Explorer.exe doesn't run

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bellecat1, Nov 29, 2008.

  1. bellecat1

    bellecat1 Private E-2

    Hi guys,
    Got a problem. Pretty much every time I boot my pc, explorer doesn't run after login. Something adds explorer.exe to:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

    Which basically doesn't allow the process to run. So I have to start task manager, then launch regedit then DELETE explorer.exe from the registry. Then I can start explorer via task manager.

    I've ran spybot, symantec EPP, AVG antispy, counterspy and about 4 or 5 others and they havn't picked up much. I can't see any suspicious processes running or any in the startup.

    Where do we go from here? Anyone ever had this one before?

    Thanks in advance!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. bellecat1

    bellecat1 Private E-2

    Hi,
    After the scans the problem still remains. Attached at the logs from the scans
     

    Attached Files:

  4. bellecat1

    bellecat1 Private E-2

    and more...
     

    Attached Files:

  5. bellecat1

    bellecat1 Private E-2

    Bump...anyone?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Too bad you did not rad the sticky threads like Don't Bump! It Only Hurts You!!! This post cost you more than a day of additional waiting time.

    You did not attach the C:\MGlogs.zip file from running MGtools. Please attach it as requested. We need this to continue.

    Also you did not update Malwarebytes as requested. Please do this now and then run a new scan and attach a new log. Your PC was very badly infected so this is highly recommended to make sure nothing was missed.
     
    Last edited: Dec 7, 2008
  7. bellecat1

    bellecat1 Private E-2

    Hey, sorry abot that bumping...eek!
    Sorry bout attaching the wrong logs as well plus I thought I had updated MBAM. Anyway here goes.
    MBAM found security.hijact which pointed to:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
    I removed the threat but I believe all it did is remove explorer.exe from the registry. Something keeps adding that item.

    Thnanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you using Remote Desktop CopyPaste (the below process)
    C:\WINDOWS\system32\rdpclip.exe

    Are you using Microsoft Scheduling Agent for something?
    O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon

    What is the below script/sreen saver for that I see running?
    C:\WINDOWS\system32\logon.scr
    Put a copy of the above file into a ZIP file and attach it here.

    Are the below valid services that you still software for? Why is it using an executable file in the root folder of the drive? Bad idea!!!!
    O23 - Service: Firebird Guardian Service (InterBaseGuardian) - Unknown owner - C:\Program.exe (file missing)
    O23 - Service: Firebird Server (InterBaseServer) - Unknown owner - C:\Program.exe (file missing)

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player (Remove Only) <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix to remove some malware and some leftovers from CounterSpy.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. bellecat1

    bellecat1 Private E-2

    Hi mate,
    And thanks for all your help. The log produce from combofix was called log.txt not combofix.txt just so you know.

    It's hard to know if it has fixed it yet because it doesn't always happen after every restart. I'll test it out though..

    Thanks again.
     

    Attached Files:

  10. bellecat1

    bellecat1 Private E-2

    sorry for the double post

    Are you using Remote Desktop CopyPaste (the below process)
    C:\WINDOWS\system32\rdpclip.exe
    yes
    Are you using Microsoft Scheduling Agent for something?

    O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon
    As in scheduled tasks? There is only one disabled scheduled task which is for defender scan

    What is the below script/sreen saver for that I see running?
    C:\WINDOWS\system32\logon.scr
    Put a copy of the above file into a ZIP file and attach it here.
    done.

    Are the below valid services that you still software for? Why is it using an executable file in the root folder of the drive? Bad idea!!!!
    O23 - Service: Firebird Guardian Service (InterBaseGuardian) - Unknown owner - C:\Program.exe (file missing)
    O23 - Service: Firebird Server (InterBaseServer) - Unknown owner - C:\Program.exe (file missing)
    As Stated, the files are missing but the application still runs. it is needed.

    Thanks
     

    Attached Files:

  11. bellecat1

    bellecat1 Private E-2

    The dreaded explorer is back....and I don't believe anything has happned since as in no apps being run anything...
    I had the regedit up with no explorer in the list...then refreshed it today and it's back in there...inside that folder is a key:
    Value name:
    Debugger
    Value data:
    C:\Program Files\Microsoft Common\wuauclt.exe


    Hope this may help....
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not. That is an intermediate log. When ComboFix finishes running properly, the log will be C:\combofix.txt
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you mean explorer is back. explorer.exe is your Windows shell and it needs to be running. What are you referring to by it's back?


    What list are you referring to? You should not be using regedit on your own as you can break your PC if you do the wrong thing in the registry.

    What folder?


    Not really since wuauclt.exe is just the program used to perform automatic Windows updates.

    Who made the below folder and what is in it?
    Code:
    "C:\Program Files\Internet Explorer\"
    QUARAN~1      Dec  9 2008              "Quarantine"
    
    The last logs you posted were clean.
     
  14. bellecat1

    bellecat1 Private E-2

    here is the combofix log...sorry for the confusion
     

    Attached Files:

  15. bellecat1

    bellecat1 Private E-2

    When I say it's back, I mean the entry is back in the Image file execution options in the registry.

    In order for explorer to run, explorer.exe needs to be removed from the Image file execution options in the registry. Something keeps adding it back to that registry list which causes it NOT to run.

    The folder I am referring to is the registry (Image file execution options). See pic01.jpg. If explorer.exe is in that list explorer will not load automatically and nor will it run manually from task manager.

    There is nothing in that quarantine folder inside internet explorer. Apparently the folder was created 9-dec-08.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not seeing any signs of this in your logs. If you are fixing it before getting the logs then it would be best if you did not fix so we can see the logs before it is fixed.


    Yes I know what this registry key is. It is displayed in our logs but Explorer.exe is not showing in the list since you are removing it before getting the logs and thus we never see the problem.

    Delete this folder.

    Does the below folder really exist? If so, what is in this folder and what is the date and time stamp on the folder? This is not a normal Microsoft folder.
    C:\Program Files\Microsoft Common

    Also rename the below file. Change it to something like logon.XXX, then reboot your PC and let me know if you still have a problem.
    C:\WINDOWS\system32\logon.scr

    The logon.scr file is a valid Windows file used for having a screen saver during the logon process but it is not a necessary process. I want to check what is calling it and if an error message now occurs. I think the mstinit.exe /firstlogon process I mentioned earlier could be running it but I'm not sure.


    Also make sure that you are not logged into multiple user accounts and then do the below. You first scans looked like you may have been using Switch User. I saw winlogon.exe running at least twice. Reboot your PC and ONLY log into one user account and the continue. Not sure if this is somehow related to rdpclip being used and it causes the second winlogon.exe to appear.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 18, 2008
  17. bellecat1

    bellecat1 Private E-2

    I'm not seeing any signs of this in your logs. If you are fixing it before getting the logs then it would be best if you did not fix so we can see the logs before it is fixed.
    That's because I cannot start explorer without deleting it. Although I am in windows now and can re run any tests you like with as explorer has added it's self again.

    Delete this folder.
    Done

    Does the below folder really exist? If so, what is in this folder and what is the date and time stamp on the folder? This is not a normal Microsoft folder.
    C:\Program Files\Microsoft Common
    No it doesn't.

    Also rename the below file. Change it to something like logon.XXX, then reboot your PC and let me know if you still have a problem.
    C:\WINDOWS\system32\logon.scr
    Done.

    Thanks mate, MGLogs.zip attached. and EXPLORER.EXE IS IN THE LIST ATM,
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I saw this file still showing in your process list. Is the last MGlogs.zip file that you attach from before rebooting after it was renamed? Or had you rebooted after renaming it? If you have rebooted, did you get any error messages about this file being missing? Did the file come back?


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your PC.

    If explorer.exe comes back into the Image File Executions list, please do the below.

    • Click Start, Run, and enter regedit and click OK. This should open the Windows Registry Editor.
    • Navigate to the below registry key and select it.
      • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
    • Then click File, Export and save it to a file named IMEexp.reg somewhere that you can find it. The .reg extension is the default for registry files.
    • Now locate the IMEexp.reg file and right click on it and select rename. Rename it to IMEexp.txt
    • Now attach the IMEexp.txt file to your next message.
    Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
     
  19. bellecat1

    bellecat1 Private E-2

    Ok....so after I ran the registry file (which ran successfully) I removed explorer from the registry and rebooted. I have now logged back in an all looks ok. I'll let you know if the bugger creeps back in.

    btw, logon.scr has come back to system32 and the logon.xxx is still there too, which means it was recreated.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the new MGlogs.zip file anyway and also tell me if things still look okay. If it has come back, make sure you attach the IMEexp.txt file too.
     
  21. bellecat1

    bellecat1 Private E-2

    Hey mate,
    Explorer crept back in to the registry....grrr!
    Here is the new MG logs taken after I just rebooted and obviously removed explorer from the registry.

    Sorry, where do I find this IMEexp.txt
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps it is related to the logon.scr that came back.


    You have to follow my instructions and create it. ;)
     
  23. bellecat1

    bellecat1 Private E-2

    Thanks for all your help!

    Attached is IMEexp.txt

    Hmmm....I don't know what it is....Just to let you know that it's random...not on every startup it happens....it will just pop itself back in the registry mid windows.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now that I have this information I know much much more about what your problem is. Some call it Win32/Auraax.A and others call W32/Autorun.GA. However before we can properly remove this, we need more information. One very important piece of info is do you have any removable type drives like USB drives, flash drives....etc. They all may be infected with the source of this infection and can infect any PC that they are plugged into. If you do have drives like this you need to look on them for a file names autorun.inf and delete it. This file is trying to run an infected program named WUAUCLT.EXE which is the same file name as the Windows Update program but it is not the Windows Update program. Also look for a file named system.exe So delete all three of those files if found on any removable drives. Also look on all hard disk partitions for these and delete them. Just don't delete in C:\WINDOWS\SYSTEM32\wuauclt.exe which is the real Windows Update.

    After doing the above, continue on with the below.



    You are out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    You are also out of date with the definitions for Malwarebytes, run it and update to the current database and run a new scan with it too. Attach the new log.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Administrator\Local Settings\temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.


    Run MGtools.exe then attach the below logs:
    • The new logs from SUPERAntiSpyware & Malwarebytes
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 3, 2009
  25. bellecat1

    bellecat1 Private E-2

    See attached.
    So should I just leave the WUAUCLT.exe in system32, $NtServicePackUninstall$ and system32\DLLCACHE then just delete the rest?

    System.exe wasn't found on the machine.

    Thanks
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything.


    These are all normal. You should not delete anything unless I ask you to. There are many other possible locations where this file could be found and be valid. Other update folders, and i386 folder...etc. Only the one I mentioned in the fix with ComboFix was an issue. However on any other hard disk that is not where you boot Windows from or on any removable device if you find this file, delete it.


    You also need to tell me how things are working after following my instructions.
     
  27. bellecat1

    bellecat1 Private E-2

    Sorry,
    See the attached file. It's the search results. system.exe wasn't found at all. Which of the files in the attachment should I delete (as you requested in a previous post)?

    Thanks
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of them because they are all valid.

    You still did not tell me how things are working.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  29. bellecat1

    bellecat1 Private E-2

    Hey mate,
    The logs are attached. I will Monitorthe machine. By the way, the .reg file did run successuflly.
     

    Attached Files:

  30. bellecat1

    bellecat1 Private E-2

    MG Tools Log.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Make sure you complete my final instructions given in message # 28.
     
  32. bellecat1

    bellecat1 Private E-2

    Oh thank you so much for everything....although I just came back to the machine after a couple of days, rebooted and dum dum DUM! she's back! explorer refusing to load again!

    any ideas?:confused
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the current version of MGtools and attach a new MGlogs.zip file.
     
  34. bellecat1

    bellecat1 Private E-2

    MGLogs attached.
     

    Attached Files:

  35. bellecat1

    bellecat1 Private E-2

    Hey mate,
    Thought you may be interested in this one...
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is very important that in the future you properly download and run Mgtools.exe as instructed. You did not download it, and are simply trying to open and run it directly from your browser as the below shows:

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2H32IR2W\MGtools[1].exe

    Doing this can frequently lead to improper execution.


    I also suggest that you disable whatever you are allowing to do the remote connections. The below are related to your remote connection and perhaps this is somehow related to your issue with explorer as no malware seems to be present.
    At least disable this while you are trying to debug your problem.
     
  37. bellecat1

    bellecat1 Private E-2

    Hey mate,
    Attached are the net MGlogs. I am doing it all via the actual computer now, not RDP.
    Have disabled RDP and remote assistance.

    Thanks
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any problems other than the below:

    C:\Documents and Settings\Administrator\Desktop\MGtools.exe

    As stated in the READ & RUN ME, you need to save MGtools to C:\MGtools.exe

    Even the Image File Execution Options registry key is not showing explorer.exe
     
  39. bellecat1

    bellecat1 Private E-2

    Hey Chas,

    Explorer.exe came back to the registry. It didn't show in the last logs because I had to remove it in order to run MGtools. So Now I'm just monitoring it, waiting for explorer to come back again, then run MGtools again.

    Was the second Winlogon I showed you before due to the rdp session? It's not in the process explorer anymore.

    Will do a bit more reading on this puppy and will no doubt post these logs soon.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.
     
  41. bellecat1

    bellecat1 Private E-2

    Hey Chas,
    new MGlogs when explorer is in registry.
    thanks
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated earlier, this infection is called W32.Auraax. You can read some addition info about it in the below link. While we are seeing some of the info mentioned, we are not seein the C:\Program Files\Microsoft Common\wuauclt.exe file or folder I asked about earlier.

    http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-092409-4704-99&tabid=3

    I think it would be best to take the approach of disabling autoruns since this feature of Windows is now being misused by dozens of infections to keep PCs infected and to reinfect them once they have been cleaned.


    First please disable Windows Defender to make sure it does not get in the way of the below.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now reboot your PC and then look for any of the below files and if found, delete them:
    C:\Program Files\Microsoft Common\wuauclt.exe
    C:\AUTORUN.INF
    C:\system.exe
    C:\windows\Temp\rld*.tmp
    C:\widnows\system32\config\systemprofile\Local Settings\History\desktop.ini
    C:\widnows\system32\config\systemprofile\Cookies\index.dat
    C:\widnows\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini

    Now run Ccleaner!

    Now let me know if the problem has returned.
     
    Last edited: Feb 6, 2009
  43. bellecat1

    bellecat1 Private E-2

    Thanks for all you help Chas. Is there a central spot to disable all *ini files from running?
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You don't want to disable all .ini files from running.

    What you do want to do is look in the ROOT folder drives including every removeable type device you have incluing flash drives, usb cameras with flash cards of any kind.....etc for the below files and delete them if found.

    autorun.inf
    wuauclt.exe
     
  45. bellecat1

    bellecat1 Private E-2

    No good.
    Just came back.

    I removed:
    C:\widnows\system32\config\systemprofile\Local Settings\History\desktop.ini
    C:\widnows\system32\config\systemprofile\Cookies\index.dat
    C:\widnows\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini

    Ran CC and the reg file ran successfully aswell.

    Will do a bit of reading on this puppy.

    Thanks
     
  46. bellecat1

    bellecat1 Private E-2

    I've been through every site on Auraax. I have found a variation picked up by CA where the file LOAD1.exe is used. I've ran a spyware scan using CA and have manualy deleted a couple of the registry entries that it considers spyware (although I don't think they even had any registry files in them).

    The machine has been fine for the last 8 hours (lets cross our fingers)
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you find a load1.exe file anywhere. What registry keys did you delete?

    Hope so. Was the problem only coming back after a reboot or did it ever return without doing a reboot?
     
  48. bellecat1

    bellecat1 Private E-2

    Ok,
    Now it has been fine for almost 24 Hours now with no explorer reappearing (longest time). But I'm not saying it's fixed yet

    There was no load1.exe found. Most of the auraax tech info sites had all of the same info which was not much use. I came accross one...Which I can't seem to find now unfortunately. It asked me to remove a couple of entries where there was a pretty long list of URL folders listed. I had to remove one called either www.kloody.net or www.kood.net, can't quite remember as it was done in the wee hours of last night.

    There was that and I also installed CA antivirus and spyware and removed (what looked to be the remains of either an antispyware app or spyware itself). It was just a couple of folders in the registry called antispyware but I don't recall seeing any entries inside these folders.

    Then I installed Kaspersky - Note - Kaspersky seemed to remove the Symantec EPP and CA Antispyware which I had installed. Kaspersky found a few trojans which were just quarantined files. Other than that - nothing.

    Reason why I installed the two apps was because I knew that Kaspersky and CA were aware of this virus and was hoping it would pick up some remains.

    I think I may have had a variation of the virus as there seems to be a fair few. The virus was only discovered in sept 2008 so it's pretty new.

    As stated it's been almost 24 hrs now and all is looking good. Will let you know how it goes tomorrow! thanks for all your help Chas!

    btw, the reg entry was coming back mid windows whenever it liked. - I got a feeling it was downloading malicious code from a site as this is supposed to be 1 of the characteristics of this virus - plus the computer always had internet access.
     
    Last edited: Feb 9, 2009
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If everything is still good, you should complete my final instructions given back in message # 28.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds