Hi here are the new logfiles...
ComboFix 09-11-05.01 - Administrator 11/07/2009 9:38.15.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.959.748 [GMT 8:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\BcHCMJEEXFxaCm3q.Ttf
c:\windows\Downloaded Program Files\EBC5d44wguttJ5GpMYy.Ttf
c:\windows\Downloaded Program Files\hyxqXj4ENYN8PTavg.Ttf
c:\windows\Downloaded Program Files\jEDR2jykhSujaMqF.Ttf
c:\windows\Downloaded Program Files\ku4ruEZ6xYJAZ.Ttf
c:\windows\Downloaded Program Files\SvS2DJAqqTvtTYEU.Ttf
c:\windows\Downloaded Program Files\u8w23uRSuevxt2VP.Ttf
c:\windows\Downloaded Program Files\uMub3WCE6aZ3nFgrYRX.Ttf
c:\windows\Downloaded Program Files\VnJvkuR5sK2N57D3BA7Et.Ttf
c:\windows\Downloaded Program Files\WeTqkj55B2u5bVUqbj.Ttf
c:\windows\Downloaded Program Files\WQKrDGnXQQb3Mgjk.Ttf
c:\windows\Downloaded Program Files\xarHNxPwvfeFkYvu5dAab.Ttf
c:\windows\Downloaded Program Files\yyb75q6TYvwTE86gJ.Ttf
c:\windows\Downloaded Program Files\zU2bVwKpTwHD84n.Ttf
c:\windows\Fonts\2knxWtVjbWXmUdGG.Ttf
c:\windows\Fonts\cFDPmh3MDPjcHMPd.Ttf
c:\windows\Fonts\CRp3uYCmcxMp3qQn9.Ttf
c:\windows\Fonts\eSEWZRdrSK3NeEJVy4.Ttf
c:\windows\Fonts\G8qZ5hBX7H.Ttf
c:\windows\Fonts\HXxfduw9KeQTCeP6Z.Ttf
c:\windows\Fonts\qWskzsQA6.Ttf
c:\windows\Fonts\RCZbVbjCY6wYszD3.Ttf
c:\windows\Fonts\tBeuadwPppCBnDUPgJH7P6.Ttf
c:\windows\Tasks\EkKXXTKa2TVmc6XM.ico
c:\windows\Tasks\JXGvg56A6qE3Kgb.ico
c:\windows\Tasks\kTS4JJGUYtVagxPs.ico
c:\windows\Tasks\kwycFmBeCsEW8k4Z7Gn.ico
c:\windows\Tasks\pPuSpm4tUTwyj3JpjJV.ico
c:\windows\Tasks\vC6ykXbjUGCVeCJa.ico
c:\windows\Tasks\ZsJWEjDqyh2vTuUZF.ico
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NDISFLT
((((((((((((((((((((((((( Files Created from 2009-10-07 to 2009-11-07 )))))))))))))))))))))))))))))))
.
2009-11-06 17:17 . 2007-12-26 09:30 1970176 ----a-w- c:\windows\system32\d3dx9.dll
2009-11-06 17:17 . 2007-12-26 09:30 679936 ----a-w- c:\windows\system32\D3DX81ab.dll
2009-11-06 17:17 . 2009-11-07 01:02 -------- d-----w- c:\program files\Cheat Engine
2009-11-05 01:53 . 2009-11-05 01:53 102 ----a-w- C:\deldda881.bat
2009-11-05 01:07 . 2009-11-05 01:09 -------- d-----w- c:\documents and settings\Administrator\DoctorWeb
2009-11-04 14:11 . 2009-11-04 14:12 -------- d-----w- c:\program files\Realtek AC97
2009-11-04 14:03 . 2009-11-04 14:03 102 ----a-w- C:\del79c15f.bat
2009-11-03 10:28 . 2009-11-07 01:28 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-11-03 10:23 . 2009-11-03 10:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2009-11-03 10:23 . 2009-11-03 10:23 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-11-03 10:23 . 2009-11-03 10:23 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-11-03 10:23 . 2009-11-03 10:23 179792 ----a-w- c:\windows\system32\guard32.dll
2009-11-03 10:23 . 2009-11-03 10:23 132296 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-11-03 10:23 . 2009-11-03 10:23 -------- d-----w- c:\program files\COMODO
2009-10-28 11:42 . 2006-02-23 03:39 11264 ----a-r- c:\windows\system32\drivers\xfilt_2.sys
2009-10-24 14:05 . 2009-10-24 14:05 -------- d-----w- c:\program files\Trend Micro
2009-10-23 11:29 . 2004-08-04 12:00 792064 ------w- c:\windows\system32\comres.dll
2009-10-22 12:59 . 2009-10-22 12:59 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\ UIREPAIR.DLL
2009-10-22 12:58 . 2009-10-22 12:58 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-22 12:58 . 2009-10-22 12:58 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-22 12:58 . 2009-10-22 12:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-10-22 12:58 . 2009-10-22 12:58 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-22 12:27 . 2009-10-22 12:27 -------- d-----w- c:\program files\Common Files\Thunder Network
2009-10-22 12:27 . 2009-10-22 12:27 -------- d-----w- c:\program files\Common Files\Java
2009-10-21 11:47 . 2009-10-21 11:47 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-10-17 16:04 . 2009-10-17 16:06 -------- d-----w- C:\BOXING
2009-10-14 02:33 . 2009-11-01 12:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2009-10-13 11:00 . 2009-10-13 11:01 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2009-10-13 09:05 . 2005-05-18 02:55 32768 ----a-w- c:\windows\VMZoom.exe
2009-10-13 09:05 . 2005-05-18 02:54 24576 ----a-w- c:\windows\VMPipe.dll
2009-10-13 09:05 . 2009-10-13 09:05 -------- d-----w- c:\windows\EffectResources
2009-10-13 09:05 . 2009-10-13 09:05 -------- d-----w- c:\windows\CatRoot
2009-10-13 09:05 . 2009-10-13 09:05 -------- d-----w- c:\program files\Vimicro
2009-10-13 09:05 . 2005-10-27 06:34 390849 ----a-w- c:\windows\system32\drivers\usbVM303.sys
2009-10-13 09:05 . 2005-10-25 04:56 90112 ----a-w- c:\windows\VM303_STI.EXE
2009-10-13 09:05 . 2005-05-03 07:51 176128 ----a-w- c:\windows\amcap.exe
2009-10-13 09:05 . 2005-05-02 08:45 53248 ----a-w- c:\windows\Sti303.exe
2009-10-13 09:05 . 2005-04-30 10:46 81920 ----a-w- c:\windows\system32\VM303STI.dll
2009-10-13 09:05 . 2005-04-30 10:46 102400 ----a-w- c:\windows\VM303Cap.exe
2009-10-13 08:50 . 2004-08-03 15:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-11-06 12:18 . 2009-10-12 15:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2009-11-05 01:53 . 2009-10-27 21:04 81 ----a-w- c:\windows\Fonts\AeioFs.dat
2009-11-04 23:52 . 2004-08-04 12:00 368160 ----a-w- c:\windows\system32\dsound.dll.tmp
2009-11-04 16:25 . 2009-10-12 14:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
2009-11-04 14:12 . 2009-10-12 15:44 -------- d-----w- c:\program files\AvRack
2009-10-30 20:36 . 2009-10-27 21:04 254 ----a-w- c:\windows\Fonts\MSnoipds.dat
2009-10-25 11:54 . 2009-10-12 14:40 17848 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-22 12:25 . 2004-08-04 12:00 121856 ----a-w- c:\windows\system32\stobject.dll
2009-10-22 12:21 . 2009-10-12 15:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Winamp
2009-10-19 23:29 . 2009-10-12 14:31 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-19 10:17 . 2009-10-12 15:39 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-13 09:05 . 2009-10-12 14:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-13 09:05 . 2009-10-12 14:40 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-12 16:26 . 2009-10-12 16:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-12 16:25 . 2009-10-12 16:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-12 15:56 . 2009-10-12 15:56 -------- d-----w- c:\program files\Microsoft.NET
2009-10-12 15:56 . 2009-10-12 15:56 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-10-12 15:47 . 2009-10-12 15:47 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-10-12 15:45 . 2009-10-12 15:45 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-10-12 15:45 . 2009-10-12 15:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\DAEMON Tools
2009-10-12 15:44 . 2009-10-12 15:44 -------- d-----w- c:\program files\Realtek Sound Manager
2009-10-12 15:35 . 2009-10-12 15:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-12 15:35 . 2009-10-12 15:35 -------- d-----w- c:\program files\Yahoo!
2009-10-12 15:26 . 2009-10-12 15:26 0 ----a-w- c:\windows\nsreg.dat
2009-10-12 15:17 . 2009-10-12 15:17 -------- d-----w- c:\program files\Google
2009-10-12 14:46 . 2009-10-12 14:46 -------- d-----w- c:\program files\S3
2009-10-12 14:40 . 2009-10-12 14:40 -------- d-----w- c:\program files\VIA
2009-10-12 14:32 . 2009-10-12 14:32 -------- d-----w- c:\program files\microsoft frontpage
2009-10-12 14:28 . 2009-10-12 14:28 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-24 12:16 . 2009-10-12 15:35 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-09-10 06:54 . 2009-10-12 16:25 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 06:53 . 2009-10-12 16:25 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
.
------- Sigcheck -------
[-] 2009-03-21 . 32272BF10467C8ACF1F83138C61D541E . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-04 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"BigDog303"="c:\windows\VM303_STI.EXE" [2005-10-25 90112]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-09-22 90112]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 07:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"UPS"=3 (0x3)
"Spooler"=2 (0x2)
"ImapiService"=3 (0x3)
"ALG"=3 (0x3)
"ose"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"3961:TCP"= 3961:TCP:bbcckgsb
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [10/12/2009 10:42 PM 11264]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [11/3/2009 6:23 PM 132296]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [11/3/2009 6:23 PM 25160]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 9:24 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 9:24 PM 74480]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 9:24 PM 7408]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
batjce
.
Contents of the 'Scheduled Tasks' folder
2009-11-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-2147080445-682003330-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-12 15:18]
2009-11-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-2147080445-682003330-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-12 15:18]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gdaf2k58.default\
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dl l
FF - plugin: d:\program files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-11-07 09:43
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????????0?????????@???????????? ??
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
GMER - Rootkit Detector and Remover
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys xfilt.sys ACPI.sys hal.dll >>UNKNOWN [0x857681F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x857681f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
************************************************** ************************
.
Completion time: 2009-11-07 9:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-07 01:45
ComboFix2.txt 2009-11-03 21:14
Pre-Run: 12,889,169,920 bytes free
Post-Run: 12,872,650,752 bytes free
- - End Of File - - 0579DB862D74BDF09E95210EB0F1EC00
hijackthis logfile
----
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:48:51 AM, on 11/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\VM303_STI.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACA44DAA-F941-4928-BC6E-22A1D3B1E1CB}: NameServer = 202.78.97.41 210.4.2.61
O20 - AppInit_DLLs: c:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
--
End of file - 2592 bytes
Thanks...