I need help even before I get started.

Discussion in 'Malware Help (A Specialist Will Reply)' started by fillip, Mar 6, 2006.

  1. fillip

    fillip Private E-2

    Hello, folks....

    I've tried and tried, and can't get attachments attached.

    I read the instructions, but I haven't been able to make it happen.

    Can someone please run me through the process...in small steps, using words of few syllables?

    Many thanks.

    fillip
     
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Welcome to MajorGeek's fillip.:) You haven't said if the attachments are not uploading or if you are just having difficulty following the directions:confused: As I'm not sure what the issue is, take a look at this and see if it helps.
     
  3. fillip

    fillip Private E-2

    Hi, AbbySue...

    Thanks a lot for your reply.

    I've printed your item about attachments, and it may take a while before I get the hang of it, but I'm going to practice, and I may be able to post today.

    If not...as soon as I get it right <grin>

    I disabled my popup blocker, and hope that helps.

    Again, thanks.

    fillip
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    fillip,

    If you still have trouble attaching files, just copy and paste them inline your post and I will convert them for you.
     
  5. fillip

    fillip Private E-2

    Hello, folks...

    I’m not certain whether I have a computer problem, or an individual program problem.

    My concern centers around what appears to be peculiar to Quicken Basic 2006, but I believe it may have gone beyond that.

    This past Friday I ran all of my anti-malware programs, and Avast came up with a Trojan named Win32AgentJB, which I deleted.

    The next day I noticed the problem with Quicken, which showed itself as all investment account balances being set to 0, in both the report and individual account registers. The data in each is intact.

    I ran several online scanners, and Trend Micro found 2 Trojans; namely, Troj-se.112843, and Troj-se.112844. (Not sure I “spelled” these correctly).

    Before deleting them, I wanted some info, so I clicked on a link, but when I tried to return to the delete window, it had disappeared. My fault, no doubt, but that’s not much help <grin>.

    I ran the scan again, but Housecall said my computer was clean. So I don’t know if I’d had a false positive, or if the Trojans are still lurking on my machine somewhere.

    Another thing I’ve noticed is that when I click on some sites in Google (including this one) nothing happens, but if I type the URL into the address window, I can get onto the site.

    On the Quicken forum site, it seems that each time I click on a button, I keep getting looped to a login page, and lose all the info I’ve tried to post. So far, it’s the only site on which I’m having this experience. In other words, I mostly can’t post in Quicken's forums.

    I hope this info is relevant.

    Now, about this post...

    I did all the stuff you said to do, but I have a couple of questions:

    I had been running Counterspy, but at your suggestion I installed Windows Defender. I noticed that its system tray icon had a question mark attached to it, and I wondered if that was normal.

    However, when I uninstalled Counterspy, the Defender icon disappeared from the system tray, as did the Zone Alarm icon. I managed to get the ZA icon back, but not the Defender icon. Is that normal? The program says that Real-time protection is active.

    Below are the reports you requested. The scans were performed in Safe Mode.

    After running Panda Active Scan, there was no report to save. Their help file implied that it generates such a report only if it finds something---it didn’t.

    Here’s the computer info you asked for:

    OS=Windows XP Home Edition with SP2, version 5.1.2600/Build 2600.
    CPU=Intel P4, 2.6 GHz.
    Hard Drive=80 GB Deskstar(?) (C: 40 GB; D: 40 GB).
    RAM=512 MB.

    I hope this isn’t a waste of your time.

    I intend to try presenting this problem on the Quicken forum site, if I can get past the hurdles.

    Hopefully, you folks can help.

    Many thanks.

    Fillip

    P.S. I expected to see the logs in this window, (they're in the "Attach Files"
    section, and I don't know how to get them here).

    When I tried previewing this post, I received a message saying
    "Invalid post specified. If you followed a valid link, notify the
    Administrator".

    I'm afraid I don't know what I'm doing wrong, but I'll try submitting
    this anyhow, and perhaps I can get the logs to you later, with some
    help.
     

    Attached Files:

  6. fillip

    fillip Private E-2

    Well, I'll be darned!

    Hi, bjgarrick....

    I didn't see your message until after I had tried posting mine.

    I thought I had sent this just now, but I don't see it, so I'm trying again.

    It was most surprising to see my message posted, because my indications were that it hadn't been.

    It was also surprising to see my attachments. I must have done somethng right for a change without realizing it.

    I tried your suggestion to paste them into my post, but I got a message that they weren't formatted for the clipboard.

    At any rate, I thank you for your help.

    With any luck, I'll learn how to do all this stuff.

    fillip
     
  7. fillip

    fillip Private E-2

    Hello, bjgarrick...

    I was disappointed not getting a response to my last post.

    I had "pre-recorded" it in Word, and perhaps I should have addressed it to you.

    At any rate, I apologize if I've violated any protocol.

    I'm adding this post because I must have been sleepwalking during my last session here. It wasn't until after I turned my computer off, that I realized I had been having the same experience here as with the Quicken site.

    I kept getting messages that I might be in the wrong thread, that I may not have privileges to be on this page; and others. And I kept getting looped to a login page. I'm rather surprised that I was able to post at all. and it took several tries.

    Earlier today when I checked in to my DSL provider (Verizon) I saw that on the page I requested--instead of saying "Hello, <myname>", it said "Welcome vzer7bpl". If I switched back to the Start page, I was addressed correctly.

    Also, the message count said "0 messages, 1 unread." Duh?

    I decided to run my anti-malware programs again, which consist of Avast! AV, Windows Defender, Spybot S&D,TrojanHunter, Ad-Aware SE Pro, and Spy Sweeper.

    Avast! found two entries of the same virus/worm---Win32CTX.

    It found the first one on it's own, and the second while I was running Windows Defender.

    These were located in c:\windows\system32\activescan\pskavs.dll, and
    c:\system volume information\_restore {2D5B244C-E9F3-45F)-8F74}.

    With regard to the second one, it probably should read c:\system\volume information\...but my notes show it as I wrote it here.

    Then I went into Safe Mode, and ran Bitdefender, Panda, and Kaspersky.

    Either Panda is in trouble, or it did things to my machine, because the progress bar never moved, and the number of files remained at 0.

    Yet it said that I was clean. (The drive light indicated activity, but now I have to wonder--what kind?)

    I think I have more trouble than I thought, and I sure hope that "help is on the way."

    Thanks.

    fillip
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  9. fillip

    fillip Private E-2

    Unfortunately, Ewido came up empty.

    Last evening I ran Housecall again, and the two Trojans I mentioned appeared again:

    Troj_SE.112843, and Troj_SE.112844

    This time I tried deleting them, but got the message that there was no info about them, and that they couldn’t be deleted. Housecall referred to them as grayware; a term I’d never heard before.

    My face is a little red about the problem I thought I had with Verizon. I called them earlier today, and the strange "name" I was seeing is a Verizon ID.

    My Ad-Aware version isn't Pro; it's Plus.
     
  10. fillip

    fillip Private E-2

    I forgot the Ewido report and HJT log, and tried sending them here, but the "Manage Attachments" window won't show.

    My browser has popups unblocked, so I don't know what the problem is this time.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds