Solved IT Professional cannot solve this maybe you can - Malware/virus

cannonone

New member
Local time
12:14 AM
Messages
3
To anyone out there that has an idea what this is......

Pops up in my task bar every few minutes

It so quick you cannot see it, i took a video and paused the image

It looks like a CAT, i cannot work this out.

So FAR

Ran Antivirus scan ( macfee + trend micro house call)
Malwarebytes - nothing
Spybot - nothing

Stopped all start up programs in msconfig
killed almost all processes
de-installed any recent software that was installed

Im out of ideas, this is a relatively fresh Corporate/install WOT IS THIS ?

Many thanks

Cannonone
 

Attachments

  • cat look alike.jpg
    cat look alike.jpg
    29.3 KB · Views: 111

My Computer My Computer

OS
32 bit
Hi,

Is this PC used with any barcode scanners to catalog items? Can you do a search for catnip.exe on this PC?

Regards,
Golden
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Hi,

No its a standard office PC

Thanks for the advice though
 

My Computer My Computer

OS
32 bit
I would suggest running Process Monitor. This will show you exactly what processes are called in realtime.

Process Monitor
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2
Try running ComboFix:

A guide and tutorial on using ComboFix

It finds and fixes rootkits and other malware that nothing else seems to be able to find.

Do not get impatient when it runs; there are over 50 different tests it makes, and it reboots your PC several times.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built
OS
Win7-64
CPU
Intel i7-3770S
Motherboard
ASUS P8Z77-M
Memory
16GB
Graphics Card(s)
nVidia GT630
Sound Card
onboard
Monitor(s) Displays
dual
Screen Resolution
1920x1200 (primary) 1050x1680 (secondary)
Hard Drives
128GB SSD (boot)
64GB SSD (Temp/My Documents)
500GB (photos/videos)
1TB (rendered video, backups)
PSU
650W
Case
Thermaltake A30
Cooling
Thermaltake
Keyboard
Logitech Lighted
Mouse
Kensington Expert Mouse (trackball)
Internet Speed
FIOS 35/35
Antivirus
MS Security Essentials
Browser
Chrome (beta)
Hi,

My recommendation is to only run Combofix under the guidance of a trained malware proffessional - we have a few here that will be able to help you with that if they think it is appropriate. They may also recommend something entirely different.

Under no circumstances should you just run Combofix blindly without proffesional guidance. Every single reputable site that references Combofix (incl. the one linked above) contains this very explicit warning:


You should not run ComboFix unless you are specifically asked to by a helper. Also, due to the power of this tool it is strongly advised that you do not attempt to act upon any of the information displayed by ComboFix without supervision from someone who has been properly trained. If you do so, it may lead to problems with the normal functionality of your computer.

That warning is there for a very good reason. We shouldn't post recommendations for using Combofix without the same warning.

Regards,
Golden
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Golden:

My post was based solely on my own experience which was a rootkit that I discovered on my Win7-64 system. I tried a couple of different anti-malware products, none of which found or fixed anything. ComboFix was the 3rd or 4th fixer I tried and it simply ran to completion and fixed my problem. I had no external help or support for this; I just ran it. So it's not clear to me what "professional guidance" means or could accomplish. Combofix did generate a lot of messages & logs etc. which I did not understand, but the bottom line was it fixed my problem with no intervention on my part.

I guess a situation could occur where ComboFIx, or any other anti-malware product, could encounter some unforeseen situation and result in a non-bootable system (or some other bad problem) but that was not my experience at all and I felt making the OP aware of the fix that worked for me would be helpful.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built
OS
Win7-64
CPU
Intel i7-3770S
Motherboard
ASUS P8Z77-M
Memory
16GB
Graphics Card(s)
nVidia GT630
Sound Card
onboard
Monitor(s) Displays
dual
Screen Resolution
1920x1200 (primary) 1050x1680 (secondary)
Hard Drives
128GB SSD (boot)
64GB SSD (Temp/My Documents)
500GB (photos/videos)
1TB (rendered video, backups)
PSU
650W
Case
Thermaltake A30
Cooling
Thermaltake
Keyboard
Logitech Lighted
Mouse
Kensington Expert Mouse (trackball)
Internet Speed
FIOS 35/35
Antivirus
MS Security Essentials
Browser
Chrome (beta)
thanks all.

Through trying to install combofix which did not work. The error changed its form and i was able to see what the pop was. Ended up being the Interactive Services Detection service. I cant believe it, i have disabled the service as i have spent enough time on this problem

For those who want to see exactly
Troubleshooting Interactive Services Detection - Pat's Application Compatibility Blog - Site Home - MSDN Blogs

I could go into more detail in analyzing this, but have many other support issues at work to deal with.

Its not a proper solution i know but im happy with it
 

My Computer My Computer

OS
32 bit
Great news!!! Well done.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Golden:

My post was based solely on my own experience which was a rootkit that I discovered on my Win7-64 system. I tried a couple of different anti-malware products, none of which found or fixed anything. ComboFix was the 3rd or 4th fixer I tried and it simply ran to completion and fixed my problem. I had no external help or support for this; I just ran it. So it's not clear to me what "professional guidance" means or could accomplish. Combofix did generate a lot of messages & logs etc. which I did not understand, but the bottom line was it fixed my problem with no intervention on my part.

I guess a situation could occur where ComboFIx, or any other anti-malware product, could encounter some unforeseen situation and result in a non-bootable system (or some other bad problem) but that was not my experience at all and I felt making the OP aware of the fix that worked for me would be helpful.

I understand your point of view on this and can understand why you would suggest this as a fix, but sometimes combofix can really mess up a computer if it is badly infected. A professional will know what can and cant be cleaned with combofix or if another anti-malware option is better and safer. Here is a guide to combofix from a site that specializes in computer infections including all the warnings:

A guide and tutorial on using ComboFix
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2
Thorsen

That link is the same one I referenced in my original post. Reading through the guide does not reveal any significant decision points where some sort of expert knowledge is required. And that was precisely my experience - although the software took a while to run it did not put up any dialogs or options that I was not able to understand. So as I noted, I simply ran the software and it fixed my problem, which apparently was a rather obscure one.

I understand the potential for problems when dealing with something like a rootkit, but it seems to me its up to each user to decide if the risk of such problems is worth the benefit of fixing the problem....or not. My post was intended to give the OP the option of taking that risk, or not, depending on his perception of his particular situation.

If you are aware of bad things happening from running ComboFIx I'd be interested to hear them.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built
OS
Win7-64
CPU
Intel i7-3770S
Motherboard
ASUS P8Z77-M
Memory
16GB
Graphics Card(s)
nVidia GT630
Sound Card
onboard
Monitor(s) Displays
dual
Screen Resolution
1920x1200 (primary) 1050x1680 (secondary)
Hard Drives
128GB SSD (boot)
64GB SSD (Temp/My Documents)
500GB (photos/videos)
1TB (rendered video, backups)
PSU
650W
Case
Thermaltake A30
Cooling
Thermaltake
Keyboard
Logitech Lighted
Mouse
Kensington Expert Mouse (trackball)
Internet Speed
FIOS 35/35
Antivirus
MS Security Essentials
Browser
Chrome (beta)
Sorry that was a reading comprehension failure on my part. I didnt see your link.

The only thing I can say is that it tries to repair compromised computer data. This data in some cases would be crucial for system integrity. If you have a rootkit then the system is past integrity being the main issue. Your issue now is recovery if possible. As to what it does specifically, the secrets behind it are not often discussed to prevent malware creaters from bypassing its abilities. I know it does seek out registry keys specifically for certain things and it looks at the file structure, programs listed in the registry and other types of data to look for rootkits that often get missed by other anti-malware programs.

If you have a simple malware program on your computer, there are safer ways of going about removal instead of combofix that have less impact on system files. Even if your malware is missed by the top antivirus programs, there are specific fixes designed for specific infections that are still way safer. A pro will know what programs can fix these infections and will only use combofix if there is not another specific program that will help. That is why it is warned to stay away unless helped by a pro. there are a lot of people who get computer infections and most of them are either unskilled or dont know how to clean their computer other than running program X. Program X being combofix, I have to stress the reluctance with running this program as a solution.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2
Back
Top