I don't get why none of the tools I've tried will fix it for good. I've been working on this for over a week... guess it's time I beg for help from the experts. I would appreciate any help you can offer. Thanks in advance
ComboFix 08-04-27.3 - fayshe 2008-05-01 11:32:04.4 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.17 [GMT -4:00]
Running from: C:\Documents and Settings\FAYSHE\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-01 to 2008-05-01 )))))))))))))))))))))))))))))))
.
2008-05-01 10:28 . 08-05-01 10:28 <DIR> d-------- C:\WINNT\system32\Kaspersky Lab
2008-05-01 10:28 . 08-05-01 10:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-28 15:20 . 08-04-28 15:20 <DIR> d-------- C:\Program Files\CCleaner
2008-04-24 09:34 . 08-04-24 09:34 <DIR> d-------- C:\VundoFix Backups
2008-04-21 14:47 . 08-04-21 14:47 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-21 14:47 . 08-04-21 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-21 14:46 . 08-04-21 14:46 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-21 14:35 . 08-04-21 15:36 67,645 --a------ C:\WINNT\system32\drivers\pshook11.sys
2008-04-21 14:32 . 08-04-21 15:42 <DIR> d-------- C:\Program Files\INAC
2008-04-16 14:40 . 03-06-19 12:05 21,552 --a--c--- C:\WINNT\system32\dllcache\usbstor.sys
2008-04-16 14:27 . 08-04-16 14:27 118 --a------ C:\WINNT\system32\MRT.INI
2008-04-16 14:23 . 08-04-16 14:23 <DIR> d-------- C:\WINNT\system32\Windows Media
2008-04-16 14:22 . 08-04-16 14:22 <DIR> d-------- C:\WINNT\msiinst.tmp
2008-04-16 14:22 . 08-04-16 14:23 <DIR> d--h-c--- C:\WINNT\$NtUpdateRollupPackUninstall$
2008-04-16 14:22 . 08-04-16 14:22 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-16 14:21 . 08-04-16 14:21 <DIR> d--h-c--- C:\WINNT\$SQLUninstallMDAC25SP3-KB927779-x86-ENU$
2008-04-16 14:19 . 08-04-16 14:19 <DIR> d-------- C:\WINNT\mui
2008-04-16 14:19 . 08-04-16 14:19 957 --a------ C:\WINNT\setup.inf
2008-04-16 14:19 . 08-04-16 14:19 283 --a------ C:\WINNT\setup.rpt
2008-04-16 14:14 . 02-08-29 07:14 44,032 -----c--- C:\WINNT\system32\dllcache\msxml3r.dll
2008-04-16 13:59 . 08-04-16 13:59 <DIR> d-------- C:\WINNT\system32\BITS
2008-04-16 12:10 . 08-04-16 12:10 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-16 12:10 . 08-04-16 12:13 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-16 12:04 . 08-04-16 12:05 <DIR> d--h----- C:\WINNT\msdownld.tmp
2008-04-16 12:02 . 07-07-30 19:19 549,720 --a------ C:\WINNT\system32\wuapi.dll
2008-04-16 12:02 . 07-07-30 19:19 325,976 --a------ C:\WINNT\system32\wucltui.dll
2008-04-16 12:02 . 07-07-30 19:19 43,352 --a------ C:\WINNT\system32\wups2.dll
2008-04-16 12:02 . 07-07-30 19:18 34,136 --a------ C:\WINNT\system32\wucltui.dll.mui
2008-04-16 12:02 . 07-07-30 19:18 33,624 --a------ C:\WINNT\system32\wups.dll
2008-04-16 12:02 . 07-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuaucpl.cpl.mui
2008-04-16 12:02 . 07-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuapi.dll.mui
2008-04-16 12:02 . 07-07-30 19:18 20,312 --a------ C:\WINNT\system32\wuaueng.dll.mui
2008-04-03 16:41 . 08-04-03 16:41 120,868 --a------ C:\WINNT\system32\MSForms.TWD
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 09:26 1,644,080 ----a-w C:\WINNT\system32\WIN32K.SYS
2008-02-19 17:08 236,304 ----a-w C:\WINNT\system32\GDI32.DLL
2008-02-15 15:17 575,488 ----a-w C:\WINNT\system32\WININET.DLL
2008-02-15 13:24 96,528 ----a-w C:\WINNT\system32\dnsrslvr.dll
2004-04-14 21:38 271 ---h--w C:\Program Files\desktop.ini
2004-04-14 21:38 21,952 ---h--w C:\Program Files\folder.htt
2003-07-14 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
((((((((((((((((((((((((((((( snapshot@Mon 2008-04-28_15.11.20.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-11 13:41:36 345,656 ----a-w C:\WINNT\Downloaded Program Files\ewidoOnlineScan.dll
- 2008-04-28 19:07:55 3,103 ----a-w C:\WINNT\system32\HPANT.DAT
+ 2008-05-01 15:34:21 3,103 ----a-w C:\WINNT\system32\HPANT.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 135,251 2003-09-18 08:01:00 C:\ePOAgent\bak\UpdaterUI.exe
----a-w 249,856 2003-10-02 08:44:32 C:\WINNT\system32\bak\keyhook.exe
----a-w 667,648 2003-10-02 08:45:16 C:\WINNT\system32\bak\sistray.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B534EF37-A8FF-4F82-887F-33CDC1D47110}]
08-04-16 10:46 315712 --a------ C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-07-14 08:00 111376 C:\WINNT\system32\mobsync.exe]
"SiS Windows KeyHook"="C:\WINNT\system32\keyhook.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [03-10-08 05:41 57344 C:\WINNT\SOUNDMAN.EXE]
"McAfeeUpdaterUI"="C:\ePOAgent\UpdaterUI.exe" [ ]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [04-09-22 08:00 98304]
"INACASAP"="C:\Program Files\INAC\Anti Spyware\inac2.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-07-14 08:00 186640]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-06 02:00:00 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-06 02:00:00 51984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
R1 SiSEsc;SISLIB_ESC;C:\WINNT\system32\sisesc.sys [03-08-18 01:21 ]
R3 EntDrv50;EntDrv50;C:\WINNT\system32\drivers\EntDrv50.sys [07-01-18 20:00 ]
R3 openhci;Microsoft USB Open Host Controller Driver;C:\WINNT\system32\DRIVERS\openhci.sys [03-07-14 08:00 ]
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 08:05 ]
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-01 11:44:16
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINNT\system32\Perflib_Perfdata_32c.dat 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AxPsHook11]
"ImagePath"="\??\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINNT\system32\lsass.exe
-> C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
PROCESS: C:\WINNT\explorer.exe
-> C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
.
Completion time: 2008-05-01 11:46:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-01 15:45:52
ComboFix2.txt 2008-04-29 14:23:09
ComboFix3.txt 2008-04-28 19:42:08
ComboFix4.txt 2008-04-28 19:12:01
Pre-Run: 37,621,755,904 bytes free
Post-Run: 37,616,291,840 bytes free
123
ComboFix 08-04-27.3 - fayshe 2008-05-01 11:32:04.4 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.17 [GMT -4:00]
Running from: C:\Documents and Settings\FAYSHE\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-01 to 2008-05-01 )))))))))))))))))))))))))))))))
.
2008-05-01 10:28 . 08-05-01 10:28 <DIR> d-------- C:\WINNT\system32\Kaspersky Lab
2008-05-01 10:28 . 08-05-01 10:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-28 15:20 . 08-04-28 15:20 <DIR> d-------- C:\Program Files\CCleaner
2008-04-24 09:34 . 08-04-24 09:34 <DIR> d-------- C:\VundoFix Backups
2008-04-21 14:47 . 08-04-21 14:47 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-21 14:47 . 08-04-21 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-21 14:46 . 08-04-21 14:46 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-21 14:35 . 08-04-21 15:36 67,645 --a------ C:\WINNT\system32\drivers\pshook11.sys
2008-04-21 14:32 . 08-04-21 15:42 <DIR> d-------- C:\Program Files\INAC
2008-04-16 14:40 . 03-06-19 12:05 21,552 --a--c--- C:\WINNT\system32\dllcache\usbstor.sys
2008-04-16 14:27 . 08-04-16 14:27 118 --a------ C:\WINNT\system32\MRT.INI
2008-04-16 14:23 . 08-04-16 14:23 <DIR> d-------- C:\WINNT\system32\Windows Media
2008-04-16 14:22 . 08-04-16 14:22 <DIR> d-------- C:\WINNT\msiinst.tmp
2008-04-16 14:22 . 08-04-16 14:23 <DIR> d--h-c--- C:\WINNT\$NtUpdateRollupPackUninstall$
2008-04-16 14:22 . 08-04-16 14:22 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-16 14:21 . 08-04-16 14:21 <DIR> d--h-c--- C:\WINNT\$SQLUninstallMDAC25SP3-KB927779-x86-ENU$
2008-04-16 14:19 . 08-04-16 14:19 <DIR> d-------- C:\WINNT\mui
2008-04-16 14:19 . 08-04-16 14:19 957 --a------ C:\WINNT\setup.inf
2008-04-16 14:19 . 08-04-16 14:19 283 --a------ C:\WINNT\setup.rpt
2008-04-16 14:14 . 02-08-29 07:14 44,032 -----c--- C:\WINNT\system32\dllcache\msxml3r.dll
2008-04-16 13:59 . 08-04-16 13:59 <DIR> d-------- C:\WINNT\system32\BITS
2008-04-16 12:10 . 08-04-16 12:10 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-16 12:10 . 08-04-16 12:13 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-16 12:04 . 08-04-16 12:05 <DIR> d--h----- C:\WINNT\msdownld.tmp
2008-04-16 12:02 . 07-07-30 19:19 549,720 --a------ C:\WINNT\system32\wuapi.dll
2008-04-16 12:02 . 07-07-30 19:19 325,976 --a------ C:\WINNT\system32\wucltui.dll
2008-04-16 12:02 . 07-07-30 19:19 43,352 --a------ C:\WINNT\system32\wups2.dll
2008-04-16 12:02 . 07-07-30 19:18 34,136 --a------ C:\WINNT\system32\wucltui.dll.mui
2008-04-16 12:02 . 07-07-30 19:18 33,624 --a------ C:\WINNT\system32\wups.dll
2008-04-16 12:02 . 07-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuaucpl.cpl.mui
2008-04-16 12:02 . 07-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuapi.dll.mui
2008-04-16 12:02 . 07-07-30 19:18 20,312 --a------ C:\WINNT\system32\wuaueng.dll.mui
2008-04-03 16:41 . 08-04-03 16:41 120,868 --a------ C:\WINNT\system32\MSForms.TWD
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 09:26 1,644,080 ----a-w C:\WINNT\system32\WIN32K.SYS
2008-02-19 17:08 236,304 ----a-w C:\WINNT\system32\GDI32.DLL
2008-02-15 15:17 575,488 ----a-w C:\WINNT\system32\WININET.DLL
2008-02-15 13:24 96,528 ----a-w C:\WINNT\system32\dnsrslvr.dll
2004-04-14 21:38 271 ---h--w C:\Program Files\desktop.ini
2004-04-14 21:38 21,952 ---h--w C:\Program Files\folder.htt
2003-07-14 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
((((((((((((((((((((((((((((( snapshot@Mon 2008-04-28_15.11.20.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-11 13:41:36 345,656 ----a-w C:\WINNT\Downloaded Program Files\ewidoOnlineScan.dll
- 2008-04-28 19:07:55 3,103 ----a-w C:\WINNT\system32\HPANT.DAT
+ 2008-05-01 15:34:21 3,103 ----a-w C:\WINNT\system32\HPANT.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 135,251 2003-09-18 08:01:00 C:\ePOAgent\bak\UpdaterUI.exe
----a-w 249,856 2003-10-02 08:44:32 C:\WINNT\system32\bak\keyhook.exe
----a-w 667,648 2003-10-02 08:45:16 C:\WINNT\system32\bak\sistray.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B534EF37-A8FF-4F82-887F-33CDC1D47110}]
08-04-16 10:46 315712 --a------ C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-07-14 08:00 111376 C:\WINNT\system32\mobsync.exe]
"SiS Windows KeyHook"="C:\WINNT\system32\keyhook.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [03-10-08 05:41 57344 C:\WINNT\SOUNDMAN.EXE]
"McAfeeUpdaterUI"="C:\ePOAgent\UpdaterUI.exe" [ ]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [04-09-22 08:00 98304]
"INACASAP"="C:\Program Files\INAC\Anti Spyware\inac2.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-07-14 08:00 186640]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-06 02:00:00 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-06 02:00:00 51984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
R1 SiSEsc;SISLIB_ESC;C:\WINNT\system32\sisesc.sys [03-08-18 01:21 ]
R3 EntDrv50;EntDrv50;C:\WINNT\system32\drivers\EntDrv50.sys [07-01-18 20:00 ]
R3 openhci;Microsoft USB Open Host Controller Driver;C:\WINNT\system32\DRIVERS\openhci.sys [03-07-14 08:00 ]
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 08:05 ]
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-01 11:44:16
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINNT\system32\Perflib_Perfdata_32c.dat 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AxPsHook11]
"ImagePath"="\??\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINNT\system32\lsass.exe
-> C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
PROCESS: C:\WINNT\explorer.exe
-> C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
.
Completion time: 2008-05-01 11:46:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-01 15:45:52
ComboFix2.txt 2008-04-29 14:23:09
ComboFix3.txt 2008-04-28 19:42:08
ComboFix4.txt 2008-04-28 19:12:01
Pre-Run: 37,621,755,904 bytes free
Post-Run: 37,616,291,840 bytes free
123