OK, I am not sure if the Combo Fix thing worked right. I saved waht you posted, and then dragged it into Combofix. When combofix started, it said there was an update and asked if I wanted it. I said yes, it updated, restarted and then ran a scan. When it was done, it opened a log, but it did not open a message window as your instructions said….never a pop upasking me to say yes. The log is below with the others. I took care of getting the new Java, and I will post the other logs in a few minutes when I have them run and saved….
Sean
ComboFix Log from 5/12:
ComboFix 09-05-12.04 - Sean Brereton 05/12/2009 21:27.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.255.99 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sean Brereton\Desktop\CFscript.txt
AV: AVG 7.5.557 *On-access scanning disabled* (Outdated)
FILE ::
c:\windows\SYSTEM32\divimuvo.dll.tmp
c:\windows\SYSTEM32\vofehafi.dll.tmp
file zipped: c:\windows\SYSTEM32\DRIVERS\ozoshkbu.sys
file zipped: c:\windows\SYSTEM32\DRIVERS\zpmodemnt.sys
file zipped: c:\windows\system32\jcrprpuj.dll
file zipped: c:\windows\SYSTEM32\ojlplap.dll
file zipped: c:\windows\system32\qtiqrtf.dll
file zipped: c:\windows\system32\vikuzeja.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\profiles.ini
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\cert8.db
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\compatibility.ini
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\compreg.dat
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\cookies.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\formhistory.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\key3.db
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\localstore.rdf
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\permissions.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\places.sqlite-journal
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\places.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\pluginreg.dat
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\prefs.js
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\secmod.db
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\webappsstore.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\xpti.dat
c:\documents and settings\Sean Brereton\Local Settings\Application Data\jpbbjzja
c:\documents and settings\Sean Brereton\Local Settings\Application Data\jpbbjzja\Profiles\jfadlt30.default\urlclassifier3.sqlite
c:\documents and settings\Sean Brereton\Local Settings\Application Data\jpbbjzja\Profiles\jfadlt30.default\XPC.mfl
c:\windows\SYSTEM32\divimuvo.dll.tmp
c:\windows\SYSTEM32\DRIVERS\ozoshkbu.sys
c:\windows\SYSTEM32\DRIVERS\zpmodemnt.sys
c:\windows\system32\jcrprpuj.dll
c:\windows\SYSTEM32\ojlplap.dll
c:\windows\system32\OLD2.tmp
c:\windows\system32\qtiqrtf.dll
c:\windows\system32\vikuzeja.exe
c:\windows\SYSTEM32\vofehafi.dll.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_GCVQDQGO
——-\Legacy_ozoshkbu
——-\Legacy_ZPMODEMSYSNTDRVNT
——-\Service_ozoshkbu
——-\Service_ZPMODEMSYSNTDRVNT
((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.
2009-05-04 11:07 . 2009-05-04 11:07 ——– d—–w c:\documents and settings\All Users\Application Data\TEMP
2009-05-04 11:07 . 2009-05-04 11:09 ——– d—–w c:\program files\SpywareBlaster
2009-05-04 01:31 . 2009-05-04 01:31 ——– d—–w c:\program files\Trend Micro
2009-05-03 22:01 . 2009-05-03 22:01 ——– d—–w c:\program files\Panda Security
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\Malwarebytes
2009-05-03 03:21 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-03 03:21 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-25 13:10 . 2009-04-25 13:11 ——– d—–w c:\program files\EPSON
2009-04-25 13:01 . 2009-04-25 13:01 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\InstallShield
2009-04-25 13:01 . 2009-04-25 13:09 ——– d—–w C:\epson
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 01:27 . 2004-08-04 11:00 23424 —-a-w c:\windows\system32\drivers\eeizkvyv.sys
2009-05-09 20:36 . 2004-08-04 11:00 182912 —-a-w c:\windows\system32\drivers\ndis.sys
2009-05-04 11:34 . 2006-01-03 06:20 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-01 02:14 . 2004-08-04 11:00 14336 —-a-w c:\windows\system32\svchost.exe
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\TeaTimer (Spybot - Search & Destroy)
.
((((((((((((((((((((((((((((( SnapShot@2009-05-04_02.18.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 11:00 . 2004-08-04 11:00 182912 c:\windows\SYSTEM32\DLLCACHE\ndis.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-24 219136]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor.lnk
backup=c:\windows\pss\Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TapiSrv"=3 (0x3)
"RasMan"=3 (0x3)
"mnmsrvc"=3 (0x3)
"CiSvc"=3 (0x3)
"btwdins"=2 (0x2)
"AdobeActiveFileMonitor6.0"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"EPSON Stylus Photo R340 Series"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB001" /M "Stylus Photo R340"
"EPSON Stylus Photo R340 Series (Copy 1)"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P39 "EPSON Stylus Photo R340 Series (Copy 1)" /O6 "USB001" /M "Stylus Photo R340"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"DwlClient"=c:\program files\Common Files\Dell\EUSW\Support.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\ZCfgSvc.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\WLKEEPER.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15818:TCP"= 15818:TCP:@xpsp2res.dll,-22009
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys –> c:\windows\system32\drivers\pavboot.sys [?]
— Other Services/Drivers In Memory —
*NewlyCreated* - OZOSHKBU
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - AVG Anti-Spyware Guard
*Deregistered* - Avg7UpdSvc
*Deregistered* - AVGEMS
*Deregistered* - BITS
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - EvtEng
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RegSrvc
*Deregistered* - RpcSs
*Deregistered* - S24EventMonitor
*Deregistered* - SamSs
*Deregistered* - SCardSvr
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - UMWdf
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WLANKEEPER
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://vwvortex.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-12 21:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3263456595-3722201187-1372389037-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(968)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\SCARDSVR.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\progra~1\Grisoft\AVGFRE~1\avgupsvc.exe
c:\progra~1\Grisoft\AVGFRE~1\avgemc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\SYSTEM32\WSCNTFY.EXE
.
**************************************************************************
.
Completion time: 2009-05-13 21:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-13 01:41
ComboFix2.txt 2009-05-09 20:46
ComboFix3.txt 2009-05-04 02:24
Pre-Run: 2,813,026,304 bytes free
Post-Run: 2,798,583,808 bytes free
229 — E O F — 2008-10-06 04:09
Kaspersky Log from 5/12
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, May 13, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, May 13, 2009 04:26:30
Records in database: 2170757
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 58763
Threat name: 5
Infected objects: 6
Suspicious objects: 0
Duration of the scan: 02:17:36
File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS.vir Infected: Virus.Win32.Protector.b 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\OLD2.tmp.vir Infected: Trojan.Win32.Inject.xmi 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_jcrprpuj_.dll.zip Infected: Trojan-Clicker.Win32.Delf.cbe 1
C:\Qoobox\Quarantine\[4]-Submit_2009-05-12_21.26.50.zip Infected: Trojan.Win32.BHO.ext 1
C:\Qoobox\Quarantine\[4]-Submit_2009-05-12_21.26.50.zip Infected: Trojan-Dropper.Win32.Agent.ahfp 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP8\A0000387.sys Infected: Virus.Win32.Protector.b 1
The selected area was scanned.
GMer Scan 5/12
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-05-13 07:53:25
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.15 —-
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess [0xFA0348AC]
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess [0xFA034812]
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \FileSystem\Fastfat \Fat F0DAFC8A
AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Files - GMER 1.0.15 —-
ADS C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\OLD2.tmp.vir:ext.exe 32256 bytes executable
—- EOF - GMER 1.0.15 —-