I have been infected with several different things over the last two days. The alarm on Avast has been alerting me to the problems. I have moved all of the files into the virus chest.
I am still attempting on my own to rid my machine of what appears to be the last two nasty things Win32: Cutwail [trj](this one is hiding on c:windows\system 32\driver and about 10 different files and Win32: rootkit-gen which was found in a bunch of temp files. I have run a Spybot scan (nothing) and a Superantispyware scan. The following is the log of that scan:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/04/2009 at 05:15 PM
Application Version : 4.26.1000
Core Rules Database Version : 3829
Trace Rules Database Version: 1785
Scan type : Complete Scan
Total Scan Time : 02:29:23
Memory items scanned : 616
Memory threats detected : 0
Registry items scanned : 5811
Registry threats detected : 0
File items scanned : 21499
File threats detected : 0
Then I extracted one example of each and sent them to virustotal.com . The win 32:cutwail file came back as no bytes had been sent. The win 32:rootkit-gen file came back with the following report:
File BN1D.tmp received on 04.04.2009 23:47:42 (CET)
Current status: finished
Result: 11/40 (27.50%)
Compact Compact
Print results Print results
Antivirus Version Last Update Result ???
a-squared 4.0.0.101 2009.04.04 -
AhnLab-V3 5.0.0.2 2009.04.04 Dropper/Rootkit.32288
AntiVir 7.9.0.129 2009.04.03 TR/Drop.Agent.qkm
Antiy-AVL 2.0.3.1 2009.04.04 -
Authentium 5.1.2.4 2009.04.04 -
Avast 4.8.1335.0 2009.04.04 Win32:Rootkit-gen
AVG 8.5.0.285 2009.04.04 Small.BHE
BitDefender 7.2 2009.04.04 -
CAT-QuickHeal 10.00 2009.04.04 -
ClamAV 0.94.1 2009.04.04 -
Comodo 1099 2009.04.04 -
DrWeb 4.44.0.09170 2009.04.04 -
eSafe 7.0.17.0 2009.04.02 -
eTrust-Vet 31.6.6435 2009.04.03 -
F-Prot 4.4.4.56 2009.04.03 -
F-Secure 8.0.14470.0 2009.04.04 Trojan-Dropper.Win32.Agent.alhs
Fortinet 3.117.0.0 2009.04.04 -
GData 19 2009.04.04 Win32:Rootkit-gen
Ikarus T3.1.1.49.0 2009.04.04 -
K7AntiVirus 7.10.692 2009.04.03 -
Kaspersky 7.0.0.125 2009.04.04 Trojan-Dropper.Win32.Agent.alhs
McAfee 5574 2009.04.04 -
McAfee+Artemis 5574 2009.04.04 -
McAfee-GW-Edition 6.7.6 2009.04.03 Trojan.Drop.Agent.qkm
Microsoft 1.4502 2009.04.04 -
NOD32 3988 2009.04.04 Win32/Wigon
Norman 6.00.06 2009.04.03 -
nProtect 2009.1.8.0 2009.04.04 -
Panda 10.0.0.14 2009.04.04 -
PCTools 4.4.2.0 2009.04.04 -
Prevx1 V2 2009.04.04 High Risk Cloaked Malware
Rising 21.23.41.00 2009.04.03 -
Sophos 4.40.0 2009.04.04 -
Sunbelt 3.2.1858.2 2009.04.04 -
Symantec 1.4.4.12 2009.04.04 -
TheHacker 6.3.4.0.302 2009.04.04 -
TrendMicro 8.700.0.1004 2009.04.03 -
VBA32 3.12.10.2 2009.04.03 Trojan-Dropper.Win32.Agent.alhh
ViRobot 2009.4.4.1678 2009.04.04 -
VirusBuster 4.6.5.0 2009.04.04 -
Additional information
File size: 32288 bytes
MD5…: 3a15a0c028906de6fbf3e3af0dfa2ee8
SHA1…: 24c9cfa21b5cccface91a954b15e40eae913a016
SHA256: dd78c993eec332a3c7f128b6289b848c64956e0a2a91d18f997631fe9bbe22e5
SHA512: 3891173d1f643bc7e0eef86769212c585a25be1b13ac75751770983bbb1f09b7
a8c5d4e55e3c8d39ae018f0cb320e0a9d97e8e371ea06fb05c0ad47297d05b69
ssdeep: 768:HdaducpaiP/cIniDowDSIll8NFFuIZsf8pQG0RpWYmRfPy:H4ucp//clDo+Z
IFFuIZs9RoYi6
PEiD…: -
TrID…: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
VXD Driver (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x13cf
timedatestamp…: 0x49d20972 (Tue Mar 31 12:15:46 2009)
machinetype…: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x91c 0x920 6.51 fdb8f122796434d6b26128f17fe1c015
.data 0x2000 0x436 0x438 4.86 fade022292b13c278bb5aaee6ffd33bf
.rsrc 0x3000 0x6c20 0x6c20 7.99 7f3ee7eebe55bcaa22423e7fe82c240f
( 2 imports )
KERNEL32.dll: GetLastError, GetModuleHandleA, GetSystemInfo, GetVersionExA, LocalAlloc, ExitProcess
USER32.dll: BeginPaint, CharUpperA, CreateDialogParamA, CreateWindowExA, DefWindowProcA, DispatchMessageA, EndDialog, EndPaint, FindWindowA, GetClassInfoExA, GetMessageA, GetSystemMetrics, GetTopWindow, LoadCursorA, LoadIconA, MessageBoxA, PostQuitMessage, RegisterClassExA, RegisterWindowMessageA, SendMessageA, SetDlgItemInt, SetFocus, SetWindowTextA, ShowWindow, TranslateMessage, UpdateWindow
( 0 exports )
RDS…: NSRL Reference Data Set
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=3D25F34F20A6D6847EF20064F94599009E99E11B
I will post a copy of my avast log in another post or two