unknown virus attack

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by laughing elf, Apr 3, 2006.

  1. laughing elf

    laughing elf Private E-2

    Norton, AD-Aware, Spy Sweeper, spyware Doctor have not fixed the problem.

    WindowXP on HP laptop.

    Keyboard pauses during typing, window scrolls up, updates will not install.
    Microsoft Optical Mouse stops working

    Web site minimizes.

    Typing I-beam scrolls off the page

    Here is an xample of keybe action.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Your problems could be hardware related. The best way to determine that is for you to work thru the below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. laughing elf

    laughing elf Private E-2

    Attachments as requested.
    No mouse
    Cursor dancing page scrolling
    Difficult
    Hope you have all info needed
     

    Attached Files:

  4. laughing elf

    laughing elf Private E-2

    missing attachment
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why? Did you forget to attach the Bitdefender log? Do you still have it?

    Are your copies of Spyware Doctor and Spy Sweeper the free trial versions or are the paid versions?

    Your installation of Spy Sweeper appears to be broken based on the below line. Did you attempt to uninstall it?
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)


    Let's get an installed programs list from HijackThis too!

    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  6. laughing elf

    laughing elf Private E-2

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not recommend having multiple full blocking antispyware programs installed like this. SInce you have paid versions of programs, start by uninstalling Windows Defender. Now choose which or the two below you like the most and uninstall the other:
    Spyware Doctor
    Spy Sweeper <--- My personal choice! You installation seems to be broken though!

    Uninstall this old Sun Java version:
    Java 2 Runtime Environment, SE v1.4.2_03

    Also uninstall this old version of FireFox:
    Mozilla Firefox (1.0.7)

    Install the current version of FireFox from: Mozilla FireFox

    Did you install this? WexTech AnswerWorks
    If not, I would uninstall it!

    Where did you get the below from? Was it a P2P site or other illegal download. Bitdefender says it is infected:
    C:\Downloads\systemmechanic5pro.exe

    What is the below stuff?
    C:\FINANCE\Tradsim prg\by Fry - tradesim.ace
     
    Last edited: Apr 10, 2006
  8. laughing elf

    laughing elf Private E-2

    Thank you, thank you, thank you!!!!

    Everything is working.

    Laughing Elf
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We still have some more to do!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
    O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
    O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Mozilla Firefox\plugins\NPMySrch.dll

    You did not answer my question about the below. If you do not know what these are, delete that Tradsimprg folder and everything in it.
    C:\FINANCE\Tradsim prg\by Fry - tradesim.ace[setup.exe]
    C:\FINANCE\Tradsim prg\serial tradesim.zip[setup.exe]


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds