Home / Software / Computer viruses and spyware / I thought I had it figured out
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] - (Bottom) Print
Author Topic: I thought I had it figured out  (Read 1637 times)
cthis
Topic Starter
Rookie



Posts: 27


« on: November 18, 2008, 10:17:20 AM »

 Please help again, everything on my computer was running smooth until I got the new Yahoo! mail and it opened a malicious email automatically (i think). Now my computer is running super slow, and having trouble opening browsers. Also I found agent.exe and explorer.exe in my running processes and ended them. When I did this (mistake) my taskbar dissapeared. When I restarted all of my folders on my desktop were jumbled around. Thanks in advance for your help, you guys are life savers and should be paid for your services. (don't get any ideas, though). Thanks. Here are my logs.

[Saving space - attachment deleted by admin]
IP logged
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #1 on: November 19, 2008, 06:40:51 AM »

You need to update your Java, but aside from that, your computer looks squeaky clean.  If you'd like us to check out a deeper scan, you can follow these instructions...

Download ComboFix and save it to your desktop.  Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says.  Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt.  Go ahead and post that here.  Note: Don't click on the window while it's running; this may cause stalls.
IP logged

Quote
An undefined problem has an infinite number of solutions.
由obert A. Humphrey

Actually, the name's Chris...
cthis
Topic Starter
Rookie



Posts: 27


« Reply #2 on: November 19, 2008, 03:18:52 PM »

Thanks CBMatt, I just updated my Java 2 weeks ago when I had the first problem. However, I did go just now and try to update it again and the browser would'nt let me it said webpage cannot be found. So I already had combofix downloaded and ready to go. So here it is. Thank you for the help.

[Saving space - attachment deleted by admin]
IP logged
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #3 on: November 19, 2008, 05:03:00 PM »

Everything seems to be checking out, but there's one file I'm not entirely sure about.  Please follow the directions on this page:
http://www.computerhope.com/forum/index.php/topic,63393.msg404302.html#msg404302

I would like you to use VirusTotal to scan c:\windows\L&EAPPS.INI and then post the results here.
IP logged

Quote
An undefined problem has an infinite number of solutions.
由obert A. Humphrey

Actually, the name's Chris...
cthis
Topic Starter
Rookie



Posts: 27


« Reply #4 on: November 19, 2008, 06:48:22 PM »

Every thing seems to be fine with that file. I scanned it twice and found nothing, my computer is still acting funny but not as. Should I do the OTMoveit, atf cleaner and OTCleanit. or just leave everything on here just in case? Thanks a ton.

[Saving space - attachment deleted by admin]
IP logged
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #5 on: November 20, 2008, 04:08:46 AM »

Don't try anything extra just yet.  According to the VirusTotal log you posted, it didn't find the file.  Before taking any additional steps, there is something I would like you to try real quick...

First, open My Computer and go to to Tools > Folder Options.  Click on the View tab and place a check next to Show hidden files and folders.  Click OK.  Using the Windows search tool (Start > Search > For Files And Folders), perform a search for L&EAPPS.  You should also do the same for the agent.exe file you mentioned before, as it doesn't show up in your logs.  If you find either file, please compress it/them in a zip file and attach it in your next post.  You may then go back to the Folder Options and turn off hidden files/folders.



If you don't find the file, then go ahead with the following instructions...

Please print these instructions as they will be needed later when Internet access is not available.
 
Download SDFix by AndyManchesta and save it to your desktop. http://rapidshare.com/files/157266031/SDFix.exe.html

When using this tool, you must use the Administrator's account or an account with Administrative rights
  • Double click SDFix.exe and it will extract the files to %systemdrive%
  • (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
.Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
 
Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your next reply.
IP logged

Quote
An undefined problem has an infinite number of solutions.
由obert A. Humphrey

Actually, the name's Chris...
cthis
Topic Starter
Rookie



Posts: 27


« Reply #6 on: November 20, 2008, 08:08:28 AM »

For some reason that rapid share link wouldn't let me in, it said error this file is allocated to a premium account and wouldn't let me download the SDFix. Also when I ran a search for those files the L&EAPPS was easy to find but the agent came up with 8 different files that looked like it or were similar. I took a few and zipped them anyway. What should I do with the SDfix. Thanks

[Saving space - attachment deleted by admin]
IP logged
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #7 on: November 20, 2008, 05:51:30 PM »

L&EAPPS checks out and those agent files are just shortcuts.  If you found one that has the exact name of agent.exe (and nothing else), then that's what we want.

I'm sorry about SDFix; I didn't realize that link had reached its limit.  Try downloading from this link instead:
http://download.bleepingcomputer.com/andymanchesta/SDFix.exe

Once you download it, follow the steps from my previous post.
IP logged

Quote
An undefined problem has an infinite number of solutions.
由obert A. Humphrey

Actually, the name's Chris...
cthis
Topic Starter
Rookie



Posts: 27


« Reply #8 on: November 20, 2008, 08:40:00 PM »

Oh! sorry bout' that. Here is the file, it comes from Install sheild in the program files. I'll run the other scan in the mean time. Thanks again.

[Saving space - attachment deleted by admin]
IP logged
cthis
Topic Starter
Rookie



Posts: 27


« Reply #9 on: November 21, 2008, 09:32:37 AM »

Okay, I got it to download. Thanks. Here is the log from SDFix.

[Saving space - attachment deleted by admin]
IP logged
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #10 on: November 21, 2008, 05:16:12 PM »

Thanks for getting the file to me.  "agent" is a fairly common filename, so I wasn't sure what program it might've belonged to.  Thankfully, it checks out.  And your SDFix log is clean as well.  From everything I've seen, I have no reason to think you're infected.  Are you still experiencing issue with speeds?  If so, your computer may simply need a bit of spring cleaning.  CCleaner can help you out a bit with this.  Download CCleaner (install without Yahoo! toolbar) and configure it according to this guide.


Oh, and I'm sure you're probably wondering about something, so I'll give you a quick explanation...
Also I found agent.exe and explorer.exe in my running processes and ended them. When I did this (mistake) my taskbar dissapeared. When I restarted all of my folders on my desktop were jumbled around.
Ending explorer.exe is what caused these things to happen.  This program is what handles things such as the taskbar, your desktop, and folders.  When you ended it, all of these things disappeared.  It usually doesn't rearrange folders/files, but it has happened; it may depend on your settings.  Just for future reference, if you ever end the process again, you don't have to restart.  Simply press Ctrl+Alt+Delete to open the Task Manager.  Then click on File > New Task, type in explorer.exe, and click OK.


If you're having any other problems or have any questions, feel free to ask and I will do what I can to help, or will at least point you in the right direction.
IP logged

Quote
An undefined problem has an infinite number of solutions.
由obert A. Humphrey

Actually, the name's Chris...
cthis
Topic Starter
Rookie



Posts: 27


« Reply #11 on: November 22, 2008, 08:03:10 AM »

Thank you so much. One question, do you know why my dvd drive would quit playing CD's but still plays DVD movie's. I have a dual drive DVD/CD and the CD lens burned out I guess. I can't burn a CD or even listen to one. Is that common? Can I fix it?
IP logged
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #12 on: November 23, 2008, 05:56:37 AM »

You're welcome!  You should go ahead and uninstall ComboFix now since you don't need it anymore.  Simply go to Start > Run and type in combofix /u and click OK.  There is a space between the "combofix" and the "/u".

Now, as for you DVD/CD question...I agree that it sounds like your CD lens has burned out.  A lot of people actually don't realize that CD's and DVD's don't use the same lens.  That's why many people lose functionality of one format and don't understand because the other format works fine.  So, to answer your first question: yes, this is fairly common.  And it technically can be fixed, but it's much easier to replace the drive.  If you go to a site such as Newegg or MeritLine, you can get new drives for fairly cheap (and shipping is often cheap or free).  For $45, I managed to get my wife a really nice CD/DVD+R/RW/DL drive for her laptop (they're even cheaper for desktops).  But don't say anything 'cause it's for Christmas.  Heh.
IP logged

Quote
An undefined problem has an infinite number of solutions.
由obert A. Humphrey

Actually, the name's Chris...
Pages: [1] - (Top) Print 
Home / Software / Computer viruses and spyware / I thought I had it figured out « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.109 seconds with 20 queries.