Help PLEASE - Hijack this Results

Discussion in 'Malware Help (A Specialist Will Reply)' started by pocomia, Mar 9, 2006.

  1. pocomia

    pocomia Private E-2

    I have having a right pain in the .... problem ! About one week ago I opened IE and it crashed immediatly, and kept doing so I cannot open it - when i double click it the error comes up the page doesnt even pop up to load or anything. I have it currently blocked for access to the internet through my McAfee firewall this is because it randomly pops up the box saying : IE has encountered an error and must now close etc when i dont click on it.... I dont install much and I have done a full scan with my antivirus, and Adware se, both in normal and safe mode there were a few threats all gone. I run on XP so I get an error if I try to reinstall IE - there is a newer version detected etc .... I followed some directions from microsoft website did some stuff in the registry then reinstalled it, bang still crashing. If I do keep it blocked from accessing the internet and I click on internet explorer to open, it opens (with not being able to display the page) and does not crash. I have spent 3 days reading through ur forums and I did the Hijack this and will post it in an attachment.

    If anyone can please help me this would be greatly appreciated, Im currently using firefox and its a right pain !! Does anyone recommened as well all alternative browser to IE, is netscape any good ?? Thanks
     

    Attached Files:

  2. AbbySue

    AbbySue MajorGeeks Administrator

    Welcome to MajroGeeks!:)

    I see an indication of a SpySherrif hijack in your log so please run through this:

    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal And

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    When you return to make your next post make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    Bitdefender
    Panda Scan
    HijackThis
     
  3. pocomia

    pocomia Private E-2

    Ok I have done everything that was listed through all the links you posted. I cannot attach the Pandascan or Bitdefender because you need to have certain requirements and one of those being using IE internet explorer .... and of course thast crashing like I mentioned in the original post. However when I load it now the window comes up then the error so its delay. Other problems I had were, Microsoft Windows Defender 1051 (Beta 2) this is because i run service pack 1a not 2 (because it screws up my pc making it go all weird etc...). I ran everything as said and on first boot back out of safe mode I got 2 error messages saying the same thing first thing on loading (and my pc is now taking about 3x longer to boot up) ... the error was microsoft has recovered from a serious error..... When i followed all the directions for the hijack this I also found that there as nothing abnormal to fix. I will attach the smitfiles and the hijack this done properly. Thank you. Please let me know if im missing out something Im sure i got it right but I dunno if im being detailed enough, im sorry.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about Spybot? It does not seem to be installed. At least not like requested with the SDhelper function enabled (which is the default). Did you run Spybot?

    Let's get an installed programs list from HijackThis too!

    Run HijackThis, click Open the Misc Tools section
    Click Open Uninstall Manager
    Click Save List (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment too.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\System32\archi.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    c:\secure32.html
    c:\WINDOWS\system32\paytime.exe
    C:\WINDOWS\System32\archi.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. pocomia

    pocomia Private E-2

    Hello yes I did install spybot and ran it exactly as described, I think howvere that the HJT files i included was from before i did everything (oops sorry) this is because it was the one of the first things to do.

    I have included both files you said to include, and my internet explorer is still exactly the same crashing what a pain! :rolleyes:

    Thank you very much for your help my computer seems to be running a bit faster as well !
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is still present. Did you fix it last time:

    F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\System32\archi.exe

    Did you find the C:\WINDOWS\System32\archi.exe file and delete it? Check again. Make sure you have enable viewing of hidden files. Use Windows Explorer (do not use Windows Search).

    You did not Reset Web Settings as requested. Please use www.majorgeeks.com for your home page (at least until we get problems worked out). You page right now shows about:blank.
     
  7. pocomia

    pocomia Private E-2

    Hey there i went through all ur directions and that path u said when i went to windows explorer (no search) there were two files with that name one .dll and one a .pdf both i tried to delete and they said restricted access .... both in safe mode over and over to no avail so i checked and no process was runinnng.

    my homepage is set to www.google.com definatly not blank (it went o uk.msn.com when reset) and I 100% sure reset my web settings. I followed ur directions to a absolute T.

    Oh yes and I run my computer all time to veiw hidden files that has always been there, I checked when it asked me to do it .... so that is defo sorted.
    Thanks once again for your post.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot your system in Safe Mode with Command Prompt

    When it comes up there will be no Desktop (no icons etc). Just a command prompt window. Enter the below commands each followed by the enter key. Keep track of any reply messages you get and tell me later. (Note there are spaces inbetween the "-r", "-h", and "-s" parameters.

    cd c:\windows\system32
    attrib -r -h -s archi.*
    del archi.*

    explorer <--- this will bring back your Desktop.

    Now reboot normally and tell me the results and attach a new HJT log.
     
  9. pocomia

    pocomia Private E-2

    Hello again, I restard safe mode comand prompt ect .... I type all of it correctly and it said can not find file.

    I then reboot etc ... and a message popped up once my computer loaded saying :
    Windows cannot findc:\WINDOWS\system32\archi.exe. Make sure you typed the name correctly ..... ect.

    Thank you again for your time, do you think I should just give up and surrender and just continue with netscape .... forget IE ?? Or is what is causing this to my IE affecting, or can affect anything else on the computer.

    ty very much:)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No we are not giving up yet.

    Run HijackThis and select the below lines
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\System32\archi.exe

    Now make sure you do not click Fix check until ALL browsers have been closed including this one you are reading in. After click Fix check. Get a new HJT log and make sure that F2 line is gone. If it is not gone, shut down all of your McAfee software and try fixing it again.

    Let me know what happens. If it does look like it is gone, reboot and then get a new HJT log and check again to confirm it stays gone. If it is gone, you should not get that error message.
     
  11. pocomia

    pocomia Private E-2

    Thank you so much !! I opened explore tonite and it works fine I have been using it one hour now ( didnt want to post right away and not test first)..... (now the weird part haha) I didnt do anything u said in the last post yet. I will do it tonite to be sure explore still works.

    Thank you very much though for everything you do on this site ! You helped me big time, your all really nice. I learned loads and my comp is now working tip top.

    :) Thanks a million times !:D
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You probably only need to fix the F2 line.

    The previous steps we had done removed the real problem. The line left over in HJT was just causing the error message to be seen since the file no longer exists.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  13. pocomia

    pocomia Private E-2

    Thanks very much for everything it is all sorted and I have done the system restore etc ... and read through now to help prevent malware.

    This site is wonderful, and you helped me immensely I cannot thank you enough.

    :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds