Ok first off i have read a lot of the treads and post's dealing with this issue.
the problem has stopped but people have said that it doesn't necessarily mean the it is fixed. So i am posting my comboFix log to have someone check it for possible problems.
ComboFix 09-05-04.04 - Kyle Rinkes 05/05/2009 1:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1538 [GMT -7:00]
Running from: c:\documents and settings\Kyle Rinkes\My Documents\Firefox Downloads\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090504-1] *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Kyle Rinkes\Application Data\WeatherDPA
c:\documents and settings\Kyle Rinkes\Application Data\WeatherDPA\Weather\WeatherStartup.xml
c:\program files\AntiSpywareMaster
c:\program files\autorun.inf
c:\windows\pack.epk
c:\windows\system32\DMUxIRqr.ini
c:\windows\system32\DMUxIRqr.ini2
c:\windows\system32\geBqRiHx.dll
c:\windows\system32\Kjlmlnnn.ini
c:\windows\system32\Kjlmlnnn.ini2
c:\windows\system32\nnnnLFVP.dll
c:\windows\system32\nvs2.inf
c:\windows\system32\oiuywyq.dat
c:\windows\system32\oiuywyq_nav.dat
c:\windows\system32\oiuywyq_navps.dat
c:\windows\system32\rqRIxUMD.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-04-05 to 2009-05-05 )))))))))))))))))))))))))))))))
.
2009-05-05 08:05 . 2009-05-05 08:05 -------- d-sh--w c:\documents and settings\Kyle Rinkes\IETldCache
2009-05-05 07:58 . 2009-05-05 07:58 -------- d-----w c:\documents and settings\Kyle Rinkes\Application Data\ParetoLogic
2009-05-05 07:57 . 2009-05-05 07:57 -------- d-----w c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-05-05 07:51 . 2009-05-05 07:53 -------- d-----w c:\program files\QuickTime
2009-05-05 07:39 . 2009-05-05 07:42 -------- dc-h--w c:\windows\ie8
2009-05-05 07:38 . 2009-05-05 07:38 -------- d-----w c:\windows\system32\MpEngineStore
2009-05-05 07:31 . 2007-04-23 20:29 812544 ----a-w c:\windows\system32\drivers\ti21sony.sys
2009-05-05 07:30 . 2009-05-05 07:30 87328 ----a-w c:\windows\system32\bcmwlcoi.dll
2009-05-05 07:30 . 2009-05-05 07:30 -------- d-----w c:\program files\Broadcom
2009-05-05 07:29 . 2009-05-05 07:29 -------- d-----w c:\windows\OPTIONS
2009-05-05 07:29 . 2009-05-05 07:29 -------- d-----w c:\program files\Realtek
2009-05-05 07:29 . 2009-05-05 07:29 -------- d-----w c:\documents and settings\Kyle Rinkes\Application Data\InstallShield
2009-05-05 07:29 . 2009-05-05 07:29 -------- d-----w c:\documents and settings\Kyle Rinkes\Local Settings\Application Data\BVRP Software
2009-05-05 07:29 . 2009-05-05 07:29 -------- d-----w c:\program files\NetWaiting
2009-05-05 07:27 . 2007-10-12 16:40 9096 ----a-w c:\windows\system32\drivers\amdide.sys
2009-05-05 06:41 . 2009-05-05 06:42 -------- d-----w c:\documents and settings\Kyle Rinkes\Application Data\DriverCure
2009-05-05 06:41 . 2009-05-05 06:41 -------- d-----w c:\program files\Common Files\ParetoLogic
2009-05-05 06:41 . 2009-05-05 07:57 -------- d-----w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-05-05 06:41 . 2009-05-05 08:21 -------- d-----w c:\documents and settings\All Users\Application Data\DriverCure
2009-05-05 06:41 . 2009-05-05 06:41 -------- d-----w c:\program files\ParetoLogic
2009-05-05 06:07 . 2009-05-05 06:26 -------- d-----w c:\program files\RegCure
2009-04-24 16:16 . 2009-04-24 16:16 -------- d-----w c:\program files\Perfect World Entertainment
2009-04-24 16:14 . 2005-05-11 01:54 258352 ----a-w c:\windows\system32\unicows.dll
2009-04-24 16:06 . 2000-09-15 22:51 372736 ----a-w c:\program files\ijl15.dll
2009-04-24 16:06 . 2008-11-26 23:02 1196032 ----a-w c:\program files\install.exe
2009-04-24 16:06 . 2002-08-16 06:58 28672 ----a-w c:\program files\JPGI.dll
2009-04-24 16:06 . 2005-05-11 01:54 258352 ----a-w c:\program files\unicows.dll
2009-04-24 16:06 . 2008-12-01 18:51 -------- d-----w c:\program files\background
2009-04-24 16:06 . 2009-04-24 16:06 -------- d-----w c:\program files\New Folder
2009-04-23 22:14 . 2009-04-24 16:05 -------- d-----w c:\documents and settings\Kyle Rinkes\Application Data\GetRightToGo
2009-04-23 07:15 . 2009-04-23 07:15 -------- d-----w c:\documents and settings\All Users\Application Data\Avg7
2009-04-20 06:05 . 2009-04-20 06:05 -------- d-----w c:\documents and settings\Kyle Rinkes\Application Data\Sierra Wireless
2009-04-20 06:04 . 2005-03-15 18:11 17920 ----a-w c:\windows\system32\apintfnt.dll
2009-04-20 06:01 . 2009-04-20 06:01 -------- d-----w c:\program files\Common Files\Research in Motion
2009-04-20 06:01 . 2009-04-20 06:01 -------- d-----w c:\program files\Novatel Wireless
2009-04-20 06:01 . 2009-04-20 06:01 -------- d-----w c:\program files\Sprint
2009-04-20 06:01 . 2009-04-20 06:01 -------- d-----w c:\documents and settings\All Users\Application Data\Sprint
2009-04-16 02:59 . 2008-05-03 11:55 2560 ----a-w c:\windows\system32\xpsp4res.dll
2009-04-16 02:59 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-16 02:58 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-16 02:58 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-16 02:58 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 02:58 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-16 02:58 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 02:58 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 02:58 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 02:58 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 02:58 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 02:58 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-06 18:49 . 2009-05-05 08:39 -------- d-----w c:\documents and settings\Kyle Rinkes\Tracing
2009-04-06 18:40 . 2009-02-07 01:08 55152 ----a-w c:\windows\system32\drivers\fssfltr_tdi.sys
2009-04-06 18:39 . 2009-04-06 18:39 -------- d-----w c:\program files\Microsoft Sync Framework
2009-04-06 18:38 . 2009-04-06 18:38 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-04-06 18:29 . 2009-04-06 18:29 -------- d-----w c:\program files\Microsoft
2009-04-06 18:28 . 2009-04-06 18:28 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-06 18:11 . 2009-04-06 18:11 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-06 17:46 . 2009-04-06 17:46 -------- d-----w c:\program files\jEdit 4.2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 08:02 . 2008-02-06 09:02 -------- d-----w c:\program files\BitComet
2009-05-05 07:48 . 2006-10-02 20:28 -------- d-----w c:\program files\Apple Software Update
2009-05-05 07:30 . 2005-11-28 09:35 1294200 ----a-w c:\windows\system32\drivers\BCMWL5.SYS
2009-05-05 07:29 . 2006-04-14 03:48 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-05 07:29 . 2006-04-14 02:43 -------- d-----w c:\program files\CONEXANT
2009-04-20 06:01 . 2009-01-31 20:38 -------- d-----w c:\program files\Sierra Wireless
2009-04-20 06:01 . 2009-01-31 20:38 -------- d-----w c:\program files\Common Files\Motorola Shared
2009-04-06 18:48 . 2006-09-21 05:39 107760 -c--a-w c:\documents and settings\Kyle Rinkes\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-06 18:40 . 2008-02-06 09:49 -------- d-----w c:\program files\Windows Live
2009-04-06 18:40 . 2006-09-27 07:44 -------- d-----w c:\program files\Windows Live Toolbar
2009-04-02 18:55 . 2006-04-14 03:51 -------- d-----w c:\program files\Java
2009-03-20 22:58 . 2008-06-04 03:09 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-20 21:24 . 2008-11-20 17:40 -------- d-----w c:\program files\Curse
2009-03-09 12:19 . 2009-01-06 08:32 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2004-08-10 15:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2004-08-10 15:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2004-08-10 15:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2004-08-10 15:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2004-08-10 15:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2004-08-10 15:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:31 . 2004-08-10 15:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2004-08-10 15:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2004-08-10 15:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2004-08-10 15:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-07 05:51 . 2009-03-07 05:51 26888 ----a-w c:\windows\system32\drivers\swmsflt.sys
2009-03-07 05:51 . 2008-07-07 22:42 149512 ----a-w c:\windows\system32\drivers\swmx00.sys
2009-03-07 05:51 . 2009-03-07 05:51 222720 ----a-w c:\windows\system32\drivers\NWADIenum.sys
2009-03-07 05:51 . 2009-03-07 05:51 38680 ----a-w c:\windows\system32\drivers\pctnullport.sys
2009-03-07 04:41 . 2009-03-07 04:41 61440 ----a-w c:\windows\system32\pxfhwmcp.dll
2009-03-07 04:41 . 2009-03-07 04:41 32408 ----a-w c:\windows\system32\PCTINDIS5.sys
2009-03-07 04:41 . 2009-03-07 04:41 137752 ----a-w c:\windows\system32\PCTIN50.dll
2009-03-06 14:22 . 2004-08-10 15:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-25 22:58 . 2005-11-10 22:51 3565568 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-25 22:15 . 2008-02-06 09:58 593920 ----a-w c:\windows\system32\ati2sgag.exe
2009-02-25 21:42 . 2007-12-21 03:09 442368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-02-25 21:41 . 2005-11-10 22:52 325120 ----a-w c:\windows\system32\ati2dvag.dll
2009-02-25 21:30 . 2005-11-10 23:06 11841536 ----a-w c:\windows\system32\atioglxx.dll
2009-02-25 21:30 . 2007-12-21 02:59 204800 ----a-w c:\windows\system32\atipdlxx.dll
2009-02-25 21:29 . 2007-12-21 02:59 155648 ----a-w c:\windows\system32\Oemdspif.dll
2009-02-25 21:29 . 2005-11-10 22:46 26112 ----a-w c:\windows\system32\Ati2mdxx.exe
2009-02-25 21:29 . 2005-11-10 22:46 43520 ----a-w c:\windows\system32\ati2edxx.dll
2009-02-25 21:29 . 2005-11-10 22:46 155648 ----a-w c:\windows\system32\ati2evxx.dll
2009-02-25 21:27 . 2005-11-10 22:45 602112 ----a-w c:\windows\system32\ati2evxx.exe
2009-02-25 21:26 . 2007-12-21 02:56 53248 ----a-w c:\windows\system32\ATIDDC.DLL
2009-02-25 21:16 . 2005-11-10 22:37 3817984 ----a-w c:\windows\system32\ati3duag.dll
2009-02-25 21:09 . 2005-11-11 01:33 307200 ----a-w c:\windows\system32\atiiiexx.dll
2009-02-25 20:59 . 2005-11-10 22:32 2670080 ----a-w c:\windows\system32\ativvaxx.dll
2009-02-25 20:44 . 2007-12-21 02:24 49664 ----a-w c:\windows\system32\amdpcom32.dll
2009-02-25 20:40 . 2005-11-10 22:19 475136 ----a-w c:\windows\system32\atikvmag.dll
2009-02-25 20:38 . 2009-02-25 20:38 126976 ----a-w c:\windows\system32\atiadlxx.dll
2009-02-25 20:38 . 2005-11-10 22:00 17408 ----a-w c:\windows\system32\atitvo32.dll
2009-02-25 20:37 . 2005-11-10 21:59 53248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-25 20:35 . 2007-12-21 02:15 290816 ----a-w c:\windows\system32\atiok3x2.dll
2009-02-25 20:32 . 2009-02-25 20:32 45056 ----a-w c:\windows\system32\aticalrt.dll
2009-02-25 20:32 . 2009-02-25 20:32 45056 ----a-w c:\windows\system32\aticalcl.dll
2009-02-25 20:32 . 2005-11-10 21:55 626688 ----a-w c:\windows\system32\ati2cqag.dll
2009-02-25 20:30 . 2009-02-25 20:30 3227648 ----a-w c:\windows\system32\aticaldd.dll
2009-02-17 19:21 . 2009-02-17 19:21 40960 ----a-w c:\windows\Imagination Studio.dll
2009-02-17 19:21 . 2009-02-17 19:21 184400 ----a-w c:\windows\Imagination Studio.scr
2009-02-17 19:21 . 2009-02-17 19:21 18192 ----a-w c:\windows\Imagination Studio.dat
2009-02-17 19:21 . 2009-02-17 19:21 1071752 ----a-w c:\windows\Imagination Studio.exe
2009-02-09 12:10 . 2004-08-10 15:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-10 15:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-10 15:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-10 15:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-10 15:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-08 02:02 . 2004-08-10 15:00 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-07 02:03 . 2009-02-07 02:03 307576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-07 01:52 . 2009-02-07 01:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 11:11 . 2004-08-10 15:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2004-08-10 15:00 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-10 15:00 35328 ----a-w c:\windows\system32\sc.exe
2008-11-26 23:07 . 2009-04-24 16:06 4822 ----a-w c:\program files\install.ini
2008-11-26 23:02 . 2009-04-24 16:13 1222776 ----a-w c:\program files\check.md
2008-11-26 23:02 . 2009-04-24 16:12 660612519 ----a-w c:\program files\data1.pck
2008-11-26 23:02 . 2009-04-24 16:06 623501266 ----a-w c:\program files\data4.pck
2008-11-26 23:00 . 2009-04-24 16:07 660569555 ----a-w c:\program files\data3.pck
2008-11-26 22:57 . 2009-04-24 16:10 660636086 ----a-w c:\program files\data2.pck
2008-08-04 21:52 . 2009-04-24 16:13 29256 ----a-w c:\program files\CopyRight.txt
2007-03-13 22:20 . 2008-05-04 07:52 35979 ----a-w c:\program files\Photoshop CS3 Read Me.html
2005-07-14 22:12 . 2009-04-24 16:06 4150 ----a-w c:\program files\icon.ico
2006-09-21 08:32 . 2006-09-21 08:32 22 --sha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-07 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DriverCure"="c:\program files\ParetoLogic\DriverCure\DriverCure.exe" [2009-02-27 2922064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-07-27 221184]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2009-04-08 75008]
"RDVCHG"="c:\program files\Sprint\Sprint SmartView\RDVCHG.exe" [2009-03-07 316672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DNA
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Corel\\WordPerfect Office 2002\\Register\\NAVBrowser.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.4.3-to-3.0.2-enUS-Win-Final-downloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Sprint\\Sprint SmartView\\SwiApiMux.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"27074:TCP"= 27074:TCP:BitComet 27074 TCP
"27074:UDP"= 27074:UDP:BitComet 27074 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundRouterRequest"= 1 (0x1)
R1 yxksognn;yxksognn; [x]
R3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-07 533360]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2009-02-07 55152]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-15 226656]
S3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-04-23 812544]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-05-05 c:\windows\Tasks\DriverCure.job
- c:\program files\ParetoLogic\DriverCure\DriverCure.exe [2009-02-27 19:07]
2009-05-05 c:\windows\Tasks\ParetoLogic Privacy Controls_{73782D74-394A-11DE-A19F-0014A5BEDD6A}.job
- c:\program files\ParetoLogic\Privacy Controls\Pareto_PC.exe [2008-11-25 18:29]
2009-05-05 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]
2009-05-05 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
2009-05-05 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
2009-05-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
2009-03-05 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-11-27 16:59]
2007-11-27 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-11-27 16:59]
.
- - - - ORPHANS REMOVED - - - -
BHO-{69A746D8-80D5-40DE-A020-C029F3845E79} - (no file)
BHO-{AA9B4AAD-1B34-41A3-8125-99B296FDEA1D} - c:\windows\system32\rqRIxUMD.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://news.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://rappelz.gpotato.com/download/tutorial.php
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Kyle Rinkes\Application Data\Mozilla\Firefox\Profiles\2crlanbf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
FF - component: c:\documents and settings\Kyle Rinkes\Application Data\Mozilla\Firefox\Profiles\2crlanbf.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\documents and settings\Kyle Rinkes\Application Data\Mozilla\Firefox\Profiles\2crlanbf.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07074039.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npitunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-05 01:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1080)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(8024)
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\progra~1\WINDOW~1\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\windows\system32\spool\drivers\w32x86\3\HPZIPM12.EXE
c:\windows\ehome\mcrdsvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
.
**************************************************************************
.
Completion time: 2009-05-05 1:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-05 08:43
Pre-Run: 7,567,183,872 bytes free
Post-Run: 7,442,120,704 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
354 --- E O F --- 2009-04-29 15:59
Thanks in advance