Click here to get back home

[System Process]:0 Virus?

 HomeNewsGroups | Search

microsoft.public.security.virus - Computer virus info for MS Windows users 

get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
[System Process]:0 Virus? Frank Martin 06-05-2009
Posted by Frank Martin on June 5, 2009, 10:14 pm
Please log in for more thread options
I have WindowsXP Pro.

Just today my internet connection has slowed right down, and
an inspection of "Windows Task Manager" shows a lot of
traffic even though I am not using any internet
applications.

I have run TCPView and there are numerous TCP protocol
addresses in a "TIME_WAIT" state, all with the process name
"[System Process]:0. All the remote addresses attached to
this process have different names, and there are about 100
of them.


Can someone help me.
Regards, Frank








Posted by David H. Lipman on June 6, 2009, 7:50 am
Please log in for more thread options

| I have WindowsXP Pro.

| Just today my internet connection has slowed right down, and
| an inspection of "Windows Task Manager" shows a lot of
| traffic even though I am not using any internet
| applications.

| I have run TCPView and there are numerous TCP protocol
| addresses in a "TIME_WAIT" state, all with the process name
| "[System Process]:0. All the remote addresses attached to
| this process have different names, and there are about 100
| of them.


| Can someone help me.
| Regards, Frank


It sounds like malware has injected a process into the kernel.

What anti virus/anti malware software have you used to scan the PC ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Frank Martin on June 6, 2009, 8:47 pm
Please log in for more thread options

show/hide quoted text



Thanks,
I have used "stopZilla", "ADaware", "Spybot search &
destroy", "Malwarebytes Anti-malware", MS
"malicious-software removal tool", also "CCleaner (with reg
cleaner)", and other reg cleaners,

Also I am running the "whatslivern" software.

This happened once before but with a different Process Name,
as as I remember I fixed this by ticking and deleting one of
the lines in the "HiJack This" lists, which was:
"F2Reg:system.ini:
Shell=Explorer.exe\C:\Windows\Config\csrss.exe.


Regards, Frank





Posted by David H. Lipman on June 6, 2009, 10:22 pm
Please log in for more thread options




| Thanks,
| I have used "stopZilla", "ADaware", "Spybot search &
| destroy", "Malwarebytes Anti-malware", MS
| "malicious-software removal tool", also "CCleaner (with reg
| cleaner)", and other reg cleaners,

| Also I am running the "whatslivern" software.

| This happened once before but with a different Process Name,
| as as I remember I fixed this by ticking and deleting one of
| the lines in the "HiJack This" lists, which was:
| "F2Reg::system.ini: Shell=Explorer.exe\C:\Windows\Config\csrss.exe.


| Regards, Frank


StopZilla - not that good aanti adware/spyware
CCleaner - not anti malware.
Reg Cleaners in general - snake oil
whatslivern - is a 2007 plagiarised version of Andrew Aranoff's Silent Runners
and if you
are going to use such software, use the orginal from the real author, Andrew
Aranoff,
which was last updated Dec. '08, revision 59. -- http://www.silentrunners.org/



Usually at this point I'd have you post in an expert forum. However, in this
case, I have
a gut feeling.

I'd like you to scan your PC using the AntiRootkit utility Gmer and to use the
McAfee and
Sophos modules in my Multi AV Scanning Tool.


http://www.gmer.net/


Download MULTI_AV.EXE from the URL --
http://www.pctip.ch/ds/28400/28470/Multi_AV.exe
or
http://212.98.39.7/ds/28400/28470/Multi_AV.exe

http://www.pctip.ch/downloads/dl/35905.asp
or
http://212.98.39.7/downloads/dl/35905.asp

English:
http://www.raymond.cc/blog/archives/2008/01/09/scan-your-computer-with-multiple-anti-virus-for-free/


To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file.



* * * Please report back your results * * *




--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Frank Martin on June 7, 2009, 1:21 am
Please log in for more thread options

show/hide quoted text
http://www.raymond.cc/blog/archives/2008/01/09/scan-your-computer-with-multiple-anti-virus-for-free/
show/hide quoted text


Thanks, I installed the Gmer software and ran it and it gave
a screen with 3 lines, though not in red. I no longer have
these (see below).

I downloaded and installed the MULTI_AV software into the
C:\AV_CLS as instructed and this subsequently gave the
coloured DOS-type window with the four sites.
The first one downloaded OK, but the second one, after a
while induced Windows error screens saying "Windows Files
are being replaced with other similar ones" and then the
MULTI_AV software froze up, and I then rebooted the
computer.

On startup the reboot stopped at a black-screen stage and
gave the error message "NTLDR not found" and so I was
locked out.

I then went to a Ghost12 backup and rebooted from the Ghost
disk and recovered the C Drive (only) of 12 April 09. All
my other partitions seem OK. But I seem to have lost all
the results of the Gmer software and any fragments of the
MULTI_AV.

The TCPView software shows the virus has disappeared too,
though this may be too soon to tell.

Perhaps this has fixed the virus?

How can I stop it coming back; this morning when it was
there there were about 200 sites being fed from my computer.

Regards, Frank









Similar ThreadsPosted
AVG Found 2 Trojan Horses in the System process! March 26, 2007, 6:23 pm
Annoying virus - can't tell what process it's associated with... July 16, 2008, 6:04 pm
task manager process hog or virus? April 4, 2007, 9:28 am
Urgent System Message; Virus --- #2 - Your computer is infect July 26, 2006, 6:20 pm
Is this a virus or something else? Disappearing folder named "system", then can't delete the parent June 6, 2006, 6:28 pm
"Internet Gateway: Disconnected" icon showing next to the system clock. What is this? Spyware, Virus or other? June 24, 2005, 5:17 pm
A problem with a process CRCAB.exe July 5, 2005, 8:55 am
Generic Host Process for Win 32 August 6, 2005, 11:29 am
Process remover/killer May 6, 2007, 9:37 pm
A new startup process SlowDowncpu.exe gets added July 19, 2005, 10:36 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

Friends:

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap
Privacy Policy