ok here is the combo fix log.......also internet is running ok....i get a few times a day asking to try again connection in IE but msn stays signed in.....thats just weird, but after combofix run i had to repair my connection as it wasnt working at all.
ComboFix 08-01-15.4 - pIXSELL 2008-01-15 11:48:55.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.181 [GMT 1:00]
Running from: C:\Documents and Settings\pIXSELL\My Documents\Downloads\New Folder\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\sitdat5.dll
C:\WINDOWS\system32\sitinfo.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-15 to 2008-01-15 )))))))))))))))))))))))))))))))
.
2008-01-15 11:47 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 09:35 . 2008-01-11 09:36 <DIR> d-------- C:\Program Files\Advanced Email Extractor PRO
2008-01-11 09:35 . 1999-06-25 10:55 149,504 --a------ C:\WINDOWS\UNWISE.EXE
2008-01-02 19:49 . 2008-01-02 19:50 <DIR> d-------- C:\Documents and Settings\pIXSELL\Application Data\VideoEgg
2007-12-30 00:07 . 2008-01-10 12:08 <DIR> d-------- C:\Program Files\Blaze Media Pro
2007-12-30 00:07 . 2007-12-30 00:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{CFAB4006-0AE0-414D-866A-DCB2C46553CF}
2007-12-29 22:15 . 2004-08-04 05:58 5,376 --a------ C:\WINDOWS\system32\MSPCLOCK.sys
2007-12-29 22:05 . 2007-12-29 22:05 <DIR> d-------- C:\Program Files\PIXELA
2007-12-29 22:04 . 2001-11-05 09:23 299,923 --a------ C:\WINDOWS\system32\drivers\sonyhcs.sys
2007-12-29 22:04 . 2001-07-03 20:33 53,248 --a------ C:\WINDOWS\system32\SONYHCY.DLL
2007-12-29 22:04 . 2001-11-05 09:23 38,739 --a------ C:\WINDOWS\system32\drivers\sonyhcc.sys
2007-12-29 22:04 . 2001-11-05 09:23 6,097 --a------ C:\WINDOWS\system32\drivers\sonyhcb.sys
2007-12-29 22:04 . 2001-07-03 20:39 3,654 --a------ C:\WINDOWS\system32\drivers\Sonyhcp.dll
2007-12-29 21:57 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2007-12-29 21:57 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\dllcache\sonypvu1.sys
2007-12-29 21:55 . 2004-08-04 06:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-12-29 21:55 . 2004-08-04 06:07 59,264 --a------ C:\WINDOWS\system32\dllcache\usbaudio.sys
2007-12-22 03:07 . 2007-12-22 03:07 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-21 23:34 . 2007-12-21 23:34 3,532 --a------ C:\drmHeader.bin
2007-12-21 13:19 . 2007-12-21 13:19 <DIR> d-------- C:\Program Files\WAYN
2007-12-21 13:19 . 2007-12-21 13:19 <DIR> d-------- C:\Documents and Settings\pIXSELL\Application Data\WAYN
2007-12-18 23:35 . 2007-12-18 23:35 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-12-18 01:31 . 2007-12-18 01:32 <DIR> d-------- C:\Documents and Settings\pIXSELL\Application Data\GetRightToGo
2007-12-18 01:23 . 2007-12-18 01:23 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-12-18 01:22 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-12-18 00:57 . 2007-12-18 01:04 <DIR> d-------- C:\Program Files\GameShadow
2007-12-16 11:00 . 2007-12-16 11:00 <DIR> d-------- C:\Program Files\PCPitstop
2007-12-16 10:51 . 2007-12-16 10:51 <DIR> d-------- C:\Program Files\Maxis
2007-12-15 02:10 . 2008-01-10 18:16 1,374 --a------ C:\WINDOWS\imsins.BAK
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 07:53 --------- d-----w C:\Documents and Settings\pIXSELL\Application Data\uTorrent
2008-01-13 22:19 --------- d-----w C:\Documents and Settings\pIXSELL\Application Data\Skype
2008-01-11 17:22 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-09 19:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-09 19:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-26 20:54 --------- d-----w C:\Documents and Settings\pIXSELL\Application Data\LimeWire
2007-12-23 15:52 --------- d--h--w C:\Documents and Settings\pIXSELL\Application Data\Creative
2007-12-23 15:44 --------- d-----w C:\Program Files\Creative
2007-12-18 19:00 --------- d-----w C:\Program Files\MSN Messenger
2007-12-18 19:00 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-14 17:36 --------- d-----w C:\Program Files\pIXSELL
2007-12-13 00:59 --------- d-----w C:\Program Files\UltraMon
2007-12-13 00:59 --------- d-----w C:\Program Files\Common Files\Realtime Soft
2007-12-13 00:59 --------- d-----w C:\Documents and Settings\pIXSELL\Application Data\Realtime Soft
2007-12-13 00:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Realtime Soft
2007-12-10 16:38 --------- d-----w C:\Program Files\Diskeeper Corporation
2007-12-10 16:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
2007-12-09 00:27 --------- d-----w C:\Program Files\Diskeeper Corporation(2)
2007-12-09 00:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation(2)
2007-12-06 18:25 --------- d-----w C:\Program Files\DivX
2007-12-04 23:37 --------- d-----w C:\Program Files\PC Wizard 2007
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2007-11-29 22:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-11-29 22:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-11-29 15:50 4,096 ----a-w C:\WINDOWS\system32\sysres.dll
2007-11-29 15:50 38,567 ----a-w C:\WINDOWS\system32\pcpbios.exe
2007-11-28 21:55 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 21:53 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-11-28 21:53 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 21:53 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-11-28 21:52 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-22 00:41 --------- d-----w C:\Program Files\Adobe Type Manager
2007-11-21 18:23 81,920 ----a-w C:\WINDOWS\system32\frapsvid.dll
2007-11-07 17:26 278,528 ----a-w C:\WINDOWS\system32\livesnth.dll
2007-11-07 17:26 203,776 ----a-w C:\WINDOWS\system32\clrviddc.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 16:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 16:39 230,912 ------w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-27 16:37 2,109,440 ------w C:\WINDOWS\system32\dllcache\wmvcore.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2003-02-28 11:32 11,776 ----a-w C:\WINDOWS\inf\dt154stickoem_wxp.exe
2002-11-14 21:32 55,808 ----a-w C:\WINDOWS\inf\devcon154stick.exe
2006-10-01 14:30 104 --sh--r C:\WINDOWS\system32\BA23C75FDC.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tgcmd"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-04 08:56 380416 C:\WINDOWS\system32\irprops.cpl]
"tgcmd"="" []
"UC_Start"="C:\IBMTools\Updater\ucstartup.exe" [2003-03-17 23:27 32768]
"Mouse Suite 98 Daemon"="ICO.EXE" [2003-11-20 22:08 57344 C:\WINDOWS\system32\ico.exe]
"WinVNC"="C:\Program Files\TightVNC\WinVNC.exe" [2003-08-01 09:28 474624]
"Matrox Powerdesk"="C:\WINDOWS\system32\PDesk\PDesk.exe" [2004-09-14 09:13 684032]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-20 18:35 579072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"mouseElf"="C:\PROGRA~1\NAVIGA~1\MouseElf.EXE" [2004-09-20 07:16 196608]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36 114688]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 16:24 86016]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 21:46 624248]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-07 18:19 185632]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36 267048]
"PC Pitstop Optimize Scheduler"="C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe" [2007-12-07 23:37 1680883]
"UltraMon"="C:\Program Files\UltraMon\UltraMon.exe" [2006-10-12 21:27 304640]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16 286720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-11-06 18:08 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ibmmessages]
--a------ 2003-09-30 17:05 536576 C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
R0 sonyhcb;Sony Digital Imaging Base;C:\WINDOWS\system32\DRIVERS\sonyhcb.sys [2001-11-05 09:23]
R2 UltraMonUtility;UltraMon Utility Driver;C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2006-09-24 21:22]
R3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys [2006-09-24 21:23]
R3 V0260VID;Live! Cam Vista IM;C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-11-04 06:45]
S0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys []
S0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys []
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
S3 cpuz126;cpuz126;C:\Program Files\PC Wizard 2007\pcwiz32.sys [2006-12-14 13:00]
S3 DT154_A02;Sinus 154 data II Driver;C:\WINDOWS\system32\DRIVERS\TS154USB.sys []
S3 genmcmnUSB;USB Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gflmouhid.sys [2004-04-19 07:01]
S3 pelmouse;Mouse Suite Driver;C:\WINDOWS\system32\DRIVERS\pelmouse.sys [2003-01-10 21:55]
S3 pelusblf;USB Mouse Low Filter Driver;C:\WINDOWS\system32\DRIVERS\pelusblf.sys [2003-02-11 21:25]
S3 sonyhcs;Sony Digital Imaging Video;C:\WINDOWS\system32\DRIVERS\sonyhcs.sys [2001-11-05 09:23]
S3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys []
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-01-10 09:45:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-15 11:53:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-15 11:54:07
ComboFix-quarantined-files.txt 2008-01-15 10:53:52
.
2007-07-10 22:43:55 --- E O F ---