Okey Dokey!
I followed your directions and then tried the web searches. Both seemed to come up OK for a while, but after about the 4th search I started getting re-directs again. Both programs are indicating that the infected files will be deleted on reboot, but it doesn't seem to work.
Here are the scans from both Combofix and Malwarebytes:
Malwarebytes' Anti-Malware 1.33
Database version: 1717
Windows 5.1.2600 Service Pack 2
2/2/2009 8:18:13 PM
mbam-log-2009-02-02 (20-18-13).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|P:\|Q:\|)
Objects scanned: 136475
Time elapsed: 33 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{605bba4d-d3a0-4c21-9165-fba063eb5259} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{605bba4d-d3a0-4c21-9165-fba063eb5259} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{605bba4d-d3a0-4c21-9165-fba063eb5259} (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Delete on reboot.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\camoc.dll (Trojan.BHO.H) -> Delete on reboot.
ComboFix 09-02-02.04 - All 2009-02-02 18:03:00.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1486 [GMT -6:00]
Running from: c:\documents and settings\All\Desktop\ComboFix.exe
AV: Norton Internet Security 2006 *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.
2009-01-25 10:36 . 2009-01-25 10:36 <DIR> d-------- c:\documents and settings\All\Application Data\Endicia
2009-01-17 16:34 . 2009-01-17 16:35 1,374 --a------ c:\windows\imsins.BAK
2009-01-17 16:09 . 2008-10-24 05:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-01-17 15:17 . 2009-01-17 15:17 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-17 15:17 . 2009-01-17 15:17 <DIR> d-------- c:\documents and settings\All\Application Data\Malwarebytes
2009-01-17 15:17 . 2009-01-17 15:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-17 15:17 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-17 15:17 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-05 08:01 . 2006-03-15 06:00 95,744 --a------ c:\windows\system32\camoc.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-01 04:19 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-01 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-31 17:08 --------- d-----w c:\program files\PayWindow Payroll
2009-01-31 17:08 --------- d-----w c:\documents and settings\All\Application Data\paywin
2009-01-31 17:08 --------- d-----w c:\documents and settings\All\Application Data\GetRightToGo
2009-01-17 21:51 --------- d-----w c:\documents and settings\All\Application Data\AVG7
2009-01-17 21:51 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
2008-12-21 21:47 --------- d-----w c:\documents and settings\All\Application Data\LimeWire
2008-12-21 21:29 --------- d-----w c:\program files\LimeWire
2008-12-21 18:57 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2007-10-19 01:45 92,064 ----a-w c:\documents and settings\All\mqdmmdm.sys
2007-10-19 01:45 9,232 ----a-w c:\documents and settings\All\mqdmmdfl.sys
2007-10-19 01:45 79,328 ----a-w c:\documents and settings\All\mqdmserd.sys
2007-10-19 01:45 66,656 ----a-w c:\documents and settings\All\mqdmbus.sys
2007-10-19 01:45 6,208 ----a-w c:\documents and settings\All\mqdmcmnt.sys
2007-10-19 01:45 5,936 ----a-w c:\documents and settings\All\mqdmwhnt.sys
2007-10-19 01:45 4,048 ----a-w c:\documents and settings\All\mqdmcr.sys
2007-10-19 01:45 25,600 ----a-w c:\documents and settings\All\usbsermptxp.sys
2007-10-19 01:45 22,768 ----a-w c:\documents and settings\All\usbsermpt.sys
2006-11-20 00:20 156 ----a-w c:\documents and settings\All\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{605BBA4D-D3A0-4C21-9165-FBA063EB5259}]
2006-03-15 06:00 95744 --a------ c:\windows\system32\camoc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-03-15 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-27 69632]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-11 151552]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-19 28672]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2006-02-14 176128]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2006-08-05 217088]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-06 86016]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2005-12-04 437008]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 143360]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-04-07 122940]
"AppMon Utility"="c:\program files\Sony\AppMonUtil\AppMonUtility.exe" [2006-06-22 29696]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-17 118784]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"StxTrayMenu"="c:\program files\Seagate\SystemTray\StxMenuMgr.exe" [2007-01-18 190008]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-06 7561216]
c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-09-09 113664]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-09-09 113664]
c:\documents and settings\All\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-09-09 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-02-02 1753088]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-11-06 815104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-03-09 15:51 73728 c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=gufcse.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"msacm.ulmp3acm"= ulmp3acm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All^Start Menu^Programs^Startup^AutoBackup Launcher.lnk]
path=c:\documents and settings\All\Start Menu\Programs\Startup\AutoBackup Launcher.lnk
backup=c:\windows\pss\AutoBackup Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-08-05 14:56 64512 c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"AVGEMS"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2006\\QBDBMgrN.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\msncall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
R0 adkurxcg;adkurxcg;c:\windows\system32\drivers\adkurxcg.sys [2006-08-11 23424]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2006-09-06 5376]
R2 USBDLM;USBDLM;c:\usbdlm\USBDLM\USBDLM.exe [2007-09-20 124416]
R3 5U870CAP_VID_1262&PID_25FD;Sony Visual Communication Camera VGP-VCC2 ;c:\windows\system32\drivers\5U870CAP.sys [2006-08-11 75264]
R3 slim;Sony Lucid Integrated Mpeg encoder;c:\windows\system32\drivers\slim.sys [2006-08-11 698496]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2006-08-11 30080]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-08-11 226304]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96874ab9-eb70-11db-b81b-0013a9287fbf}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-01-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
2009-01-26 c:\windows\Tasks\EasyShare Registration Task.job
- c:\docume~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.4.20.2.sxt _RegistrationOffer@16 []
2009-01-26 c:\windows\Tasks\Sand County Logging, LLC 1196800739.job
- c:\program files\Intuit\QuickBooks 2006\AutoBackupEXE.exe [2007-11-06 17:26]
2009-01-26 c:\windows\Tasks\SyncBack My Documents Weekly Backup.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.sony.com/vaiopeople
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-02 18:05:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\VESWinlogon.dll
.
Completion time: 2009-02-02 18:06:21
ComboFix-quarantined-files.txt 2009-02-03 00:06:19
Pre-Run: 173,564,162,048 bytes free
Post-Run: 173,559,693,312 bytes free
163 --- E O F --- 2009-01-17 22:35:58