hi,
zone alarm asked for permission for
bundlekillah.exe
what’s this for application ??
(i think it’s has to make with wmplayer because
he doesn’ launch anymore …)
best regards
hi,
zone alarm asked for permission for
bundlekillah.exe
what’s this for application ??
(i think it’s has to make with wmplayer because
he doesn’ launch anymore …)
best regards
Go to www.security-ops.tk and use Kaspersky or RAV single file scan and check the file. Also perform full system scan with local or online antivirus scanner.
it is a worm that takes over media player-max
hi,
how to get rid of it
if find nothing on the web ??
i found this too : Win32.IstBar.dr
best regards
morph
Did you tried Adaware and SpybotSD ( update them first!)? You can find the Links in RejZoR Link above. If that would not help post a hijackthis log: http://tomcoyote.com/hjt/
hi,
here’s the hijack log
Logfile of HijackThis v1.97.7
Scan saved at 13:23:45, on 11/04/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashserv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\WINNT\system32\DeltTray.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\My Documents\downloads\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=138442
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=138442
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=138442
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.be/
N2 - Netscape 6: user_pref(“browser.search.defaultengine”, “engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src”); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\8t98up3l.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: (no name) - {8FB0F3E2-5193-11d7-9F88-0050FC5441CB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM..\Run: [DeltTray] DeltTray.exe
O4 - HKLM..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM..\Run: [CreateCD] C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe -r
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {00000000-0000-0000-0000-d4c4b96b0d97} -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/230614fd060c0bb24621/netzip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/nl/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37957.5034490741
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
thanks
morph
Coolwebsearchhijacker! Download and start this:
http://www.spywareinfo.com/~merijn/files/HijackThis.exe
If you did not changed the Mozillasearchengine by yourself and CWshredder did not delete it, you can fix this too:
N2 - Netscape 6: user_pref(“browser.search.defaultengine”, “engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src”); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\8t98up3l.slt\prefs.js)
and fix this:
O3 - Toolbar: (no name) - {8FB0F3E2-5193-11d7-9F88-0050FC5441CB} - (no file)
O16 - DPF: {00000000-0000-0000-0000-d4c4b96b0d97} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/230614fd060c0bb24621/netzip/RdxIE601.cab
hi,
don’t understand
should i delete the 4 items in hi jack
N2 - Netscape 6: user_pref
O3 - Toolbar: (no name) - {8FB0F3E2-5193-11d7-9F88-0050FC5441CB} - (no file)
O16 - DPF: {00000000-0000-0000-0000-d4c4b96b0d97} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
sorry but i’am newbie
thancks
Yes, fix them (check the entries and press “fix checked” ) but first use cwshredder.
hi,
where to find cwshredder ?
after this can i use again my windowsplayer normal ???
best regards
morph
Sorry! My fault: http://www.spywareinfo.com/~merijn/files/CWShredder.exe
hi,
i’ve done what you told me and it looks all ok
…splendid…
thanks a lot for the great help !
morph
hi,
the whole week everything was ok but after surfing a few minutes
zone amarm asked again for windows media player to acces internet …
cwshredder removed the media player and i reinstalled him
Should i do something else ??? … and what can i do to stop
this in the future ?
this is my logfile
Logfile of HijackThis v1.97.7
Scan saved at 22:40:39, on 18/04/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashserv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\WINNT\system32\DeltTray.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\My Documents\secure\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.be/
N2 - Netscape 6: user_pref(“browser.search.defaultengine”, “http://www.google.com/”); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\8t98up3l.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM..\Run: [DeltTray] DeltTray.exe
O4 - HKLM..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM..\Run: [CreateCD] C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe -r
O4 - HKLM..\RunOnce: [ACMWrapperV2.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CDEngine\ACMWrapperV2.dll”
O4 - HKLM..\RunOnce: [MediaPlayerV2.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CDEngine\MediaPlayerV2.dll”
O4 - HKLM..\RunOnce: [driversV2.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CDEngine\driversV2.dll”
O4 - HKLM..\RunOnce: [Cdbootable.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\Cdbootable.dll”
O4 - HKLM..\RunOnce: [cdDataPS.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\cdDataPS.dll”
O4 - HKLM..\RunOnce: [cdExtra.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\cdExtra.dll”
O4 - HKLM..\RunOnce: [cdmp3.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\cdmp3.dll”
O4 - HKLM..\RunOnce: [database.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\database.dll”
O4 - HKLM..\RunOnce: [ISO9660.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\ISO9660.dll”
O4 - HKLM..\RunOnce: [Joliet.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\Joliet.dll”
O4 - HKLM..\RunOnce: [Udf.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\Udf.dll”
O4 - HKLM..\RunOnce: [creator.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\creator.dll”
O4 - HKLM..\RunOnce: [Translator.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CreatorAPI\Translator.dll”
O4 - HKLM..\RunOnce: [CDEngine.dll] c:\winnt\system32\regsvr32.exe /s “C:\Program Files\Common Files\Adaptec Shared\CDEngine\CDEngine.dll”
O4 - HKLM..\RunOnce: [WMC_RebootCheck] C:\WINNT\inf\unregmp2.exe /FixUps
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/nl/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37957.5034490741
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip..{9962A0AC-EF43-4EB3-9165-39CF990EA3F1}: NameServer = 195.238.2.22 195.238.2.21
best regards
morph
nobody ??? ???
Search the file jview, normally stored in system32 folder, and take a look which version it is ( 5.0.38XX?)
It is necessary to update Windows/IE!
hi,
jview version is
5.0.3810.0
morph
Hm, thats up to date. Made the other windowsupdates too? That should protect you from getting hit by CWS.
BTW: Which CWS variant did CWshredder report?
hi,
updates windows …yes
can’t find any log from cwshredder anymore …
or where should i look ?
morph
Hm, if i remember correctly, CWshredder does not save its log!? If you get infected again( i do not hope so, but if), please write down the Name.
I had that “bundlekillah.exe” file and it also tried to hijack Windows Media Player.
Some people on another forum told me how to clean it: http://www.computercops.biz/postlite30230-bundlekillah+exe.html
I erased the file, reinstalled Windows Media Player, and made sure the registry references to bundlekillah.exe were also removed. It would regenerate itself if you merely deleted it.
I e-mailed three virus scanner websites, but none of them had heard of it at that point, but they all wanted a copy of the file, so if you or anyone else gets it, please e-mail them a copy of it if you get the chance.