Infected computer: can't open applications, internet explorer problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by momoney, Sep 22, 2009.

  1. momoney

    momoney Private E-2

    My computer's been infected with some sort of virus/malware.

    I'm not sure exactly what virus I have now, but I can't open any programs, except for Internet Explorer. If I double-click on Word or Excel, it comes up with a this error: "Application not found". However, I can go into my documents and open up a word or excel file and have the program open up that way. But trying to open it through the start menu or desktop doesn't work.

    I can open and use IE, but when I open IE, it comes up with a message box every time that says "Your last session ended unexpectedly -- Reopen old session or go to homepage?" And that message comes up every time, no matter if it's the first time I'm opening IE or the 10th. If I click go to home page, it brings me to my home page. But, my homepage is Google and anytime I search for something on Google, if I click the link directly, a spam ad-page will open up in a new window. But, if I right-click the link and click "open like in new tab", I can open the link successfully. This happens for all pages, ESPN, CNN, etc. I can access any web site if I click on it from my favorites tab. Those sites open up fine. The only problem occurs when I click a link from google, it re-directs me to another spam page.

    I also can't open the control panel or anything else like that (date/time, calendar, security settings). Every time I try to do that, it says "C:\WINDOWS\system32\rundll32.exe Application not found". I've read things online about the rundll32.exe becoming corrupt from a virus and basically ruining your computer, but I'm not sure exactly what I can do to fix it.

    I've downloaded Malwarebytes and when I tried to run it, the box came up that said "choose the program you want to open this file with." It's the same thing that comes up when I try to open pretty much any kind of application, aside from IE. Any type of application I download, this happens to. I can download and save applications to my desktop or wherever with no problem, but when I try to open them, it says I need to "choose the program you want to open this file with" and it lists IE, itunes, notepad, etc. as the programs I can open the program with. So obviously, there's a problem there too, because I can't even run Malwarebytes or any other malware cleaning program. Something is preventing these applications from running.

    I should also mention that when I go to the Task Manager (ctrl+alt+del), and look at the processes running, there are like 7 or 8 iexplore.exe processes running when I only have 1 IE window open. These extra iexplore.exe's often have memory usages that run very high. It seems as though some IE things are running even though I can't see them and are eating up memory at the same time. Even if I go through and delete all the iexplore.exe processes, they pop back up just as quickly as I delete them, making it basically impossible to get rid of them all.

    I'm stuck because I can't open/run any programs that would seem to help clean up this mess.

    I've gone through the READ AND RUN ME and there are several things I can't do.

    -I removed all the old Java updates and downloaded the newest versioun, but once again, I can't open/run the program.
    -I have some temporary internet files in my recycle bin and it won't let me delete that folder. It says: "Cannot remove folder Dc3: the directory is not empty".
    -I downloaded and saved to my desktop CCleaner, but when I try to run it, it says "choose the program you want to open this file with."
    -I can't open MSconfig. Even if I type it into Start/Run, it comes up with the "choose the program you want to open this file with".

    I've looked through the list of malware you have in the READ AND RUN ME, but none of that shows up in the task manager.

    I hope I've given you a detailed enough description of what my problems are. Hope you can help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Questions:
    1. Did you try running all scans?
    2. Did you try running MGtools?
    3. Did you try scanning in safe boot mode?
    4. Can you boot your PC in safe boot mode with command prompt?
    5. What versions of Windows are you running?
    6. Do you have your Windows boot CD?
    Since you say you can run Internet Explorer, please run the below.

    Please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.


    Also run this and attach the log: Using ESET's Online Scanner
     
  3. momoney

    momoney Private E-2

    I've answered your questions below, with my responses in bold.


    Thanks for getting back to me and I hope this information can help. Please let me know what to try next. Thanks again.
     

    Attached Files:

    • log.txt
      File size:
      922 bytes
      Views:
      7
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When I asked about running all scans, I was referring to our procedures not McAfee which we really could care less about ;) since it is not helpful to our fixing this malware.

    Let's see if we can get some info so that we can determine which system file has been corrupted. That way we can try to replace it.

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools

    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  5. momoney

    momoney Private E-2

    Sorry, for some reason I assumed you were asking if I had run all my virus scans. I did attempt to run all the scans you recommended, but none of them worked.

    I couldn't open/run any of these new recommendations either.

    I downloaded AVPFind.bat to the desktop, but when I double-click it, it comes up with the "Open With" box and says "choose the program you want to use to open this file". It lists IE, iTunes, Word, Excel, etc. as options. Clearly those aren't going to help.

    I also downloaded exeHelper to the desktop and double-clicked it, but I got the same "Open With" box as happened when I tried to open AVPFind.bat. It seems that this box appears whenever I try to run anything I download. It's done it for every program I've downloaded that you (and your site) has recommended. This includes CCleaner, MGTools, etc.

    When I try to run the Super Anti-Spyware Oline Scan, it also comes up with the "Open With" box when I click run.

    I've downloaded MGTools to my C: drive but when I double-click it, it comes up with the "Open With" box.

    Sadly, none of the programs will run, so I don't have any logs to attach. The only thing that has worked so far was ESET's Online Scanner that you recommended earlier and I attached that log in my last post.

    Maybe not being able to run any of these programs will help? I hope.

    Thanks again for you help. Keep it coming please! :)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want to see if you can do the below and also have you check a couple things and also answer a couple questions:

    1. First let's see if Task Manager runs. Press CTRL-SHIFT-ESC. If Task Manager opens, select the Processes tab. Look to see if there is a process named wscript.exe running. Also see if there is a process named autorun.exe. You can click on the column title Image Name to sort and make it easier to find process names. You cna just close Task Manager now. This is an information collection exercise before we can continue
    2. Now click Start, Run, and enter cmd and click OK. Does a command prompt window open up? If yes, enter the below command (there is a space after the dir and after the /ah ) in the window and hit enter, let me know if this finds any files with the autorun name in them
      • dir /ah C:\autorun.*
    3. Also in the command prompt window enter the below command and hit enter. Let me know it the Windows Registry Editor opens up.
      • regedit
    4. How many hard disk drive/partitions do you have?
    5. Do you use USB flash drive/memory sticks? If yes, how many and what drive letter is it?
     
  7. momoney

    momoney Private E-2

    1. Task manager opens no problem, but there isn't wscript.exe or autorun.exe running. There are however, several (3 to 4, sometimes more) iexplore.exe running. Not sure if that helps at all, but it started doing that after I started having all these problems.

    2. When I enter 'cmd' into the Start-->Run, it comes up with the "Open With" box that says "choose the program you want to use to open this file". So I can't do anything with the command prompt.

    3. Command prompt doesn't work.

    4. Not sure exactly what you mean by hard disk drive/partitions, but I'm assuming it to be how many drives I have? If so, I have a C: drive and a DVD-RW Drive, which is a D: drive.

    5. I've used USB flash drives before, but not particulary often. None in several months at least. But I do have some lying around the house, maybe 1 or 2. When I use them, they come up as Removable Disk E: drive.

    Hope that's what you were asking for. If not, let me know.

    Thanks
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of IE are you running and when you say you saw 3 or 4 iexplore.exe process running did you have any browser sessions started at all?


    Boot to Safe Mode with Command Prompt and see if you can run the two below commands.
    • dir /ah C:\autorun.*
    • regedit
    Also while in this boot mode. Enter the below which assumes you have saved MGTools.exe to the C:\ folder as requested and also downloaded and save the Malwarebytes installed to the same C:\ root folder.

    • When the PC boots up, you should eventually get a command prompt Windows to open (assuming everything works OK).
    • In the command prompt window, enter the below commands (the commands are in black bold print. Other text are just comments or explanations).
      • cd C:\
      • mbam-setup.exe
        • this will attempt to install Malwarebytes. At the end of the installation procedure, just uncheck the option to update Malwarebytes but leave the option to Launch the program checked. This should automatically run the program.
        • If it installs and runs, select Perform quickscan
        • when it finishes running, make sure your fix everything it finds and then save a log.
        • Now continue on with the next commands below
    • mgtools.exe
      • again this assumes you have save it into the C:\ folder where the cd C:\ command entered above should change directorires to. Wait for MGtools to finish running. When it finishes, the C:\MGlogs.zip file will exist. Now continue on to the next steps below.
    • Now hit CTRL-ALT-DEL to bring up Task Manager and select the Shutdown tab and then select Restart to restart the PC in normal mode.
    • If Malwarebytes previously ran, try to run another scan now and see what happens. If it runs again, attach both logs when you return.
    • Also if MGTools ran, attach the C:\MGlogs.zip file from it.
     
  9. momoney

    momoney Private E-2

    I'm running Internet Explorer 8, and as I'm typing this there are 5 iexplore.exe's running under the processes tab in the task manager. Before I even opened IE for the first time after starting up the computer, there were already 2 iexplore.exe's running.

    In safe mode with command prompt:

    - Typing dir /ah C:\autorun.* came up with this in the command prompt:
    Volume in drive C has no label
    Volume Serial Number is 10FC-5CE8
    Directory of C:\
    File not found

    - Typing regedit successfully opened up the registry.

    - When I typed mb.exe (I re-named MalwareBytes' mb.exe as you recommended FYI) it came up and tried to install it. All was going well until it came to the 'Finishing installation' part. When it said that, something in it froze. I could still move my mouse but I couldn't click anything. I let it sit for about 5 minutes and nothing happened. I CTRL-Shift-ESC to bring up the task manager and I ended the installation process. I tried to run it again, and this time it froze on the 'Extracting files' part. Neither time did it successfully install or allow me to run anything.

    - When I typed mgtools.exe, it came up with the "Open With" box and said "choose the program you would like to use to open this file". After I closed that window, this error message came up: "Failed to run GetLogs.bat, working dir=\MGtools (check to see if this file is in the EXE)." So that wouldn't run either.

    After I restarted the computer in normal mode, when I logged in, it said that I had a new program installed in the Start Menu, and it was MalwareBytes'. But if I go to click on it to run it, it comes up with the "Open With" box. Also, there are no files or anything saved in the C:\ drive where I told it to save it to during the beginning of the installation.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try one more thing before we have to resort to using the Recovery Console from your boot CD.

    Since you can open a command prompt and a DIR command runs, please enter the below command into a command prompt window. Note that this is a space after the DIR and also before every C:\

    DIR /a/s C:\WINDOWS\scecli.dll C:\WINDOWS\netlogon.dll C:\WINDOWS\eventlog.dll C:\Windows\cngaudit.dll > C:\flist.txt

    If the above runs, a file named C:\flist.txt should be created. Attach this file here or post inline what is in the file (do whatever is easier).
     
  11. momoney

    momoney Private E-2

    Ran what you told me to do in the Command Prompt. The flist.txt is attached.

    Thanks
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. momoney

    momoney Private E-2

    I've read up a bit on the Recovery Console and started going through the directions on the link you gave me.

    I have the Windows XP installation CD and I tried to get Windows XP Recovery Console to show up in the start menu. To do this, I followed the instructions and inserted the XP CD and going to Start-->Run and typing D:\i386\winnt32.exe /cmdcons where D: is my CD-Rom drive. When I do this, it comes up with the famous "Choose the program you want to use to open this file". So, I can't even get Recovery Console installed on my computer.

    If there is an alternate way to install Recovery Console, I'll try that. If there isn't, what are my next options?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't want to install the Recovery Console on your PC, you just need to run it from the CD. See the instructions in the link I gave you.
     
  15. momoney

    momoney Private E-2

    Ok, I don't really have much data on this computer and would be okay with just re-installing Windows XP and starting from scratch.

    Is that a realistic option here? And would that cure what is wrong with my computer? I feel like that would be much easier to do from my situation right now.

    FYI, my computer came with XP pre-installed by the OEM, so do I not have a product key that is needed to successfully re-install XP? I am currently running XP SP 3, but the re-install CD is XP SP 2. I have the CD of disks and drivers too. Also, I have the Dell CFI CD Restore Disk that came with the computer. Not sure if that would be of any help.

    Please let me know which is the best route to take. Like I said, I don't have any problem with re-installing XP and wiping my computer clean to fix this issue. It seems like the easiest route. If doing that will or will not get rid of whatever's infected my computer, please let me know.

    Thanks again for everything.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That decision is yours if you wish to do that.

    Without seeing all the logs that we need, we cannot say for sure what problems you had so we cannot answer this with anything other than maybe or probably.

    Then you will have to reinstall you OEM XP2 version and reinstall SP3 later.

    The best route is whatever you feel comfortable with doing. We cannot guide you on doing reinstalls in this forum as we are too busy doing malware removal. At this point we don't even know for sure if you are having malware problems since we don't have enough info from the minimal logs provided and they show nothing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds