Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Popups and regenerating files


  • Please log in to reply

#1
Rendezvous

Rendezvous

    New Member

  • Member
  • Pip
  • 1 posts
Background:
I've been working on my roomie's computer because he's been getting popups etc. I've been able to get most things taken care of whenever I havd had spyware/malware problems, but this one is getting to me.

The Details:
I ran through HJT and killed some things which may have had small problems, but after I cleaned them out I rebooted, everythign seemed great, then I saved a HJT log from a clean reboot, (pretty clean) opened IE and saved a new HJT log which had two new processes in it. (msiexec.exe and wuauclt.exe, both in C:\Windows\system32)
After proceeding to research these files, both of them are alledgedly legitimate files, (windows installer and windows update) but I believe they may be fakes because the windows installer should not have been running, and windows updates are completely disabled.
I then decided to try to delete them (with backups) to see if it would kill them, nope, they were regenerated within 10 seconds of moving/deleting. Other research shows that some parts of windows may be re-created from the dllcache when someone deletes the files, explaining the behavior here, but I was thinking it may be another part of the malware regenerating the files. I did notice that after restarting again, when I opened IE it gave me an error message telling me IE had encountered a serious error and myust be closed down, although *my* window didn't get closed, I suspect it was the popup dying.

Conclusion:
I still have some sort of popup generating spyware/malware on this system, with some files I believe should not exist, and won't go away. I would appreciate some guidance and/or review of my HJT logs. I will post them here if requested, just specify if it's a log of when windows starts up, when IE starts up, or both.

Thanks a ton,

~ Rendezvous
  • 0

Advertisements


#2
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Hi and welcome to GeeksToGo! My name is Sam and I will be helping you. :tazz:

I apologize for the delay getting to your log, the helpers here are very busy.
If you still need help, please post a Hijackthis log, in this thread, so I can help you with your Malware Problems.

If you have resolved this issue please let us know.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP