Help With Tr/dropper.msil.hhlju Please

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MartinoL, Dec 8, 2016.

  1. MartinoL

    MartinoL Private E-2

    My Avira scan found this "TR/Dropper.MSIL.hhlju" on my laptop and I can't figure out what it is, or whether I need to remove it and how...

    Please help..? o_O
     
  2. MartinoL

    MartinoL Private E-2

    Can someone help...? Do I need to post again??
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What was the filename and where was it located?

    Turn off System Restore and run a full scan with Avira. Is anything still detected?
    Are you have any noticeable problems?
     
  4. MartinoL

    MartinoL Private E-2

    How do I turn off System Restore?

    So far, I noticed my laptop tends to slow down, at times... for example, I may see the ' thinking circle' when I try to access web pages (not always), or as I am trying to scroll down on those web pages. Last night my laptop crashed. May have nothing to do with this issue??

    I ran Malwarebytes scan on December 7th, with the results below (I will run Avira scan also, if needed... but how do I turn off System Restore?). Malwarebytes found two instances of "PUP.Optional.SysTweak", one in a folder, one in the registry... can we also take care of those 2 please?

    Malwarebytes Anti-Malware (PRO) 1.70.0.1100
    www.malwarebytes.org

    Database version: v2016.12.07.12

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 11.0.9600.18524
    Martino :: PAVILLIONDV7 [administrator]

    Protection: Enabled

    12/7/2016 11:11:45 PM
    MBAM-log-2016-12-08 (10-56-25).txt

    Scan type: Full scan (C:\|D:\|E:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 618301
    Time elapsed: 2 hour(s), 21 minute(s), 13 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 1
    HKLM\SOFTWARE\Systweak (PUP.Optional.SysTweak) -> No action taken.

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 1
    C:\Users\Martino\AppData\Roaming\Systweak (PUP.Optional.SysTweak) -> No action taken.

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. MartinoL

    MartinoL Private E-2

    In answer to your questions:

    (1) What was the filename and where was it located? "TR/Dropper.MSIL.hhlju". I do not know where it was found/located. I disabled system restore, as you suggested. I then ran both Avira and Malwarebytes scans and it does not look to be detected at this time. Do I enable back system restore now? Should I first reboot the laptop?

    (2) Turn off System Restore and run a full scan with Avira. Is anything still detected? Neither Avira or Malwarebytes scan detects it now.

    (3) Are you have any noticeable problems? I cant' tell right now... But Malwarebytes scan is still showing 2 other items: PUP.Optional.SysTweak, one as Registry Key, the other one in folder C:\Users\my name\AppData\Roaming Systweak. Can you help me remove both? What are these??

    I also asked at the beginning of the thread what "TR/Dropper.MSIL.hhlju" is.... do you know? Also, can I now enable back system restore? Should we first reboot the laptop and clear the PUP suspicious files? Thank you....
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good. Then whatever this unknown miscellaneous issue was it is gone and you don't need to worry about. Names like this are invented by scanning tools and typically they do not mean very much at all. They are just a generic area that they use to classify things into. Many times they are not even problems which is why I asked for the filename and path.

    SysTweak is just from some performance optimizing software that you may have installed. See this>> http://www.systweak.com/advanced-system-optimizer/

    If you did not knowingly install it then just have Malwarebytes remove it. The logs you showed indicate that you took no action.

    Then you can reboot and after reboot, you should enable System Restore.
     
  8. MartinoL

    MartinoL Private E-2

    Thank you for your help! When I enabled System Restore, I selected "Restore settings and previous files", NOT just "Restore previous files". Am I doing this correctly?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. You are not restoring any files. Earlier was just disabled the System Restore/System Protection feature. We are merely re-enabling it now.
     
  10. MartinoL

    MartinoL Private E-2

    Let me clarify... when you sent me the link 'Disable and Enable System Restore', for Window 7 I followed these steps:
    1. Click Start 2. Right click Computer > Properties > Choose Advanced System Settings option in left menu listing. 3. Click System Protection tab 4. Then highlight the drive you wish to turn off System Restore and click Configure (Image 1) 5. Then choose Turn off system protection (Image 2) 6. Click Apply > OK

    Once I rebooted, I went back to the system properties > configure > restore settings > and had to select, for the 'C' drive, one of the following (whichever was selected to turn off system protection): 1. Restore settings and previous files, 2. Restore previous files, or 3. turn off system protection. I can't remember which was was turned off that needs to be selected now.... make sense?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the third option is already saying Turn Off System Protection then it has already been enabled and you do not need to do anything else.
     
  12. MartinoL

    MartinoL Private E-2

    So, I need to select Turn Off System Protection? What does that mean... ? Why keep system protection off? I don't follow....
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were suppose to turn it off previously back when I posted message # 3. And now it is supposed to be turned back on. Since you already have it on ( because the only option you saw was to turn it off it means it is already on ) you don't need to do anything else.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds