Can't download .exe or run antimalware programs - help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by huffk, Apr 5, 2011.

  1. huffk

    huffk Private E-2

    Hi there. Last week I was hit with antimalware doctor popups. I don't think that anyone in my family clicked on any of the false advertisements but not 100% sure. I ran a hijack this and removed the antimalware doctor files and I'm not seeing that specific popup, however there's tons of other popups in both firefox and IE. System errors like Explorer.exe suddenly stops working is also now a common occurrence.

    1. OK so I did the Read ME stuff and something is blocking me from downloading .exe files so I couldn't get Malwarebytes, MGTools, Rootrepeal, or Combofix. Also something causes Spybot S&D and SUPERAntispyware (both previously installed) to hang up and not finish their job.
    2. I deleted Viewpoint Player.
    3. I couldn't specifically figure out how to turn off MSCONFIG. Help there would also be appreciated.

    I can't thank you all enough in advance. Apologies if I didn't do everything you all asked but I tried. Nothing seems to be working for me though. And I suck at this.

    THANK YOU!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, are you saying that you can download programs but they just don't run or do you mean something is blocking you from downloading? Can you download to a different computer and transfer them via USB thumb drive?

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now you will need to try to manually delete the following:
    C:\WINDOWS\system32\tukdtjsr.exe
    C:\WINDOWS\system32\tukdtjsrx.exe
    C:\WINDOWS\negics.dll
    C:\Documents and Settings\oneild\Application Data\C7EACBD9EFBAAC660C4807161DE2A93D\satdll70snn.exe
    C:\DOCUME~1\oneild\LOCALS~1\Temp\zitui1.exe
    C:\Documents and Settings\oneild\Application Data\C7EACBD9EFBAAC660C4807161DE2A93D\upd_debug.exe

    Now see if you can download and run the scans.
     
  3. huffk

    huffk Private E-2

    Hi Tim. Thanks for the assistance.

    I don't currently have another computer available to do the thumb drive thing.

    I did what you said with hijack this and fixed everything.

    I couldn't find the tukdtjsr.exe or tukdtjsrx.exe files.
    I was not allowed to delete negics.dll
    I deleted upd_debug.exe
    I couldn't find zituil.exe or satdll70snn.exe in that folder.

    Still cannot download malwarebytes. It starts to inn the firefox download queue but just says canceled. When I click the retry button it says it downloads but the file comes out 0kb i n the download folder.

    Should I try to run SUPERantispyware again? Thanks!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try running the tools you have in safe mode with networking. See if you can download then. Do try to run as many of the tools as you can. Tell me what happens if you try running MGTools.

    We can also try doing this:
    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now lets see if you can download this:

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Where you able to do that?
     
  6. huffk

    huffk Private E-2

    Hey Tim - thanks again for helping.

    OK so the current state of affairs is this. I was able to update and run SUPERantispyware and spybot S&D in safe mode. They didn't really come up with anything of significance beyond tracking cookies and I don't know where it saves logfiles for those programs if it does at all.

    I can't download .exe or the exehelper.com file. In Firefox it brings up the downloader but says that the file download has been canceled. If I retry it looks like it downloads but the file is empty on my desktop. I tried in IE and there's a popup that says that my security settings do not allow me to download the file.

    I just downloaded the avenger.zip file but windows won't allow me to unzip it.

    Is there some way to override whatever's not allowing me to download or open these files?

    About to run the online scan... will let u know what happens.

    Thanks again!
     
  7. huffk

    huffk Private E-2

    Scratch that about avenger. It was blocked by IE but I was able to run it with firefox and it opened.
     
  8. huffk

    huffk Private E-2

    Also - no luck with the Super antispyware online scan either. Blocked :(
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So you were able to get Avenger to open?

    If so:

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Attach the log which will be:
    C:\Avenger.txt

    Now see if you can download and run the other scans.

    Go ahead and re-run HJT and get me that log, but first, rename it to analyse.exe.
     
  10. huffk

    huffk Private E-2

    OK. Ran Avenger and the log is attached. I got a system error popup upon reboot saying "Error loading Negics.dll ... module not found" so that's probably good. Is there a way to get rid of that error message?

    I still can't download any .exe files.

    Thanks for your time on this and helping me out.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Xpokuy] rundll32.exe "C:\WINDOWS\onetilarejucow.dll",Startup
    O4 - HKCU\..\Run: [Pguwakulejarivew] rundll32.exe "C:\WINDOWS\negics.dll",Startup

    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    See if you can download the reg fix:
    http://www.dougknox.com/xp/file_assoc.htm
    (Scroll down to the exe fix ).

    Were you able to download MGTools? If so, try renaming the extension to MGTools.com and see if it will run. If not let's try a different tool.

    Download OTL by Old Timer. and save it to your Desktop.

    * Double click on OTL.exe to run it.
    * Under Output, ensure that Minimal Output is selected.
    * Under Extra Registry section, select Use SafeList.
    * Click the Scan All Users checkbox.
    * Click on Run Scan at the top left hand corner.
    * When done, two Notepad files will open.
    o OTListIt.txt <-- Will be opened
    o Extra.txt <-- Will be minimized
    * Please post the contents of these 2 Notepad files in your next reply.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am about to shut down for the night. Long day. I have asked the other malware fighters to check in to see if there is something I may have missed that might help. In the meantime, do try to do the things I posted and if necessary, do them in safe mode. I will be back tomorrow. ;)
     
  13. huffk

    huffk Private E-2

    You are a true jedi.

    thanks again!
     
  14. huffk

    huffk Private E-2

    Alright I did the avenger and it's attached.

    Again I'm still not able to download any .exe files even after running Dougs .exe fixer. Are there any links to these programs that are .zips? Apparently I can download .zips in Firefox and then just run them from the firefox downloader. I don't have that option anywhere else and whatever bogus security settings these malware gave me has made it so i can't download or run anything.

    Soooo frustrating. :guns
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try and get this to run however you can but preferably with the way the instructions provided!

    Please download RogueKiller.exe and save it to your desktop.
    • Now quit all running programs.
    • Double click RogueKiller.exe to run it.
    • When prompted, type 1 and hit Enter.
    • A RKreport.txt should appear on your desktop.
    • Note: If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe .
    • Please post the contents of the RKreport.txt in your next Reply.

    Now are you able to run anything of the READ & RUN ME FIRST. Malware Removal Guide :) ?
     
  16. huffk

    huffk Private E-2

    Hi Kestrel - thanks for trying to help but I can't download anything that ends in a .exe or .com.

    It seems like I can only download .zip files b/c Firefox allows me to just run it directly.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this then
     

    Attached Files:

  18. huffk

    huffk Private E-2

    Thanks - that worked! logfile attached.

    So my computer has started freezing up recently and for some reason I couldn't connect to the internet a little bit ago. When I rebooted everything was fine again except I got a Data Execution Prevention popup saying that it closed a program called Generic Host PRocess for Win32 Services (Publisher Microsoft Corporation). Not sure what that means.

    It seems like the longer i leave it on the more problems it starts having until eventually it completely freezes up and I have to force a reboot by holding the reset button.

    I tried to download mgtools, combofix, and malwarebytes again but no dice. It says that they're all binary files and cancels the download.

    :(
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's take another shot at it with this:

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif


    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.

    If you are having problems running Rkill, you can download iExplore.exe or eXplorer.exe, which are renamed copies of Rkill.com, and try them instead.

    * If the tool does not run from any of the links provided, please let me know.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to use another computer to download all of the tools needed to complete the R&R, then transfer over onto the sick PC to run? :confused
     
  21. huffk

    huffk Private E-2

    I'll see if I can get someone to put these files on a thumb drive b/c it's just not working right now.

    Will check back with you all on Monday with some positive results hopefully. Thanks!
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds