Author Topic: "Nimda" Built-In admin account appears win7 x64  (Read 2913 times)

0 Members and 1 Guest are viewing this topic.

user10

  • Guest
"Nimda" Built-In admin account appears win7 x64
« on: August 17, 2012, 01:31:53 AM »
Noticed that my logins were slowing down. Looked around and found a new user account which I can't delete.
Scanned with many products offline and with in windows - nothing found by any.
Hijack This finds (below) which indicates trouble, but I can't ID the culprit - has anyone seen this?

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

« Last Edit: August 17, 2012, 02:41:13 AM by user10 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: "Nimda" Built-In admin account appears win7 x64
« Reply #1 on: August 17, 2012, 01:42:18 AM »
If you have a problem see this. http://forum.avast.com/index.php?topic=53253.0

user10

  • Guest
Re: "Nimda" Built-In admin account appears win7 x64
« Reply #2 on: August 17, 2012, 02:11:43 AM »
Posted the logs - thanks
« Last Edit: August 17, 2012, 02:42:25 AM by user10 »

user10

  • Guest
Re: "Nimda" Built-In admin account appears win7 x64
« Reply #3 on: August 17, 2012, 06:22:18 PM »
What's the best rootkit detector for windows?