Hidden IE windows, Audio Ads, Wave Volume turned Down

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bylebog, Jul 5, 2010.

  1. Bylebog

    Bylebog Private E-2

    Well, I seem to have a not so uncommon issue. And, I'm almost ashamed to be posting here. Any help is appreciated. Glad folks like you seem to enjoy helping those of us that know enough to get ourselves in trouble. I'm another that had this issue creep up after only using Chrome now for a few years.

    I am having iexplore.exe running in the taskmanager multiple times, listed user is SYSTEM. It appeared to be playing just audio adds, but I am now starting to see pop-ups as well. Also, it seems that after it's played a snippet of audio it turns Wave Volume under Volume Control all the way down.

    I have attached my logs. I can't get a RootRepeal log, running that program results in my PC rebooting after it displays "Initializing" for about 15 seconds.

    Thanks again in advance.

    Edited to correct Typos
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware in those logs.

    What happens when you use the browser the issue is occuring in, in safemode with networking?

    Normal.

    Does the same thing happen with both IE and Firefox? Try using this: AdBlocker PLus for Firefox

    Complete a scan with your anti virus and let me know if anything crops up?
     
    Last edited: Jul 5, 2010
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should also do this:

    Please go to Add/Remove programs and uninstall the following software:

    Java(TM) 6 Update 17

    Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6
     
  5. Bylebog

    Bylebog Private E-2

    Done. And the audio ads and hidden/invisible IE windows will happen right after I start the PC. Currently running an scan with Avast. **Scan is showing malware in my System Restore folders, still running, though.**

    Before I made my post here I had tried running BootKitRemover from Post # in this thread http://forums.majorgeeks.com/showthread.php?p=1504066 Attaching the output from that.
     

    Attached Files:

    Last edited: Jul 5, 2010
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So continue on with this part of the fix:

    Thus for example with remover.exe on the Desktop and assuming the physicaldrive0

    ---------------------------------------------------------------------------------------

    • Click Start, Run and copy and paste the below into the Run box and click OK.

    • Now reboot your PC and after reboot continue with the below instructions.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Bylebog

    Bylebog Private E-2

    BootKitRemover seems to hate me.
     
  8. Bylebog

    Bylebog Private E-2

    Rebooted and was greeted by a couple of those "Internet Explorer is not your current default browser" windows.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The is no evidence of that kind of infection on your system. In fact, I am not seeing any malware in your logs. I would suggest that you first try resetting your router to factory setting. If you had it configured for your network, you will have to re-configure it. Tell us if that makes a difference.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. Bylebog

    Bylebog Private E-2

    Honestly telling me that there's no evidence of infection is both good and bad. Good in that it confirms I follow smart computing practices. Bad in that what I had is put together fairly well. Unfortunately, I need the PC with audio working, so I've decided to just blow out the partition and re-install Windows. This time I will remember to Ghost the stupid drive after I have everything set back up again.

    I think part of the issue with not being able to find/fix things is due to the set up I use with multiple drives each split into multiple partitions. I do thank you guys both for your time. I really wish I could have gotten a couple of the tools you folks use to run for me. Problems that don't get "solved" but wiped out tend to be like an itch that doesn't you can't scratch. I will probably keep an eye out for similar issues, in case the family calls me with the same problem.

    Thanks again.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this could potentially present problems. If you have not already reinstalled your system and if you have important data backed up, you could try boot your Windows XP boot CD into the Recovery Console and running fixmbr to repair your Master Boot Record which could be the source of the infection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds