Here are the two logs I did:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:23:52, on 26/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Billionton\Bluetooth Software\bin\btwdins.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: BTTray.lnk = ?
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Billionton\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Billionton\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Billionton\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 9350 bytes
ComboFix 09-04-25.A3 - angelita 26/04/2009 22:05.9 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.250 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: COMODO Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000021_.tmp.dll
c:\windows\system32\_000022_.tmp.dll
c:\windows\system32\_000023_.tmp.dll
c:\windows\system32\_000024_.tmp.dll
c:\windows\system32\kr_done1
—– BITS: Possible infected sites —–
hxxp://download.linksys.com
.
((((((((((((((((((((((((( Files Created from 2009-05-26 to 2009-4-26 )))))))))))))))))))))))))))))))
.
2009-04-26 13:27 . 2009-04-26 13:27 ——– d-sh–w c:\documents and settings\angelita\IECompatCache
2009-04-26 13:27 . 2009-04-26 13:27 ——– d-sh–w c:\documents and settings\angelita\PrivacIE
2009-04-26 13:24 . 2009-04-26 13:24 ——– d-sh–w c:\documents and settings\NetworkService\IETldCache
2009-04-26 13:24 . 2009-04-26 13:24 ——– d-sh–w c:\documents and settings\angelita\IETldCache
2009-04-26 13:07 . 2009-04-26 13:12 ——– dc-h–w c:\windows\ie8
2009-04-26 12:52 . 2009-04-26 12:52 ——– d—–w C:\c32e251886cc88127a0fc7a4
2009-04-26 12:32 . 2009-04-26 12:32 ——– d—–w c:\program files\Pure Networks
2009-04-26 12:30 . 2008-09-14 10:36 23992 —-a-w c:\windows\system32\drivers\pnarp.sys
2009-04-26 12:30 . 2008-09-14 10:36 25272 —-a-w c:\windows\system32\drivers\purendis.sys
2009-04-23 22:06 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-23 22:06 . 2009-03-06 14:22 284160 —-a-w c:\windows\system32\SETD5.tmp
2009-04-23 22:06 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-23 22:06 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-23 22:06 . 2009-02-09 12:10 401408 —-a-w c:\windows\system32\SETD4.tmp
2009-04-23 22:06 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-23 22:06 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-23 22:06 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-23 22:06 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-23 22:06 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-23 22:06 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-23 21:59 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-23 21:59 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-04-23 21:59 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-23 02:47 . 2009-04-23 02:47 ——– d—–w c:\windows\system32\LogFiles
2009-04-14 00:04 . 2009-04-14 00:04 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\SACore
2009-04-13 02:56 . 2009-04-18 03:44 ——– d–h–w C:\$AVG8.VAULT$
2009-04-13 02:35 . 2009-04-13 02:35 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-13 02:35 . 2009-04-13 02:35 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-13 02:35 . 2009-04-13 02:35 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-13 02:35 . 2009-04-26 06:29 ——– d—–w c:\windows\system32\drivers\Avg
2009-04-13 02:35 . 2009-04-24 06:25 ——– d—–w c:\documents and settings\angelita\Application Data\AVGTOOLBAR
2009-04-13 02:34 . 2009-04-13 02:34 ——– d—–w c:\program files\AVG
2009-04-13 02:34 . 2009-04-13 02:34 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-13 02:27 . 2009-04-13 02:27 48 —ha-w c:\windows\system32\ezsidmv.dat
2009-04-05 09:21 . 2009-04-05 09:29 ——– d—–w c:\documents and settings\angelita\Application Data\InfraRecorder
2009-04-05 09:19 . 2009-04-05 09:19 ——– d—–w c:\program files\InfraRecorder
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-26 12:29 . 2009-04-26 12:29 ——– d—–w c:\program files\Common Files\Pure Networks Shared
2009-04-26 12:29 . 2009-04-24 02:10 ——– d—–w c:\documents and settings\All Users\Application Data\Pure Networks
2009-04-26 10:06 . 2009-04-26 10:06 ——– d—–w c:\program files\DIFX
2009-04-24 06:26 . 2009-04-24 02:25 ——– d—–w c:\program files\Advanced IP Scanner
2009-04-24 06:25 . 2008-08-31 08:37 ——– d—–w c:\program files\Glary Utilities
2009-04-24 06:25 . 2008-05-30 12:43 ——– d—–w c:\documents and settings\angelita\Application Data\gtk-2.0
2009-04-22 13:30 . 2008-08-31 09:02 ——– d—–w c:\documents and settings\angelita\Application Data\wsInspector
2009-04-21 02:56 . 2008-01-24 14:04 ——– d—–w c:\documents and settings\angelita\Application Data\Datalayer
2009-04-13 23:53 . 2009-02-15 04:21 ——– d—–w c:\program files\McAfee
2009-04-13 02:27 . 2006-05-01 07:24 ——– d—–w c:\documents and settings\angelita\Application Data\Skype
2009-04-13 02:27 . 2009-02-15 04:45 ——– d—–w c:\documents and settings\angelita\Application Data\skypePM
2009-04-09 08:58 . 2009-02-15 05:02 ——– d—–w c:\program files\Mozilla Thunderbird
2009-04-05 09:49 . 2007-02-03 05:08 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-05 09:40 . 2009-02-16 16:15 ——– d—–w c:\program files\F-Secure Internet Security
2009-04-05 09:36 . 2009-02-16 16:10 ——– d—–w c:\documents and settings\All Users\Application Data\f-secure
2009-04-05 09:12 . 2008-12-15 00:39 ——– d—–w c:\documents and settings\angelita\Application Data\DAEMON Tools Lite
2009-03-27 06:58 . 2009-04-23 21:59 1203922 —-a-w c:\windows\AppPatch\SET82.tmp
2009-03-07 20:34 . 2005-01-03 22:20 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-07 20:34 . 2005-01-03 22:20 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-07 20:33 . 2005-01-03 22:20 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-07 20:33 . 2005-01-03 22:20 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-07 20:32 . 2005-01-03 22:20 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-07 20:32 . 2005-01-03 22:20 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-07 20:31 . 2005-01-03 22:20 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-07 20:31 . 2005-01-03 22:20 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-07 20:31 . 2005-01-03 22:20 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-07 20:22 . 2005-01-03 22:20 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2005-01-03 22:20 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2009-03-03 00:18 826368 —-a-w c:\windows\system32\SETFB.tmp
2009-02-20 18:09 . 2009-02-20 18:09 1160192 —-a-w c:\windows\system32\SETFD.tmp
2009-02-20 18:09 . 2009-02-20 18:09 105984 —-a-w c:\windows\system32\SETFE.tmp
2009-02-20 18:09 . 2009-02-20 18:09 52224 —-a-w c:\windows\system32\SET105.tmp
2009-02-20 18:09 . 2009-02-20 18:09 459264 —-a-w c:\windows\system32\SET106.tmp
2009-02-20 18:09 . 2009-02-20 18:09 3595264 —-a-w c:\windows\system32\SET104.tmp
2009-02-20 18:09 . 2009-02-20 18:09 268288 —-a-w c:\windows\system32\SET10A.tmp
2009-02-20 18:09 . 2009-02-20 18:09 63488 —-a-w c:\windows\system32\SET115.tmp
2009-02-20 18:09 . 2009-02-20 18:09 6066176 —-a-w c:\windows\system32\SET10D.tmp
2009-02-20 18:09 . 2009-02-20 18:09 383488 —-a-w c:\windows\system32\SET10F.tmp
2009-02-20 06:16 . 2009-02-20 06:12 3370 —-a-w C:\avenger.txt
2009-02-16 16:24 . 2005-08-02 12:29 70960 —-a-w c:\documents and settings\angelita\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-15 02:49 . 2009-02-15 02:49 147192 —-a-w c:\windows\system32\guard32.dll
2009-02-09 12:10 . 2005-01-03 22:20 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2005-01-03 22:20 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2005-01-03 22:20 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2005-01-03 22:20 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2005-01-03 22:20 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-07 11:02 . 2004-08-03 22:59 2066048 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2005-01-03 22:20 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2005-01-03 22:20 2189056 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2005-01-03 22:20 35328 —-a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2009-02-03 19:59 56832 —-a-w c:\windows\system32\SET167.tmp
2009-02-03 19:59 . 2005-01-03 22:20 56832 —-a-w c:\windows\system32\secur32.dll
2007-02-02 02:49 . 2007-02-02 02:49 7459 —-a-w c:\documents and settings\angelita\Local Settings\Application Data\Update.12.Bron.Tok.bin
2007-02-02 02:33 . 2007-02-02 02:33 7459 —-a-w c:\documents and settings\angelita\Local Settings\Application Data\Bron.tok.A12.em.bin
2004-03-11 05:27 . 2008-07-20 23:30 40960 —-a-w c:\program files\Uninstall_CDS.exe
