Hello gerbil,I've just finish scanning using Combofix.It takes quite a while,but I manage to complete it as you asked me to do.Here's the log - ComboFix 08-12-03.04 - sam08 2008-12-04 23:56:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1614 [GMT 8:00]
Running from: c:\documents and settings\sam08\Desktop\comfix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\crypts.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Drivers\TDSSmxoe.sys
c:\windows\system32\pthreadVC.dll
c:\windows\system32\rs32net.exe
c:\windows\system32\TDSScixx.dll
c:\windows\system32\TDSSmhxw.dll
c:\windows\system32\TDSSmtpe.dat
c:\windows\system32\TDSSncur.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoeqh.dll
c:\windows\system32\TDSSqxtx.dll
c:\windows\system32\TDSSwgod.log
c:\windows\system32\TDSSyavu.dll
D:\resycled
d:\resycled\boot.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Legacy_TDSSSERV.SYS
-------\Service_NPF
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.
2008-12-02 22:46 . 2008-12-02 22:46 <DIR> d-------- C:\Deckard
2008-12-02 18:20 . 2008-04-14 08:12 116,224 --a--c--- c:\windows\system32\dllcache\xrxwiadr.dll
2008-12-02 18:20 . 2001-08-17 22:37 99,865 --a--c--- c:\windows\system32\dllcache\xlog.exe
2008-12-02 18:20 . 2001-08-17 22:37 27,648 --a--c--- c:\windows\system32\dllcache\xrxftplt.exe
2008-12-02 18:20 . 2001-08-17 22:36 23,040 --a--c--- c:\windows\system32\dllcache\xrxwbtmp.dll
2008-12-02 18:20 . 2004-08-03 22:29 19,455 --a--c--- c:\windows\system32\dllcache\wvchntxx.sys
2008-12-02 18:20 . 2008-04-14 02:46 19,200 --a--c--- c:\windows\system32\dllcache\wstcodec.sys
2008-12-02 18:20 . 2008-04-14 08:12 18,944 --a--c--- c:\windows\system32\dllcache\xrxscnui.dll
2008-12-02 18:20 . 2001-08-17 12:11 16,970 --a--c--- c:\windows\system32\dllcache\xem336n5.sys
2008-12-02 18:20 . 2004-08-03 22:29 12,063 --a--c--- c:\windows\system32\dllcache\wsiintxx.sys
2008-12-02 18:20 . 2001-08-17 22:37 4,608 --a--c--- c:\windows\system32\dllcache\xrxflnch.exe
2008-12-02 18:18 . 2001-08-17 22:36 495,616 --a--c--- c:\windows\system32\dllcache\sblfx.dll
2008-12-02 18:17 . 2001-08-17 13:28 899,146 --a--c--- c:\windows\system32\dllcache\r2mdkxga.sys
2008-12-02 18:16 . 2001-08-17 13:28 802,683 --a--c--- c:\windows\system32\dllcache\ltsm.sys
2008-12-02 18:15 . 2008-04-14 08:11 702,845 --a--c--- c:\windows\system32\dllcache\i81xdnt5.dll
2008-12-02 18:14 . 2001-08-17 14:56 1,733,120 --a--c--- c:\windows\system32\dllcache\g400d.dll
2008-12-02 18:13 . 2001-08-17 12:13 980,034 --a--c--- c:\windows\system32\dllcache\cicap.sys
2008-12-02 18:12 . 2001-08-17 13:28 871,388 --a--c--- c:\windows\system32\dllcache\bcmdm.sys
2008-12-02 18:11 . 2001-08-17 13:28 762,780 --a--c--- c:\windows\system32\dllcache\3cwmcru.sys
2008-11-30 12:36 . 2008-12-04 21:36 2,259 --a------ c:\windows\system32\TDSSnrsr.dll
2008-11-30 12:28 . 2008-11-30 12:28 104,448 --a------ c:\windows\system32\winhlp.exe
2008-11-30 12:24 . 2008-11-30 12:25 2 --a------ C:\1151076018
2008-11-29 20:37 . 2008-11-29 22:45 <DIR> d-------- c:\documents and settings\sam08\Application Data\vlc
2008-11-28 17:42 . 2008-11-28 17:41 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-28 17:25 . 2008-11-28 17:25 <DIR> d-------- c:\windows\system32\LogFiles
2008-11-28 16:10 . 2008-11-28 17:44 <DIR> d-------- c:\program files\Java
2008-11-28 16:10 . 2008-11-28 17:41 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-25 20:43 . 2008-11-25 20:43 <DIR> d-------- c:\program files\CCleaner
2008-11-23 10:43 . 2008-11-23 10:43 <DIR> d--h----- c:\documents and settings\All Users\Application Data\CanonBJ
2008-11-23 10:43 . 2005-03-25 13:10 139,776 --a------ c:\windows\system32\CNMLM76.DLL
2008-11-23 10:43 . 2005-03-09 02:17 90,112 -ra------ c:\windows\system32\CNMCP76.exe
2008-11-23 10:43 . 2005-03-25 13:00 8,704 --a------ c:\windows\system32\CNMVS76.DLL
2008-11-23 10:37 . 2008-04-14 02:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-11-23 10:37 . 2008-04-14 02:47 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2008-11-22 14:14 . 2008-11-30 18:15 <DIR> d-------- c:\documents and settings\sam08\Application Data\dvdcss
2008-11-17 00:19 . 2008-11-17 00:19 <DIR> d-------- c:\windows\system32\scripting
2008-11-17 00:19 . 2008-11-17 00:19 <DIR> d-------- c:\windows\system32\en
2008-11-17 00:19 . 2008-11-17 00:19 <DIR> d-------- c:\windows\system32\bits
2008-11-17 00:17 . 2008-11-17 00:17 <DIR> d-------- c:\windows\ServicePackFiles
2008-11-16 01:18 . 2008-11-16 01:18 <DIR> d--h----- c:\windows\PIF
2008-11-15 22:33 . 2008-12-04 09:57 <DIR> d-------- c:\documents and settings\sam08\.tfo3
2008-11-15 22:32 . 2008-12-04 09:57 <DIR> d-------- c:\program files\ThinkFree Office
2008-11-15 17:39 . 2008-11-15 17:39 <DIR> d-------- c:\documents and settings\sam08\Application Data\Media Player Classic
2008-11-15 07:25 . 2008-04-14 08:12 2,134,528 --a--c--- c:\windows\system32\dllcache\smtpsnap.dll
2008-11-15 07:24 . 2008-04-14 08:11 1,888,992 --a--c--- c:\windows\system32\dllcache\ati3duag.dll
2008-11-13 18:41 . 2008-11-13 18:41 <DIR> d-------- c:\program files\ConvertHelper
2008-11-13 15:58 . 2008-11-13 15:58 <DIR> d-------- c:\program files\IObit
2008-11-13 14:04 . 2008-11-13 14:19 <DIR> d-------- c:\program files\BitComet
2008-11-13 12:54 . 2008-11-13 13:23 <DIR> d-------- c:\windows\BDOSCAN8
2008-11-13 03:02 . 2008-11-13 03:02 <DIR> d-------- c:\program files\MSXML 6.0
2008-11-13 03:01 . 2008-12-02 20:40 <DIR> d--h----- c:\windows\$hf_mig$
2008-11-13 03:01 . 2008-11-13 03:01 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-13 03:00 . 2004-08-04 07:56 221,184 --a------ c:\windows\system32\wmpns.dll
2008-11-13 03:00 . 2007-08-10 20:46 26,488 --a------ c:\windows\system32\spupdsvc.exe
2008-11-12 19:34 . 2008-11-12 19:34 <DIR> d-------- c:\documents and settings\sam08\dwhelper
2008-11-12 19:34 . 2008-11-12 19:34 <DIR> d-------- c:\documents and settings\LocalService\Application Data\SACore
2008-11-12 18:35 . 2008-11-12 18:35 <DIR> d-------- c:\documents and settings\sam08\Application Data\Malwarebytes
2008-11-12 18:28 . 2008-11-12 18:28 <DIR> d-------- c:\documents and settings\sam08\WINDOWS
2008-11-12 17:19 . 2008-11-12 17:19 <DIR> d-------- c:\documents and settings\sam08\Application Data\TMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 05:16 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-02 05:09 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-02 05:09 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-15 14:19 --------- d-----w c:\program files\McAfee
2008-11-12 14:15 --------- d-----w c:\program files\Google
2008-11-12 13:45 --------- d-----w c:\program files\Trend Micro
2008-11-12 11:17 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-11-12 11:02 --------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-11-12 11:00 --------- d-----w c:\program files\Common Files\McAfee
2008-11-12 10:59 --------- d-----w c:\program files\McAfee.com
2008-11-12 10:41 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-11-12 10:40 --------- d-----w c:\program files\Common Files\Adobe
2008-11-12 10:39 --------- d-----w c:\program files\VideoLAN
2008-11-12 10:38 --------- d-----w c:\program files\DivX
2008-11-12 10:35 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-12 10:29 --------- d-----w c:\program files\TM Net
2008-11-12 10:29 --------- d-----w c:\program files\Common Files\FTL Shared
2008-11-12 10:25 11 ----a-w C:\SelfTests.dat
2008-11-12 10:23 --------- d-----w c:\program files\WinPcap
2008-11-12 09:19 --------- d-----w c:\program files\Marvell
2008-11-12 08:42 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-12 08:26 --------- d-----w c:\program files\microsoft frontpage
2008-11-12 08:22 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 06:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 06:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 06:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 06:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 06:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 06:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 06:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 06:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 06:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 06:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-30 08:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-09 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-09 81920]
"%FP%TM Net fts.exe"="c:\program files\TM Net\tmnet streamyx dialer\fts.exe" [2004-01-07 77312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2008-07-11 641208]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2008-06-13 1176808]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-16 479232]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-28 136600]
"nwiz"="nwiz.exe" [2008-01-09 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 c:\windows\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2007-05-28 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IE7-11"="advpack.dll" [2008-08-26 c:\windows\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"17182:TCP"= 17182:TCP:BitComet 17182 TCP
"17182:UDP"= 17182:UDP:BitComet 17182 UDP
"10920:TCP"= 10920:TCP:BitComet 10920 TCP
"10920:UDP"= 10920:UDP:BitComet 10920 UDP
"14531:TCP"= 14531:TCP:BitComet 14531 TCP
"14531:UDP"= 14531:UDP:BitComet 14531 UDP
"21508:TCP"= 21508:TCP:BitComet 21508 TCP
"21508:UDP"= 21508:UDP:BitComet 21508 UDP
"27182:TCP"= 27182:TCP:BitComet 27182 TCP
"27182:UDP"= 27182:UDP:BitComet 27182 UDP
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-11-12 203280]
.
Contents of the 'Scheduled Tasks' folder
2008-11-14 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-07-09 18:10]
2008-11-30 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-07-09 18:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
FireFox -: Profile - c:\documents and settings\sam08\Application Data\Mozilla\Firefox\Profiles\sppmb9tg.default\
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-04 23:59:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(580)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\windows\system32\rundll32.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\McAfee\MSK\msksrver.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-05 0:01:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 16:01:31
Pre-Run: 9,544,310,784 bytes free
Post-Run: 9,515,438,080 bytes free
237 --- E O F --- 2008-12-02 12:40:57
Hope we'll get all this over soon.Is there anything else,just tell me. I really appreciate your helpful efforts.Thank you.