Application windows randomly switches

Discussion in 'Malware Help (A Specialist Will Reply)' started by titanium13, Sep 5, 2015.

  1. titanium13

    titanium13 Private E-2

    The problem started after I installed GorMedia Webcam Software Suite. It came with a bunch of malware including moviedea.exe and msnetcore.exe, which I've deleted.

    I have two symptoms:

    1) Open applications windows will randomly switch. For example, I may have a Firefox window open and Internet Explorer open. I will be typing something in Firefox and it will switch to the Internet Explorer window automatically.

    2) The applications list on my taskbar will randomly close and open. If I have a Firefox window up, the indicator on the taskbar will randomly close and then open back up by shrinking and then expanding back.

    Logs are attached.

    Thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system. You can rerun Hitman and have it remove the Potentially Unwanted Programs, but other than that your logs are clean. I suggest you post in the software forum for additional assistance.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not possible with Hitman. See the log
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Reboot and rescan with Hitman ahd attach the new log. Be sure to tell me how things are running.
     
  5. titanium13

    titanium13 Private E-2

    The registry change was successful.

    New Hitman log attached.
     

    Attached Files:

  6. titanium13

    titanium13 Private E-2

    Forgot to mention that the problem still exists.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    
    :reg
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}]
    [-HKU\S-1-5-21-3315882755-3958961015-3068296615-1001\Software\Classes\clsid\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}]
    [-HKU\S-1-5-21-3315882755-3958961015-3068296615-1001\Software\Classes\Wow6432Node\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}]
    [-HKU\S-1-5-21-3315882755-3958961015-3068296615-1001_Classes\clsid\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}]
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Since there is little malware showing, I will probably send you to the software forum.
     
  8. titanium13

    titanium13 Private E-2

    I couldn't copy the text under the green bar because the reboot button was blocking it and was the only thing I could click on. I've attached the log which I assume has the same information.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your issues are not caused by malware. I suggest you post in the software forum for additional assistance,

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:

     
  10. titanium13

    titanium13 Private E-2

    OK, thanks. I've already made a post in the Software section.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good luck.....I will monitor the thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds