Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Please Help! Suspected Vundo!!!


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Please Help! Suspected Vundo!!!
Reply
 
Thread Tools
Old 09-02-2008, 15:23   #1
cf.member
 
Join Date: Mar 2007
Posts: 53
FV2007 is on a distinguished road
Please Help! Suspected Vundo!!!

I keep getting new IE windows appear from various websites, Celldorado, leading4.com.

I have tried VundoFix, Virtumondobegone, Avast, SS&D, Ad-Aware.

Nothing has worked!

Here is my latest Hijackthis log:

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\StormII\stormliv.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Documents and Settings\Josh\Desktop\HiJackThis_v2.exe

O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Contrl Center of Storm Media (ccosm) - ???????????? - C:\Program Files\StormII\stormliv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 2672 bytes
FV2007 is offline   Reply With Quote
Old 09-02-2008, 15:26   #2
Eric Cartman Wannabe
 
punky's Avatar
 
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 11,881
punky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quads
punky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quads
Re: Please Help! Suspected Vundo!!!

This looks suspicious, do you recognise it?

C:\Program Files\StormII\stormliv.exe

there's a major network of computers with viruses called Storm as well.
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
punky is online now   Reply With Quote
Old 09-02-2008, 15:31   #3
cf.member
 
Join Date: Mar 2007
Posts: 53
FV2007 is on a distinguished road
Re: Please Help! Suspected Vundo!!!

I don't recognise it, what should I do? Delete the file? I am extremely grateful for any help about this. Thank You
FV2007 is offline   Reply With Quote
Old 09-02-2008, 15:33   #4
Eric Cartman Wannabe
 
punky's Avatar
 
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 11,881
punky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quads
punky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quads
Re: Please Help! Suspected Vundo!!!

Boot into safe mode and rename the file.. see if it reappears
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
punky is online now   Reply With Quote
Old 09-02-2008, 15:53   #5
cf.member
 
Join Date: Mar 2007
Posts: 53
FV2007 is on a distinguished road
Re: Please Help! Suspected Vundo!!!

File has gone. Pop ups remain.
FV2007 is offline   Reply With Quote
Old 09-02-2008, 16:08   #6
vista home premium user
 
nffc's Avatar
 
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,344
nffc is a king among kings
nffc is a king among kingsnffc is a king among kingsnffc is a king among kings
Re: Please Help! Suspected Vundo!!!

www.superantispyware.com

Download, update and run a full scan.
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
10111 pts
nffc is offline   Reply With Quote
Old 09-02-2008, 16:32   #7
Eric Cartman Wannabe
 
punky's Avatar
 
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 11,881
punky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quads
punky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quadspunky has a fine set of Quads
Re: Please Help! Suspected Vundo!!!

Can you do another hijack this log, it might have a slightly different name
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
punky is online now   Reply With Quote
Old 09-02-2008, 17:04   #8
Garlic Bread?
 
alferret's Avatar
 
Join Date: Jun 2003
Location: Mansfield, Notts.
Age: 41
Services: Freesat SKY x2 - VM-10mb, TU-TI-TM. Cheaper than ASDA price!!!!!
Posts: 1,479
alferret has entered a golden reputation era
alferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation eraalferret has entered a golden reputation era
Send a message via MSN to alferret
Re: Please Help! Suspected Vundo!!!

http://www.prevx.com/filenames/X7290...RMLIV.EXE.html
__________________
I have not failed. I've just found 10,000 ways that won't work.
alferret is offline   Reply With Quote
Old 09-02-2008, 23:22   #9
ntl: 4Mb SACM
 
Nanook's Avatar
 
Join Date: Jan 2005
Location: Notts
Posts: 152
Nanook is a jewel in the roughNanook is a jewel in the roughNanook is a jewel in the roughNanook is a jewel in the roughNanook is a jewel in the roughNanook is a jewel in the rough
Re: Please Help! Suspected Vundo!!!

Upload any suspect file at this site to be scanned by several AV progs

http://www.virustotal.com/
__________________

Nanook is offline   Reply With Quote
Old 10-02-2008, 08:25   #10
cf.mega poster
 
Aragorn's Avatar
 
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 43
Posts: 2,548
Aragorn is a pillar of societyAragorn is a pillar of societyAragorn is a pillar of societyAragorn is a pillar of society
Aragorn is a pillar of societyAragorn is a pillar of society
Re: Please Help! Suspected Vundo!!!

Quote:
Originally Posted by Gavin View Post
Can you do another hijack this log, it might have a slightly different name
And this time post the entire log - looks like you've only included running processes and services above.
Note - there is an online anlayser here.
Aragorn is online now   Reply With Quote
Old 10-02-2008, 15:47   #11
vista home premium user
 
nffc's Avatar
 
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,344
nffc is a king among kings
nffc is a king among kingsnffc is a king among kingsnffc is a king among kings
Re: Please Help! Suspected Vundo!!!

Ewwwwww online analysers. Seriously, they can cause a lot of problems with false +ves and ignoring entries which are bad.

Best off posting the log here or on a specialist forum.
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
10111 pts
nffc is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 11:24.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)