45 d–hs—- C:\WINDOWS\Installer
2008-03-10 02:28 . 2008-03-10 02:28 d——– C:\Documents and Settings\Amanda\Application Data\AVG7
2008-03-10 02:27 . 2006-02-16 02:18 d——– C:\Documents and Settings\Amanda\WINDOWS
2008-03-10 02:27 . 2006-02-16 02:56 d——– C:\Documents and Settings\Amanda\Application Data\You've Got Pictures Screensaver
2008-03-10 02:27 . 2006-02-16 02:18 d——– C:\Documents and Settings\Amanda\Application Data\toshiba
2008-03-10 02:27 . 2008-02-02 09:38 d——– C:\Documents and Settings\Amanda\Application Data\Intel
2008-03-10 02:27 . 2008-02-02 17:39 d——– C:\Documents and Settings\Amanda\Application Data\AOL
2008-03-10 02:11 . 2008-03-10 02:11 d——– C:\Documents and Settings\Daniel\Application Data\SUPERAntiSpyware.com
2008-03-10 02:01 . 2006-02-16 02:18 d——– C:\Documents and Settings\Daniel\WINDOWS
2008-03-10 02:01 . 2006-02-16 02:56 d——– C:\Documents and Settings\Daniel\Application Data\You've Got Pictures Screensaver
2008-03-10 02:01 . 2006-02-16 02:18 d——– C:\Documents and Settings\Daniel\Application Data\toshiba
2008-03-10 02:01 . 2008-02-02 09:38 d——– C:\Documents and Settings\Daniel\Application Data\Intel
2008-03-10 02:01 . 2008-03-14 04:30 d——– C:\Documents and Settings\Daniel\Application Data\AVG7
2008-03-10 02:01 . 2008-02-02 17:39 d——– C:\Documents and Settings\Daniel\Application Data\AOL
2008-03-10 01:11 . 2004-08-04 00:56 33,280 –a—— C:\WINDOWS\system32\rundll32.exe
2008-03-10 01:07 . 2008-03-10 01:07 d——– C:\Documents and Settings\Administrator\Application Data\AVG7
2008-03-09 09:19 . 2008-03-09 09:19 d——– C:\Program Files\SUPERAntiSpyware
2008-03-09 09:19 . 2008-03-09 09:19 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-07 10:43 . 2008-03-07 10:43 d——– C:\Documents and Settings\David Dara\Application Data\Move Networks
2008-03-02 10:44 . 2004-08-04 00:08 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-03-02 10:44 . 2004-08-04 00:08 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-20 09:12 . 2008-02-20 09:12 d——– C:\Documents and Settings\David Dara\Bluetooth Software
2008-02-20 09:12 . 2004-08-04 01:56 21,504 –a—— C:\WINDOWS\system32\hidserv.dll
2008-02-20 09:12 . 2004-08-04 01:56 21,504 –a–c— C:\WINDOWS\system32\dllcache\hidserv.dll
2008-02-20 09:08 . 2008-02-20 09:08 d——– C:\Program Files\ANYCOM
2008-02-20 09:08 . 2006-08-18 19:26 77,824 –a—— C:\WINDOWS\system32\btw_ci.dll
2008-02-20 09:08 . 2006-08-18 19:06 67,384 –a—— C:\WINDOWS\system32\drivers\btwusb.sys
2008-02-20 09:08 . 2006-08-18 19:44 19,436 –a—— C:\WINDOWS\system32\drivers\frmupgr.sys
2008-02-20 09:00 . 2008-02-20 09:00 12,254,415 ——— C:\avg7qt.dat
2008-02-20 09:00 . 2004-08-03 23:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-02-20 09:00 . 2004-08-03 23:58 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-02-20 08:45 . 2008-02-20 08:45 d——– C:\Program Files\Common Files\Adobe
2008-02-20 08:37 . 2008-02-20 08:37 d——– C:\Documents and Settings\David Dara\Application Data\AdobeUM
2008-02-19 01:08 . 2008-02-19 01:08 21 –a—— C:\WINDOWS\atid.ini
2008-02-17 11:52 . 2008-02-17 11:52 d——– C:\Program Files\Common Files\IviSDK
2008-02-17 11:52 . 2006-09-13 12:58 45,316 –a—— C:\WINDOWS\system32\HCWTVServer.tlb
2008-02-17 11:48 . 2008-02-17 11:59 d——– C:\MyVideos
2008-02-17 11:48 . 2006-10-24 15:46 716,873 –a—— C:\WINDOWS\system32\hcwtvwnd.dll
2008-02-17 11:47 . 2008-03-02 11:01 2,115 –a—— C:\WINDOWS\HCWPNP.INI
2008-02-17 11:44 . 2004-08-04 01:56 90,624 –a—— C:\WINDOWS\system32\kswdmcap.ax
2008-02-17 11:41 . 2008-03-02 11:13 d——– C:\Program Files\WinTV
2008-02-17 11:41 . 2001-07-19 10:44 393,216 –a—— C:\WINDOWS\system32\hcwsnbd9.dll
2008-02-17 11:36 . 2008-02-17 11:36 d——– C:\WinTV-HVR950
2008-02-17 11:36 . 2006-09-13 13:21 292,864 –a—— C:\WINDOWS\system32\drivers\emBDA.sys
2008-02-17 11:36 . 2006-09-06 20:14 249,912 ——— C:\WINDOWS\system32\hcwpnp32.dll
2008-02-17 11:36 . 2006-05-16 16:34 98,360 –a—— C:\WINDOWS\system32\hcwi2c32.dll
2008-02-17 11:36 . 2006-05-31 13:24 61,440 –a—— C:\WINDOWS\HCWemMON.exe
2008-02-17 11:36 . 2005-09-16 17:39 40,960 –a—— C:\WINDOWS\system32\bdadll.dll
2008-02-17 11:36 . 2006-05-08 09:54 36,921 –a—— C:\WINDOWS\system32\hcwutl32.dll
2008-02-17 11:36 . 2006-09-13 13:20 32,768 –a—— C:\WINDOWS\system32\emPRP.ax
2008-02-17 11:36 . 2006-09-13 13:21 27,904 –a—— C:\WINDOWS\system32\drivers\emOEM.sys
2008-02-17 11:36 . 2005-11-01 18:33 20,736 –a—— C:\WINDOWS\system32\drivers\emAudio.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 15:15 ——— d—–w C:\Documents and Settings\David Dara\Application Data\AVG7
2008-03-08 03:22 ——— d—–w C:\Program Files\WarRock
2008-02-20 16:06 ——— d—–w C:\Program Files\Metamail Inc
2008-02-20 16:05 ——— d—–w C:\Program Files\TOSHIBA
2008-02-20 15:33 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-20 15:32 ——— d—–w C:\Program Files\Common Files\Nullsoft
2008-02-19 08:08 ——— d—–w C:\Program Files\Viewpoint
2008-02-19 07:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-02-17 18:52 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-09 03:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-08 10:53 ——— d—–w C:\Program Files\Xfire
2008-02-08 03:21 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-08 03:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-07 17:42 ——— d—–w C:\Documents and Settings\David Dara\Application Data\Xfire
2008-02-03 03:32 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-02-03 01:16 ——— d—–w C:\Documents and Settings\David Dara\Application Data\InterVideo
2008-02-03 01:12 ——— d—–w C:\Documents and Settings\David Dara\Application Data\Template
2008-02-03 00:49 ——— d—–w C:\Program Files\Toshiba Games
2008-02-03 00:39 ——— d—–w C:\Documents and Settings\David Dara\Application Data\AOL
2008-02-03 00:39 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AOL
2008-02-02 16:39 21,275 —-a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-02-02 16:39 ——— d—–w C:\Program Files\Intel
2008-02-02 16:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intel
2008-02-02 16:38 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-02-02 16:38 ——— d—–w C:\Documents and Settings\David Dara\Application Data\Intel
2008-02-02 16:38 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Intel
2008-02-02 16:11 ——— d—–w C:\Program Files\AVerMedia
2008-02-02 16:10 ——— d—–w C:\Program Files\InterVideo
2008-02-02 16:10 ——— d—–w C:\Program Files\Common Files\InterVideo
2008-01-31 02:02 54,608 —-a-w C:\WINDOWS\system32\xfcodec.dll
2004-07-22 18:51 3,432,656 —-a-w C:\Program Files\ManagedDX.CAB
2004-07-20 06:58 1,156,363 —-a-w C:\Program Files\BDANT.cab
2004-07-20 06:53 976,020 —-a-w C:\Program Files\BDAXP.cab
2004-07-09 22:17 13,265,040 —-a-w C:\Program Files\dxnt.cab
2004-07-09 17:13 703,080 —-a-w C:\Program Files\BDA.cab
2004-07-09 17:13 15,493,481 —-a-w C:\Program Files\DirectX.cab
2004-07-09 12:08 472,576 —-a-w C:\Program Files\dxsetup.exe
2004-07-09 12:08 2,242,560 —-a-w C:\Program Files\dsetup32.dll
2004-07-09 11:03 62,976 —-a-w C:\Program Files\DSETUP.dll
.
——- Sigcheck ——-
2004-08-10 05:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-10 05:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2007-03-08 08:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll
2007-03-08 08:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\dllcache\user32.dll
2004-08-10 05:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2005-09-02 16:53 660480 97a6fd7cafd688cf2c78939ebaf0cd0c C:\WINDOWS\$hf_mig$\KB896688\SP2QFE\wininet.dll
2007-10-10 16:47 825344 0e5d918f87efa7d2424d66b499c7eb04 C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-06 19:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2004-08-10 05:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB896688$\wininet.dll
2005-09-02 16:52 658432 af61ebb1f550175eff406d545d6ab086 C:\WINDOWS\$NtUninstallKB912945$\wininet.dll
2006-01-09 11:02 662016 dde9597a3311748c1519444e2bc147bd C:\WINDOWS\ie7\wininet.dll
2007-08-13 19:54 818688 a4a0fc92358f39538a6494c42ef99fe9 C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll
2007-10-10 16:56 824832 30c1e0f34ad2972c72a01db5c74ab065 C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
2007-10-10 16:56 824832 30c1e0f34ad2972c72a01db5c74ab065 C:\WINDOWS\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2GDR\wininet.dll
2007-10-10 16:47 825344 0e5d918f87efa7d2424d66b499c7eb04 C:\WINDOWS\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2QFE\wininet.dll
2007-10-10 22:57 666112 80d660a49e0d118144423099b2a9f5da C:\WINDOWS\SoftwareDistribution\Download\fa58243222bcfe35e5467668df396003\sp2qfe\wininet.dll
2007-12-06 19:21 824832 806d274c9a6c3aaea5eae8e4af841e04 C:\WINDOWS\system32\wininet.dll
2007-12-06 19:21 824832 806d274c9a6c3aaea5eae8e4af841e04 C:\WINDOWS\system32\dllcache\wininet.dll
2005-05-25 12:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-10 05:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
2005-05-25 12:04 359808 88763a98a4c26c409741b4aa162720c9 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-10 05:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2004-08-10 05:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
2004-08-10 05:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2004-08-10 05:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 17:34 2056832 81013f36b21c7f72cf784cc6731e0002 C:\WINDOWS\$NtUninstallKB896256$\ntkrnlpa.exe
2005-09-28 16:35 2015744 48472d224e1703882b4de0e28e205e9b C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 02:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2007-02-28 02:15 2017280 2dfb215e291e3d9b1cf9a6739b3bf16c C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 02:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2005-03-01 18:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2004-08-10 05:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 17:59 2179328 4d4cf2c14550a4b7718e94a6e581856e C:\WINDOWS\$NtUninstallKB896256$\ntoskrnl.exe
2005-09-28 17:02 2136064 25c36dbc46e8eff2a811769a60715ac5 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 02:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2007-02-28 02:53 2137600 e6679c3023b17d8b78946bc5df53fa20 C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 02:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\explorer.exe
2007-06-13 04:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 05:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-03-12_ 7.06.52.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-02-04 23:09:46 18,214,008 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-03-05 16:30:54 19,148,408 —-a-w C:\WINDOWS\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24 1694208]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 01:32 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TFncKy"="TFncKy.exe" []
"TDispVol"="TDispVol.exe" [2005-03-11 16:03 73728 C:\WINDOWS\system32\TDispVol.exe]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-27 22:55 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-27 22:52 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-27 22:55 118784]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:56 64512]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 15:02 352256]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 01:34 82009]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 01:32 761945]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 07:29 88203 C:\WINDOWS\agrsmmsg.exe]
"NDSTray.exe"="NDSTray.exe" []
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 13:25 73728]
"TPSMain"="TPSMain.exe" [2005-05-31 22:00 282624 C:\WINDOWS\system32\TPSMain.exe]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 17:13 122880]
"dla"="C:\WINDOWS\system32\dla\DLACTRLW.exe" [2005-10-06 06:20 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 18:37 151552]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 12:41 602182]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-07 20:34 579072]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-16 02:56 98304]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 13:37 667718]
"emMON"="HCWemMON.exe" [2006-05-31 13:24 61440 C:\WINDOWS\HCWemMON.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-07 20:21 219136]
C:\Documents and Settings\David Dara\Start Menu\Programs\Startup\
TitanTV Remote Scheduler.lnk - C:\Program Files\WinTV\Scheduler\TitanTV.exe [2008-02-17 12:14:24 782336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= C:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys [2005-01-12 01:05]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2006-10-03 16:58]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-09-09 15:47]
S3 USB28xxBGA;WinTV HVR-900;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2006-09-13 13:21]
S3 USB28xxOEM;WinTV OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2006-09-13 13:21]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-14 11:29:59 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-03-10 10:18:43 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-14 04:33:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\system32\TDispVol.dll
.
Completion time: 2008-03-14 4:34:27
ComboFix2.txt 2008-03-12 14:07:04
.
2008-03-12 14:10:03 — E O F —
=====HTJ Log
Logfile of HijackThis v1.99.1
Scan saved at 7:12:31 AM, on 3/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ANYCOM\Blue USB-200-250\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\HCWemMON.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ANYCOM\Blue USB-200-250\BTTray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Documents and Settings\Daniel\Desktop\Hi Jack This\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [emMON] HCWemMON.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ANYCOM\Blue USB-200-250\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ANYCOM\Blue USB-200-250\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ANYCOM\Blue USB-200-250\bin\btwdins.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Thank you so much for your help and sticking with me even though the virus thwarted many of our attempts to get rid of it.