PC Overrun with Problems.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Scathe666, Apr 22, 2008.

  1. Scathe666

    Scathe666 Private E-2

    About a week ago, A windows update failed to complete, however the same night, I was also subject to a pop up window and in my haste accidentally clicked, not sure if the problem arose from the unfinished Windows Update, or the Pop Up.

    My computer has been having major problems ever since specifically Adobe Photoshop CS2 will not start without crashing immediately, anything I install past that date will also error automatically. A lot of programs I have downloaded to try and fix my problem, have not worked, cause they have automatically been corrupted. My internet was not showing .png files for a while, but I fixed that.

    I am not sure what to do, I don't want to format. I really need help, please!

    Here is my Hijackthis log, I know there are quite a few anomalies... I have already run Hijackthis once to try to remove the problems but on restart they always return.
     

    Attached Files:

    Last edited by a moderator: Apr 22, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Scathe666

    Scathe666 Private E-2

    Ok, I did the steps you suggested, It found a lot of stuff that needed cleaning, but my primary problem is not fixed.
    My EXE files continue to screw up, usually giving me the "Had to Shut Down, sorry for the Inconvenience Error" I have also completely uninstalled Photoshop, and Reinstalled, with the same result. Also downloaded a demo of photoshop cs 3, it did the same thing.

    On an attempt to uninstall my Wacom Tablet Driver a Dos Prompt Window popped up saying "Program to big to fit in memory" then flashed off. I have had this before and had to reformat.

    Could be unrelated but my MSN Messenger is also messed up and gives me endless pop ups about Custsat.dll till I have to force close it through, task manager.

    Attached are all my logs, any help would be greatly appreciated.
     

    Attached Files:

  4. Scathe666

    Scathe666 Private E-2

    Just the Mglogs.zip file.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6"
    Java(TM) SE Runtime Environment 6"

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime 6
     
  6. Scathe666

    Scathe666 Private E-2

    I appreciate all the help, sadly the EXE's continue to have problems, on the plus side my pc has become much faster...

    I have also noticed certain programs, such as notepad, do not have the proper Icon beside them. and when I attempt to run the programs with this, they do nothing.

    Once again, I really appreciate the help.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a quick reply ...right click the notepad / properties / find target ...does it open?

    Do that with other exe's .....what do you get?

    I still would like to see a new MGLogs.zip ( run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file) and the avenger log.
     
  8. Scathe666

    Scathe666 Private E-2

    The Notepad had no target, and when I clicked it did nothing at all.

    Some of the others like Photoshop, do have a target.

    I also get this error on occasion while trying to install

    (did it with Overlord and Napster)
    Error Code: -5009 : 0x80040707

    Anyway, here are my log files. I really hope you can help me, and I thank you for the help.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to C:\WIndows\system 32 ...scroll down to notepad.exe and double click it...it should open ..but also tell me if there is another notepad.exe or notpad.exe on your system by doing a search....

    After you open notepad..please stop and delete those services.

    On the .exe files...if you find the target, right click the exe file and send to desktop as a shortcut.
     
  10. Scathe666

    Scathe666 Private E-2

    There was 2 more instances of Notepad.exe, one spelt in all capitals, located in the c:\windows folder. I deleted them all.

    I tried doing the shortcut thing for Photoshop, but it continues to give me the "Illegal Operation" error.

    Any ideas?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member



    Where you able to get notepad to open from the sys32 folder ....and did you do the registry patch?
     
  12. Scathe666

    Scathe666 Private E-2

    I was able to get notepad to open from the system32 folder.

    What is the registry patch?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.
     
  14. Scathe666

    Scathe666 Private E-2

    Ok, I did do that before, but I did it again for good measure...

    problems persist :(
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me exactly what you are experiencing and then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  16. Scathe666

    Scathe666 Private E-2

    Basically what I am experiencing is. If I attempt to start photoshop CS2
    whether it be from the start menu, the desktop, or the actual exe file in the adobe/photoshop folder, it brings up the Photoshop splash screen, hangs for a moment, then gives me the "Illegal Operation" error, if I click on show details it mentions "ModName: Kernel32.dll".

    On every exe that does this... (eg.Registry Booster, Hell Gate London Multiplayer) I check the details, and see the same problem... the "ModName: Kernel32.dll". ANd it automatically shuts me out. Nothing as fixed that, as of yet. I don't know if the EXE files were corrupted, or the Windows Update from 2 weeks ago, that failed to finish" has messed them up.

    I find this odd, because some other files, even ones I installed after the problem do work (eg. Baldurs Gate, or the different files I have downloaded from this site)

    Another problem is when attempting to install Napster or Overlord, I get this error
    Error Code: -5009 : 0x80040707

    Not sure what that is exactly, but I cannot bypass it.

    Anyway that is a rundown of my problems, I thank you for your time, and help.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This could be a result of the broken download ...or something else. But the only thing I see in your logs is:
    C:\WINDOWS\system32\dfhkj.tmp ---which you should find and delete.

    Your other issues would be best addressed in the software section. :(
     
  18. Scathe666

    Scathe666 Private E-2

    Just posting to let you know that everything is working again.

    Someone suggested doing a sfc check, and problem solved.

    Just wanted to let you know, and thank you in helping clear my system of some of the malware that has been infecting it.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds