Stumped

Discussion in 'Malware Help (A Specialist Will Reply)' started by texasharper, Sep 14, 2007.

  1. texasharper

    texasharper Corporal

    I am following the steps in the read & run me first guide and I am currently at a stand still. In step 1. it says to empty any quarantine files from AV applic.

    I have Avast 4.7 HE and I don't know where to go to find the files to delete.
    I've clicked on chest and don't find an option there. I also went to logs and found a bunch of files in the warning sub-group, however, didn't see an option to delete.

    Please help soon, the only time I can work on this is at night after the hellions have passed out ( I have been working on this for weeks, if that gives you any indication of my quality of concentration when they are awake!!).


    Thank you!
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just skip this step for now, I will post our initial instructions for you as a reference.

     
  3. texasharper

    texasharper Corporal

    Do you need to see screenshots fron Ccleaner, because I have done the cleaning and registry and Iobit defrag. but I can't figure out how to copy and paste to get it on here for you to see. And even if you dont need to see these reports or files I know you will need to see others. Can you advise?
    Also I have enabled viewing of hidden files. So I am at step 5.

    If you couldn't tell already....I am very computer illiterate!!! Please have patience ( I am sure you hear this request often).

    About to start on step 5.
    TIA


    ETA: Went to HJT and saw instructions for uploading, Sorry.
     
    Last edited: Sep 15, 2007
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    No! The only logs I need are the ones requested in my previous post.

    • CounterSpy Log - only for Windows XP, 2K, & NT users
    • AVG Antispyware Log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • Bitdefender Log - from step 6
    • Panda Scan Log - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis Log
     
  5. texasharper

    texasharper Corporal

    bjgarrick, may I ask how long it usually takes for a novice to complete this procedure....steps 0 thru 9 or 10? Also, when I need to stop working on it (like right now) should I go back to folder options and re-hide my system files?
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The online scans are the most time consuming part, I would estimate a few hours for everything.

    No! You don't have to if you're going to resume soon.

    Keep in mind, if you have ran a certain scan and have logs from it then a delay in posting can cause problems such as the infections mutating and changing names so it's best to run the whole process at once if possible.
     
  7. texasharper

    texasharper Corporal

    I can't imagine getting through the whole process at once, even if I didn't have the hellions!:D I am very intimidated by it all.

    I don't know if I am infected or not. Today there was an error box saying Scnex.exe had an error and would have to close and did I want to report to Microsoft. When I clicked on send report it acted as if I hadn't done a darn thing and kept popping back up!

    Also occasionally, screens will start to fan or cascade slowly like a deck of cards. Is that an infection?

    Thanks for a reply...I will start were I left off tomorrow.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The file "Scnex.exe" is related to RedHand Pro, a invisible key logger that records every keystroke along with the window title of the window or program you are using.

    I would go ahead with the steps, because even if this is this is false I would still run them to be 100% sure.
     
  9. texasharper

    texasharper Corporal

    when trying to install and run counterspy I get a windows message saying "the system administator has set poloicies to prevent this installation" what do I do?
     
  10. texasharper

    texasharper Corporal

    Is activity on this site slow on the weekends?
     
  11. texasharper

    texasharper Corporal

    counterspy

    when trying to install and run counterspy I get a windows message saying "the system administator has set policies to prevent this installation" what do I do? I've gone to user accts. I am admin for this computer!
    :eek:
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: counterspy

    First, be sure the account you’re logged in under has Admin privileges, if it does not then login in under one that does and try again.
     
  13. texasharper

    texasharper Corporal

    Re: counterspy

    did that...no go!
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: counterspy

    The user account your logged in under, does it have Administrator privileges?

    If it does, then skip this step for now.
     
  15. texasharper

    texasharper Corporal

    Re: counterspy

    yes it does. I'll skip it. You sure I'm not skipping too much? Will this long endeavor be accurate?:confused
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: counterspy

    You are only skipping CounterSpy correct?

    Run all of the steps you can, attach what logs you can and we will go from there.
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I didn't realize you had another thread, I have merged your threads to your initial thread so please post here now. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds