Suspicious .exe files in Task Manager

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vantage_Point, Apr 4, 2005.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did a similar O4 line appear in you HJT log? It does not look like it from the Generic Detection Tool output. I only need the Generic Tool to be run if the O4 line came back.

    If there is still an O4 line with this randomly named file, post a new HJT log.
     
  2. Vantage_Point

    Vantage_Point Private E-2

    There is no sign of the random file names in the 04 line. That seems to be a good thing.

    I still have these processes in the log, although the file extensions were changed to .xxx in the folder. Would it be safe to "FIX" them?

    O23 - Service: NTBOOTMGR (NTBOOT) - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntuser.exe (file missing)
    O23 - Service: NTLOAD - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntsrv.exe (file missing)
    O23 - Service: NTSVCMGR - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntsrv.exe (file missing)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was still waiting to make sure none of these were needed for anything. If you feel comfortable that they are not required for anything, we can work on fixing those O23 lines.

    Before fixing the lines with HJT you have to run services.msc again and make sure that the service is stopped and disable.

    Then you can attempt to fix the O23 lines using HJT. That may not work either. You may need to do the below:

    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:
    NTBOOTMGR
    If that does not work try entering the short name: NTBOOT

    Then repeat the above for NTLOAD and NTSVCMGR

    Then reboot and let's see if the services are truly gone.
     
  4. Vantage_Point

    Vantage_Point Private E-2

    Are you saying to rename the files back to .exe and allow them to run again before I delete them? If so, should I reboot before deleting them?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I'm saying exactly as I wrote. You must make sure the services have been stopped and disabled.

    To do this, click Start, Run, and enter the following in the Open box: "services.msc" (without the quotes). Then click OK. Now in the Services window that pops up look for each of the below three services:
    - NTBOOTMGR or short name NTBOOT
    - NTLOAD
    - NTSVCMGR

    If you find them, you must stop it by right clicking on it then select stop. Now disable it by right clicking on it and selecting Properties. Then in the General tab see the area that says "Startup type: " click on the pull down arrow and change it to Disabled.

    Then continue with the other steps using HJT.
     
  6. Vantage_Point

    Vantage_Point Private E-2

    Mission accomplished. I was able to stop and disable them and then remove them with the "Delete a Windows NT service" tool.

    After a reboot there is no sign of them in the log, but there is only one more question. What is this line of the log?

    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use the same steps as you just did for the other services to remove this one.
    - stop & disable
    - fix with HJT
     
  8. Vantage_Point

    Vantage_Point Private E-2

    It didn't show up in the WINDOWS folder, so I had to use HJT to delete it using the NT service tool. After the reboot there is no sign of it anymore. I will continue to monitor it, but for now things seem to be getting back to normal.

    I am eternally grateful for your patience and guidance.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! I'm happy to hear things are looking normal!

    Sounds like we are done here!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds