Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 6th, 2009, 11:44 AM
BuzzStone BuzzStone is offline
Regular Poster
 
Join Date: Nov 2006
Posts: 163
Default Unknown App

I have the following application that I found in Task Scheduler: prvlzwkb. It is located in Windows System32 Rundll32.exe - nnnoNffg.dll. I have no idea what it does and cannot find any info on it. Does anyone have any ideas what it could be?
  #2  
Old November 6th, 2009, 02:56 PM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: Unknown App

Did a Google of the process nnnoNffg.dll, looks like it's a vundo variant.
Does the application prvlzwkb change its name after a reboot?

I'd start off trying to terminate the process and running MBAM, if you haven't already.

Links to the Google results:http://www.exterminate-it.com/malped...o-virtumondo/8 and http://forums.spybot.info/archive/in...p/t-27218.html
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #3  
Old November 6th, 2009, 07:14 PM
BuzzStone BuzzStone is offline
Regular Poster
 
Join Date: Nov 2006
Posts: 163
Default Re: Unknown App

Thanks for the reply Tarq57. I did some more googling after my post and found the info you have posted. I have scanned with MBAM, SAS, MSE and all comes up clean.
  #4  
Old November 6th, 2009, 07:22 PM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: Unknown App

I reckon it's there, but cloaking itself. Such process names bear similarities to those used by rootkits. Or polymorphic malware.
Either way, you'll need to find a way to stop it or uncloak it before it can be recognized and eliminated for good.
Not my province, sorry, not trained/knowledgeable enough to confidently help others, there are folk here that are, and plenty of malware removal forums that can help, too. (MajorGeeks, Bleeping computer, Aumha etc. There's a sticky about that Here.
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #5  
Old November 8th, 2009, 01:04 AM
subhrobhandari subhrobhandari is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 238
Default Re: Unknown App

Spybot should clean Vundo variants.
__________________
Realtime: Webroot SecureAnywhere Private Beta + Zemana Antilogger + HitmanPro Alert
On-Demand: Hitman Pro
Others: Router + EMET (Custom Conf.) + Fully Updated Windows 7 SP1 64Bit + Other Security Measures
  #6  
Old November 8th, 2009, 07:19 AM
ha14 ha14 is offline
Infrequent Poster
 
Join Date: Sep 2009
Posts: 48
Default Re: Unknown App

Hi

Download Hijackthis and do a scan and save the log file, then post here so someone can help you. Alternatively download superantispyware and malwarebytes antimalware. Instal both of them the reboot in safe mode and then scan first with superantispyware, then reboot normal and clean. Repeat the same with malwarebtres antimalware. Good luck.
  #7  
Old November 8th, 2009, 09:53 AM
lordpake's Avatar
lordpake lordpake is offline
Frequent Poster
 
Join Date: Aug 2004
Location: Helsinki ~ European Union
Posts: 563
Default Re: Unknown App

Quote:
Originally Posted by ha14
Download Hijackthis and do a scan and save the log file, then post here so someone can help you.

I do believe forum policies forbid posting of HjT logs here unless specifically requested by forum staff member or other expert, see this thread http://www.wilderssecurity.com/showthread.php?t=42148
__________________
~i~ System info ~i~
  #8  
Old November 10th, 2009, 07:39 AM
catcherintherye catcherintherye is offline
Infrequent Poster
 
Join Date: Oct 2008
Posts: 13
Default Re: Unknown App

See if AppRanger works
  #9  
Old November 10th, 2009, 09:29 AM
twl845's Avatar
twl845 twl845 is online now
Massive Poster
 
Join Date: Apr 2005
Location: New York, USA
Posts: 3,328
Default Re: Unknown App

Here's the fix. just run it. http://vundofix.atribune.org/
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums