1
Tech Clinic / coolwwwsearch leftover (again) ;(
« on: March 11, 2005, 05:12:19 AM »
ok thankx..
here is DLLCompare log:
* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
O^E says: "There were no files found
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\'
\' />"
________________________________________________
1,249 items found: 1,249 files, 0 directories.
Total of file sizes: 246,301,550 bytes 234.89 M
Administrator Account = True
--------------------End log---------------------
i guess thats good ... here is StartDreck Log:
StartDreck (build 2.1.7 public stable) - 2005-03-11 @ 11:08:03 (GMT +01:00)
Platform: Windows XP (Win NT 5.1.2600 Service Pack 1)
Internet Explorer: 6.0.2800.1106
Logged in as HH
»Registry
»Run Keys
»Current User
»Run
*CTFMON.EXE=C:\WINDOWS\System32\ctfmon.exe
*MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
»RunOnce
»Default User
»Run
*CTFMON.EXE=C:\WINDOWS\System32\CTFMON.EXE
»RunOnce
»Local Machine
»Run
*NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
*C-Media Mixer=Mixer.exe /startup
*APVXDWIN="D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE" /s
*QuickTime Task="D:\movie stuff\QuickTime\qttask.exe" -atboottime
*EPSON Stylus CX3200=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
*zafit=C:\WINDOWS\zafit.exe
*SunJavaUpdateSched=C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
*WinFoxV2=C:\WINDOWS\System32\WF2K.EXE Initial
*WinFast2KLoadDefault=rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
*SoundMan=SOUNDMAN.EXE
*nwiz=nwiz.exe /install
*NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
*NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
*sp=rundll32 C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll,DllInstall
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
»RunOnce
»RunServices
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»Browser Helper Objects (LM)
*{4613BB30-5B2F-40FD-AC33-E6661DB18062}
`InprocServer32=C:\WINDOWS\System32\colg.dll
»Files
»System/Drivers
»Running Processes
+0=<idle>
+4=<system>
+600=\SystemRoot\System32\smss.exe
+672=\??\C:\WINDOWS\system32\csrss.exe
+696=\??\C:\WINDOWS\system32\winlogon.exe
+740=C:\WINDOWS\system32\services.exe
+752=C:\WINDOWS\system32\lsass.exe
+936=C:\WINDOWS\system32\svchost.exe
+1024=C:\WINDOWS\System32\svchost.exe
+1140=C:\WINDOWS\System32\svchost.exe
+1216=C:\WINDOWS\System32\svchost.exe
+1416=C:\WINDOWS\system32\spoolsv.exe
+1428=C:\WINDOWS\Explorer.EXE
+1560=C:\WINDOWS\Mixer.exe
+1628=D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE
+1660=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
+1668=C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
+1684=C:\WINDOWS\System32\WF2K.EXE
+1712=C:\WINDOWS\SOUNDMAN.EXE
+1732=C:\WINDOWS\System32\RUNDLL32.EXE
+1764=C:\WINDOWS\System32\rundll32.exe
+1772=C:\WINDOWS\System32\ctfmon.exe
+1992=C:\WINDOWS\System32\alg.exe
+2008=D:\Maya 6\docs\Wrapper.exe
+2028=C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
+2040=C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
+224=C:\WINDOWS\System32\nvsvc32.exe
+228=C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
+408=D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
+872=D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
+976=C:\WINDOWS\System32\svchost.exe
+1000=C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
+1280=D:\Misc Apps\Panda Anti-Virus\AVENGINE.EXE
+1324=D:\Maya 6\docs\jre\bin\java.exe
+2412=D:\Misc Apps\Panda Anti-Virus\WebProxy.exe
+1832=D:\Misc Apps\Spybot - Search & Destroy\SpybotSD.exe
+2328=C:\WINDOWS\regedit.exe
+2348=C:\Program Files\Internet Explorer\iexplore.exe
+3508=C:\Documents and Settings\Henrik & Hilde\Desktop\eugen\startdreck\StartDreck.exe
»Application specific
and here is the hijackthis log i got afterwards...
Logfile of HijackThis v1.99.1
Scan saved at 11:09:21, on 11-03-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\System32\WF2K.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Maya 6\docs\Wrapper.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
D:\Misc Apps\Panda Anti-Virus\AVENGINE.EXE
D:\Maya 6\docs\jre\bin\java.exe
D:\Misc Apps\Panda Anti-Virus\WebProxy.exe
D:\Misc Apps\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Henrik & Hilde\Local Settings\Temp\Temporary Directory 3 for hijackthis_199.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {4613BB30-5B2F-40FD-AC33-E6661DB18062} - C:\WINDOWS\System32\colg.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [APVXDWIN] "D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "D:\movie stuff\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [zafit] C:\WINDOWS\zafit.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [WinFoxV2] C:\WINDOWS\System32\WF2K.EXE Initial
O4 - HKLM\..\Run: [WinFast2KLoadDefault] rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft\Office XP\Office10\OSA.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O18 - Filter: text/html - {DE0003E3-BD1E-48ED-92D8-E429CE14996A} - C:\WINDOWS\System32\colg.dll
O18 - Filter: text/plain - {DE0003E3-BD1E-48ED-92D8-E429CE14996A} - C:\WINDOWS\System32\colg.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - D:\Maya 6\docs\Wrapper.exe" -s "D:\Maya 6\docs/Wrapper.conf (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
thank you so much for your help....
Looking forward to your answer..
Keeza
here is DLLCompare log:
* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
O^E says: "There were no files found
\' />"________________________________________________
1,249 items found: 1,249 files, 0 directories.
Total of file sizes: 246,301,550 bytes 234.89 M
Administrator Account = True
--------------------End log---------------------
i guess thats good ... here is StartDreck Log:
StartDreck (build 2.1.7 public stable) - 2005-03-11 @ 11:08:03 (GMT +01:00)
Platform: Windows XP (Win NT 5.1.2600 Service Pack 1)
Internet Explorer: 6.0.2800.1106
Logged in as HH
»Registry
»Run Keys
»Current User
»Run
*CTFMON.EXE=C:\WINDOWS\System32\ctfmon.exe
*MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
»RunOnce
»Default User
»Run
*CTFMON.EXE=C:\WINDOWS\System32\CTFMON.EXE
»RunOnce
»Local Machine
»Run
*NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
*C-Media Mixer=Mixer.exe /startup
*APVXDWIN="D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE" /s
*QuickTime Task="D:\movie stuff\QuickTime\qttask.exe" -atboottime
*EPSON Stylus CX3200=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
*zafit=C:\WINDOWS\zafit.exe
*SunJavaUpdateSched=C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
*WinFoxV2=C:\WINDOWS\System32\WF2K.EXE Initial
*WinFast2KLoadDefault=rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
*SoundMan=SOUNDMAN.EXE
*nwiz=nwiz.exe /install
*NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
*NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
*sp=rundll32 C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll,DllInstall
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
»RunOnce
»RunServices
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»Browser Helper Objects (LM)
*{4613BB30-5B2F-40FD-AC33-E6661DB18062}
`InprocServer32=C:\WINDOWS\System32\colg.dll
»Files
»System/Drivers
»Running Processes
+0=<idle>
+4=<system>
+600=\SystemRoot\System32\smss.exe
+672=\??\C:\WINDOWS\system32\csrss.exe
+696=\??\C:\WINDOWS\system32\winlogon.exe
+740=C:\WINDOWS\system32\services.exe
+752=C:\WINDOWS\system32\lsass.exe
+936=C:\WINDOWS\system32\svchost.exe
+1024=C:\WINDOWS\System32\svchost.exe
+1140=C:\WINDOWS\System32\svchost.exe
+1216=C:\WINDOWS\System32\svchost.exe
+1416=C:\WINDOWS\system32\spoolsv.exe
+1428=C:\WINDOWS\Explorer.EXE
+1560=C:\WINDOWS\Mixer.exe
+1628=D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE
+1660=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
+1668=C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
+1684=C:\WINDOWS\System32\WF2K.EXE
+1712=C:\WINDOWS\SOUNDMAN.EXE
+1732=C:\WINDOWS\System32\RUNDLL32.EXE
+1764=C:\WINDOWS\System32\rundll32.exe
+1772=C:\WINDOWS\System32\ctfmon.exe
+1992=C:\WINDOWS\System32\alg.exe
+2008=D:\Maya 6\docs\Wrapper.exe
+2028=C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
+2040=C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
+224=C:\WINDOWS\System32\nvsvc32.exe
+228=C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
+408=D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
+872=D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
+976=C:\WINDOWS\System32\svchost.exe
+1000=C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
+1280=D:\Misc Apps\Panda Anti-Virus\AVENGINE.EXE
+1324=D:\Maya 6\docs\jre\bin\java.exe
+2412=D:\Misc Apps\Panda Anti-Virus\WebProxy.exe
+1832=D:\Misc Apps\Spybot - Search & Destroy\SpybotSD.exe
+2328=C:\WINDOWS\regedit.exe
+2348=C:\Program Files\Internet Explorer\iexplore.exe
+3508=C:\Documents and Settings\Henrik & Hilde\Desktop\eugen\startdreck\StartDreck.exe
»Application specific
and here is the hijackthis log i got afterwards...
Logfile of HijackThis v1.99.1
Scan saved at 11:09:21, on 11-03-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\System32\WF2K.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Maya 6\docs\Wrapper.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
D:\Misc Apps\Panda Anti-Virus\AVENGINE.EXE
D:\Maya 6\docs\jre\bin\java.exe
D:\Misc Apps\Panda Anti-Virus\WebProxy.exe
D:\Misc Apps\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Henrik & Hilde\Local Settings\Temp\Temporary Directory 3 for hijackthis_199.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {4613BB30-5B2F-40FD-AC33-E6661DB18062} - C:\WINDOWS\System32\colg.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [APVXDWIN] "D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "D:\movie stuff\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [zafit] C:\WINDOWS\zafit.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [WinFoxV2] C:\WINDOWS\System32\WF2K.EXE Initial
O4 - HKLM\..\Run: [WinFast2KLoadDefault] rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft\Office XP\Office10\OSA.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O18 - Filter: text/html - {DE0003E3-BD1E-48ED-92D8-E429CE14996A} - C:\WINDOWS\System32\colg.dll
O18 - Filter: text/plain - {DE0003E3-BD1E-48ED-92D8-E429CE14996A} - C:\WINDOWS\System32\colg.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - D:\Maya 6\docs\Wrapper.exe" -s "D:\Maya 6\docs/Wrapper.conf (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
thank you so much for your help....
Looking forward to your answer..
Keeza