This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Syschost

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was given my bro's computer running windows ME and dont exactly know what is going on with it, but………….At random times an error message will pop up saying "text exceeds memo" and just keeps poping up on and on till my screen is full! I ran Process Explorer and these are the running processes

Process PID CPU Description Company Name
Idle 0x0 79.80 System Idle Process
STMGR.EXE 0xFFFB6A3B Microsoft ® PC State Manager Microsoft Corporation
KERNEL32.DLL 0xFF0FFBA3 Win32 Kernel core component Microsoft Corporation
MSGSRV32.EXE 0xFFFE3EC7 Windows 32-bit VxD Message Server Microsoft Corporation
MPREXE.EXE 0xFFFECD5B WIN32 Network Interface Service Process Microsoft Corporation
STIMON.EXE 0xFFFD7A1F Still Image Devices Monitor Microsoft Corporation
MSTASK.EXE 0xFFFD538B Task Scheduler Engine Microsoft Corporation
ATI2EVXX.EXE 0xFFFD4943
mmtask.tsk 0xFFFE964B Multimedia background task support module Microsoft Corporation
EXPLORER.EXE 0xFFFB78A3 Windows Explorer Microsoft Corporation
HIJACKTHIS.EXE 0xFFFDA60B HijackThis Soeperman Enterprises Ltd.
IEXPLORE.EXE 0xFFF7740B 3.56 Internet Explorer Microsoft Corporation
DDHELP.EXE 0xFFF7D7DB Microsoft DirectX Helper Microsoft Corporation
TASKMON.EXE 0xFFFCDD8F Task Monitor Microsoft Corporation
SYSCHOST.EXE 0xFFFBF42B 0.99
ATI2CWXX.EXE 0xFFFBDE17 ATI Common Windows Display Driver Extension ATI Technologies Inc.
ATIPTAXX.EXE 0xFFFBC883 ATI Desktop Control Panel ATI Technologies, Inc.
IRMON.EXE 0xFFFBAF73 Infrared Monitor Microsoft Corporation
SYSTRAY.EXE 0xFFFB896B System Tray Applet Microsoft Corporation
WMIEXE.EXE 0xFFF9A5AF WMI service exe housing Microsoft Corporation
HPOSTR05.EXE 0xFFFAE413 Main Executable Hewlett-Packard Co.
HPOVDX05.EXE 0xFFF986A3 14.55 VDI Manager Hewlett-Packard Co.
PROCEXP.EXE 0xFFF6F137 1.09 Sysinternals Process Explorer Sysinternals

Process: Procexp Pid: FFFFFFFE

Type Name

I have heard that some of the processes I highlighted should not be running are are trojans, virus….ect…..

Here is my hijackThis log

Logfile of HijackThis v1.99.0
Scan saved at 12:16:38 AM, on 1/6/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\WINDOWS\SYSTEM\ATI2CWXX.EXE
C:\WINDOWS\SYSTEM\SYSCHOST.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP OFFICEJET T SERIES 9X\BIN\HPOSTR05.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP OFFICEJET T SERIES 9X\BIN\HPOVDX05.EXE
C:\WINDOWS\DESKTOP\EVERYTHING\MOV\PROGRAMS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.52.208.43:8000
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [IrMon] irmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [Ati2cwxx] Ati2cwxx.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [winsys] syschost.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: HP OfficeJet T Series Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet T Series 9x\Bin\HPOstr05.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?325
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay101.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate2.exe

Please HElP!! Let me know if I need to post anything else or do something to thiss flippin' puter!


Thanks

Frank

Reboot in SAFE MODE.
Some of these files and folders might have hidden atributes.
Delete the following file(s) listed in bold
(do a search for this one. It'll probably be in c:\windows or c:\windows\system32.)
syschost.exe

Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

O4 - HKLM\..\Run: [winsys] syschost.exe


The following activeX controls( Download Program Files)will reinstall when(and if) you revisit that website,
UNLESS you know they are from a safe source, check to remove.



Then reboot and download System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

Go here and run online scans (all), allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed
Reboot when done. Rescan with HJT and post a new log here.

Also please describe how your computer behaves at the moment
Glad we could help :DDue to inactivity this topic will be closed.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI