Ok, looks like that did the trick, rootcheck, combofix and hijack follow,
Anti virus now runs, it found and removed trojan.zlob.n and found the generic trojan in ..system32\kddwe.exe but can only quarantine.
Everything else seems to be working a bit better, the system is a bit unstable on shutdown/startup but i'll keep running it and see how it goes.
Thanks Andrea
RootCheck Log
********************************* ROOTCHK-(21-07-07)-LOG, by ejvindh
07/08/2007 17:59:52.43
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-07 17:59:54
Windows 5.1.2600 Service Pack 2
detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden processes ...
detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden services & system hive ...
detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden registry entries ...
detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden files ...
hidden processes: 0
hidden files: 0
ComboFix Log
ComboFix 07-08-04.3 - "Michael McClelland" 2007-08-07 18:05:49.1 [GMT 1:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.True
/wow section not completed
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\video activex access
C:\Program Files\video activex access\iesunst.exe
C:\Program Files\video activex access\ot.ico
C:\Program Files\video activex access\ts.ico
C:\Program Files\video activex access\uninst.exe
C:\WINDOWS\system32\kddwe.exe
((((((((((((((((((((((((( Files Created from 2007-07-07 to 2007-08-07 )))))))))))))))))))))))))))))))
2007-08-07 18:03 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-07 17:36 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-05 16:10 9,216 --a------ C:\WINDOWS\system32\avgwlntf.dll
2007-08-05 16:10 110,592 --a------ C:\WINDOWS\system32\avgfwafu.dll
2007-08-05 13:54 <DIR> d-------- C:\Program Files\AVG
2007-08-04 23:52 <DIR> d-------- C:\Program Files\CCleaner
2007-08-04 12:16 28,672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-08-04 11:34 <DIR> d-------- C:\DOCUME~1\MICHAE~1\APPLIC~1\WholeSecurity
2007-07-23 21:58 684,032 --a------ C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-23 21:58 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\APPLIC~1\Gtek
2007-07-23 21:58 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver
2007-07-23 21:58 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-07-23 21:58 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Jasc Software Inc
2007-07-23 21:58 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Intel
2007-07-19 19:13 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-12 19:59 <DIR> d-------- C:\Program Files\iPod
2007-07-12 19:56 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-07-12 19:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-07 17:37 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-07-29 09:01 --------- d-------- C:\Program Files\Modem Helper
2007-07-29 09:01 --------- d-------- C:\Program Files\Hewlett-Packard
2007-07-29 09:01 --------- d-------- C:\Program Files\DivX
2007-07-29 09:01 --------- d-------- C:\Program Files\Common Files\AOL
2007-07-29 09:01 --------- d-------- C:\Program Files\Apple Software Update
2007-07-26 18:29 --------- d-------- C:\DOCUME~1\MICHAE~1\APPLIC~1\VideoEgg
2007-07-19 19:22 --------- d-------- C:\Program Files\Norton Internet Security
2007-07-19 19:18 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-07-19 19:18 8014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-07-19 19:18 48776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-19 19:18 115000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-19 19:18 --------- d-------- C:\Program Files\Symantec
2007-07-12 19:59 --------- d-------- C:\Program Files\iTunes
2007-07-12 19:53 --------- d-------- C:\Program Files\QuickTime
2007-06-17 20:06 --------- d-------- C:\DOCUME~1\MICHAE~1\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-06-09 11:19 --------- d-------- C:\Program Files\SystemRequirementsLab
2007-06-09 00:05 108144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-06-08 21:40 --------- dr-h----- C:\DOCUME~1\MICHAE~1\APPLIC~1\SecuROM
2007-06-08 21:28 --------- d-------- C:\Program Files\Electronic Arts
2007-05-31 07:45 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-05-31 07:44 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 07:44 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 07:44 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 07:44 740442 --a------ C:\WINDOWS\system32\DivX.dll
2007-05-16 16:12 86528 --------- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 16:12 85504 --------- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 16:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 16:12 683520 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 16:12 510976 --------- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 16:12 1314816 --------- C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-08 10:24 3583488 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2006-03-12 15:45 1634 --a------ C:\Program Files\D2P.exe.config
2005-05-12 12:35 913408 --a------ C:\Program Files\D2P.exe
2005-05-12 12:35 53248 --a------ C:\Program Files\CommonUtils.dll
2005-05-12 12:35 323584 --a------ C:\Program Files\CommonGUI.dll
2005-04-04 11:52 765952 -ra------ C:\Program Files\CDDBUI.dll
2005-04-04 11:52 589824 -ra------ C:\Program Files\CDDBControl.dll
2005-04-04 11:52 143360 --a------ C:\Program Files\Interop.CDDBCONTROLLib.dll
2005-04-04 11:52 12800 --a------ C:\Program Files\Interop.CDDBUICONTROLLib.dll
2005-03-31 12:34 93148 -ra------ C:\Program Files\D2P.chm
2005-03-30 17:02 15360 --a------ C:\Program Files\Autoproxy.dll
2005-03-10 17:39 749568 -ra------ C:\Program Files\mp3enc.dll
2005-03-10 14:06 86016 -ra------ C:\Program Files\CddbLangJA.dll
2005-03-10 14:06 81920 -ra------ C:\Program Files\CddbLangKO.dll
2005-03-10 14:06 77824 -ra------ C:\Program Files\CddbLangZT.dll
2005-03-10 14:06 77824 -ra------ C:\Program Files\CddbLangZH.dll
2005-03-10 14:06 110592 -ra------ C:\Program Files\CddbLangPT_BR.dll
2005-03-10 14:06 110592 -ra------ C:\Program Files\CddbLangNL.dll
2005-03-10 14:06 110592 -ra------ C:\Program Files\CddbLangIT.dll
2005-03-10 14:06 110592 -ra------ C:\Program Files\CddbLangFR.dll
2005-03-10 14:06 110592 -ra------ C:\Program Files\CddbLangES.dll
2005-03-10 14:06 110592 -ra------ C:\Program Files\CddbLangDE.dll
2005-03-10 14:06 106496 -ra------ C:\Program Files\CddbLangSV.dll
2005-03-10 14:06 102400 -ra------ C:\Program Files\CddbLangTH.dll
2005-03-10 04:02 49152 --a------ C:\Program Files\AxInterop.SHDocVw.dll
2005-03-10 04:02 126976 --a------ C:\Program Files\Interop.SHDocVw.dll
2005-02-28 19:11 53248 --a------ C:\Program Files\Interop.Shell32.dll
2004-11-09 13:07 606 -ra------ C:\Program Files\D2P.exe.manifest
2004-11-09 13:07 118784 -ra------ C:\Program Files\mp3dec.dll
2004-11-09 13:07 0 -ra------ C:\Program Files\D2P.exe.local
2004-08-04 01:56 49152 --a------ C:\Program Files\AxInterop.WMPLib.dll
2004-08-04 01:56 270336 --a------ C:\Program Files\Interop.WMPLib.dll
2004-08-04 00:01 49152 --a------ C:\Program Files\Interop.IWshRuntimeLibrary.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 15:02]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 15:02]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 04:10]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 11:26]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 06:33]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 22:19]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-11 11:08]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-10-11 22:16]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2002-12-17 11:40]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2002-12-02 20:56]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 09:18]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-05 16:10]
"!AVG Anti-Spyware"="C:\Documents and Settings\Michael McClelland\My Documents\Downloaded Program Updates\Virus Killer\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2004-07-19 07:51]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"Steam"="C:\Program Files\Valve\Steam\\Steam.exe" [2007-06-28 18:51]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-10-11 22:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 09:15:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-08-05 16:10 9216 C:\WINDOWS\system32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
R1 AvgMfx86;AVG Minifilter x86 Resident Driver;C:\WINDOWS\system32\Drivers\avgmfx86.sys
R1 sscdbhk5;sscdbhk5;C:\WINDOWS\system32\drivers\sscdbhk5.sys
R1 ssrtln;ssrtln;C:\WINDOWS\system32\drivers\ssrtln.sys
R2 ASCTRM;ASCTRM;C:\WINDOWS\system32\drivers\ASCTRM.sys
R2 s24trans;WLAN Transport;C:\WINDOWS\system32\DRIVERS\s24trans.sys
R2 tfsnpool;tfsnpool;C:\WINDOWS\system32\dla\tfsnpool.sys
R3 HSFHWICH;HSFHWICH;C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
R3 IWCA;Intel Wireless Connection Agent Miniport for Win XP;C:\WINDOWS\system32\DRIVERS\iwca.sys
R3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys
R3 sffdisk;SFF Storage Class Driver;C:\WINDOWS\system32\DRIVERS\sffdisk.sys
R3 sffp_sd;SFF Storage Protocol Driver for SDBus;C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
R3 w29n51;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows XP;C:\WINDOWS\system32\DRIVERS\w29n51.sys
S3 CO_Mon;CO_Mon;\??\C:\WINDOWS\system32\Drivers\CO_Mon.sys
S3 E100B;Intel(R) PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys
S3 EraserUtilDrv10501;EraserUtilDrv10501;\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10501.sys
S3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
S3 wceusbsh;Windows CE USB Serial Host Driver;C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-07-19 12:22:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-07-27 19:00:14 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Michael McClelland.job - C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-07 19:04:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-07 19:09:44 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-07 19:09
--- E O F ---
Hijack Log
Logfile of HijackThis v1.99.1
Scan saved at 19:17:02, on 07/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Documents and Settings\Michael McClelland\My Documents\Downloaded Program Updates\Virus Killer\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe |