Unnusual Behaviour Flashing Screen etc..

Discussion in 'Malware Help (A Specialist Will Reply)' started by rDog, Feb 10, 2007.

  1. rDog

    rDog Private E-2

    Hi I have run your Read and Run Me First Guide through all steps and attached are the logs you require. Counterspy ran but didn't give me an option to save or view a log (from memory it didn't detect anything), so I ran AVG Anti Spyware and have posted that log.

    I am having a number of issues with the PC. The screen flashes black than goes back to normal almost every time you click a link or open a window. I have had a couple of user accounts appear out of nowhere, the system intermittently reboots at random (also happens when you use the mouse wheel). The adsl receive and transmit lights are extremely active (although I don't know if this is a problem or simply automatic updates). Windows and explorer pages don't load correctly and you either have to minimise and maximise to get text or roll cursor over to display the screen.

    Please help as I am concerned I have some form of malware or trojan/hacker program running that I can't see.
     

    Attached Files:

  2. rDog

    rDog Private E-2

    Additional logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox.

    Save it to its own folder somewhere that you will be able to locate it later.


    Please go to add/remove programs in the control panel and uninstall:

    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 7"
    J2SE Runtime Environment 5.0 Update 9"

    Now reboot and install:
    Java Runtime 6

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\sqmnoopt04.sqm
    C:\sqmdata04.sqm
    C:\sqmdata02.sqm
    C:\sqmdata03.sqm
    C:\sqmnoopt02.sqm
    C:\sqmnoopt03.sqm

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  4. rDog

    rDog Private E-2

    Thanks Tim. Followed all of your steps and everything appears to have run correctly. Have attached new logs as requested. Only thing that I have noticed is the system is slow when booting up but may be down to so many spyware processes starting up, not sure.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your problems as more than likely not malware related.

    I suggest first uninstalling the two items installed in the READ ME. CounterSpy & AVG Antispyware.

    Are the below paid or trial programs and did the problems start before or after installing them:
    Spyware Detector
    Uniblue Registry Booster
    Uniblue SpyEraser
    Uniblue System Tweaker

    Also what exactly was done with these programs and did the problems begin after doing whatever you did with these programs? Especially the Registry Booster and System Tweaker utilities.

    I don't think it is a good idea to have both SpywareDetector and SpyEraser running.

    If either are free trials, uninstall whichever is free. In fact it may be a good idea to uninstall both even if paid to see if the problems go away.
     
  6. rDog

    rDog Private E-2

    The problem was there prior to the spywares being downloaded, I downloaded them in an attempt to sort the problem out. I think both products are paid for, they were run in their standard format, I haven't changed anyhting with the registry tweaker. Should I uninstall them also?

    I will remove spyware detector and spy eraser as on startup spy eraser uses 100% of the cpu for quite a while.

    If it isn't malware should I be looking to another forum for system setup or hardware issues?

    Thanks.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you refering to the unknown user accounts? Are they still showing in the control panel and if so, what are they?
    You don't need to remove the registry tweaker if you plan on using it (carefully).

    This may speed up your start up!

    I would suggest starting in the software section.
     
  8. rDog

    rDog Private E-2

    Tim, no the problem I was referring to was the flashing screen, PC random rebooting and pages/programs not loading correctly. The user accounts happened a few weeks ago, and concerned me because one set itself up as wetnet (my service provider is westnet). I removed the accounts via administrator and they have not returned since.

    I will continue removing the unneccessary spyware and have alook at the software forum for any similar problems.

    Thanks for your help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds