A couple of strange and mysterious things that happened

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mr. Dave, Apr 23, 2007.

  1. Mr. Dave

    Mr. Dave Private E-2

    Hi, everyone. I'm new to this forum and I've had a couple of strange and mysterious things happen on my computer. Also, just for the record, there may be a logical explanation for these things, but then on the other hand, these things may indicate the presence of malware or outside intrusion. But anyway the two strange things that happened on my computer were:

    1) I had a bookmarked website in my "Favorites" section mysteriously vanish on it's own and two more websites mysteriously appeared in my "Favorites" section.

    2) I had a legitimate malware tool(which was checked by someone from another forum) cause my system to stop working. The malware tool was the Advanced Anti Keylogger from the www.spydex.com site. The Advanced Anti Keylogger caused my desktop icons and taskbar to disappear and then caused my computer to stop running.

    I use the Windows XP OS, IE7, and currently I use Prevx1, Windows Live OneCare, AVG Anti-Malware, SUPERAntiSpyware, and Ad-Aware SE Personal Edition. If anyone could give me some feedback as to what possibly could be going on with my computer, I would appreciate that.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    First I have to ask why are you coming here for help if you are already working at another forum. Did the other site ask you to install Advanced Anti Keylogger or did you install this on your own. If your PC does not run anymore (do you mean not at all - not even in safe mode), there is not too much that we can do for you.

    Exactly what disappeared from your Favorites and was that your only problem at the time? Any antispyware scanner could remove things from your Favorites if it looks suspicious or matches something that has a name similar to malware.

    AVG AntiSpyware, Prevx1, and SuperAntiSpyware free versions or paid versions?

    What about Windows Live OneCare? Is it the 90 day trial or did you subscribe?
     
  3. Mr. Dave

    Mr. Dave Private E-2

    Just to get a second opinion.

    On my own, but I found the product in a thread at the other site.

    It still runs, but there are strange things that it has been doing lately like some of the things that I mentioned so far.

    Dictionary.com disappeared on it's own and Onelook.com and Onelook.com/reverse-dictionary.shtml appeared in my Favorites on their own.

    I don't think that would apply to me since only dictionary sites were involved.

    Trial version of Prevx1 and the free versions of SAS and AVG.

    The 90 day trial.

    Also, something else strange happened last night. I deleted a folder that I wasn't using anymore from my Favorites, however, a dialogue box appeared on my screen and said something like: "Someone is using a site in the folder that you are trying to delete or the site is in use and therefore this folder cannot be deleted." And I'm like: "Whaaat????" This was definitely a first for me. But I tried deleting the folder again and got the same message, however, around the third time that I tried to delete the folder, I was successful.

    I would love a logical explanation, however, it has just been too many little strange things that have been happening on my computer lately.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot say for sure what is going on or whether you even have any infections. In reality it does not really sound like malware. You do have too many realtime blocking antispyware applications install which in itself can be problematic and can cause many strange things to happen.

    I suggest that you do the steps below so we can determine whether there are any malware issues on your PC.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. Mr. Dave

    Mr. Dave Private E-2

    Sorry about taking so long to respond. Chaslang, I have two questions for you:

    1) Which realtime blocking antispyware application would you suggest that I take off my computer?

    2) If the other forum that I posted at already had me go through their "Do This First" type scanning and cleaning procedure, is it still necessary that I go through yours?

    By the way, after completing the other forums "Do This First" scanning and cleaning procedure and after posting my hijack this log at their forum, no malware or infection showed up on either account.(Although I was still a bit concerned about possible rootkit infection - because of the strange happenings - since rootkit infections are so stealthy.)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well first I would need more information.
    • Do you have more than what you mentioned in your first message
    • you said Prevx1 was a trial. Are you going to buy it?
    • you said AVG AntiSpyware and SuperAntispyware were free. Are you going to purchase either of them?
    • are you going to continue to subscribe to Windows Live OneCare
    Yes! We have our own procedures and our own required logs and we would want to see your current status not one from a week or so ago. I cannot tell from anything that you have said thus far whether you have malware problems or not. Nothing yet really sounds like malware. Nothing seems malicious. The only major issue you mentioned seems to be around the fact that a tool you installed caused you problems. And as I said too many tools can be a bad thing!


    Most people are under the very mistaken misconception that HijackThis is a scanning/removal tool. It is not! HijackThis is simply a tool that is used to identify browser hijackers and in some cases it will show entries for some malware that is for instance running at startup. All it does is list a few of the thousands of registry keys that exist, and it makes no inferences to whether anything being shown is good or bad. That decision is left a person with significant Windows and malware cleaning experience. HijackThis does not come close to showing all malware that could be hiding on a PC. Anyone who has an infected computer and is relying on HijackThis without the benefit of running other scans such as Spybot, Windows Defender, BitDefender & Panda, CCleaner, etc. are more than likely still infected. In most cases, where there is one virus/trojan there are more. The goal of this forum is to remove all malware, and this cannot be done properly by just seeing a HijackThis log.
     
  7. Mr. Dave

    Mr. Dave Private E-2

    I'm so glad that this *old* rolleyes thread hadn't been closed. Chaslang, sorry about taking soooo long in getting back to this thread, but I think that I am finally ready to try Majorgeeks' anti-malware removal procedure. Also, I know it's been a long time, but I have read that hackers and intruders do not always want to invade other people's computers to either damage those computers or to try to find out personal or financial information about the computer's user so that they can steal finances from them or to steal their identities. I have also read that hackers and intruders can invade a person's computer and use it send tons of SPAM to other computers so that the SPAM can't be traced back to the actual hacker's computer. Therefore, within the next several days, I am going to finally buckle down and go through the steps of Majorgeeks' anti-malware removal procedure. BTW, one thing that I have noticed about my computer since I first thought that it had gotten infected months ago is that at times, my computer has awfully low CPU resoursces left.(I'm not sure if I said that right, but I think you know what I mean.)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Low resouces also does not necessarily mean you have malware. As I stated before, you could have too much stuff installed and running too. Or you could have an inadequate amount or RAM or too little hard disk space or to low a virtual memory setting....etc.

    Run the READ & RUN ME sticky and attach ALL 6 of the requested logs and then we will tell you whether you are having malware issues or not.
     
  9. Mr. Dave

    Mr. Dave Private E-2

    Will do. However, I did want to tell you that I have been posting on this board from the library just in case I did have an infection or an intruder so that I wouldn't tip them off as to what I was trying to do. Therefore, it will be soon when I finally get on my home computer and come to this site and run the READ & RUN ME sticky.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Just attach the 6 requested logs when you complete the procedure.
     
  11. Mr. Dave

    Mr. Dave Private E-2

    Chaslang, I just wanted to let you know that I've been delayed and I'll have those logs posted soon.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem. Just attach the logs when you finish.
     
  13. Mr. Dave

    Mr. Dave Private E-2

    Well, Chaslang, it's early Sunday morning and I don't know when you'll see this, but right now I would like to update you on my progress. First of all, I'm not sure if I downloaded GetRunKey and ShowNew into my own folder(which I call Spyware Tools) correctly. I kind of downloaded them twice into that folder. One time as GetRunKey and ShowNew folders and the second time as GetRunKey and ShowNew zip folders. But I'm sure that's not a major problem. I ran the Spybot and the CounterSpy scans in Safe Mode and they both came out clean.(Although, I wish you would have warned me that the CounterSpy scan took around 4 hours.rolleyes ) I also ran CClear(which I actually did first), but I was a little bit confused on one point. When we're instructed to Run CCleaner with the default options to clean out temporary files and to only use the Default Scan on the Windows Tab, I wasn't sure if you meant to have the entire Windows Tab default scan options checked(i.e. the Internet Explorer, Windows Explorer, and System sections) or just the Internet Explorer option section checked which has the "Temporary Internet Files" and/or the System option section checked which has the "Temporary Files." I ran CCleaner with all three default scan options checked under the Windows Tab while leaving everything unchecked under the Applications Tab. Also, right now I'm in Safe Mode with Networking Support waiting for BitDefender to complete it's scan.
     
  14. Mr. Dave

    Mr. Dave Private E-2

    Well, if I'm doing this right, here is my Bitdefender log.
     

    Attached Files:

  15. Mr. Dave

    Mr. Dave Private E-2

    Here is my Panda Active Scan log.
     

    Attached Files:

  16. Mr. Dave

    Mr. Dave Private E-2

    Okay, I'm probably a bit brain challenged right now from being at this since around 12:30 AM, :yum but I need help with 6B on the READ & RUN ME in trying to locate the getrunkey.bat file and running it. I obviously need a break right now and I'll be back sometime later.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Default means don't change anything. Thus that means you can Ccleaner wrong since you changed the settings on the Applications tab based on what you stated. Also sounds like you might have changed things on the Windows tab. You may want to uninstall it, and then delete the C:\Program Files\CCleaner folder and then reinstall it (all though this may not restore defaults if they are saved in the registry).
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really! You should complete everything in the READ ME before posting individual messages for each log. You can cause excessive delay in getting answers to your messages this way since it is almost like bumping because it makes your thread newer each time. Also we are not goingt to create any fixes until all logs are posted.

    GetRunKey.bat and ShowNew.bat will be in whatever folder you extracted them to when you extracted the files from the ZIP file as instructed. If you followed our instructions exactly, that folder would be C:\MGTools
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds