What I have done to try to self fix.
1. Ran Spybot S&D 1.5
2. Ran Ad Aware SE
3 Ran full scan CA Antivirus
4. Removed old version of Java 1.4.01. (has been removed but I have not installed jre-6u3 so machine has no Java Presently)
5. Ran VundoFix.exe
6. Ran Symantic Vundo Removal Tool
7. Ran Combofix
8. Cleared Prefetch
9. Cleared all temp files and index.dat files Under command prompt logon
10. When CA antivirus runs it says it finds no virus but during scan it pops up a window saying it found a virus and deleted it.
11. Machine installed BHO toolbar and tried to open several hundred IE windows before Java was removed
and machine would reinstall virus as DLL in system folder and fake security toolbar after each reboot even after running all scrubbrers listed above.
Please Help, Thank You Mark
Kaspersky log part 1
KASPERSKY ONLINE SCANNER REPORT
Tuesday, November 13, 2007 3:30:29 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 13/11/2007
Kaspersky Anti-Virus database records: 457645
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 318735
Number of viruses found: 52
Number of infected objects: 222
Number of suspicious objects: 3
Duration of the scan process: 04:19:50
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users.WINDOWS\Application Data\Bluebeam Software\Brewery\V45\Printer Support\BBPDFPortMon.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\004137f3b2973be2b4495f6ff0567162_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\06f4cc38239afc093815da46149d07ce_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\146278ce98c1b1ddb01bdbada8c10a22_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\1898c61ec6aaa1c2f261abf1cf4e44b2_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b540020b3f61a5b65c5df42aca8c18b_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\2fc76b2ad79960cdd75bedcdd2ccf647_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\3646238f14e4d61dc23d9f8813fda7b6_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\3dbe0df78e98f3f52cd824df41681bd4_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f6458d69e426858bfe62b1924936a55_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\4552b0b796d1ce07303a83ef677a53e5_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\4cb5957dc58b5adf41d9493b48a962df_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\50d176d9d4033ee17d653bc80e3d2c9d_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\55a6e0ef1e50535e94d1f04663d950f9_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\5673e956e59cbe8b28f5f15954dbb826_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\589f3d4c8ffd0c55c81f26ef49a2fe01_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\70d9fbb498cb9f52296ffec71bf2ebd2_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\74744b72cfb024cc479fa57a95f35a95_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\76587a117d78f98b3abc86fb2f40daf4_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d9ec97a8e0fb5e286c481a32ed7e563_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\850fa58e6cd36d27b9aa114b28d2e771_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bdcd7428d242fb2b7cda3bbccc53b84_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0dbb5fa5eef1231d4900cc9606a847d_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\a22cc4cf343408bea9d2353788cf92f5_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\a704651421013dbef3164244139fd1e8_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\a9182eccd56a22eeb9ab455eeb970310_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1c56d2e7402a8399dcbdefd1f8a737f_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0334d06422e8d22d2a643c417588d4a_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce44bcd38ba5dd53d6f6bb010a1ea9da_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf314ccadce1705effa18573528c69e5_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\d6633bf09e6b53fa817d94412db01c34_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\d90ef69710c83d86dadac446d9a22276_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\de7261215b5bbcd81bad7f7e41e0a83d_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\e22b800121a01b758bf6674f20665ab8_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\e5edc8f2f860a933858e6345f30141ad_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaf0d4f66ecef8b91d3b88dfe6624508_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\f35e29a41e7e67bfa6f1b978e9599044_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/cbxyyaw.dll Infected: Trojan-Downloader.Win32.Small.ddy skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Cain and Able Password Cracker\cain25b47.exe/WISE0018.BIN Infected: not-a-virus
SWTool.Win32.Cain.c skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Cain and Able Password Cracker\cain25b47.exe/WISE0023.BIN Infected: not-a-virus
SWTool.Win32.Cain.b skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Cain and Able Password Cracker\cain25b47.exe/WISE0025.BIN Infected: not-a-virus
SWTool.Win32.Cain.b skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Cain and Able Password Cracker\cain25b47.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\keyfinder.exe/data.rar Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\keyfinder.exe RarSFX: infected - 3 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip/keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip/keyfinder.exe/data.rar Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip/keyfinder.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip ZIP: infected - 4 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\Old\setupneonapster.exe/data0007 Infected: not-a-virus:AdWare.Win32.180Solutions.m skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\Old\setupneonapster.exe/data0008 Infected: not-a-virus:AdWare.Win32.EZula.d skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\Old\setupneonapster.exe Inno: infected - 2 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0006/UCMIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0006/IUCMORE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0006 Infected: not-a-virus:AdWare.Win32.Ucmore skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0007/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.v skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0007/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0007 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0008 Suspicious: not-a-virus:AdWare.Win32.GigatechSuperBar skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0009 Infected: not-a-virus:AdWare.Win32.180Solutions.m skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0010 Infected: not-a-virus:AdWare.Win32.EZula.d skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0011/data0115 Infected: not-a-virus:AdWare.Win32.TopMoxie.d skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0011 Infected: not-a-virus:AdWare.Win32.TopMoxie.d skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0012 Infected: not-a-virus:AdWare.Win32.IGetNet skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe Inno: infected - 11, suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\userco1\Application Data\CallingID\CallingID.ldb Object is locked skipped
C:\Documents and Settings\userco1\Application Data\CallingID\CallingID.mdb Object is locked skipped
C:\Documents and Settings\userco1\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\History\History.IE5\MSHist012007111320071114\index.dat Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Temp\JET196D.tmp Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Temp\~DF85D6.tmp Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Temp\~DFAD1C.tmp Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\userco1\ntuser.dat Object is locked skipped
C:\Documents and Settings\userco1\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\Cain\Cain.exe Infected: not-a-virus
SWTool.Win32.Cain.c skipped
C:\Program Files\Ektron\EktronWindowsService20\log\bdebd0a2-dcce-4b99-8f7a-1e972efd1970test.log Object is locked skipped
C:\Program Files\Ektron\EktronWindowsService20\log\test.log Object is locked skipped
C:\Program Files\GetPaid2Search Toolbar\getpaid2search.dll Infected: not-a-virus:AdWare.Win32.Mostofate.y skipped
C:\Program Files\GetPaid2Search Toolbar\tbhelper.dll Infected: not-a-virus:AdWare.Win32.Mostofate.y skipped
C:\Program Files\MzRam\Cpu_Power.exe Infected: Trojan.Win32.Small.sx skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\sysdl132.exe.vir Infected: Trojan-Downloader.Win32.BHO.bo skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\XunLeiBHO_001.dll.vir Infected: not-a-virus:AdWare.Win32.BHO.aj skipped
C:\qoobox\Quarantine\catchme2007-11-12_ 44104.09.zip/cbxyyaw.dll Infected: Trojan-Downloader.Win32.Small.ddy skipped
C:\qoobox\Quarantine\catchme2007-11-12_ 44104.09.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C5911632-D810-4F33-9A05-BBA1DCEB2216}\RP1\A0000008.dll Infected: not-a-virus:AdWare.Win32.BHO.aj skipped
C:\System Volume Information\_restore{C5911632-D810-4F33-9A05-BBA1DCEB2216}\RP1\A0000009.exe Infected: Trojan-Downloader.Win32.BHO.bo skipped
C:\System Volume Information\_restore{C5911632-D810-4F33-9A05-BBA1DCEB2216}\RP1\A0000018.dll Infected: Trojan-Downloader.Win32.Small.ddy skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{21E88291-564D-4738-B75A-45876A3F0B93}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\EktronL2.evt Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\jmlekmfc.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\trhwryqn.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\Temp\Perflib_Perfdata_614.dat Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_8d0.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
1. Ran Spybot S&D 1.5
2. Ran Ad Aware SE
3 Ran full scan CA Antivirus
4. Removed old version of Java 1.4.01. (has been removed but I have not installed jre-6u3 so machine has no Java Presently)
5. Ran VundoFix.exe
6. Ran Symantic Vundo Removal Tool
7. Ran Combofix
8. Cleared Prefetch
9. Cleared all temp files and index.dat files Under command prompt logon
10. When CA antivirus runs it says it finds no virus but during scan it pops up a window saying it found a virus and deleted it.
11. Machine installed BHO toolbar and tried to open several hundred IE windows before Java was removed
and machine would reinstall virus as DLL in system folder and fake security toolbar after each reboot even after running all scrubbrers listed above.
Please Help, Thank You Mark
Kaspersky log part 1
KASPERSKY ONLINE SCANNER REPORT
Tuesday, November 13, 2007 3:30:29 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 13/11/2007
Kaspersky Anti-Virus database records: 457645
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 318735
Number of viruses found: 52
Number of infected objects: 222
Number of suspicious objects: 3
Duration of the scan process: 04:19:50
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users.WINDOWS\Application Data\Bluebeam Software\Brewery\V45\Printer Support\BBPDFPortMon.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\004137f3b2973be2b4495f6ff0567162_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\06f4cc38239afc093815da46149d07ce_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\146278ce98c1b1ddb01bdbada8c10a22_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\1898c61ec6aaa1c2f261abf1cf4e44b2_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b540020b3f61a5b65c5df42aca8c18b_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\2fc76b2ad79960cdd75bedcdd2ccf647_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\3646238f14e4d61dc23d9f8813fda7b6_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\3dbe0df78e98f3f52cd824df41681bd4_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f6458d69e426858bfe62b1924936a55_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\4552b0b796d1ce07303a83ef677a53e5_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\4cb5957dc58b5adf41d9493b48a962df_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\50d176d9d4033ee17d653bc80e3d2c9d_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\55a6e0ef1e50535e94d1f04663d950f9_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\5673e956e59cbe8b28f5f15954dbb826_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\589f3d4c8ffd0c55c81f26ef49a2fe01_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\70d9fbb498cb9f52296ffec71bf2ebd2_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\74744b72cfb024cc479fa57a95f35a95_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\76587a117d78f98b3abc86fb2f40daf4_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d9ec97a8e0fb5e286c481a32ed7e563_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\850fa58e6cd36d27b9aa114b28d2e771_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bdcd7428d242fb2b7cda3bbccc53b84_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0dbb5fa5eef1231d4900cc9606a847d_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\a22cc4cf343408bea9d2353788cf92f5_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\a704651421013dbef3164244139fd1e8_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\a9182eccd56a22eeb9ab455eeb970310_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1c56d2e7402a8399dcbdefd1f8a737f_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0334d06422e8d22d2a643c417588d4a_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce44bcd38ba5dd53d6f6bb010a1ea9da_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf314ccadce1705effa18573528c69e5_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\d6633bf09e6b53fa817d94412db01c34_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\d90ef69710c83d86dadac446d9a22276_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\de7261215b5bbcd81bad7f7e41e0a83d_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\e22b800121a01b758bf6674f20665ab8_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\e5edc8f2f860a933858e6345f30141ad_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaf0d4f66ecef8b91d3b88dfe6624508_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\RSA\MachineKeys\f35e29a41e7e67bfa6f1b978e9599044_85affd7a-f0a7-43e4-9e2d-7c471ed64590 Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/cbxyyaw.dll Infected: Trojan-Downloader.Win32.Small.ddy skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Cain and Able Password Cracker\cain25b47.exe/WISE0018.BIN Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Cain and Able Password Cracker\cain25b47.exe/WISE0023.BIN Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Cain and Able Password Cracker\cain25b47.exe/WISE0025.BIN Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Cain and Able Password Cracker\cain25b47.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\keyfinder.exe/data.rar Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\keyfinder.exe RarSFX: infected - 3 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip/keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip/keyfinder.exe/data.rar Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip/keyfinder.exe Infected: not-a-virus
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Keyfinder\kf141.zip ZIP: infected - 4 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\Old\setupneonapster.exe/data0007 Infected: not-a-virus:AdWare.Win32.180Solutions.m skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\Old\setupneonapster.exe/data0008 Infected: not-a-virus:AdWare.Win32.EZula.d skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\Old\setupneonapster.exe Inno: infected - 2 skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0006/UCMIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0006/IUCMORE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0006 Infected: not-a-virus:AdWare.Win32.Ucmore skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0007/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.v skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0007/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0007 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0008 Suspicious: not-a-virus:AdWare.Win32.GigatechSuperBar skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0009 Infected: not-a-virus:AdWare.Win32.180Solutions.m skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0010 Infected: not-a-virus:AdWare.Win32.EZula.d skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0011/data0115 Infected: not-a-virus:AdWare.Win32.TopMoxie.d skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0011 Infected: not-a-virus:AdWare.Win32.TopMoxie.d skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe/data0012 Infected: not-a-virus:AdWare.Win32.IGetNet skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Utilities\Neo Napster 3.1\setupneonapster.exe Inno: infected - 11, suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\userco1\Application Data\CallingID\CallingID.ldb Object is locked skipped
C:\Documents and Settings\userco1\Application Data\CallingID\CallingID.mdb Object is locked skipped
C:\Documents and Settings\userco1\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\History\History.IE5\MSHist012007111320071114\index.dat Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Temp\JET196D.tmp Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Temp\~DF85D6.tmp Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Temp\~DFAD1C.tmp Object is locked skipped
C:\Documents and Settings\userco1\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\userco1\ntuser.dat Object is locked skipped
C:\Documents and Settings\userco1\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\Cain\Cain.exe Infected: not-a-virus
C:\Program Files\Ektron\EktronWindowsService20\log\bdebd0a2-dcce-4b99-8f7a-1e972efd1970test.log Object is locked skipped
C:\Program Files\Ektron\EktronWindowsService20\log\test.log Object is locked skipped
C:\Program Files\GetPaid2Search Toolbar\getpaid2search.dll Infected: not-a-virus:AdWare.Win32.Mostofate.y skipped
C:\Program Files\GetPaid2Search Toolbar\tbhelper.dll Infected: not-a-virus:AdWare.Win32.Mostofate.y skipped
C:\Program Files\MzRam\Cpu_Power.exe Infected: Trojan.Win32.Small.sx skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\sysdl132.exe.vir Infected: Trojan-Downloader.Win32.BHO.bo skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\XunLeiBHO_001.dll.vir Infected: not-a-virus:AdWare.Win32.BHO.aj skipped
C:\qoobox\Quarantine\catchme2007-11-12_ 44104.09.zip/cbxyyaw.dll Infected: Trojan-Downloader.Win32.Small.ddy skipped
C:\qoobox\Quarantine\catchme2007-11-12_ 44104.09.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C5911632-D810-4F33-9A05-BBA1DCEB2216}\RP1\A0000008.dll Infected: not-a-virus:AdWare.Win32.BHO.aj skipped
C:\System Volume Information\_restore{C5911632-D810-4F33-9A05-BBA1DCEB2216}\RP1\A0000009.exe Infected: Trojan-Downloader.Win32.BHO.bo skipped
C:\System Volume Information\_restore{C5911632-D810-4F33-9A05-BBA1DCEB2216}\RP1\A0000018.dll Infected: Trojan-Downloader.Win32.Small.ddy skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{21E88291-564D-4738-B75A-45876A3F0B93}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\EktronL2.evt Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\jmlekmfc.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\trhwryqn.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\Temp\Perflib_Perfdata_614.dat Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_8d0.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped