Possible rootkit problem??? :(

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Meekiecheese, Oct 9, 2012.

  1. Meekiecheese

    Meekiecheese Private First Class

    Normally we run Avast's BootScan daily, but we got busy and didn't check the scan logs for a couple of days. On September 27th and 29th there was a problem found, but not on the 28th. Here's the 2 files that Avast found:

    FILE NAME - C:\WINDOWS\Favorites\MEDICAL\HEART FAILURE\Heart Failure - Causes, Symptoms & Treatment.url; SEVERITY - HIGH; STATUS - THREAT: INI:Shortcut-inf [Trj]

    FILE NAME - C:\WINDOWS\Favorites\MEDICAL\POOR CIRCULATION\Heart Failure - Causes, Symptoms & Treatment.url; SEVERITY - HIGH; STATUS - THREAT: INI:Shortcut-inf [Trj]

    Being "uncaffeinated" I deleted instead of quarantined the files. The reason I believe I was reminded to review the logs was because the computer did not shut down --- it just "hangs" with the wallpaper showing and the icons gone when trying to shutdown and the only way to shut it down is to power off. I ran Malwarebytes, SuperAntiSpyware, Spybot and Avast and they all came back clean. I next tried System Restore (at this time October 2nd, I had 3 months worth of restore points) and the computer seemed to be OK even though the restores were "incomplete". Also, whenever I was able to boot or reboot, the desktop would "freeze" and the only icon in the system tray was the Volume icon. I would hear the start-up music and then the one icon would show in the sys tray. If I tried to click on a program icon like AOL or whatever, the desktop would freeze and i would have to power off and the only way I would get any "normal" use of the computer (especially internet access) was to try to do a system restore. In addition, after my first system restore attempt, without turning SR off, all of my restore points were flushed out (originally I had restore points back to July!!!) and I was left with October 2nd! Now I think I only have Oct 6th.

    I was able to use Safe Mode without any problems and I ran all of the above programs in Safe Mode to no avail. I tried downloading a couple of programs, one of which was ESET Online Scanner. Their instructions/interface was a little confusing, so I did not use "delete" at first because I didn't know if it was really going to delete or quarantine. Initially, ESET found 4 problem files:

    RESULTS OF ESET SCANNER — FOUR (4) THREATS FOUND:

    C:\AOL Instant Messenger\AIM.exe Win32/Adware.WBug.A application

    C:\MyFiles\BUSINESS FILE\ART DECO\frzfonts.exe a variant of Win32/InstallIQ application

    C:\Program Files\InternationalPrimoPDF.exe Win32/OpenCandy application

    C:\Program Files\EVERYTHING FROM LIBRARY DISK\UBCD4WinV350.exe Win32/PrcView application
    (this last one was originally on a USB stick when I had problems with another old computer and I had to download files using the library computer)

    After much frustration and resignation, I ran ESET again and set it to delete and only 2 files came up - please see log file attached.

    So, after trying everything I could on my own, here I am. Logs are attached along with some extra ones (I hope that's OK, thought it might help). Some of the programs you request us to download, I already have on my computer. My system is Windows XP Pro, 3 Pack. I use AOL dial-up for the internet and for resolving this problem, I am using Palemoon browser. Hope I covered everything. THANK YOU VERY, VERY MUCH!!! Love you guys! (((((((HUGS))))))) :)

    UPDATE: While trying to run Hitman, my computer crashed. I couldn't see the writing on the screen (it wasn't a BSOD, it looked like a green background with maybe yellow or white writing --- it was just a flash) and then the computer rebooted. The following gray error box came up with this info in it:

    BCCode : 1000008e BCP1 : C0000005 BCP2 : 8A454AF9 BCP3 : A67FECCC
    BCP4 : 00000000 OSVer : 5_1_2600 SP : 3_0 Product : 256_1

    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WER8098.dir00\Mini100812-01.dmp

    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WER8098.dir00\sysdata.xml

    So far everything is OK, I'm online. I will just proceed as if this never happened. If it crashes again while I am trying to use Hitman, I will skip this. The error message said it was "serious". :(

    ADDITIONAL UPDATE: The computer crashed again and I had to try System Restore again in Safe Mode in order to get the desktop to fully load and be able to get online. I will skip Hitman.
     
  2. Meekiecheese

    Meekiecheese Private First Class

    I was having problems with attaching the files, hopefully here they are.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not having malware problems. Your logs are all clean. Nothing that you mentioned in message # 1 was malware. As the user of the PC you ( or other users ) should have recognized these are items you have put on the PC.
     
  4. Meekiecheese

    Meekiecheese Private First Class

    What do you mean by "these are items you have put on the PC."? What items are you talking about? If it's not malware, then what could it be? The computer hangs at shutdown, the system tray does not fully load and the the desktop freezes. What are those symptoms of? I'm confused. Yes, other people use the computer, but what was put on the computer?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ones you noted in your first message.
    They are not malware. They are thing you or someone else who uses the PC put there.

    Possibly Windows problems or hardware problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds