I'm not sure what's wrong.

Discussion in 'Malware Help (A Specialist Will Reply)' started by PCneedsHelp, Feb 11, 2007.

  1. PCneedsHelp

    PCneedsHelp Private E-2

    I haven't noticed that there is anything wrong with my computer other than some erratic mouse behavior. I cleaned the mouse, can't find any new drivers, and also stopped using the scroll wheel but these don't seem to be the problem.

    The mouse will sometimes randomly jump much farther than it normally moves, close a window if I mouse over the "X button" in the top right, move the page up or down too much when scrolling, go back to the previous page, or go back to the previous page and then go forward to the window I was just at. This doesn't happen all the time.

    I ran Activescan a few days ago to see if there was anything wrong. After some time, all the windows that were open closed including the Activescan window. It did produce an Activescan.txt file but it only lists cookies. This is what alerted me.

    I followed all of the steps but could not complete step 6 as the Activescan failed to finish and did not produce a new activescan.txt file or overwrite the previous one so I attached the file from 4 days ago.

    I deleted the quarantine from Officescan.
    Spybot found no problems.
    CounterSpy found no problems.
    BitDefender found the Trojan.Downloader.Zlob.db in two places in the System Volume Information and deleted both instances.

    Also before I started this procedure, Officescan found a Generic Trojan as:
    C:\System Volume Information\_restore{858BEBE6-FC6F-44C5-BC5F-16DF821C9AD1}\RP362\A0061623.EXE which very similar to one of the files that BitDefender found except that the last number is a four ( ...0061624.EXE). I deleted the other file but I guess it came back. I'm not sure if BitDefender actually fixed this as I still have these problems.

    Do you need a HJT logfile?
     

    Attached Files:

  2. PCneedsHelp

    PCneedsHelp Private E-2

    Here are the other two files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    99.99% of the time problems like you are describing with your mouse are hardware related. Mice do wear out! Try another mouse and see if your problems go away.

    You don't have any malware problems based on your logs.

    I do recommend that you now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also I question what the below 5 temp files are in your root folder??? They are wasting over 5 Gigabytes of disk space. Do you know what they are from? Are you doing any kind of manipulation with video files or DVDs?
    Code:
    "C:\:
    11.tmp        Feb 10 2007  1071645184  "11.tmp"
    1c4.tmp       Feb  7 2007  1071645184  "1C4.tmp"
    40d.tmp       Feb  1 2007  1071645184  "40D.tmp"
    666.tmp       Feb  1 2007  1071645184  "666.tmp"
    f.tmp         Feb 11 2007  1071645184  "F.tmp"
    
    It also looks like CCleaner did not clean your Temp folder. Let's do it another way.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.
     
  4. PCneedsHelp

    PCneedsHelp Private E-2

    I was puzzled by those files as well. I don't do manipulation with video or DVD files as far as I know.

    I ran ATFCleaner.

    I'll try another mouse and let you know.

    Thank you very much for your help.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would suggest deleting those files and watch to see if any more are created.

    You're welcome!


    PS. The files in System Restore you mentioned can only be cleaned by doing step 8 in the READ ME. No matter what your AV says, it is not fixing them.
     
  6. PCneedsHelp

    PCneedsHelp Private E-2

    I did delete 4 of the files as I couldn't find the other one. I guess it could be hidden so I will try looking for it.

    Also, is there a reason that Activescan doesn't work?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you skipped step 2 of the READ & RUN ME. If you had done that step properly, you would be able to see the file. I know that step 2 was not done because I can see the registry keys in the runkeys.txt log that show that the settings were not changed as requested.

    I'm not sure! Many people seem to have problems running the online scan tools. Frequently it is due to incorrect settings. You could try uninstalling it from Add/Remove programs and then reboot, and try again, but you don't really need it since you don't have any malware.
     
  8. PCneedsHelp

    PCneedsHelp Private E-2

    That's odd because I remember checkmarking and dotting those three things, clicking apply, and clicking OK. I'll try this procedure again after trying a new mouse just to be sure.

    Thank you, again sir.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maybe you did them on a different user account. On the one you posted your logs from, none of step 2 was performed.
     
  10. PCneedsHelp

    PCneedsHelp Private E-2

    I changed the mouse and everything seems fine.

    I ran the procedure properly this time and found nothing.

    I'm going to clear the restore points now.

    Thank you for your help.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds