Evil little thing kills hijack this and task manager

Discussion in 'Malware Help (A Specialist Will Reply)' started by Plastic Squirrel, Mar 7, 2005.

  1. Plastic Squirrel

    Plastic Squirrel Private E-2

    Please help me, I have spent the last 4 and a half hours trying to kill the spyware/virus/whatever the heck it is that has infected my PC. I have gone through all your processes (it killed the online scans so I had to miss them). And while some of the others (sorry can't remember exact specifics) picked up a few things and killed them off. The main problem remains, my PC keeps trying to connect to various addresses (private.kicks.ass and h-1.us.cream being memorable ones, will post more when they come back to me) and when I try to use task manager to shut down any processes it cuts out as soon as it appears. I tried to run hijack this, but the thing is evidently scared of it, as it shuts that down as well. I've managed to use the process explorer to view the running processes, but not knowing as much about PCs as I like to think I do, I'm a little worried about deleting something I need to keep. There's more to this story, but like I say, I've been staring at this thing all night, and I can't remember everything, except that all of this began with two trojans, that AVG saw off as a soon as I realised there was a problem.
    Any ideas? (promise I'll be more lucid when I can get back on here tommorrow evening)

    Dave
    (Neither plastic nor squirrely, but everyone needs a handle...)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To help us to best help you, please follow the steps below closely and in the order given and do not skip anything. If you have any difficulty, please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better. Don't be afraid to ask for additional help if you don't understand something!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download
    HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message.(Do NOT copy/paste the log into your post).
     
  3. Plastic Squirrel

    Plastic Squirrel Private E-2

    Oh, btw, I'm running windows XP (home edition version 2002, no updates, yes I know....) with a 1.5 Ghz pentium 4, and 512 megs of RAM and a 54.4 Gb HDD. I think that's about it, sorry I didn't mention it in the first post.
     
  4. Plastic Squirrel

    Plastic Squirrel Private E-2

    Like I say, I went through all of the tutorial, the online scans utterly refused to work for me (I even went back 3 times after finishing the other steps) and Avert killed off two worms, then Ad-Aware removed a whole load of stuff (sorry I can't be more specific here) and Spy Bot found 55 problems and fixed them all. The other tools all came out clean, and then Hijack This refused to initialise, just like Task Manager has been doing.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try renaming hijackthis.exe to myhjt.com and then see if it runs.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also download the below and follow the instructions below the link.

    ProcessExplorer for Win NT/2K/XP

    Unzip it and now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager cannot.
     
  7. Plastic Squirrel

    Plastic Squirrel Private E-2

    Here's the process attachment. Off to change the Hijackthis file name.
    Sorry for the long delay between posts, but I had to sleep and go to work for a while there. Thanks for the help so far.
     

    Attached Files:

  8. Plastic Squirrel

    Plastic Squirrel Private E-2

    Wahey, change the name, hijackthis works fine, now using your helpful user guide to try and fix the prob. Expect me back any minute now.
     
  9. Plastic Squirrel

    Plastic Squirrel Private E-2

    Managed to run Hijackthis, have "023 services" on the log, and these are not covered in your manual. Smartlink service? Not heard of them, and I don't think it can be good.
     
  10. Plastic Squirrel

    Plastic Squirrel Private E-2

    Not sure if you want it or not, but seeing as it's best to be safe here's my hjt log as an attachment. Got rid of all that was on the lists you guys recommend, but there's some other weird stuff there. Off to reboot now and see if any of it worked.
     

    Attached Files:

  11. Plastic Squirrel

    Plastic Squirrel Private E-2

    Still there, I haven't killed it yet, will be off for a while, but back later.
     
  12. Plastic Squirrel

    Plastic Squirrel Private E-2

    Okay, I'm back again. Things still not running smoothly at all, I think it must be the smart link service, but hjt can't seem to kill it. Plus I have Java Virtual claiming to be running, when I don't even have it on my machine.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    The service you are referring to is for your modem and should be left alone.

    You must remember to always exit ALL browsers before using HijackThis. You had the below running:
    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    Do you recognize the below IP address to be part of your network or from your ISP:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4288365E-9CF3-4303-9738-4E59A3D7B707}: NameServer = 212.74.114.129 212.74.114.193
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\javavm.exe
    C:\WINDOWS\System32\msproc.exe


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Ms Processe Manager] msproc.exe
    O4 - HKLM\..\Run: [Microsoft Java Virtual Machine] javavm.exe
    O4 - HKLM\..\RunServices: [Ms Processe Manager] msproc.exe
    O4 - HKLM\..\RunServices: [Microsoft Java Virtual Machine] javavm.exe
    O4 - HKLM\..\RunOnce: [Microsoft Java Virtual Machine] javavm.exe
    O4 - HKCU\..\Run: [Ms Processe Manager] msproc.exe
    O4 - HKCU\..\Run: [Microsoft Java Virtual Machine] javavm.exe
    O4 - HKCU\..\RunServices: [Ms Processe Manager] msproc.exe
    O4 - HKCU\..\RunOnce: [Microsoft Java Virtual Machine] javavm.exe


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\javavm.exe
    C:\WINDOWS\System32\msproc.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.


    Now run Ccleaner that you downloaded while running the initial READ ME FIRST.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  15. Plastic Squirrel

    Plastic Squirrel Private E-2

    Okay, so I followed your instructions, hjt couldn't stop the javavm process, in it's process manager, neither could the services.msc, but it fixed the 04 lines, and after deleting it in safe mode, it seems to be gone. Also, the msproc was already gone when I got to safe mode (hoping that's a good thing).
    Things seem to be running okay now, my AVG update just went through fine (it wouldn't half an hour ago before I ran your process) and I have task manager back.
    Here's the new log, just in case I have false hope, but all does seem okay now, thanks for your help. A donation will follow when I get paid next.
     

    Attached Files:

  16. Plastic Squirrel

    Plastic Squirrel Private E-2

    Oh, by the way, I'm not sure if that's part of my ISP or not, I figured it must be when I saw it, but I could be wrong I suppose. Where do I find out if it's right? (Please forgive my lack of knowledge).
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely it is you ISP. You could call and ask but the below my give you the answer:

    mk-cache-3.ns.uk.tiscali.com = [ 212.74.114.129 ]
    Registrant:
    Tiscali SpA (TISCALIS839)
    Piazza del Carmine 22
    09124 Cagliari
    IT
    Domain name: tiscali.com
    Technical contact:
    S.p.A. Tiscali (TS1029)
    Viale Trento 39
    Cagliari Cagliari
    IT
    techc@IT.TISCALI.COM

    Your log is clean now. You should now be able to rename HijackThis to its correct name.
    Rename myhjt.com back to hijackthis.com and makes sure it works. I do not need a log.

    You now need to get your OS and IE versions updated. Please run the steps in the below link the first of which is Windows Update. If you are on a slow connection (like dial-up) this could be an issue since many file will be very large.

    How to Protect yourself from malware!
     
  18. Plastic Squirrel

    Plastic Squirrel Private E-2

    I am with Tiscali, so I reckon that is what it is.
    Have installed the updates just now.
    The msproc came back this afternoon, and the probs were there again (this could be because after it was fixed last night, I didn't get the windows updates until now, and the missus was online last night).
    I ran throught the same process again, exactly the same results, still no msproc file to physically delete, but all seems well again now, and hopefully, if I do all the protective steps you suggest it won't come back.
    Thanks again, and here's another log from just now (post-update installation)
     

    Attached Files:

  19. Plastic Squirrel

    Plastic Squirrel Private E-2

    Okay, so I put in a sygate firewall, and everything is like treacle, and I'm not entirely sure what the hell is going on. I'm sure i'll sort it out in time, but I remember why I got rid of my last firewall.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log still indicates you have not updated your system. So I'm not sure what it is that you are doing but you are definitely not installing your updates.

    Running without a firewall is just about the most dangerous thing you can do. Without a firewall, you will almost always have some sort of malware problem.

    What are your issues with a firewall?

    Try downloading and installing Windows XP SP1A network version from the below link:
    http://www.microsoft.com/windowsxp/downloads/updates/sp1/network.mspx

    Note these are big files! If you are on dial-up, it will take a very long time to download this.
     
    Last edited: Mar 11, 2005
  21. Plastic Squirrel

    Plastic Squirrel Private E-2

    The link doesn't work, and microsoft is only giving me SP2, so I'm going for that one.
     
  22. Plastic Squirrel

    Plastic Squirrel Private E-2

    Never mind, found a way in through the network install (even though I have no network).
     
  23. Plastic Squirrel

    Plastic Squirrel Private E-2

    Put on the Sp1a, and redone the security updates, I'm now going through the firewalls you recommend, trying to find one that doesn't use as much CPU as the sygate one did.

    The problem I have with firewalls is that they slow down my whole system even when I'm not online, if I could find one that didn't do this, I'd be very happy. Is the inbuilt XP firewall ineffective then?
     
  24. Plastic Squirrel

    Plastic Squirrel Private E-2

    Okay, installed the Kerio firewall, and everything runs smoothly with this one, so I think I'm good now.
    Here's another log, just to make sure, should have all the windows updates on it now.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now you have
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    That's better! I wonder why it does not show up as SP1a. I have seen this happen sometimes.

    Sorry about the broken link. It did not paste in the full link. I'll edit and fix that link later, so that anyone else trying to use it does not have a problem.

    How is everything working on your PC now?

    Make sure you complete the equivalent of all the steps in the below link to help you avoid future problems:

    How to Protect yourself from malware!
     
  26. Plastic Squirrel

    Plastic Squirrel Private E-2

    All seems fine, done all the steps in the malware tutorial, and this here kerio firewall is great. you'd hardly know it was there. Thanks a lot Chas, you're a genius.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy I could help!
     
  28. harin25

    harin25 Private E-2

    Re:Help required on Killing application..

    Hi.

    I have a situation here. I want to kill "Resin web server" services from using a Java application. Is it possible. From the task manager i was able to kill Resin process only if it was "httpd.exe" and not standalone.exe, since it generates a java.exe associated with it.

    Also, how in java, will you create a process with a Process name and how do you kill the same from within the java application?

    Thanks
    Hari
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help required on Killing application..

    Hari,

    Why did you post in this thread? You should be starting your own thread and are you having a malware problem or are you asking us about writing a program?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds