Infection says 'catch me'

Discussion in 'Malware Help (A Specialist Will Reply)' started by dangle, Jul 10, 2013.

  1. dangle

    dangle Private E-2

    Have tried many things to get rid of my pest(s). Multiple hard drive replacements (6) and as many laptops have fallen victim. Not sure where to begin with a description of probs. but usually comp. is accessed, searched, indexed, files replaced, all activity logged and uploaded. Well that's a start anyway. I've been a visitor to MG for many years and I'm hoping you can help with my tiny problem
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There is no malware in your logs. The only issue that I see is that you have no antivirus program installed.
     
  3. dangle

    dangle Private E-2

    %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Smart Projects\IsoBuster

    Is this normal? It's the path listed in system variables. It has c:\windows\system32:c:\wi... until i hit edit and that's what it shows.



    also have multiple duplicate processes running - crss.exe, explorer.exe, flashplayerplugin, and several others that disappear after a second or two.

    If I'm being paranoid, please forgive me but when I find 'catch me' listed in the device manager's hidden devices, well, that would tend to make anybody a bit concerned.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal.

    It is csrss.exe and yes you will see it twice. Explorer.exe running twice is due to how you setup your PC and other applications. Same for flashplayerplugin.exe


    This is a driver that is used by GMER, Combofix and a few other tools. You probably ran at least one of them at some time.
     
  5. dangle

    dangle Private E-2

    I just wanted to let you know that your patience and superhuman restraint (thx for not bustin' my balls!) has paid off and there's a happy ending to this 3 month long ordeal. I was at wit's end and feeling like an idiot, so I decided to quit being one. If it wasn't software, then it had to be hardware! I share a connection with my elderly parents so I went next door and started at square one. Sure enough my father had gotten in-behind his t.v. (for reasons known only to him) and had reversed the connections on the in-line filter. I found my 'ghost in the machine'. No more network acrobatics!
    You've restored my faith in humanity (for a couple hours anyway, then it's right back to being totally screwed).
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds