Hello mowman!
So I followed all of the steps you gave me in your post above. At first, ComboFix said that I had rootkit and told me to write down on a piece of paper these three things.
C:\WINDOWS\system32\PRAGMAsrcr.dat
C:\WINDOWS\system32\pragmaserf.dll
C:\WINDOWS\system32\pragmabbr.dll
However, it never asked me to retype these 3 again. It rebooted my computer two times and ended up with this log.
ComboFix 10-04-28.03 - Administrator 04/28/2010 17:10:13.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.594 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\combo.com
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\0869C220B4407F533205A7C785AE3FBC
c:\documents and settings\Administrator\Application Data\0869C220B4407F533205A7C785AE3FBC\enemies-names.txt
c:\documents and settings\Administrator\Application Data\0869C220B4407F533205A7C785AE3FBC\newupdate1142C.exe
c:\documents and settings\Administrator\Application Data\APManager
c:\documents and settings\Administrator\Application Data\APManager\files
c:\documents and settings\Administrator\Application Data\APManager\iplog
c:\documents and settings\Administrator\Application Data\APManager\languages\Czech.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Danish.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Dutch.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\English.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\French.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\German.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Italian.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Portuguese.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Slovak.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Spanish.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\template.lng
c:\documents and settings\Administrator\Application Data\APManager\settings.ini
c:\documents and settings\Administrator\Application Data\APManager\uninstall.exe
c:\documents and settings\Administrator\Application Data\APManager\wallpaper.jpg
c:\documents and settings\Administrator\Application Data\ezLife
c:\documents and settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Digital Protection.lnk
c:\documents and settings\Administrator\Desktop\Digital Protection Support.lnk
c:\documents and settings\Administrator\Desktop\Digital Protection.lnk
c:\documents and settings\Administrator\Local Settings\Application Data\ave.exe
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\741wXJ8y2.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\7MvWGE3n.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\aKHGghL.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\g13TyP1oS.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\kYRv2BV.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\n0UNw4.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\ndx088b.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\TestBrowser.html
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\udP647J.jpg
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\About.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Activate.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Buy.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Digital Protection Support.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Digital Protection.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Scan.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Settings.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Update.lnk
c:\documents and settings\All Users\Application Data\fiosejgfse.dll
c:\documents and settings\All Users\Application Data\pragmamfeklnmal.dll
c:\documents and settings\All Users\Favorites\_favdata.dat
c:\documents and settings\LocalService\Application Data\ezLife
c:\program files\Digital Protection
c:\program files\Digital Protection\about.ico
c:\program files\Digital Protection\activate.ico
c:\program files\Digital Protection\buy.ico
c:\program files\Digital Protection\dighook.dll
c:\program files\Digital Protection\help.ico
c:\program files\Digital Protection\scan.ico
c:\program files\Digital Protection\settings.ico
c:\program files\Digital Protection\splash.mp3
c:\program files\Digital Protection\update.ico
c:\program files\Digital Protection\virus.mp3
c:\program files\ezLife
c:\program files\ezLife\ezLife\1.5.2.0\uninstall.exe
c:\program files\Smart-Ads-Solutions
c:\program files\Smart-Ads-Solutions\SmartAds\1.5.2.0\uninstall.exe
c:\windows\irudifemeyu.dll
c:\windows\PRAGMAwkbdribipy
c:\windows\PRAGMAwkbdribipy\PRAGMAc.dll
c:\windows\PRAGMAwkbdribipy\PRAGMAcfg.ini
c:\windows\PRAGMAwkbdribipy\PRAGMAd.sys
c:\windows\system32\6to4v32.dll
c:\windows\system32\certstore.dat
c:\windows\system32\ctfmon .exe
c:\windows\system32\kutyrlijof.exe
c:\windows\system32\nizdzwmssthtutmk.dll
c:\windows\system32\nwiz .exe
c:\windows\system32\pragmabbr.dll
c:\windows\system32\pragmaserf.dll
c:\windows\system32\PRAGMAsrcr.dat
c:\windows\system32\rundll32 .exe
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_PRAGMAwkbdribipy
——-\Legacy_PRAGMAwkbdribipy
——-\Legacy_6TO4
——-\Service_6to4
((((((((((((((((((((((((( Files Created from 2010-03-28 to 2010-04-29 )))))))))))))))))))))))))))))))
.
2010-04-28 02:54 . 2010-04-28 02:55 ——– d—–w- c:\program files\ERUNT
2010-04-27 04:33 . 2010-04-27 04:33 ——– d—–w- c:\documents and settings\Administrator\Application Data\Avira
2010-04-27 04:23 . 2010-04-27 04:23 ——– d—–w- c:\program files\Avira
2010-04-27 04:23 . 2010-04-27 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-04-27 04:23 . 2010-03-01 17:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-04-27 04:23 . 2010-02-16 21:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-04-27 04:23 . 2009-05-11 19:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-04-27 04:23 . 2009-05-11 19:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-04-27 03:42 . 2010-04-27 03:42 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\program files\Conduit
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\WeFiBar
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\program files\WeFiBar
2010-04-27 03:28 . 2008-12-30 23:38 13824 ——w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jasj80uq.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}\components\FFAlert.dll
2010-04-27 03:28 . 2008-12-30 23:38 114688 ——w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jasj80uq.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}\components\npmozax.dll
2010-04-27 03:06 . 2010-04-27 03:07 ——– d—–w- c:\program files\WeFi
2010-04-27 03:04 . 2010-04-29 00:18 823808 —-a-w- c:\windows\system32\drivers\evffxswk.sys
2010-04-27 03:03 . 2010-04-27 03:03 118 —-a-w- C:\tujserrew.bat
2010-04-27 03:03 . 2010-04-27 03:03 162304 —-a-w- c:\windows\Amogia.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-28 23:46 . 2009-09-29 21:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-14 07:55 . 2008-07-17 03:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-11 12:38 . 2008-04-23 00:16 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2008-07-12 19:10 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2008-07-12 19:09 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-09 11:06 . 2008-07-12 19:09 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-02-24 13:11 . 2008-04-14 08:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 16:10 . 2008-04-14 08:00 2189952 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 04:01 2066816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:27 . 2008-04-14 08:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 11:36 . 2008-07-12 19:09 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
.
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\Avira\AntiVir Desktop\avgnt .exe
c:\program files\Common Files\Ahead\Lib\nerocheck .exe
c:\program files\Common Files\Ahead\Lib\nmbgmonitor .exe
c:\program files\HP\HP Software Update\hpwuschd2 .exe
c:\program files\HP\hpcoretech\hpcmpmgr .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\windows\ime\imjp8_1\imjpmig .exe
c:\windows\system32\IME\PINTLGNT\imscinst .exe
c:\windows\system32\IME\TINTLGNT\tintsetp .exe
——- Sigcheck ——-
[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk.disabled [2009-5-11 1808]
HP Image Zone Fast Start.lnk.disabled [2009-5-11 798]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-08-19 20:26 77824 -c–a-w- c:\windows\SOUNDMAN.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"QZAIB7KITK"=c:\windows\Amogia.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" /min
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"MSPY2002"=c:\windows\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"PHIME2002A"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [9/29/2009 2:16 PM 13696]
— Other Services/Drivers In Memory —
*Deregistered* - evffxswk
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Mozilla Firefox (3.5.3) - c:\program files\Mozilla Firefox\uninstall\helper.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-28 17:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\evffxswk]
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3912)
c:\windows\system32\WININET.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
.
**************************************************************************
.
Completion time: 2010-04-28 17:21:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-29 00:21
Pre-Run: 21,152,985,088 bytes free
Post-Run: 21,571,284,992 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 302CCE8B292AA848E4B42B6BC07A80EC