the vundo keeps coming back.
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 12/22/2007 at 07:42 PM
Application Version : 3.9.1008
Core Rules Database Version : 3363
Trace Rules Database Version: 1362
Scan type : Complete Scan
Total Scan Time : 00:28:16
Memory items scanned : 186
Memory threats detected : 0
Registry items scanned : 6612
Registry threats detected : 4
File items scanned : 35634
File threats detected : 48
Adware.Vundo-Variant/B
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F29F4B6-5434-44A5-A379-8DBEA4B179C2}
HKCR\CLSID\{2F29F4B6-5434-44A5-A379-8DBEA4B179C2}
HKCR\CLSID\{2F29F4B6-5434-44A5-A379-8DBEA4B179C2}\InprocServer32
HKCR\CLSID\{2F29F4B6-5434-44A5-A379-8DBEA4B179C2}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\CRYPT3.DLL
Adware.Tracking Cookie
C:\Documents and Settings\Jon\Cookies\jon@statse.webtrendslive[2].txt
C:\Documents and Settings\Jon\Cookies\jon@www.burstnet[1].txt
C:\Documents and Settings\Jon\Cookies\jon@richmedia.yahoo[2].txt
C:\Documents and Settings\Jon\Cookies\jon@atdmt[2].txt
C:\Documents and Settings\Jon\Cookies\jon@cbcnewmedia.112.2o7[1].txt
C:\Documents and Settings\Jon\Cookies\jon@adopt.specificclick[1].txt
C:\Documents and Settings\Jon\Cookies\jon@doubleclick[1].txt
C:\Documents and Settings\Jon\Cookies\jon@tribalfusion[1].txt
C:\Documents and Settings\Jon\Cookies\jon@tacoda[1].txt
C:\Documents and Settings\Jon\Cookies\jon@ad.yieldmanager[1].txt
C:\Documents and Settings\Jon\Cookies\jon@mediaplex[2].txt
C:\Documents and Settings\Jon\Cookies\jon@ads.revsci[1].txt
C:\Documents and Settings\Jon\Cookies\jon@xiti[1].txt
C:\Documents and Settings\Jon\Cookies\jon@specificclick[2].txt
C:\Documents and Settings\Jon\Cookies\jon@questionmarket[2].txt
C:\Documents and Settings\Jon\Cookies\jon@casalemedia[2].txt
C:\Documents and Settings\Jon\Cookies\jon@buycom.122.2o7[1].txt
C:\Documents and Settings\Jon\Cookies\jon@adinterax[1].txt
C:\Documents and Settings\Jon\Cookies\jon@bluestreak[1].txt
C:\Documents and Settings\Jon\Cookies\jon@media.adrevolver[3].txt
C:\Documents and Settings\Jon\Cookies\jon@www.burstbeacon[1].txt
C:\Documents and Settings\Jon\Cookies\jon@2o7[2].txt
C:\Documents and Settings\Jon\Cookies\jon@adrevolver[1].txt
C:\Documents and Settings\Jon\Cookies\jon@eb.adbureau[2].txt
C:\Documents and Settings\Jon\Cookies\jon@edge.ru4[1].txt
C:\Documents and Settings\Jon\Cookies\jon@traffic.buyservices[1].txt
C:\Documents and Settings\Jon\Cookies\jon@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Jon\Cookies\jon@counter.surfcounters[1].txt
C:\Documents and Settings\Jon\Cookies\jon@ads.bridgetrack[1].txt
C:\Documents and Settings\Jon\Cookies\jon@realmedia[2].txt
C:\Documents and Settings\Jon\Cookies\jon@pro-market[2].txt
C:\Documents and Settings\Jon\Cookies\jon@media.adrevolver[2].txt
C:\Documents and Settings\Jon\Cookies\jon@zedo[2].txt
C:\Documents and Settings\Jon\Cookies\jon@anad.tacoda[1].txt
C:\Documents and Settings\Jon\Cookies\jon@partner2profit[1].txt
C:\Documents and Settings\Jon\Cookies\jon@interclick[2].txt
C:\Documents and Settings\Jon\Cookies\jon@revsci[1].txt
C:\Documents and Settings\Jon\Cookies\jon@burstnet[2].txt
C:\Documents and Settings\Jon\Cookies\jon@adopt.euroclick[2].txt
C:\Documents and Settings\Jon\Cookies\jon@advertising[1].txt
C:\Documents and Settings\Jon\Cookies\jon@serving-sys[2].txt
C:\Documents and Settings\Jon\Cookies\jon@trafficmp[1].txt
C:\Documents and Settings\Jon\Cookies\jon@eas.apm.emediate[1].txt
C:\Documents and Settings\Jon\Cookies\jon@fastclick[2].txt
C:\Documents and Settings\Jon\Cookies\jon@ads.pointroll[2].txt
C:\Documents and Settings\Jon\Cookies\jon@bs.serving-sys[1].txt
C:\Documents and Settings\Jon\Cookies\jon@server.iad.liveperson[1].txt
here is hijack this after the virus scan:
Logfile of HijackThis v1.99.1
Scan saved at 8:02:48 PM, on 12/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
f:\Program Files\a-squared Anti-Malware\a2service.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
J:\TRENDM~3\PcCtlCom.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
J:\TRENDM~3\Tmntsrv.exe
J:\TRENDM~3\TmPfw.exe
J:\TRENDM~3\tmproxy.exe
F:\Program Files\Hewlett-Packard\HP OfficeJet Series 500\bin\ktchnsnk.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
J:\trend micro\pccguide.exe
D:\Utopia\Angel\Angel.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Internet Explorer\iexplore.exe
J:\TRENDM~3\PcScnSrv.exe
C:\WINDOWS\System32\svchost.exe
F:\WINZIP\winzip32.exe
C:\Documents and Settings\Jon\Local Settings\Temp\wz437f\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F29F4B6-5434-44A5-A379-8DBEA4B179C2} - C:\WINDOWS\system32\crypt3.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon
O4 - HKLM\..\Run: [HP OfficeJet Series 500] "f:\Program Files\Hewlett-Packard\HP OfficeJet Series 500\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 500\Install"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [pccguide.exe] "J:\trend micro\pccguide.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Utopia Angel] "D:\Utopia\Angel\Angel.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Timex Data Link USB Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1189200242343O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1189200229171O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{3C09C8CD-35C7-4B74-90A5-D0F64F4992CF}: NameServer = 4.2.2.2,4.2.2.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{3C09C8CD-35C7-4B74-90A5-D0F64F4992CF}: NameServer = 4.2.2.2,4.2.2.1
O17 - HKLM\System\CS3\Services\Tcpip\..\{3C09C8CD-35C7-4B74-90A5-D0F64F4992CF}: NameServer = 4.2.2.2,4.2.2.1
O20 - Winlogon Notify: !SASWinLogon - F:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winjrs32 - winjrs32.dll (file missing)
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - f:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - J:\TRENDM~3\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - J:\TRENDM~3\PcScnSrv.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - (no file)
O23 - Service: RoxUpnpRenderer - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - J:\TRENDM~3\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - J:\TRENDM~3\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - J:\TRENDM~3\tmproxy.exe