iexplore.exe persists

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hughlowe, Oct 2, 2007.

  1. hughlowe

    hughlowe Private E-2

    I have some bad bugs that won't go away. One of the bad files is iexplore.exe. If I run Explorer, then try to reboot the computer, it won't let the computer shut down. It keeps saying it's trying to close iexplore.exe, but the program's not responding. I have to unplug the computer. It seems to replicate itself on reboot--when I first thought to look at Task Manager there were two iexplore.exe processes running. After a few reboots it was up to five. I'm now using only Firefox (and no iexplore.exe shows on Task Manager).

    I've done online scans. Kaspersky says I have Win32 not_a_virus, and a Wise virus, but the online version doesn't try to fix it. BitDefender reports a Wise virus, but says it can't fix it. I have logs of the scans, and of HiJackThis run at various times. Other scanners, including Avira and the program I'm now using, NOD32, aren't picking up anything. Spybot keeps finding keyloggers.

    The computer has frozen twice, and I've taken it to two techs, who said they'd cleaned it each time, but I doubt it.

    To top it off, my sound has disappeared. The hardware troubleshooter says no device is present, but I haven't knowingly changed anything. I tried earphones, and no sound there either.

    If somebody will lead me somewhere, I can follow directions slavishly, and my appreciation will be boundless.

    Many thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. hughlowe

    hughlowe Private E-2

    I'm attaching the first three of six files.
     

    Attached Files:

  4. hughlowe

    hughlowe Private E-2

    No log file from Counterspy. There were no detections, so it appears not to have kept a log. I've uploaded the other requested files.

    I followed the directions you gave.

    In general, no problems, other than cookies, were identified by the scans.

    I'm still having trouble with iexplore.exe. I've taken my computer to two techs because of this, and both have pronounced it clean.

    Iexplore.exe would refuse to shut down. I'd get "program not responding." When I clecked on "end now," the box would go away and come right back, but the program would finally end, after I repeated the "end now" routine several times. I ran online scans. Kaspersky said I had a Wise virus and a Win32 not_a_virus virus.

    Finally the computer crashed. I took it to the first tech. After he said it was clean, the very first thing when I booted up was a notice from AV (then my resident antivirus from SBC/Yahoo) that it had detected two tainted files, both iexplore.exe, and had quarantined one and removed the other.

    I again started having the problem with iexplore.exe not wanting to end. Whenever I'd check Task Manager it would show iexplore.exe as a process, taking up memory, but not using any CPU, and not showing as a running application. Kaspersky again said I had the two viruses described above, and BitDefender said I had a Wise virus.

    The problem with iexplore.exe got worse. I took it to the second tech, who said he had it clean. He said he found rootkit infections. Then the iexplore.exe problem resumed. I checked Task Manager sometime in there and saw two iexplore.exe processes. Later, after I had closed Explorer a few times, and had probably rebooted a few times, I saw five iexplore.exe processes. It seemed to replicate itself on reboot.

    I began using Firefox exclusively, and had no problems, and saw no iexplore.exe in Task Manager. Somewhere in the course of trying to track down the problem I lost the sound altogether in my computer. The hardware troubleshooter says no device is installed, but I've made no knowing changes. I tried earphones instead of speakers, but still no sound.

    Then I came to you. During the course of doing all the steps in your instructions I encounterd the iexplore problem again, but the program would end if I kept clicking on the "end program" boxwhen it came up. It took three tries on one occasion--but that's better than when the problem was out of hand, when it wouldn't end no matter how many times I clicked on the box, and when I couldn't shut down the computer even with the reset button. I had to unplug it.

    By the way, you will see that I have too many antivirus and antispy programs running at one time. That's only because in following your instructions I downloaded several programs, and your instructions said to let everything start before I ran HighJack This. I don't customarily run redundant programs, and I'll shut them down after I send this post.

    Thanks, your instructions are remarkably complete for a complex task, especially in anticipating that the user will not be able to do something the way you instruct, and in then giving him an alternative. I appreciate your help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be installing/extracting all of the tools to your Desktop. This cause clutter and can also slow your PC down. It also makes it easier for malware to hide in all the clutter.

    What is the below process?
    "MImpPro"="C:\\PROGRA~1\\TV4STU~1\\MImpPRO\\MIProHst.exe"

    I'm not sure what you are talking about. We specifically requested in step 3 that you uninstall ALL but one antivirus. You have both NOD32 and CA Antivirus (from Yahoo) installed. You must uninstall one of these now. Also you did not rename HijackThis.exe as requested in step 7 of the READ ME. Please rename it now to analyse.exe.

    Did you purchase the below? If not, uninstall them now.
    Uniblue SpyEraser
    Uniblue System Tweaker

    Also since CounterSpy came up clean, uninstall it now since it is only a trial program.

    Also uninstall Java(TM) 6 Update 2 which is the olde version.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach new logs from
    • ShowNew
    • HijackThis - make sure it has been renamed first.
     
  6. hughlowe

    hughlowe Private E-2

    I'm downloading into a download file now, and I'll clean up the desktop.

    You asked what this program is: "MImpPro"="C:\\PROGRA~1\\TV4STU~1\\MImpPRO\\MIProHst.exe". I don't know. When I googled it I found it only in some HijackThis logs in some forums, with no comment.

    I've removed CA Antivirus.

    I've purchased the UniBlue programs, so I didn't uninstall them, but I will if it will help.

    I uninstalled Counterspy and the Java Update 2.

    I disabled Windows Messenger (and thank you for that).

    I saved the REGEDIT 4 file and let it merge with the registry.

    I ran the ATF Cleaner, on Select All.

    I've attached new logs from HijackThis and ShowNew. (I did rename HiJackThis.exe to analyse.exe, but the log is neverthelesss titled hijackthis.log. I had renamed it last time as well, but I renamed it on the desktop download, and I guess it didn't take. I hope it did this time.)

    Thanks again for your help.
     

    Attached Files:

  7. hughlowe

    hughlowe Private E-2

    Re the process "MImpPro"="C:\\PROGRA~1\\TV4STU~1\\MImpPRO\\MIProHst.exe", here's a site that says it's some sort of program to enhance mouse versatility:

    http://www.processlib.net/files/MIProHst.exe.html

    I don't know how it got into the computer.

    hughlowe
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure? It seems to be something called MouseImp PRO host module It's a program for scrolling the contents of any windows with right, left or middle buttons of a mouse. (see: http://www.winsite.com/bin/Info?500000019244 )

    Help with what? I'm not sure at this point what your problems are? We have not seen any malware so perhaps you are in the wrong forum.

    That is what the log is supposed to be named. Change the name of the EXE has nothing to do with the log file name.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see we were posting at the same time. Then just use HijackThis to fix that startup and then delete the C:\Program Files\TV4 STUDIOS (or similar) folder if it exists.
     
  10. hughlowe

    hughlowe Private E-2

    OK.

    I guess the problem got fixed in the process of going through the steps you directed. I've been using Explorer today with no problem.

    I'll try the hardware forum for my sound problem.

    Thanks again for your help.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    2. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds