should i delete the kmd.exe???
Heres the Combo Fix Log file...
ComboFix 08-02.05.3 - David Sanchez 2008-02-08 21:09:18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.267 [GMT 8:00]
Running from: C:\Documents and Settings\David Sanchez\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\kavo0.dll
C:\WINDOWS\system32\kavo1.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-07 20:45 . 2008-02-07 20:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-03 11:39 . 2004-08-04 09:07 13 --a------ C:\WINDOWS\system32\WINSPOOL.CRC
2008-01-27 12:26 . 2008-01-27 12:26 <DIR> d-------- C:\Program Files\MegauploadToolbar
2008-01-27 12:26 . 2008-02-07 21:03 <DIR> d-------- C:\Documents and Settings\David Sanchez\Application Data\MegauploadToolbar
2008-01-27 02:53 . 2008-01-27 02:53 <DIR> d-------- C:\Program Files\BearShare Applications
2008-01-27 02:53 . 2008-01-27 12:21 <DIR> d-------- C:\Documents and Settings\David Sanchez\Application Data\BearShare
2008-01-27 02:53 . 2006-11-12 11:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
2008-01-27 02:08 . 2008-01-27 02:08 <DIR> d-------- C:\Program Files\iriver
2008-01-25 02:32 . 2008-01-25 02:32 <DIR> d-------- C:\Documents and Settings\David Sanchez\DoctorWeb
2008-01-13 09:24 . 2008-01-13 09:24 <DIR> d-------- C:\WINDOWS\FreeStyle Online
2008-01-13 09:24 . 2008-02-03 16:30 <DIR> d-------- C:\Program Files\FreeStyle Online
2008-01-12 11:18 . 2008-01-12 11:18 <DIR> d-------- C:\Program Files\Apple Software Update
2008-01-12 11:18 . 2008-01-12 11:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-02-07 16:10 --------- d-----w C:\Program Files\Warcraft III
2008-02-07 13:02 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-31 12:19 --------- d-----w C:\Documents and Settings\David Sanchez\Application Data\Business Logic
2008-01-21 00:14 --------- d-----w C:\Program Files\Google
2008-01-20 16:07 --------- d-----w C:\Program Files\PopCap Games
2008-01-10 14:44 --------- d-----w C:\Program Files\Pivot Stickfigure Animator
2008-01-06 15:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-30 09:11 --------- d-----w C:\Program Files\Eidos
2007-12-30 07:55 --------- d-----w C:\Program Files\Mystery Case Files - Prime Suspects
2007-12-19 13:08 --------- d-----w C:\Program Files\Common Files\AnimeVamp
2007-12-15 12:55 --------- d-----w C:\Program Files\SourceTec
2007-12-15 12:55 --------- d-----w C:\Program Files\Common Files\SourceTec
2007-12-14 02:03 --------- d-----w C:\Program Files\TrendyFlash Site Builder
2007-12-10 00:58 --------- d-----w C:\Program Files\BFG
2007-12-08 12:35 --------- d--h--w C:\Program Files\Zero G Registry
2007-12-08 12:34 --------- d-----w C:\Program Files\Siemens
2007-12-08 12:33 --------- d-----w C:\Program Files\mIRC
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-17 17:19 802,816 ----a-w C:\WINDOWS\feedingfrenzy.scr
2007-11-17 17:17 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-07-12 13:57 108,330 ----a-w C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
2004-10-01 07:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2004-07-22 02:51 3,432,656 ----a-w C:\Program Files\ManagedDX.CAB
2004-07-19 14:58 1,156,363 ----a-w C:\Program Files\BDANT.cab
2004-07-19 14:53 976,020 ----a-w C:\Program Files\BDAXP.cab
2004-07-09 06:17 13,265,040 ----a-w C:\Program Files\dxnt.cab
2004-07-09 01:13 703,080 ----a-w C:\Program Files\BDA.cab
2004-07-09 01:13 15,493,481 ----a-w C:\Program Files\DirectX.cab
2004-07-08 20:08 472,576 ----a-w C:\Program Files\dxsetup.exe
2004-07-08 20:08 2,242,560 ----a-w C:\Program Files\dsetup32.dll
2004-07-08 19:03 62,976 ----a-w C:\Program Files\DSETUP.dll
2004-08-03 22:56 202,474 --sha-r C:\WINDOWS\system32\mveo.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:07 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp. exe" [2007-12-04 21:00 79224]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray. dll" [2006-10-22 12:22 86016]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-28 02:11 180269]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
C:\Documents and Settings\David Sanchez\Start Menu\Programs\Startup\
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 06:05:02 630784]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GetRight - Tray Icon.lnk]
backup=C:\WINDOWS\pss\GetRight - Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ampli]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BHR]
C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDog303]
C:\WINDOWS\VM303_STI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 09:07 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 C:\Program Files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Domino]
-r------- 2006-06-28 17:54 49152 C:\WINDOWS\Domino.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-02 05:34 3739648 C:\Program Files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---hs---- 2004-08-04 01:06 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 12:22 7700480 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 12:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2006-06-15 12:36 229376 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeekmoOE]
C:\Program Files\Seekmo\bin\10.0.406.0\OEAddOn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeekmoSA]
C:\Program Files\Seekmo\bin\10.0.406.0\SeekmoSA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-r------- 2005-09-23 00:42 90112 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-04-28 02:11 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMSnap3]
-r------- 2006-08-30 10:58 49152 C:\WINDOWS\VMSnap3.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-11-22 01:38 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-07-16 15:17 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
--a------ 2007-03-29 06:10 224248 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"Symantec Core LC"=2 (0x2)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"Macromedia Licensing Service"=3 (0x3)
"IDriverT"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Bonjour Service"=2 (0x2)
"SQLWriter"=3 (0x3)
"ServiceLayer"=3 (0x3)
"MSSQL$SQLEXPRESS"=2 (0x2)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX3 2.sys [2006-02-23 11:38]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 11:39]
R3 vmfilter303;vmfilter303;C:\WINDOWS\system32\driver s\vmfilter303.sys [2006-04-25 10:57]
R3 ZSMC303;A4 TECH PC Camera H;C:\WINDOWS\system32\Drivers\usbVM303.sys [2006-12-01 14:23]
S4 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2005-10-14 03:53]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{6876d310-c5c1-11dc-aec4-0018f31960bb}]
\Shell\
0pen\command - krag.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL krag.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{f5f3caa4-f60a-11db-b57e-ea2a123e6a9b}]
\Shell\AutoRun\command - E:\SSCVIIHOST.exe
\Shell\Open\command - E:\SSCVIIHOST.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-01 02:04:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-08 21:13:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-02-08 21:14:30
ComboFix-quarantined-files.txt 2008-02-08 13:14:15
ComboFix2.txt 2008-01-28 00:52:13
THANKS