Computer challenged - help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Happy99, Sep 5, 2007.

  1. Happy99

    Happy99 Private E-2

    I completed or at least tried to complete all the steps in the "Read & Run Me First, Malware Removal Guide."

    Attached in this post are the first three txt logs/files you had me complete and in the next post will be the following three txt logs/files you had me complete.


    I use Windows XP Home edition upgrated with that second package thing from Microsoft upgrade center, and I use McAfee for computer protection.

    I don't know very much about computers. However, I was referred here by a friend because I believe my computer is infected even though McAfee says nothing is wrong, but does tell me I was "visited."


    My questions and observations during the process:

    1.) I have CCleaner but was not aware that it had a registry cleaner - that is really neat:)

    2.) Did not do anything with the start up buttons because I just don't know enough about them to decide which to delete.

    3.) Defragmented computer with the IObit Smart Defrag downloaded program - thank you:)

    4:) I checked ADD/delete programs for any of the files listed in your "Uninstall Malware via add/remove programs" list -- I did not have any of those files listed.


    5:) Don't know how big a problem this is but ---------- Got an error message when I did the MSconfig start up mode.
    -------- I did notice however that it is in "Normal Mode"

    -------- Here is the error message I got ------- "An access denied error was returned while attempting to change a service. You may need to log on using an administrator account to make specified changes" ---- I tried to set up another Owner/admin account but I still got the same message when I tried the run>msconfig thing. So I deleted the account.



    6.) Enabled viewing of hidden files, etc.


    7.) Why is it not a good idea to download tools into any folder within "c:\documents and settings" ?


    8.) Ran the CounterSpy program and did the "Immunize" thing and got a results that says 476 files are unprotected - can I do anything to protect these files, what ever they are?

    That's it for this post - Really looking forward to your reply.
     

    Attached Files:

  2. Happy99

    Happy99 Private E-2

    2nd post - computer challenged, please help

    This is the second post with the logs/files requested in the "Read & Run Me first"



    My questions and comments on the process:

    1.) Ran the Spybot and it found 8 problems see log.

    2.) Ran Counter Spy and it found 2 items see log. Actually I ran this twice because when I tried to run Bitdefender, it crashed my computer. Ran the CounterSpy program and tried the Bitdefender again.

    3.) Bitdefender - during the second attempt it ran but its strange so I stopped it. Basically it said it was going to take about 2 hours to scan - I let it do its thing, but then when it got to time of 0:00:00 it changed to 10 hours!!!! and kept going - I let it run for a while and finally got fed up and stopped it and ran the report. It found nothing.


    4.) Ran Panda Active Scan - it found some stuff - see report - but would not delete these problems - how do I delete or get rid of these malware stuff? help:)


    5.) Read and followed the instructions for downloading and installing Hijackthis log - yup, I changed the exe file to "ananlyse.exe" - attached is the log.


    I would not blame you if you don't want to help me, maybe it would be easier to take the computer to Staples or something. I have no idea how to go about getting rid of the bugs.


    Thank you for your time in reading these two posts:)
    Happy99


    a special thanks to Gurlinthesun for recommending me to the Major Geeks site:)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do you think your PC is infected? What malware problems are you actually having?

    For a few reasons:
    1. The folder is called Documents and Settings which is where you should save documents and settings for each user account. Programs and downloads...etc are not documents or settings
    2. If you save the downloaded file in a particular user account folder, no one else using the PC will have access to it
    3. malware likes to save things here thus it could make anything you save here look suspicious. The malware could even overwrite your files.
    4. normal cleaning procedures may inadvertantly remove files you have save here. If you download something you need, it should be saved to a safe and appropriately named folder so that you and people like us reading your logs will always know exactly what it is.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: 2nd post - computer challenged, please help

    Only one item in the Panda log is an issue and you could have easily deleted the c:\windows\system32\unPPC.exe file yourself. You can still do that now.

    I repeat what bugs? You need to explain what problems you are having.

    You don't really have any major malware issues although you can delete the above mentioned file which only a minor issue since it came from your PeoplePC ISP. I will however give you a few things to do none of which are malware.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 11
    LiveReg (Symantec Corporation)
    LiveUpdate 1.80 (Symantec Corporation)
    Sunbelt CounterSpy <--- we are finished with this trial now


    Then delete the below folders which might be left behind by the uninstall:
    C:\Documents and Settings\Owner\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to WPEServ
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - (no file)
    O23 - Service: WPEServ - Unknown owner - C:\Program Files\Common Files\WPE\wpeserv.exe <--- you may not see this line now since stopping the service may have removed it.

    After clicking Fix, exit HJT
    Now reboot your PC.

    Now run Ccleaner!


    Now attach a new HijackThis log.


    Make sure you tell me how things are working now!
     
  5. Happy99

    Happy99 Private E-2

    I noticed a couple of weeks ago that the first screen on Windows was ok, but has F10 now as the reset/re-program button instead of F12, but then I got a second screen - a black screen with then Open Windows Xp on one line and the re-program/use F8 on the next line.

    so I became more aware of my computer:) Then I noticed that this last Friday when I ordered something - all of a sudden one of the buttons to download a product turned blue (like it does when I click on it) only I was downloading at the same time - then on this last Friday I got a "Visited" message from McAfee ----never had that before - but it happened when I thought I might have a neighbor using wireless to get in to my computer - why? - once (a couple of weeks ago) I was in a chat and typed in - how do you tell a new neighbor that singing and stuff can be overheard by everyone cause walls are not soundproof. - all of a sudden singing quit and tv was turned down.

    Next - on Saturday, I ordered something, heard neighbor laughing, changed the file name and heard "off comments" then "ahaha." I ran McAfee and got another "Visited" message. Also, this Saturday I noticed that the cursor arrow is now bigger and there is a real looking zipper that goes down the side of a Zipped file on my desktop - I did not change this. Oh, there are now three little dots blinking under the two little computer connections when I log on to the internet. There only use to be two before.

    All of this is probably nuts, but the fact is I have no idea except I don't want bugs and all of a sudden now I have problems based objectively by the scans suggested by Major Geeks Help post.

    I want to rid my computer of all bugs and spy stuff and adware.
    Please:)
    Thank you
    Happy99





     
  6. Happy99

    Happy99 Private E-2

    forgot to mention:

    Why am I no longer the Administrator of my own computer?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but I have no idea what you are talking about! I will say however that your logs show no malware and none of what you are talking about (which I don't follow) sounds anything like malware.

    Did you follow my instructions in message # 4?
     
  8. Happy99

    Happy99 Private E-2

    Followed #4 to the best of my ability. Since I have no idea what is going on, I guess it is hard for others to figure out what is going on. All I can say is what I see and feel.

    Do you know how I can become Owner and Administrator?

    For example, when I type in msconfig in the run command to make my computer Normal Mode, why am I not able to change anything? This is my computer, I bought it, I own it.

    Why do I get an error saying "An Access Denied error was returned while attempting to change a service. You may need to log on using an administrator account to make a specified change."

    Happy99



     
  9. Happy99

    Happy99 Private E-2

    I purchased my Compaq 7550 in 2003, I think
     
  10. Happy99

    Happy99 Private E-2

    Did I mention I have an External Hard Drive?

    Does this change stuff?

    No need to be kind - you can yell at me!
    Happy99
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know that you are not? Did you check in Control Panel, User Accounts to see what it says for your account?

    No!


    Then where is the follow up HijackThis log I requested.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds