My computer is infected please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by gps, Aug 25, 2008.

  1. gps

    gps Private E-2

    Please help me. 2 days ago I went to check my hotmail account, internet explorer was already open and when I went to open a new window the computer started beeping and the screen turned multiple pastel colors and removed my backround pictures. I closed everything and shut down the computer, when i restarted it the same multiple colored backround was there, i was able to reset my original background, however after anywhere from a few minutes to a half hour i was not able to run any programs and at one time the computer crashed. I have Mionet for mybook external hard drive and everytime it asked me to connect is when the system seemed to start going crazy. I did try and remove this, but I am not sure if it helped. I tried to run spybot search and destroy, but it did not seem to correct the problem. I also tried to do a system restore and that failed as well. Then I proceeded with your Windows XP Cleaning Procedures and attched are the logs that you request for help.( i will need to attach the 4 log in another message) Also when I try to shut down the computer a window comes up with "SheWconHiddenWindow" still running, even after performing all the cleaning procedures.
     

    Attached Files:

  2. gps

    gps Private E-2

    Attached is my MGlogs.zip log.
     

    Attached Files:

  3. gps

    gps Private E-2

    Can someone please review my logs and let me know how I should proceed.
    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should have read all of the sticky threads. See this: Don't Bump! It Only Hurts You!!! This post cost you another day.

    Now as to whether you are infected or not the answer is no. You just have a lot of unnecessary junk running and you did not disable Spybot's Teatimer as requested in the READ & RUN ME. If you want to cleanup the junk, just do the below.

    First see this How to disable Spybot's TeaTimer and disable Teatimer.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    Optionally fix the below items from Dell which you don't really need
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    After clicking Fix, exit HJT.

    Delete the below file:
    C:\WINDOWS\system32\2163131295.dat

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 28, 2008
  5. gps

    gps Private E-2

    First, let me thank you for your valuable time and expertise. Sorry for my mistakes, I truely tried to follow all your Read and run me 1st advice. I followed all of your instructions below, however I ran C:\MGtools.exe before I realized I was supposed to run C:\MGtools\analyse.exe ( had a hard time finding it, stupid I know, hope I didn't screw things up) I then ran C:\MGtools\analyse.exe and fixed what you had written except I did not see:
    04 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    I completed the rest of your instructions. Got a success message about adding to the registry.

    The computer seems to be ok, much better than before. I still get a pop up window when I try to shut down my computer with "SheWconHiddenWindow" still running ...., is this something to be concerned about?
    Also I was reading your section on how to protect your computer and did not see how you rated McAfee or should I go with another program for virus and firewall protection?

    Attached is my C:\MGlogs.zip

    Again thanks so much for all your help, I really appreciate it.
     

    Attached Files:

    Last edited: Aug 27, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No! It is not malware. It is just from some program/process you are running. You could experiment on yyour own with disabling various programs from running to see if you can find out which one. Also check to see if it occurs in safe boot mode which it may not. However this is not a topic for this forum.

    Rating protection programs is not the goal of that link. It just shows you how you can protect yourself and that you can even do it for free. If you are happy with McAfee's Security suite and don't mind how it slows your PC down then keep. We don't believe any security suite should ever be used because they are all resource hogs and many things in them are just not needed.


    It is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. gps

    gps Private E-2

    Thanks again for your time and expertise. Everything is working great.:)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds