View Single Post
Old 06-16-2008, 03:07 AM   #12 (permalink)
Katana
Analyst, Security Team
 
Katana's Avatar
 
Join Date: Nov 2007
Location: Manchester, UK
Posts: 1,357
OS: W2K SP4 + XP SP2 + Vista


Re: Suspected "vundo" problem

Sorry for the delay, I didn't get notified of your response.

Let's have a last couple of scans to make sure

Please Download GMER to your desktop

Please create a folder in the Program Files folder called GMER.

Download GMER and extract it to the C:\program files\GMER folder you have just made.


Run the Gmer.exe program by double-clicking the executable file gmer.exe.
You may be prompted to scan immediately if GMER detects rootkit activity.

If you are prompted to scan your system click "yes" to begin the scan.
If you are not prompted, Click the "Rootkit" tab, then click "Scan".


DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in your next reply.

Please post the results from the GMER scan in your reply.



Delete the copy of ComboFix.exe that you have, and download the updated version

ComboFix.exe 1
ComboFix.exe 2
ComboFix.exe 3

Please re-run ComboFix and post the log.
__________________
Katana is online now