Can I download HJT

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Timton, Dec 11, 2004.

  1. Timton

    Timton Private E-2

    I have something affecting my computer. I want to download HJT to a cd and load it on my laptop. Whatever has taken control of my laptop, will not allow me to log onto the internet...everytime I try I get a blank screen and the following shows up in the address window res://kzzg.dll/http-404.htm

    So I'm asking if I could download HJT ?

    Timton
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Timton,

    You can put HijackThis on a floppy (or CD).

    If you are having Malware Problems, I would suggest that you first print out all of the instructions here:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    Then, you should Download all of the anti-malware tools prescribed in the link and put THEM on a CD and run them on your ailing machine as per the Read Me Tutorial. HJT is really a last step.

    Best :)

    PP
     
  3. Timton

    Timton Private E-2

    PhilliePhan, I followed all direction as best as I could from "READ ME FIRST" The first problem I ran into was under "Scanning & Cleaning Steps" I could not the scans from "Trend Mirco or Symantec Security Check" because I can get my computer to log-on to the internet. I did download all the scan software that is suggested and ran all the scans. I did stop at the final OPTIONAL steps, as I am a novice and and I'm not sure if I should be doing those steps.

    I tried to connect to the internet and I'm still getting the "res://kzzg.dll/http-404.htm

    I could sure use some assistance.

    Timton
     
  4. PhilliePhan

    PhilliePhan Guest

    Hi Timton,

    Please send us a HijackThis Log for the ill computer. Please make sure to locate HJT in C:\Program Files\HijackThis.

    Then, scan in Normal Windows and save the log as a .txt file. If you need to put the log on a floppy and use a different computer to post it, please do so.

    Make sure to attach your log via the "Manage Attachments" tool when you post back. Somebody will take a look when they get a chance.

    Best Luck :)
    PP
     
  5. Timton

    Timton Private E-2

    I hope I did everything correctly! Thanks for all your help with this, I hope can find whats going on with my computer!

    timton
     

    Attached Files:

  6. PhilliePhan

    PhilliePhan Guest

    Hi Timton,

    There are a lot of Trojans and assorted Malware on your machine.

    Please download the following tools and run them (if possible). Run them both twice each:

    Peper FIX

    a-squared (a²) Free edition
    Note that this one requires an email address to register. You may have to do this first from a working machine.

    After doing the above, attach a fresh log and we'll go about removing the remaining malware!

    PP :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here are the fixes you need!

    You need to download LSP-Fix to your other computer and then get it on to your broken one.
    Download it here: http://www.majorgeeks.com/download4180.html
    Unzip it and run it. Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move aklsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.


    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\WINDOWS\sysqt32.exe
    C:\Documents and Settings\Tim\Application Data\osoa.exe
    C:\WINDOWS\System32\?hkdsk.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\lyinr.dll/sp.html#32526
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {3AC2B270-5616-68F4-58BA-C0AC2CB2188C} - C:\WINDOWS\sdknu32.dll
    O4 - HKLM\..\Run: [27] C:\temp\27.exe
    O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\LsxI62.exe
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
    O4 - HKLM\..\Run: [vwneuc] C:\WINDOWS\System32\vwneuc.exe
    O4 - HKLM\..\Run: [pynqgngfpsxdd] C:\WINDOWS\System32\pxilsj.exe
    O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
    O4 - HKLM\..\Run: [netlp.exe] C:\WINDOWS\netlp.exe
    O4 - HKLM\..\Run: [sysqt32.exe] C:\WINDOWS\sysqt32.exe
    O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
    O4 - HKCU\..\Run: [Ncao] C:\Documents and Settings\Tim\Application Data\osoa.exe
    O4 - HKCU\..\Run: [Bfzqkmh] C:\WINDOWS\System32\?hkdsk.exe
    O10 - Broken Internet access because of LSP provider 'c:\windows\system32\aklsp.dll' missing

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\lyinr.dll
    C:\WINDOWS\sdknu32.dll
    C:\WINDOWS\sysqt32.exe
    C:\Documents and Settings\Tim\Application Data\osoa.exe
    C:\temp\27.exe
    C:\WINDOWS\System32\LsxI62.exe
    C:\WINDOWS\System32\winupdtl.exe
    C:\WINDOWS\System32\vwneuc.exe
    C:\WINDOWS\System32\pxilsj.exe
    C:\Program Files\SED <--- the whole directory
    C:\WINDOWS\netlp.exe
    C:\WINDOWS\sysqt32.exe
    C:\Program Files\Common Files\tsa <--- the whole directory
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. PhilliePhan

    PhilliePhan Guest

    What happened to "Mr. One step at a time?" Anyhoo, thanks Chas :)
    Timton - Let us know how Chas' instructions shake out.

    PP
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL! It was one step at a time! Just all in one message! :p
     
  10. Timton

    Timton Private E-2

    Chaslang, I'm in the process of following your instructions to a tee. But, there's always a BUT. I can't find the following in the HJT log:

    O10-BrokenInternet access because of LSP provider 'c:\window\system32\aklsp.dll missing

    Is this someting I should be concerned about?

    timton

    PS Thanks for your help
     
  11. PhilliePhan

    PhilliePhan Guest

    If you ran LSP-Fix as per Chas' instructions, then that should be gone.
    Carry on :)

    PP
     
  12. Timton

    Timton Private E-2

    Chaslang & PhilliePhan, I followed all the directions. Some of the things Chaslang told me to delete in safe mode could not be found. I thinking this is a good thing. As instructed I am posting another HJT log. Please take a look at it and let me know what you see or don't see.

    Thanks again!!!!!

    timton
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Hey, HiJack This 1.99.0 was just released update to this version and post new log. Make sure you run HiJack This from ex. C:\Program Files\hijackthis\HijackThis.exe The log you posted from version 1.98.2 looks good. Are you still having problems?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Agreed! Get the new version and repost but your log looks clean now!
     
  15. Timton

    Timton Private E-2

    Chaslang, I can finally get onto the internet. I'm still getting pop-ups but can get onto the internet. I tried to download the new version of HJT and save it to a disk to load it on my laptop but I get a message telling me I need permission.

    I want to thank you for all your help!!!! I was completely lost and totally frustrated with this problem!!!

    Is there anyway of blocking these pop-ups completely?

    timton
     
  16. Timton

    Timton Private E-2

    Chaslang, I did get HJT to download to the problem computer and here is the HJT log. Take a look and let me know what you see.

    Thanks
    timton
     
  17. Timton

    Timton Private E-2

    OOoopsss I didn't get the attachment on that last post...I'll try again
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do the popups say? And when do they occur?

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O15 - Trusted IP range: 206.161.125.149
    O15 - Trusted IP range: (HKLM)

    Do you know what this next line is for? If not, fix it too.
    O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://centra.waddell.com/SiteRoots/main/Install/CentraDownloader.cab

    O23 - Service: ISEXEng - Unknown - C:\WINDOWS\System32\angelex.exe (file missing)
    O23 - Service: WLTRYSVC - Unknown - C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe (file missing)

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
    You should look into taken the steps I discuss here: How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds