I'm really stuck here, starting yesterday I just started getting bombarded by malware. I've done alot of reading and downloading various antivirus apps but nothing is working, it's just getting worse. TR/vundo.gen is the most popular virus showing up in my AV, but it's getting to the point where it just shuts down now from all the bombardment. Here are my hijackthis log and my combofix log that I tried. Any help is much appreciated.
** Edit** I dunno if it matters but I ran vundofix 7.0.6 and it found nothing, yet my AV finds up to 50 vundo.gens on a scan. **Edit**
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:03, on 6/29/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
D:\Program Files\iolo\System Mechanic 7\SMSystemAnalyzer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarerefer...=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearc...ce.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\ntos.exe,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: gxvpsafm - {63733480-2CC8-4334-8627-35651AAF74F4} - C:\DOCUME~1\Marley\LOCALS~1\Temp\ac8zt2\gxvpsafm.dll (file missing)
O4 - HKLM\..\Run: [SMSystemAnalyzer] "d:\Program Files\iolo\System Mechanic 7\SMSystemAnalyzer.exe"
O4 - HKLM\..\Run: [70372535] rundll32.exe "C:\WINDOWS\System32\xjsuramx.dll",b
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [BM730416a9] Rundll32.exe "C:\WINDOWS\System32\djgnwosj.dll",s
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [msvecurity] C:\WINDOWS\msvecurity.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O21 - SSODL: pntqkflv - {02F5B585-193C-49E0-A11B-D19F6ED8DB13} - C:\WINDOWS\pntqkflv.dll
O21 - SSODL: qegbdmwf - {D5616AEF-47A0-48E5-975C-DDB64E15A06B} - C:\WINDOWS\qegbdmwf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 5351 bytes
ComboFix 08-06-20.4 - Marley 2008-06-29 16:34:18.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.771 [GMT -4:00]
Running from: C:\Documents and Settings\Marley\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM730416a9.xml
C:\WINDOWS\efks.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\BJPoYGgh.ini
C:\WINDOWS\system32\BJPoYGgh.ini2
C:\WINDOWS\system32\ekfaivpu.ini
C:\WINDOWS\system32\giRYcfii.ini
C:\WINDOWS\system32\giRYcfii.ini2
C:\WINDOWS\system32\hgGYoPJB.dll
C:\WINDOWS\system32\lkQqqtwa.ini
C:\WINDOWS\system32\lkQqqtwa.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\qriraivu.ini
C:\WINDOWS\system32\rgjgvuda.ini
C:\WINDOWS\system32\vksawyuq.ini
C:\WINDOWS\system32\wsnpoem\audio.dll . . . . failed to delete
C:\WINDOWS\system32\wsnpoem\video.dll . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-29 )))))))))))))))))))))))))))))))
.
2008-06-29 11:43 . 2008-06-29 11:43 <DIR> d-------- C:\Program Files\Avira
2008-06-29 11:43 . 2008-06-29 11:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-06-29 11:39 . 2008-06-29 12:16 <DIR> d-------- C:\Documents and Settings\TEMP.COZ
2008-06-28 21:28 . 2008-06-28 21:28 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-28 19:16 . 2008-06-21 11:35 3,262 --a------ C:\WINDOWS\system32\sex2.ico
2008-06-28 19:14 . 2008-06-28 19:14 <DIR> d-------- C:\WINDOWS\Torrents
2008-06-28 19:14 . 2008-06-28 19:14 28,288 --a------ C:\WINDOWS\system32\khfFXopm.dll
2008-06-28 19:14 . 2008-06-28 19:14 28,288 --a------ C:\WINDOWS\system32\byXQHwWN.dll
2008-06-28 19:13 . 2008-06-29 13:00 <DIR> d-------- C:\WINDOWS\system32\788877
2008-06-28 19:13 . 2008-06-29 12:36 36,757 --a------ C:\WINDOWS\msvecurity.config
2008-06-28 19:12 . 2008-06-29 12:37 <DIR> d-------- C:\Program Files\VAV
2008-06-28 19:12 . 2008-06-28 10:11 409,600 --a------ C:\WINDOWS\gfetqaxsbfk.dll
2008-06-28 19:12 . 2008-06-28 10:11 253,952 --a------ C:\WINDOWS\pntqkflv.dll
2008-06-28 19:12 . 2008-06-28 10:11 225,280 --a------ C:\WINDOWS\qegbdmwf.dll
2008-06-28 19:12 . 2008-06-28 10:11 155,648 --a------ C:\WINDOWS\gxvpsafm.dll
2008-06-28 19:12 . 2008-06-19 18:20 117,248 --a------ C:\WINDOWS\system32\vav.cpl
2008-06-28 19:12 . 2008-06-28 10:11 81,920 --a------ C:\WINDOWS\tovafrnm.exe
2008-06-28 19:12 . 2008-06-21 11:35 3,262 --a------ C:\WINDOWS\system32\sex1.ico
2008-06-28 19:11 . 2008-06-29 12:49 <DIR> d-------- C:\Program Files\PCHealthCenter
2008-06-28 19:10 . 2008-06-28 19:10 34,304 --------- C:\WINDOWS\system32\opnMfCsS.dll
2008-06-21 08:49 . 2008-06-21 08:49 <DIR> d-------- C:\Documents and Settings\Marley\Application Data\NCH Swift Sound
2008-06-16 20:32 . 2008-06-16 20:35 <DIR> d-------- C:\Program Files\PartyGaming
2008-06-16 20:12 . 2008-06-16 21:00 <DIR> d-------- C:\Program Files\PokerStars.NET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-29 18:42 --------- d-----w C:\Documents and Settings\Marley\Application Data\DNA
2008-06-29 00:56 --------- d-----w C:\Program Files\DNA
2008-06-28 23:12 --------- d-----w C:\Documents and Settings\Marley\Application Data\BitTorrent
2008-06-28 23:11 --------- d-----w C:\Program Files\BitTorrent
2008-06-24 14:06 --------- d-----w C:\Program Files\Soulseek
2008-05-19 17:14 --------- d-----w C:\Documents and Settings\Timmy\Application Data\BitTorrent
2008-05-13 16:28 --------- d-----w C:\Documents and Settings\Marley\Application Data\ICAClient
2008-05-13 16:25 --------- d-----w C:\Program Files\Citrix
2008-05-05 14:44 --------- d-----w C:\Documents and Settings\Marley\Application Data\Command & Conquer 3 Tiberium Wars
2008-05-04 21:36 --------- d-----w C:\Documents and Settings\Timmy\Application Data\iolo
2008-05-03 20:56 --------- d-----w C:\Documents and Settings\Marley\Application Data\iolo
2008-05-03 20:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\iolo
2008-05-03 20:24 --------- d-----w C:\Program Files\iolo
2008-05-03 20:24 --------- d-----w C:\Documents and Settings\LocalService\Application Data\iolo
2008-05-03 17:03 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-05-03 17:03 --------- d-----w C:\Documents and Settings\Marley\Application Data\SystemRequirementsLab
2008-05-03 14:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-02 23:33 --------- d-----w C:\Program Files\Alcohol Soft
2008-05-02 23:29 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-05-01 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ubisoft
2007-12-26 06:00 15,872 --sha-w C:\Program Files\Thumbs.db
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05d1b4b6-0f9b-468b-869e-4195bf79fd7a}]
C:\WINDOWS\System32\uiacvk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E64E841-2463-47C9-8797-DAF2810BBF61}]
2008-06-28 19:10 34304 --------- C:\WINDOWS\System32\opnMfCsS.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bdf21582-f109-4bab-a660-437476cf0d2a}]
2008-06-28 10:11 409600 --a------ C:\WINDOWS\gfetqaxsbfk.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{63733480-2CC8-4334-8627-35651AAF74F4}"= "C:\DOCUME~1\Marley\LOCALS~1\Temp\ac8zt2\gxvpsafm.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{63733480-2cc8-4334-8627-35651aaf74f4}]
[HKEY_CLASSES_ROOT\gxvpsafm.1]
[HKEY_CLASSES_ROOT\TypeLib\{FCEC91BA-D0AA-4C87-AC80-45891152C8BD}]
[HKEY_CLASSES_ROOT\gxvpsafm]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-07 22:06 289088]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 12:46 217544]
"msvecurity"="C:\WINDOWS\msvecurity.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSystemAnalyzer"="d:\Program Files\iolo\System Mechanic 7\SMSystemAnalyzer.exe" [2008-03-31 15:09 725352]
"70372535"="C:\WINDOWS\System32\upviafke.dll" [ ]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"BM730416a9"="C:\WINDOWS\System32\tpqlcmrl.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-04-12 20:48:54 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{0E64E841-2463-47C9-8797-DAF2810BBF61}"= C:\WINDOWS\System32\opnMfCsS.dll [2008-06-28 19:10 34304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pntqkflv"= {02F5B585-193C-49E0-A11B-D19F6ED8DB13} - C:\WINDOWS\pntqkflv.dll [2008-06-28 10:11 253952]
"qegbdmwf"= {D5616AEF-47A0-48E5-975C-DDB64E15A06B} - C:\WINDOWS\qegbdmwf.dll [2008-06-28 10:11 225280]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,C:\\WINDOWS\\System32\\ntos.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnMfCsS]
opnMfCsS.dll 2008-06-28 19:10 34304 C:\WINDOWS\system32\opnMfCsS.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wingzy32]
wingzy32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MI-SC4"= MI-SC4.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\DRIVERS\avgntmgr.sys [2008-01-21 18:11]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2008-01-21 18:12]
R2 ioloFileInfoList;iolo FileInfoList Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-03-31 14:46]
R2 ioloSystemService;iolo System Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-03-31 14:46]
S1 404e0770;404e0770;C:\WINDOWS\System32\drivers\404e0770.sys []
S3 dwusbdnt;dwusbdnt;C:\WINDOWS\System32\DRIVERS\dwusbdnt.sys [2002-05-24 11:52]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-29 16:43:44
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\ntos.exe 466432 bytes executable
C:\WINDOWS\system32\wsnpoem
scan completed successfully
hidden files: 2
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\opnMfCsS.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
.
**************************************************************************
.
Completion time: 2008-06-29 16:48:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-29 20:48:17
Pre-Run: 1,761,824,768 bytes free
Post-Run: 2,151,641,088 bytes free
164
Thanks for any help.
Edited by th3coz, 29 June 2008 - 06:48 PM.