IE window won't stop opening

Discussion in 'Malware Help (A Specialist Will Reply)' started by darrylqmiller, Jun 28, 2009.

  1. darrylqmiller

    darrylqmiller Private E-2

    I have a laptop that I use for my DJ business. Some how I got infected with something that keeps causing the Windows Internet Explorer window to keep opening. Many times. In fact I have given up trying to type this reply on that computer because the window opens so much it is making it all but impossible to type this. Actually 48 times before I could even get this far on that computer.
    I have run the Read & Run section and will post that when I am done here under the same topic title from that computer.
    Back ground:
    I do not use that computer to access any porn sites, sites such as limewire or any other sites I thought might be of danger or sites I have viewed on my other computers and had no problem with. I only buy my music from Amazon and now even download that onto a flash drive off another computer and onto the DJ computer.
    When it does open it only goes to the MSN home page. It has never gone to any other site or tried to use access any other site. I have a PCM card to connect to my wireless system and when that is not installed it cannot access the internet but will still try. When this happens it simply says Cannot Find Server-Microsoft Internet Explorer.
    In fact, I am now connected to the internet through Firefox on that computer and while I can access the internet fine that way, this darn pop-up window still keeps coming up but now stating Cannot Find Server every since I have run the Read Me and Run Section.
    The only other thing I notice wrong is my screen saver has been removed(downloaded from a haunted house forum not some random site) and my desktop back ground is a standard Microsoft picture, not the one I downloaded from the company that produces my DJ software.
    I also am not sure what log to use from the MGlogs.zip. It seems there are several GetUnkey.txt, runkeys.txt, newfiles.txt, ffdata.txt, winfiles.txt, UserInfo.txt, hijackthis.log and procdll.txt. No of these are from the MGTools folder as stated in the instruction. If I am to paste all of these I just don't know how except individually.
    Nothing came back infected except for one in the Rootrepeal log.
    Thanks in advance, I have at least one gig every weekend in July and need this fixed as it seems to be popping up more and more, making it really hard to DJ!
     
  2. darrylqmiller

    darrylqmiller Private E-2

    Logs from my DJ computer. Please see next post for explanation.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What next post? You did not make one.

    You need to attach the requested log from MGtools before we can continue. Thus far, there are no malware issue showing.
     
  4. darrylqmiller

    darrylqmiller Private E-2

    My next post was my log. I had to type my first post explaining my problems off of my desktop since the window was popping up so fast it was all but impossible for me to do it off of my laptop. My second post was the copy of my logs which I had to do off of my laptop for obvious reasons, I'm assuming one of the mods combined my two posts into one which is why it seems that I only posted once.
    I am not sure how to attach the MGtools log which is why I didn't.
    I just found out late last night that I wasn't going to be home today due to having to spend the night out of town for work but will try to figure out how to attach the MGtools log when I get back home tomorrow. Any tips on how to do this will be much appreciated. This is killing me when trying to DJ and I really don't have the option to recreate all those music files and software from scratch as it literally took months.
    Thanks in advance and sorry for the confusion.
     
  5. darrylqmiller

    darrylqmiller Private E-2

    Just got home. Here it is.
    Thanks again.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it was still two posts. They were just in 2 different threads which they should not have been and that is why they were merged back into one thread.

    Your logs do not show any malware issues. They just show a few programs you have installed out of date like the below
    Java(TM) 6 Update 13
    Spybot - Search & Destroy 1.4
    SpywareBlaster v3.5.1

    You problems are likely due to some program that you are running that is trying to access the internet. For example, perhaps the feedback.exe program that you are running from Outpost. You could try uninstalling Outpost to see if it is the problem. Also you could try running in safe boot mode to see if it still happpens. If it does not happen in safe mode, then something that loads in normal mode but not safe mode is the problem.

    I do suggest that you delete the below folder:
    C:\Documents and Settings\Owner\Local Settings\temp\7zO3.tmp

    Also delete the below file:
    C:\Documents and Settings\Owner\Local Settings\temp\m1pra92i.exe

    Do you know what the below drivers are for?
    R2 MarxDev1;MarxDev1;c:\windows\system32\drivers\MARXDEV1.SYS [2/29/2008 5:54 PM 8864]
    R2 MarxDev2;MarxDev2;c:\windows\system32\drivers\MARXDEV2.SYS [2/29/2008 5:54 PM 8864]
    R2 MarxDev3;MarxDev3;c:\windows\system32\drivers\MARXDEV3.SYS [2/29/2008 5:54 PM 8864]
     
    Last edited: Jul 3, 2009
  7. darrylqmiller

    darrylqmiller Private E-2

    Sorry was out of town for three days again.
    Thes spyware programs came with the computer and I hardly use them but will up date them.
    Deleted both of those files and uninstalled Outpost.exe. It also does it in safe mode.
    I have no ideas what those drivers are for. They don't ring a bell and I don't remember installing them. I did Google them and the only two hits I got were in Spanish and some other language, both at malware sites similar to MajorGeeks. I have a friend who speaks Spanish and I will try to get him to translate for me this weekend when I see him.
    Can I create a restore point, delete these drivers and then if something in my DJ software stops working just go back to that restore point?
    Like you, I also feel that something is trying to access the internet but like I previously stated it just pops open the MSN homepage. Never anything else. I wish it would go to a specific site so I could nail it down.
    I will patiently wait for the reply before I make any moves but as always your help is much appreciated as I have taken this to a computer store before but they couldn't figure it out.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does it do it in safe mode without networking?

