Malaware Odd Small Window Glimpsed on Desktop at Startup

Discussion in 'Malware Help (A Specialist Will Reply)' started by esszeeeye, Nov 30, 2014.

  1. esszeeeye

    esszeeeye Private E-2

    I see a very small window on my desktop at startup. Not every time, but maybe once a week. It goes away when I try to open it & I cannot find it anywhere.

    I couldn't download GM Tools directly to C, but had to cut & paste it there. After running all 5 programs, I tried to download another copy of MG to see if anything had changed. Downloaded it (second copy) no problem.

    My search index became corrupted, not sure why; I turned it off, updated all drivers & applied Windows updates, cleaned off excess programs, etc.

    Not sure I'm ok yet, please advise?
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing alot to do at all: Try and screenshot what you see...

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - (no file)
    • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    • O9 - Extra button: Virtual Keyboard - {09A10376-994C-4BBF-9121-F50CF7BA237E} - (no file)
    After clicking Fix exit HJT.



    Delete as many files/folders as Windows lets you from this location please:
    • C:\Users\PC\AppData\Local\Temp


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  3. esszeeeye

    esszeeeye Private E-2

    Thanks so much for replying, Kestrel13.

    I have not seen that small window recently, maybe for a week, but will get a screenshot when I do.

    Ran C:\MGtools\analyse.exe as Admin. (W7) and it failed to fix any of the 4 items you listed, got 4 of the same messages:-
    "Error Details: An unexpected error has occurred at procedure
    modBackup_MakeBackup(sItem=06 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present.Error #5 - Invalid procedure call or argument."
    Then:-
    "HijackThis is about to remove a BHO and the corresponding file from your system. Close all Internet Explorer windows AND all Windows Explorer windows before continuing for the best chance of success."
    All 4 items were still there in the second scan.

    Deleted all but a few files/folders from C:\Users\PC\AppData\Local\Temp.

    Ran JRT from desktop, log attached. JRT removed all 4 HJ could not remove.

    AdwCleaner showed some crims.com entry I have no idea at all about, and there is nothing in there I need.

    Only weird thing I can see now is 2 desktop.ini files on desktop, one locked, one not, presumably from showing hidden files & folders?

    Thanks again.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. :)


    Adwcleaner looks like it's showing something to do with online Romanian Banking? Let it fix that entry if you're still not sure...

    Then I'm not seeing anything else to do.

    The desktop.ini files you are seeing is because hidden files and folders are set to show.
     
  5. esszeeeye

    esszeeeye Private E-2

    Online Romanian Banking? Omgosh, no idea where that could have come from. It's gone.

    TY again Kestrel13!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seen the odd window since?
     
  7. esszeeeye

    esszeeeye Private E-2

    Nope, must have been cleaned up by one of the Read me & Run or the two you had me run? I remember Googling around and seeing it listed as adware, ages ago, so possibly wasn't too nasty.
    The Online Romanian Banking/Crims entry bothered me more (When I say bothered, I mean from a point of view of not knowing what the hell I'm talking about, that's why I'm here *-) A leftover from some banking virus of some kind? There's no online banking going on on this computer, so maybe not an issue.
    Thanks again:major
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  9. esszeeeye

    esszeeeye Private E-2

    Never played it. Plus, this computer got a new hard drive & Windows reinstall 6 months ago. I could be wrong, but pretty sure no one else has had access to it since then.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, whatever it was, it's gone now. :) Ready for final steps?
     
  11. esszeeeye

    esszeeeye Private E-2

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  13. esszeeeye

    esszeeeye Private E-2

    No more issues I can see, tyvm.
    I didn't know I could keep MAM on the machine, and after reading up on it, the paid version that's good for up to 3 computers, I think, is top of my shopping list *-)
    I'm off to clean up the tools & review AV, etc.
    Thanks again!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds