I have 709 processess running on a win2k pc.
these 2 programs are repeating them selfs over and over.
844b7whatk.exe and 8wlo0jlvhs.exe/
is this a virus? I ran adware and spybot s&d and they found nothing.
I also did a google search on them and nothing.
what are they?

Dani AI

Generated

Short summary: this looks like a classic MS Blaster/Lovsan infection — the repeated, randomly‑named executables and the huge process count match that worm’s behaviour. was right to point toward a Blaster‑class worm, and ’s HijackThis suggestion helped show the many auto‑start entries that give the malware persistence; ’s symptoms (hundreds of processes, repeating executables) line up with Microsoft’s Blaster guidance. Microsoft: Blaster guidance. (learn.microsoft.com)

Action checklist (do these now, in order):

  1. Isolate the PC — unplug the network cable or disable the adapter.
  2. If the system shows a shutdown countdown, abort it quickly with shutdown /a.
  3. Try Safe Mode and run removal tools; if the machine won’t stay up, either boot a rescue disk or attach the drive to a clean machine for scanning. Microsoft explicitly recommends network isolation and using vendor removal tools. [Microsoft: recovery steps] (https://learn.microsoft.com/en-us/troubleshoot/windows-server/security-and-malware/blaster-worm-virus-alert). (learn.microsoft.com)

Removal and cleanup:

  • Run an up‑to‑date AV scan and the Microsoft Malicious Software Removal Tool (MSRT) or your AV vendor’s Blaster removal tool. MSRT can run from Safe Mode and is useful as part of removal. MSRT / KB890830. (support.microsoft.com)
  • After removal, check and remove stubborn startup entries with Autoruns (Sysinternals) rather than hand‑editing the registry blind — it shows every Run/RunOnce and scheduled task so you can remove the malware’s autoruns safely. Autoruns (Sysinternals). (learn.microsoft.com)

Final steps and cautions: install the MS03‑026/824146 fix (or the latest OS updates), enable a host firewall / block ports used by the worm (eg. TCP 135/4444 and TFTP ports), update AV signatures, and consider a clean OS reinstall if the machine was heavily compromised — Microsoft lists a full clean install as the safest recovery for a previously compromised PC. Microsoft: patch & prevention. (learn.microsoft.com)

If needed, post an updated HijackThis or the MSRT/AV scan results and note whether the machine can stay up long enough to run tools; that will help recommend the exact next step.

Recommended Answers

All 3 Replies

Do you ahve a virus scan program .If Yes do a scan ,also run the online scan in my signature .
If you want you could get HIJACKTHIS in my signature and run it don't fix anything yet
, and post a log ,
How to download and use hijackthis --

sorry took so long my friend took awhile to send me the file.
I cut out alot of the repeated files from the log already other wise it would take up alot of space.


Logfile of HijackThis v1.97.7
Scan saved at 4:59:10 PM, on 2/29/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\devldr32.exe
C:\Program Files\3dhq Tools\v_ctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\taskmgr.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\PB41\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINNT\system32\searchbar.html
O2 - BHO: TX4 - {00000000-0C95-B1F8-547A-405204D6961A} - C:\WINNT\System32\avifile32.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [xv_crtl] C:\Program Files\3dhq Tools\v_ctrl.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\Updreg.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [bkf8r4vgh0] C:\WINNT\8w1o0jlvhs.exe
O4 - HKLM\..\Run: [xy0dl5iy4t] C:\WINNT\8w1o0jlvhs.exe
O4 - HKLM\..\Run: [mcopxlwar9] C:\WINNT\844b7whatk.exe
O4 - HKLM\..\Run: [8p22sdksl2] C:\WINNT\844b7whatk.exe
O4 - HKLM\..\Run: [gji8bpvyat] C:\WINNT\844b7whatk.exe
O4 - HKLM\..\Run: [xczevuy47j] C:\WINNT\8w1o0jlvhs.exe
O4 - HKLM\..\Run: [stlgk5k1hg] C:\WINNT\844b7whatk.exe
O4 - HKLM\..\Run: [1m2m49w6f7] C:\WINNT\8w1o0jlvhs.exe


O13 - WWW. Prefix: http://ehttp.cc/?
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

You've been infected with the Blaster worm, which spawns random filename processes if one of them gets killed.

Do a search on Google for a Blaster removal tool, such as from Symantec, Sophos, etc., then PATCH YOUR BOX using Windows Update - specifically, the DCOM update.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.