Windows 7 - Computer weirdness

Discussion in 'Malware Help (A Specialist Will Reply)' started by Menlo, Aug 9, 2013.

  1. Menlo

    Menlo Private E-2

    Hey

    Been having some weird issues as of late:

    Couple weeks back I was on chatroulette (Boredom), and one claimed that he could see my desktop (with good evidence... he able to see the tabs I had opened).

    Now today, I believe I heard a voice coming from my computer (twice), was unable to catch any (was listening to music on other speakers) of the words.
    Then later I heard what sounded like phone calling again from the computer.

    In both instances I'm not 100% sure what I heard, but fairly certain I heard something and that it wasn't caused by anything I was doing.

    The logs are attached, however mbam log is only the most recent,
    I ran mbam twice after my first incident.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs are clean. The only problem observed is the illegal copy of MS Office.

    We can run a couple more scans just to be sure.


    Please run the below anti-rootkit tool from Malwarebytes.

    http://blog.malwarebytes.org/news/2013/05/malwarebytes-anti-rootkit-beta-1-06/

    Attach a log from the above.



    Now download and save a copy of combofix.exe and save it directly onto your Desktop folder.
    • Then right click on it and select Run As Administrator. Do not disturb it by clicking in the window that opens or it may stall.
    • After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.
    • If after running Combofix you discover none of your programs will open up because you receive the following error:
      • Illegal operation attempted on a registry key that has been marked for deletion
    • Then you will need to reboot your computer which will normally fix this problem.
     
  3. Menlo

    Menlo Private E-2

    Hey

    I uploaded the logs, I also included to extra mbam logs (The two times I ran a scan before today/yesterday)

    Also files "desktop.ini" have started to pop up everywhere (with the hidden flag)
    is it safe to delete them? (in my desktop, download and documents folders )
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Malwarebytes Anti-Rootkit and ComboFix logs were also clean.
    The only thing detected here was the below which is from what I already mentioned ( the illegal copy of MS Office ).
    .
    You don't need to delete them. They are part of Windows and always were there. You just did not see them until viewing of hidden and system files was enabled while running the READ & RUN ME. The below should restore normal settings.



    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds