Pc Problems /// Here Are My Logs /// Help /// Sos

Discussion in 'Malware Help (A Specialist Will Reply)' started by superstar, Oct 13, 2006.

  1. superstar

    superstar Major-Superstar

    Where do I begin?

    Well yesterday I was using my pc as usual, and I installed a couple of new programs I was trying out. I always scan my programs for virus' with AVG, and well they had no problems. I tested out the new programs, and even unistalled one I didn't like. I than installed a new game I was trying out, but my system specs could'nt run it so I uninstalled that.

    Anyways my system seemed fine, and at the end of the day I did my regular routine of running spybot, adaware, avg, and than system mechanic 4. I don't remember if I ran all of those programs because I was sleepy, but I usually do everyday. If I didn't run them all I know must have run at least a couple. So I cleaned off the regular junk, than I turned off my pc and went to bed.

    I started my pc today and out of nowhere the following sympthoms occured on their own without me even touching anything:

    - Systray kept opening and closing (ie: the arrow next to the clock)

    - 101 explorer windows opened up by themselves

    - A mass amount of errors were displayed on my screen. Some seemed to be loading errors or something.

    - A couple programs on my pc opened up on their own. The one I can remember that opened up by itself was "download accelerator", but that's been on my system for a very long time.

    - My high speed internet connection opened up like 5 times on top of eachother. As if I were trying to connect to the internet, but as I mentioned before this all happened without me even touching anything.

    - & the worst thing that caught my attention was the fact that windows made a note come up on my systray that said my windows firewall was turned off!

    I IMMEDIATELY REBOOTED MY PC THINKING IT WOULD STOP WHATEVER WAS HAPPENING!!!


    I thought something must have attacked me so bad that maybe I could have lost everything on my drives. To my surprise my pc booted up fine, I logged into windows xp and all loaded up normally. I immediately went into my control panel to check the status of my firewall. I clicked on the firewall icon and I got a message that said the following:

    Windows Firewall

    Windows Firewall settings cannot be displayed because the associated service is not running. Do you want to start the Windows
    Firewall/Internet Connection Sharing (ICS) service?

    Yes /// No




    I chose the "NO" button, and clicked on the firewall icon again. This time the normal firewall panel opened up and said that my firewall was on. I restarted my pc again and my system booted up fine. I went into my control panel and clicked on the firewall icon and it asked the same message I wrote above. I chose "No" again, and than clicked on the firewall icon, and it was turned "on" like normal.

    This time I got cheezed off and ran spybot, adaware, avg, and than system mechanic 4 (I always run them in that order). Cleaned off everything it found, and rebooted my pc. System mechanic is known to clean the registry or some stuff like that. When I run system mechanic I always use the wizard, which requires a reboot when your done.

    Anyways I rebooted my pc and than went in the control panel, clicked on the firewall icon, and this time that message didn't appear. The firewall panel opened up, and my firewall was turned on like normal.

    That's when I came to seek help from my heros at major geeks. I read the "read me first" sticky like a good pc user should, and did everything you all recommended.

    Note: My bitdefender, and panda scans were done on normal boot mode since I couldn't access the internet in safe mode. Oh and when I did the safe mode part I logged in win xp with my user name not the administrator one. I am the administrator though, on normal boot my user name is the only one that you can log in to windows with. I was told in the past by other people on this site that it is my administrator just with my personal name, not like a guest user account with limited settings. For example when I installed win xp my "username" was the only one at startup and still is. I don't have any guest accounts on this system at all.


    ANYWAYS HERE ARE MY LOGS, AND SINCE ALL THE LOGS DON'T FIT I'M REPLYING TO MYSELF AND POSTING THE REST:

    (All panda found was one malware item but couldn't clean it. By the way I still haven't flushed system restore because I fear I'm infected with something. I went up to step 7 of the sticky and now here are my logs)




    Thank You
     
    Last edited: Aug 4, 2007
  2. superstar

    superstar Major-Superstar

    Here are the rest of my logs since my first post only allowed me to upload three logs...


    Thanks again
     
    Last edited: Aug 4, 2007
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not show any malware problems!

    The only thing I see is that you need to install the current version of Sun Java and then uninstall the two old versions.

    If you are still having problems, explain what they are. Also explain exactly what you were downloading and installing when you problems occurred. Was it Daemon Tools?
     
  4. superstar

    superstar Major-Superstar

    Thank goodness!

    Thank you for replying Chaslang, that's good news. You mentioned that I needed to have the new version of sun java which I assume is at www.java.com. & than you said I should uninstall the two old versions... How will I know which ones are the old ones? & why uninstall the old ones after not before?

    And yes the day that I got those problems I was experimenting with "Alcohol 120%" software, and "Daemon Tools" because I wanted to see what all the fuss was about from the virtual drives they make. I uninstalled "Alcohol 120%", but I still have "Daemon Tools" installed... I also downloaded something called "Securom Loader", that's still on my machine. & hmmm... I think that was all. I tried to play a video game that I made an image of, which I made so I don't have to pop in the dvd game anymore. I was trying out the cool virtual drive with it! My game didn't work for the longest time for some reason so I searched the net and read that I needed a "Securom Loader". I don't know what it's for but it worked and got my game working. I think my game had some sort of protection or something. I did some reading on the net today and found out that some protected media can leave .dll or reg files on your pc. Can this be so? I don't even know what those files are for but I bet maybe they caused the problems. I wonder if they're still lurking around my pc! I uninstalled the game already because I thought that could have been the problem. I kept the "Daemon" thing because it seems like a cool tool to have a virtual drive. I still don't know what it does fully. But I love seeing the fact that I have another drive in my computer! It's cool! And I just love experimenting with new software. But if for any reason something is causing or caused my issue let me know and they're gone in 1, 2, 3!

    Well I haven't seen any sympthoms occur since the first thing happened. What do you think it could have been? I mean my firewall even turned off on it's own, so how could that have happened by itself?

    Oh yes my system restore is not flushed should I do that now? Or am I in the clear?

    & last thing how do I put "spybot" the way it was? During my log process I was told to put it in advanced mode and deselect a list of things, how do I select them back or does this not matter?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The one already on your PC and that are seen in your log from ShowNew are the old ones. They are:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6


    You can uninstall them before or after, it still works. However it is normally a better practice to uninstall first so you can do that.

    Anything that you install can and often do leave things lying around on your PC in both the registry and the file folders. This is just the nature of the poor programming practices and installation/deinstallation programs that software companies use.

    Not sure, but the Windows firewall does not provide adequate protection and is prone to problems like this. We see them all them time. You should install and use one of the firewalls mention in the below link:

    How to Protect yourself from malware!

    Since we did not clean any malware from your PC it is not really necessary! But you could do it anyway to remove restore points that may contain programs that you no longer use.

    Not necessary nor is it desired to do this. Leave it in the advanced more and do not want to deselect anything anyway. That would tell Spybot not to scan for the items.
     
  6. superstar

    superstar Major-Superstar

    Thank You!

    All Done Sargent!


    MANY MANY MANY MANY THANKS!

    ALL HONOR THE GREAT CHASLANG!!!


    I WILL NOW BUILD YOU A PYRAMID... JUST COME SEE IT IN 1000 YEARS AS IT'S MY FIRST TIME MAKING ONE...
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  8. superstar

    superstar Major-Superstar

    I installed Hijack this according to the "read me first" instructions...

    But how do I unistall Hijack this now that my problems are solved?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't really need to. It takes up only a very small amount of diskspace and use no resources unless you run it. But if you want to uninstall it, goto add/remove programs and uninstall it. Then goto all folders where you may have had it installed at anytime and delete all the HijackThis related files.

    For example you can delete the below folder:
    C:\Program Files\HJT
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds