My ComboFix log:
ComboFix 08-07-13.11 - user 2008-07-15 6:56:27.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.616 [GMT -4:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\user\Application Data\inst.exe
C:\Documents and Settings\user\Desktop\Error Cleaner.url
C:\Documents and Settings\user\Desktop\Privacy Protector.url
C:\Documents and Settings\user\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\user\Favorites\Error Cleaner.url
C:\Documents and Settings\user\Favorites\Privacy Protector.url
C:\Documents and Settings\user\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((( Files Created from 2008-06-15 to 2008-07-15 )))))))))))))))))))))))))))))))
.
2008-07-15 06:19 . 2008-07-15 06:20 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-15 06:18 . 2004-04-08 01:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-07-15 06:18 . 2008-07-15 06:18 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-15 06:10 . 2008-07-15 06:42 <DIR> d-------- C:\SDFix
2008-07-15 05:17 . 2008-07-15 05:17 <DIR> d-------- C:\Deckard
2008-07-15 03:36 . 2008-07-15 03:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-15 00:41 . 2008-07-15 05:52 <DIR> d-------- C:\Program Files\Exterminate It!
2008-07-15 00:32 . 2008-07-14 18:43 516,096 --a------ C:\WINDOWS\kgxmotaptvw.dll
2008-07-15 00:32 . 2008-07-14 18:43 356,352 --a------ C:\WINDOWS\evgratsm.dll
2008-07-15 00:32 . 2008-07-14 18:43 311,296 --a------ C:\WINDOWS\kvxqmtre.dll
2008-07-15 00:32 . 2008-07-14 18:43 159,744 --a------ C:\WINDOWS\qndsfmao.dll
2008-07-02 13:00 . 2008-07-15 01:27 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-02 11:13 . 2008-07-15 05:58 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-02 11:13 . 2008-07-02 11:13 <DIR> d-------- C:\Documents and Settings\JaneGuy\Application Data\AVG7
2008-07-02 11:13 . 2008-07-02 11:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVG7
2008-07-02 11:13 . 2008-07-04 12:33 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-02 11:13 . 2008-07-04 12:34 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-02 11:13 . 2008-07-04 12:33 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-02 11:12 . 2008-07-15 04:44 <DIR> d-------- C:\Program Files\AVG
2008-07-02 11:12 . 2008-07-02 11:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-20 13:41 . 2008-06-20 13:41 245,248 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 06:44 . 2008-06-20 06:44 138,368 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-19 00:32 . 2008-06-19 00:32 <DIR> d-------- C:\Documents and Settings\user\Application Data\Ableton
2008-06-19 00:32 . 2008-06-19 00:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ableton
2008-06-19 00:31 . 2008-06-19 00:31 <DIR> d-------- C:\Program Files\Ableton
2008-06-19 00:31 . 2007-09-03 14:03 368,640 --a------ C:\WINDOWS\system32\ReWire.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-15 09:58 --------- d-----w C:\Program Files\BitLord
2008-07-15 08:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-15 06:56 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-15 06:56 --------- d-----w C:\Program Files\Trillian
2008-07-15 06:52 --------- d-----w C:\Program Files\SpywareBlaster
2008-07-15 06:42 --------- d-----w C:\Program Files\DC++
2008-07-11 02:42 --------- d-----w C:\Program Files\Lavasoft
2008-07-11 02:42 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-11 02:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-09 19:53 9,626 ----a-w C:\Documents and Settings\JaneGuy\Application Data\wklnhst.dat
2008-07-09 06:52 --------- d-----w C:\Program Files\Amazon
2008-07-02 17:00 --------- d-----w C:\Program Files\DIGStream
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 16:08 --------- d-----w C:\Documents and Settings\JaneGuy\Application Data\InterVideo
2008-06-07 15:42 52,228 ----a-w C:\Documents and Settings\user\Application Data\wklnhst.dat
2008-06-02 07:20 --------- d-----w C:\Documents and Settings\JaneGuy\Application Data\Search Settings
2008-06-02 06:22 --------- d-----w C:\Documents and Settings\user\Application Data\DivX
2008-06-02 03:32 --------- d-----w C:\Program Files\Dealio
2008-06-02 02:31 --------- d-----w C:\Documents and Settings\user\Application Data\Search Settings
2008-06-02 02:29 --------- d-----w C:\Program Files\Search Settings
2008-06-02 02:22 --------- d-----w C:\Program Files\The KMPlayer
2008-05-26 08:40 --------- d-----w C:\Documents and Settings\JaneGuy\Application Data\vlc
2008-05-24 02:48 --------- d-----w C:\Program Files\Google
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2007-07-30 05:54 3,836,577 ----a-w C:\Program Files\DCPlusPlus-0.698.exe
2007-07-08 22:54 47,360 ----a-w C:\Documents and Settings\user\Application Data\pcouffin.sys
2005-12-12 03:05 79,952 ----a-w C:\Documents and Settings\user\Application Data\GDIPFONTCACHEV1.DAT
2005-05-31 06:56 2,576,384 ----a-w C:\Program Files\Transcoder.exe
2004-10-11 23:23 150 ---ha-w C:\Documents and Settings\user\hpothb07.dat
2004-10-01 19:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2005-01-01 05:38 4,402 --sha-w C:\WINDOWS\dblat.dat
2005-01-08 06:37 4,402 --sha-w C:\WINDOWS\zxwrv.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05721FB0-2C8D-41A1-BEF7-0957168A3502}]
2008-07-14 18:43 516096 --a------ C:\WINDOWS\kgxmotaptvw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9A3D91FB-FCF6-46A4-A0C2-B4865D8D05DC}"= "C:\WINDOWS\qndsfmao.dll" [2008-07-14 18:43 159744]
[HKEY_CLASSES_ROOT\clsid\{9a3d91fb-fcf6-46a4-a0c2-b4865d8d05dc}]
[HKEY_CLASSES_ROOT\qndsfmao.1]
[HKEY_CLASSES_ROOT\TypeLib\{1CA3FDCA-2340-4DD0-80E3-68EC677CD140}]
[HKEY_CLASSES_ROOT\qndsfmao]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 12:00 200704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 01:31 208952]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-03-31 08:00 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-03-31 08:00 455168]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 16:28 790528]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 11:24 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 11:11 114688]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-06-25 15:30 335872]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 07:32 50688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 14:03 36975]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2006-07-12 05:58 1397760]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 11:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SearchSettings"="C:\Program Files\Search Settings\SearchSettings.exe" [2008-02-06 17:47 1036640]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-04 12:34 1232152]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2004-04-08 01:39:00 114688]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 16:05:56 65588]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"evgratsm"= {1B25B29D-4C71-4306-8DDD-4DA6FA910B99} - C:\WINDOWS\evgratsm.dll [2008-07-14 18:43 356352]
"kvxqmtre"= {38D6D4BE-706C-493F-A42A-7CAD1794F3D4} - C:\WINDOWS\kvxqmtre.dll [2008-07-14 18:43 311296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax DllCmd 4.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax DllCmd 4.0.lnk
backup=C:\WINDOWS\pss\eFax DllCmd 4.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 4.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax Tray Menu 4.0.lnk
backup=C:\WINDOWS\pss\eFax Tray Menu 4.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Finding Notes Easy.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Finding Notes Easy.lnk
backup=C:\WINDOWS\pss\Finding Notes Easy.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-09 11:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DIGServices]
--a------ 2005-05-19 13:55 101888 C:\Program Files\ESPNRunTime\DIGServices.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
--------- 2004-04-21 10:26 86016 C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 11:56 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
--a------ 2006-05-25 21:24 1003520 C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2004-11-02 20:24 32768 C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
--a------ 2002-04-17 10:42 69632 c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 16:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"TapiSrv"=3 (0x3)
"iPod Service"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\TorrentStorm\\Downloader\\Tor032\\tor032.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\AIM95\\aim.exe"=
"C:\\Program Files\\DC++\\DCPlusPlus.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-04 12:33]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-04 12:33]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-04 12:33]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-04 12:34]
R3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2005-05-04 08:58]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a699bfe6-2c23-11dc-9fc9-806d6172696f}]
\Shell\AutoRun\command - D:\AutoRun\Demo.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-07-02 00:37:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{0AEBF16C-963C-4CA2-8673-E4F0650D6DA9} - C:\WINDOWS\system32\pmkhg.dll
HKCU-Run-PowerBar - (no file)
MSConfigStartUp-DIGStream - C:\Program Files\DIGStream\digstream.exe
MSConfigStartUp-TkBellExe - C:\Program Files\Common Files\Real\Update_OB\realsched.exe
MSConfigStartUp-updateMgr - C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-15 06:59:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ????????????l?@?l?@?D?????A~??????????????A~l?@?l?@????? ???????????W?D~??A~??????A~K?A~x???????[?A~???????? ??????????????|x???0?????????????st??A~????????????????`8??????R???????l?@?l?@?????Q?B~????t?@?????l?@?8?@?l?@?3??s????????????????????8?@?_??s8?@?8?@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-15 7:02:11
ComboFix-quarantined-files.txt 2008-07-15 11:01:52
Pre-Run: 67,084,783,616 bytes free
Post-Run: 67,858,534,400 bytes free
217 --- E O F --- 2008-07-09 07:26:02
Tara