2003-08-27 13:19 . 2005-08-02 06:45 36963 —-a-r c:\program files\Common Files\SM1updtr.dll
2008-09-23 12:40 . 2008-09-23 12:40 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092320080924\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 1388544]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-05-25 184320]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 292152]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-07-09 36352]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-02-15 1797880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-15 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-13 1932568]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-09-14 648488]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-04-26 705832]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-07-22 88361]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
c:\documents and settings\angelita\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\Billionton\Bluetooth Software\BTTray.exe [2003-12-1 499779]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="logonuiSS.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-13 02:35 10520 —-a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"SM1BG"=c:\windows\SM1BG.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R3 IFXTPM;IFXTPM;c:\windows\system32\DRIVERS\IFXTPM.SYS [2004-05-13 32640]
S0 R592;R592;c:\windows\system32\DRIVERS\R592.sys [2004-01-18 54912]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-13 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-13 108552]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2009-02-15 101776]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2009-02-15 31504]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-13 298264]
S2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [2004-09-08 4300]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{480a2f02-339d-11dc-80ba-ccc4a46b2aa9}]
\Shell\AutoRun\command - F:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9877779b-2bc0-11de-bd6c-b88e6f82d4a6}]
\Shell\AutoRun\command - F:\password_viewer.exe %1
\Shell\Explore\command - F:\password_viewer.exe %1
\Shell\Open\command - F:\password_viewer.exe %1
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d2fb33e3-dbe4-11dd-bc96-eca58cbd20aa}]
\Shell\AutoRun\command - wscript.exe sowar.vbs
\Shell\Open\Command - wscript.exe sowar.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6e03716-24ec-11de-bd61-fec6e86917aa}]
\Shell\AutoRun\command - F:\password_viewer.exe %1
\Shell\Explore\command - F:\password_viewer.exe %1
\Shell\Open\command - F:\password_viewer.exe %1
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed2fd8c4-459d-11dd-867d-a5520f4f9fab}]
\Shell\AutoRun\command - F:\cb.exe
\Shell\open\Command - F:\cb.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef1746f4-0f76-11de-bd3d-0000f078acc3}]
\Shell\AutoRun\command - h:\recycle\D-0-060-0000000000-1111111-2222222\fix.exe
\Shell\open\command - h:\recycle\D-0-060-0000000000-1111111-2222222\fix.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-04-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-08-31 01:49]
2009-04-26 c:\windows\Tasks\User_Feed_Synchronization-{85AB0AF4-B342-4999-A3F7-5A4C7DCC22D2}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 20:31]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride =
FF - ProfilePath - c:\documents and settings\angelita\Application Data\Mozilla\Firefox\Profiles\u0nqfndi.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-26 22:09
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\guard32.dll
- - - - - - - > 'lsass.exe'(760)
c:\windows\system32\guard32.dll
.
Completion time: 2009-04-26 22:12
ComboFix-quarantined-files.txt 2009-04-26 14:12
ComboFix2.txt 2009-03-02 00:51
ComboFix3.txt 2009-02-24 00:43
ComboFix4.txt 2009-02-18 16:13
ComboFix5.txt 2009-04-26 14:03
Pre-Run: 29,573,181,440 bytes free
Post-Run: 29,553,377,280 bytes free
242 — E O F — 2009-04-25 06:00
Observations:
1. Internet Explorer cannot connect to the internet, but Mozilla Firefox can.
2. The error message regarding the SCV file is finally gone.
3. Task Manager Window is incomplete. Mostly the other tabs included in it aren't present anymore.
[external image: Posted Image]
Thank you again for helping me, and Good Day.