IEXPLORE.EXE wont go away

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by IOStream, Aug 26, 2004.

  1. IOStream

    IOStream Private E-2

    I've noticed for the past few days 2 instances of IEXPLORE.EXE running in task manager constantly. I do not have any Internet Explorer windows open, and when I "end task" they come back right away. occasionally when I'm off line they will pull up my login screen for my dial-up internet. I know it is those processes doing this because when I clicked "end task" that login went away, but again, the process came back almost instantly. I use Mozilla~Firefox 0.9.3 about 95% of the time (Windows updates must be done through IE, and occasional sites give firefox trouble), so I have no idea why Internet Explorer would be acting up.
    My Hijack This log is attached if you want to check.
    Thanks for your time
    IOStream
     

    Attached Files:

  2. Kodo

    Kodo SNATCHSQUATCH

  3. IOStream

    IOStream Private E-2

    I've went to Windows update, gotten all avalible updates. I have scanned this PC with Adaware, and Spybot. I have defragged, disk clean up.. and dont some tidying up myself (removing various programs and such I dont use any longer). If there's something I missed, would you please specify what that is?
     
  4. Kodo

    Kodo SNATCHSQUATCH

    scanned for viruses?
     
  5. IOStream

    IOStream Private E-2

  6. Kodo

    Kodo SNATCHSQUATCH

    were you infected?
     
  7. IOStream

    IOStream Private E-2

    Indeed... however, not sure if this has to do with the explorer thing, but it might. Awaiting completion of second scan, to remove what couldn't be removed the first time. Then I will restart. It appears that I have downloader.lstbar.something or other and a few other peices to it as well, includeing a proxy file, dll file, and a couple others. With what I've found over the internet this type of virus comes in a few shapes and sizes... and names for that matter, ranging from porndialer to autodownloader. My understanding of them is just that they infect computers with dial up modems, and try to dial different things (some international numbers). I assume this is to get your computer to a site that will put more things on your computer, that will put more programs on your computer....... etc. untill you die of starvation, and your computer still infected. Maybe its to run up your phone bill. ..or maybe the number is to a machine that dirrectly connects to your PC, and wreaks havok on your compy. So far I have 6 of the 7 files that had the same suffix. AVG doesn't do anything about the last one, all it says is:
    Files infected: 1
    Files cured by healing: 0
    Files removed: 0
    Files still on hard drive: 1
    (Not sure if those are the exact phrases, but you get the idea)
    I will restart now, and see if that helps anything out.
     
  8. Kodo

    Kodo SNATCHSQUATCH

    I've found that AVG is a good scanner but poor cleaner. I would try Avast Home Edition or NOD32.
     
  9. IOStream

    IOStream Private E-2

    That was not the problem. I have gotten rid of traces of that autodownloader, and IEXPLORE.EXE is still plotting against me. I noticed when I turned on my computer, I had walked away from it, to let it start up, and when I came back, there was about 32 (approximatly) Dial-up windows on my desktop. This number climbing about once every second or so. Again ending task on task manager solves this quickly (or right click > Close group). I have also searched my computer for IEXPLORE.EXE and found only net explorer in its respectable place in the Programs folder.
     
  10. Kodo

    Kodo SNATCHSQUATCH

    you definately have a dialer on your machine.
    Reboot to safe mode and run your scans again.
     
  11. IOStream

    IOStream Private E-2

    Safe mode should be called "Impossible mode" for me. No internet with Safe mode, so no online scans. I have tried starting up AVG, I see the process running, however no window comes up with the options, and no system tray icon either. I have tried starting up a program or two, something small that safe mode can handle, and it seems other programs run fine. I got Norton 2004 Pro for my laptop (used for school) I supposed I could slap it on, and give it a run (never have because I only have one key). Suggestions.....?
     
  12. Kodo

    Kodo SNATCHSQUATCH

    Avast.. that should run in safe mode.
     
  13. IOStream

    IOStream Private E-2

    ..Looking into it now. I will post with results asap.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the TrendMicro and PandaSoftware online scans that were in the first Readme link Kodo gave you? If not, you need to run them.

    From the first HJT log you posted there were a bunch of things wrong. Here are a few that need to be fixed if still there:

    Download LSPFix from here: http://cexx.org/lspfix.htm

    Check "I know what I'm doing" and select xfire_lsp_7626.dll from the left hand side. Click the arrow so it goes over to the right. Click Finish.

    That should fix this line:
    O10 - Broken Internet access because of LSP provider 'xfire_lsp_7626.dll' missing


    Now run HijackThis and check off the below lines and have it fix them:
    O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} (SBITAX7Ctrl Class) - http://www.movie-browser.com/tl7000.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_42.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2346f9fe2fa1da46aa03/netzip/RdxIE601.cab
    O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} - http://install.wildtangent.com/bgn/partners/aolim/install.cab

    After doing all this, I may want to see a new HJT log attachment but please make sure you have done EVERYTHING from that Readme link first (you do not need to run About:Buster or HSremove).
     
  15. IOStream

    IOStream Private E-2

    Ok, here's what I have so far, and what I've done with it.
    ----------------------------
    HJT (should be obvious)
    Ad-Aware (Ran twice before first post)
    S_S&D (also ran twice before first post, and twice durring posting)
    Panda (Ran once durring posting)
    AVG (Have run numerous times, and tried in safe-mode.. didn't work)
    Avast(I have installed, scanning immidiatly after this post)
    TrendMicro (not yet tried)

    Note: I have AVG running now, and I've had black ice firewall for weeks (even before this dialing virus)
     
  16. IOStream

    IOStream Private E-2

    I appologise for the double post.
    I'm going to work, so I will not respond untill late tonight (FYI)
    Avast is currently running.
    I moved IEXPLORE.EXE out of the folder, and then killed those processes, they did not start back up of coarse, and was hoping to see a "IEXPLORE.EXE Cannot be found" type of error. I did not get one. When I went back to the folder, windows courageously put iexplore.exe back in the folder, and I deleted the other executable (I had cut > pasted to desktop). I have been running avast for the past 15-20 minutes, and havn't noticed those two processes start back up. I'm hoping the problem is resolved, I will see after work, and after a restart. Thank you guys for your help. I will continue to look into the suggestions you've sent. Perhaps to prevent things from happening in the future. Again, thank you for your help.
    -IOStream :)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let us know if all problems are resolved.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds