TASKMGRU.EXE, MSIMN32.EXE, BHOASS.DLL...and MORE

Discussion in 'Malware Help (A Specialist Will Reply)' started by meggsgj, Apr 22, 2005.

  1. meggsgj

    meggsgj Private E-2

    I had a new virus yesterday evening and after searching (on different machine!) it seemed to be very similar to that posted as http://www.techsupportforum.com/showthread.php?threadid=49162, but before posting I followed the steps in your spyware tutorial.

    When I ran Trend micro online I found
    'HouseCall has found 6 infected files'
    TROJ LOADER.E C:\WINDOWS\SYSTEM32\MSIMN32.EXE
    TROJ LOADER.E C:\WINDOWS\SYSTEM32\TASKMGRU.EXE
    TROJ STARTPAG.NZ C:\WINDOWS\BHOASS.DLL
    TROJ STARTPAG.NZ C:\WINDOWS\BHOASSW.DLL
    TROJ LOADER.E C:\WINDOWS\EXPLORER32DBG.EXE
    TROJ LOADER.E C:\WINDOWS\IEXPLORE_DBG.EXE

    All 'Non Cleanable'...so I chose to delete, but top two could not be cleaned because they were in use. I closed Internet explorer, but then could not open it again - message said that file c:\program files\internet explorer\iexplore.exe did not exist. I checked and it did exist, but gave me same message when I clicked on it directly.

    I renamed iexplore.exe to foo.exe and ran - this brought up Internet Explorer but it said it was running in 'compatibility mode'. So IE works, but not fully.

    I then ran Trend micro again and got just the following 2
    TROJ LOADER.E C:\WINDOWS\SYSTEM32\MSIMN32.EXE
    TROJ LOADER.E C:\WINDOWS\SYSTEM32\TASKMGRU.EXE

    again they could be deleted so I moved on with recommended tasks and all was well until I ran Kill2Me. This ran successfully, but said that taskbar and desktop would disappear temporarily - They went alright, but haven't come back yet! I have tried booting in normal and safe mode, but to no avail.

    I can get to some programs (using CTRL+ALT+DEL and taskmanager), but things are very difficult and i don't know if I have fixed the original problem.

    Can someone help please!!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. meggsgj

    meggsgj Private E-2

    Many thanks for your advice, but things went from bad to worse and I decided to perform a system rebuild.

    Keep doing a great job!!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! That probably was not necessary! I have fixed quite a few PCs with the problem files you listed. But at any rate you should be okay now. Make sure you get the proper protections in place immediately. See the steps in the below thread:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds