Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > Malware and Virus Removal

Malware and Virus Removal Problems removing malware/viruses? Get help from our Malware removal experts.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 9th May 2005   #1
Senior Member
 
Profile:
Join Date: Jan 2002
Location: Woodstock NY
Posts: 233
Computer Experience:
experienced
marty Reputation Level


A Hijack This based worm??

I've been having problems for months. The latest symptom I noticed starting yesterday is that when I run Security Task Manager I now see the following processes (name & file) :

HijackThis 1.99.1 D:\APPS\FIREFOX\FIREFOX.EXE
HijackThis 1.99.1 D:\Apps\Eudora\Eudora.exe
HijackThis 1.99.1 C:\WINDOWS\Explorer.EXE

SpybotSD, AdAware SE, Hijack This, and TDS-3 all ran clean earlier this morning.

Marty

marty is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 11th May 2005   #2
SuperGeek
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,523
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Hi Marty,

Sounds strange. Re-install STM?? Could you expand a bit on what other problems you're experiencing?

noahdfear is offline  
Old 11th May 2005   #3
Senior Member
 
Profile:
Join Date: Jan 2002
Location: Woodstock NY
Posts: 233
Computer Experience:
experienced
marty Reputation Level


Hi Noah,

Ok it turned out to be pretty simple. Reinstalling STM didn't do a thing, but reinstalling HJT has cleared it up.

Funny thing - HJT doesn't install visibly. IOW I uninstalled from the control panel as usual, but afaik HJT just comes as a .exe which is on a network drive. So I ran it after uninstalling, right from the network share. Then ran STM which now looks fine, then looked at the add/rem pgms screen and HJT is there so apparently it installs itself, at least putting in registry entries when run for the 'first' time.

As far as other problems go, I recently removed a rootkit - located with TDS-3, forget which it was. Now I seem to not have problems of my connection being hijacked etc.., all scans (STM, TDS-3, AdAware, Spybot S&D, HJT) are running clean... but my system gets unstable after several hours.

What happens is that a variety of actions which all seem to do a similar thing will eventually stop working; at that point I might get away with ending the app, but eventually I'll lose my taskbar, or the modem icon disappears, or I just lose all control of my machine, so I reboot.

The actions that will do this are

- going to a link on Firefox from a click on Eudora email
- trying to save a web page from Firefox
- attempting a 'save as' from Textpad and then trying to navigate to another location on my computer in the resulting dialog box

Each of these times I note that Win Explorer seems to continue working properly, and STM doesn't show any unusual processes running. Before removing that rootkit at this point I would see malware processes running e.g. veritas.exe, tftp1234.exe (any four digits), and others.

What a mess, eh?

Marty

marty is offline  
Old 11th May 2005   #4
SuperGeek
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,307
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Hi Marty,

FYI, to double check TDS: http://www.sysinternals.com/ntw2k/fr...itreveal.shtml rootkitrevealer It's updated fairly frequently with newer versions, the latest v1.4

And out of curiousity, what was the rootkit that TDS caught?

Regards - Charles

charlesvar is offline  
Old 11th May 2005   #5
Senior Member
 
Profile:
Join Date: Jan 2002
Location: Woodstock NY
Posts: 233
Computer Experience:
experienced
marty Reputation Level


Charles,

I had been running Rootkit Revealer 1.2 with clean results before TDS found one a few days ago. But I don't recall which. I did have consistent problems with Agobot related agents so if there's an Agobot related rootkit betcha that's what I had.

Just installed and ran RKR 1.4 with clean results.

marty is offline  
Old 11th May 2005   #6
SuperGeek
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,307
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Ok, thanks Marty.

Regards - Charles

charlesvar is offline  



Closed Thread

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Nasty CWS I cant rid of.... psuedo IT General Security 17 21st July 2004 21:33
Hijacking gerdcurli General Security 4 15th July 2004 16:27
New Worm spreading miniB General Security 1 6th June 2003 21:10
The Big Lessons of a Litttle Worm schamish General Security 0 5th February 2003 05:36
Yaha.K worm schamish General Security 6 6th January 2003 14:55


All times are GMT +1. The time now is 22:55.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]