Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Generate data entry and reporting .NET Web apps in minutes, straight from your database. Read our FREE whitepaper “Build Web 2.0 Applications Without Hand-Coding” Download now!
  #1  
Old November 9th, 2004, 03:45 PM
geetus geetus is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 3 geetus User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
What is this?

This is in my HKLM\...\run (that's abbreviated - no "..." reg keys, fyi) reg entry & spysweeper keeps prompting me after every startup to either keep it or remove it. I keep telling it "remove" since I can't find what it is anywhere. I keep seeing it in hijackthis logs from people loaded with spyware... That's about all I can find on it with google. It's not running, and I can easily remove it, but I was wondering if it was a legit program or windows (XP) component, or if it's spy\mal\adware. Here are the details:

file: c:\WINNT\System32\vcdmf.exe
Process: cgdedl
registry entry: HKLM\...\run\vcdmf.exe

Reply With Quote
  #2  
Old November 11th, 2004, 03:37 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 13
Hi geetus,

Looks suspicious. Please post a HijackThis log:

Download HijackThis. Make sure you install HijackThis to a permanent folder such as C:\HJT as it creates backups of what we will fix. Run the program, press Scan, after a brief pause... press Save log. Notepad will open, copy and paste the entire log into your post. Do not fix anything yet, most of what's in the log is needed!

http://www.majorgeeks.com/download3155.html

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
  #3  
Old November 11th, 2004, 04:55 PM
geetus geetus is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 3 geetus User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I temporatily took care of it.

I renamed the file vcdmf.ren (rather than exe) and guess what? doesn't run at startup, doesn't set off spysweeper, etc. Everything seems to be working fine without it, too. I'll re-rename it & reboot so I can get it in the log. I just wanna know what it is... Curious...

Reply With Quote
  #4  
Old November 11th, 2004, 05:05 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 13
It's probably a random named virus/trojan/spyware/adware it does not appear to be a well known file.

Tom

Reply With Quote
  #5  
Old November 11th, 2004, 05:23 PM
geetus geetus is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 3 geetus User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I figured as much

I'm sort of against running the exe just to get it to show up in my hjt log, though. I'm going to trust my instinct on this one & just get rid of it. I've had it renamed for a while now & had no problems running anything... no errors... everything's fine. If anyone feels like doing some reverse engineering, I can e-mail it to them (renamed to a harmless file ext, of course) to play around with. IMO, if it were legit, it would have been documented better. I think I'll just quarantine it & let it collect dust. If anyone wants to dissect it, just post your e-mail address in this thread & I'll send it to you.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > What is this?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway