This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Is This A Problem (virus Or Trojan?)

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry I have't responded Micah. But things are getting worse and I had to switch to my desktop computer. I rebooted and ran HJT. There were four instances of winmon.exe. I made it to this website and attempted to paste it here when the Net connection crashed. I reconnected but could not access any web pages. I noticed that my Norton had big red X right through. I tried rebooting again and still cannot access any web pages. I ran HJT and fixed all instances of winmon.exe. I rebooted. There is no evidence of winmon.exe. However, Norton still has a big red X through it and I still cannot access any webpages. I have the laptop next to me. There is one new file on HJK. csrss.exe It is located in windows/system folder. Is this what is preventing my Net access? Thanks again.
I googled the term csrss.exe and it said that it is only a legitimate file in the system32 folder and that any other occurrence is a virus. I check the properties of the version in the system folder and it said it was created today. ??? I still can't access the Net on my laptop. Sigh. Don't know what to do.
My bad!!! :oops: You are correct. It needs to be in the C:\windows\system32 to be legit… Can you run Hijack This! on the laptop, transfer the log file to a floppy, and post it here? :unsure:
Minor victory! I have regained control of the laptop. The laptop does not have a floppy drive and I don't have a flashdrive yet so I couldn't transfer the hijack this log.

I doubled checked the old logs that file was definitely never there before. So I deleted as I've done the others. Everything seems fine expect when I reboot Norton has the red X through it meaning the auto protect is off and forcing me to manually turn it on.

Norton is also acting up again. 2 deletes of spybot, two of Korgo and another. I have no idea where they are coming from.

Here is the newest log though it looks pretty clear:

Logfile of HijackThis v1.98.2
Scan saved at 5:23:35 PM, on 9/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\igfxext.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.computers.us.fujitsu.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.computers.us.fujitsu.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.computers.us.fujitsu.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{983F6A20-B8CF-4FF0-A4D6-BC73E06DD67D}: NameServer = 207.69.188.187 207.69.188.186
Whew!!!! :o That log looks clean. I'm sorry I popped the cork on the champagne too soon… Wait a minute folks….. The Referee has thrown a flag on the field…. :unsure: We're waiting for the call…. Oh My! Malware has just been penalized 15 yds for unnecessary roughness!!! ;) :rofl: I have to go offline for a few hours. When I return I will investigate this "korgo" you keep getting. TTFN (tah-tah-for-now) M68 :)
Korgo:

Symatec Korgo Description

Symantec Korgo Removal Tool

I don't know of anyone that has used that tool. It's your call….

I DO recommend this, however:

Clean your "temp" files.

First, CLOSE INTERNET EXPLORER!!!

Go to:

Start > My Computer > on "Local Disk C:" > choose "Properties" > Disk Cleanup, then CHECK THESE ONLY:

Temporary files

Temporary Internet files

Then click "OK"

Then turn system restore "OFF" (link provided earlier)

Run the online virus scans:

Trend-Micro:
http://housecall.trendmicro.com/housecall/start_corp.asp

Panda:
http://www.pandasoftware.com/activescan/

Etrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

Bitdefender http://www.bitdefender.com/scan/licence.php

Choose fix or clean.

Let them remove any infections found. Reboot inbetween each scan.

Run your resident virus scan & reboot.

Then, as long as NONE of the virus scans found anything they couldn't "fix" or "clean", turn system restore ON and create a new restore point:

Start > All Programs > Accessories > System Utilities > System Restore > Create Restore Point

Make a restore point & reboot.

That's about as "clean" as I'm able to get you. :)
Thanks again for all your hlep Micah_6:8. I've been working on this all night. Here is where I stand: I read the Korgo explanation from Symantec and it stresses downloading the microsoft patch or "you will continue to get reinfected." I did that. Next I updated my Norton files. Or I tried. The live update feature is not working. It all the way through installation, but there is a message at the botton that says they did not load right. Hmm. I think this has been going on since the beginning. I followed Symantec's online instructions to the point that they said uninstall the program. I did and install a boxed version of McAfee and donwloaded the most recent updates. McAfee detected two viruses (including Korgo) in the temp and temp internet folders. I then cleared out those folders and followed your instructions above (turn of system resource; online virus scans). The first three scans were clear. The fourth detected one file. So today I'm going to try again. During the few hours I spent running the scans, McAfee never beeped once. So I'm encouraged. I ran HJT after every reboot and the log (which I now know by heart) has been clear the whole time. So hopefully I can run the online scans and come back clear. Fingers-crossed.
Victory????? It may have a taken an unlikely comeback, but I've been virus free all day.

4 online scans, all negative.
Ran HJT each reboot no problems on the log

Ran Mcafee full system scan. all clear. I've reset the restore and rebooted. I haven't been online a lot today, but all the times I have no problems. Mcafee hasn't beeped, gurgled, hooted or made a peep.

System seems back to normal.

Here is my lastest scan (mcafee sure adds a lot of stuff to the computer):



Logfile of HijackThis v1.98.2
Scan saved at 8:48:37 PM, on 9/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\igfxext.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\WINDOWS\System32\1XConfig.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.computers.us.fujitsu.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.computers.us.fujitsu.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.computers.us.fujitsu.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
Glad we could be of assistance. This topic is now closed. If you wish it
reopened, please send us an email (Click here to email) with a link to your thread.


Donations in support of this Web Site are always appreciated

Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI