I downloaded the combofix and the rootlog and the computer seems to be running much smoother now!
ComboFix 07-08-17.2 - "Administrator" 2007-08-24 16:20:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.46.1033.18.1265 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot\Log\log_2007_08_16_15_36_28.log
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot\Log\log_2007_08_16_15_36_48.log
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot\Settings\CustomScan.stg
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot\Settings\IgnoreList.stg
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot\Settings\ScanInfo.stg
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot\Settings\ScanResults.stg
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot\Settings\SelectedFolders.stg
C:\DOCUME~1\ADMINI~1\APPLIC~1\AntiSpywareBot\Settings\Settings.stg
C:\DOCUME~1\ADMINI~1\Desktop.\Spyware&Malware Protection.url
C:\DOCUME~1\ADMINI~1\Desktop\Error Cleaner.url
C:\DOCUME~1\ADMINI~1\Desktop\internet.lnk
C:\DOCUME~1\ADMINI~1\Desktop\Privacy Protector.url
C:\DOCUME~1\ADMINI~1\FAVORI~1.\Error Cleaner.url
C:\DOCUME~1\ADMINI~1\FAVORI~1.\Privacy Protector.url
C:\DOCUME~1\ADMINI~1\FAVORI~1.\Spyware&Malware Protection.url
C:\WINDOWS\dat.txt
C:\WINDOWS\main_uninstaller.exe
C:\WINDOWS\sconf32.dll
C:\WINDOWS\Tasks.\AntiSpywareBot Scheduled Scan.job
C:\WINDOWS\wmplayer.dll
C:\WINDOWS\wmsound.dll
((((((((((((((((((((((((( Files Created from 2007-07-24 to 2007-08-24 )))))))))))))))))))))))))))))))
2007-08-24 16:18 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-24 16:10 <KAT> d-------- C:\WINDOWS\LastGood.Tmp
2007-08-22 23:08 82,248 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-22 23:08 57,672 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-22 23:08 40,264 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-22 23:08 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-08-22 23:07 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-22 23:07 <KAT> d-------- C:\Program Files\Spyware Doctor
2007-08-22 23:07 <KAT> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Tools
2007-08-22 22:05 <KAT> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-08-22 22:04 <KAT> d-------- C:\Program Files\Lavasoft
2007-08-18 20:56 218,112 --a------ C:\alternativ.exe
2007-08-16 22:46 <KAT> d-------- C:\WINDOWS\system32\appmgmt
2007-08-16 21:09 <KAT> d-------- C:\Program Files\SPYWAREfighter
2007-08-16 21:09 <KAT> d-------- C:\Program Files\Common Files\Application
2007-08-14 15:31 <KAT> d-------- C:\Program Files\CCleaner
2007-08-14 14:59 <KAT> d-------- C:\WINDOWS\network diagnostic
2007-08-07 00:04 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-06 17:11 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-08-06 17:10 <KAT> d-------- C:\Program Files\Common Files\Download Manager
2007-08-06 16:03 <KAT> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-05 21:29 <KAT> d-------- C:\Program Files\iTunes
2007-08-05 21:29 <KAT> d-------- C:\Program Files\iPod
2007-07-31 14:37 <KAT> d-------- C:\Program Files\Personal
2007-07-31 14:37 <KAT> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Personal
2007-07-31 14:37 <KAT> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Netscape
2007-07-31 14:32 <KAT> d-------- C:\DOCUME~1\ADMINI~1\cbt
2007-07-24 23:34 <KAT> d-------- C:\Program Files\traffic3D
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-24 16:24 --------- d-------- C:\Program Files\BullGuard
2007-08-05 21:28 --------- d-------- C:\Program Files\Apple Software Update
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-16 00:08 --------- d-------- C:\Program Files\QuickTime
2007-07-16 00:05 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-01 17:00 --------- d-------- C:\Program Files\DivX
2007-06-26 08:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 12:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-08 11:52 947096 --a------ C:\WINDOWS\system32\_ISource30.dll
2007-05-31 08:45 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-05-31 08:44 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 08:44 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 08:44 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 08:44 740442 --a------ C:\WINDOWS\system32\DivX.dll
2007-05-27 22:32 3676952 --a------ C:\Program Files\DivXWebPlayerInstaller.exe
2007-04-11 23:28 1823624 --a------ C:\Program Files\WindowsXP-KB925902-x86-ENU.exe
2007-04-02 17:42 37860928 --a------ C:\Program Files\iTunesSetup.exe
2007-03-11 15:47 14730232 --a------ C:\Program Files\DivXInstaller.exe
2006-12-15 22:53 5926912 --a------ C:\Program Files\pokerclient.exe
2006-11-20 17:08 2005504 --ahs---- C:\Program Files\ehthumbs.db
2006-11-10 18:27 359112 --a------ C:\Program Files\LimeWireWin.exe
2006-11-08 17:49 16193832 --a------ C:\Program Files\Install_Messenger.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{34E6F97C-34E0-4CE5-B92B-F83634BEDC01}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:56]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 C:\WINDOWS\system32\HdAShCut.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 21:00 C:\WINDOWS\system32\bthprops.cpl]
"RaidTool"="C:\Program Files\VIA\RAID\raid_tool.exe" [2005-08-12 17:38]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 18:41]
"RTHDCPL"="RTHDCPL.EXE" [2006-02-27 18:28 C:\WINDOWS\RTHDCPL.exe]
"SMSERIAL"="sm56hlpr.exe" [2005-09-16 15:01 C:\WINDOWS\sm56hlpr.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-25 16:25]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-04-15 17:13]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-29 22:55]
"BDMCon"="C:\Program Files\BullGuard\\bdmcon.exe" [2004-08-09 16:11]
"BGNewsAgent"="C:\Program Files\BullGuard\bgnewsag.exe" [2004-05-03 14:28]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 19:41]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
"spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 17:02]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:55]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-30 20:41]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Personal.lnk - C:\Program Files\Personal\bin\Personal.exe [2007-07-31 14:37:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=sockspy.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys
R2 FILESpy;FILESpy;\??\C:\Program Files\BullGuard\filespy.sys
R2 REGSpy;REGSpy;\??\C:\Program Files\BullGuard\regspy.sys
R3 SpyFighter;SpyFighter Guard Device;\??\C:\Program Files\SPYWAREfighter\spyfighter.sys
R3 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Program Files\SPYWAREfighter\spfprc.exe"
S3 BVRPMPR5;BVRPMPR5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
S3 MOD3700;XM400I Analog/DVB-T;C:\WINDOWS\system32\Drivers\xm400i.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0315784-e99a-11db-b4fa-001060d019ae}]
AutoRun\command- F:\Installer.exe
Contents of the 'Scheduled Tasks' folder
2007-08-18 19:47:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-24 16:29:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BGNewsAgent = C:\Program Files\BullGuard\bgnewsag.exe?????????????8???8??? ??????????|x??|????q??|????????`???????????????????????????`???????????b?oc????j?oc????????????????????05?????????|i'pc???????????????????????????? ?(_?k?w1???????tl?w????H???p*@??????*@?????1??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-24 16:33:00 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-24 16:32
--- E O F ---
********************************* ROOTCHK-(22-08-07)-LOG, by ejvindh
2007-08-24 16:16:08,01
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-24 16:16:08
Windows 5.1.2600 Service Pack 2
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
detected NTDLL code modification:
ZwClose
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001060d019ae]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001060d019ae]
detected NTDLL code modification:
ZwClose
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000214
detected NTDLL code modification:
ZwClose
scanning hidden files ...
hidden processes: 0
hidden files: 0
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 23:41:43 2007-08-24
+ Scan result:
C:\Documents and Settings\Administrator\Cookies\administrator@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@connextra[3].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
::Report end
Thank you so much for your help!!
Johannes