Solved

Virus - Shutsdown Process Explorer/IE if go to virus website/pc-cillian

Posted on 2004-09-23
11
1,061 Views
Last Modified: 2013-12-04
I seem to have a virus on my 233MHz PII Win2K Pro system.

pc-cillian causes the virus to hog all cpu time so that anti-virus software will not run.  The process viewer under task manager is a gray screen.  Hijackthis is terminated as soon as it starts.  Process Explorer will not start.  Internet explorer will shutdown if I try to go to an virus related website.  Regedit will not run.  The virus retains these abilities if I go to safe mode.  Ad-aware does not find anything.  As long as I don't try to remove the virus, it lets the system run as normal only slower.  If you try to remove it, the system grinds to a halt due to cpu usage going way up.  Task manager will let you kill a user program and monitor cpu usage.  Only the process termination screen is affected.  I am having to use my laptop to type this message.

I downloaded the gaobot virus removal tool from norton and changed the file name and executed it from a floppy.  It did not find the virus on the system.  

Basically, I can't identify the virus so as to try to remove it from my System.

Help,
Lanny
0
Comment
Question by:LannyP
  • 6
  • 5
11 Comments
 
LVL 65

Expert Comment

by:SheharyaarSaahil
Comment Utility
Hello LannyP =)

Can u think abt Slaving ur hard drive in another system, and then perform a virus scan on it to delete all viruses present on it, or manually delete the infected files if u know abt them :-?
U can also use Stinger for cleaning ur system >> http://vil.nai.com/vil/stinger
0
 

Author Comment

by:LannyP
Comment Utility
I do not have another system to slave the hard drive into.  I was able to get to the stinger site and execute the stinger program.  It has been running 30 minutes and has not found the virus.  I will let you know the results when it finishes scanning.  Thanks
0
 

Author Comment

by:LannyP
Comment Utility
Stinger finished scanning and found 164750 clean files -- no virus!  Of my problem is still there.  New info -- I found a list of files in the /winnt/system32/drivers/etc/hosts file that were directing my IE to dns not found errors.  I elimated the extra entries and made the file read-only.  The virus does not seem to be able to change the file again after the read-only status.  IE will still shutdown if I visit certain websites.  Hope this info helps.  LannyP
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
Comment Utility
hmmmmm do this, in IE>Tools>Internet Options>Advanced>untick Enable Third Party Browser Objects
apply and check ??

Also Download HijackThis v1.98.2 from here, run it and Save the LOG file:
http://tools.radiosplace.com/HijackThis.exe

Then Post the log at this site >> http://www.hijackthis.de/index.php?langselect=english
and it will automatically analyse it for u,,, Fix everything which it labels as Nasty :)
To Fix, check the lines and click on Fix Checked !!

But if still u cannot get it working, then Post here that LOG file, and we will tell u that what is BAD in it and how to remove them :)
0
 

Author Comment

by:LannyP
Comment Utility
I can get to radiosplace.  If I try to open HiJackthis immediately; it is simply terminated.  I can download it to my drive ok.  When I try to execute it from my drive it is terminated as soon as it starts.

I have removed viruses before but this thing is horrible.
0
Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

 
LVL 65

Expert Comment

by:SheharyaarSaahil
Comment Utility
when u download msconfig from here >> http://www.perfectdrivers.com/howto/msconfig.html
and try to open it, does it open ??

if u can open it, then goto Startup section, and untick all applications except ur Antivirus and firewall softwares, reboot and now check if u can run hijackthis or not,,,, ror try it in safemode !!
0
 

Author Comment

by:LannyP
Comment Utility
msconfig.exe is killed just like Hijackthis.  The window flashes as it is trying to startup but then the process is terminated.
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
Comment Utility
hmmmmmmmm that means u are having this problem =\

Task Manager, MSCONFIG, or REGEDIT disappears while opening:
http://www.mvps.org/sramesh2k/ToolsQuit.htm
( site credit goes to Ramesh >> http://www.experts-exchange.com/M_926622.html :)
0
 

Author Comment

by:LannyP
Comment Utility
=< Close but not quite the same problem.  In the examples on the tools quit page the taskmgr.exe file is terminated.  On mine the taskmgr.exe runs.  You can access the the applications and performance tabs fine.  The process tab is just a gray window.  The other files hijackthis, msconfig, process explorer are simply terminated immediately.  Anyway I can change the name of any of the files and the virus still knows what they are and reacts like the nasty virus it is.
0
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 500 total points
Comment Utility
U didn't tell me abt the safemode results,,,,, coz if in Normal mdoe a background process is causing these problems,,,, in safemode it will be not there,,,, so these problems shudn't occur there !!

and if it Does occur there,,,, then we are in trouble,,,, coz not Antivirus is picking it up, we dont know abt this virus so we can manually search for its variant files,,,,, we will get stuck !! =\
0
 

Author Comment

by:LannyP
Comment Utility
Success!!!!  I downloaded "Security Task Manager" and opened it from the website.  This allowed the program to start from the zipfile which the virus could not detect.  I used this program to kill all unknow processes.  Now my anti virus software could run.  The Culprits were w32.spybot.worm / backdoor.hacarmy.c  /  and  backdoor.core.flood

Thanks for your help!!!! =)
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Join & Write a Comment

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now