i just realized that this all started the day after i changed from avir anti-virus to mbam. could the mbam be what is making my computer sluggish? I thought the the avira was not really doing anything so i decided to switch over.
heres the combofix log
ComboFix 09-04-01.01 - ben 2009-04-02 19:21:24.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.991.586 [GMT -4:00]
Running from: c:\documents and settings\ben\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-02 to 2009-04-02 )))))))))))))))))))))))))))))))
.
2009-03-29 14:39 . 2009-03-29 14:39 685,056 --a------ c:\windows\isRS-000.tmp
2009-03-25 17:38 . 2009-03-29 14:31 <DIR> d-------- C:\Rooter$
2009-03-25 14:43 . 2009-03-25 14:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-03-10 22:04 . 2009-03-10 22:04 <DIR> d-------- c:\documents and settings\ben\Application Data\AdobeUM
2009-03-07 17:23 . 2009-03-07 17:23 <DIR> d-------- c:\program files\NOS
2009-03-07 17:23 . 2009-03-07 17:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-03-06 15:05 . 2009-03-29 14:40 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-06 15:05 . 2009-03-06 15:05 <DIR> d-------- c:\documents and settings\ben\Application Data\Malwarebytes
2009-03-06 15:05 . 2009-03-06 15:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-06 15:05 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-06 15:05 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 23:06 --------- d-----w c:\program files\Warcraft III
2009-03-27 20:11 34 ----a-w c:\documents and settings\ben\jagex_runescape_preferences.dat
2009-03-26 01:50 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-25 18:58 --------- d-----w c:\documents and settings\ben\Application Data\BitTorrent
2009-03-06 00:37 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-28 17:26 --------- d-----w c:\documents and settings\ben\Application Data\Auslogics
2009-02-23 00:34 --------- d-----w c:\documents and settings\ben\Application Data\InterVideo
2009-02-21 06:29 --------- d-----w c:\program files\Auslogics
2009-02-21 05:15 --------- d-----w c:\program files\DivX
2009-02-18 04:42 --------- d-----w c:\documents and settings\ben\Application Data\DivX
2009-02-06 05:00 --------- d-----w c:\program files\PokerStars
2009-01-07 01:51 2,829 ------w c:\windows\War3Unin.pif
2009-01-07 01:51 139,264 ------w c:\windows\War3Unin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-02 7557120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-11 136600]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-14 503808]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 221184]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 2341632]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-03-26 401040]
"nwiz"="nwiz.exe" [2006-03-02 c:\windows\system32\nwiz.exe]
"Mouse Suite 98 Daemon"="ICO.EXE" [2005-04-13 c:\windows\system32\ico.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
c:\documents and settings\ben\Start Menu\Programs\Startup\
OneNote Table Of Contents.onetoc2 [2009-01-20 3656]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-03-06 179856]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [2006-07-14 3968]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-03-06 15504]
R3 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMOUSE.SYS [2009-01-05 16384]
R3 pelusblf;USB Mouse Low Filter Driver;c:\windows\system32\drivers\pelusblf.sys [2009-01-05 9216]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-03-07 33752]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{129a2f61-db95-11dd-86f0-001617ac11b0}]
\Shell\AutoRun\command - D:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E17D8D3C-762E-E86C-BC90-D2638B15129B}]
c:\windows\alg.exe
.
Contents of the 'Scheduled Tasks' folder
2009-04-02 c:\windows\Tasks\Malwarebytes' Scheduled Update for ben.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-26 16:49]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.lenovo.com/us/en/
IE: &Download All with FlashGet - c:\documents and settings\Default User\Local Settings\Temp\flgpxtryd\jc_all.htm
IE: &Download with FlashGet - c:\documents and settings\Default User\Local Settings\Temp\flgpxtryd\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\ben\Application Data\Mozilla\Firefox\Profiles\ul8mikez.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-02 19:36:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Zune\ZuneNss.exe
c:\windows\system32\FSRremoS.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\PELMICED.EXE
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-04-02 19:46:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-02 23:46:48
Pre-Run: 166,566,019,072 bytes free
Post-Run: 166,515,478,528 bytes free
135 --- E O F --- 2009-03-15 14:59:43