Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Regimra, Apr 2, 2007.

  1. Regimra

    Regimra Private E-2

    I'm in trouble.

    I tried to follow the guidance in the Malware Removal Guide: identified and deleted a number of infected files. Some still left on the system

    Unable to go on-line while in SafeMode+Networking, so had to go out live.

    Bitdefender worked OK: several viruses identified.
    Active Scan crashed out 2/3 through so unable to generate a text report.

    Hijack seemed to work OK.

    Did not restore system as there was evidence of continued infection.

    What do I do now ? Try the whole thing again ?

    Help and advice very welcome.

    Bill
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the other requested logs:
    • CounterSpy - only for Windows XP, 2K, & NT users
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • HijackThis
    Also you need to explain what malware problems you are actually having.
     
  3. Regimra

    Regimra Private E-2

    I was originally working through Fixya web-site who recommended I contact you re the problem. Here is the correspondence. Advice would be really welcome !

    Problem:
    posted by regimra on Apr 01, 2007
    Report abuse

    I've just bought a new monitor. I use MS XP.

    When not in use the screen freezes with an egg-timer in the middle. I have to reboot each time in order to free it up.

    I've checked the power-off in Control Panel - OK.
    I've down loaded the correct driver.

    The previous 'older' tube monitor worked fine: problems have arisen since installing this one.

    Can you help ?

    Bill

    Comment by regimra, posted on Apr 01, 2007

    Thanks for your comments. You are clearly correct - it cannot be a monitor matter, the same thing occurred when I reconnected my old one. However, I have run a full virus check with up-to-date checker (Norton 2007), I have cleaned up the HD, got rid of unnecessary files,(I have yet to defrag); I have tried (without success) to restore the system to a point some 2 weeks ago. For some reason it could not do it. So I am still left with the problem.

    If the computer is left running for, say, 5-10 minutes, the screen goes blank, the mouse is inoperative, and there is that damned egg-timer in the middle of a blank screen. The only way out of this is to re-boot.

    One thing which may help you advise further is that I can forestall the crash by constantly moving the mouse. (I sat and read a book for some 3 hours, with the mouse in my hand !). That way, the system stays 'up'.

    Any further ideas, please ?
    Comment by regimra, posted on Apr 02, 2007

    Hi cousin !

    Thanks very much for the careful advice. Much appreciated !

    I've done all that and it has cured the screen freeze problem - without any evidence of the egg-timer.

    I will go carefully through the Malware procedures as suggested, but it does look very 'techy' so it will be a very careful expedition on my part. I have one further complication which has arisen and which I am negotiating with MS support over. For some reason I am now getting an error message indicating a failure to load document viewer, together with a similar one to do with MS.Net Framework. There is a download dealing (I think) with the latter, but it has failed twice to download successfully - hence the contact with MS Tech Support.

    If you have a view on that I'd be interested.

    Many thanks

    Bill
    Comment by regimra, posted on Apr 02, 2007

    By the way: when can I (or should I) check the tick box on Hiberation in Control Panel Display ?
    Best Solution
    posted on Apr 01, 2007
    Excellent (5)

    printerhater
    By Master printerhater
    Rank: Master
    Rating: 78.82%, 17 votes

    The hourglass / egg-timer you're seeing has NOTHING to do with your new monitor. It is an indication that some program (possibly something NASTY) is running and using the CPU. While the CPU is tied up by the (possibly unknown) program, Windows displays the hourglass so you will know that the system is busy...

    First, update your antivirus program, then use it to scan your ENTIRE hard drive; this could take HOURS, so you might want to let the AV program work all night. If you don't have an AV program, you can do an online scan of your system in order to find the culprit; open Internet Explorer, then open this link:

    http://housecall.trendmicro.com

    Run the FREE online scan; again, this could take HOURS to finish, so you might want to let it run all night to see if the problem can be resolved...

    There are OTHER types of nasty software ("malware") which could have the same effect on your system, so if you can't find the source of the problem, open these links for more information:

    http://forums.majorgeeks.com/showthread....

    http://forums.majorgeeks.com/showthread....

    I realize that this probably isn't what you expected, but at least now you know what is most likely to be causing this problem, and the links I've posted can help you correct this problem...

    Lastly, this COULD be caused by a program you (or someone else with access to your system) has intentionally installed, but you didn't mention adding any software recently, and I think it is best to atacck this problem head-on. Best of luck; let us know what you learn...

    Comment by printerhater, posted on Apr 02, 2007

    Moving the mouse keeps the CPU busy updating the position of the mouse pointer (AKA the cursor), which prevents the unknown program from taking control of your system...

    Open Control Panel, and click on the Display icon. When the Display Properties open, click on the Screen Saver tab. Next, click on the Power button. Look on the Power Schemes tab; set your system to the "Home/Office Desk" option, then set the "Turn off monitor", "Turn off hard disks", and "System standby" options to "NEVER". Next, click the "Apply" button, then click on the "Hibernate" tab. Make sure the "Enable Hibernation" box is NOT checked; if there is a checkmark in the box, use the mouse to remove it, then click the "Apply" button again, then click the "OK" buttons, and finally, close the Control Panel. Once you're back to the Desktop, test the system to see if the monitor still goes blank, and if the hourglass reappears. The monitor SHOULD remain active, though I suspect you will still see the hourglass... Making these changes will eliminate the chance that Windows itself is responsible for blanking the monitor (for power-saving purposes), though you'll still have to deal with whatever program is causing the hourglass to appear...

    Since you've scanned the system with your AV program and found no problems, the odds are that your system is infected with a "malware" program which the AV program cannot detect, which is why I suggested following the steps listed on those MajorGeeks.com webpages to try to disinfect your system. As a general rule, antivirus programs are NOT designed to solve the type of problem you're experiencing, but it was best to begin this process by scanning your computer with an AV program to rule out the worst-case scenario, which you've done.

    I hate to tell you this, but I suspect that you're going to have to follow the steps listed on the MajorGeeks webpages here:

    http://forums.majorgeeks.com/showthread....

    and here:

    http://forums.majorgeeks.com/showthread....

    to find and eliminate the rogue program (or programS) which are causing the problems you've described. I KNOW that it seems like a LOT of work, but it is the BEST method I've ever found for fixing the types of problems you're experiencing... I get paid to repair computers, and I can attest to the effectiveness of the methods used by the advisory staff at MajorGeeks.com; their procedures are as thorough as any you'll find, and the advice they provide is outstanding. I use their methods to clean (and protect) the infected systems I encounter each week, and I can only hope you'll take my advice here and begin the system disinfection process they recommend, so you will have the peace of mind of knowing that your system has been properly scanned, cleaned, and protected...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I still need the logs I requested in message # 2.
     
  5. Regimra

    Regimra Private E-2

    Thanks for your time. Much appreciated.

    Logs attached.

    Various viruses identified, as you will see. Big mail-box hi-jack problem and much slowness of response.

    You're talking with a computer-illiterate here, so step by step help would be very helpful.

    Bill

    I've uploaded all the reports I have: will you need any more ?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still what was requested in the READ ME, message # 2, and in message number 4. You still never posted your CounterSpy log; however at this point I don't see any real major malware issues. Thus I will give a few things that you need to do anyway.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_04

    Make sure you reboot after uninstalling the above!



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/28aca5dc2b889c0cf321/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below folder and delete it if found:
    F:\WINDOWS\BBStore

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. HJT


    If you believe you are having malware problems now, you will have to describe them.
     
  7. Regimra

    Regimra Private E-2

    I've done all that - at least I think that the registry merge was carried out OK.

    I'm not sure what changes I should have seen.

    Bill
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not add the registry patch in correctly. You MUST check for a success message after trying to add in the patch. Tell me what you see.

    Did you find and delete the F:\WINDOWS\BBStore folder?

    You also did not fix the lines indicated with HijackThis.

    You were supposed to be in normal boot mode when you got the logs. Please attach HJT log from normal boot mode.

    Also attach a new log from ShowNew.

    Also you MUST explain whether you are having any malware problems at this time.
     
  9. Regimra

    Regimra Private E-2

    You're very patient: thanks.

    Registry patch successfully added now: Message displayed "successful entry on registry..."

    F:\WINDOWS\BBStore deleted

    The original malware symptom of screen freezing, eggti8mer displayed, mouse inoperative, needing to reboot in order to carry on - all of that has gone. But I'm still getting evidence through email of misuse of addressbook.

    I inadvertently copied the registry patch first time into another folder - not desktop. Repeated in to desk-top and carried out the patch procedure. I assume it is OK to delete the unused copy from the other folder.

    HJT, ShowNew logs attached.


    Appreciate all this !

    Bill
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not fix the lines indicated with HijackThis. Are you sure you are clicked Fix checked? Are you getting any popus from your antivirus when you do this? You must allow the changes to occur.

    Run HJT again with ALL browsers closed and fix the lines previously requested. Then double check your log to make sure you actually fix them. If you get them fixed, attach a new log. If not, explain any problems you are having.

    Sounds like you are saying someone has your email address book. We cannot help you with that. Once someone had your info, they have it.


    Yes you can delete the registry patches.
     
  11. Regimra

    Regimra Private E-2

    Log attached. It seems OK

    Life seems very slow on this machine: e.g. several seconds to change pages within MS Excel.

    Also, I have now got a registry problem : Fatal error 1606 MSI selfinstallingportmonitor which is to do with re-installing my printer (one of the casualties of the recent virus attack). Checking the error on the HP website, it is a registry issue, which may well have occurred during our recent regedit process - do you think ?

    Bill
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any remaining slowness is not due to malware. It is due to things you are running. Uninstall unnecessary programs (Google Toolbar and Desktop for example) and don't allow items you don't need to load at startup to run. You should also look into a less resource hungry antivirus program. Symantec is a hog!

    You can have HJT fix the below auto update program from Sun Java which will help a little:
    O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.6.0_01\bin\jusched.exe


    No this has nothing to do with the steps we did. We just removed a spyware registry key related to Broderbund Software.
     
  13. Regimra

    Regimra Private E-2

    Thanks Chas. I think we've chased this rabit down enough borrows !

    Many thanks for your help.

    Bill
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds