I have been infected recently on my Dell laptop, but I managed to stop them using my antivirus, Comodo, and my on-demand scanners, Malwarebytes and Superantispyware. The case is that I cannot run combofix on normal mode. I've recently saw a C:32788R22FWJFW folder and it has something to do with combofix. Whenever I try to go on combofix it will say that it cannot find 32788R22FWJFW. I cannot go into safe mode because it will automatically shut down by itself within a few seconds. I wanted to reformat my computer but again, when I am trying to reformat it, the stupid laptop just shuts down by itself. Whenever I'm in normal mode of the laptop, it rarely shuts down by itself. So, I really do not know what is the problem. Either I still have rootkits that I cannot find, or hardware problems. I'm at a loss.
Here is my MBAM log.
Malwarebytes' Anti-Malware 1.41
Database version: 2831
Windows 5.1.2600 Service Pack 2
1/20/2009 12:27:43 PM
mbam-log-2009-01-20 (12-27-43).txt
Scan type: Full Scan (C:|)
Objects scanned: 246807
Time elapsed: 1 hour(s), 9 minute(s), 56 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:Program FilesCOMODOCOMODO Internet SecurityQuarantineUACkxmubiqrlp.dll (Trojan.Agent) -> Delete on reboot.
ROOTREAPL LOG.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/01/20 12:42
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:windowsSystem32Driversdump_atapi.sys
Address: 0xEDF24000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:windowsSystem32Driversdump_WMILIB.SYS
Address: 0xF7AA0000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_PNP2658
Image Path: DriverPCI_PNP2658
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:windowssystem32drivers
ootrepeal.sys
Address: 0xEB442000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spgx.sys
Image Path: spgx.sys
Address: 0xF7343000 Size: 1048576 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: Driversptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 011 Function Name: NtAdjustPrivilegesToken
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11dd46
#: 031 Function Name: NtConnectPort
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11d250
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11d8ea
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11e2c2
#: 046 Function Name: NtCreatePort
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11d132
#: 050 Function Name: NtCreateSection
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11f254
#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11f52c
#: 053 Function Name: NtCreateThread
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11ccf8
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11df2c
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11e0dc
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11ca5a
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spgx.sys" at address 0xf7362ca2
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spgx.sys" at address 0xf7363030
#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11eed6
#: 105 Function Name: NtMakeTemporaryObject
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11d4d4
#: 116 Function Name: NtOpenFile
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11db2e
#: 119 Function Name: NtOpenKey
Status: Hooked by "spgx.sys" at address 0xf73440c0
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11c78a
#: 125 Function Name: NtOpenSection
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11d764
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11c902
#: 160 Function Name: NtQueryKey
Status: Hooked by "spgx.sys" at address 0xf7363108
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spgx.sys" at address 0xf7362f88
#: 192 Function Name: NtRenameKey
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11e688
#: 200 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11e9f0
#: 210 Function Name: NtSecureConnectPort
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11ec72
#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11f084
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11e488
#: 249 Function Name: NtShutdownSystem
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11d46e
#: 255 Function Name: NtSystemDebugControl
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11d658
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11cffc
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:windowsSystem32DRIVERScmdguard.sys" at address 0xee11ceca