What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » Block-Checker

Block-Checker
Author: Message:
CookieRevised
Elite Member
*****

Avatar

Posts: 15519
Reputation: 173
– / Male / Flag
Joined: Jul 2003
Status: Away
RE: Block-Checker
quote:
Originally posted by Fergy
thanks cookie. When i did it, blockchecker.exe was a branch of the fake csrss.exe, perhaps i killed the blockchecker.exe process first and the csrss process restarted it.
yep, indeed... as explained in Segosa's post, csrss.exe constantly checks for blockchecker.exe. If blockchecker.exe is killed it is restarted again by csrss.exe. Hence you need to kill csrss.exe first ;)

(btw, I modified your step-by-step instructions and posted it on mess.be; I will also repeat it here, so I can update it if needed)






-----IMPORTANT---------------IMPORTANT---------------IMPORTANT---------------IMPORTANT-----


How to remove the "Block Checker" malware correctly
Originally composed by Fergy here and further modified by CookieRevised


Step 1: Killing the processes
  • Download Sysinternals' "Process Explorer" here and install it.
  • Open Process Explorer and kill "csrss.exe" first.
    To avoid killing the wrong csrss.exe process, look at the "User Name" column which lists who has started the process.
    If it is "SYSTEM" or "NT AUTHORITY" or the likes, then it means it is the legit windows process started by Windows itself and shouldn't be killed. If it is your username/computername then it means the csrss.exe process has started up as a normal user program and thus is not legit and the fake one. This is the one you need to kill...
    In Process Explorer, you can also look at the path of csrss.exe (right click on it and choose "Properties"). If it is "C:\Program Files\Block Checker" then it is the fake one.
  • While still in Process Explorer, kill "block-checker.exe" if it is still there.

Step 2: Removing the files
  • Uninstall the block checker by going to "Add/Remove Programs" in the control panel.
  • Go into "C:\Program Files" and delete the folder labelled "Block Checker" (where C:\ is the drive you installed Windows on) if it is still there.
  • Delete the "exclusion_AOL.ini", "exclusion_MSN.ini" and "exclusion_Yahoo.ini" files located in windows' system folder (C:\Windows\System).
  • Clean out your recycle bin to totally remove the files from your HDD.

Step 3: Fixing the registry
  • Open your registry editor (Start > Run > regedit.exe) and navigate to "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" and delete the key named "block-checker".
    (For a small tutorial on this, go to this site, because deleting the wrong keys could corrupt Windows).
-------

Note 1: The reason why you need to use a program like Process Explorer to do this is because the Windows Task/Process Manager itself could refuse to kill "csrss.exe" as it could think it is a legit system process. Also, not all Windows versions have a Task/Process Manager that is able to kill processes.

Note 2: Do not use MSCONFIG to delete startup entries. This will NOT permanently delete the startup entries, and above all Windows will use an alternative boot sequence to start up. This boot sequence is easly switched back by accident and the things you wanted deleted will be put back! If you must use a program to alter the registry, then use a program like AutoRuns (this program will also list ALL the startup entries that exist in Windows; MSCONFIG seriously lacks an extreme large amount of such entries).

Note 3: (technical) info of what this malware exactly does can be found in Segosa's reply.



-----IMPORTANT---------------IMPORTANT---------------IMPORTANT---------------IMPORTANT-----

This post was edited on 08-25-2005 at 08:52 PM by CookieRevised.
.-= A 'frrrrrrrituurrr' for Wacky =-.
08-21-2005 05:19 PM
Profile PM Find Quote Report
« Next Oldest Return to Top Next Newest »

Messages In This Thread
Block-Checker - by mwe99 on 08-17-2005 at 03:29 PM
RE: Block-Checker - by absorbation on 08-17-2005 at 03:31 PM
RE: Block-Checker - by mwe99 on 08-17-2005 at 03:32 PM
RE: Block-Checker - by ~INVASION~ on 08-17-2005 at 03:34 PM
RE: Block-Checker - by mwe99 on 08-17-2005 at 03:36 PM
RE: Block-Checker - by Millenium_edition on 08-17-2005 at 03:41 PM
RE: Block-Checker - by mwe99 on 08-17-2005 at 04:04 PM
RE: Block-Checker - by toddy on 08-17-2005 at 04:05 PM
RE: Block-Checker - by segosa on 08-17-2005 at 04:17 PM
RE: Block-Checker - by Concord Dawn on 08-17-2005 at 04:33 PM
RE: Block-Checker - by zaher1988 on 08-17-2005 at 04:36 PM
RE: Block-Checker - by mwe99 on 08-17-2005 at 04:41 PM
RE: Block-Checker - by segosa on 08-17-2005 at 04:45 PM
RE: Block-Checker - by mwe99 on 08-17-2005 at 04:47 PM
RE: Block-Checker - by zaher1988 on 08-17-2005 at 04:48 PM
RE: Block-Checker - by guanako on 08-17-2005 at 05:14 PM
RE: Block-Checker - by mwe99 on 08-17-2005 at 05:16 PM
RE: Block-Checker - by Millenium_edition on 08-17-2005 at 05:29 PM
RE: Block-Checker - by mwe99 on 08-17-2005 at 06:06 PM
RE: Block-Checker - by CookieRevised on 08-17-2005 at 06:07 PM
RE: RE: Block-Checker - by kipper2258 on 08-20-2005 at 03:31 PM
RE: Block-Checker - by Joa on 08-17-2005 at 06:51 PM
RE: Block-Checker - by Fergy on 08-19-2005 at 05:50 AM
RE: Block-Checker - by segosa on 08-19-2005 at 09:40 AM
RE: RE: Block-Checker - by CookieRevised on 08-19-2005 at 12:06 PM
RE: Block-Checker - by Fergy on 08-19-2005 at 02:44 PM
RE: Block-Checker - by Val on 08-21-2005 at 04:11 AM
RE: Block-Checker - by Fergy on 08-21-2005 at 04:06 PM
RE: Block-Checker - by CookieRevised on 08-21-2005 at 04:41 PM
RE: Block-Checker - by Fergy on 08-21-2005 at 04:54 PM
RE: Block-Checker - by CookieRevised on 08-21-2005 at 05:19 PM
RE: RE: Block-Checker - by selene on 08-26-2005 at 02:56 PM
RE: Block-Checker - by Fergy on 08-21-2005 at 05:29 PM
RE: Block-Checker - by qgroessl on 08-22-2005 at 01:46 AM
RE: Block-Checker - by mwe99 on 08-22-2005 at 02:10 AM
RE: Block-Checker - by qgroessl on 08-22-2005 at 03:23 AM
RE: Block-Checker - by Lou on 08-22-2005 at 03:35 AM
RE: Block-Checker - by ~INVASION~ on 08-22-2005 at 03:56 AM
RE: Block-Checker - by qgroessl on 08-22-2005 at 04:07 AM
RE: Block-Checker - by Fergy on 08-22-2005 at 04:19 AM
RE: Block-Checker - by CookieRevised on 08-22-2005 at 09:35 AM
RE: Block-Checker - by Sunshine on 08-24-2005 at 10:12 AM
RE: Block-Checker - by Idium on 08-24-2005 at 10:34 AM
RE: Block-Checker - by saralk on 08-24-2005 at 10:47 AM
RE: RE: Block-Checker - by segosa on 08-24-2005 at 02:50 PM
RE: Block-Checker - by Idium on 08-24-2005 at 02:15 PM
RE: Block-Checker - by ShawnZ on 08-24-2005 at 02:29 PM
RE: Block-Checker - by CookieRevised on 08-24-2005 at 03:34 PM
RE: Block-Checker - by Fergy on 08-24-2005 at 04:34 PM
RE: Block-Checker - by Idium on 08-24-2005 at 05:50 PM
RE: Block-Checker - by kipper2258 on 08-24-2005 at 09:35 PM
RE: Block-Checker - by lui2603 on 08-24-2005 at 11:51 PM
RE: Block-Checker - by Fergy on 08-25-2005 at 04:34 AM
RE: RE: Block-Checker - by CookieRevised on 08-25-2005 at 04:48 AM
RE: Block-Checker - by kipper2258 on 08-25-2005 at 03:49 PM
RE: Block-Checker - by Fergy on 08-26-2005 at 03:55 PM
RE: Block-Checker - by selene on 08-26-2005 at 04:05 PM
RE: Block-Checker - by segosa on 08-26-2005 at 04:37 PM
RE: RE: Block-Checker - by selene on 08-31-2005 at 01:31 AM
RE: Block-Checker - by benjyrama on 08-27-2005 at 11:53 AM
RE: Block-Checker - by CookieRevised on 08-27-2005 at 04:06 PM
RE: Block-Checker - by underacloud11 on 09-04-2005 at 10:01 PM
RE: RE: Block-Checker - by CookieRevised on 09-05-2005 at 04:46 AM
RE: Block-Checker - by daveok on 09-19-2005 at 06:06 AM
RE: Block-Checker - by jiz on 03-07-2006 at 01:04 AM
RE: Block-Checker - by Ladylibra_10 on 04-12-2006 at 05:30 AM
RE: Block-Checker - by NiteMare on 04-12-2006 at 06:16 AM
RE: Block-Checker - by adam9106 on 05-21-2006 at 07:15 PM
RE: Block-Checker - by Beabees on 08-03-2006 at 06:57 PM
RE: Block-Checker - by ryxdp on 08-09-2006 at 06:32 AM


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On