Internet explorer not working

Discussion in 'Malware Help (A Specialist Will Reply)' started by nicksimec, Jul 28, 2007.

  1. nicksimec

    nicksimec Corporal

    i already saw other threads about this but i am running on vista and a message come up about every 10 seconds and says internet explorer is not working then a new box pops up and says windows explorer is restarting and some windows close and the desktop flashes i think it may be malware should i use the hijack thing HELP?
     
  2. nicksimec

    nicksimec Corporal

    help me i want to have this done within the day
     
  3. nicksimec

    nicksimec Corporal

    i think i know the problen i have something installed on my computer call video AX then something else i cant read it because my start button just dissapered
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I surprised that Vista let you install this. Did you have UAC (User Account Control) disable?

    Try running the below procedure, you may have to select run as Administrator or you may even have to disable UAC to run this. See the below link if you do not know how to work with UAC:

    http://technet2.microsoft.com/WindowsVista/en/library/0d75f774-8514-4c9e-ac08-4c21f5c6c2d91033.mspx?mfr=true


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     
  5. nicksimec

    nicksimec Corporal

    ok so what you want me to do is disable UAC?
     
  6. nicksimec

    nicksimec Corporal

    ok smitfraudfix.cmd is called dumphive and it will not allow me to run this a black box comes up and then disappears also i dont know if UAC is disalbled a box comes up and says window cannot find secpol.msc if that is even right please get back to me ASAP
     
  7. nicksimec

    nicksimec Corporal

    oh yes and i forgot it is really hard to do all of this because folders and start button things such and the start button close about every 7 seconds is there anyway to stop that or will i have to continue what you tell me but pull everything im using to the desktop
     
  8. nicksimec

    nicksimec Corporal

    oh i think i may have found it still in the zipped file it has 2 gears as its icon and is called smitfraudfix and is red and says press any key to continue
     
  9. nicksimec

    nicksimec Corporal

    it is red command thing when you run it
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First answer my question. Did you already have UAC disabled before you became infected? This is about the only way I have seen thus far that you could easily infect Vista. The other way is if you knowlingly override the security blocks put in place and choose to run malware and install it.

    I'm not sure exactly what messages # 8 & 9 are talking about.

    Skip SmitFraudFix and try running this: RogueRemover Free
     
  11. nicksimec

    nicksimec Corporal

    well i do not know how to check if UAC is enabled/disabled and in post 6 i was talking about not smitfraudfix thing being called dumphive and then i found a new one in the unzipped file called smitfraudfix so i pressed it and it was a red command prompt screen and i was just asking was that the right one and also do i send you a log thing first before i delete the rouge software detected on my computer or do i do i delete it and i dont know how to send you a log?
     
  12. nicksimec

    nicksimec Corporal

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I gave you a link in message # 4 that explains this.

    You should have just followed the directions given. You are not supposed to be clicking on dumphive.exe. That is something that the SmiFraudFix program calls on its own. All we aksed you to run was smitfraudfix.cmd And there were two steps to run and each created a log with the same name which is why we say run step 1 and attach the log before continuing. Did the program run properly or not?
     
  14. nicksimec

    nicksimec Corporal

    yes i know i am susposed click on dumphive now did you check my file log is it ok to delete
     
  15. nicksimec

    nicksimec Corporal

    i mean not sussposed to click on dumphive now i found the other one
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! The Video ActiveX stuff is your SmitFraud infection. I'm not exactly sure what the stuff detected as 2-Antispyware is. It may or may not be a valid. Some sites indicate the VoucherReg.dll and VCHreg.dll are okay. Do they sound like they are related to anything you installed.
     
  17. nicksimec

    nicksimec Corporal

    the 2 anti spyware stuff got installed on my computer when i became infected so i assume they are bad if no i can always reinstall them and i dont remember installing VoucherReg.dll and VCHreg.dll but they could have been from various registry cleaner trials i downloaded
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then allow RogueRemover to fix them too. Afterwards make sure that UAC is enabled and let us know how things are working.
     
  19. nicksimec

    nicksimec Corporal

    im still keep getting a message saying window explorer has stopped working windows explorer is restarting
     
  20. nicksimec

    nicksimec Corporal

    should i reboot my computer
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    May or may not be a malware problem. The only way we could determine this now is by having you follow our standard cleaning procedures given below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  22. nicksimec

    nicksimec Corporal

    i found a thimg installed on my computer called IExplorer security plug-in installed on the 28/07/2007 could this be causeing the problem i dont think it is but just curious
     
  23. nicksimec

    nicksimec Corporal

    Do all of these steps work for vista because reading it it only mentions 98 ME 2k 2003 and XP
     
  24. nicksimec

    nicksimec Corporal

    is smit fraud bad?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is one of the many things that could get installed with a SmitFaud infection. Yes SmitFraud is bad.

    There are notes in the READ ME for exceptions with Vista. Everything runs except the two online scanners in step 6A. Also as noted in step 6B, UAC must be disabled so that GetRunKey and ShowNew will run.
     
  26. nicksimec

    nicksimec Corporal

    ok when i tried to delete the internet explorer thing i got a message saying error you already uninstalled this program would you like to remove it from the programs and featres list do i press yes or press no and find out some other way to remove it i also found a program called messenger service is this also bad help
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just say yes!

    I need to see logs to know what you are talking about. Some are good and some are bad.

    I'm not sure you ever answered my question and I need an answer now. Was UAC disabled before you got infected? I have not seen one Vista PC get these infections yet while UAC was enabled.
     
  28. nicksimec

    nicksimec Corporal

    it is not a log it is in unistall a program in the control panel and i dont know how to tell if UAC is disabled
     
  29. nicksimec

    nicksimec Corporal

    i just checked my norton history and it says it has detected trojan.Zlob
     
  30. nicksimec

    nicksimec Corporal

  31. nicksimec

    nicksimec Corporal

    i just did the show hidden files thing but i cant see the files how do i find them
     
  32. nicksimec

    nicksimec Corporal

    i downloaded getrun key and shownew to acer hard drive C:spyware tools and then extracted them to MGtools file in my C: HD
     
    Last edited: Jul 31, 2007
  33. nicksimec

    nicksimec Corporal

    i think i have somthing on my computer called virus protect pro i think it is bad
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you read the link I gave you in message # 4. It is explained in that link.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No we don't ask for these logs because we don't need them. Ccleaner is not a malware scanner. It is just a disk cleaner.

    What are you looking for?


    You need to run them and also the rest of the READ ME and attach the requested logs.

    What detected this?
     
  36. nicksimec

    nicksimec Corporal

    i think the problen is fixed i will continue the steps anyway and a norton message appeared that said norton is blocking virusprotectpro from startup

    do you have vista?
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it keeps blocking this then you still have something trying to load and it sounds like UAC is disabled.

    No I do not have Vista.
     
  38. nicksimec

    nicksimec Corporal

    ok is UAC the thing where evertime you try to download or install a message comes up saying allow i used this befor or cancel if yes then i have it enabled
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  40. nicksimec

    nicksimec Corporal

  41. nicksimec

    nicksimec Corporal

    i tried to run smit fraud fix but when i press it it said unsuported version window xp/2000 requierd
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should complete all the steps in the READ & RUN ME and then post all the logs. The only two logs (out of the 6) that you will not be able to get are the two online scanners (BitDefender and Panda). CounterSpy is only one of the scans required.
     
  43. nicksimec

    nicksimec Corporal

    i accidently deleted RUN how do i get it back
     
  44. nicksimec

    nicksimec Corporal

    and did you want me to send you the spybot search and destroy log beacaose i already scaned and deleted the stuff
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is "RUN"?

    We don't ask for a Spybot log. Only the logs requested in the READ ME and itemized below in message # 21 are requested.
     
  46. nicksimec

    nicksimec Corporal

    run is a program that comes with vista mabye all window OS that is requierd to change UAC and to change the boot mode it tells you to type in MSconfig to change the boot mode i think it is in the read me accualy or something you probly heard of it
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean Run command seen when you click the Start button and when you select Run the Run box opens?
     
  48. nicksimec

    nicksimec Corporal

    yeah thats what it is.........i deleted it
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you delete and how?

    You don't normally delete it. You just set an option to either show it or not show it. Right Click Start and select Properties. Then click Start Menu and click Customize. Then click the Advanced tab. Under Start menu items: put a check in the box for Run command

    The above are directions for older Windows OS's. Hopefully Vista is still basically the same.
     
  50. nicksimec

    nicksimec Corporal

    thank you i got it in the start menu now and i deleted because i draged it out onto the desktop when my computer was messed than i aciddentaly deleted it
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds