OK, here we go...
1. SpyKiller, BestPopUpKiller, and SpyHunter all fall into the category of "dubious" programs, in that they are unreliable and at the very least return "false positive" findings as a way of enticing users to buy the commercial versions of the programs. You should uninstall them and use the trusted, recommended (and free) alternatives instead. For more information on bogus vs. legit "spyware" utilities, please visit this site:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
Links to some of the reputable programs (of which Lavasoft's Ad Aware is one) can be found in my sig below.
2. " C:\Program Files\Internet Explorer\IEXPLORE.EXE"
That entry in your HJT log indicates that you had at least on instance of Internet Explorer running when you ran HijackThis. HJT cannot fully perform its fixes unless all instances of your web browsers are closed. Please make sure that is the case before proceeding.
* -> Before doing the following, you should probably disable XP's System Restore function. Instructions for doing so (and an explanation of why you should) can be found here .
3. Once you have closed all instances of all web browsers, have HijackThis fix:
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvdme32.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [E981F653] C:\WINDOWS\system32\ctLinra.exe
O4 - HKLM\..\Run: [XPSP2 Firewall] C:\WINDOWS\system32\xpsp2fw.exe
O4 - HKLM\..\Run: [FDBF3A4E] C:\WINDOWS\system32\dsntcer.exe
O4 - HKLM\..\Run: [Windows TaskAd] C:\Program Files\Windows TaskAd\WinTaskAd.exe
O4 - HKCU\..\Run: [kbdsw] C:\WINDOWS\System32\kbdsw.exe
O4 - HKCU\..\Run: [FDBF3A4E] C:\WINDOWS\system32\dsntcer.exe
O4 - HKCU\..\Run: [E981F653] C:\WINDOWS\system32\ctLinra.exe
O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: DigiChat Applet - http://host4.digichat.com/DigiChat/...s/Client_IE.cab
O16 - DPF: {15589FA1-C456-11CE-BF01-000000000000} - http://www.nuker.com/products/swn20...erInstaller.exe
4. Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up)
- Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files".
- Locate and delete the following files:
C:\windows\system32\kalvdme32.exe
C:\WINDOWS\system32\ctLinra.exe
C:\WINDOWS\system32\xpsp2fw.exe
C:\WINDOWS\system32\dsntcer.exe
C:\WINDOWS\System32\kbdsw.exe
C:\WINDOWS\system32\dsntcer.exe
C:\WINDOWS\system32\ctLinra.exe
- Locate and delete the following folders entirely:
C:\Program Files\Enigma Software Group
C:\Program Files\Windows TaskAd
C:\Program Files\Common Files\tsa
C:\Program Files\SpyKiller
C:\Program Files\BestPopUpKiller
- For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
1. Local Settings\Temp
2. Cookies
3. History
4. Local Settings\Temporary Internet Files\Content.IE5
- Delete the entire content of your C:\Windows\Temp folder.
Note- If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed. Windows will allow you to delete the versions of those files which exist in sub-folders within the main Temp/Temorary folders, but might not let you delete the versions of those files that exist in the main Temp folders themselves; this is normal and OK.
- Empty your Recycle Bin.
- Reboot normally.
5. Post a fresh/new HijackThis log.