Problem with auto logout after cleanup

Discussion in 'Malware Help (A Specialist Will Reply)' started by johnplinton, Mar 17, 2010.

  1. johnplinton

    johnplinton Private E-2

    Hi!
    I recently had the HelpAssistant virus. I did the readme and run first steps and it fixed my problem. (woo-hoo!!! and MAJOR THANKS!!!!!)

    Unfortunately now I've got a little problem and I am not sure if it is a side effect of the clean-up activities or what.

    When I login to my PC I have no problem..but if I switch user to another account after about 5 mins the first account is completly logged off (I hear the logout chime and everything)

    This is more annoying to my wife than anything else as one of the kids hops on and everything she was in the middle of is lost.

    Hopefully I just didn't follwo the instructions right or something. After doing some google searches I have seen some others with the same exact problem but there was no solution posted for the problem.

    Any info would be appreciated!

    thanks!


    p.s. I think I still have my log files (at least some) if you want me to post them
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. Attach all of the resquested logs and then I can see if indeed any malware remains on the system. :)
     
  3. johnplinton

    johnplinton Private E-2

    ok here they are. I am running SuperAntiSpyware again as I had cleaned out that log but I figured I would get you what I could as fast as I could.

    For Rootrepeal I had one little problem. I have two USB drives attached to my computer (G: and H:) for some reason it alawys got hung up when it tried to run against G:.

    will attach other MGlogs on next post
     

    Attached Files:

  4. johnplinton

    johnplinton Private E-2

    here is MGlogs
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks like your logs are clean. For any non malware related issues you will have to visit the software forum.

    Which of the scanners removed the problem, do you remember, I am curious?

    Please go to Add/Remove programs and uninstall the following software:

    • Java 2 Runtime Environment, SE v1.4.2_19
    • Java(TM) 6 Update 13

    Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Mar 20, 2010
  6. johnplinton

    johnplinton Private E-2

    I believe that MAlwarebytes found some and I think SuuperAntiSpyware found a couple of things. I can't recall exactly when the virus stopped coming back, however I think it was around the combofix was run but I can't swear to it.

    Now for you other actions......Java deleted and installed per instructions

    Cleanup actions:
    1 I had Malwarebytes on from before and left on SuperAntispyware
    2.N/A
    3. Did the uninstall of combofix before I started the thread
    4.
    5. N/A
    6. N/A (I'm XP)
    7. Done (told me that it may have already been uninstalled)
    8. Done
    9. Done

    Now the reason that I came through this forum for my problem is because the auto-logout of the other user never happen prior to me running through the steps listed on this site. I was curious as to if you have seen this problem before with folks after they ran the malware cleanup stuff and what they did to fix it.

    thanks
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, personally I haven't seen anyone have this problem before, and the combofix certainly did not make any wrong deletions, so all I can say, is to visit the software forum for advice as your logs are malware free and I can only address malware related issues here in this forum. :)

    Then you didn't attach the log in which threats were found.

    But you deleted the logs, so I will never know if it made a wrong deletion or not.
     
  8. johnplinton

    johnplinton Private E-2

    Thanks for taking the time to look. I included the current logs to demonstrate that I was virus free. I have attached the logs for the day when MBAM and SAS actually found stuff. I don't any of the items would have caused the auto-logout problem.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, what they found would not have caused the issue.
     
  10. johnplinton

    johnplinton Private E-2

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Am asking about it. Please be patient. :)
     
  12. johnplinton

    johnplinton Private E-2

    no problem. I have started a thread in the software per your suggestion.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have spoken to Chaslang.

    Your log did not show any evidence of anything being fixed by the cleaning procedure other than the below by combofix and these did not need to be removed and don't have anything to do with your problem anyway:

    Thus I'm not sure what you think the cleaning procedure fixed for you as you stated in your first message. That is unless you did not post the logs from the first time thru the cleaning process.

    Since you said you uninstalled CF before you started the thread, it is possible that I did not see the original log. Could you attach the older MBAM logs that actually show something?

    What else had you done before you came here and ran our cleaning procedures?
     
  14. johnplinton

    johnplinton Private E-2

    I kept trying to remove the Helpassistant user and it kept coming back.
    When I discovered that I had something wierd going on I ran malwarebytes (I had it installed on my system prior to reading your forum).
    I have attached the log from the 3/9.

    I also ran an on-demand scan of Mcafee. After that I went looking for help and came across your forum. and that's when I went and downloaded the tools you suggest (SuperAntiSpyware, COmboFix, Rootrepeal, etc.).

    I tried to follow the procedure as best I could. During the process I did have a few BSODs (I didn't write down exactly when they happened.) But I am pretty sure I only ran combofix once.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Since there is nothing showing in any logs that would indicate files being removed in My Documents, something else would likely be the cause. I am going to suggest that you hit up the software forum to try and resolve this, but do not toggle system restore yet. Perhaps you could use a tool such as Recuva. Let us know how you get on.

    Final steps below, just do NOT toggle sys restore yet!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. johnplinton

    johnplinton Private E-2

    Unfortunately I did all of the cleanup steps including toggling the system restore prior to starting this thread.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Visit the software forum and see what the guys and gals in there say. :)
     
  18. johnplinton

    johnplinton Private E-2

    - funny....yesterday they said to wait and see if you had anything. :)

    Got any other ideas as to any settings in Windows that would force a logout of a user?
     
    Last edited by a moderator: Mar 29, 2010
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, personally I haven't. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds