re: hijack this

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by alecat, Nov 1, 2004.

  1. alecat

    alecat Private E-2

    Hi: I have spent most of the afternoon trying to clean up this computer. :eek: Please note I have gone thru all the steps in "Read Me First Before Asking for Support". I have now resorted to Hijack this. I have copy of log available on request. I am trying to get rid of Win32 Kernel core component (tries to connect to internet thru firewall) and windllsys32. I don't know what matcli is or motive directory. These all come up even after using the various spybots etc. Can you provide me with any further steps I can take? also i was a recent victim of an about:blank hijack... I fixed that by accident. I deleted a file and then i could access internet and my security worked again. It is provided by my internet provider and it is called zero knowledge or freedom

    Thank you
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have seen this zero knowledge crap before and their name summarizes what they know!

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT Version 1.98.2 and follow the guideline on where to install it and how to post a log as an attachment.
     
  3. alecat

    alecat Private E-2

    As requested here is a copy of my log file. since i am a newbie i have no idea what these mean. Can you tell me which ones i have to delete? please note previous owner changed some file names to read windoze instead of windows. dont ask me why because i don't know. thank you


    Edit by chaslang: Inline log changed to an attachment.
     
    Last edited by a moderator: Nov 1, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read my message again! What you posted is inline text not an attachment. I'll fix it in a second and show you what I mean.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    WINDLLSYS32.EXE


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {2ACC2C82-2B42-11D9-85DE-00506B92629B} - C:\WINDOZE\SYSTEM\BDOB.DLL (file missing)
    O4 - HKCU\..\Run: [windllsys32.exe] C:\WINDOZE\SYSTEM\windllsys32.exe


    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOZE\SYSTEM\WINDLLSYS32.EXE


    No reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. alecat

    alecat Private E-2

    sorry for the mistake. I really appreciate all your help. Thank you for taking the time to help a silly newbie :confused:
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem let me know when you complete those steps!
     
  8. alecat

    alecat Private E-2

    OK I hope i post my log right this time. I did steps as instructed. Those 3 things seem to be gone. I still would like to know what matcli is and what is mad? I keep on getting a message that mad has performed an illegal operation and shuts down
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look here for info on matcli.exe: http://www.windowsstartup.com/wso/browse.php?l=19&start=200&end=225

    Does the error message on mad give more info? Like a full path to the file.

    Search your PC for mad?

    It does not look like you fixed the below line with HJT, try again:

    O4 - HKCU\..\Run: [windllsys32.exe] C:\WINDOZE\SYSTEM\windllsys32.exe

    The error message may be related.
     
  10. alecat

    alecat Private E-2

    OK i read over matcli and understand what that is. the illegal operation of MAD has details as follows: MAD caused an exception c0000006H in module HLP.DLL at 0167:2ae7e7b5.
    Registers:
    EAX=ffffffff CS=0167 EIP=2ae7e7b5 EFLGS=00010206
    EBX=5cef8d10 SS=016f ESP=008df7e4 EBP=ffffffff
    ECX=00000002 DS=016f ESI=2ae71004 FS=12f7
    EDX=2ae60fff ES=016f EDI=2ae61000 GS=0000
    Bytes at CS:EIP:
    8a 02 42 88 07 47 49 75 f7 e9 63 ff ff ff 90 8b
    Stack dump:
    2ae61000 00000000 2ae60000 008df9cc 008df808 8197545c c00309cc c15c87c0 2ae7e700 bff7ddd6 2ae60000 00000001 00000000 00000000 2ae60000 8197545c

    and here is my new log:

    Thanks again for all your time and patience
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. alecat

    alecat Private E-2

    ok here is new log and mad thing is connected to telus ecare (part of my isp)


    umm now can't upload log :rolleyes:
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We probably don't need the log as long as those two last lines I gave you are gone.
    The problem you are having is that you need to rename the file each time for upload.
    Like hjt2.txt, hjt2.txt, hjt3.txt etc.


    Sound like you are all fixed up now! You should check this out: How to Protect yourself from malware!
     
  14. alecat

    alecat Private E-2

    I can't thank you enough for all your help. You provide a great service for us barely computer literate people as well as saving us a whole bunch of money. I probably would have resorted to taking my computer in somewhere to have them do exactly what i did this afternoon. A thousand thank yous and a million kudos. :)
     
    Last edited: Nov 1, 2004
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're quite welcome Alecat! Spread the word to your friends!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds