"Cheeky Kate" (?) occupying desktop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kapparomeo, Feb 29, 2012.

  1. kapparomeo

    kapparomeo Private E-2

    I'm terribly sorry to bother you all with this - I appreciate that you're probably inundated with similar requests, but in addition to working abroad with no easy access to an IT professional I'm also not in the least bit technical, and I'm afraid that all I can do here is cry for help. Sorry again for the trouble, and thank you sincerely for any help you can provide.

    I seem to have contracted a hostile application which obstructs my desktop and prevents me from performing almost any action on the computer. Unfortunately I'm unable to follow the advice in the "READ ME FIRST" thread because of this, and I can't run any diagnostics of my own so the information on this thread will have to be limited to what I can see on my screen.

    The computer starts up and Windows loads as normal. I am using Windows 7. Instead of my desktop, however, I only have a white screen with the words "please wait while a connection is beeing [sic] established", with the same repeated in German beneath it. I can hear the standard 'mouse-click' sound intermittently, so I worry that some background action is being performed (frankly I'm terrified of turning my computer on in case it's busy formatting my hard drive). I cannot click on anything. I can use Ctrl+Alt+Del to access the Windows options screen (log off, change password, shut down etc.), but trying to start the Task Manager does nothing - occasionally a window briefly flickers open but it is immediately hidden behind the white screen in a fraction of a second. I think that I may have caught a glimpse of an unfamiliar application called something like "cheeky ind kate" - apologies again for being vague, but that's all the detail I could notice. This message has continually appeared despite multiple restartes. I have tried starting Windows in Safe Mode, and this white screen and message still appears.

    Apologies again for not being able to provide more specific information, but if this description seems familiar to anyone you will have my gratitude.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You will need a USB flashdrive in order to do the below.

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    Option2: Enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. kapparomeo

    kapparomeo Private E-2

    Thanks, chaslang. Here's what I've got:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like you did not run FSRT from the System Recovery Options. Based on the log, it looks like you had run Windows and then just ran FSRT which is not what we need to do. Did you run it from Windows or did you run it exactly how I asked you to run it?
     
  5. kapparomeo

    kapparomeo Private E-2

    Apologies, chaslang, the last file came about because I missed the BIOS startup (I must have pressed F8 too quickly because it started beeping) and so went into the command prompt via Windows Safe Mode. This time, I was able to follow your instructions exactly. I hope that this is more useful for you:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really need to layoff all the Torrent downloading stuff. This is very likely the source of your malware problems!

    Download this >> View attachment fixlist.txt

    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows if possible. If you can then continue with the below.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide
     
  7. kapparomeo

    kapparomeo Private E-2

    Apologies for taking a few days to follow-up on this, chaslang, work has been keeping me very busy lately.

    Regarding the torrents - yes, you're probably right. Suffice to say that I'm working in a place that's fairly isolated and the odd afternoon to stuff some videos down the pipe is the sum total of my entertainment, but I'll be more circumspect in future. :-o

    In any case, whatever witchcraft was concealed in fixlist.txt seems to have worked - the computer is now functioning apparently normally,although all of my desktop icons have disappeared (but can still be viewed in their Explorer folder). The other malware programs detected some files as well; Logs are posted below. Waiting on your final summation, I have not yet re-enabled UAC or toggled System Restore. I will post another message after this one with the MGLogs.zip file attached.
     

    Attached Files:

  8. kapparomeo

    kapparomeo Private E-2

    Following my last message, see MGLogs attached:

    EDIT: I have another post with four different log files from the fixlist.txt and the Malware Removal Guide which has been put into the moderation queue, hoepfully it should appear soon.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it ( if you are running Vista or Win 7, use right click and select Run As Administrator ). Did that help with your missing items?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds