IE problems, HijackThis log not posted as per suggestion

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shimooka, Aug 2, 2004.

  1. shimooka

    shimooka Private E-2

    I was having some IE problems and I tried to fix some stuff myself, but the problems are basically persisting. Here are the symptoms before I tried to fix it:
    1) Whenever I clicked on a link or entered anything into the toolbar, text would appear in the bottom status bar showing that IE was actually sending some request to another website called ad(something). I checked it out and it was for a company called midaddle.
    2) Any form that I submitted (including trying to send email from Yahoo mail) would almost always cause IE to just keep spinning, without giving me a confirmation page. Sometimes I would click on the send button various times, and find out that it had actually sent like 5 emails.
    3) Any link I clicked on that opened a new window would open the new window, but then not find anything and just keep searching forever without giving me any “Page not found” errors.
    4) MSN messenger did not work correctly, was not sending messages/log me off every few seconds.

    Here’s what I did to try and solve the problem:
    1) I ran Spybot Search & Destroy and Ad-Aware.
    2) Ran HijackThis and checked/fixed some lines that corresponded to another forum posting that I found online.

    But the problem still occurs, only now IE doesn’t say that it is sending requests to midaddle. I probably have other things in Hijackthis that I should correct, but like I said, I only used fixed items in someone else’s HijackThis log that corresponded to items in my log. There are probably additional items still there, maybe other problems entirely.

    Help?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please refer to this link: http://forums.majorgeeks.com/showthread.php?t=35407
    And after following along with Getting Prepared Steps 1-5:
    Do steps 1 to 4 from (ignore step 5) Time To Start Scanning And Cleaning Steps 1-5:
    Also ignore

    Please make sure you have the correct versions of all the utilities mentioned. Click the links to see what versions are available and make sure you have the same ones. Also check for updates on Ad-aware and SpyBot. HijackThis just came out with a new version yesterday. Run Ad-aware and SpyBot after booting in safe mode.

    If still having a problems after doing the above, post your HijackThis attachment.
     
  3. shimooka

    shimooka Private E-2

    ok, i followed all instruction in that last link you sent me, and the problems are still there. In fact, one of the problem behaviors is that IE won't let me add an attachment to this posting. When I click the Manage Attachments button below, it opens a new window but nothing ever appears in it. I hit F5 refresh but does not work. So I'm going to have to paste the logfile into this posting, sorry.

    By the way, I also posted my hijack this log on tomcoyote.com forum for help their help person responded, so I'm including his response down at the bottom, just to double check with you guys. thanks for all of your help.

    ================================================

    Edit by chaslang: changed log into an attachment. Please follow instructions properly.
     

    Attached Files:

    • hjt.txt
      File size:
      8.6 KB
      Views:
      3
    Last edited by a moderator: Aug 2, 2004
  4. NeoNemesis

    NeoNemesis Moutharrhea

    post it as an attachment next time. it just makes it a lot easier for search engines and stuff. thanx a ton :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you need to save the HJT log to a .txt file or rename the hijackthis.log to hijackthis.txt. Then you when you click Manage attachments you have to Browse to the place you saved the .txt file, select it, and Upload it.

    Why are you trying to work this problem in two places simultaneously? You have feedback from tomCoyote.com already. I know you said you are double checking but you should first decide where you want to work this issue out in its entirety and stay there until it is fixed. If that fails to work out for you then you should use the option of going someplace else to work the issue. Working from too places at once can serve to confuse the people trying to help you since each does not know what the other is having you do.

    So pick a place tomCoyote.com or majorgeeks.com. It's your choice, just let me know.

    I'll give one heads up. The solution given to you is fine but it left out one item in the list of files to delete in safe mode. You need to find sqlgr.exe. You may have to search for it using advanced search options (since it could be hidden). It could be in any of the following directories:
    c:\windows
    c:\windows\system
    c:\windows\system32
    c:\documents and settings\..... <--- someplace under here in a particular user's directory
     
    Last edited: Aug 2, 2004
  6. shimooka

    shimooka Private E-2

    hi chaslang,

    ok, i understand what you mean about postings on multiple sites. i'll stick with you guys since i've been mostly following along your site's suggestions anyway. by the way, i really appreciate all your help.

    about attaching the HijackThis log, i am unable to do that from this forum, so i'm going to include a link to my website where i'll upload it. the problem is that when I hit the "manage attachments" button, nothing appears inside the subsequent window. the IE frame appears, but nothing else inside, no browse button, no text, nothing. i took a screenshot and uploaded it to my website here to show you what i mean:
    http://www.shimooka.com/screen1.jpg

    this is one of the persistent problems i have with IE. also, when I go to windows update webpage, and begin downloading updates, it gives me the downloading dialog box but never seems to start downloading the updates. the dialog box never shows the download progress bar and never closes on it's own, no matter how many times i click on the "download updates" link. i've had similar problems whenever i've tried to submit forms online, including in yahoo mail. when i hit the send button, IE just spins and never gives me a confirmation screen that my email has been sent, even though in some cases it has been sent.

    finally, on the last item you commented about, the sqlgr.exe, I am running mySQL server on my machine (Apache platform). is there any way that the HijackThis entry relates to a necessary mySQL file (since the file name starts with "sql")? are you sure it is a malware? i would hate to delete it and have to reinstall mySQL server.

    so i followed the instructions and fixed those items that you said to do, except for the sqlgr.exe item, which i'll wait for your confirmation. i then ran Hijackthis again and posted the log here:
    http://www.shimooka.com/hijackthis1.txt

    IE is still behaving strangely although faster in some regards, like clicking on normal links. also MSN messenger is still virtually unusable. help? would it help to try re-installing IE and/or messenger?
     
  7. NeoNemesis

    NeoNemesis Moutharrhea

    Just thought I would add that the links you had posted don't work. It says that the page cannot be found.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really don't think that the sqlgr.exe entry has anything to do with running mySQL server. You should fix it too. There must be another reason why you cannot view the Manage Attachments windows and why you cannot do Windows Updates. Perhaps something is disabled in your Internet Explorer settings that is causing this.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The links work just fine!
     
  10. NeoNemesis

    NeoNemesis Moutharrhea

    Oh yeah now they are. But like 30 minutes ago they weren't.
     
  11. shimooka

    shimooka Private E-2

    So I discovered something in my problem. I think the problem may be internet explorer, i tried using netscape on various sites and it seems to work fine. IE has that weird problem of stalling on some websites (like any of my 3 mail websites) and not being able to open new pop-up windows. does anyone know how to uninstall and reinstall IE? I tried resetting all the web settings in IE using Tools-> Reset Web settings but to no avail.
     
  12. shimooka

    shimooka Private E-2

    So I discovered something in my problem. I think the problem may be internet explorer, i tried using netscape on various sites and it seems to work fine. IE has that weird problem of stalling on some websites (like any of my 3 mail websites) and not being able to open new pop-up windows. Do you think that re-installing IE would help? I tried resetting all the web settings in IE using Tools-> Reset Web settings but to no avail.

    charles

    ps- anyone know how to do this with Win XP?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Of course there was a problems with Internet Explorer. That's what all the malware stuff out there does. They attach IE. But you still need to make sure your Security, Privacy, and Advanced settings in IE. You may have something set incorrectly. Look at the Browsing settings under the Advanced tab also look to see that Java (Sun) is enabled.

    Did you ever finish fixing all the items from your HijackThis log yet?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds