Problems w/ IE, won't download.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JBOCARD, Dec 6, 2006.

  1. JBOCARD

    JBOCARD Private E-2

    I've attached my hijack this zip log file. For a while my PC was having issues that IE was showing up multiple times on my task manager process list, even when I wasn't running it..and it would continuously eat up more and more memory until my system slowed to a halt. I ran spybot and that seemed to stop it, but now when I try to download a file from an internet site, the popup box to download or save the file just blips and dissapears, so I do "save target as" when I can and get the file that way...but then when I try to open the .exe I download...nothing happens.

    any ideas?
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com, please follow our standard cleaning procedures:

    [​IMG] Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    [​IMG] Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    [​IMG]After doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    [​IMG] Downloading, Installing, and Running HijackThis
    • Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around..
    [​IMG]When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • CounterSpy
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. JBOCARD

    JBOCARD Private E-2

    I'm having major problems unfortunately. W/ my issue I cannot seem to get any program to download or run, so I cannot install the necessary things in your list. I had hijack this installed on my PC already.

    Also, I cannot find my windows firewall (I know where it should be) to change the settings on it..and when I right click on a network connection and try to select properties, it blips on the screen for a second and dissapears as well.

    I'm sorry I can't follow all your instructions, but I hopw you understand that I have tried.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Pleaase at least install and rename HijackThis as required. You have this:

    C:\Documents and Settings\Justin & Sanya Bowen\Desktop\HijackThis.exe

    You need to have it like below:

    C:\Program Files\HJT\analyse.exe

    This is very important and is mentioned in step 7 of the READ ME. Don't attach a new log yet though! Wait until doing the below.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    R3 - URLSearchHook: (no name) - _{A6612371-09EA-2945-113A-A0861B194766} - (no file)
    O2 - BHO: (no name) - {c23594b2-804f-4051-b84e-de5104e057f1} - C:\WINDOWS\system32\Gapext.dll (file missing)
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/05f0f54dc0405ea2c003/netzip/RdxIE2.cab
    O20 - Winlogon Notify: ftpwave - C:\WINDOWS\system\ftpwave.dll (file missing)
    O20 - Winlogon Notify: Gapext - Gapext.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach a new log from a properly installed and renamed HijackThis

    Any change to your problems?
     
    Last edited: Dec 9, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds