Hi I really need your help please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by wildhorses, Feb 10, 2006.

  1. wildhorses

    wildhorses Private First Class

    I did not see powerreg scheduler.exe help!Thanks and sorry for being such a sour puss:)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well either CounterSpy already removed it or the location you gave before was not correct. I'm just going by where you said CounterSpy reported it, which was:

    C:\windows\start menu\programs\start up\powerreg scheduler.exe

    What do you see in the C:\windows\start menu\programs\start up folder
     
  3. wildhorses

    wildhorses Private First Class

    all I can see is Encoder Agent,Microsoft Office and WinZip Quick Pick
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then CounterSpy or something else already removed it and you don't need to worry about it.

    Since CounterSpy has expired you should uninstall it now since it is no longer of any use to you.
     
  5. wildhorses

    wildhorses Private First Class

    Alright thanks for all your help I will delete that then take care...........
     
  6. wildhorses

    wildhorses Private First Class

    Oh no I don't know how I can remove counter spy please help??
    I looked in my add remove programs and it is not listed there?
    I looked in my programs and it is not listed there either please help mne out here:0)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do the below processes and O4 line still show in a new HJT log (look for yourself - no need to post one).


    C:\PROGRAM FILES\SUNBELT SOFTWARE\COUNTERSPY\CONSUMER\SUNSERVER.EXE
    C:\PROGRAM FILES\SUNBELT SOFTWARE\COUNTERSPY\CONSUMER\SUNPROTECTIONSERVER.EXE
    C:\PROGRAM FILES\SUNBELT SOFTWARE\COUNTERSPY\CONSUMER\SUNTHREATENGINE.EXE

    O4 - HKLM\..\Run: [SunServer] C:\PROGRAM FILES\SUNBELT SOFTWARE\COUNTERSPY\CONSUMER\sunserver.exe

    If they do not show, then it is already uninstalled.
     
  8. wildhorses

    wildhorses Private First Class

    ok so you want me to go to windows explorer and delete all of this?? Is this what I am understanding, you are probably sitting there saying what an airhead but honestly I am a total moron when it comes to this computer stuff ask me anything about nursing and I would have answers but ask me about computers and I am clueless!!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I just said do they show in a new HJT log scan?

    If they do, the program has not been uninstalled and should be in Add/Remove programs.

    If they do not show, it is probably uninstalled already.

    Okay! Define in laymens terms: foramen magnum
     
  10. wildhorses

    wildhorses Private First Class

    Ha ha ha...........this means a very large hole in the skull???Why the question?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because you said you knew about nursing. ;)

    Close enough but for the other people reading who wonder what the heck. The foramen magnum is the large hole at the base of the skull thru which the spinal cord passes.
     
  12. wildhorses

    wildhorses Private First Class

    can i just send you my hjt log??I am getting frustrated and frankly I may have to go to ezboards to help me out as they are not very sarcastic there.......Thanks again and sorry for bothering you:(
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excuse me.....who is being sarcastic?
     
  14. wildhorses

    wildhorses Private First Class

    If you wanted me to go into more detail about my nursing I would have, but that is irrelevant here! I am here for help for my Pc I was hoping that you can make it easy on me and let me send in my hjt log........Thank you.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you ever here of joking around! Lighten up! You brought it up and I was just trying have some fun. It was not meant as a dig.

    We have made it easy on you all the way along. We have been allowing you to post logs without attaching them and this is not the way we do things. By now you should be attaching your own logs like everyone else. You have been treated very nicely so I don't understand why you should react the way you have.

    Are you saying you do not even have the ability to look at your HJT log for the lines I gave you and find them yourself.
     
  16. wildhorses

    wildhorses Private First Class

    how about I go back and start all over I am sorry for the attitude it is just that I want to take this counter spy off my system..........yes, i did here about joking around the computer is just making me frustrated and I just want to throw it across the room.Sorry again for the bad attitude and thanks for the priveledges:)
     
  17. wildhorses

    wildhorses Private First Class

    the complicated thing is that I see it at
    04-HKLM\\Run:[sunserver]C:pROGRAM FILES\SUNBELT SOFTWARE\COUNTER SPY\CONSUMER\sunserver.exe
    what do I do to this??
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that indicates that a process is trying to load at startup? But do you see the below items running in the HijackThis process list (the top section of a log before the R0 & R1 lines is a process list).

    C:\PROGRAM FILES\SUNBELT SOFTWARE\COUNTERSPY\CONSUMER\SUNSERVER.EXE
    C:\PROGRAM FILES\SUNBELT SOFTWARE\COUNTERSPY\CONSUMER\SUNPROTECTIONSERVER.EXE
    C:\PROGRAM FILES\SUNBELT SOFTWARE\COUNTERSPY\CONSUMER\SUNTHREATENGINE.EXE

    It is important that we don't just fix things if the program is still installed. That would leave many things lying around in the registry. It is always best to use a programs uninstall capability first.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still are not sure what to do, please follow the below steps so I can determine what is installed and what is not installed.


    Run HijackThis, click Open the Misc Tools section
    Click "Open Uninstall Manager"
    Click "Save List" (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment.

    From this I should be able to see if CounterSpy is still installed.
     
  20. wildhorses

    wildhorses Private First Class

    here is my hjt for your review thanks alot I really do appreciate all the help you have given me some times I can be such a sh*t head I am sorry!:confused: :eek: :)
     
    Last edited: Mar 10, 2006
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well based on the last HJT log, it would appear that CounterSpy was uninstalled but left an O4 line behind.

    Run HJT and select the below line and then click Fix.
    O4 - HKLM\..\Run: [SunServer] C:\PROGRAM FILES\SUNBELT SOFTWARE\COUNTERSPY\CONSUMER\sunserver.exe

    Then exit HJT. Then use Windows Explorer to see if the below folder exists. If it does, just delete it.
    C:\PROGRAM FILES\SUNBELT SOFTWARE

    Are you having any other malware problems?
     
  22. wildhorses

    wildhorses Private First Class

    Great!! Thanks for a;ll your help it is off my system I really appreciate all your help!!:)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     
  24. wildhorses

    wildhorses Private First Class

    I will be back if and when I happen to have any more problems but it seems that everything is ok:) Thank you for all you kindness in helping me:)
    This forum rocks!:)
     
  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Glad things are running good for you!

    Surf Safely!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds