Threat Detected, Then Video Switching Between Monitors

Discussion in 'Malware Help (A Specialist Will Reply)' started by csebasti, Feb 11, 2017.

  1. csebasti

    csebasti Private E-2

    Two days ago on Wednesday 2/8, my wife was searching on the web, and got an Avast warning that a threat had been detected. She closed the sight, and then didn't notice anything else for a little while till later that day. She woke the computer up from sleep mode, and the secondary monitor did not wake up. Also, the programs that had been open on that monitor were all on the primary monitor. I checked it later, and the primary monitor did not wake up, but the secondary did and had switched to being the primary. When I tried detecting monitors, it said there were on other monitors. I restarted, and both came on, but then the secondary went blank within a couple seconds. Again, no other monitor was detected. As I sat here trouble shooting, the monitors switched on and off every few minutes sometimes both on, sometimes one, sometimes the other. Each switch I got the windows ding noise when new hardware is detected.

    While all this was going on, I continuously got Zonealarm popups of suspicious behavior saying something about pwershell.exe. I kept denying it, not knowig what it was. I ran a smart scan with Avast, and 3 programs were identified for updates, so I let it update them. After that the powershell.exe popups stopped. At this point I still only had one monitor working. Then I ran a full scan, and 4 items were found, and resolved. Both monitors are back on now, and they seem to be staying this way.

    Also of note is that the computer hasn't been going into sleep mode consistently since this started. Last night when clicking on the power button in the start menu, "Sleep" was no longer an option, only "Shut down" or "Restart". Today "Sleep" is back. I'm not sure what that is all about.

    I ran all the scans in the "read and Run Me first" thread. Logs are attached.

    I'd appreciate some help determining if there is an issue, and what could possibly have caused the strange behavior with the monitors. It's like something took over control of the video card...

    Thanks for the help.

    Chris
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it remove these items:

    ¤¤¤ Files : 3 ¤¤¤
    [Tr.Gen0][File] C:\Users\Sebastian\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe -> Found
    [Tr.Gen0][File] C:\Users\Sebastian\AppData\Roaming\uTorrent\updates\3.4.9_42923\utorrentie.exe -> Found
    [Tr.Gen0][File] C:\Users\Sebastian\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe -> Found

    Then rerun Hitman and remove these items:

    Potential Unwanted Programs _________________________________________________

    ask.com
    C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Web Data

    HKLM\SOFTWARE\Classes\s\ (Softonic)

    Rerun ADWCleaner and remove these:

    Chrome pref Found: [C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Web data] - aol.com
    Chrome pref Found: [C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Web data] - ask.com
    Chrome pref Found: [C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Web data] - wta.org

    Reboot and rescan with both Hitman and RogueKiller and attach the new logs.
     
  3. csebasti

    csebasti Private E-2

    Thanks for the help, Tim.

    I ran RogueKiller and deleted the three items. RK_Delete.txt log attached.

    I reran Hitman. The ask.com item did not come up, but the Softonic item did. I removed it. HitmanPro_20170211_2053.log attached.

    I reran ADWCleaner. It did not find anything. AdwCleaner[S1].txt log attached.

    I rebooted, and reran RogueKiller. Found 0 items. RK_after_reboot.txt log attached.

    Reran Hitman. Found the ask.com tool bar this time. Deleted it. HitmanPro_20170211_2125.log attached.

    Rebooted and reran Hitman. Found nothing. HitmanPro_20170211_2133.log attached

    I zipped the files since I think 6 is over the limit for one post.


    I have a few more questions:

    1. I now have two desktop.ini files on my desk top that were not there before running all this tonight. Is that expected? How do I get rid of or hide them?
    2. any idea why my video card seemed to be going haywire with my monitors? Does there appear to have been anything on the computer that would have caused that?
    3. Should I be concerned about the powershell.exe warnings I was getting from Zonealarm? Haven;t goten one in a few days now, so it looks like that stopped.

    Thanks again for your help. I really appreciate it.

    Chris
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should pursue the video card issue in the hardware forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  5. csebasti

    csebasti Private E-2

    Thanks again for the help. I went through your last steps and everything seems good. I'll ask about the video thing on the hardware forum.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds