problem with Internet Explorer

Discussion in 'Malware Help (A Specialist Will Reply)' started by srmjdm, Jan 10, 2008.

  1. srmjdm

    srmjdm Private E-2

    Hubby has been having a problem with his computer.. whenever he opens Internet Explorer it tries to load but then comes up with an error that says:

    Internet Explorer has encountered a problem and needs to close...then we clikck on dont send and it comes up with another box that says:
    iexplore.exe - Application Error The instruction at "0x00e638ae" referenced memory at "0x00f79e0". The memory could not be "read".
    Click ok to terminate
    Click cancel to debug

    But if he opens IE and immediately clicks the page while its loading it will come up fine.

    He said he has been having this problem for about 2 weeks now.

    We thought it might be some kinda virus or something so we did the REad and Run Me First stuff. I have attached the logs.. could not get the newest spybot to run so used version 1.4.. also when running the avg spyware steps.. i changed the report setting to make a report always.. but there are no reports showing up on the report page.

    Thanks in advance for the help!
     

    Attached Files:

    Last edited: Jan 10, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like you had McAfee at one time, is this true? Did you uninstall it completely?

    Let's try to figure out what is going on:

    Please delete this folder:
    C:\Documents and Settings\S Mosley\Application Data\Viewpoint

    And tell me what these two are (if you don't know - remove them):
    C:\Documents and Settings\All Users\Desktop\2736331.lnk
    C:\Documents and Settings\All Users\Desktop\8739600.lnk

    And unninstall:
    Java 2 Runtime Environment, SE v1.4.2

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Use windows explorer to find and delete:
    C:\WINDOWS\addins\kbwms.dll

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  3. srmjdm

    srmjdm Private E-2

    It looks like you had McAfee at one time, is this true? Did you uninstall it completely?
    McAfee came preinstalled on the computer, never used it.. have always used avg. I did run the McAfee removal tool I found somewhere on majorgeeks.

    Deleted the Viewpoint folder. Can you tell me what it was?


    And tell me what these two are (if you don't know - remove them):
    C:\Documents and Settings\All Users\Desktop\2736331.lnk
    C:\Documents and Settings\All Users\Desktop\8739600.lnk
    These are dial up connection shortcuts. Have had them since before I got dsl.. should be totally safe.

    Uninstalled Java 2 Runtime Environment, SE v1.4.2


    Starting the MGTools steps now...
     
  4. srmjdm

    srmjdm Private E-2

    Use windows explorer to find and delete:
    C:\WINDOWS\addins\kbwms.dll

    Could not find this to delete it.. have attached a screenshot of my addins folder.. if you notice the file names are backwards smwbk instead of kbwms... are these ok?

    attached is the new logs and the screenshot

    Thanks so much for your help Tim

    no screenshot .. upload says its too big and i dont know how to make it smaller
     

    Attached Files:

    Last edited: Jan 11, 2008
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly I would delete the whole contents of the addins folder ...however, can you copy and paste to notepad and then either attach or zip it and attach so I can see what you are talking about?

    Find and delete:
    c:\PROGRA~1\mcafee.com

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  6. srmjdm

    srmjdm Private E-2

    ok.. took another screenshot saved it as a jpeg.. hope this one works

    Could not find this, I looked for it in exporer and also did a search for it neither way could i find it.
    c:\PROGRA~1\mcafee.com

    ran the fixme.reg
     

    Attached Files:

  7. abri

    abri MajorGeek

    srmjdm!
    It's not uncommon for malware to do that - use file names backwards and forwards.
    The backwards ones are certainly related to the forwards ones.
    abri
     
  8. srmjdm

    srmjdm Private E-2

    So should I delete those files in the addins folder? What exactly is that folder anyways?

    Thanks
     
  9. abri

    abri MajorGeek

    Hi srmjdm!

    Delete the following out of the addins folder. Leave any others.
    smwbk.bak1
    smwbk.bak2
    smwbk.ini
    smwbk.ini2
    smwbk.tmp

    The addins folder is a normal windows folder. (weak answer, I know, but all I have time for at the moment)

    abri
     
  10. srmjdm

    srmjdm Private E-2

    i started to delete these but it told me they were system files .. and if i remove them my computer or programs may no longer work correctly.

    Should I go ahead and delete them?

    and if yes I should delete them.. whats my next steps?
     
  11. abri

    abri MajorGeek

    Hi srmjdm!
    I'm quite sure they are malware, because there's nothing on them in the internet. However, to be careful, please have any two of them scanned at jotti or VirusTotal and let me know the results.

    After you upload them for the scan, please rename all of them by adding .zzz to the end of each one. So smwbk1.bak will then be smwbk1.bak.zzz and so forth.

    After you get the results back from Jotti / Virus Total and we see if your computer suffers any ill effects by chaning the names, then we will try to delete them again.

    abri
     
  12. srmjdm

    srmjdm Private E-2

    scanned with both sites.. both sites found in the smwbk.bak1 file under bitdefender possible trojan.vundo.dvs

    neither site found anything with the other files


    so what now?
     
  13. abri

    abri MajorGeek

    Hi srmjdem!

    Are you able to delete these files after renaming them? If not, make sure the file names in your Windows Explorer addins folder match those in the box below and then do the following:

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run CCleaner at the default setting with the Windows tab as the top one. After you run CCleaner, please attach the avenger log and let me know how this went.

    abri
     
  14. srmjdm

    srmjdm Private E-2

    abri

    I renamed those files with the .zzz , restarted my computer.. then tried to delete them.. they came up again with the message.. they were system files .. and if i remove them my computer or programs may no longer work correctly.

    so I am gonna go ahead and run the avenger program
    will post logs as soon as it is finished.

    thanks
    renee
     
  15. srmjdm

    srmjdm Private E-2

    ok.. here is the avenger log

    Internet explorer is still having the same problem.

    whats next?

    Thanks again!
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run MGTools.exe and attach the MGLogs.zip.
     
  17. srmjdm

    srmjdm Private E-2

    ok.. here is my new logs

    Let me know what I need to do next.. Thanks!
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is the below file for?
    Code:
    C:\Documents and Settings\All Users\Desktop\"
    2736331.lnk   Oct 22 2003         610  "2736331.lnk"
    8739600.lnk   Jan 11 2004         610  "8739600.lnk
    
    You need to uninstall:
    Ad-Aware SE Personal --- way out of date and no longer supported. It is now Ad-Aware2007.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - http://webiq001.webiqonline.com/WebIQ/bin/WebIQ.cab
    O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://lopes.armstrong.com/ib/databases/actimage40803.cab
    O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigner.hgtv.com/images/app/view22rte.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://livenj02.custhelp.com/7550-b415h/rnl/java/RntX.cab

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  19. srmjdm

    srmjdm Private E-2

    The files below are shortcuts to my dialup internet service provider
    Code:
    C:\Documents and Settings\All Users\Desktop\"
    2736331.lnk Oct 22 2003 610 "2736331.lnk"
    8739600.lnk Jan 11 2004 610 "8739600.lnk

    completed your steps.. logs are attached

    internet explorer is still having the same problem.. it wont open.. comes up with the same message.

    thanks
    Renee
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing any malware ....are you able to use a different browser?

    Are there other issues that are going on with any other programs?
     
  21. srmjdm

    srmjdm Private E-2

    Tim,

    I dont currently have another browser installed.. I guess I could download one and try it out. I know if I click on a link say thru email or on a website... the browser has no problem opening the new page. Could I possible just need to reinstall?? or update?? Internet Explorer?

    No other issues going on other than the computer being slow .. especially at startup.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may wish to use a Startup Manager

    Yes, you could try a different browser and try uninstalling and reinstalling as well as running sfc /scannow .....

    Is your start page supposed to be netscape?
     
  23. srmjdm

    srmjdm Private E-2

    what is sfc/scannow ??

    my start page is msn.com
     
  24. srmjdm

    srmjdm Private E-2

    ok.. i ran the sfc/scannow using my xp service pack 2 cd.. but apparantly it found no errors as it didnt tell me I needed to insert the disk nor did it show any errors during the checking process. I went ahead and upgraded IE to IE 7. Will try it out for a day or so and see if the error stops coming up after the upgrade.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The startup manager is for you to stop the programs that you don't want running at start up (often update managers and other garbage).

    Let's do two things:
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now let's reset your IE defaults:
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me how things are running.
     
  26. srmjdm

    srmjdm Private E-2

    Tim,
    sorry didnt see your post before upgrading Internet Explorer.. am running version 7.0.5730.13 now. Have used it for the past 2 days and the error message has not happened at all since upgrading IE.

    Should I still go ahead and do the above fixes that you listed in your last post?
     
  27. srmjdm

    srmjdm Private E-2

    also.. i ran the start up tool.. how do i find out what these process are and if i can stop them or not??

    thanks
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You shouldn't need to do the fix if you are running without problems.

    Here are three items you can stop from running at startup:
    DellSupport
    WMPNSCFG
    DVDSentry

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  29. srmjdm

    srmjdm Private E-2

    Thank you Tim for all your help!

    Things seem to be running smoothly on this computer now..
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds