Computing.Net > Forums > Security and Virus > I think I have virii/trojans. Hijac

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

I think I have virii/trojans. Hijac

Reply to Message Icon

Name: HalfGallon
Date: September 4, 2003 at 03:53:39 Pacific
OS: WinXP
CPU/Ram: 256
Comment:


Hello, everyone. I have just resolved a crppy problem I had. Taskmanager would disappear, and icon would remain in systray until mouse was pointed at it. Then it too would disappear. Also, I could not get into regedit.

Well, downloaded prcview.exe, a freeware utility for viewing running processes. Found a booboo process called: EXPLORES.exe. Well, when I killed the process, all was well again.

Unfortunately, I killed it before I traced its source. Dang me. I have been kiking myself very hard for this, as a command line utility comes with prcview.exe that allows you to trace running processes.

I did a scan of my registry with hijackthis.exe, and the following is the log. I am having troubles with it, as it looks like a completely diferent language to me. Can anyone here give me a clue? Any help would be very apreciated.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\pctspk.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pavsrv.exe
C:\WINDOWS\System32\AVENGINE.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Half Gallon\Local Settings\Temporary Internet Files\Content.IE5\NCCV2HRX\PrcView[1]\PrcView.exe
C:\Documents and Settings\Half Gallon\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 12-226-231-10.client.attbi.com:80
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [windows auto update] msblast.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [Microsoft Tray] C:\My Shared Folder\Games.exe
O4 - HKLM\..\Run: [Winsock2 driver] EXPLORES.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.exe" /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Winsock2 driver] EXPLORES.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37844.8213194444
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D5A6919-DDF0-49E3-9BB1-5392D6A065AE}: NameServer = 209.244.0.3 209.244.0.4


Computing.net rocks.


---HG---




Sponsored Link
Ads by Google

Response Number 1
Name: Tom41
Date: September 4, 2003 at 06:31:39 Pacific
Reply:

You have 2 viruses.. W32.Blaster.worm and W32.Spybot.worm

Download and run the Blaster removal tool from here:

http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

And install the MS patch:

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp

To remove W32.Spybot, Boot into safe mode and run HT again. Place a check in the box next to the following entries and click fix checked.

O4 - HKLM\..\Run: [windows auto update] msblast.exe
O4 - HKLM\..\Run: [Microsoft Tray] C:\My Shared Folder\Games.exe
O4 - HKLM\..\Run: [Winsock2 driver] EXPLORES.exe
O4 - HKCU\..\RunOnce: [Winsock2 driver] EXPLORES.exe

Delete the following files:

Games.exe
EXPLORES.EXE

Reboot to Windows.



0

Response Number 2
Name: HalfGallon
Date: September 4, 2003 at 08:38:40 Pacific
Reply:

Hello, Tom41. Thank you very much for your help. I did all that you said. This is what happened:


I downloaded the blaster removal tool. I was given the message that I wasn't infected. (I'm still scratching my head over that one, as I know that--sometime in the past few weeks--I have seen a process running that was called 'msblast'.)

I downloaded and installed the patch from microsoft.

Rebooted into safemode and ran HT. Checked only two of the reg entries, as they were the only ones still present. They were:

04-HKLM.....Games.exe
04-HK**......EXPLORES.EXE

Could not find the one for msblast.exe or the other one that ends in 'EXPLORES.EXE'. I will later go into regedit and very carefully look for/delete those entries if still present, as HT did not pick them up the last couple of go rounds.

I found and deleted 3 files called 'games.*' (.exe, .inf, and I can't remember the other extnsion.)

I could not find explores.exe .

My system is not backed up, system restore not enabled, but after doing all of this, I noticed that there are now 2 new backup files on my desktop. They are small (one is 66bytes;4k on disk. The other is 66bytes; 4k on disk.) Does this sound odd? I haven't the foggiest.

The following is my new HT scan:


Logfile of HijackThis v1.96.4
Scan saved at 9:36:36 AM, on 9/4/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pavsrv.exe
C:\WINDOWS\System32\AVENGINE.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\Documents and Settings\Half Gallon\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 12-226-231-10.client.attbi.com:80
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.exe" /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37844.8213194444
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

I don't know if it is clean now, but it is certainly much cleaner now, thanks to your kind help. Thank you, Tom.

Be well.
--Half Gallon--



0

Response Number 3
Name: Tom41
Date: September 4, 2003 at 11:41:31 Pacific
Reply:

It's clean... Those two backup files are from HijackThis, you can delete them.

The Symantec tool must have removed the Blaster registry entry.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


2nd Blaster-Worm fool arr... Quarantined Virus



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: I think I have virii/trojans. Hijac

I have a trojan www.computing.net/answers/security/i-have-a-trojan/18258.html

i have 2 trojans i cant get rid of www.computing.net/answers/security/i-have-2-trojans-i-cant-get-rid-of/9002.html

I have a trojan www.computing.net/answers/security/i-have-a-trojan-/26037.html