Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hello, everyone. I have just resolved a crppy problem I had. Taskmanager would disappear, and icon would remain in systray until mouse was pointed at it. Then it too would disappear. Also, I could not get into regedit.Well, downloaded prcview.exe, a freeware utility for viewing running processes. Found a booboo process called: EXPLORES.exe. Well, when I killed the process, all was well again.
Unfortunately, I killed it before I traced its source. Dang me. I have been kiking myself very hard for this, as a command line utility comes with prcview.exe that allows you to trace running processes.
I did a scan of my registry with hijackthis.exe, and the following is the log. I am having troubles with it, as it looks like a completely diferent language to me. Can anyone here give me a clue? Any help would be very apreciated.
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\pctspk.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pavsrv.exe
C:\WINDOWS\System32\AVENGINE.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Half Gallon\Local Settings\Temporary Internet Files\Content.IE5\NCCV2HRX\PrcView[1]\PrcView.exe
C:\Documents and Settings\Half Gallon\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 12-226-231-10.client.attbi.com:80
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [windows auto update] msblast.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [Microsoft Tray] C:\My Shared Folder\Games.exe
O4 - HKLM\..\Run: [Winsock2 driver] EXPLORES.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.exe" /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Winsock2 driver] EXPLORES.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37844.8213194444
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D5A6919-DDF0-49E3-9BB1-5392D6A065AE}: NameServer = 209.244.0.3 209.244.0.4
Computing.net rocks.
---HG---

You have 2 viruses.. W32.Blaster.worm and W32.Spybot.worm
Download and run the Blaster removal tool from here:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
And install the MS patch:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
To remove W32.Spybot, Boot into safe mode and run HT again. Place a check in the box next to the following entries and click fix checked.
O4 - HKLM\..\Run: [windows auto update] msblast.exe
O4 - HKLM\..\Run: [Microsoft Tray] C:\My Shared Folder\Games.exe
O4 - HKLM\..\Run: [Winsock2 driver] EXPLORES.exe
O4 - HKCU\..\RunOnce: [Winsock2 driver] EXPLORES.exeDelete the following files:
Games.exe
EXPLORES.EXEReboot to Windows.

Hello, Tom41. Thank you very much for your help. I did all that you said. This is what happened:
I downloaded the blaster removal tool. I was given the message that I wasn't infected. (I'm still scratching my head over that one, as I know that--sometime in the past few weeks--I have seen a process running that was called 'msblast'.)I downloaded and installed the patch from microsoft.
Rebooted into safemode and ran HT. Checked only two of the reg entries, as they were the only ones still present. They were:
04-HKLM.....Games.exe
04-HK**......EXPLORES.EXECould not find the one for msblast.exe or the other one that ends in 'EXPLORES.EXE'. I will later go into regedit and very carefully look for/delete those entries if still present, as HT did not pick them up the last couple of go rounds.
I found and deleted 3 files called 'games.*' (.exe, .inf, and I can't remember the other extnsion.)
I could not find explores.exe .
My system is not backed up, system restore not enabled, but after doing all of this, I noticed that there are now 2 new backup files on my desktop. They are small (one is 66bytes;4k on disk. The other is 66bytes; 4k on disk.) Does this sound odd? I haven't the foggiest.
The following is my new HT scan:
Logfile of HijackThis v1.96.4
Scan saved at 9:36:36 AM, on 9/4/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pavsrv.exe
C:\WINDOWS\System32\AVENGINE.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\Documents and Settings\Half Gallon\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 12-226-231-10.client.attbi.com:80
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.exe" /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37844.8213194444
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabI don't know if it is clean now, but it is certainly much cleaner now, thanks to your kind help. Thank you, Tom.
Be well.
--Half Gallon--

It's clean... Those two backup files are from HijackThis, you can delete them.
The Symantec tool must have removed the Blaster registry entry.

![]() |
2nd Blaster-Worm fool arr...
|
Quarantined Virus
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |