My AntirVir program keeps detecting the Vundo.Gen trojan and it will not go away. Here is my Hijackthis log followed by the combofix log.
Any help would be appreciated very much.
Thanks,
Carrie
Logfile of HijackThis v1.99.1
Scan saved at 6:11:49 PM, on 8/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\tbctray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Infinite Mind LC\eyeQ\ARLaunch.exe
C:\Program Files\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\System32\tbctray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: MiniEYE-MiniREAD Launch.lnk = C:\Program Files\Infinite Mind LC\eyeQ\ARLaunch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml:file://c:\\nores.mht!http://adxgate.net/zscript/pre.chm::/xpreload.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - mk:@MSITStore:C:\DOCUME~1\CARRIE~1\LOCALS~1\Temp\winfix.chm::/SystemDoctor2006FreeInstall.cab
O20 - AppInit_DLLs:
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: WUSB54GSv2SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54GSv2.exe (file missing)
ComboFix 07-06-13.7 - C:\Documents and Settings\Carrie\Desktop\ComboFix.exe
"Carrie" - 2007-08-11 18:16:32 - Service Pack 1 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\SYSTEM32\bccdd.bak1
C:\WINDOWS\SYSTEM32\bccdd.bak2
C:\WINDOWS\SYSTEM32\bccdd.ini
C:\WINDOWS\SYSTEM32\bccdd.ini2
C:\WINDOWS\SYSTEM32\bccdd.tmp
C:\WINDOWS\SYSTEM32\bccdd.bak1
C:\WINDOWS\SYSTEM32\bccdd.bak2
C:\WINDOWS\SYSTEM32\bccdd.ini
C:\WINDOWS\SYSTEM32\bccdd.ini2
C:\WINDOWS\SYSTEM32\bccdd.tmp
C:\WINDOWS\system32\ddccb.dll
C:\WINDOWS\system32\fcccbbc.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\CARRIE~1\APPLIC~1.\ystem3~1
C:\Program Files\Common Files\dobe~1
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CMDSERVICE
-------\LEGACY_CORE
-------\LEGACY_NETWORK_MONITOR
-------\cmdService
-------\core
((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))
2007-08-11 18:15 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-08-11 16:22 524,288 --ah----- C:\DOCUME~1\ADMINI~1.CAR\NTUSER.DAT
2007-08-11 16:22 <DIR> d-------- C:\DOCUME~1\ADMINI~1.CAR\APPLIC~1\Symantec
2007-08-11 14:52 <DIR> d-------- C:\WINDOWS\SYSTEM32\SoftwareDistribution
2007-08-11 14:49 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-08-11 14:48 549,720 --a------ C:\WINDOWS\SYSTEM32\wuapi.dll
2007-08-11 14:48 33,624 --a------ C:\WINDOWS\SYSTEM32\wups.dll
2007-08-11 14:48 325,976 --a------ C:\WINDOWS\SYSTEM32\wucltui.dll
2007-08-11 14:48 203,096 --a------ C:\WINDOWS\SYSTEM32\wuweb.dll
2007-08-11 14:48 186,136 --a------ C:\WINDOWS\SYSTEM32\wuaueng1.dll
2007-08-11 14:48 167,704 --a------ C:\WINDOWS\SYSTEM32\wuauclt1.exe
2007-08-11 14:09 <DIR> d-------- C:\WINDOWS\Prefetch
2007-08-11 13:50 9,728 --a------ C:\WINDOWS\SYSTEM32\mstinit.exe
2007-08-11 13:50 81,408 --a------ C:\WINDOWS\SYSTEM32\msoert2.dll
2007-08-11 13:50 73,728 --a------ C:\WINDOWS\SYSTEM32\ils.dll
2007-08-11 13:50 69,248 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sr.sys
2007-08-11 13:50 65,536 --a------ C:\WINDOWS\SYSTEM32\msconf.dll
2007-08-11 13:50 63,488 --a------ C:\WINDOWS\SYSTEM32\srclient.dll
2007-08-11 13:50 587,776 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2007-08-11 13:50 32,256 --a------ C:\WINDOWS\SYSTEM32\mnmdd.dll
2007-08-11 13:50 250,368 --a------ C:\WINDOWS\SYSTEM32\mstask.dll
2007-08-11 13:50 24,576 --a------ C:\WINDOWS\SYSTEM32\nmmkcert.dll
2007-08-11 13:50 228,864 --a------ C:\WINDOWS\SYSTEM32\msoeacct.dll
2007-08-11 13:50 226,304 --a------ C:\WINDOWS\SYSTEM32\srrstr.dll
2007-08-11 13:50 221,696 --a------ C:\WINDOWS\SYSTEM32\qmgr.dll
2007-08-11 13:50 17,408 --a------ C:\WINDOWS\SYSTEM32\qmgrprxy.dll
2007-08-11 13:50 159,232 --a------ C:\WINDOWS\SYSTEM32\schedsvc.dll
2007-08-11 13:50 158,720 --a------ C:\WINDOWS\SYSTEM32\srsvc.dll
2007-08-11 13:48 98,816 --a------ C:\WINDOWS\SYSTEM32\clipbrd.exe
2007-08-11 13:48 9,216 --a------ C:\WINDOWS\SYSTEM32\wuauserv.dll
2007-08-11 13:48 9,216 --a------ C:\WINDOWS\SYSTEM32\icaapi.dll
2007-08-11 13:48 88,064 --a------ C:\WINDOWS\SYSTEM32\tscfgwmi.dll
2007-08-11 13:48 75,912 --a------ C:\WINDOWS\SYSTEM32\rdpwsx.dll
2007-08-11 13:48 598,016 --a------ C:\WINDOWS\SYSTEM32\mstscax.dll
2007-08-11 13:48 582,656 --a------ C:\WINDOWS\SYSTEM32\catsrvut.dll
2007-08-11 13:48 57,856 --a------ C:\WINDOWS\SYSTEM32\licwmi.dll
2007-08-11 13:48 56,320 --a------ C:\WINDOWS\SYSTEM32\remotepg.dll
2007-08-11 13:48 534,016 --a------ C:\WINDOWS\SYSTEM32\spider.exe
2007-08-11 13:48 53,080 --a------ C:\WINDOWS\SYSTEM32\wuauclt.exe
2007-08-11 13:48 44,032 --a------ C:\WINDOWS\SYSTEM32\rdpclip.exe
2007-08-11 13:48 40,960 --a------ C:\WINDOWS\SYSTEM32\tscupgrd.exe
2007-08-11 13:48 388,608 --a------ C:\WINDOWS\SYSTEM32\mstsc.exe
2007-08-11 13:48 359,936 --a------ C:\WINDOWS\SYSTEM32\msdtcprx.dll
2007-08-11 13:48 339,968 --a------ C:\WINDOWS\SYSTEM32\mspaint.exe
2007-08-11 13:48 32,768 --a------ C:\WINDOWS\SYSTEM32\cfgbkend.dll
2007-08-11 13:48 200,192 --a------ C:\WINDOWS\SYSTEM32\termsrv.dll
2007-08-11 13:48 182,400 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rdpdr.sys
2007-08-11 13:48 14,848 --a------ C:\WINDOWS\SYSTEM32\rdpsnd.dll
2007-08-11 13:48 135,680 --a------ C:\WINDOWS\SYSTEM32\rdchost.dll
2007-08-11 13:48 129,024 --a------ C:\WINDOWS\SYSTEM32\sessmgr.exe
2007-08-11 13:48 12,288 --a------ C:\WINDOWS\SYSTEM32\rdsaddin.exe
2007-08-11 13:48 116,736 --a------ C:\WINDOWS\SYSTEM32\mplay32.exe
2007-08-11 13:48 115,976 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rdpwd.sys
2007-08-11 13:48 1,710,936 --a------ C:\WINDOWS\SYSTEM32\wuaueng.dll
2007-08-11 13:48 1,172,992 --a------ C:\WINDOWS\SYSTEM32\comsvcs.dll
2007-08-11 13:47 5,888 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\splitter.sys
2007-08-11 13:47 24,960 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbprint.sys
2007-08-11 13:46 56,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\redbook.sys
2007-08-11 13:46 14,208 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbscan.sys
2007-08-11 13:45 4,096 --a------ C:\WINDOWS\SYSTEM32\ksuser.dll
2007-08-11 13:44 38,024 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\termdd.sys
2007-08-11 13:40 71,168 --a------ C:\WINDOWS\SYSTEM32\storprop.dll
2007-08-11 13:40 24,661 --a------ C:\WINDOWS\SYSTEM32\spxcoins.dll
2007-08-11 13:40 13,312 --a------ C:\WINDOWS\SYSTEM32\irclass.dll
2007-08-11 13:31 <DIR> d-------- C:\$WIN_NT$.~BT
2007-08-11 12:20 651,264 --a------ C:\WINDOWS\SYSTEM32\libeay32.dll
2007-08-11 12:20 17,801 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys
2007-08-11 12:20 147,456 --a------ C:\WINDOWS\SYSTEM32\ssleay32.dll
2007-08-11 12:20 1,396,831 --a------ C:\WINDOWS\SYSTEM32\AegisE5.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-11 20:59:05 -------- d-----w C:\Program Files\Common Files\owwz
2007-08-11 20:59:00 -------- d-----w C:\Program Files\SymNetDrv
2007-08-11 20:58:56 -------- d-----w C:\Program Files\iTunes
2007-08-11 20:58:48 -------- d-----w C:\Program Files\QuickTime
2007-08-11 20:09:35 354 --sha-w C:\WINDOWS\system32\bjknghkl.ini2
2007-08-11 19:49:40 -------- d--h--w C:\Program Files\WindowsUpdate
2007-08-11 18:50:36 -------- d-----w C:\Program Files\Movie Maker
2007-08-11 18:49:30 22,736 ----a-w C:\WINDOWS\system32\emptyregdb.dat
2007-08-11 18:48:53 -------- d-----w C:\Program Files\Online Services
2007-08-11 18:48:46 -------- d-----w C:\Program Files\Messenger
2007-08-11 17:30:17 -------- d-----w C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor
2007-06-21 01:00:54 -------- d-----w C:\Program Files\Norton AntiVirus
2007-06-21 01:00:54 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2005-07-29 21:24:26 472 --sha-r C:\WINDOWS\Q2FycmllIEZhbGtl\kZIVwA55KHt1v3Q5.vbs
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 23:08]
{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}=C:\Program Files\Microsoft Money\System\mnyviewer.dll [2001-07-25 10:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" []
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2002-08-15 09:15]
"NvCplDaemon"="NvQTwk" []
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-20 15:08]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [2001-07-25 10:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
Contents of the 'Scheduled Tasks' folder
2007-08-11 19:09:36 C:\WINDOWS\tasks\At1.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At10.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At11.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At12.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At13.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At14.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At15.job
2007-08-11 20:00:01 C:\WINDOWS\tasks\At16.job
2007-08-11 21:00:00 C:\WINDOWS\tasks\At17.job
2007-08-11 22:00:01 C:\WINDOWS\tasks\At18.job
2007-08-11 23:00:00 C:\WINDOWS\tasks\At19.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At2.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At20.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At21.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At22.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At23.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At24.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At3.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At4.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At5.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At6.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At7.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At8.job
2007-08-11 19:09:36 C:\WINDOWS\tasks\At9.job
2002-09-16 01:26:22 C:\WINDOWS\tasks\Symantec NetDetect.job
2007-05-26 02:26:43 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-05-26 02:26:38 C:\WINDOWS\tasks\Uniblue SpyEraser.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 18:24:06
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-11 18:26:07 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-11 18:26
--- E O F ---

