Weird Instance of IETray Can't Remove

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by matrixtna, Jan 24, 2005.

  1. matrixtna

    matrixtna Private E-2

    Hi, i recently downloaded Microsoft AntiSpyware, In addition to Spyware Search and Destroy

    When i Scan my PC it picks up only one thing, IETray. As far as i can tell IE has not been hijacked. I use Firefox so i dont really mind but the thought of spyware on my perfect machine is a pain in my side.

    Whenever i remove it it regenerates when i boot up again.
    The weirdest thing is that i have researched specific removal instructions, and all of the signs of having this browser hijacker (registry entries, .exe file, etc) are not on my machine at all.
    The Spyware is located in the following Registry Location:

    HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\&define

    Removal Instructions that i have viewed do not say anything about this registry entry being part of the IETray Browser Hijacker.
    Any Help is appreciated
     
  2. TheOldThug

    TheOldThug First Sergeant

    Hi

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure one of the PROS can help you. These guys are quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)

    TheOldThug
     
  3. matrixtna

    matrixtna Private E-2

    Thanks for the suggestion Old Thug,

    Although it renders useless,
    i tryed what was listed in that guide, but this weird instance of IE Tray doesnt seem to go away, what would be the next thing to try,

    HJT Log matbe???

    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. matrixtna

    matrixtna Private E-2

    Thanks for the site Chaslang, but as i said before, in removal instructions, i have none none of the signs of havingthis spyware (except for the HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt "&define" entry)

    what should my next step be, should I post an HJT log (i really want to do this because my computer has been REALLY sluggish and i have no clue why)

    Or what?????

    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have more problems than just that registry entry. So do the below.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  7. matrixtna

    matrixtna Private E-2

    OKay, i ran Hijack This as stated in the directions, and i have attached my log

    ;) enjoy ;)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log is clean!

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixit.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)
    Now boot in safe mode and do the following:
    Double-click on the fixit.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    No reboot in normal mode. Let me know if that finishes it off or not.
     
  9. matrixtna

    matrixtna Private E-2

    Thanks a bunch Chaslang, I am 99Percent sure that you took care of this problem with your registry modifying entry 1 question though what exactly did that do to fix the problem


    Thanks again

    PS: if you know anything about installing Norton Internet Security 2005 i have a thread in the Software Section that needs attenion

    ;)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    We simply deleted the registry key that was being detected as part of IE Tray.

    It was mentioned in the link I previously gave you to look at:
    http://www.doxdesk.com/parasite/IETray.html

    You said you did not have any of those signs. Read the link again! You obviously did.

    I have never touch Norton's stuff.
     
  11. matrixtna

    matrixtna Private E-2

    hmmm, well i have been deleting that registry entry for a while now and every time i reboot that entry is recreated, we will have to see if you fix really worked if all it did was delete the entry

    As i said before the only sign I had was that &define entry, and i do not have any of the other signs of having this Spyware maybe you misunderstood or I didnt explain it well enough,

    Well in a few minutes I make a post to tell you if I still Have the problem or not.
     
  12. matrixtna

    matrixtna Private E-2

    Well THANKYOU VERY MUCH Chaslang

    you succesfully removed my IETray Spyware
    I guess my spyware removers got rid of the other components except for this one
    Thanks again for all your help

    Matrixtna
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy to help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds