Need some help... Hijack log included

Discussion in 'Malware Help (A Specialist Will Reply)' started by rage66621, Sep 20, 2006.

  1. rage66621

    rage66621 Private E-2

    Ok so my computer is starting to act pretty wierd. First of all on my quickstart icons I have one that says extender resourse moniter... don't know where it came from, just showed up one day. I don't know how to get rid of it. Also everytime I turn my computer on now it runs really slow for about five minutes. Well I opened my task manager and something called wmccds.exe is running and taking up all the memory usage. For user name it says Network Service. I don't know where this came from, it just started happening about 2 weeks ago. Well this morning I got on my computer and every site I went to it didn't matter what I clicked on, whatever I did click on just opened a little pop up window for internet explorer help. Well I closed all the windows down then like 35 windows would just start opening on their own and then close and they just kept doing it over and over again. I had to restart my computer. Anyways, I have no idea what to do and I hope someone will be kind enough to help.

    Here is my hijackthis log

    Edit by chaslang: Inline HJT log removed!
     
    Last edited by a moderator: Sep 21, 2006
  2. rage66621

    rage66621 Private E-2

    anybody?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. rage66621

    rage66621 Private E-2

    Ok sorry about not going through all this stuff before, I have now though and here are the first 3 logs.
     

    Attached Files:

  5. rage66621

    rage66621 Private E-2

    here are the other two logs
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any major malware problems but we do have some things to cleanup which I will get too.

    First wmccds.exe (Windows Media Connect) is a process installed alongside D-Link and Roku media playing devices, and provides additional configuration options for these devices. This is a valid process.


    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6

    You are running SpywareBlaster v3.4 which is out of date. You need to get the current version from SpyWare Blaster make sure you update after installing and then enable all protection (including for FireFox).

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Windows Explorer and locate the below files and delete them:
    C:\Documents and Settings\Dan.MEDIACENTER\Local Settings\temp\pmt.exe
    C:\WINDOWS\system32\objsafe.tlb
    C:\WINDOWS\WildApp.dll

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Dan.MEDIACENTER\Local Settings\Temp


    Now reboot your PC.

    Let me know how things are working now.
     
  7. rage66621

    rage66621 Private E-2

    Okay I did everything you said except my computer was unable to find the files...

    C:\Documents and Settings\Dan.MEDIACENTER\Local Settings\temp\pmt.exe
    C:\WINDOWS\WildApp.dll

    So I was unable to delete those.

    Anyways after restarting I went to sign in to myspace and when I clicked to enter my email the getting started with internet explorer box popped up again and would continually as I tried to enter my email and password. So I went to this site and attempted to go to the forums, but when I clicked on the link the getting started with internet explorer window popped up again. Well I noticed that the little exterder resourse moniter bar was full in my icons on the lower right hand side of the screen. I opened up my task manager to see what was running and it was that wmccds.exe Network Service was running. Well I waited until it finished and then clicked on the link for the forums and it took me here.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. rage66621

    rage66621 Private E-2

    No I don't use it so I just unistalled it. After reading the link you posted I know it must have been installed on my computer because I just got an Xbox 360 not too long ago and tried it out playing media from my computer through it. Wasn't that impressed though so I don't use it. Funny thing though, I just uninstalled it and went to reply to your last post... well I clicked the curser in the box and typed the "N" key and that window for internet explorer help popped up again. I closed it then went back to type again and it worked though, so I don't know what's up with that.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After a reboot of your PC are you still having problems?
     
  11. rage66621

    rage66621 Private E-2

    Yes still having problems indeed.

    Tonight I could barely get internet explorer to work. It didn't matter where I clicked or on what page all it would do is open an internet explorer help window or something like that. I rebooted and it did the same thing. Went to reboot again and like 18 consecutive windows popped up and continued to open and close. I couldnt get the computer to respond so I had to manually reboot. Well I went back to the page I was trying to access before and clicked in the box to enter my password and the internet explorer help window opened up again. Frustrated I wasn't sure what to do so just sat there and thought for a minute. Then for the heck of it I went to enter my password again and it worked. So for now at the moment I am not having problems, I know it will happen again though.

    There has got to be some kind of virus or something causing this right? I don't know what else could cause this.

    Also when it happened earlier my computer wasn't busy like before when it used to happen. It was just in idle process, nothing running.

    Any help or ideas would be wonderful.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not necessarily. I have seen quite a few PCs lately where conflicts with installed or corrupted software (including Windows inself) were the cause of similar problems. On one PC that woud take from 5 to 15 minutes just to login and then almost no applications would run when trying to start them. And then 15 minutes later they would all start opening. Shutting down the Automatic Updates for Windows fixed this particular PC. Why is still a question but recent Windows Updates may have caused a problem.

    Are you still experiencing problems?
    If so, do they occur when you boot in safe mode?

    You can try running the steps in the below link but I doubt it will find anything:

    Using Sophos Anti-Rootkit

    Then attach the requested log.
     
  13. rage66621

    rage66621 Private E-2

    I just ran a thorough scan of my hard drive with avast and it took forever but it found a virus, a worm. So I deleted it. Haven't had any problems yet but haven't tried to do much yet, will probably find out if that solved the problem tomorrow.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What did it find and where did it find it? Do you have a log?

    Was it found in System Restore?
     
  15. rage66621

    rage66621 Private E-2

    I don't think it found it in system restore because I cleared that all out the other day. Also I'm not sure exactly what it was it found. I was too tired to think about what it was I just deleted it. It was pretty late and my girlfriend woke me up because she heard avast find something. I didn't even think to save a log, sorry. I disabled system restore though after I deleted the worm and then rebooted and enabled it again.

    However, the problem is not solved. This morning I turned my computer on and went to put in a password... same "getting started with internet explorer" window popped up and continued to do so. I opened my favorites to come here and try to post and when I clicked on the link to the support forums the window popped up again. Well I waited probably five minutes then clicked the link again and it worked. So I don't know what the deal is.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would suggest you post a message about this in the Software Forum. It sounds more like a configuration/settings issue to me. Make sure you tell them you have already been checked out for malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds