Solved

Suspected Malware

Posted on 2016-09-11
13
53 Views
Last Modified: 2016-10-16
Hi Experts,

I have been through my usual programs with this one....any suggestions

Desktop:
HP: All In One Desktop running Windows 10 Home

Symptoms:
Flashing circles appearing on the desktop
A second mouse icon suddenly appears from nowhere & a Word document keeps trying to opening usually the last document that failed to open.
Along with some pictures opening the onscreen keyboard and bottom right of screen the calendar opens as well.

I downloaded and checked With Process explorer but that even opened a heap of dialogue boxes when I hovered over or clicked on one in particular.

The calendar and onscreen keyboard usually shut themselves down after a while.


Things I have tried:
Malwarebytes have now run three times twice in Chameleon mode all time and found nothing!!
Registry investigator (which showed nothing out of the ordinary)
TDSKiller (nothing found)
Hijackthis. (nothing bad found)
CCLeaner  - Cleaned up a bit but made no difference
HitmanPro  - nothing much
Junkwaretool (a couple of things)
ADWCleaner (found two things and removed)

Again nothing that is sticking out as major in terms of virus or malware...


Advise apart from a wipe and reload much appreciated.Southern


thanks.
0
Comment
Question by:it_fan
  • 3
  • 3
  • 2
  • +4
13 Comments
 
LVL 23

Expert Comment

by:NVIT
ID: 41793609
See my post here, using Autoruns
0
 
LVL 6

Expert Comment

by:K_Wilke
ID: 41793612
I would try emsisoft which can be found here:
https://www.emsisoft.com/en/
If anything tries to run that is sneaky it will ask you if it is okay and from there you can remove it or do research on it.
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 41793618
basically do you mean when the chaos starts. the computer behaves strangely like doing random things on its own?

if so, how do you stop it? wait until it stops or reboot the computer?
0
 
LVL 6

Expert Comment

by:K_Wilke
ID: 41793623
Download the emsisoft if possible on that computer, install it, enable PUPS detection (it will ask when you install) then reboot
As soon as the chaos tries to start emsisoft will pop up a screen if you want to allow this or not
0
 

Author Comment

by:it_fan
ID: 41793634
Thanks trying suggestions as we speak!!
0
 
LVL 90

Expert Comment

by:John Hurst
ID: 41793652
If the earlier suggestions do not work and your machine is seriously hosed, back up the hard drive (boot with a bootable CD) and then reinstall Windows 10.
0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 
LVL 91

Expert Comment

by:nobus
ID: 41793757
can it be the pc is hijacked?
0
 
LVL 23

Expert Comment

by:DanCh99
ID: 41794389
If you UNPLUG  the keyboard and mouse before you turn it on, does it still do it?

I'm wondering if you have a faulty keyboard / mouse that's going berserk with some stuck keys, etc.

If this helps, try different physical devices.  I'd also try logging in as a different user to see if it's a profile problem.
0
 
LVL 23

Expert Comment

by:DanCh99
ID: 41794392
Does it also have a touchscreen?  That could be at fault too...
0
 

Accepted Solution

by:
it_fan earned 0 total points
ID: 41795149
Hi Experts,

Sorry didn't get a chance to jump back on last night and let you know it is resolved....I called HP on a chance they were aware of issues as I was convinced it was virus & malware free after my cleanup.

Turns out they are aware that particular model has a touchscreen problem and will need to be sent back for repair.

Thanks so much for your suggestions
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 41795609
thanks for the feedback. your experience and HP's feedback let me recall my experience on a crazy iPhone 5s.
0
 
LVL 23

Expert Comment

by:DanCh99
ID: 41809671
it_fan - anything else you need here, or can you close this?
0
 

Author Closing Comment

by:it_fan
ID: 41845487
Resolved by me.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Storage devices are generally used to save the data or sometime transfer the data from one computer system to another system. However, sometimes user accidentally erased their important data from the Storage devices. Users have to know how data reco…
A Bare Metal Image backup allows for the restore of an entire system to a similar or dissimilar hardware. They are highly useful for migrations and disaster recovery. Bare Metal Image backups support Full and Incremental backups. Differential backup…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now