Author Topic: C:\windows\system32\taskmon.exe  (Read 107469 times)

0 Members and 1 Guest are viewing this topic.

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #165 on: December 12, 2008, 03:15:26 PM »
it can't be another (similar) name, but the exact one... the files aren't read always through ntfs.sys while doing the antirootkit scan, but i don't know what can cause the difference between our driver and default ntfs driver..

Well where do I go from here?

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: C:\windows\system32\taskmon.exe
« Reply #166 on: December 12, 2008, 03:31:31 PM »
i don't know ATM.. is there any MFT validating tool?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: C:\windows\system32\taskmon.exe
« Reply #167 on: December 12, 2008, 05:17:02 PM »
The only MFT checker as far as I know is checkdisc

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #168 on: December 13, 2008, 01:53:47 AM »
Maxx,

Why would you want a MFT checker - my system is fat32 see previous email.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: C:\windows\system32\taskmon.exe
« Reply #169 on: December 13, 2008, 12:55:13 PM »
aah, you're right, sorry... hmmm are you able to access your drive in raw mode and do some lookups (WinHex should be able to do that)?

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #170 on: December 13, 2008, 03:12:43 PM »
aah, you're right, sorry... hmmm are you able to access your drive in raw mode and do some lookups (WinHex should be able to do that)?

Maxx which Winhex should I look for ? There seems to be a few of them about.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: C:\windows\system32\taskmon.exe
« Reply #171 on: December 13, 2008, 05:58:43 PM »

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #172 on: December 14, 2008, 01:01:44 AM »
http://www.x-ways.com/winhex/index-m.html

maxx can't get this loaded as the set up constantly hangs and I have to cancel via task manager.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: C:\windows\system32\taskmon.exe
« Reply #173 on: December 14, 2008, 01:21:28 AM »
Hi paddyc,

Let’s do this next to fix your Task Manager problem.

Please download from.http://www.kellys-korner-xp.com/regs_edits/taskmanager.reg and save it to your desktop
A blue-white cubicle  icon will appear..
Double-click on it and when it asks you if you want to merge the contents to the registry, click "Yes" or "OK". You should receive a message that it was successful.

REBOOT afterwards.... really important!

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #174 on: December 14, 2008, 03:00:41 AM »
Hi paddyc,

Let’s do this next to fix your Task Manager problem.

Please download from.http://www.kellys-korner-xp.com/regs_edits/taskmanager.reg and save it to your desktop
A blue-white cubicle  icon will appear..
Double-click on it and when it asks you if you want to merge the contents to the registry, click "Yes" or "OK". You should receive a message that it was successful.

REBOOT afterwards.... really important!

pol

Before I go and do that I need to report that I used internet to get a list of all known files that might be associated with taskmon and decided to check out my system and see if I found any.

Rundll32.exe was named as a possible and I have found 3 copies of it on my system. A scan with Avast produced nothing but a scan with spybot hueristics said smitfraud-c on 2 and win32.delf.rtk on the other.

I used Jotti Viruscan on system 32\rundll32.exe and this was the report

canner      Malware name
A-Squared    Trojan-PWS.Win32.LdPinch!IK
AntiVir    TR/Crypt.PEPM.Gen
ArcaVir    X
Avast    Win32:LdPinch-NO
AVG Antivirus    PSW.Ldpinch
BitDefender    Trojan.PWS.LDPinch.TIK
ClamAV    Trojan.Dropper.Agent-106
CPsecure    Troj.PSW.W32.LdPinch.beo
Dr.Web    Trojan.Packed.1197
F-Prot Antivirus    W32/LdPinch.K.gen!Eldorado
F-Secure Anti-Virus    Trojan-PSW.Win32.LdPinch.dlt
G DATA    X
Ikarus    Trojan-PWS.Win32.LdPinch
Kaspersky Anti-Virus    Trojan-PSW.Win32.LdPinch.dlt
NOD32    a variant of Win32/PSW.LdPinch.NCB
Norman Virus Control    Sandbox: W32/Malware
Panda Antivirus    Trj/Ldpinch.gen
Sophos Antivirus    Troj/LdPinch-PZ
VirusBuster    Rootkit.LDPinch.Gen.4
VBA32    MalwareScope.Trojan-PSW.Pinch.1

I then scanned windows\$NTServicePackUninstall$\rundll32.exe and this was produced by Jotti

Last file scanned at least one scanner reported something about: ChamaleonButton.ocx (MD5: a73cd21288945e3045502bd47131034e, size: 102400 bytes), detected by:

Scanner    Malware name
A-Squared    HackTool.Win32.MadMSN!IK
AntiVir    X
ArcaVir    X
Avast    X
AVG Antivirus    X
BitDefender    X
ClamAV    X
CPsecure    X
Dr.Web    X
F-Prot Antivirus    X
F-Secure Anti-Virus    X
G DATA    X
Ikarus    HackTool.Win32.MadMSN.40
Kaspersky Anti-Virus    X
NOD32    X
Norman Virus Control    X
Panda Antivirus    X
Sophos Antivirus    X
VirusBuster    X
VBA32    X

I finally submitted windows\ServicePackFiles\i386\rundll32.exe and Jotti came up with following

Last file scanned at least one scanner reported something about: Webmail_Hack_2.3.zip (MD5: c2779e69591e6351aa877f8350e6447a, size: 231849 bytes), detected by:

Scanner    Malware name
A-Squared    Trojan-Clicker.MSIL.Xone!IK
AntiVir    TR/Click.MSIL.Xone.AC
ArcaVir    Trojan.Downloader.Small.Dug
Avast    Win32:Trojan-gen {Other}
AVG Antivirus    X
BitDefender    Trojan.Generic.358370
ClamAV    Trojan.Clicker-2249
CPsecure    Troj.Clicker.MSIL.Xone.ac
Dr.Web    X
F-Prot Antivirus    X
F-Secure Anti-Virus    Trojan-Clicker.MSIL.Xone.ac
G DATA    X
Ikarus    Trojan-Clicker.MSIL.Xone.ac
Kaspersky Anti-Virus    Trojan-Clicker.MSIL.Xone.ac
NOD32    X
Norman Virus Control    X
Panda Antivirus    X
Sophos Antivirus    X
VirusBuster    X
VBA32    Trojan-Clicker.MSIL.Xone.ac

What should I do about these?  There were also a bunch of.pf files in prefetch referenced back to rundll32.exe but spybot said they were clear.

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #175 on: December 14, 2008, 04:05:47 AM »
Hi paddyc,

Let’s do this next to fix your Task Manager problem.

Please download from.http://www.kellys-korner-xp.com/regs_edits/taskmanager.reg and save it to your desktop
A blue-white cubicle  icon will appear..
Double-click on it and when it asks you if you want to merge the contents to the registry, click "Yes" or "OK". You should receive a message that it was successful.

REBOOT afterwards.... really important!

pol

Polonus this link opens text on the browser and does not offer a file to be saved ???

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #176 on: December 15, 2008, 07:25:26 AM »
Hi paddyc,

Let’s do this next to fix your Task Manager problem.

Please download from.http://www.kellys-korner-xp.com/regs_edits/taskmanager.reg and save it to your desktop
A blue-white cubicle  icon will appear..
Double-click on it and when it asks you if you want to merge the contents to the registry, click "Yes" or "OK". You should receive a message that it was successful.

REBOOT afterwards.... really important!

pol

Polonus this link opens text on the browser and does not offer a file to be saved ???

OK got this to work by using internet explorer instead of firefox!!


Can anyone help me with the rundll32/.exe problems ???

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #177 on: December 16, 2008, 02:00:14 PM »
Guys,

I really need some help to sort out this rundll32.exe problems.

I have done full scans of my system using Avast, Spybot, SAS, MBAM, Dr Web CureIt, F Secure Backlight,
including bootscan and safe mode but none of them are picking up the viruses in the rundll32.exe files.

Rundll32.exe is not showing as a running process on the computer and there does not appear to be anything going amiss with my computer.

I am tempted to simply delete the offending files using command mode but internet search says that Rundll32.exe is a required file and that it should be in windows\system 32 - which it is even though it appears to be infected. Is there a way to delete these files and reinstate a proper rundll32.exe file without screwing up my computer?

Even though the complete scans are not picking up anything, if I do a file scan using Spybot it does flag viruses on all three copies of the file.

Spybot is finding the virus via heuristics and Avast is finding Taskmon using the same technique although Taskmon does not appear to exist. Is it possible that Avast is seeing the same file but thinks it is something else?

I really need some help here as I don't know what else to try :-\

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: C:\windows\system32\taskmon.exe
« Reply #178 on: December 16, 2008, 03:56:49 PM »
The rundll32.dll doesn't show in the Task Manager if that is where you are looking, if not where are you looking (as it is an essential file used to register other dll files) ?

Effectively the only way to remove (replace it with the correct version for your OS version) it is when windows isn't running. I have never tried this and it could be fraught with danger.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

paddyc

  • Guest
Re: C:\windows\system32\taskmon.exe
« Reply #179 on: December 16, 2008, 04:52:39 PM »
The rundll32.dll doesn't show in the Task Manager if that is where you are looking, if not where are you looking (as it is an essential file used to register other dll files) ?

Effectively the only way to remove (replace it with the correct version for your OS version) it is when windows isn't running. I have never tried this and it could be fraught with danger.

DavidR,

I am not talking about a rundll32.dll I do not appear to have one of those on my hard disk. I am talking about rundll32.exe which resides in windows\system32 and two other directories. A search using explorer reveals them and then a scan of each file reveals viruses. I looked to see if this file was running in task manager, msconfig startup and services.

What I don't understand is if it's an active file and it's corrupt then why is it not affecting my system and why have none of the scanners picked it up?