Please Help! Suspected Vundo!!!
09-02-2008, 15:23
|
#1
|
|
cf.member
Join Date: Mar 2007
Posts: 53
|
Please Help! Suspected Vundo!!!
I keep getting new IE windows appear from various websites, Celldorado, leading4.com.
I have tried VundoFix, Virtumondobegone, Avast, SS&D, Ad-Aware.
Nothing has worked!
Here is my latest Hijackthis log:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\StormII\stormliv.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Documents and Settings\Josh\Desktop\HiJackThis_v2.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Contrl Center of Storm Media (ccosm) - ???????????? - C:\Program Files\StormII\stormliv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 2672 bytes
|
|
|
09-02-2008, 15:26
|
#2
|
|
Eric Cartman Wannabe
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 11,881
|
Re: Please Help! Suspected Vundo!!!
This looks suspicious, do you recognise it?
C:\Program Files\StormII\stormliv.exe
there's a major network of computers with viruses called Storm as well.
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
|
|
|
09-02-2008, 15:31
|
#3
|
|
cf.member
Join Date: Mar 2007
Posts: 53
|
Re: Please Help! Suspected Vundo!!!
I don't recognise it, what should I do? Delete the file? I am extremely grateful for any help about this. Thank You
|
|
|
09-02-2008, 15:33
|
#4
|
|
Eric Cartman Wannabe
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 11,881
|
Re: Please Help! Suspected Vundo!!!
Boot into safe mode and rename the file.. see if it reappears
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
|
|
|
09-02-2008, 15:53
|
#5
|
|
cf.member
Join Date: Mar 2007
Posts: 53
|
Re: Please Help! Suspected Vundo!!!
File has gone. Pop ups remain.
|
|
|
09-02-2008, 16:08
|
#6
|
|
vista home premium user
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,344
|
Re: Please Help! Suspected Vundo!!!
www.superantispyware.com
Download, update and run a full scan.
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
 10111 pts
|
|
|
09-02-2008, 16:32
|
#7
|
|
Eric Cartman Wannabe
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 11,881
|
Re: Please Help! Suspected Vundo!!!
Can you do another hijack this log, it might have a slightly different name
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
|
|
|
09-02-2008, 17:04
|
#8
|
|
Garlic Bread?
Join Date: Jun 2003
Location: Mansfield, Notts.
Age: 41
Services: Freesat SKY x2 - VM-10mb, TU-TI-TM. Cheaper than ASDA price!!!!!
Posts: 1,479
|
Re: Please Help! Suspected Vundo!!!
__________________
I have not failed. I've just found 10,000 ways that won't work.
|
|
|
09-02-2008, 23:22
|
#9
|
|
ntl: 4Mb SACM
Join Date: Jan 2005
Location: Notts
Posts: 152
|
Re: Please Help! Suspected Vundo!!!
Upload any suspect file at this site to be scanned by several AV progs
http://www.virustotal.com/
|
|
|
10-02-2008, 08:25
|
#10
|
|
cf.mega poster
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 43
Posts: 2,548
|
Re: Please Help! Suspected Vundo!!!
Quote:
Originally Posted by Gavin
Can you do another hijack this log, it might have a slightly different name
|
And this time post the entire log - looks like you've only included running processes and services above.
Note - there is an online anlayser here.
|
|
|
10-02-2008, 15:47
|
#11
|
|
vista home premium user
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,344
|
Re: Please Help! Suspected Vundo!!!
Ewwwwww online analysers. Seriously, they can cause a lot of problems with false +ves and ignoring entries which are bad.
Best off posting the log here or on a specialist forum.
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
 10111 pts
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 11:24.
|