3rd security scare this month...!

Discussion in 'Malware Help (A Specialist Will Reply)' started by insan_art, Jan 11, 2011.

  1. insan_art

    insan_art Private First Class

    Well, I'm back yet again. This is the third time in nearly a month I've had a security scare. The two times before I WAS infected, this time I don't know if I am or not! This is really getting tough on my already over-taxed mind and body.

    I do remember seeing a pop-up (or rather one of those "pop-down" messages at the top of Firefox, like when it asks if you want it to save a password) last night before I went to bed - it said something about Flash, possibly something blocked? Not sure - I was very sleepy.

    Then this morning when I turned on my laptop, the first thing I noticed was that my desktop/display settings had changed (AGAIN - this was one of the signs from before that I had a problem). Custom desktop photo gone (goes to Windows blue) and my custom settings using the Classic Windows view (gray toolbar/start button) has reverted back to the Windows XP settings (blue toolbar/green rounded start button). Maybe I'm just freaking out over nothing here, but it is not "nothing" to me when my settings have been suddenly changed and I DIDN'T DO IT!

    If I am infected (again), I need to figure out the root of this vulnerability. All these infections are really screwing with my ability to get my work done, to say the least. To the best of my knowledge, I am all up-to-date with everything. I follow (mostly) all of the MG advice for running a tight ship - I do not run a real-time scanner as suggested and Kestrel advised me last time I was here to seek advice in the software forum about free firewalls - I hadn't gotten to that yet, but sure as sh*t I'll be installing one ASAP now!!! I had problems before using Online Armor, so I stopped using it.

    About Flash: In my add/remove list I see the following Flash items:

    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 9 ActiveX

    Why is there both 9 and 10? Should they both be there? Is 10 the most up to date, or did I possibly miss an update, and could this lead to my issues?

    As to my internet activity - I mainly read lots of news and use facebook. I don't usually do anything suspect - after the past two infections, I've even pared down the news sites I read to only ones that I really, REALLY trust (I rarely strayed from these before).

    I'm sorry about the lengthy post, but I'm seriously fed up with all of this and I'm really trying to understand why it is happening so I can correct it!

    Logs are attached.

    Thanks again for all of your help.
     

    Attached Files:

  2. insan_art

    insan_art Private First Class

    MG log attached. Thanks again!
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, insan_art

    I find nothing in your logs that indicate malware present.

    It is normal to see different versions of the same program listed in Add/Remove, and "Adobe Flash Player 10" is the latest version.

    *You should have installed a firewall immediately after working with Kestrel13! in your December thread.

    Please follow the below steps to remove a couple of left-overs:

    Open notepad, then copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.

    Double-click fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now using Windows Explorer, navigate and delete these left-over folders:
    C:\$AVG
    C:\Program Files\WildTangent

    Then "Open" CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    If you wish, you can run this online scanner -

    Using ESET's Online Scanner
    NOTE: This scan can take more than an hour, so be patient!
    -------------------------------------------------------

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    Last edited: Jan 11, 2011
  4. insan_art

    insan_art Private First Class

    Thank you dr. moriarty for your help.

    What exactly is this "gameconsoleservice"? I don't do games on here. Also wondering where the hell that Wild Tangent crap crept back from? I deleted that a while ago! Are they part of the same thing? I never installed either of them.

    EDIT: I'm not seeing the Wild Tangent folder? Like I said, could have sworn that was nixed a long time ago.

    I'm going to try the Comodo firewall as soon as I'm done with what you've outlined below and the final steps.

    Any thoughts on why my settings changed suddenly? I'm very concerned about this!!!

    Thank you again for your time!
     
    Last edited: Jan 11, 2011
  5. insan_art

    insan_art Private First Class

    Whoa....strange! After did as you asked, then did final steps (including wiping the system restore), after the reboot, my display settings were back to normal!

    WEIRD!

    Downloading Comodo NOW! Thanks again!
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.
    As seen in your HJT log:
    O23 - Service: GameConsoleService - Unknown owner - C:\Program Files\WildTangent\Apps\TOSHIBA Game Console\GameConsoleService.exe (file missing)

    A left-over service from part of the appls that came pre-installed on your TOSHIBA, and I was just making sure that the WildTangent folder was deleted.

    Glad to hear that your machine is back to normal.

    dr.m
     
  7. insan_art

    insan_art Private First Class

    Hi again Dr. Moriarty. I apologize, I feel like I'm probably beating a dead horse with this issue, but this morning (after my display settings went back to normal yesterday), the settings were again defaulting to the Windows XP theme (blue taskbar, green rounded start button) - I did not initiate this change. I'm very concerned about this, but since my scan results appeared to be clean, should I take this issue up with the software forum? I just don't understand why the settings would shift back and forth like this. I've never had this happen before, except as the result of an infection.

    Thanks!
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, insan_art

    Your logs are clean of malware and now need to investigate the problem in a thread in our Software Forum.

    Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds