Author Topic: C:\windows\system32\taskmon.exe  (Read 107493 times)

0 Members and 4 Guests are viewing this topic.

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #135 on: December 04, 2008, 03:42:57 PM »
RSIT Log Part 5



« Last Edit: December 19, 2008, 03:30:23 PM by paddyc »

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: C:\windows\system32\taskmon.exe
« Reply #136 on: December 05, 2008, 12:07:16 AM »
have you ever used Kaspersky? how about the klif.sys file? in cases when Kaspersky was never present on the system can't be this file present (it belongs to Kavo malware in these cases)...

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #137 on: December 05, 2008, 02:58:04 AM »
have you ever used Kaspersky? how about the klif.sys file? in cases when Kaspersky was never present on the system can't be this file present (it belongs to Kavo malware in these cases)...
Maxx

Ltangelic asked me to run Kaspersky online and it did pick up some virus - so I guess this file came from that operation?

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: C:\windows\system32\taskmon.exe
« Reply #138 on: December 05, 2008, 09:55:12 AM »
paddyc: good idea is (mentioned by Eddy, i guess) to run a repair console from the OS installation CD (or some linux distro with NTFS driver) and look for the file in "offline" mode.. but if you're not experienced in using the repair console (and "old" dos commands) it would be a risk to try something...

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #139 on: December 05, 2008, 12:40:50 PM »
paddyc: good idea is (mentioned by Eddy, i guess) to run a repair console from the OS installation CD (or some linux distro with NTFS driver) and look for the file in "offline" mode.. but if you're not experienced in using the repair console (and "old" dos commands) it would be a risk to try something...

Maxx I will try anything once...............but I do have a couple of questions before we get there.

Is it possible that I have a corrupt copy of Avast and perhaps it is seeing something that is not there? Remember that I had RPC problems that would not go away after the initail set up, which were resolved by the update but then the update started my problem off. Would an uninstall and reinstall perhaps be an option? I know that along the way we have found some viruses but none that have appeared to be dangerous or active.

Second point is that I note that some of what has been found refers back to Pinnacle. I have had a number of problems over the years with Pinnacle. The original copy of my computer software had some cd software by Pinnacle which got lost somewhere along the line. A reinstall from the reload disc brought it back up  but it got lost along the way again. later I bought a TV pro Hybrid stick with pinnacle software which worked fine but a couple of months back I tried to do an uninstall which went wrong and did not seem to clear out all the files it should have. I then uploaded new software from Pinnacle which seemed to be working fine. Later when I was having all these problems I noticed that streamserve seemed to be in constatnt use so I decided to uninstall all the Pinnacle software. I note that Dr web picked up Pinnacle Distan as a possible virus but it's main objective is to allow TV To b estreamed to another computer such as a laptop.

Short version  - is it possible that what is being picked up is some orphan files that were not properly cleared down by the Pinnacle uninstalls?

I am really stretching now ???

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: C:\windows\system32\taskmon.exe
« Reply #140 on: December 05, 2008, 12:49:20 PM »
paddyc: a fully working installation of avast should work as expected - accumulate the suspicious files in the spool folder (mentioned above) until they are sent to us (during the VPS update)... i don't know if the fresh install can make any difference, but you can give it a try..

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #141 on: December 06, 2008, 06:08:31 AM »
paddyc: a fully working installation of avast should work as expected - accumulate the suspicious files in the spool folder (mentioned above) until they are sent to us (during the VPS update)... i don't know if the fresh install can make any difference, but you can give it a try..

Maxx

Did the reinstall of Avast but the suspicious file is still showing. Did an ignore and checked the spool files again but it was still showing empty.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: C:\windows\system32\taskmon.exe
« Reply #142 on: December 06, 2008, 10:29:47 AM »
how about checking the consistency of your filesystem? try to right-click the C drive icon, select properties -> tools -> error checking -> check now (and select automatic repair of found problems).. it will do the validation of MFT and some more checking (it can take more than a moment, so be patient)...

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #143 on: December 06, 2008, 11:56:01 AM »
how about checking the consistency of your filesystem? try to right-click the C drive icon, select properties -> tools -> error checking -> check now (and select automatic repair of found problems).. it will do the validation of MFT and some more checking (it can take more than a moment, so be patient)...


Ok Maxx did that and it came up clean

I am thinking about trying to figure this thing out in reverse. We know that Taskmon.exe is the creation but it does not appear to be visible so is it hiding within something else? What viruses will cause this to happen? Are there some specific files or folders that the virus would lurk in? Can you give me a list that I can manually check and if I identify anything I will run it through virus scan before advising you.

Remember I am not a computer expert just someone trying to think logically :)

Re your thoughts on the recovery console I will give this a try if you give me specific instructions what to do. I am old enough to remember some of the dos commands and I still have a dos manual somewhere..........??

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #144 on: December 06, 2008, 11:58:23 AM »
Ltangelic,

When Dr WebCureIt says that it will move a folder does that mean delete? If not do I still have stuff that I need to kill off? I am still getting the suspicious file warning.

Ltangelic

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #145 on: December 06, 2008, 02:08:43 PM »
Hey paddyc,

Sorry for the delay. I'm going off for a year as of today due to important examinations. I have asked essexboy, another expert to take over me from now on, hope you don't mind. Apologies for the sudden leave.

Ltangelic,

When Dr WebCureIt says that it will move a folder does that mean delete? If not do I still have stuff that I need to kill off? I am still getting the suspicious file warning.

To answer your last question, if it says it will move a folder, it means literally moving it to a quarantined folder created by DrWeb. Please allow Dr Web to move the following:

Quote
stream004\strmserver.exe.184BCE29_589D_4695_8887_63F4C08E3857;C:\Documents and Settings\Paddy\Local Settings\Application Data\Downloaded Installations\{D9F82F04-BB9A-4E88-A34E-93BB52DE3F37};Probably DLOADER.Trojan;;
stream004;C:\Documents and Settings\Paddy\Local Settings\Application Data\Downloaded Installations\{D9F82F04-BB9A-4E88-A34E-93BB52DE3F37};Archive contains infected objects;;
stream004\strmserver.exe.184BCE29_589D_4695_8887_63F4C08E3857;C:\System Volume Information\_restore{B1AF6306-70F0-4416-91D0-2A49F3B95B86}\RP1\A0000014.msi\stream004;Probably DLOADER.Trojan;;
stream004;C:\System Volume Information\_restore{B1AF6306-70F0-4416-91D0-2A49F3B95B86}\RP1\A0000014.msi;Archive contains infected objects;;
A0000014.msi;C:\System Volume Information\_restore{B1AF6306-70F0-4416-91D0-2A49F3B95B86}\RP1;Archive contains infected objects;Moved.;

The rest are all legit items that can be left alone. Good luck, and hope you get your problem resolved soon!

Regards,

LT
« Last Edit: December 06, 2008, 02:12:47 PM by Ltangelic »

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #146 on: December 06, 2008, 11:59:34 PM »
Ltangelic,

Thank you for all your help! I hope the examinations go well for you - sometimes we need to concentrate on the important things in life.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: C:\windows\system32\taskmon.exe
« Reply #147 on: December 07, 2008, 12:11:37 AM »
Hi Paddy having just come in and not having read all the thread yet what is your current status ?

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #148 on: December 07, 2008, 07:26:56 AM »
Hi Essexboy,

Have run very type of malware and rootkit detectives and although we have found the odd virus we have not yet cracked what appears to make this taskmon file replicate itself. It is still doing it and Avast is still calling out the warning but oddly it is not sending a copy back to the virus lab via spooler and vtp. 

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: C:\windows\system32\taskmon.exe
« Reply #149 on: December 07, 2008, 06:10:01 PM »
Would tend to agree there paddy there are maybe two tools not yet used but I do not feel that they would add anything.  A question though (and I may have missed you doing this ) When you start and Avast has alarmed, select ignore.  Then see if the process is running in Task manager, if it is right click and select properties.  Let me know what it says.  If it does not appear in task manager then we might use sysinternals to take a look, but that can wait