When there's something strange, and it don't look good...

Discussion in 'Malware Help (A Specialist Will Reply)' started by -Bob-, Apr 2, 2007.

  1. -Bob-

    -Bob- Private E-2

    I'm pretty sure I have a problem with my computer, but I haven't had any luck finding out what's wrong so far (oh, and a small disclaimer before I start- I'm an idiot).

    First, the problems started firefox- I'd try and open it, and then it would swamp me with up to 20 new windows- although after that it would work fine for that session. This happened more than once.

    I tried scanning it at the time with AVG 7.5, although that couldn't finish a scan, and the same happened with Ad-aware, although slightly differently- it would notice problems on my computer, but when it got to about 190K files or so it wouldn't go any further. If I stopped the scan, the results would say nothing was found (although the summary details on the first results page said files scanned: 1234567890, and other random numbers). I think the actual log summary still said that it found things, but stupidly I didn't keep it. Similar things happened with Sybot S&D.

    I searched a little bit online for how to deal with the problems, and followed one persons reply to another guy's question, of installing AVG antispyware and running it in safe-mode, but it didn't deal with the problem. Since then, something's tried to disable my AVG firewall and the AVG antispyware resident shield at startup, and the windows firewall, pretty regularly. My comp seems to have slowed down, too.


    Well I found this forum and have done everything in the READ & RUN ME FIRST guide, but I don't think it's done much- now whatevers up with my PC is messing with counterspy too, trying to shut it down or disable protection (incedentally, the toolbar icon says CS is active, but the main window says *Not Avtivated* at the top). Bitdefender found something but couldn't deal with it, and Panda Activescan found somethings which it mainly dealt with (I did the process a week ago because it found things and disinfected them I thought it was dealt with, but it hadn't so I've done the whole guide again- I can attach both panda activescan logs).


    It's also worth noting that I have both AVG anti-spyware AND CounterSpy running at the moment, which could clash since I haven't really thought about it, but I wouldn't have thought that they would be the main problem.


    I'll attach the BD, Activescan, Runkey, shownew and HJT logs, but I couldn't get the counterspy log- it says that I haven't ran any scans yet, even though I have. If it turns out that I was in a different user at the time or something, I'll post that up too.
     

    Attached Files:

  2. -Bob-

    -Bob- Private E-2

    Here are the other logs:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You don't really show much in the way of malware. I have some suggestions, comments, and questions though.

    First the questions:
    1. Did you install Media Bar 3.2.12 ?
    2. Do you trust/know that it is clean?
    3. Did you configure the below about:blank settings yourself:
      • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
      • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
      • R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
      • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Morpheus 1.9 <-- should have been uninstalled in step 0 of the READ ME

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now boot into safe mode and delete the below file if found:
    C:\WINDOWS\system32\moaupd.exe

    Now as a backup check, I want to look for rootkits just to be safe. Please run this AVG Anti-Rootkit and attach a log if anything is found.


    Other than the above, you may want to look into possible hardware problems with your system.
     
  4. -Bob-

    -Bob- Private E-2

    Thanks very much for replying!

    1. I personally didn't install it, and I don't think anyone else intentionally did in the past either.

    2. See above.

    3. No, I haven't configured those settings.


    Also, I don't seem to be able to uninstall Morpheus 1.9- counterspy says that MediaForge/XML Runtime Player (xmforgert.exe) is trying to run, and even if you allow that nothing happens.


    And I've done the rest as you said! Thanks!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then uninstall it.
    .

    Then fix those lines with HJT. Make sure no browsers are open when you click Fix checked.


    My instructions had you uninstalling CounterSpy before uninstalling Morpheus. Why didn't you uninstall CounterSpy? Is it a paid version that you already had prior to running the READ ME? It does not look like it based on the date it was installed in your logs.

    No you did not! Where is the log from AVG AntiRootkit?
     
  6. -Bob-

    -Bob- Private E-2

    Sorry for the lack of information before, here's the update:

    I have uninstalled MediaBar and Counterspy, although Morpheus 1.9 doesn't seem to be able to be removed- nothing happens when I click 'remove' on the Add/Remove programs list.

    I've used HJT to fix the about:blank settings.

    I didn't post the AVG Rootkit logs because nothing was actually found, which I should have said in the first place!


    Thanks for all your help so far :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if this can uninstall it: Your Uninstaller! 2006

    Let me know the results!

    Are you having any malware problems now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds