Ok looks like sdbot.vb worm on the first Hijackthis so I will hit that first
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. [b]
O4 - HKLM..\Run: [zzzHPSETUP] D:\Setup.exe
O23 - Service: Windows Process Moniter - Unknown owner - C:\WINNT\winmon.exe (file missing)
[/b]Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
THEN
@echo off
sc stop Windows Process Moniter
sc delete Windows Process Moniter
exit
Next you will need to create the batch fix to do that copy and paste [b]ALL[/b] of the above in the quote box to a notepad file.
Then in the text file go to [b]FILE > SAVE AS [/b] and in the dropdown box select [b]SAVE AS TYPE [/b] to[b] ALL FILES [/b]
Then in the [b]FILE NAME [/b] box type [b]fix.bat[/b]
This will create a batch file
http://img524.imageshack.us/img524/9383/batmp6.jpg
Then run fix.bat by double clicking you may see a black box appear this is normal
NEXT
Please download the OTMoveIt2 by OldTimer.
[*] Save it to your desktop.
[*] Please double-click OTMoveIt2.exe to run it.
[*]Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
C:\WINNT\winmon.exe
[*] Return to OTMoveIt2, right click in the “Paste List of Files/Folders to be Moved” window (under the light blue bar) and choose Paste.
[*] Return to OTMoveIt2, right click in the “Paste List Of Files/Patterns To Search For and Move” window (under the yellow bar) and choose Paste.
[*]Click the red Moveit! button.
[*]Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
[*]Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
FINALLY FOR NOW
Download WinPFind35u.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind35u on your desktop.
[*]Close ALL OTHER PROGRAMS.
[*]Open the WinPFind35u folder and double-click on WinPFind35U.exe to start the program.
[*]Under Additional Scans click the checkboxes in front of the following items to select them:
Reg - BotCheck
[*]Now click the Run Scan button on the toolbar.
[*]Let it run unhindered until it finishes.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and attach the log. I will review it when it comes in.