I just discovered my laptop running multiple copies of notepad.exe program to the point of hanging at last. I use endpoint symantec AV but it couldn't even detect it as a virus/worm . Any one come across this?
thax!
The virus seems to have propagated to more users on my LAN. Find below the log. a Samml popup, with a heading of "notepad.exe" then it dispalys/generates
Logfile of HijackThis v1.99.1
Scan saved at 4:06:47 PM, on 5/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Several red flags on this one: C:\WINDOWS\system32\dllcache\svchost.exe Normally this runs from the system32 directory. Check it out. O4 - HKLM\..\Run: [(Default)] C:\WINDOWS\system32\dllcache\svchost.exe Same thing O4 - HKLM\..\Run: [Microsoft Windows Update Client] C:\WINDOWS\services.exe Added by SoberX worm? C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp .tmp You have several of these running. Stop them and get rid of them O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S What is this? If you didn't add it, get rid of it. O4 - HKLM\..\Run: [CPQEASYBTTN] C:\WINDOWS\system32\GroupPolicy\BttnServ.exe Same thing.
Several of these like the svhosts, services, and tmp.tmp are running multiple time. Carefully check them out. Also, if Unknown O17 - KLM\System\CCS\Services\Tcpip\..\{A6C6A0DA-77B3-4163-8992-391674A76E5B}: NameServer = 172.16.51.3,213.55.64.36 is not your local DNS server, change this, too.
James P. Cottingham
----------------------------------------- I'm number 1,229!
I'm number 1,229!
thanks! I am able to stop the services and resolve the problem temporarily. I can stay likes this till the next AV update takes care of it once and for all.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.