Can't Download HyjackThis!

Discussion in 'Malware Help (A Specialist Will Reply)' started by SparkyintheSnow, Nov 24, 2005.

  1. SparkyintheSnow

    SparkyintheSnow Private E-2

    Hi All... I'm new here, so please be gental! ;)

    Ok, so I've been having problems with my computer. A virus has obviously gotten in. It destroyed my AVG, and now I can't download a new copy. It also killed my Microsoft Anti-Spyware; it's still on my desk top, but will not open.

    I posted my issues on XForums, and some members directed me here. I tried all of the info from the "Read this first" Thread, but my computer won't let me open Hyjack This... It's downloaded, and I unzipped it, but when I try to open it, the window automatically closes before the program gets the chance to start up.

    I've recently switched to FireFox, I'm running on Windows XP Home Edition, Service Pack 2. The info listed when I opened "System Properties" looks like this:

    Toshiba Satelite Intel(R) Celeron(R) CPU 2.80GHz, 2.80GHz, 192 MB of Ram

    I still have use of SpyBot, which I ran, and fixed problems, Ad-Aware, which I ran and removed problems, Trend Micro HouseCall, which detected no viruses, Kapersky and Bit Defender, which gave me this for a result:

    Scan Info

    Scanned Files 283892

    Infected Files 1

    Virus Detected Trojan.Purityad.BK

    I don't know what to do now. If anyone can help, it would be greatly appreciated!

    -SparkyintheSnow
     
  2. SparkyintheSnow

    SparkyintheSnow Private E-2

    Update:

    I tried to download Spy Sweeper, as that seems to be what is recommended, and when I got to the point where FireFoz asked me what to do with the file (it will only let me save it to a disk for some reason), the entire browser shut down! If that isn't frustrating, I don't know what is!

    So... What now?
     
  3. SparkyintheSnow

    SparkyintheSnow Private E-2

    Update 2: Ok, so now it let me install Spy Sweeper. I am running it now. Once it is done, I will post the .txt file, as per the instructions in another thread... Hopefully I will also be able to run Hijack this soon!
     
  4. SparkyintheSnow

    SparkyintheSnow Private E-2

    Update 3: This is the .txt file I saved from spysweeper. I will try and get Hyjack to run now.

    Update 4: The program still shuts down as soon as I try to open it... Any suggestions? Please? I'm at my wits end!!
     

    Attached Files:

  5. SparkyintheSnow

    SparkyintheSnow Private E-2

    Update 5: I tried to find another site to download Hyjack from, but no matter where, whenever I click on a link, my browser shuts down. This is starting to be a real pain.
     
  6. SparkyintheSnow

    SparkyintheSnow Private E-2

    Update 6: It's been a few hours... I've downloaded AntiVir as an Anti Virus program to replace AVG, but it just told me to run my most up-to-date virus scanner... which I don't have... Blarg!

    I'm prepared to keep bumping this thread until I get an answer! that's how desperate I am! Please, please help?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please realize it is a holiday for most of the people who spend time help in this forum. So we will not be around much. I'm not sure what your problem with HijackThis is. You keep changing what you are saying. First you said you cannot download it. Then you said you have it downloaded and unzipped but cannot run it. Then you said you cannot download it again. So what exactly is the problem?

    Can you download the HijackThis from our link or not?
    Can you unzip into a folder like we request?
    Can you run Hijackthis.exe?

    Please also run this Running HOSTER...

    And if no one is around for awhile you may want to give the following items a run to see what they find:

    Running Ewido Security Suite

    Microworld Antivirus Toolkit Utility 7.4.2

    Post the logs too if you can run these tools. Microworld will not fix anything, but it may help us detect some problems to remove manually.
     
  8. SparkyintheSnow

    SparkyintheSnow Private E-2

    Sorry! I completly forgot that it's the American Thanksgiving! I'm sorry!

    I guess I'm a little confused too... Sometimes I click on the link you provided, and FireFox tells me that the Download is complete, and try to unzip the program, and WinZip shuts down. Other times, I click on the link, and FireFox itself shuts down. This has been happening with other files aswell And now I'm having issues with my cursrumin back...gpj ossi gnv w d.ew i

    In any case, The window does not remain open long enough for me to do more than click on the file, then the window just cses!ol

    I wil trylthe other programs and see what happens yrt lliw
    Sorry again! I'm just really fustrated...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Were are you located if not here in the USA?

    Try downloading hijackthis.exe (not in a ZIP file) directly from here:

    http://216.180.233.162/~merijn/files/HijackThis.exe

    Put it in the proper folder per our instructions in step 7 of the READ ME & also follow those directions on running it. Then attach a log (from normal boot mode) to your next message. I should be popping in again later.
     
  10. SparkyintheSnow

    SparkyintheSnow Private E-2

    Hi Chaslang. I've been out of town and without internet for the past few days... Sorry for the delay on this! I'm in Northern Ontario, so I'm in Canada. I know I should have known that it was a holiday weekend, but I'm without television, so I tend to be out of the loop!

    Ok, so I followed the link you provided, and downloaded the .exe file. A popup comes up from FireFox called Downloads, and my only 2 options are "Open" or "remove"... for some reason it will only download things to the desktop, and I can't figure out how to get it to the HJT file I created, as per the instructions. So, I clicked on it, and tried to run the scan. A box came up, and I chose the first option (scan and create logfile, or sometihng like that). Another box comes up, and it looks like the program scans part way through, and then the box just disapears.

    So, I tried unzipping it again, just for kicks. Once Mozilla tells me that the download is complete, the WinZip opens, and then vanishes before I can click on anything. Though, sometimes it lets me click on extract to, but as soon as I do, the box vanishes again.

    If you like, I can create a list of the programs that are listed under processes when I hit Alt+Ctrl+Del... but other than that, I don't know what to do next.

    Thank you so much for your help!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have actually gotten the HijackThis.exe file downloaded. Just create the c:\Program Files\HJT folder per the instructions in the sticky threads and copy or move hijackthis.exe there. Then continue to run the steps to post the log as an attachment.

    The sticky I'm referring to is: Downloading, Installing, and Running HijackThis

    By the way you can change FireFox's settings to ask where to download to. Also you can change the default folder too. It's under Tools, Options, Downloads.
     
  12. SparkyintheSnow

    SparkyintheSnow Private E-2

    Ok.

    I re-downloaded HijackThis from the .exe file you posted (every time it doesn't work, I delete it and start again incase I'm doing something wrong). I then cut/pasted it into the HJT file I created in the Program Files file. I clicked on it to run the scan, selected the first option, and the screen vanished. Arg! :rolleyes:

    I don't know if it's worth anything to you, but I"m attatching the Processes file I made up... these are all the processes currently running on my computer (I have shut down AntiVir since creating that file, and before re-downloading hijack)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't quite understand what you are saying and doing.

    Did you create the C:\Program Files\HJT folder as specified?
    If yes, just download the file, and save it to this folder.
    At this point you should have hijackthis.exe in the C:\Program Files\HJT folder. The file should be 213 KB in size. Is that what you see?
     
  14. SparkyintheSnow

    SparkyintheSnow Private E-2

    Sorry to keep re-posting, but I don't see an option to edit posts...

    This is a new, and somewhat odd, development: I tried to read someone elses Hijack log file, to see what it looks like. I tried to open it, and it did the same thing as Hijack: The .txt file opened, then immediatly closed! I'm assuming the two are related, I just don't know why it's happening.
     
  15. SparkyintheSnow

    SparkyintheSnow Private E-2

    Yes, that's what I see. Then I double click on it to open it, right?

    [ETA (and yes, the edit button came up this time... I guess it just doens't load sometimes...): I'm really sorry that I'm not being clear... I'm not exactly computer-intelligent! I'm used to having someone looking over my shoulder as I do anything more than run virus scans and word process.]
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the terminology is that you double click on it to run it! It should open up a window where you can select options. You want to select the one that says Do a system scan and save a log

    Do you get this far?
     
  17. SparkyintheSnow

    SparkyintheSnow Private E-2

    I double click on it, then the window comes up, but it almost instantly closes again, before I can even move my mouse! Am I doing something wrong?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maybe not! It could be malware! Try this. Rename (right click on the file and select Rename) hijackthis.exe to myhjt.com

    Then try double click on the new file name to run it. Does this stay running?
     
  19. SparkyintheSnow

    SparkyintheSnow Private E-2

    It did, long enough for me to click on "do a system scan and save log file", then it opens another window, starts to scan, then vanishes.

    I tried a second time, and I didn't even get chance to click on that button before the window closed.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download GetRunKeys.Zip to your PC someplace you can locate it. Then extract the getrunkeys.bat file from the ZIP. Locate the getrunkeys.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . Unload that file here are an attachment.

    By the way, look in the folder you have hijackthis.exe running from. Do you see a filenamed hijackthis.log?
     
  21. SparkyintheSnow

    SparkyintheSnow Private E-2

    It worked! *big grin!*

    Oh, and no, I don't see anything other than the Hijack file, which you told me to re-name myhjt.com. That is the ONLY thing in that file.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also do the following:

    Download Process Explorer

    Unzip it and now run ProcessExplorer and lets configure some options first:

    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".

    Now click on File and then Save As. And save the process list. Save it to a filename like prlist.txt

    Post it back here as an attachment.
     
  23. SparkyintheSnow

    SparkyintheSnow Private E-2

    Ok... I clicked on the link above, and then on "Download from Author's site". it then went to the download page... And then I got an "Alert" which read as the following:

    "The connection was refused when attempting to contact www.sysinternals.com"

    I've seen similar messages before, when attempting to download other things from this site.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After posting the prolist.txt file. Run Process Explorer again and see if you can locate a process named XNUR.EXE The Image path column should say: c:\program files\XNUR\XNUR.exe

    Right click on it and select Kill Process Tree
    Watch the processes for a minute and make sure it does not restart.
    If it does not restart, try runing HijackThis now and see if you can save a log.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have no problem with it. So try it again! If it does not work, the problem is on your end. Let me know.
     
  26. SparkyintheSnow

    SparkyintheSnow Private E-2

    Sorry... I guess I wasn't clear again. I can't download Process Explorer. once that Alert comes up, and I click "OK", nothing else happens.

    I will do a quick search for that file, though, and see what comes up.
     
  27. SparkyintheSnow

    SparkyintheSnow Private E-2

    The problem is definatly on my end... I tried the link again, and got the same message!

    BUT: I used the "Search" tool, and found that XNUR file you mentioned... Should I delete it?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot delete it while the process is running. That was why I was trying to kill the process. Let's try this:

    Press CTRL-SHIFT-ESC at the same time to bring up Task Manager. Click the Image Name column heading to sort by name. Look for XNUR and right click it and select End Process Tree. If that works, see if you can delete the whole folder named c:\program files\XNUR
     
  29. SparkyintheSnow

    SparkyintheSnow Private E-2

    XNUR is not listed in the Processes window.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's typcial of Task Manager. It is also why we use programs like Process Explorer and HijackThis. Because they show all things that are running unlike Microsoft's stupid Task Manager.

    Let's try a different approach.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixbad.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixbad.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Then immediately reboot your PC into safe mode and use Windows Explorer to locate the below folder and delete the whole folder:
    c:\program files\XNUR

    Then run CCleaner and also goto the c:\windows\Prefetch folder and delete all files in this folder.

    Then reboot your system in normal mode and see if you can run HijackThis now.
     
  31. SparkyintheSnow

    SparkyintheSnow Private E-2

    Ok, I double-clicked on the fixbad.reg file, created using the instructions above, and I got the following message:

    "C:\Documents and Settings\Lacey B. Richmond\Desktop\fixbad.reg is not a vaild Win32 application"

    What does that mean?

    Oh, and I did see csrss on on the Task Manager, if that helps at all.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It sounds like two things.
    1) did you enable viewing of hidden and system files and also did you uncheck the option to hide extensions for know file types per the READ & RUN ME.

    2) did you save the file using Save As and did you change the Save as Type to All Files?
     
  33. SparkyintheSnow

    SparkyintheSnow Private E-2

    1) Ah. I did that the last time I was here, and my computer has been shut down since then. It must have re-set to defaults. Fixed that.

    2) Yes, I did.

    So, having fixed my mistake, I clicked on the file again, and got the same error message.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not reset to defaults by itself. They must be changed manually.

    Something must be wrong with how you are saving the file. Just to double check that I did not make a mistake in what I put in there, I followed my instructions just now with the registry patch and it added it into the registry without a problem.

    Are you using notepad?
    Is the error message still exactly the same?
     
  35. SparkyintheSnow

    SparkyintheSnow Private E-2

    I am using Notepad, I even double checked in the "Help" menu.

    The error message is exactly the same.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached ZIP file and save it to the root folder of drive C
    Then extract the fixbad.reg file from the ZIP also into the root folder of drive C.
    When finish Windows Explorer should show a c:\fixbad.reg file

    If you see this file, then click Start, Run, and enter regedit c:\fixbad.reg then click OK!
     

    Attached Files:

  37. SparkyintheSnow

    SparkyintheSnow Private E-2

    Ok, I'm back.

    I got rid of the XNUR, and cleared the Prefetch folder, and ran CCleaner, all while in safe mode.

    I double clicked on the myhjt.com file we created, and the same thing happened: the window came up, then immediatly closed again.

    Could it be something else? Should I try downloading Hijack over again?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could try that but I don't think that is the problem. But you even had problems with the ZIPPED version originally.

    Run getrunkeys.bat again and get me an new runkeys.txt log. You may need to change the name to runkeys2.txt in order to attach it.
     
  39. SparkyintheSnow

    SparkyintheSnow Private E-2

    Here is the new file.
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well one item is gone (XNUR) but the other items with "csrss"=- still remain. csrss.exe running from c:\windows\system32 is okay. But these lines in the registry are not okay and it make me wonder what is hiding in the background and bring these back.

    Do you still have SpySweeper installed? If so I want you to do the following,
    - boot into safe mode and run SpySweeper and save the log. Post here later
    - try to run myhjt.com
    - try to run some of the other scans that you may have been able to download and install
    - try running Process Explorer in safe mode and save that log I requested and post it here

    Reboot in normal mode and tell me the results. Gotta run now. I have an early day tomorrow and need! I'll check in during the day if I get time.

    You have a real nasty hiding in here and it is difficult not being able to run any tools. Try downloading some of the below. Just download them to a Downloads folder. I want to at least see if you can download them. If so, we may be able to get some to run some how.

    avast! Virus Cleaner Tool No installation required! Ready to run as is
    McAfee AVERT Stinger..... No installation required! Ready to run as is.
    Microsoft Malicious Software Removal Tool
     
  41. SparkyintheSnow

    SparkyintheSnow Private E-2

    Hi! Back again!

    I couldn't run Process Explorer because I booted in Safe mode without a network connection... But, I got HJT to run!

    These are ALL of the reports from all of the scans I ran, including HJT. I hope I got it right...
     

    Attached Files:

  42. SparkyintheSnow

    SparkyintheSnow Private E-2

    More reports...
     

    Attached Files:

  43. SparkyintheSnow

    SparkyintheSnow Private E-2

    And more reports...
     

    Attached Files:

  44. SparkyintheSnow

    SparkyintheSnow Private E-2

    And lastly the HJT report.

    Again, I didn't have an internet connection at the time, so I hope I did everything right.

    Hopefully all of this will shed some light on whatever's mangling my computer.

    Also, I ran the Ewido Security program, but I wasn't able to save a log file... I couldn't bring the window up high enough to hit the save button! But, It got rid of about 8 infected files.
     

    Attached Files:

  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Process Explorer does not need a network conection to run in either safe mode or normal mode. It is a process explorer not a network explorer.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot back into safe mode. And run open Windows Explorer. Locate the below file:

    C:\WINDOWS\system32\ukpgqqzlo\csrss.exe

    Right click on it and select rename and change the csrss.exe file to csrss.xxx
    If you cannot rename it, try right clicking on it and dragging it to the Desktop and when you let go of the mouse button on the Desktop select Move here.
    Now see if you can rename it.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions (if any are open):
    F3 - REG:win.ini: load=C:\WINDOWS\system32\ukpgqqzlo\csrss.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\ukpgqqzlo\csrss.exe
    O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    After clicking Fix, exit HJT.

    Now reboot in normal mode and tell me where things stand. If you can run HJT now, post a new log. Also start running all the steps in the READ & RUN ME.
     
  47. SparkyintheSnow

    SparkyintheSnow Private E-2

    Done.

    Here is the New HJT log.

    I am still unable to download process explorer... I click on the link, then on download from author's site, but I get an alert message saying that "The Connection was refused when attempting to contact www.sysinternals.com".

    I will start going through the Read Me First file, and see what that turns up.
     

    Attached Files:

  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should now rename myhjt.com back to hijackthis.exe

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions (if any are open):

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
    O4 - Startup: csrss.lnk = ?

    After clicking Fix, exit HJT.

    Now after another reboot into normal mode, post a new log HJT log!

    How is everything working now?
     
  49. SparkyintheSnow

    SparkyintheSnow Private E-2

    OK... I followed your instructions, and everything went swimmingly until I hit Fix Checked in Hijack this... The R1 file was deleted, but the 04 - Startup: csrss.lnk = ? caused problems.

    These are the error messages I recieved, in order of apperance:

    "Unexpected error occurred!
    Error #52 (Bad file name or number) in Sub GetLongPath(?.exe).

    Please send a report to merijn@spywareinfo.com, mentioning what you were doing, and what version of Windows you have.

    This message has been copied to your clipboard."

    "Unable to delete file 04 - Startup: csrss.lnk = ? File may be in use."

    [Edited to add hjt file...]

    I'm attatching the hijack log. Other than that, things are running better, except that my homepage keeps changing to http://www.messengersite.net/forum/portal.htm
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must remember to post HJT logs from normal boot mode. Do not post a new one yet.

    You more than likely have a csrss.lnk file in your Startup folder we need to find and delete.
    C:\Documents and Settings\username\Start Menu\Programs\Startup\csrss.lnk

    where username is the name of the user. Let's run the below to help us dig further.

    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside c:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds