Thanks for the help so far, I thought it was too good to be true this website at first
Heres the Combo log:
"Paul" - 2007-07-07 10:28:22 - ComboFix 07-07-04.4 - Service Pack 2
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
D:\WINDOWS\system32\aleikkcl.dll
D:\WINDOWS\system32\byxyxvs.dll
D:\WINDOWS\system32\efcbaxy.dll
D:\WINDOWS\system32\exyusjjo.dll
D:\WINDOWS\system32\fauemfcc.dll
D:\WINDOWS\system32\fbgyfmvq.dll
D:\WINDOWS\system32\fgjeegoj.dll
D:\WINDOWS\system32\hggdaya.dll
D:\WINDOWS\system32\hggfffd.dll
D:\WINDOWS\system32\iifcywv.dll
D:\WINDOWS\system32\kdpcgqvn.dll
D:\WINDOWS\system32\khfdaxv.dll
D:\WINDOWS\system32\lcnjsicx.dll
D:\WINDOWS\system32\ljjihfd.dll
D:\WINDOWS\system32\ljjjjjg.dll
D:\WINDOWS\system32\mntxtmux.dll
D:\WINDOWS\system32\qomkifg.dll
D:\WINDOWS\system32\reuityan.dll
D:\WINDOWS\system32\sbjexsmt.dll
D:\WINDOWS\system32\sgapyvql.dll
D:\WINDOWS\system32\ssqpoml.dll
D:\WINDOWS\system32\ssqrqro.dll
D:\WINDOWS\system32\syllgqhv.dll
D:\WINDOWS\system32\urqqolk.dll
D:\WINDOWS\system32\uuljjaxc.dll
D:\WINDOWS\system32\vlvqpcdj.dll
D:\WINDOWS\system32\vtvlfnxc.dll
D:\WINDOWS\system32\lckkiela.ini
D:\WINDOWS\system32\ojjsuyxe.ini
D:\WINDOWS\system32\qvmfygbf.ini
D:\WINDOWS\system32\uwycf.bak1
D:\WINDOWS\system32\uwycf.bak2
D:\WINDOWS\system32\uwycf.ini
D:\WINDOWS\system32\nvqgcpdk.ini
D:\WINDOWS\system32\xcisjncl.ini
D:\WINDOWS\system32\xumtxtnm.ini
D:\WINDOWS\system32\naytiuer.ini
D:\WINDOWS\system32\tmsxejbs.ini
D:\WINDOWS\system32\lqvypags.ini
D:\WINDOWS\system32\vhqgllys.ini
D:\WINDOWS\system32\cxajjluu.ini
D:\WINDOWS\system32\cxnflvtv.ini
D:\WINDOWS\system32\fcywu.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-06-07 to 2007-07-07 )))))))))))))))))))))))))))))))
2007-07-06 23:34 51,200 --a------ D:\WINDOWS\nircmd.exe
2007-07-06 17:48 556,544 --a------ D:\WINDOWS\system32\NexPlayerX.dll
2007-07-06 17:29 94,000 --a------ D:\WINDOWS\system32\drivers\ss_mdm.sys
2007-07-06 17:29 6,144 --a------ D:\WINDOWS\system32\drivers\ss_cmnt.sys
2007-07-06 17:29 6,144 --a------ D:\WINDOWS\system32\drivers\ss_cm.sys
2007-07-06 17:28 8,304 --a------ D:\WINDOWS\system32\drivers\ss_mdfl.sys
2007-07-06 17:28 58,320 --a------ D:\WINDOWS\system32\drivers\ss_bus.sys
2007-07-06 17:28 5,808 --a------ D:\WINDOWS\system32\drivers\ss_whnt.sys
2007-07-06 17:28 5,808 --a------ D:\WINDOWS\system32\drivers\ss_wh.sys
2007-07-06 17:28 <DIR> d-------- D:\WINDOWS\system32\Samsung_USB_Drivers
2007-07-06 16:59 50,752 --a------ D:\WINDOWS\system32\idxjcqax.exe
2007-07-05 12:31 344,064 --a------ D:\WINDOWS\system32\msexch35.dll
2007-07-05 12:31 294,912 --a------ D:\WINDOWS\system32\msxbse35.dll
2007-07-05 12:31 262,144 --a------ D:\WINDOWS\system32\msrd2x35.dll
2007-07-05 12:31 166,672 --a------ D:\WINDOWS\system32\mstext35.dll
2007-07-05 12:31 139,264 --a------ D:\WINDOWS\system32\msjint35.dll
2007-07-05 12:30 44,304 --a------ D:\WINDOWS\system32\msrpfs35.dll
2007-07-05 12:30 415,504 --a------ D:\WINDOWS\system32\msrepl35.dll
2007-07-05 12:30 39,424 --a------ D:\WINDOWS\system32\JETCOMP.exe
2007-07-05 12:30 368,912 --a------ D:\WINDOWS\system32\VBAR332.DLL
2007-07-05 12:30 252,688 --a------ D:\WINDOWS\system32\msexcl35.dll
2007-07-05 12:30 250,128 --a------ D:\WINDOWS\system32\mspdox35.dll
2007-07-05 12:30 24,848 --a------ D:\WINDOWS\system32\msjter35.dll
2007-07-05 12:30 168,720 --a------ D:\WINDOWS\system32\msltus35.dll
2007-07-05 12:30 1,238,288 --a------ D:\WINDOWS\system32\msjt4jlt.dll
2007-07-05 12:30 1,050,896 --a------ D:\WINDOWS\system32\msjet35.dll
2007-07-05 12:30 <DIR> d-------- D:\Program Files\Samsung
2007-06-27 22:19 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-27 22:16 <DIR> d-------- D:\Program Files\SUPERAntiSpyware
2007-06-27 22:16 <DIR> d-------- D:\DOCUME~1\Paul\APPLIC~1\SUPERAntiSpyware.com
2007-06-26 23:26 552 --a------ D:\WINDOWS\system32\d3d8caps.dat
2007-06-26 22:37 10,872 --a------ D:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-25 20:07 <DIR> d-------- D:\Program Files\Picasa2
2007-06-25 20:07 <DIR> d-------- D:\Program Files\Google
2007-06-24 21:27 <DIR> d-------- D:\Program Files\Lavasoft
2007-06-24 21:27 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-24 21:19 <DIR> d-------- D:\Program Files\Common Files\Wise Installation Wizard
2007-06-23 14:35 4,672 --a------ D:\WINDOWS\system32\dfmhbdel.exe
2007-06-18 17:27 <DIR> d-------- D:\DOCUME~1\Paul\OngameNetwork
2007-06-17 15:21 126,016 --a------ D:\WINDOWS\system32\aaxmlgom.dll
2007-06-13 14:20 <DIR> d-------- D:\Program Files\MSN Messenger
2007-06-11 15:33 147,456 --a------ D:\DOCUME~1\Hannah\spee.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-06 18:33:27 -------- d--h--w D:\Program Files\InstallShield Installation Information
2007-07-05 18:56:22 -------- d-----w D:\Program Files\Common Files\InstallShield
2007-07-03 20:42:38 -------- d-----w D:\Program Files\PokerRoom.com
2007-06-13 13:00:29 -------- d-----w D:\Program Files\TVAnts
2007-06-04 14:42:28 -------- d-----w D:\Program Files\Audacity
2007-06-04 14:18:48 9,344 ----a-w D:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 14:17:02 8,320 ----a-w D:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 14:14:56 6,272 ----a-w D:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-14 21:51:34 -------- d-----w D:\Program Files\Online Services
2007-05-14 15:52:46 -------- d-----w D:\Program Files\Ahead
2007-05-14 15:52:34 -------- d-----w D:\Program Files\Common Files\Ahead
2007-05-02 21:57:47 1,477 -c--a-w D:\WINDOWS\mozver.dat
2007-04-18 16:12:23 2,854,400 ----a-w D:\WINDOWS\system32\msi.dll
2007-04-16 21:47:36 33,624 -c--a-w D:\WINDOWS\system32\wups.dll
2007-04-16 21:45:54 1,710,936 ----a-w D:\WINDOWS\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 ----a-w D:\WINDOWS\system32\wuapi.dll
2007-04-16 21:45:42 325,976 ----a-w D:\WINDOWS\system32\wucltui.dll
2007-04-16 21:45:36 203,096 ----a-w D:\WINDOWS\system32\wuweb.dll
2007-04-16 21:45:28 92,504 ----a-w D:\WINDOWS\system32\cdm.dll
2007-04-16 21:45:20 53,080 ----a-w D:\WINDOWS\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 -c--a-w D:\WINDOWS\system32\wups2.dll
2007-04-13 14:19:52 7,680 ----a-w D:\WINDOWS\system32\lsdelete.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38]
"AVG7_CC"="D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-02-09 11:43]
"Windows Defender"="D:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ISUSPM"="D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 18:34]
"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"iTunesHelper"="D:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="D:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-01-24 11:37]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"SUPERAntiSpyware"="D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39]
"Uniblue Registry Booster"="D:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe" []
"MSMSGS"="D:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="D:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="D:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnmkll]
nnnmkll.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
Contents of the 'Scheduled Tasks' folder
2007-07-07 10:14:12 D:\WINDOWS\tasks\MP Scheduled Scan.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-07 11:15:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-07 11:17:52
D:\ComboFix-quarantined-files.txt ... 2007-07-07 11:17
--- E O F ---
And heres a fresh HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 11:20:25, on 07/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\EPSON\ESM2\eEBSVC.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\system32\imapi.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\notepad.exe
D:\Program Files\HijackThis\seek.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
https://login.live.c...uth.srf?lc=2057O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISUSPM] "D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Uniblue Registry Booster] D:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://*.windowsupdate.comO16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zon...kr.cab56986.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cabO16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zon...er.cab56986.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSN Messenger\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: nnnmkll - nnnmkll.dll (file missing)
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - D:\Program Files\EPSON\ESM2\eEBSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Unknown owner - D:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: IviRegMgr - InterVideo - D:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
-----
The PC isn't really behaving any differently as far as I can see either.