Is this a Malware problem?

Discussion in 'Malware Help (A Specialist Will Reply)' started by OD Joe, Jan 20, 2008.

  1. OD Joe

    OD Joe Private E-2

    Noticed some problems recently (last 2 days) with the computer. Trying to open My Computer or in any way browse for files (in notepad, explore from Start Menu right-click, etc.) generates a "Windows explorer has encountered a problem & needs to close" error message. The day before I used Ccleaner on my registry (removed the usual missing file keys, etc. I have been uninstalling a lot recently.) and it also removed three lines I was unsure of but deleted anyway. If my memory serves, they went regsvr32 /u C:\...\???????.dll. These files, which are still in the application data folder, had filenames that seemed to be random strings of letters (Google couldn't find them). So my first question, what happens when you unregister a .dll, and should I have left it alone?
    Since explorer has blown up, I was forced to run MGTools from the start menu by clicking on run and typing C:\MGTools\getlogs.bat. I used DOS edit from the command prompt to check over the logs and see if anything drastic has happened since I did a test run of the programs before using Ccleaner. Aside from my wife installing SweetIM, I don't see any major changes.
    I had installed Kaspersky AV to get a 2nd opinion after Norton found nothing, and have since uninstalled KAV. I ran AVG antispy twice and after clicking apply all actions then reports, it tells me "No reports available". I triple checked the settings and they are exactly as set down in the sticky. AVG, incidentally, found nothing but some tracking cookies. I'm going to close Firefox and rerun AVG to try to get a report, but first I wanted to submit the other two since AVG found nothing anyway. Hopefully the answer is in the logs.
    I have one final question, unrelated to my problem, that I have wanted to ask for a while (it's the reason I joined): How do you get to be a Malware expert? I have learned a ton about computers and malware following a bout with Zlob and a trojan last year, and I would like to learn more, and possibly help out if I can. Before the computer started acting up, I was planning on checking out some of the back logs and solutions that have been posted to get some experience, but now I get to ask for help. Sorry for the long message, but thanks for any help you can give.
    Now to log off, close down and wrestle AVG for that report. Thanks again!
     

    Attached Files:

  2. OD Joe

    OD Joe Private E-2

    Got the AVG report. 4 tracking cookies in all their resplendent glory. Sorry about replying, but the scan takes 40 min, and the edit button didn't stick around that long.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcoem to Major Geeks!

    You should not be playing around in the registry as it can cause your PC to become unusable. Have you tried restoring whatever you removed? CCleaner does offer to make backups. You could also try using System Restore to go back to a point before doing whatever you did.

    You logs show multiple antivirus programs installed!!!! You MUST NEVER INSTALL MORE THAN ONE at any given time. It you wish to use a different program, then you MUST uninstall the first one before installing the second one. Not doing this can cause many problems. In fact right now I would suggest that you uninstall ALL antiivirus programs, and then reboot and make sure ALL traces of them are gone. Norton is notorious for almost never uninstalling properly. This you should also run the below which is also not 100% effective:

    Norton Removal Tool (SymNRT)

    After doing the above, you should reinstall only one antivirus program (preferably not Norton) and then attach new logs and tell us what your current problems are.

    Are the below still on your PC? They were in your ComboFix log:
    2008-01-20 03:41 --------- d-----w C:\Program Files\wwlgqpvw
    2007-12-14 22:13 23,040 ----a-w C:\WINDOWS\system32\smrgdf.ex
    2007-10-17 19:51 126,976 ----a-w C:\Documents and Settings\All Users\Application Data\rmtujuxg.dll
    2007-10-17 19:44 126,976 ----a-w C:\Documents and Settings\All Users\Application Data\hktyvgpo.dll
    2007-10-17 19:43 126,976 ----a-w C:\Documents and Settings\All Users\Application Data\zufstshi.dll


    Becoming a malware fighter is a lot of work and requires a lot of time. If you are already an expert in the Windows OS's (DOS, 9x, ME, 2K, XP, and Vista) it is less work but still requires a significant amout of learning/time.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds