New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1159
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Need help with an insanely infested machine

 
Post new topic   Reply to topic       Computer Cops Forum Index -> Spyware Tools
View previous topic :: View next topic  
Author Message
AliCat_Klein

Cadet
Cadet



Joined: Jun 05, 2004
Posts: 2
Location: USA

PostPosted: Sat Jun 05, 2004 12:57 am    Post subject: Need help with an insanely infested machine
Reply with quote

Hello,

I am a home PC user consultant and I am in need of help with a PC that is horribly infested with all sorts of "yicky" bad things that I am not able to research through the usual channels. The machine is an old PC running Win ME.

I have things listed in the machine's start up and running processes that I can not recognize because they are all sorts of letters and numbers in combination. I would appreciate any and all assistance with this. Here's what's loaded:

GLEL.EXE
5QEKE7T5NG9WG2-OKXY.EXE (general comment....What the hell???)
16494293046456 (again, what the hell???)
AUTOLOADERPZ5Q1JISKJIX UPN2DLL.EXE-PC="AM.WILD" HIDE UNINSTALL (I am really uncomfortable with anything that is installed and goes to the extreme to hide its uninstaller)
IEGSJ NSSDRKBI.EXE-QUIET
VS7DEBUG/MDMEXE

I also am working on a pair of machines that currently (Win XP HE) that have an item listed in the MSCONFIG as existing as a line item but there is no identifying information on the items. It is just a checkbox and the area next to it where the identification info is supposed to be is blank. Does anyone know how to figure out what is hiding itself? My opinion/gut feeling is that it is something nefarious.

Thank you all in advance for your assistance. If you wish to e-mail me directly my e-mail is removed for your security; spambots pass this way

I will also be using the much recommended hijackthis program

Sincerely,
AliCat_Klein


Rolling Eyes
Back to top
View users profile Send private message
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1904

PostPosted: Sat Jun 05, 2004 1:10 am    Post subject:
Reply with quote

Hi AliCat_Klein,

Best have one of our experts take a look at those strange running processes then. Please follow these instructions carefully then proceed as follows:


First:
Please read these messages
Virus=Read This: http://www.computercops.biz/postt8864.html
HiJack= Read This: http://www.computercops.biz/postt911.html

Then
Download: HiJack This!

Create and Unzip to a folder not your Desktop or the Temp folder, doubleclick HijackThis.exe, and press "Scan".
Unzip the download (using a piece of software like: Winzip)


When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log in a text file, and post it in the CCSP "Spyware - Hijack Related" forum:

http://computercops.biz/forum67.html


Most of what it lists will be harmless or even required, so do NOT fix anything yet.
Someone here will be happy to help you analyze the results.


*Please, be patient. An expert will examine your log and this does take time. Please, no 'Bumps' and no 'Duplicates'. Thank you.*
Back to top
View users profile Send private message
AliCat_Klein

Cadet
Cadet



Joined: Jun 05, 2004
Posts: 2
Location: USA

PostPosted: Sat Jun 05, 2004 1:28 am    Post subject: Thanks for the directional assistance with my posting
Reply with quote

Hello,

Thank you for the quick reply to my problem. I have reviewed the instructions and I sincerely apologize for any person that I might have offended with my "What the "H"" comments.

It is my intention to make use of the Hijackthis program when I return to my client as I have already downloaded it.

Have a great day!

AliCat_Klein
Laughing Embarassed
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Spyware Tools All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops