Well thank you[sorry admin I messed up somewhere placing the thread] I got through combofix which found and deleted a few things but I still have problems. A new one stranger that before actually, and I believe it was already happening though and is not related to this. I can't log in using safemode.... as soon as the finger comes up where I can actually select my profile it reboots the computer. I'm guessing a reinstall was in order, but I tried before and it's caused more problems[can you believe that?]. I tried a few weeks back, and the install didnt finish. Now every time the computer is starting up I have to select what windows starts and it defaults to windows setup which then gives me an error and stays there unless I reset, so I have to choose the top one every time. Yes my computer has some problems haven't reinstalled in years but a clean wipe is just not really viable. Anyway back to the logs:
ComboFix 08-06-12.2 - Teddy 2008-06-14 23:27:06.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1438 [GMT -7:00]
Running from: D:\Documents and Settings\Teddy.GAMERSCOMP\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Documents and Settings\Jakob\err.log
D:\Documents and Settings\Teddy.GAMERSCOMP\err.log
D:\setup.exe
D:\WINDOWS\hosts
D:\WINDOWS\rs.txt
D:\WINDOWS\system32\c1
D:\WINDOWS\system32\drivers\core.cache.dsk
D:\WINDOWS\system32\j2
D:\WINDOWS\system32\m8
D:\WINDOWS\system32\MSINET.oca
D:\WINDOWS\system32\qtvwa.ini
D:\WINDOWS\system32\qtvwa.ini2
D:\WINDOWS\system32\rMa14yy
D:\WINDOWS\system32\winitn.dll
H:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-05-15 to 2008-06-15 )))))))))))))))))))))))))))))))
.
2008-06-14 18:43 . 2008-06-14 18:43 <DIR> d-------- D:\Deckard
2008-06-14 18:35 . 2008-06-14 18:35 <DIR> d-------- D:\Program Files\Trend Micro
2008-06-14 10:50 . 2008-06-14 18:52 <DIR> d-------- D:\Program Files\Common Files\AOL
2008-06-14 10:50 . 2008-06-14 10:50 <DIR> d-------- D:\Documents and Settings\Jakob\Application Data\acccore
2008-06-14 10:50 . 2008-06-14 10:50 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\AOL OCP
2008-06-14 10:50 . 2008-06-14 10:50 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\AOL
2008-06-14 10:49 . 2008-06-14 10:50 <DIR> d-------- D:\Program Files\AIM6
2008-06-13 22:30 . 2008-06-13 22:30 <DIR> d-------- D:\Program Files\Security Task Manager
2008-06-11 21:13 . 2008-06-11 21:13 33,792 --a------ D:\WINDOWS\system32\sdqnike.dll
2008-06-10 16:59 . 2008-06-10 16:59 <DIR> d-------- D:\Documents and Settings\Jakob\Application Data\Leadertech
2008-06-10 13:17 . 2008-04-14 04:01 272,128 --------- D:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 13:17 . 2008-04-14 04:01 272,128 -----c--- D:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 18:30 . 2008-06-03 18:30 <DIR> d-------- D:\WINDOWS\nvidia icons
2008-06-02 17:56 . 2008-06-02 17:56 41,296 --a--c--- D:\WINDOWS\system32\xfcodec.dll
2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ D:\WINDOWS\system32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ D:\WINDOWS\system32\QuickTime.qts
2008-05-25 11:58 . 2008-05-02 22:46 6,554,496 --a------ D:\WINDOWS\system32\drivers\nv4_mini.sys
2008-05-23 10:38 . 2008-05-23 10:38 <DIR> d-------- D:\Documents and Settings\Jakob\Application Data\RTPlayer
2008-05-23 10:37 . 2008-05-23 11:18 <DIR> d-------- D:\Documents and Settings\Jakob\Application Data\tunebite
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ D:\WINDOWS\system32\lsdelete.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-06-15 06:34 --------- d---a-w D:\Documents and Settings\All Users\Application Data\TEMP
2008-06-15 04:30 --------- d-----w D:\Program Files\Steam
2008-06-15 02:01 --------- d-----w D:\Program Files\Tunebite
2008-06-15 01:52 --------- d-----w D:\Documents and Settings\Teddy.GAMERSCOMP\Application Data\Tunebite
2008-06-15 01:48 --------- d-----w D:\Documents and Settings\Teddy.GAMERSCOMP\Application Data\Xfire
2008-06-15 00:09 --------- d-----w D:\Program Files\QuickTime
2008-06-14 17:50 --------- d-----w D:\Program Files\Viewpoint
2008-06-14 17:50 --------- d-----w D:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-14 17:46 --------- d-----w D:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-06-14 09:21 --------- d-----w D:\Program Files\Lavasoft
2008-06-14 09:21 --------- d-----w D:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-14 09:20 --------- d-----w D:\Program Files\Common Files\Wise Installation Wizard
2008-06-14 05:45 --------- d-----w D:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-06-14 05:38 --------- d-----w D:\Program Files\Spyware Doctor
2008-06-12 05:14 --------- d-----w D:\Documents and Settings\Teddy.GAMERSCOMP\Application Data\BitTorrent
2008-06-11 18:02 --------- d-----w D:\Program Files\Lx_cats
2008-06-10 01:22 --------- d-----w D:\Program Files\Xfire
2008-06-03 04:24 --------- d-----w D:\Program Files\Eusing Free Registry Cleaner
2008-05-29 17:48 --------- d-----w D:\Program Files\Games Workshop
2008-05-24 07:04 --------- d-----w D:\Documents and Settings\Teddy.GAMERSCOMP\Application Data\IGN_DLM
2008-05-20 08:23 --------- d-----w D:\Documents and Settings\Jakob\Application Data\Xfire
2008-05-19 23:09 22,328 -c--a-w D:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-12 00:22 22,328 -c--a-w D:\Documents and Settings\Teddy.GAMERSCOMP\Application Data\PnkBstrK.sys
2008-05-08 12:28 202,752 ----a-w D:\WINDOWS\system32\drivers\rmcast.sys
2008-04-29 18:20 15,648 ----a-w D:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 18:19 15,648 ----a-w D:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 18:19 12,960 ----a-w D:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-28 02:40 --------- d-----w D:\Program Files\LimeWire
2008-04-23 23:26 --------- d-----w D:\Program Files\Apple Software Update
2008-04-21 07:44 --------- d-----w D:\Program Files\MySpace
2008-04-21 07:44 --------- d-----w D:\Documents and Settings\Jakob\Application Data\MySpace
2008-04-19 04:03 --------- d-----w D:\Documents and Settings\Jakob\Application Data\LimeWire
2008-04-15 06:03 --------- d-----w D:\Documents and Settings\Teddy.GAMERSCOMP\Application Data\LimeWire
2008-04-15 00:07 --------- d-----w D:\Documents and Settings\All Users\Application Data\RapidSolution
2008-03-29 07:27 167 -c--a-w D:\Documents and Settings\Teddy.GAMERSCOMP\udownload.dat
2008-03-22 10:17 2,829 -c--a-w D:\WINDOWS\War3Unin.pif
2008-03-22 10:17 139,264 -c--a-w D:\WINDOWS\War3Unin.exe
2008-03-22 08:44 33,964 -c--a-w D:\Program Files\install.log
2007-11-27 04:58 246 -c--a-w D:\Program Files\Common Files\quhar
2007-09-11 04:19 22,328 -c--a-w D:\Documents and Settings\Jakob\Application Data\PnkBstrK.sys
2007-07-28 09:06 135 -c--a-w D:\Program Files\Common Files\rteqeg.html
2007-02-13 02:10 2,682,880 -c----w D:\Documents and Settings\All Users\VCREDI~3.EXE
2006-10-31 04:31 0 -c--a-w D:\Documents and Settings\Teddy.GAMERSCOMP\fda2aifc.exe
2006-05-25 06:34 1 -c--a-w D:\Documents and Settings\Jakob\SI.bin
2006-03-08 23:48 26,922 -c--a-w D:\Program Files\MoviePass Terms.html
2006-02-24 08:17 22,264 -c--a-w D:\Program Files\keys.dat
2006-02-24 08:17 1,803 -c--a-w D:\Program Files\preferences.txt
2005-12-27 09:40 3,341,892 -c--a-w D:\Program Files\iTunesSetup.exe
2005-12-26 15:36 11,079 -c-ha-w D:\Program Files\folder.htt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"NVIDIA nTune"="D:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32 81920]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-07-21 02:01 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"CTSysVol"="D:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 17:10 57344]
"ISTray"="D:\Program Files\Spyware Doctor\pctsTray.exe" [2008-06-02 21:51 1107848]
"iTunesHelper"="D:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"LXDCCATS"="D:\WINDOWS\System32\spool\DRIVERS\W32X 86\3\LXDCtime.dll" [2007-01-22 15:05 102400]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 D:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="D:\WINDOWS\system32\NvMcTray. dll" [2008-05-02 22:46 86016]
"QuickTime Task"="D:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="D:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-03-22 19:29 39264]
"MySpaceIM"="D:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 13:32 8699904]
D:\Documents and Settings\Teddy.GAMERSCOMP\Start Menu\Programs\Startup\
hc_tray.lnk - D:\Program Files\Kuma Games\hcsystray\hc_tray.exe [2007-04-26 13:49:20 31944]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"NoSecCPL"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"NoResolveSearch"= 1 (0x1)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"DisableMyPicturesDirChange"= 0 (0x0)
"DisableMyMusicDirChange"= 0 (0x0)
"DisableFavoritesDirChange"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"NoStrCmpLogical"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoStrCmpLogical"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"NoSMBalloonTip"= 1 (0x1)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoAutoTrayNotify"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sdqnike]
sdqnike.dll 2008-06-11 21:13 33792 D:\WINDOWS\system32\sdqnike.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtursro]
vtursro.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKLM\~\startupfolder\D:^Documents and Settings^Teddy.GAMERSCOMP^Start Menu^Programs^Startup^Diskeeper 9 Professional Edition Registration.lnk]
backup=D:\WINDOWS\pss\Diskeeper 9 Professional Edition Registration.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^Teddy.GAMERSCOMP^Start Menu^Programs^Startup^GameSpot Download Manager.lnk]
backup=D:\WINDOWS\pss\GameSpot Download Manager.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^Teddy.GAMERSCOMP^Start Menu^Programs^Startup^Memeo AutoBackup Launcher.lnk]
backup=D:\WINDOWS\pss\Memeo AutoBackup Launcher.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^Teddy.GAMERSCOMP^Start Menu^Programs^Startup^Memeo AutoSync Launcher.lnk]
backup=D:\WINDOWS\pss\Memeo AutoSync Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
--a--c--- 2007-08-08 18:31 148760 D:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
--a--c--- 2007-08-08 18:39 1945448 D:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a--c--- 2008-01-11 23:16 39792 D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced WindowsCare]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
--a------ 2006-08-01 15:35 67112 H:\gamers.comp\Documents\Teddy H DRIVE\A i M\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
-----c--- 2004-12-02 19:23 102400 D:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
--a--c--- 2007-03-05 13:57 1103480 D:\Program Files\IGN\Download Manager\dlm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a--c--- 2006-03-20 18:34 213936 D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 D:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdcamon]
--a--c--- 2007-04-30 08:19 20480 D:\Program Files\Lexmark 1300 Series\lxdcamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxBlastMonitor.exe]
--a--c--- 2007-08-08 18:26 1169440 D:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2008-02-01 13:32 8699904 D:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 10:50 155648 D:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-05-02 22:46 13529088 D:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
--a--c--- 2007-07-03 12:32 81920 D:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-05-02 22:46 86016 D:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-05-02 22:46 1630208 D:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
--a--c--- 2005-05-03 20:38 64512 D:\WINDOWS\system32\P17.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 D:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\razertra]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahsc--- 2008-01-28 12:43 2097488 D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a--c--- 2007-07-21 02:01 68856 D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
--a--c--- 2005-07-08 19:18 151552 D:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
"ImapiService"=3 (0x3)
"McShield"=2 (0x2)
"iPod Service"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"nTuneService"=2 (0x2)
"gusvc"=3 (0x3)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AVGEMS"=2 (0x2)
"aswUpdSv"=2 (0x2)
"nHancer"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
"aawservice"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\WINDOWS\\system32\\LEXPPS.EXE"=
"D:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"D:\\LimeWire\\LimeWire.exe"=
"D:\\Program Files\\LimeWire\\LimeWire.exe"=
"D:\\Program Files\\Steam\\SteamApps\\jtbrekhus\\counter-strike source\\hl2.exe"=
"D:\\Program Files\\Steam\\SteamApps\\jtbrekhus\\day of defeat source\\hl2.exe"=
"D:\\Program Files\\DAP\\DAP.exe"=
"D:\\Program Files\\Steam\\SteamApps\\jtbrekhus\\half-life 2\\hl2.exe"=
"D:\\WINDOWS\\system32\\dpvsetup.exe"=
"D:\\Program Files\\BitTorrent\\bittorrent.exe"=
"D:\\Documents and Settings\\Teddy.GAMERSCOMP\\My Documents\\eMule\\emule.exe"=
"D:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"D:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"D:\\Program Files\\Steam\\SteamApps\\jtbrekhus\\source sdk base\\hl2.exe"=
"D:\\Program Files\\Steam\\SteamApps\\common\\red orchestra\\System\\RedOrchestra.exe"=
"D:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"D:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"D:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"D:\\WINDOWS\\system32\\dplaysvr.exe"=
"D:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files\\NetMeeting\\conf.exe"=
"D:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat"=
"D:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.3\\cnc3game.dat"=
"D:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.4\\cnc3game.dat"=
"D:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"D:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"D:\\Program Files\\CrosuS\\CrosuSApp.exe"=
"D:\\Program Files\\Steam\\SteamApps\\jtbrekhus\\garrysmod\\hl2 .exe"=
"D:\\WINDOWS\\system32\\mmc.exe"=
"D:\\WINDOWS\\system32\\lxdccoms.exe"=
"D:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe"=
"D:\\Program Files\\Lexmark 1300 Series\\app4r.exe"=
"D:\\WINDOWS\\system32\\pnkbstra.exe"=
"D:\\WINDOWS\\system32\\PnkBstrB.exe"=
"D:\\Program Files\\Steam\\Steam.exe"=
"D:\\Program Files\\Steam\\SteamApps\\jtbrekhus\\team fortress 2\\hl2.exe"=
"D:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander - Forged Alliance\\bin\\ForgedAlliance.exe"=
"D:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"D:\\Program Files\\Xfire\\Xfire.exe"=
"D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"D:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"D:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"D:\\Documents and Settings\\Teddy.GAMERSCOMP\\Local Settings\\Application Data\\Xenocode\\ApplianceCaches\\KumaClient.exe_v1 D0007A2\\Native\\STUBEXE\\@PROGRAMFILES@\\Kuma Games\\Kuma.exe"=
"H:\\gamers.comp\\Documents\\Teddy H DRIVE\\eMule\\emule.exe"=
"H:\\gamers.comp\\Documents\\Teddy H DRIVE\\eMule\\xtrememod\\New Folder\\emule.exe"=
"H:\\gamers.comp\\Thrones and Patriots\\Thrones.exe"=
"H:\\gamers.comp\\Documents\\Teddy H DRIVE\\A i M\\aim.exe"=
"D:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"D:\\Program Files\\iTunes\\iTunes.exe"=
"H:\\gamers.comp\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"H:\\gamers.comp\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"D:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \lxdcjswx.exe"=
"D:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \lxdcpswx.exe"=
"D:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"D:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \lxdctime.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Emule reg
"6112:UDP"= 6112:UDP

oW
"6500:UDP"= 6500:UDP:gs
"27900:UDP"= 27900:UDP:gspy
"27901:UDP"= 27901:UDP:gamspy
"28910:TCP"= 28910:TCP:gamnespy
"29900:TCP"= 29900:TCP:gamsp
"29901:TCP"= 29901:TCP:gamsy
"29910:UDP"= 29910:UDP:dowgspy
"29920:TCP"= 29920:TCP:gamespydow
"15101:TCP"= 15101:TCP:tribes 2
"15104:TCP"= 15104:TCP:tribes2
"80:TCP"= 80:TCP:trbies
"6112:TCP"= 6112:TCP:rts
"9103:UDP"= 9103:UDP:gpgnet
"67:UDP"= 67:UDP

HCP Discovery Service
"88:UDP"= 88:UDP:Xbl
"3074:UDP"= 3074:UDP:xbl2
"3074:TCP"= 3074:TCP:xbl3
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"25777:UDP"= 25777:UDP:csxfire.com
"25999:TCP"= 25999:TCP:cs.xfire.com
"30275:UDP"= 30275:UDP:coh 1
"9100:UDP"= 9100:UDP:coh2
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\IcmpSettings]
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
R2 lxdc_device;lxdc_device

:\WINDOWS\system32\lxdcco ms.exe [2007-05-25 09:38]
S3 ewdmaudn;ewdmaudn

:\DOCUME~1\TEDDY~1.GAM\LOCALS~1 \Temp\ewdmaudn.sys []
S3 KTalk;KTalk

:\DOCUME~1\Jakob\LOCALS~1\Temp\ktalk. sys []
S3 Razerlow;Razerlow USB Filter Driver

:\WINDOWS\system32\Drivers\Razerlow.sys [2005-04-24 22:43]
S3 usbprint;Microsoft USB PRINTER Class

:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]
S4 AutoSyncService;Memeo AutoSync ;"D:\Program Files\Memeo\AutoSync\MemeoService.exe" [2007-07-06 18:28]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\wd_windows_tools\setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
D:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-14 23:30:00 D:\WINDOWS\Tasks\Advanced WindowsCare.job"
- D:\Program Files\IObit\Advanced WindowsCare V2\AutoCare.exe
"2008-06-14 04:28:03 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- D:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-15 03:00:00 D:\WINDOWS\Tasks\AwcUpdate.job"
- D:\Program Files\IObit\Advanced WindowsCare V2\AutoUpdate.ex
"2008-06-13 09:00:10 D:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (GAMERSCOMP-Teddy).job"
- d:\program files\mcafee.com\vso\mcmnhdlr.exe
"2008-06-06 00:18:00 D:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- D:\Documents and Settings\Teddy.GAMERSCOMP\My Documents\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-06-21 21:30:34 D:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- D:\Documents and Settings\Teddy.GAMERSCOMP\My Documents\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-14 23:34:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: D:\WINDOWS\explorer.exe
-> D:\WINDOWS\system32\nview.dll
.
------------------------ Other Running Processes ------------------------
.
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\LEXPPS.EXE
D:\WINDOWS\system32\CTSVCCDA.EXE
D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\pnkbstra.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\iPod\bin\iPodService.exe
.
************************************************** ************************
.
Completion time: 2008-06-14 23:38:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-15 06:38:00
Pre-Run: 7,488,720,896 bytes free
Post-Run: 8,840,343,552 bytes free
417 --- E O F --- 2008-06-10 20:32:48
attached is the Hijackthis log and of course thank you for your help so far I really need this as company of heroes and such are virtually unplayable at 6 fps help meh out!!