Weirdest Thing

Discussion in 'Malware Help (A Specialist Will Reply)' started by amrof, Sep 21, 2008.

  1. amrof

    amrof Private E-2

    Okay.. It started yesterday night.. I was surfing nothing dangerous.. and for some reason I cant right click anymore.. I mean I cant right click in my IE nor my desktop.. I cant even open taskmanager or run..
    After I restart everything is back to normal..
    Tonight.. It happens again.. This time worse.. Live Messenger is totally deleted from my laptop.. Computer starts messing around.. I cant right click nothing! AVG stops working.. Spybot stops working.. Taskmanager doesnt open.. Run doesnt open.. I scanned with Spybot. AVG.. SuperAntiSpyware.. Checked for weird installed things in Add/Remove.. nothing!!
    Did an online scan.. and also no result..
    Can someone please please help! The thing is I cant find out if it fixed it at the right time... Does anyone know what the problem is??
     
  2. amrof

    amrof Private E-2

    Please help!

    I dont know what it is.. I scanned for it and havent found anything.. Sometimes im not allowed to right click anymore and I can open run or taskmanager. My computer starts messing around. Please help! here are my logs..
     

    Attached Files:

  3. amrof

    amrof Private E-2

    Re: Please help!

    Combofix..
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It really does not sound like this is a malware problem. Especially if it is only happening sometimes. You should check to see if it occurs in Safe Boot mode and also in normal boot, use a different user account and see if it still happens.

    Let's cleanup some items that I do see.

    First uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 5

    Now you MUST disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now look on any other hard disks and removable drives (like flash drives) for the below files and delete them if found. If you use a flash drive, you may have spread these infections to other PCs where you inserted the flash drive.

    d.com
    fooool.exe
    main.vbs
    rqq2v.bat
    t.com
    xp19.com



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. amrof

    amrof Private E-2

    Well everything seems fine now..
    Thanks for everything!
    Here are the logs...
    and just one more question.. Can I put my startup back to Custom?
     
  6. amrof

    amrof Private E-2

    Everything seems fine now..
    Thanks for everything..
    Just one question.. Can I go back to Custom Startup?
    Here are the logs..
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But according to your ComboFix log the fix I gave you did not work. Did you have any problems making the script file and getting it to run. Was the KILLALL:: line the first line in the file?


    No! Normal Startup mode is what you should be in as stated in the READ & RUN ME step 1.
     
  8. amrof

    amrof Private E-2

    Yes, I did everything like you told me. The script file gave me a message saying it was succesful.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not. I still see C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe running in your logs and this may be why the steps did not work. I asked you to disable this before you ran the other steps. Please follow the previous instructions again and make sure you do ALL steps. Teatimer must be disabled.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds