here is the combofix log
ComboFix 08-08-04.01 - Owner 2008-08-04 14:10:07.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.120 [GMT -7:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\LBDDJXMD\interclick.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\LBDDJXMD\interclick.com\ud.sol
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\BMd3e981d3.txt
C:\WINDOWS\BMd3e981d3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\DefLib.sys
C:\WINDOWS\system32\drivers\clbdriver.sys
C:\WINDOWS\system32\drivers\ntndis.exe
C:\WINDOWS\system32\drivers\ntndis.sys
C:\WINDOWS\system32\gdiwxp.dll
C:\WINDOWS\system32\icdnvjvp.dll
C:\WINDOWS\system32\logon16x.dll
C:\WINDOWS\system32\mmlogon.sys
C:\WINDOWS\system32\MSplg7.dll
C:\WINDOWS\system32\ntio256.sys
C:\WINDOWS\system32\omdtcjcj.dll
C:\WINDOWS\system32\rAJkknpo.ini
C:\WINDOWS\system32\rAJkknpo.ini2
C:\WINDOWS\system32\rsdapi.dll
C:\WINDOWS\system32\sefuydav.dll
C:\WINDOWS\system32\utonlpnj.ini
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.
2008-08-04 05:01 . 2008-08-04 05:01 d-------- C:\aa0019f0269a2bb7fa4d45
2008-08-04 05:00 . 2008-08-04 05:00 1,137 --a------ C:\WINDOWS\system32\msexcr.ini
2008-08-03 17:53 . 2008-08-03 17:53 d-------- C:\WINDOWS\system32\LogFiles
2008-08-01 05:30 . 2007-03-25 19:01 39,208 --a------ C:\WINDOWS\system32\drivers\amonlwlh.sys
2008-08-01 04:39 . 2008-08-04 04:25 5,947,903 --a------ C:\WINDOWS\system32\AhnSZds.szd
2008-08-01 04:39 . 2008-08-04 04:29 4,687,354 --a------ C:\WINDOWS\system32\AhnSZhs.szd
2008-08-01 04:39 . 2008-08-04 04:24 2,469,430 --a------ C:\WINDOWS\system32\AhnSZns.szd
2008-08-01 04:39 . 2008-08-04 05:34 1,484,032 --a------ C:\WINDOWS\system32\drivers\v3engine.sys
2008-08-01 04:39 . 2008-07-28 01:49 70,528 --a------ C:\WINDOWS\system32\drivers\AhnSZE.sys
2008-08-01 04:39 . 2007-03-19 20:28 24,667 --a------ C:\WINDOWS\system32\V3W32SE2.dll
2008-08-01 04:38 . 2008-08-01 04:40 d-------- C:\Program Files\Common Files\AhnLab
2008-08-01 04:38 . 2008-08-01 04:39 d-------- C:\Program Files\AhnLab
2008-08-01 04:38 . 2008-01-11 11:57 86,278 --a------ C:\WINDOWS\system32\drivers\AMonTDnt.sys
2008-08-01 04:38 . 2008-01-11 11:57 78,336 --a------ C:\WINDOWS\system32\drivers\AMonTDLH.sys
2008-08-01 04:38 . 2008-01-09 11:53 47,327 --a------ C:\WINDOWS\system32\drivers\AhnFltNt.sys
2008-08-01 04:38 . 2008-04-07 11:30 46,438 --a------ C:\WINDOWS\system32\drivers\AMonHKnt.sys
2008-08-01 04:38 . 2008-01-09 11:53 45,824 --a------ C:\WINDOWS\system32\drivers\AhnFlt2k.sys
2008-08-01 04:38 . 2008-01-09 11:54 28,672 --a------ C:\WINDOWS\system32\drivers\AhnRghNt.sys
2008-08-01 04:38 . 2007-03-19 20:08 13,696 --a------ C:\WINDOWS\system32\drivers\AhnRec2k.sys
2008-08-01 04:38 . 2007-03-19 20:08 13,599 --a------ C:\WINDOWS\system32\drivers\AhnRecNt.sys
2008-08-01 04:38 . 2007-10-01 10:39 12,893 --a------ C:\WINDOWS\system32\drivers\CdmDrvNT.sys
2008-08-01 04:36 . 2008-08-01 04:36 d-------- C:\Documents and Settings\LocalService\Application Data\Xfire
2008-08-01 04:35 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-01 04:35 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-01 04:35 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-01 04:35 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-08-01 04:34 . 2008-08-04 02:35 d-------- C:\Program Files\Spyware Doctor
2008-08-01 04:34 . 2008-08-01 04:34 d-------- C:\Documents and Settings\Owner\Application Data\PC Tools
2008-08-01 04:29 . 2008-08-01 04:30 d-------- C:\Program Files\Google
2008-08-01 04:29 . 2008-08-04 08:48 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-01 04:18 . 2008-08-01 04:18 d-------- C:\Program Files\PSTRUH
2008-07-31 21:35 . 2008-07-31 22:44 d-------- C:\Program Files\Norton 360
2008-07-31 21:32 . 2008-07-31 22:44 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-31 21:25 . 2008-07-31 22:42 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-31 21:22 . 2008-07-31 22:05 d-------- C:\Documents and Settings\Owner\Application Data\Symantec
2008-07-27 13:12 . 2008-07-27 13:12 d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-07-27 13:09 . 2008-07-27 13:09 d-------- C:\Program Files\GALA-NET
2008-07-27 13:09 . 2005-08-11 15:29 73,728 --a------ C:\WINDOWS\system32\ISUSPM.cpl
2008-07-24 21:54 . 2008-07-25 01:14 d-------- C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
2008-07-24 21:54 . 2008-07-24 21:54 d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-07-16 09:33 . 2008-07-16 09:33 d-------- C:\Program Files\Red Kawa
2008-07-15 20:57 . 2008-07-15 20:57 d-------- C:\ConverterOutput
2008-07-15 20:56 . 2008-07-15 20:56 d-------- C:\Program Files\Cucusoft
2008-07-15 20:56 . 2007-03-25 00:51 3,049,984 --a------ C:\WINDOWS\system32\libavcodec.dll
2008-07-15 20:56 . 2007-03-25 21:40 2,174,976 --a------ C:\WINDOWS\system32\ffdshow.ax
2008-07-15 20:56 . 2007-03-25 00:51 404,480 --a------ C:\WINDOWS\system32\libmplayer.dll
2008-07-15 20:56 . 2007-01-01 05:30 200,704 --a------ C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-07-15 20:56 . 2007-03-25 00:51 114,688 --a------ C:\WINDOWS\system32\libmpeg2_ff.dll
2008-07-15 20:56 . 2004-09-10 13:50 34,820 --a------ C:\WINDOWS\system32\ffdshow.reg
2008-07-15 16:09 . 2008-07-15 16:09 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-07-15 00:40 . 2008-07-15 00:40 d-------- C:\Program Files\Advanced Batch Converter
2008-07-14 13:44 . 2008-07-14 13:44 360,320 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-07-13 22:26 . 2008-07-13 22:26 d-------- C:\WINDOWS\Sun
2008-07-12 20:27 . 2008-07-31 20:05 d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-07-12 20:26 . 2008-07-12 20:27 d-------- C:\Program Files\LimeWire
2008-07-12 15:34 . 2008-07-12 15:34 d-------- C:\Program Files\Microsoft Silverlight
2008-07-09 17:01 . 2008-07-09 21:08 d-------- C:\Program Files\Armadillo Run Demo
2008-07-08 14:22 . 2008-07-14 16:02 d-------- C:\Fraps
2008-07-08 11:05 . 2008-07-08 11:05 336 --a------ C:\DVD.cue
2008-07-08 10:41 . 2008-07-08 10:41 d-------- C:\Program Files\Smart Projects
2008-07-06 16:27 . 2008-07-06 16:27 d--h----- C:\BJPrinter
2008-07-06 16:27 . 1998-10-30 00:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-07-06 16:27 . 2001-07-25 21:00 94,720 --a------ C:\WINDOWS\system32\CNMLM38.DLL
2008-07-06 16:27 . 2001-07-25 21:00 94,720 --a------ C:\WINDOWS\system32\CNMLM38(2).DLL
2008-07-06 16:27 . 2001-08-01 15:46 36,864 --a------ C:\WINDOWS\system32\CNMCP38.EXE
2008-07-06 16:27 . 2001-07-25 21:00 5,632 --a------ C:\WINDOWS\system32\CNMVS38.DLL
2008-07-06 16:27 . 2008-07-06 16:27 260 --a------ C:\WINDOWS\_delis32.ini
2008-07-06 16:24 . 2008-07-06 16:24 d-------- C:\Program Files\uTorrent
2008-07-06 16:24 . 2008-07-31 22:42 d-------- C:\Documents and Settings\Owner\Application Data\uTorrent
2008-07-06 16:11 . 2008-07-06 16:11 d-------- C:\Program Files\Common Files\Adobe
2008-07-06 12:26 . 2008-07-06 12:26 d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-06 11:47 . 2008-07-06 11:48 d-------- C:\Program Files\BannedStory
2008-07-04 01:17 . 2008-07-04 10:42 d-------- C:\Documents and Settings\All Users\Application Data\NexonUS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-04 21:09 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-04 05:13 --------- d-----w C:\Documents and Settings\Owner\Application Data\Xfire
2008-07-31 19:45 --------- d-----w C:\Program Files\Xfire
2008-07-27 20:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-27 20:09 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-14 20:44 360,320 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-06-30 09:29 --------- d-----w C:\Program Files\Java
2008-06-30 09:26 --------- d-----w C:\Program Files\Common Files\Java
2008-06-29 20:02 --------- d-----w C:\Documents and Settings\Nevenka\Application Data\Gtek
2008-06-28 17:17 --------- d-----w C:\Documents and Settings\Owner\Application Data\Nexon
2008-06-28 17:16 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-06-28 06:09 --------- d--ha-w C:\Documents and Settings\All Users\Application Data\GTek
2008-06-28 06:09 --------- d--h--w C:\Documents and Settings\Owner\Application Data\GTek
2008-06-28 06:09 --------- d-----w C:\Program Files\Linksys EasyLink Advisor
2008-06-28 05:30 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-06-26 01:10 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
.
------- Sigcheck -------
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2004-08-04 05:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2008-07-14 13:44 360320 3adce4790f591bf160a94f6f08039577 C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-07-14 13:44 360320 3adce4790f591bf160a94f6f08039577 C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 17:16 454784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-01 04:29 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 05:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 05:00 455168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-12-01 22:05 344064]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2006-04-18 10:32 405504]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 17:22 794713]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"AhnLab Session Process"="C:\PROGRA~1\COMMON~1\AhnLab\ACA\ACASP.exe" [2007-11-20 03:10 54862]
"AHNSD"="C:\Program Files\AhnLab\Smart Update Utility\AhnSD.exe" [2008-01-28 18:23 199368]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 15:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2008-07-15 16:09:02 3050832]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="%windir%\\Resources\\LogonUI\\playin-catch\\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\Nexon\Combat Arms\CombatArms.exe"= C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe"= C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\\Nexon\\Combat Arms\\NMService.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
R1 AMonTDnt;AMonTDnt;C:\WINDOWS\system32\Drivers\AMonTDnt.sys [2008-01-11 11:57]
R2 AhnLab Application Service;AhnLab Application Service;C:\Program Files\Common Files\AhnLab\ACA\ACAAS.exe [2007-09-09 17:25]
R2 AhnLab Guarantee Service;AhnLab Guarantee Service;C:\Program Files\Common Files\AhnLab\ACA\ACAEGMgr.exe [2007-11-22 10:56]
R2 AhnLab Information Service;AhnLab Information Service;C:\Program Files\Common Files\AhnLab\ACA\ACAIS.exe [2007-09-09 17:26]
R2 AhnLab Log Service;AhnLab Log Service;C:\Program Files\Common Files\AhnLab\ACA\ACALS.exe [2007-08-10 10:55]
R2 AhnLab Task Scheduler;AhnLab Task Scheduler;C:\Program Files\AhnLab\Smart Update Utility\AhnSDsv.exe [2008-01-28 18:23]
R2 AMonHKnt;AMonHKnt;C:\WINDOWS\system32\Drivers\AMonHKnt.sys [2008-04-07 11:30]
R3 AhnFlt2k;AhnFlt2k;C:\WINDOWS\system32\Drivers\AhnFlt2k.sys [2008-01-09 11:53]
R3 AhnRec2k;AhnRec2k;C:\WINDOWS\system32\Drivers\AhnRec2k.sys [2007-03-19 20:08]
R3 AhnRghNt;AhnRghNt;C:\WINDOWS\system32\Drivers\AhnRghNt.sys [2008-01-09 11:54]
R3 AhnSZE;AhnSZE;C:\WINDOWS\system32\drivers\AhnSZE.sys [2008-07-28 01:49]
R3 ASZFltNt;ASZFltNt;C:\PROGRA~1\AhnLab\V3IS2007\ASZFltNt.sys [2008-01-09 12:10]
R3 CdmDrvNt;CdmDrvNt;C:\WINDOWS\system32\Drivers\CdmDrvNt.sys [2007-10-01 10:39]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 15:06]
R3 ISFWEnt;ISFWEnt;C:\Program Files\AhnLab\V3IS2007\ISFWEnt.sys [2008-01-09 12:10]
R3 ISIPSEnt;ISIPSEnt;C:\Program Files\AhnLab\V3IS2007\ISIPSEnt.sys [2008-02-18 23:38]
R3 ISPIBEnt;ISPIBEnt;C:\Program Files\AhnLab\V3IS2007\ISPIBEnt.sys [2007-10-05 11:42]
R3 ISPrxEnt;ISPrxEnt;C:\Program Files\AhnLab\V3IS2007\ISPrxEnt.sys [2007-10-03 23:39]
R3 ISTrkEnt;ISTrkEnt;C:\Program Files\AhnLab\V3IS2007\ISTrkEnt.sys [2007-03-19 20:28]
R3 v3engine;v3engine;C:\WINDOWS\system32\drivers\v3engine.sys [2008-08-04 05:34]
R3 V3Flt2K;V3Flt2K;C:\PROGRA~1\AhnLab\V3IS2007\V3Flt2K.sys [2008-02-18 23:39]
R3 V3IFt2K;V3IFt2K;C:\PROGRA~1\AhnLab\V3IS2007\V3IFt2K.sys [2008-01-09 12:11]
S3 ArfMonNt;ArfMonNt;C:\Program Files\AhnLab\V3IS2007\ArfMonNt.sys [2008-02-18 23:39]
S3 ATICDSDr;ATICDSDr;C:\Program Files\ATI Technologies\ATI Control Panel\atiicdxx.sys [2005-12-02 02:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8dfecb6-c0e7-11db-a10c-806d6172696f}]
\Shell\AutoRun\command - E:\bit.exe -S "LTFT.bits"
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-WinampAgent - C:\Program Files\Winamp\winampa.exe
HKLM-Run-BMd3e981d3 - C:\WINDOWS\system32\sefuydav.dll
Notify-nnnkKcyy - nnnkKcyy.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://basilmarket.com/
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-04 14:14:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\AhnLab\V3IS2007\MSProxy.ahn
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
.
**************************************************************************
.
Completion time: 2008-08-04 14:17:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-04 21:17:45
Pre-Run: 30,634,532,864 bytes free
Post-Run: 30,761,857,024 bytes free
242 --- E O F --- 2008-08-04 12:06:44