Click here to fix problem..

Discussion in 'Malware Help (A Specialist Will Reply)' started by Podhalan, Mar 27, 2008.

  1. Podhalan

    Podhalan Private E-2

    Hey GEEKS!

    Little trouble here.
    Was looking for a Virtual Dongle to run Avid DVD studio, (lost a dongie durring last crash ) found something and tried to download...... rest you all can guess.

    I use AVG free and my ISP/DSL provider bundled security software from Telus.xxx

    AVG kept of finding different Trojans each time with one repeating Dropper.Agent.HHK

    Security Bundeled software found the same.
    Even when all scans I did with my ISP sec. bundle and online with simantec came clear, AVG was still going nuts.

    After running: SpyBot, SUPERAantispaware, malwarebytes and Xclean Micro seems I got rid off the bugs that were being fount by the software.

    Still my PC is so slow. I get this yellow triangle asking me to click on it to fix a problem.
    Also, so called System Security is bugging me with notifications about a posible virus infection and wants me to download PC-Cleaner software.

    My Outlook Express is a snail slow, most of time times out.
    IE turns a white frozen page at times.
    Opera runs fine so far but slow.
    Sometimes I get errors on program sturtups and when opening My Documents and such ... all freeyes as well.

    Boy! .... I wish I could tell ya more.:confused


    Have not run MGtools yet.
     
  2. Podhalan

    Podhalan Private E-2

    Hmmm.
    Is there something I need to do first so you can try to help me with my issue??
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome to Majorgeeks



    Do please run the Read Me guide below and follow all of the steps, do not skip any as its crucial to run them in the order given, then attach all the logs as requested and one of our malware experts will review then and reply with some further manual removal instructions if needed.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide plus a guide on how to attach the logs HOW TO: Attach Items To Your Post



    also please read this as bumping while putting you on the malware forum 1st page, does in reality move you to the back of the work queue, so while I know malware is damm frustrating, do be patient and try not to post un-necassary replies Don't Bump! It Only Hurts You!!!
     
  4. Podhalan

    Podhalan Private E-2

    Thank you for welcome!
    Halo... sorry, did not released this is a NO-NO. I have MODed on some help sites ... I understand your position and will respect 100%. PLS excuse me.


    Below are logs:

    MGlogs
    SAS
    MalwareBytes

    Please NOTE:
    SAS zip - contains - S&D logs, HijackThis log, ComboFix log.
    If you do not want to see those in the future pls let me know.

    SAS, MalwareBytes and S&D scans come clear of malware now, still I have issues with the PC being v. slow.
    Virus scanners find nothing.
    Takes close to a minute to open any window, Outlook Express is v. slow so is IE.
    Still receive the info 'yellow triangle' referring to download PC-Cleaner.

    Thanks a milion !!
     

    Attached Files:

    Last edited: Mar 28, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please only attach the logs we request and only attach one copy of them. You don't need to run things multiple times.

    Please start by disabling Spybot's Teatimer as requested in the READ ME. See: How to disable Spybot's TeaTimer


    Uninstall the below old versions of software:
    Java(TM) 6 Update 3
    Make sure you reboot after uninstalling the above!

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ngduqiwk] C:\WINDOWS\system32\xwxsfqpg.exe
    O4 - HKCU\..\Run: [qskgfxyo] C:\WINDOWS\system32\twlsdgrm.exe
    O4 - HKCU\..\Run: [tmlordyl] C:\WINDOWS\system32\rkhuvshe.exe
    O4 - HKLM\..\Policies\Explorer\Run: [F6iipNNJB3] C:\Documents and Settings\All Users\Dane aplikacji\hkpmhuzc\hgrqzgrq.exe
    O21 - SSODL: ComponentRunOnce - {b3703716-8b71-4e79-8101-cfe26b8aff77} - C:\WINDOWS\Installer\{b3703716-8b71-4e79-8101-cfe26b8aff77}\ComponentRunOnce.dll (file missing)
    O21 - SSODL: SysKernel - {ca7a31fc-ede3-47da-a0bd-d9f7ff91baf0} - C:\WINDOWS\Installer\{ca7a31fc-ede3-47da-a0bd-d9f7ff91baf0}\SysKernel.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  6. Podhalan

    Podhalan Private E-2

    Thank YOU!

    Did what was asked.
    Created - fixme.reg and saved to my desktop, clicked on it and..... nothing happens with the exception of a window oppening and asking me to choose a program to open fixme.reg

    Deleted old Java and installed new one.

    PC seems a little better with the exception of : when clicked on Shearch in under START tab I receive a white blanc page.. no place to input text.
    It just happened after instaling the fixes and Java.

    Here are the files:
    Also after uploading the files I have noticed a txt file that was created by MGtools and put on my desktop and not in the MGtools.zip folder.
    Not sure if this is needed or not.
     

    Attached Files:

    Last edited: Mar 29, 2008
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Note you do not need to put the Avenger logs in a ZIP file. I'm not sure why the procdll.txt file was not copied to the MGlogs.zip file. I would however guess it is because you did not follow the instructions for using MGtools. You did not download MGtools.exe to c:\MGtools.exe as requested. You have it here:

    C:\Documents and Settings\Krzysztof\Moje dokumenty\Moje Programy\MGtools.exe

    Also I did not ask you to run this last time. I asked you to run C:\MGtools\GetLogs.bat


    Your registry file association is broken. Do the below to fix this.

    Now Copy the bold text below to notepad. Save it as RegFix.reg to your desktop. Be sure the "Save as" type is set to "all files". Then Click Start, Run, and enter regedit and click OK. This will open the Registry Editor.

    In the Registry Editor click File and Import. Navigate to the RegFix.reg patch you saved on your Desktop and double click on it. Click OK at the prompt to add to the registry. Do you get a success message for this?
    Now retry the fixME.reg patch I gave in my last message. Did it work now? Did you receive a success message about the above being added to the registry?


    You can try the below. I'm not sure what caused this as nothing in the fixes should do this. We run these tools all the time. It is possible that malware actually did something to Windows Search and after removing the malware it causes this problem.

    Re-register Jscript.dll and Vbscript.dll, see if that solves anything.
    1. Click Start, and then click Run.
    2. In the Open box, type regsvr32 jscript.dll, and then click OK.
    3. Click OK.
    4. Click Start, and then click Run.
    5. In the Open box, type regsvr32 vbscript.dll, and then click OK.
    6. Click OK.
    Did the above help with Search?


    Your logs were clean last time.
     
  8. Podhalan

    Podhalan Private E-2

    OK.. good to know.

    Sorry.. you might be right...
    After the recent crash, I decided to save all new programs in a folder in My Documents first, so I can back them up easier.

    Believe me... I did.
    After the process was finished, I could not see the file .ZIP anywhere.
    I went to Shearch tab to find it.
    This is when I found it did not work.

    So.... not having any luck finding the GetLogs.zip on my PC, I decided to run MGtools to get some files for you.

    Yes it did work

    No go... did not work.
    Still asked me to choose a program to open the file.

    Did this... no help.
    Still cant use Search. - Blanc window.

    Can't thank you enough....
    THANKS
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but no you did not. I can tell by the HijackThis log that is embedded in the last MGlogs.zip file you attached. It shows you were running this:

    C:\Documents and Settings\Krzysztof\Moje dokumenty\Moje Programy\MGtools.exe

    It is right where the READ ME says it will be. And that is C:\MGlogs.zip.


    It is not GetLogs.zip. It is C:\MGlogs.zip.


    Just import it into the registry like you did with the RegFix.reg patch.


    Then you will most likely have to ask about this in the Software Forum.
     
  10. Podhalan

    Podhalan Private E-2


    Thank you VERY much for your help....
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds