Explorer process in backgound & misc' popups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by amq, Jul 8, 2010.

  1. amq

    amq Private E-2

    Hello I have been through the cleaning process and still have something strange going on that hopefully the attached logs may help you to find if you could have a look please.
    I use safari for browsing but there are copies of iexplore.exe processes running that I can see in Task Manager and Process Explorer. I periodically also get explorer windows opening with adverts.
    I'll add the final log in the next post.
    Regards,
    amq
     

    Attached Files:

  2. amq

    amq Private E-2

    Final attachment:
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It appears that you have not turned off your disc emulation software. Please do step 6 of the Read and Run first instructions:
    Now we need to see if you have a corrupt system file:

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  4. amq

    amq Private E-2

    Hi Tim. Thanks for the reply.
    I had run Defogger previously. I have run it again but it didn't inform me this time that it had disabled anything (ie requiring no reboot). I don't mind removing Deamon Tools completely if it helps, it being the CD emulation I have. It's only used occasionally anyway.
    The output from TDSSKiller is attached.
    Regards.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It didnt find anything, so it must have been your disc emulation software that was making it look like you had a MBR infection.

    Tell me what issues you are still having and also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  6. amq

    amq Private E-2

    I problem I have is at least one iexplore process running (sometimes two) - usually under svchost.exe but occasionally elsewhere. See attached jpg.
    Their CPU share fluctuates but can often cause the machine to crawl.
    I'm guessing these are responsible for the popup ads that appear at random when I am web surfing.
    I never use IE for web browsing incidentally only Safari or sometimes Chrome, but the IE windows appear when I seem to be browsing.
    I've attached the logs you asked for.
    Thanks.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to boot to the Recovery Console to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. amq

    amq Private E-2

    Ok will try this. I'm having some trouble getting recovery console to work with a USB keyboard though, so might take a while until i get a ps2 version.
    Can you tell what infection is this?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If goes by numerous names, but lately it is identified as a BLack Web infections that corrupts the MBR.
     
  10. amq

    amq Private E-2

    I've run fixmbr. I now no longer see instances of iexplore.exe running, so this could have cracked it.
    Logs are attached
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Although I see you have disabled your disc emulation software, the infection is still showing in your logs.


    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.
     
  12. amq

    amq Private E-2

    It did this:

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: 6def5ffcbcdbdb4082f1015625e597bd

    Size Device Name MBR Status
    --------------------------------------------
    152 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


    Press any key to quit...
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That eliminates one thing. Now let's check for another.

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  14. amq

    amq Private E-2

    Still not experiencing any problems with my system now. TDSSKiller Logs attached anyway - don't think it found anything though. Could the drive image software have confused things? Can I run Defogger again?
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, it didnt find anything. Are you no longer having malware issues?
     
  16. amq

    amq Private E-2

    Not that I can see. CPU usage is ok. No instances of iexplore.exe running. No IE ad popups.
    I can do the full system clean from scratch and the post results again if you think its worth it.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  18. amq

    amq Private E-2

    Right. I'll get on and do this.
    Thanks for you help. Much appreciated.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds