Suspicious files (?)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Whovian33, Apr 10, 2005.

  1. Whovian33

    Whovian33 Private First Class

    I have come across suspicious files in my computer, but it appears to run OK.
    What is EMM386.EXE (I see it when I run AVG7)? Why do I have RunDDL32.exepowrprof.dll,LoadCurrentPowerScheme twice in WinPatrol? Huh? Thanks if you can enlighten me. OLB
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. Whovian33

    Whovian33 Private First Class

    Just to let you know I haven't forgotten (or had time to work on this) due to homework projects, tests, and registration--university related--I am hoping to have more time this weekend, when things settle down for a little while. Thanks for your patience. OLB
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It wont take but about 45 seconds to attach a HJT log. If you can do this then I will get your fix started.
     
  5. Whovian33

    Whovian33 Private First Class

    Well, I tried to run HJT, but the download said Can't find Program.exe. I have run CCleaner,Ad-AwareSE,Spybot S&D,AVG7 & ran Ad-AwareSE in safe mode; the only thing that turned up was some type of error and the usual suspects (Cache, Cookie, & other Windows applications). After all this, do you think I should leave well enough alone, or what would you suggest? Thanks. OLB
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  7. Whovian33

    Whovian33 Private First Class

    Good news, bad news. I got HJT to work, BUT I can't save the Logfile for some reason to post it so you can look at it. I HAVE NOT checked or deleted anything on the logfile. Suggestions for an experienced rookie? Thanks. OLB
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    What do you mean you cant save it?

    Run HJT and choose "Do a system scan and save a logfile", it will then scan and a log will pop up. The log will be in the same directory that your running HJT from.

    When you go to post, click "Manage Attachments" and attach the log file. It will be in a .txt format.
     
  9. Whovian33

    Whovian33 Private First Class

    OK, I tried the download you sent & had to add WinZip to my programs--with that done, when I run HJT, it loops after the scan and save log; the log doesn't save so I can post it. Am I missing something else here? Thanks. OLB
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Look in the folder your running HJT in. Do you see hijackthis.txt?
     
  11. Whovian33

    Whovian33 Private First Class

    I was able to run HJT & save it to a program file on my C drive. How do I transfer that to the majorgeeks.com post? Thanks for your patience. OLB
    P. S.: I have NOT checked or deleted any files.
     
    Last edited: Apr 17, 2005
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    When you go to post, click the REPLY button, then under where you type this text you will be a button "Manage Attachments". Use this feature to attach your log.
     
  13. Whovian33

    Whovian33 Private First Class

    OK, as your instructions, I have attached my hijackthis.log . Go for it. Thanks. OLB
     

    Attached Files:

  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Are you familiar with ACCESS4LESS EXPRESS
     
  15. Whovian33

    Whovian33 Private First Class

    Yes; it is my web browser. OLB
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I see no major problems in your log. However it probably would be a good idea for you to run CCleaner to cleanup any junk files.

    Download & Run CCleaner

    Let me know what problems you still have if any.
     
  17. Whovian33

    Whovian33 Private First Class

    Thanks for your patience and for checking my log for me. I already have CCleaner--I run it every day, sometimes twice a day since my wife uses the computer too. Thanks again. OLB
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    So everything is ok, no further problems?
     
  19. Whovian33

    Whovian33 Private First Class

    Exactamundo. Thanks. OLB
     
  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  21. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Just a a side note or background info.........

    EMM286.exe is an upper memory manager for the OS


    The two instances of RunDLL32.exepowrprof.dll,LoadCurrentPowerScheme ( and with the typo in th first post being RunDDL32.... I thought ahhh trojan at first ) BUT,

    those two are required if you are using Power Management (accessed through Start > Settings > Control Panel > Power). If so, there will be two instances. This is normal
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds