Ok done, i used Avira and it found 14 viruses so i quarantined them.
ComboFix 09-05-23.03 - Nick 23/05/2009 22:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.2047.1432 [GMT 1:00]
Running from: c:\documents and settings\Nick\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\GDS32.DLL
c:\windows\system32\tmp27.tmp
c:\windows\system32\tmp28.tmp
.
((((((((((((((((((((((((( Files Created from 2009-04-23 to 2009-05-23 )))))))))))))))))))))))))))))))
.
2009-05-23 19:31 . 2009-05-23 19:31 -------- d-----w c:\windows\LastGood
2009-05-23 19:31 . 2009-03-30 09:33 96104 ----a-w c:\windows\system32\drivers\avipbb.sys
2009-05-23 19:31 . 2009-03-24 15:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-23 19:31 . 2009-02-13 11:29 22360 ----a-w c:\windows\system32\drivers\avgntmgr.sys
2009-05-23 19:31 . 2009-02-13 11:17 45416 ----a-w c:\windows\system32\drivers\avgntdd.sys
2009-05-23 19:31 . 2009-05-23 19:31 -------- d-----w c:\program files\Avira
2009-05-23 19:31 . 2009-05-23 19:31 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-05-23 17:30 . 2009-05-23 17:30 -------- d-----w c:\program files\Trend Micro
2009-05-22 21:15 . 2009-05-22 21:15 -------- d-----w C:\logs3
2009-05-22 19:47 . 2009-05-23 17:32 117760 ----a-w c:\documents and settings\Nick\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\ UIREPAIR.DLL
2009-05-22 19:47 . 2009-05-22 19:47 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-22 19:46 . 2009-05-22 19:46 -------- d-----w c:\program files\SUPERAntiSpyware
2009-05-22 19:46 . 2009-05-22 19:46 -------- d-----w c:\documents and settings\Nick\Application Data\SUPERAntiSpyware.com
2009-05-22 10:45 . 2009-05-23 19:30 1374 ----a-w c:\documents and settings\Nick\Application Data\ASUS\Xonar D2 Audio Center\AsusAudioCenter.dll
2009-05-22 10:45 . 2009-05-22 10:45 -------- d-----w c:\documents and settings\Nick\Application Data\ASUS
2009-05-22 10:42 . 2007-04-19 07:12 32768 ----a-r c:\windows\system32\cmudaxp.dll
2009-05-22 10:42 . 2004-04-14 03:28 315392 ----a-r c:\windows\system\CmiFltr.dll
2009-05-22 10:42 . 2008-01-14 08:46 1867840 ----a-r c:\windows\system32\drivers\cmudaxp.sys
2009-05-20 23:39 . 2009-05-20 23:39 -------- d-----w c:\program files\PCI Latency Tool 3
2009-05-20 18:59 . 2009-05-20 18:59 -------- d-----w c:\program files\SpacialAudio
2009-05-20 18:59 . 2005-09-22 23:05 548864 ----a-w c:\windows\system32\msvcp80.dll
2009-05-20 18:59 . 2009-05-20 18:59 -------- d-----w c:\program files\Firebird
2009-05-20 18:59 . 2005-09-22 23:05 626688 ----a-w c:\windows\system32\msvcr80.dll
2009-04-29 21:19 . 2009-04-29 21:19 41808 ----a-w c:\windows\system32\xfcodec.dll
2009-04-26 17:14 . 2009-05-05 14:25 -------- d-----w c:\program files\SnapStream Media
2009-04-25 23:44 . 2009-04-25 23:44 -------- d-----w c:\documents and settings\Nick\Application Data\Webcammax
2009-04-25 23:43 . 2009-04-25 23:45 -------- d-----w c:\program files\WebcamMax
2009-04-25 23:43 . 2009-04-25 23:54 -------- d-----w c:\documents and settings\All Users\Application Data\Webcammax
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-05-23 19:26 . 2007-05-01 14:32 -------- d-----r c:\program files\mIRC
2009-05-23 00:25 . 2007-11-08 13:58 189072 ----a-w c:\windows\system32\PnkBstrB.exe
2009-05-22 23:56 . 2007-11-08 13:58 138920 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-05-22 21:15 . 2008-12-03 21:37 -------- d-----w c:\program files\Kontiki
2009-05-22 21:06 . 2008-10-11 22:30 -------- d-----w c:\documents and settings\All Users\Application Data\wfwbwjwn
2009-05-22 19:46 . 2007-05-01 15:38 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-22 19:15 . 2007-05-02 21:13 -------- d-----w c:\program files\Analog Devices
2009-05-22 18:17 . 2009-01-14 16:02 -------- d-----w c:\documents and settings\Nick\Application Data\Spotify
2009-05-22 10:45 . 2007-04-27 15:51 28544 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-22 10:44 . 2009-05-22 10:44 -------- d-----w c:\program files\OpenAL
2009-05-22 10:44 . 2007-04-27 17:03 413696 ----a-w c:\windows\system32\wrap_oal.dll
2009-05-22 10:44 . 2007-04-27 17:03 110592 ----a-w c:\windows\system32\OpenAL32.dll
2009-05-22 10:44 . 2009-05-22 10:43 -------- d-----w c:\program files\ASUS Xonar DX Audio
2009-05-22 09:36 . 2007-04-27 17:02 -------- d-----w c:\program files\Creative
2009-05-22 09:36 . 2007-04-27 17:04 -------- d-----w c:\documents and settings\All Users\Application Data\Creative
2009-05-21 19:32 . 2008-05-15 17:51 -------- d-----w c:\documents and settings\All Users\Application Data\TrackMania
2009-05-20 12:59 . 2007-05-22 19:59 -------- d-----w c:\documents and settings\Nick\Application Data\teamspeak2
2009-05-17 22:35 . 2009-01-14 14:47 -------- d-----w c:\documents and settings\Nick\Application Data\HLSW
2009-05-15 00:11 . 2007-04-27 16:09 84664 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-14 10:19 . 2009-02-07 16:11 -------- d-----w c:\program files\Rockstar Games
2009-05-14 10:19 . 2007-04-27 15:40 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-05 23:08 . 2007-05-01 17:17 -------- d-s---w c:\program files\Xfire
2009-05-05 16:12 . 2007-05-01 15:41 -------- d-----w c:\documents and settings\Nick\Application Data\Xfire
2009-05-02 14:02 . 2009-03-25 14:18 5588312 ----a-w c:\documents and settings\Nick\Application Data\TVU networks\TVU AutoUpgrade\TVUPlayer2.4.5.1.exe
2009-05-01 20:49 . 2007-05-05 19:52 -------- d-----w c:\program files\aequitas
2009-04-25 19:58 . 2009-03-09 19:24 -------- d-----w c:\program files\UT2004
2009-04-22 20:23 . 2008-12-17 22:05 -------- d-----w c:\documents and settings\Nick\Application Data\Skype
2009-04-22 20:20 . 2008-12-17 22:05 -------- d-----w c:\documents and settings\Nick\Application Data\skypePM
2009-04-18 13:47 . 2007-11-08 13:57 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-04-18 13:26 . 2007-11-08 13:58 22328 ----a-w c:\documents and settings\Nick\Application Data\PnkBstrK.sys
2009-04-18 13:26 . 2007-11-08 13:58 22328 ----a-w c:\documents and settings\Nick\Application Data\PnkBstrK.sys
2009-04-18 13:25 . 2008-11-01 17:59 682280 ----a-w c:\windows\system32\pbsvc.exe
2009-04-08 10:45 . 2009-04-08 10:45 -------- d-----w c:\documents and settings\Nick\Application Data\Logitech
2009-04-08 10:44 . 2009-04-08 10:44 -------- d-----w c:\documents and settings\Nick\Application Data\Leadertech
2009-04-08 10:44 . 2009-04-08 10:44 53248 ----a-r c:\documents and settings\Nick\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2009-04-08 10:44 . 2009-04-08 10:42 -------- d-----w c:\program files\Common Files\Logishrd
2009-04-08 10:44 . 2009-04-08 10:44 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_0 1005.Wdf
2009-04-08 10:44 . 2009-04-08 10:44 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_0 1005.Wdf
2009-04-08 10:43 . 2009-04-08 10:43 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_C oinstaller_Critical.Wdf
2009-04-08 10:42 . 2009-04-08 10:42 -------- d-----w c:\documents and settings\All Users\Application Data\Logitech
2009-04-08 10:42 . 2009-04-08 10:42 -------- d-----w c:\program files\Logitech
2009-04-08 10:42 . 2009-04-08 10:42 -------- d-----w c:\documents and settings\All Users\Application Data\LogiShrd
2009-04-08 10:34 . 2009-04-08 10:34 -------- d-----w c:\program files\viewsonic
2009-03-31 13:03 . 2009-03-31 13:03 -------- d-----w c:\documents and settings\All Users\Application Data\ATI
2009-03-31 13:01 . 2009-03-31 11:24 -------- d-----w c:\program files\ATI Technologies
2009-03-31 11:32 . 2009-03-31 11:32 0 ----a-w c:\windows\ativpsrm.bin
2009-03-31 11:26 . 2009-03-31 11:26 9158 ----a-r c:\documents and settings\Nick\Application Data\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
2009-03-31 11:26 . 2009-03-31 11:26 -------- d-----w c:\program files\Common Files\ATI Technologies
2009-03-29 01:31 . 2009-03-29 01:31 -------- d-----w c:\program files\microsoft frontpage
2009-03-28 19:00 . 2009-03-14 18:09 -------- d-----w c:\program files\lg_fwupdate
2009-03-25 18:06 . 2009-03-25 18:16 2082104 ----a-w c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\
0xhbgp89.default\extensions\firefox@tvunetworks.com \plugins\npTVUAx.dll
2009-03-25 14:51 . 2008-02-20 00:37 8 ----a-w c:\windows\system32\nvModes.dat
2009-03-25 14:18 . 2009-03-25 14:18 -------- d-----w c:\documents and settings\Nick\Application Data\TVU networks
2009-03-09 19:30 . 2007-06-24 19:24 43520 ----a-w c:\windows\system32\CmdLineExt03.dll
2009-03-07 14:20 . 2009-03-07 14:20 488960 ----a-w c:\documents and settings\Nick\Application Data\Macromedia\Flash Player\
http://www.macromedia.com\bin\octosh...240-0-main.dll
2009-03-07 14:20 . 2009-03-07 14:20 319488 ----a-w c:\documents and settings\Nick\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\octoshape\octoshape.exe
2009-02-25 22:58 . 2008-10-01 05:10 3565568 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-25 21:42 . 2009-03-31 11:25 442368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-02-25 21:41 . 2008-10-01 03:30 325120 ----a-w c:\windows\system32\ati2dvag.dll
2009-02-25 21:30 . 2008-10-01 04:10 11841536 ----a-w c:\windows\system32\atioglxx.dll
2009-02-25 21:30 . 2008-10-01 03:20 204800 ----a-w c:\windows\system32\atipdlxx.dll
2009-02-25 21:29 . 2008-10-01 03:20 155648 ----a-w c:\windows\system32\Oemdspif.dll
2009-02-25 21:29 . 2008-10-01 03:20 26112 ----a-w c:\windows\system32\Ati2mdxx.exe
2009-02-25 21:29 . 2008-10-01 03:20 43520 ----a-w c:\windows\system32\ati2edxx.dll
2009-02-25 21:29 . 2008-10-01 03:20 155648 ----a-w c:\windows\system32\ati2evxx.dll
2009-02-25 21:27 . 2008-10-01 03:18 602112 ----a-w c:\windows\system32\ati2evxx.exe
2009-02-25 21:26 . 2008-10-01 03:17 53248 ----a-w c:\windows\system32\ATIDDC.DLL
2009-02-25 21:16 . 2008-10-01 03:08 3817984 ----a-w c:\windows\system32\ati3duag.dll
2009-02-25 21:09 . 2009-03-31 11:25 307200 ----a-w c:\windows\system32\atiiiexx.dll
2009-02-25 20:59 . 2008-10-01 02:52 2670080 ----a-w c:\windows\system32\ativvaxx.dll
2009-02-25 20:44 . 2008-10-01 02:38 49664 ----a-w c:\windows\system32\amdpcom32.dll
2009-02-25 20:40 . 2008-10-01 02:34 475136 ----a-w c:\windows\system32\atikvmag.dll
2009-02-25 20:38 . 2008-10-01 02:33 126976 ----a-w c:\windows\system32\atiadlxx.dll
2009-02-25 20:38 . 2008-10-01 02:32 17408 ----a-w c:\windows\system32\atitvo32.dll
2009-02-25 20:37 . 2008-10-01 02:31 53248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-25 20:35 . 2008-10-01 03:19 290816 ----a-w c:\windows\system32\atiok3x2.dll
2009-02-25 20:32 . 2009-02-25 20:32 45056 ----a-w c:\windows\system32\aticalrt.dll
2009-02-25 20:32 . 2009-02-25 20:32 45056 ----a-w c:\windows\system32\aticalcl.dll
2009-02-25 20:32 . 2008-10-01 02:26 626688 ----a-w c:\windows\system32\ati2cqag.dll
2009-02-25 20:30 . 2009-02-25 20:30 3227648 ----a-w c:\windows\system32\aticaldd.dll
2009-02-25 14:15 . 2009-03-31 11:25 593920 ------w c:\windows\system32\ati2sgag.exe
.
------- Sigcheck -------
[-] 2007-05-02 22:14 360576 E7DFCFFA380749B8626AD71E8F367DCB c:\windows\system32\dllcache\TCPIP.SYS
[-] 2007-05-02 22:14 360576 E7DFCFFA380749B8626AD71E8F367DCB c:\windows\system32\drivers\TCPIP.SYS
[-] 2008-02-18 13:18 502272 9B87F4EB80008CD45EBA76162DBDA138 c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_09\bin\jusched.exe" [2006-09-07 49263]
"MBM 5"="c:\program files\Motherboard Monitor 5\MBM5.EXE" [2004-06-12 594944]
"MultiRes"="c:\program files\MultiRes\MultiRes.exe" [2006-01-09 54784]
"Ai Nap"="c:\program files\ASUS\Ai Suite\AiNap\AiNap.exe" [2007-09-06 1426432]
"CPU Power Monitor"="c:\program files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe" [2007-10-04 626176]
"Cpu Level Up help"="c:\program files\ASUS\Ai Suite\CpuLevelUpHelp.exe" [2007-09-11 880640]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2008-11-04 413696]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"WebcamMaxMoniter"="c:\program files\WebcamMax\wcmmon.exe" [2007-08-01 450048]
"Cmaudio8788GX"="c:\windows\system\CMGxMon.exe " [2007-12-19 20480]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-09-21 55824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\Nick\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Common Files\Logishrd\eReg\Common\eReg.exe [2009-3-30 517384]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless Networking Utility.lnk - c:\program files\Belkin\F5D8051v2\Belkinwcui.exe [2008-5-4 1581056]
Bluetooth.lnk - c:\program files\Belkin\Bluetooth Software\BTTray.exe [2005-8-24 577597]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-8 784912]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2007-7-28 49220]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 09:10 72208 ----a-w c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GammaTray.lnk]
backup=c:\windows\pss\GammaTray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"SCardSvr"=3 (0x3)
"PnkBstrB"=2 (0x2)
"PnkBstrA"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Documents and Settings\\Nick\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\TmUnitedForever\\TmForever.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Infogrames\\Tactical Ops\\System\\TacticalOps.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Canon\\Color Network ScanGear\\SgTool.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\klame_one@hotmail. com\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\HLSW\\hlsw.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Java\\jre1.5.0_09\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Documents and Settings\\Nick\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octosh ape.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Mumble\\murmur.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"e:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"e:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer .exe"=
"e:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"e:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\UT2004\\System\\UT2004.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"e:\\Program Files (x86)\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\SpacialAudio\\SAMBC\\SAMBC.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [14/05/2009 14:22 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [14/05/2009 14:22 72944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [23/05/2009 20:31 108289]
R2 CamthWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CamthWDM.sys [11/01/2007 06:39 243584]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
R2 LtcyCfgSvc;PCI Latency Tool Service;c:\program files\PCI Latency Tool 3\LtcyCfgSvc.exe [26/12/2005 00:24 5120]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [31/03/2009 12:26 89600]
R3 cmudaxp;ASUS Xonar DX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [22/05/2009 11:42 1867840]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
R3 LtcyCfgWDM;PCI Latency Tool Driver Service;c:\windows\system32\drivers\LtcyCfgWDM.sys [26/12/2005 00:24 6656]
S1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys --> c:\windows\system32\DRIVERS\cmdguard.sys [?]
S1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys --> c:\windows\system32\DRIVERS\cmdhlp.sys [?]
S2 NetFxUpdate_v1.1.4322;Microsoft .NET Framework v1.1.4322 Update;c:\windows\Microsoft.NET\Framework\v1.1.432 2\netfxupdate.exe --> c:\windows\Microsoft.NET\Framework\v1.1.4322\netfx update.exe [?]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [31/07/2008 21:54 22784]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [01/05/2007 14:37 17149]
S3 PciCon;PciCon;\??\g:\pcicon.sys --> g:\PciCon.sys [?]
S3 PLUsbbc2;Trust NB-7500p USB 2.0 Data Transfer Cable;c:\windows\system32\drivers\usbbc2.sys [01/05/2007 15:05 8960]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [14/05/2009 14:22 7408]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\DRIVERS\WPN111.sys --> c:\windows\system32\DRIVERS\WPN111.sys [?]
S4 .EsetTrialReset;Eset Trial Reset;c:\windows\system32\regedt32.exe [04/08/2004 12:00 3584]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ANTIVIRSCHEDULERSERVICE
*NewlyCreated* - ANTIVIRSERVICE
*NewlyCreated* - AVGIO
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
*NewlyCreated* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder
2009-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Cmaudio8788 - cmicnfgp.cpl
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: Send To &Bluetooth - c:\program files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\
0xhbgp89.default\
FF - prefs.
js: browser.startup.homepage - hxxp://www.arsenal.com/
FF - component: c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\
0xhbgp89.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\
0xhbgp89.default\extensions\firefox@tvunetworks.com \plugins\npTVUAx.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\Microsoft Silverlight\npctrl.1.0.20816.0.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLC\npvlc.dll
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-05-23 22:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{ 95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2009-05-23 22:38
ComboFix-quarantined-files.txt 2009-05-23 21:37
ComboFix2.txt 2009-03-29 01:36
Pre-Run: 23,715,864,576 bytes free
Post-Run: 24,582,062,080 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /noexecute=optin /fastdetect
328 --- E O F --- 2007-08-15 22:09
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:41:18, on 23/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Motherboard Monitor 5\MBM5.EXE
C:\Program Files\MultiRes\MultiRes.exe
C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe
C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\WebcamMax\wcmmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\F5D8051v2\Belkinwcui.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\ASUS Xonar DX Audio\Customapp\Program\ASUSAUDIOCENTER.EXE
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
C:\Program Files\PCI Latency Tool 3\LtcyCfgSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [MBM 5] "C:\Program Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [MultiRes] C:\Program Files\MultiRes\MultiRes.exe
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] C:\Program Files\ASUS\Ai Suite\CpuLevelUpHelp.exe
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [WebcamMaxMoniter] "C:\Program Files\WebcamMax\wcmmon.exe" /a
O4 - HKLM\..\Run: [Cmaudio8788GX] C:\WINDOWS\system\CMGxMon.exe Envoke
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Common Files\Logishrd\eReg\Common\eReg.exe
O4 - Global Startup: Belkin Wireless Networking Utility.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: NCProTray.lnk = ?
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: PCI Latency Tool Service (LtcyCfgSvc) - Unknown owner - C:\Program Files\PCI Latency Tool 3\LtcyCfgSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Microsoft .NET Framework v1.1.4322 Update (NetFxUpdate_v1.1.4322) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfx update.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 8597 bytes
I noticed in ComboFix it says "FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}" I dont have COMODO firewall, i had it about 6months ago and got rid of it because of its notices, so i guess theres still traces of it not that its whats causing my problems, just something i noted.
On my E: drive i have Vista64 installed, so just to check if it was something on my XP disk i booted into vista and i have none of the problems, no spikes and no audio stuttering. So im 99.9% sure its something on my XP disk.