My last AVG scan came out clean, but here's my combofix results:
ComboFix 08-01-14.2 - Juan carlo 2008-01-13 22:55:11.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.676 [GMT -6:00]
Running from: C:\Documents and Settings\Juan carlo\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Created from 2007-12-14 to 2008-01-14 )))))))))))))))))))))))))))))))
.
2008-01-13 21:38 . 2008-01-13 21:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-13 20:48 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-01-13 20:34 . 2008-01-13 21:23 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-13 20:34 . 2008-01-13 20:34 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-13 20:34 . 2008-01-13 20:34 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-13 20:34 . 2008-01-13 20:34 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-13 20:22 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-12 20:01 . 2008-01-12 20:23 <DIR> d-------- C:\VundoFix Backups
2008-01-10 23:53 . 2008-01-10 23:53 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-10 23:53 . 2008-01-13 22:15 <DIR> d-------- C:\Documents and Settings\Juan carlo\Application Data\AVG7
2008-01-10 23:52 . 2008-01-10 23:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-10 23:52 . 2008-01-12 19:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-08 10:03 . 2008-01-08 10:03 <DIR> d-------- C:\Documents and Settings\Juan carlo\Application Data\vlc
2008-01-08 09:11 . 2008-01-08 09:11 <DIR> d-------- C:\Program Files\VideoLAN
2008-01-08 07:49 . 2008-01-08 07:49 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-08 07:49 . 2008-01-08 07:49 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-08 07:49 . 2008-01-10 21:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-08 06:18 . 2008-01-10 21:22 <DIR> d-------- C:\Program Files\AllToAVI
2008-01-08 06:13 . 2008-01-08 06:16 <DIR> d-------- C:\Program Files\MKVTOAVI
2008-01-07 09:29 . 2008-01-10 23:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe
2008-01-07 09:29 . 2008-01-10 23:50 32,768 --a------ C:\WINDOWS\system32\rmctrl .exe
2007-12-29 00:31 . 2007-12-29 00:31 <DIR> d-------- C:\Program Files\OpenSource Flash Video Splitter
2007-12-29 00:27 . 2006-10-02 13:43 6,144 --a------ C:\WINDOWS\system32\ff_acm.acm
2007-12-29 00:27 . 2006-10-02 13:44 5,120 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-12-29 00:27 . 2006-08-05 12:06 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2007-12-27 02:23 . 2007-12-27 02:23 268 --ah----- C:\sqmdata02.sqm
2007-12-27 02:23 . 2007-12-27 02:23 244 --ah----- C:\sqmnoopt02.sqm
2007-12-14 00:26 . 2008-01-13 19:59 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-14 00:26 . 2007-12-14 00:26 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-14 03:12 --------- d-----w C:\Program Files\SmartFTP Client 2.0
2008-01-13 02:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-11 06:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-11 06:37 --------- d-----w C:\Program Files\QuickTime
2008-01-11 06:37 --------- d-----w C:\Program Files\iTunes
2008-01-11 05:50 --------- d-----w C:\Program Files\MSN Messenger
2008-01-11 03:22 --------- d-----w C:\Program Files\Solveig Multimedia
2008-01-11 03:22 --------- d-----w C:\Program Files\Common Files\Elecard
2008-01-11 02:26 --------- d-----w C:\Documents and Settings\Juan carlo\Application Data\uTorrent
2007-12-29 06:27 --------- d-----w C:\Program Files\ffdshow
2007-12-28 03:43 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-04 07:11 --------- d-----w C:\Documents and Settings\Juan carlo\Application Data\InstallShield
2006-11-14 22:56 16,752 ----a-w C:\Documents and Settings\Juan carlo\Application Data\GDIPFONTCACHEV1.DAT
2006-02-28 10:58 284 ----a-w C:\Documents and Settings\Juan carlo\g.bat
2005-07-29 22:24 472 --sha-r C:\WINDOWS\SnVhbiBDYXJsbw\mBp1v21GsrLPvT.vbs
.
<pre>
----a-w 90,112 2008-01-11 05:50:41 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart .exe
----a-w 149,024 2008-01-11 05:50:53 C:\Program Files\Common Files\Seagate\Schedule2\schedhlp .exe
----a-w 102,400 2008-01-08 06:37:33 C:\Program Files\Creative\MediaSource\Detector\CTDetect .exe
----a-w 278,528 2008-01-11 05:50:42 C:\Program Files\Creative\MediaSource5\MtdAcqu .exe
----a-w 700,416 2008-01-11 02:21:02 C:\Program Files\Creative\Sync Manager Unicode\CTSyncU .exe
----a-w 45,056 2008-01-11 05:50:36 C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck .exe
----a-w 278,528 2008-01-11 05:50:36 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 5,674,352 2008-01-11 05:50:51 C:\Program Files\MSN Messenger\MsnMsgr .Exe
----a-w 532,480 2008-01-11 05:50:33 C:\Program Files\NVIDIA Corporation\nTune\nTune .exe
----a-w 1,169,744 2008-01-11 05:50:39 C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor .exe
----a-w 1,945,688 2008-01-11 05:50:40 C:\Program Files\Seagate\DiscWizard\TimounterMonitor .exe
----a-w 1,460,560 2008-01-11 05:50:43 C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
----a-w 155,648 2008-01-11 05:50:36 C:\WINDOWS\system32\NeroCheck .exe
----a-w 32,768 2008-01-11 05:50:36 C:\WINDOWS\system32\rmctrl .exe
</pre>
((((((((((((((((((((((((((((( snapshot@2008-01-13_20.29.03.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-24 14:28:54 141,424 ----a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2007-03-29 15:20:50 110,592 ----a-w C:\WINDOWS\system32\ActiveScan\as.dll
+ 2006-10-05 22:15:26 233,472 ----a-w C:\WINDOWS\system32\ActiveScan\ascontrol.dll
+ 2005-06-03 20:03:18 96,256 ----a-w C:\WINDOWS\system32\ActiveScan\asmdat.dll
+ 2003-08-01 17:00:16 36,864 ----a-w C:\WINDOWS\system32\ActiveScan\certdll.dll
+ 2005-05-20 19:42:44 86,016 ----a-w C:\WINDOWS\system32\ActiveScan\instlsp.dll
+ 2007-11-12 15:46:18 26,112 ----a-w C:\WINDOWS\system32\ActiveScan\JID.dll
+ 2006-02-17 00:20:20 4,608 ----a-w C:\WINDOWS\system32\ActiveScan\memvfile.dll
+ 2005-10-26 00:08:32 348,160 ----a-w C:\WINDOWS\system32\ActiveScan\msvcr71.dll
+ 2007-11-26 17:10:36 61,440 ----a-w C:\WINDOWS\system32\ActiveScan\NanoWrapper.dll
+ 2004-05-04 21:01:02 139,264 ----a-w C:\WINDOWS\system32\ActiveScan\pavaleas.dll
+ 2006-07-14 19:04:10 45,056 ----a-w C:\WINDOWS\system32\ActiveScan\pavdr.exe
+ 2006-04-10 16:50:02 159,832 ----a-w C:\WINDOWS\system32\ActiveScan\pavexcom.dll
+ 2006-02-14 19:05:38 94,208 ----a-w C:\WINDOWS\system32\ActiveScan\pavinas.dll
+ 2006-02-17 00:35:38 180,224 ----a-w C:\WINDOWS\system32\ActiveScan\pavoe.dll
+ 2006-10-05 22:15:38 122,880 ----a-w C:\WINDOWS\system32\ActiveScan\pavpz.dll
+ 2007-06-04 17:31:52 57,344 ----a-w C:\WINDOWS\system32\ActiveScan\pavsddl.dll
+ 2006-06-30 20:13:38 8,704 ----a-w C:\WINDOWS\system32\ActiveScan\pfdnnt.exe
+ 2004-02-04 20:08:42 49,152 ----a-w C:\WINDOWS\system32\ActiveScan\port32.dll
+ 2007-10-30 16:04:14 36,864 ----a-w C:\WINDOWS\system32\ActiveScan\Prescan.dll
+ 2006-08-01 19:23:10 69,632 ----a-w C:\WINDOWS\system32\ActiveScan\pscpu.dll
+ 2007-11-21 16:00:06 376,832 ----a-w C:\WINDOWS\system32\ActiveScan\pskahk.dll
+ 2007-10-31 19:05:06 32,768 ----a-w C:\WINDOWS\system32\ActiveScan\PSKAHKPRESCAN.dll
+ 2006-08-17 17:38:14 10,752 ----a-w C:\WINDOWS\system32\ActiveScan\pskalloc.dll
+ 2006-09-04 17:49:54 61,440 ----a-w C:\WINDOWS\system32\ActiveScan\pskas.dll
+ 2006-08-18 14:46:18 779,264 ----a-w C:\WINDOWS\system32\ActiveScan\pskavs.dll
+ 2007-03-26 20:25:34 417,792 ----a-w C:\WINDOWS\system32\ActiveScan\pskcmp.dll
+ 2006-08-09 16:42:24 90,112 ----a-w C:\WINDOWS\system32\ActiveScan\pskfss.dll
+ 2006-07-19 16:55:58 208,896 ----a-w C:\WINDOWS\system32\ActiveScan\pskhtml.dll
+ 2006-01-20 22:57:00 9,728 ----a-w C:\WINDOWS\system32\ActiveScan\pskmas.dll
+ 2006-05-17 15:50:12 14,336 ----a-w C:\WINDOWS\system32\ActiveScan\pskmdfs.dll
+ 2006-08-16 16:58:12 33,280 ----a-w C:\WINDOWS\system32\ActiveScan\pskpack.dll
+ 2006-06-30 20:42:36 266,240 ----a-w C:\WINDOWS\system32\ActiveScan\pskscs.dll
+ 2006-08-17 20:33:14 62,976 ----a-w C:\WINDOWS\system32\ActiveScan\pskutil.dll
+ 2006-08-08 19:13:10 13,312 ----a-w C:\WINDOWS\system32\ActiveScan\pskvfile.dll
+ 2006-08-18 14:53:08 69,632 ----a-w C:\WINDOWS\system32\ActiveScan\pskvfs.dll
+ 2006-08-18 14:49:50 167,936 ----a-w C:\WINDOWS\system32\ActiveScan\pskvm.dll
+ 2007-10-18 15:30:16 105,472 ----a-w C:\WINDOWS\system32\ActiveScan\psnahk.dll
+ 2007-11-23 20:29:08 10,752 ----a-w C:\WINDOWS\system32\ActiveScan\psndsk.dll
+ 2007-10-18 15:30:38 42,496 ----a-w C:\WINDOWS\system32\ActiveScan\psnflg.dll
+ 2007-10-30 17:19:22 98,304 ----a-w C:\WINDOWS\system32\ActiveScan\psnglknt.dll
+ 2007-08-22 14:52:00 20,272 ----a-w C:\WINDOWS\system32\ActiveScan\psnhsh.dll
+ 2007-11-12 21:49:34 11,776 ----a-w C:\WINDOWS\system32\ActiveScan\psnjidsign.dll
+ 2007-08-22 14:52:04 76,080 ----a-w C:\WINDOWS\system32\ActiveScan\psnkrnl.dll
+ 2007-08-22 14:52:06 21,296 ----a-w C:\WINDOWS\system32\ActiveScan\psnmem.dll
+ 2007-10-04 21:26:28 28,672 ----a-w C:\WINDOWS\system32\ActiveScan\PsnPen.dll
+ 2007-10-23 17:40:10 86,016 ----a-w C:\WINDOWS\system32\ActiveScan\psntuc.dll
+ 2007-05-24 17:27:36 27,136 ----a-w C:\WINDOWS\system32\ActiveScan\PSNXprs.dll
+ 2007-04-18 23:16:04 353,840 ----a-w C:\WINDOWS\system32\ActiveScan\psscan.dll
+ 2007-01-22 20:42:48 35,328 ----a-w C:\WINDOWS\system32\ActiveScan\rawvfile.dll
+ 2007-06-08 15:44:36 8,576 ----a-w C:\WINDOWS\system32\ActiveScan\RKPavProc.sys
+ 2007-06-05 16:56:40 44,928 ----a-w C:\WINDOWS\system32\ActiveScan\sdthook.sys
+ 1997-09-18 12:12:32 9,488 ----a-w C:\WINDOWS\system32\ActiveScan\sporder.dll
+ 2006-02-28 23:23:40 69,632 ----a-w C:\WINDOWS\system32\ActiveScan\tcpvfile.dll
+ 2007-09-17 15:14:08 126,976 ----a-w C:\WINDOWS\system32\ActiveScan\Tucan.dll
+ 2006-08-02 18:39:06 73,728 ----a-w C:\WINDOWS\system32\asuninst.exe
+ 2003-03-26 00:53:50 11,776 ----a-w C:\WINDOWS\system32\ZPORT4AS.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{568F616F-FEB0-48B6-9029-E6F527D4F159}]
C:\WINDOWS\system32\pmnnk.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"krfm"="C:\PROGRA~1\COMMON~1\krfm\krfmm.exe" [ ]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [ ]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ManualRun"="D:\AUTORUN\AutoRun.exe" [ ]
"sys013466652071"="C:\WINDOWS\sys013466652071.exe" [ ]
"OESpamTest"="C:\PROGRA~1\KASPER~1\KASPER~1\KASPER~3\OESpamTest.ExE" [ ]
"50447a58"="C:\WINDOWS\system32\mmmbjxmy.dll" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-12 19:39 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-12 19:38 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= C:\WINDOWS\system32\ad.html
FriendlyName=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
R1 atitray;atitray;C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys [2007-05-22 03:04]
R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2006-03-20 01:08]
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2006-03-20 01:08]
R3 RegKill;RegKill;C:\WINDOWS\system32\Drivers\RegKill.sys [2002-11-27 15:46]
R3 Tetri5;Tetri5 driver;C:\WINDOWS\system32\Drivers\Tetri5.sys [2006-03-20 01:38]
S0 Klpf;Klpf;C:\WINDOWS\system32\drivers\Klpf.sys []
S0 Klpid;Klpid;C:\WINDOWS\system32\drivers\Klpid.sys []
S1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-13 22:58:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-13 23:01:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-14 05:01:08
ComboFix2.txt 2008-01-14 02:29:26
.
2007-11-12 09:44:41 --- E O F ---