Strange system tray icon

Discussion in 'Malware Help (A Specialist Will Reply)' started by Outlawstar15a2, Jul 1, 2006.

  1. Outlawstar15a2

    Outlawstar15a2 Corporal

    I have this strange system tray icon. I do not know what it is but it appears to be some kind of spyware perhaps a virus. In anycase I cannot take it out of the system tray and I ran ad aware and spybot twice to no avail. Below I can added a screen shot I don't know if it'll help al I know is that for the last couple of days when I search the internet even though I have and use pop up blockers a few prompts asking if I would like to install this software came up I said no to them all including one that was for Win PC Doctor which spybot picked up as spyware.
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    These are our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. Outlawstar15a2

    Outlawstar15a2 Corporal

    I think my problem is gone though I'm not sure. In any case I'm running the Bitdefender scan so wish me luck. It's found some interesting stuff.
     
  4. Outlawstar15a2

    Outlawstar15a2 Corporal

    It's back again it just popped up. And it has this weird habit of closing down programs and then preveting me from running them. Prgrams such as IE and multiplayer games like Enemy Territory. Also I might have to redo the panda abd bitdefender thing. I had to abort bitdefender because it looked as if it froze and panda was gone when I woke up so one of my sisters probably closed it.
     
  5. Outlawstar15a2

    Outlawstar15a2 Corporal

    Malware Update

    I did the whole 1-6 steps without incident until the online scanners. Bitdefender I think froze and I had to exit out of it and Panda was gone when I woke up so I don't have either log file. How do you want me to proceed because the problem is still there.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware Update

    Were you running both Bitdefender and Panda at the same time?

    Please run the below instead of the online scans and attach your Ewido log:

    Running Ewido Anti-Malware


    Then proceed to step 7 and attach a HijackThis log.

    Also please desribe your malware problems.

    [EDIT] Now I see you had already started a thread for your problem. Please remain in one thread to avoid confusion like this. All contact related to your current malware problems should occur in this thread. Continue with what I gave you above.
     
  7. Outlawstar15a2

    Outlawstar15a2 Corporal

    well the thing returned it seems to shut down all non explorer.exe programs after a certain time has passed I was in the middle of a multiplayer game and it shut the game down right in front of me however I had to manually close out of teamspeak which is a voice chat program that allows me to communicate via microphone to other players. Also I keep hearing a popping sound other few seconds and that didn't start till the weird stop sign icon appeared in the system tray. Sometimes its accompanied by a yellow caution sign neither of them can be closed down and I cannot identifiy the process that started them. I tried to run bitdefender last night but it stalled. I tried to run it today but half way through the virus shut down IE so it stopped the scan. Panda was closed down when I got up this morning. Since that was in safe mode my sisters' probably closed it down which I can stop them from doing but I will try this other program first I will boot up in safe mode and try to run it that way and I'll return with the log file.

    EDIT: Sorry about that I didn't mean to cause confusion.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still need to know (in a short direct answer) the answer to my question in message number 6. It is not clear to me what the answer is.

    Continue with the rest of message number 6. Do not post again until you have complete those instructions.
     
  9. Outlawstar15a2

    Outlawstar15a2 Corporal

    No, I ran them separatly.

    However I now have the two logs you requested, though something strange happened when I ran ewido for the first time... I went to upgrade it like you said in the post, I was still in safe mode and that icon which is causing all this trouble had appeared again no sooner did I open the program to navigate to the upgrade button it prompted me telling me it found a high risk threat within my system tray and asked me what did I want to do I said to it to clean and quarantine the file which ewido is still holding onto when I did that a few seconds later that icon in the system tray disappeared and I haven't seen it since. The name of the file was xpupdate.exe I remember it well. In any case I included the two logfiles that you asked for I hope I did the right thing.
     

    Attached Files:

  10. Outlawstar15a2

    Outlawstar15a2 Corporal

    How come I can only quote once a day? Hmm...

    Anyway even though that icon didn't return, I'm beginning to see some other things happening to my system just now I got a message saying that the page file was too small (this is when I went to open a new window of IE) and something is eatin g up CPU time as well as causing programs to close down after they were running for a short time. It's the same as before just less obvious and the system is slightly more functional but still a problem. Sorry about this I would have edited the previous message but I can't.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not allow Ewido to fix anything! Why not??? Everything shows: No action taken. If you are not going to allow it to fix your malware problems there is no sense in running it.

    You should uninstall SpamBlockerUtility if you have it installed! Do this before continuing.

    Please run Ewido again and this time make sure you FIX what it finds. Attach a new Ewido log.

    Also attach a new HJT log.
     
  12. Outlawstar15a2

    Outlawstar15a2 Corporal

    actually what happened is that I hit save report first and then i took the actions at first i was under the assumption it would take action automatically while saving the report since it had already decided what was best for each threat and the fact that i was given a chance to change the actions to be taken which i didn't because it seemed to know what it was doing and none of the files was of great importance so this i will take action first and then save the report since it doesn't seem to do it while making the report.
     
  13. Outlawstar15a2

    Outlawstar15a2 Corporal

    ok heres the logs... this time i did the cleaning actions first and then saved the log so it should show what i did. Just a question do you want me to send you a printed screen of my quarantine folder by cutting and pasting a snapshot to ms paint and just attach it in a future post?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For what purpose?

    Why is Spybot's Teatimer running? We specifically request that Teatimer not be used in the READ & RUN ME. It was not running in your previous log, so why is it running now. You need to follow only the directions we give you and nothing else.

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {0DED9096-CCC5-23DA-C84D-A0D9E703FD28} - (no file)
    O2 - BHO: (no name) - {45FEDA4A-6ACA-3CD9-D9AB-2CDEA0244912} - (no file)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O2 - BHO: (no name) - {d9ae6ddd-5fea-4082-a558-e4d6e617548f} - C:\WINDOWS\system32\intrad.dll (file missing)
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/27058d9be8ab419b9306/netzip/RdxIE601.cab
    O20 - Winlogon Notify: intrad - intrad.dll (file missing)
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete ( they may already be gone ):
    C:\WINDOWS\system32\intrad.dll
    C:\WINDOWS\System32\vbsys2.dll
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jul 5, 2006
  15. Outlawstar15a2

    Outlawstar15a2 Corporal

    heres, the logfile i disabled teatimer like you said. that backweb process didn't show up again, however theres a process called "EM_EXEC.EXE" and "ALCXMNTR.EXE" what are those for?

    well since the original problem was time based usually appearing like 20-30 mins after startup and was mostly performance based. I have a 8 hour frag match coming up if I can get the computer to stay normal for that 8 hours I will let you and we can go from there incidentally I will let you know first thing if I have a problem.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well EM_EXEC.EXE should be pretty self evident as being related to your Logitech mouse or trackball.

    ALCXMNTR.EXE - is part of your Realtek AC97 Audio (your sound card). It not really hardcore malware but many people do considered it to be spyware since Realtek uses it to collect information about customers. You could have HijackThis fix the below line and it should not cause you any problems:

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    You could also go a step further and have HJT fix the below items which are not required to load at startup:

    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background

    This will improve your startup time and overall PC performance too.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  17. Outlawstar15a2

    Outlawstar15a2 Corporal

    one question as i took note that they strongly suggest i backup critical info. I have alot of gaming based info stretching back at least several years. most of it is in the form of program specific data files. I have no way to back it up as i have no blank CDs or DVDs so does SP2 just overwrite OS files or does it clean out everything because I've heard alot of horror stories concerning SP2.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read this http://support.microsoft.com/kb/875364/

    See step 8 in particular but read all of it. But remember Microsoft is only backing up its own files not yours. None of your information is normally removed but backing up your files is always highly recommended.
     
  19. Outlawstar15a2

    Outlawstar15a2 Corporal

    the computer is working perfectly now. just one question on zone alarm i sometimes get a situation where zonealarm blocks multiple access attempts from the same IP address is there anywhere on the net I can go to see whos on the other end out of curiosity?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this one.

    http://cqcounter.com/whois/
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds