Vista explorer closing down= /

Discussion in 'Malware Help (A Specialist Will Reply)' started by Super Kaioken, Jun 11, 2008.

  1. Super Kaioken

    Super Kaioken Private E-2

    =/ Vista keeps closing the explorer every time I click it, and firefox seems like it's been hijacked :(
     

    Attached Files:

    Last edited by a moderator: Jun 12, 2008
  2. abri

    abri MajorGeek

    Hi Super Kaioken,
    Welcome to Major Geeks!

    With Vista Explorer, I'm understanding Windows Explorer in a Vista Computer. Is this correct? Or do you mean Internet Explorer in a Vista computer?

    Your computer has malware problems. There are two different ways we can try to go forward. You can go to a second computer and download the programs in the READ & RUN ME FIRST and trasnfer to them to the infected computer and run them. That way you won't need a browser.

    Or I can attempt to give you some aid by trying to first remove a bit of the problem, enough that you might be able to use the browsers on the infected computer. I don't make any promises though. But let's try the second way first. Be sure that UAC is turned off and that you reboot after you turn it off.

    However you ran HijackThis the first time, do this again. In the window that opens select "Do a system scan" and put a check in the following boxes. Then click on Fix.

    O2 - BHO: (no name) - {4BE5FF65-BA67-40E7-9F88-2639E9DCBEF5} - C:\Windows\system32\hgGxWoLb.dll
    O2 - BHO: {9e2c1e20-57e4-43ba-3de4-00e7f87307ac} - {ca70378f-7e00-4ed3-ab34-4e7502e1c2e9} - (no file)
    O4 - HKLM\..\Run: [BMe9aa1d1d] Rundll32.exe "C:\Windows\system32\jrtsntvs.dll",s
    O4 - HKLM\..\Run: [ea992e81] rundll32.exe "C:\Windows\system32\dmeuaygc.dll",b
    O4 - HKCU\..\Run: [BMe9aa1d1d] Rundll32.exe "C:\Windows\system32\jrtsntvs.dll",s

    After you click fix, just close hijackthis.


    Download and install Erunt. Use it to create a backup of your registry.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the File Type is set to "all files". Once you have saved it, look for it on your desktop and when you find it, double-click it and allow it to merge with the registry.
    Give the above a go first, and let me know if the registry patch (REGEDIT4) gives you a success message. Can you use either of your browsers? If not, go back to the original plan, which was to download the programs in the READ & RUN ME FIRST on a clean computer onto an external medium like a cd or flashdrive and transfer them to their proper destinations.

    Let me know how this all goes?
    abri
     
  3. Super Kaioken

    Super Kaioken Private E-2

    Sorry for the misunderstanding, it is the windows explorer on a Vista computer

    I am always able to use the browser, but for some reason....whenever I would use any of my bookmarks, sometimes it would close the Windows Explorer and then reopen it. and when I would try the bookmarks again, they work? odd....i keep thinking it's a Vista problem. I just installed 4 gigs of Ram on this and it's been acting funny.

    I used Regedit instead of your patch, and did not find those entries.

    here is the hijack this log:
     

    Attached Files:

    Last edited by a moderator: Jun 12, 2008
  4. abri

    abri MajorGeek

    Hi Super Kaioken,

    I am not quite sure I understand. You have Windows Explorer open and you also have Internet Explorer open. You use the bookmarks (favorites?) in Internet Explorer and this causes Windows Explorer to close but Internet Explorer stays open? (I apologize for Bill Gate's fatal error to give such important programs such similar names)

    Can you run the instructions in the READ & RUN ME FIRST yet? Your computer has a lot of malware on it. Please note, that you need to attach your logs using the Manage Attachments button. We don't use inline logs.

    abri
     
  5. Super Kaioken

    Super Kaioken Private E-2

    What you stated above is true. Does not happen anymore since I have removed the malware. I am having no more problems. :) Thanx everyone

    I used some spyware removal programs to remove the malware. It did not let me update the definitions from my home internet connection for some reason, i think it was redirecting my internet. It took a high speed internet connection to finally update my definitions and remove the malware. :-D
     
  6. abri

    abri MajorGeek

    Hi Super Kaioken,
    I'm glad you got everything resolved.
    Good luck to you.
    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds