| Answer» That's how I got rid of them.Deckard's System Scanner v20071014.68
 Run by Dave on 2008-06-26 22:53:55
 Computer is in Normal Mode.
 --------------------------------------------------------------------------------
 
 
 
 -- HijackThis (run as Dave.exe) ------------------------------------------------
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 10:53:58 PM, on 26/06/2008
 Platform: Windows Vista SP1 (WinNT 6.00.1905)
 MSIE: Internet Explorer v7.00 (7.00.6001.18000)
 Boot mode: Normal
 
 Running processes:
 C:\Windows\System32\smss.exe
 C:\Windows\system32\csrss.exe
 C:\Windows\system32\wininit.exe
 C:\Windows\system32\csrss.exe
 C:\Windows\system32\services.exe
 C:\Windows\system32\winlogon.exe
 C:\Windows\system32\lsass.exe
 C:\Windows\system32\lsm.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\System32\svchost.exe
 C:\Windows\system32\Ati2evxx.exe
 C:\Windows\System32\svchost.exe
 C:\Windows\System32\svchost.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\system32\SLsvc.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\system32\Ati2evxx.exe
 C:\Windows\system32\svchost.exe
 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 C:\Program Files\Alwil Software\Avast4\ashServ.exe
 C:\Windows\system32\Dwm.exe
 C:\Windows\Explorer.EXE
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\Windows\RtHDVCpl.exe
 C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
 C:\Program Files\Synaptics\SynTP\SynTPStart.exe
 C:\Program Files\ltmoh\ltmoh.exe
 C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
 C:\Program Files\Toshiba\SmoothView\SmoothView.exe
 C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
 C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
 C:\Program Files\ThreatFire\TFTray.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Alwil Software\Avast4\ashDisp.exe
 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
 C:\Program Files\Java\jre6\bin\jusched.exe
 C:\Windows\System32\spoolsv.exe
 C:\Program Files\Windows Sidebar\sidebar.exe
 C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
 C:\Windows\ehome\ehtray.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\system32\taskeng.exe
 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
 C:\Program Files\Synaptics\SynTP\SynToshiba.exe
 C:\Windows\ehome\ehmsas.exe
 C:\Windows\system32\taskeng.exe
 C:\Windows\system32\agrsmsvc.exe
 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
 C:\Program Files\Bonjour\mDNSResponder.exe
 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
 C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
 C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
 C:\Windows\system32\svchost.exe
 C:\Windows\system32\rpcnet.exe
 C:\Windows\system32\svchost.exe
 C:\Program Files\ThreatFire\TFService.exe
 C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
 C:\Windows\system32\TODDSrv.exe
 C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 C:\Windows\System32\svchost.exe
 C:\Windows\system32\SearchIndexer.exe
 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
 C:\Program Files\Windows Sidebar\sidebar.exe
 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
 C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
 C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
 C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 C:\Windows\system32\conime.exe
 C:\Windows\system32\wuauclt.exe
 C:\Windows\system32\taskeng.exe
 C:\Users\Dave\Desktop\dss.exe
 C:\DOWNLO~1\Dave.exe
 C:\Windows\system32\wbem\wmiprvse.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = http://exclusive.aliant.net/home.jsp
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O1 - Hosts: ::1 localhost
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
 O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
 O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
 O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
 O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
 O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
 O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
 O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
 O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
 O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
 O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
 O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
 O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
 O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
 O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
 O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
 O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
 O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
 O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
 O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
 O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
 O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
 O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
 O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
 O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\system32\rpcnet.exe
 O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
 O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
 O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
 O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
 O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
 O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
 O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 End of FILE - 9819 bytes
 
 -- Files created between 2008-05-26 and 2008-06-26 -----------------------------
 
 2008-06-22 20:33:44    0 d-------- C:\Program Files\PSCS2
 2008-06-09 00:31:20    0 d-------- C:\Midi Files
 2008-06-08 16:18:21    0 d-------- C:\Program Files\Alwil Software
 2008-05-29 11:51:25    0 --a------ C:\Program Files\gditst
 2008-05-29 11:50:20  306688 --a------ C:\Windows\IsUninst.exe
 2008-05-26 13:26:31    0 d-------- C:\Program Files\SpeedFan
 
 
 -- Find3M Report ---------------------------------------------------------------
 
 2008-06-26 22:35:48  17408 --a------ C:\Windows\system32\rpcnetp.exe
 2008-06-26 22:35:45  47104 --a------ C:\Windows\system32\rpcnet.dll
 2008-06-26 22:32:49    0 d-------- C:\Program Files\Common Files\Symantec Shared
 2008-06-25 17:50:04    0 d-------- C:\Program Files\Java
 2008-06-25 17:46:25    0 d-------- C:\Program Files\Common Files
 2008-06-12 03:07:21    0 d-------- C:\Program Files\Windows Mail
 2008-06-11 20:44:13    0 d-------- C:\Program Files\NCH Swift Sound
 2008-06-03 12:20:03  17408 --a------ C:\Windows\system32\rpcnetp.dll
 2008-05-25 11:53:35    0 d-------- C:\Program Files\coolpro2
 2008-05-23 16:11:15    0 d-------- C:\Program Files\Apple Software Update
 2008-05-23 16:07:18    0 d-------- C:\Program Files\iTunes
 2008-05-23 16:07:12    0 d-------- C:\Program Files\iPod
 2008-05-12 22:27:48    0 d-------- C:\Program Files\QuickTime
 2008-05-12 22:05:52    0 d-------- C:\Users\Dave\AppData\Roaming\Apple Computer
 2008-05-12 22:04:32    0 d-------- C:\Program Files\Bonjour
 2008-05-12 22:02:07    0 d-------- C:\Program Files\Common Files\Apple
 2008-05-11 19:57:07    0 d-------- C:\Users\Dave\AppData\Roaming\Media Player Classic
 2008-05-11 11:48:20    0 d-------- C:\Program Files\Microsoft Silverlight
 2008-04-30 11:42:01    0 d-------- C:\Program Files\ThreatFire
 2008-04-17 14:14:53  31007 --a------ C:\Users\Dave\AppData\Roaming\UserTile.png
 2008-04-05 14:13:53   174 --ahs---- C:\Program Files\desktop.ini
 2008-04-01 00:49:06  47104 --a------ C:\Windows\system32\rpcnet.exe
 
 
 -- Registry Dump ---------------------------------------------------------------
 
 *Note* empty entries & legit DEFAULT entries are not shown
 
 
 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
 25/06/2008 05:50 PM34816--a------C:\Program Files\Java\jre6\bin\jp2ssv.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [19/01/2008 04:38 AM]
 "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [10/11/2006 04:35 PM]
 "RtHDVCpl"="RtHDVCpl.exe" [09/08/2007 08:26 AM C:\Windows\RtHDVCpl.exe]
 "NDSTray.exe"="NDSTray.exe" []
 "SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [15/08/2007 04:31 AM]
 "LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [09/01/2007 03:23 AM]
 "TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [29/03/2007 10:39 AM]
 "HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [07/12/2006 04:49 PM]
 "SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [15/06/2007 09:01 PM]
 "00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [22/05/2007 04:32 PM]
 "Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" [22/05/2007 10:50 AM]
 "ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [24/04/2008 07:52 PM]
 "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [06/12/2007 09:12 AM]
 "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 10:16 PM]
 "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [28/03/2008 11:37 PM]
 "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/03/2008 10:36 AM]
 "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [15/05/2008 08:19 PM]
 "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [25/06/2008 05:50 PM]
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [19/01/2008 04:33 AM]
 "TOSCDSPD"="TOSCDSPD.EXE" []
 "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [19/01/2008 04:33 AM]
 "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43 AM]
 
 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
 Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 1:01:04 AM]
 
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
 "ConsentPromptBehaviorAdmin"=2 (0x2)
 "EnableLUA"=0 (0x0)
 "EnableUIADesktopToggle"=0 (0x0)
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
 @="Service"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
 @="Driver"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
 @="Driver"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
 @="Volume shadow copy"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
 @="IEEE 1394 Bus host controllers"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
 @="SBP2 IEEE 1394 Devices"
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
 @="SecurityDevices"
 
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
 LocalServicensi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc
 LocalSystemNetworkRestrictedhidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
 
 
 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad7b7f86-0bc7-11dd-a878-00a0d198404c}]
 AutoRun\command- F:\LaunchU3.exe
 
 
 [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed COMPONENTS\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
 C:\Windows\system32\unregmp2.exe /ShowWMP
 
 [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
 %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
 
 
 
 -- End of Deckard's System Scanner: finished at 2008-06-26 22:54:38 ------------
 
 Everything looks OK. don't know why HJT is disappearing.
 
 * Puzzled...I'm going to load it again and see what happens overnight.It's been 24 hrs. and Hijack is still on my laptop. It must have been the remnants of Norton that was messing things up. Another knock against Norton.Strange but it may have been Norton.
 
 Is everything OK now?Yup, PURRING right along. Thanks
 |