    No these may not be save in System Restore. Just try renaming the files. Change the .SYS extension to .BAD and then reboot. See if anything happens. Like any error messages. Also make sure all of your programs work okay.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the new C:\MGlogs.zip file
     
  9. darrylqmiller

    darrylqmiller Private E-2

    Good evening.
    First: I've updated Java. I didn't worry about the Spybot or Spyware blaster as we are not using these.
    Second: Okay, I am not a computer guru so maybe I'm just doing this wrong. I have searched online but can't find an answer to my question.
    To change the .sys I was trying to type c:\system32\drivers\MARXDEV1.SYS using Start>Run and then going to the file and changing it. Every time I tried it told me it needed to find the program that created it. I let it search online and it said it was a system file and would not let me access it. I then used the browse function and used every program listed to try and open it and none would. The notebook option did pop up some crazy writing and some words such as CBN device driver for NT which I looked up online. This led me to MARX Data security which is a company that makes USB dongles for software programs. So I am assuming that these are drivers need to operate the dongle for my DJ software. If you can help me figure out how to change the.SYS to .BAD I'll give it a try but I just spent two hours on Google trying to teach myself how with no success. Sorry, I'm trying.
    Third: I Dj'd a block party for ten hours Saturday and the window only popped up four times which is way better but still obviously something is on the computer. I have been playing music and such to try to get the window to pop up but can't. If it does I will go to safe mode without networking and see if it continues.
    This is the hard part. In the beginning it only did it once in a while and then got to the point where it would pop open up to 56 times during a three hour dance. Now I can't get it to open but that doesn't mean it won't next time or the time after. I'll just keep messing with it at home and if it pops up I'll hop into safe mode no networking and see what that does.
    I'll do MGTools now and post the log.
     
  10. darrylqmiller

    darrylqmiller Private E-2

    Okay, I give up. I can't edit my last post and I can't get the damn zip file to load so I'm going to do each one separate. Sorry but I've been up since 4 AM and the kids keep asking me for stuff every two minutes, my patience is gone and I now need to get up in about six hours to do it all over again.
     

    Attached Files:

  11. darrylqmiller

    darrylqmiller Private E-2

    Here's some more
     

    Attached Files:

  12. darrylqmiller

    darrylqmiller Private E-2

    Can't believe I only got three in the first post. I really need to get some sleep.
    Uugghh!!! It says file type for my winfiles.txt is to big. I'm sorry. What now?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete all steps in the order written. These are on your PC which means you are using them and they are out of date.

    To rename a file all you have to do is navigate to it with Windows Explorer and right click on it and then select Rename. Windows Explore can be run many ways. One is to right click Start and select Explore. But it sounds like the files are for your DJ software so why bother.;)

    That is why you are supposed to attach the ZIP file. There is no reason why you should not be able to attach it. Perhaps you just needed to click refresh or you were not noticing some kind of error message when you tried to upload it.

    Your logs are all clean. If you are still having a problem with IE opening on its own, it may just be related to some software you are running. Perhaps you can try renaming iexplore.exe to myie.exe and see if any program pops up complaining it cannot find Internet Explorer.
     
    Last edited: Jul 8, 2009
  14. darrylqmiller

    darrylqmiller Private E-2

    Okay. Really, thanks for your help. I was hoping it was some malware and I would be able to fix it simple. I will update those programs and make the changes you suggested. This probably isn't the right forum to try to fix this in so I think I'll just bow out gracefully and allow you to concentrate on problems related to this forum.
    So who knows, maybe one of the changes helped. Maybe one of the updates stopped a program from try to auto update, I don't know. I will just have to bite the bullet and take it to another computer place and pay them to look at it for me. This computer is to valuable as a work tool for me to screw it up trying to save a hundred bucks in repair fees versus the weeks of work it took me to organize all the songs and files.
    So once again, thanks for your time and I'll be back if I have other problems.
    Major Geeks rocks the house! :-D
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you still get IE running on its own, try renaming iexplore.exe as I suggested and see if any error message pops up. It could help you locate what application is trying to run the browser. It could even be a Windows Update issue.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. darrylqmiller

    darrylqmiller Private E-2

    Thanks. Will do the last steps. Windows popped open twice on it's own so I renamed iexplore.exe as suggested and a window opened up pointing to an issue with my wireless link (didn't know I even had this, it's built in)) named IrDA Fast Infared Port. I guess it's an infrared port for photo transfers and accessing the web. So I disabled this since I use a wireless card anyways.
    Usually when the IE pops open it does it multiple times but after disabling this infrared port it stopped!
    Thought I fixed it but about three hours latter it popped open. Crap!! I don't think I'll ever get this figured out. Guess I could disable automatic updates and see if that's the problem.
    There are so many things that could be causing this but trying to figure this out online seems rather hard. If you have any other suggestions I'll give it a shot.
    Thanks again.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you post in the Hardware Forum or Software Forum since this is not a malware problem.
     
  18. darrylqmiller

    darrylqmiller Private E-2

    Thanks. I went ahead and updated all spyware/ anti-virus software and disabled automatic updates on the computer. I am happy to say that for the first time in months I did a gig last night for 6 1/2 hours and the window didn't pop up once! We might have fixed this.
    Big applause and thanks to you for all your help. If it happens again I will go to the software/hardware section and post.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds