Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: hijack this question...  (Read 4970 times)

0 Members and 1 Guest are viewing this topic.

homer

    Topic Starter


    Expert
    hijack this question...
    « on: September 09, 2006, 08:56:27 PM »
    are BOTH these entries legitimate?im pretty sure the top one is.

    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\RUNDLL32.EXE

    i mean ive heard about viruses that have a similiar name to thwart suspicion.

    BTW, i had a minor problem with not being able to connect to the internet, so i looked for my network adapter and checked out its properties. turns out i was recieving packets while i was unable to connect using fire fox or IE. why is that????

    Fed

    • Moderator


    • Sage
    • Thanked: 35
      • Experience: Experienced
      • OS: Windows XP
      Re: hijack this question...
      « Reply #1 on: September 09, 2006, 09:06:57 PM »
      That is just 2 entries to load the 1 file, you can remove 1 of those entries.
      Remember, it is impossible to have 2 files of the same name in the same location.

      Receiving packets when you shouldn't be? That could be a problem, are you sure there are no auto update things running that you are unaware of?

      homer

        Topic Starter


        Expert
        Re: hijack this question...
        « Reply #2 on: September 09, 2006, 09:16:41 PM »
        i only have 15 programs that Zone Alarm will allow internet access without me confirming it. everything else has to ask me for internet access.

        i honestly can NOT think of ANY program that could access the internet without me knowing. also, even if they did somehow get around Zone Alarm, how could they recieve packets while i could not use an internet browser?
        « Last Edit: September 09, 2006, 09:17:01 PM by homer »

        homer

          Topic Starter


          Expert
          Re: hijack this question...
          « Reply #3 on: September 09, 2006, 09:18:02 PM »
          heres my HIJACK THIS log...

          Logfile of HijackThis v1.99.1
          Scan saved at 8:17:24 PM, on 9/9/2006
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\SYSTEM32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
          C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
          C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
          F:\virus stuff\Ewido\guard.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Logitech\G-series Software\LGDCore.exe
          C:\Program Files\Logitech\G-series Software\LCDMon.exe
          C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
          C:\WINDOWS\system32\Rundll32.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
          C:\Program Files\Microsoft IntelliPoint\point32.exe
          C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
          C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
          C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          F:\virus stuff\ZoneAlarm\zlclient.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          F:\virus stuff\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
          O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
          O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
          O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
          O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          O4 - HKLM\..\Run: [Zone Labs Client] "F:\virus stuff\ZoneAlarm\zlclient.exe"
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
          O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - F:\virus stuff\Ewido\guard.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


          Fed

          • Moderator


          • Sage
          • Thanked: 35
            • Experience: Experienced
            • OS: Windows XP
            Re: hijack this question...
            « Reply #4 on: September 09, 2006, 09:28:25 PM »
            How many bytes in that rundll32.exe file?

            homer

              Topic Starter


              Expert
              Re: hijack this question...
              « Reply #5 on: September 09, 2006, 09:33:18 PM »
              there both at ~200k according to windows task manager.

              Fed

              • Moderator


              • Sage
              • Thanked: 35
                • Experience: Experienced
                • OS: Windows XP
                Re: hijack this question...
                « Reply #6 on: September 09, 2006, 09:46:58 PM »
                Right click on the file, check it's properties to get the exact number of bytes.

                homer

                  Topic Starter


                  Expert
                  Re: hijack this question...
                  « Reply #7 on: September 09, 2006, 09:55:48 PM »
                  im sorry, the ~200k was for thier memory usage. the actual size of rundll32.exe is as follows...

                  Size              32.5KB (33,280 bytes)
                  Size On Disk   36.0KB (36,864 bytes)

                  according to rundll32.exe properties.

                  i could NOT locate RUNDLL32.EXE.
                  « Last Edit: September 09, 2006, 09:56:21 PM by homer »

                  Fed

                  • Moderator


                  • Sage
                  • Thanked: 35
                    • Experience: Experienced
                    • OS: Windows XP
                    Re: hijack this question...
                    « Reply #8 on: September 09, 2006, 10:01:59 PM »
                    Are you still receiving mystery packets?
                    Are you still unable to open a browser?

                    homer

                      Topic Starter


                      Expert
                      Re: hijack this question...
                      « Reply #9 on: September 09, 2006, 10:18:53 PM »
                      -mystery packets stopped
                      -i was always able to open a browser, i just could not connect.

                      i did ABSOLUTELY NOTHING between the time i was aware of recieving packets (the zone alarm internet monitor was showing me as recieveing packets) and when i was finally able to connect to the internet. i do believe when the packets stopped i was able to connect, but i am not certain.

                      recent events
                      - i set up a home network between my comp and my friends comp (for sharing files). i was NOT connected to the network at the time i was recieving packets, his comp wasnt even at my house at the time.

                      i was able to get a patch for BF2 off his comp, however he was not allowed to connect to my comp (for reasons unknown). and since then, this problem has happened AND windows media player 10 displays the following pop-up...


                      I DONT HAVE DIAL-UP!!
                      « Last Edit: September 09, 2006, 10:20:16 PM by homer »

                      Fed

                      • Moderator


                      • Sage
                      • Thanked: 35
                        • Experience: Experienced
                        • OS: Windows XP
                        Re: hijack this question...
                        « Reply #10 on: September 10, 2006, 01:00:08 AM »
                        Reboot & post a fresh HJT log.

                        homer

                          Topic Starter


                          Expert
                          Re: hijack this question...
                          « Reply #11 on: September 10, 2006, 02:53:48 AM »
                          rebooted and ran HJT. here is a fresh log.

                          Logfile of HijackThis v1.99.1
                          Scan saved at 1:52:58 AM, on 9/10/2006
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\SYSTEM32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                          C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                          C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                          F:\virus stuff\Ewido\guard.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\Program Files\Logitech\G-series Software\LGDCore.exe
                          C:\Program Files\Logitech\G-series Software\LCDMon.exe
                          C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
                          C:\WINDOWS\system32\Rundll32.exe
                          C:\WINDOWS\system32\RUNDLL32.EXE
                          C:\Program Files\Microsoft IntelliPoint\point32.exe
                          C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
                          C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
                          C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                          C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
                          F:\virus stuff\ZoneAlarm\zlclient.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          F:\virus stuff\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                          O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
                          O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
                          O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
                          O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
                          O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
                          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                          O4 - HKLM\..\Run: [Zone Labs Client] "F:\virus stuff\ZoneAlarm\zlclient.exe"
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                          O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - F:\virus stuff\Ewido\guard.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

                          « Last Edit: September 10, 2006, 02:54:03 AM by homer »

                          Neil



                            Expert
                          • Fear me Track. Noone can escape my wrath.
                          • Thanked: 3
                            Re: hijack this question...
                            « Reply #12 on: September 10, 2006, 09:00:45 AM »
                            Something that might be useful information: a capital I can look like a lowercase l in some fonts.

                            homer

                              Topic Starter


                              Expert
                              Re: hijack this question...
                              « Reply #13 on: September 10, 2006, 01:02:35 PM »
                              so your saying it might be rundii32.exe (with capitol i's)

                              EDIT

                              tested that theory, both files are actually rundll32 and RUNDLL32. not rundii32.
                              « Last Edit: September 10, 2006, 01:04:59 PM by homer »

                              Fed

                              • Moderator


                              • Sage
                              • Thanked: 35
                                • Experience: Experienced
                                • OS: Windows XP
                                Re: hijack this question...
                                « Reply #14 on: September 10, 2006, 02:07:30 PM »
                                Log file looks ok Homer.
                                Perhaps you were the victim of a DoS attack. :-?

                                Edit: Is your media player set for auto update?
                                « Last Edit: September 10, 2006, 02:16:30 PM by Fed »

                                homer

                                  Topic Starter


                                  Expert
                                  Re: hijack this question...
                                  « Reply #15 on: September 10, 2006, 07:42:19 PM »
                                  WMP10 is not set to auto update, i also just set it to check for updates once a month.

                                  Fed

                                  • Moderator


                                  • Sage
                                  • Thanked: 35
                                    • Experience: Experienced
                                    • OS: Windows XP
                                    Re: hijack this question...
                                    « Reply #16 on: September 11, 2006, 12:54:45 AM »
                                    I take it that you're up to date with all the Windows patches?
                                    If that dialup screen comes up when you open media player there has to be a setting in there somewhere to check for updates or auto update.

                                    homer

                                      Topic Starter


                                      Expert
                                      Re: hijack this question...
                                      « Reply #17 on: September 11, 2006, 05:23:37 PM »
                                      it hasent come up anymore. and i am not recieving any more mystery packets. i dont know how or why this all happened but so far it has not come back.