here are my combofix and hijackthis logs
ComboFix 08-04-08.7 - nk 2008-04-09 13:58:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.736 [GMT 5.5:30]
Running from: C:\Documents and Settings\nk\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM2fe57169.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\awfeysrb.dll
C:\WINDOWS\system32\fkmqanac.dll
C:\WINDOWS\system32\gjkkj.ini
C:\WINDOWS\system32\gjkkj.ini2
C:\WINDOWS\system32\hgvjmmgx.dll
C:\WINDOWS\system32\hsyjlioo.dll
C:\WINDOWS\system32\ifqoccvo.dll
C:\WINDOWS\system32\jkkjg.dll
C:\WINDOWS\system32\kcytltac.dll
C:\WINDOWS\system32\mhbfpskh.dll
C:\WINDOWS\system32\nffagoro.dll
C:\WINDOWS\system32\pmnklii.dll
C:\WINDOWS\system32\pptcgjre.dll
C:\WINDOWS\system32\pqecunfh.dll
C:\WINDOWS\system32\tqgsvuev.dll
C:\WINDOWS\system32\xgmmjvgh.ini
.
((((((((((((((((((((((((( Files Created from 2008-03-09 to 2008-04-09 )))))))))))))))))))))))))))))))
.
2008-04-09 14:03 . 2008-04-09 14:03 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-04-09 14:03 . 2008-04-09 14:03 <DIR> d-------- C:\WINDOWS\srchasst
2008-04-09 14:03 . 2008-04-09 14:03 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-04-08 22:09 . 2008-04-08 22:09 <DIR> d-------- C:\Documents and Settings\nk\Application Data\PTC
2008-04-08 21:54 . 2008-04-08 21:54 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-08 21:54 . 2008-04-08 21:54 <DIR> d-------- C:\Documents and Settings\nk\Application Data\Malwarebytes
2008-04-08 21:54 . 2008-04-08 21:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-07 12:52 . 2005-04-28 00:07 77,824 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-04-07 12:52 . 2005-04-08 19:44 45,056 --a------ C:\WINDOWS\system32\hpzll3xu.dll
2008-04-07 12:49 . 2008-04-07 12:49 <DIR> d-------- C:\Documents and Settings\nk\Application Data\HP
2008-04-06 21:47 . 2008-04-06 21:47 1,535,307 ---hs---- C:\WINDOWS\system32\torbttrw.ini
2008-04-06 12:03 . 2008-04-06 12:03 <DIR> d-------- C:\Documents and Settings\nk\Application Data\vlc
2008-04-06 12:02 . 2008-04-06 12:02 <DIR> d-------- C:\Program Files\VideoLAN
2008-04-05 21:02 . 2008-04-05 21:02 <DIR> d---s---- C:\Documents and Settings\nk\UserData
2008-04-05 13:22 . 2008-04-05 13:22 19,552 --a------ C:\Documents and Settings\nk\Application Data\GDIPFONTCACHEV1.DAT
2008-04-05 13:01 . 2007-06-13 16:56 1,033,216 --------- C:\WINDOWS\system32\dllcache\explorer.exe
2008-04-05 12:58 . 2007-06-26 11:36 1,104,896 --------- C:\WINDOWS\system32\dllcache\msxml3.dll
2008-04-05 12:32 . 2008-04-05 12:32 <DIR> d-------- C:\Documents and Settings\nk\Application Data\Bitdefender
2008-04-05 12:31 . 2008-04-05 12:31 <DIR> d-------- C:\Program Files\BitDefender
2008-04-05 12:31 . 2008-04-05 12:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-04-05 11:56 . 2008-04-09 14:00 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-05 11:53 . 2008-04-09 14:03 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-04-05 11:52 . 2008-04-05 12:31 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-04-05 00:59 . 2008-04-05 00:59 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-05 00:59 . 2008-04-05 00:59 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-05 00:58 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-05 00:04 . 2007-08-21 11:55 683,520 --a------ C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-04-04 22:55 . 2008-04-04 22:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-04 22:51 . 2007-04-23 15:44 364,160 --a------ C:\WINDOWS\system32\dllcache\update.sys
2008-04-04 22:49 . 2007-12-18 15:21 179,584 --a------ C:\WINDOWS\system32\dllcache\mrxdav.sys
2008-04-04 22:32 . 2007-10-30 04:05 1,287,680 --a------ C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-04 22:27 . 2007-10-30 22:50 360,064 --a------ C:\WINDOWS\system32\dllcache\tcpip.sys
2008-04-04 22:19 . 2007-06-19 19:07 282,112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
2008-04-04 22:17 . 2007-05-16 21:02 1,314,816 --a------ C:\WINDOWS\system32\dllcache\msoe.dll
2008-04-04 22:17 . 2007-05-16 21:02 510,976 --a------ C:\WINDOWS\system32\dllcache\wab32.dll
2008-04-04 22:17 . 2007-05-16 21:02 86,528 --a------ C:\WINDOWS\system32\dllcache\directdb.dll
2008-04-04 22:17 . 2007-05-16 21:02 85,504 --a------ C:\WINDOWS\system32\dllcache\wabimp.dll
2008-04-04 22:07 . 2007-10-26 09:04 8,460,288 --a------ C:\WINDOWS\system32\dllcache\shell32.dll
2008-04-04 22:05 . 2007-07-06 18:16 660,992 --a------ C:\WINDOWS\system32\dllcache\mqqm.dll
2008-04-04 22:05 . 2007-07-06 18:16 471,552 --a------ C:\WINDOWS\system32\dllcache\mqutil.dll
2008-04-04 22:05 . 2007-07-06 18:16 177,152 --a------ C:\WINDOWS\system32\dllcache\mqrt.dll
2008-04-04 22:05 . 2007-07-06 18:16 138,240 --a------ C:\WINDOWS\system32\dllcache\mqad.dll
2008-04-04 22:05 . 2007-07-06 18:16 95,744 --a------ C:\WINDOWS\system32\dllcache\mqsec.dll
2008-04-04 22:05 . 2007-07-06 15:35 72,960 --a------ C:\WINDOWS\system32\dllcache\mqac.sys
2008-04-04 22:05 . 2007-07-06 18:16 48,640 --a------ C:\WINDOWS\system32\dllcache\mqupgrd.dll
2008-04-04 22:05 . 2007-07-06 18:16 47,104 --a------ C:\WINDOWS\system32\dllcache\mqdscli.dll
2008-04-04 22:05 . 2007-07-06 18:16 16,896 --a------ C:\WINDOWS\system32\dllcache\mqise.dll
2008-04-04 22:04 . 2007-11-14 12:56 450,560 --a------ C:\WINDOWS\system32\dllcache\jscript.dll
2008-04-04 22:00 . 2007-07-09 18:46 582,656 --a------ C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-04-04 21:18 . 2007-04-16 21:37 986,112 --a------ C:\WINDOWS\system32\dllcache\kernel32.dll
2008-04-04 16:32 . 2007-04-25 19:51 144,896 --a------ C:\WINDOWS\system32\dllcache\schannel.dll
2008-04-04 16:31 . 2007-11-07 15:20 727,040 --a------ C:\WINDOWS\system32\dllcache\lsasrv.dll
2008-04-04 16:28 . 2007-12-05 00:08 550,912 --a------ C:\WINDOWS\system32\dllcache\oleaut32.dll
2008-04-04 12:29 . 2008-04-05 21:34 <DIR> d-------- C:\Program Files\NetMeter
2008-04-04 12:26 . 2008-04-04 12:28 <DIR> d-------- C:\Program Files\WinRARi
2008-04-04 12:26 . 2008-04-04 12:26 <DIR> d-------- C:\Program Files\Google
2008-04-04 12:18 . 2008-04-04 12:18 <DIR> d-------- C:\Documents and Settings\nk\Application Data\Talkback
2008-04-04 12:18 . 2008-04-04 12:18 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-04 12:13 . 2008-04-04 12:13 <DIR> d-------- C:\WINDOWS\OPTIONS
2008-04-04 12:09 . 2008-04-04 12:09 <DIR> d-------- C:\Program Files\C-Media 3D Audio
2008-04-04 12:09 . 2003-08-05 14:23 266,240 --a------ C:\WINDOWS\CMIUninstall.exe
2008-04-04 12:09 . 2003-07-22 11:15 225,280 --a------ C:\WINDOWS\CmiRmRedundDir.exe
2008-04-04 12:09 . 2003-07-10 01:41 155,648 --a------ C:\WINDOWS\system32\igfxres.dll
2008-04-04 12:09 . 2004-09-30 11:49 132,864 -r------- C:\WINDOWS\Cmuda.ini
2008-04-04 12:09 . 2002-10-18 15:56 28,672 --a------ C:\WINDOWS\CMIRmDriver.dll
2008-04-04 12:09 . 2008-04-04 14:50 427 --a------ C:\WINDOWS\system\CmiCnfg.ini
2008-04-04 12:09 . 2008-04-04 12:09 92 --a------ C:\WINDOWS\CMISETUP.INI
2008-04-04 12:09 . 2008-04-04 12:09 26 --a------ C:\WINDOWS\CMCDPLAY.INI
2008-04-04 12:09 . 2008-04-04 12:09 0 --a------ C:\WINDOWS\Wininit.ini
2008-04-04 12:03 . 2008-04-04 12:03 <DIR> d-------- C:\Program Files\Intel
2008-04-04 12:02 . 2008-04-04 12:02 <DIR> d-------- C:\WINDOWS\system32\Tools
2008-04-04 12:02 . 2008-04-04 12:13 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-04 12:02 . 2008-04-04 12:09 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-04-04 12:00 . 2008-04-05 11:50 <DIR> d-------- C:\Program Files\Eset
2008-04-04 12:00 . 2008-04-04 12:00 376 --a------ C:\WINDOWS\ODBC.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-05 16:36 77,824 ----a-w C:\WINDOWS\system32\xcomm.dll
2008-04-04 06:28 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-04 06:27 --------- d-----w C:\Program Files\Common Files\L&H
2008-04-04 06:20 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-04-04 06:14 --------- d-----w C:\Program Files\Windows Media Connect 2
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
2006-05-06 16:42 7,260,160 ----a-w C:\Program Files\mozilla firefox\plugins\libvlc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:26 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-07-10 01:43 114688]
"Cmaudio"="cmicnfg.cpl" []
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-02 02:52 3739648]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-04-05 21:11 360448]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2004-08-03 23:26 99840 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
"HideRunAsVerb"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12099:TCP"= 12099:TCP:BitComet 12099 TCP
"12099:UDP"= 12099:UDP:BitComet 12099 UDP
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-09 14:03:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\RunDll32.exe
.
**************************************************************************
.
Completion time: 2008-04-09 14:04:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-09 08:34:36
Pre-Run: 17,362,313,216 bytes free
Post-Run: 17,301,835,776 bytes free
.
2008-04-08 18:28:59 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:09:52 PM, on 4/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 3689 bytes