Multiple IExplorer.exe Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Thomas12345, Jan 5, 2011.

  1. Thomas12345

    Thomas12345 Private E-2

    I have been experiencing multiple IExplorer.exe running in the background of my computer. Also there are random pop up ads, audio ads that will play through my speakers and programs such as WhiteSmoke Translation software. It is also severely lagging my computer. I have read the READ AND RUN ME FIRST post and 10 other posts on the issues and followed the outlined steps however I could not solve my problems. So I am asking for any help you can provide me. Thank you in advance for your time.

    I have attached my results from Bootkit Remover. After following the instructions in other posts, running "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0 and restarting my computer I continue to receive the same message from in the Bootkit Remover.

    I have also ran MBR check and attached my results. I chose the selection to restore the MBR as advised in a previous post and restarted my computer. After restarting my computer and runnig MBR check again I received the exact same results.

    Finally I have attached the log c:\MGlogs.zip.

    Please let me know if there is anything else that you need from me or if anything is not in the correct format and I will correct it immediately. Thanks again for your time.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the rest of the logs that were requested in the READ & RUN ME. These logs were:
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    • RootRepeal
    Also I suggest that you run the below.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  3. Thomas12345

    Thomas12345 Private E-2

    Thank you for the quick reply. Sorry for the delay but I wanted to make sure I ran everything properly.

    I have attached the requested logs. I was unable to run RootRepeal. I installed it and ran it but I continued to get an error saying "could not initialize driver! Please contact the author!" after hitting scan. Then after hitting ok it would read "Could not scan drive c (error 0xc00000024). I am not sure what would be causing this or what I am doing wrong.

    Please let me know what direction you would suggest going from here. After running these processes it appears IExplorer.exe are still running in the task manager.

    Thanks again in advance.
     

    Attached Files:

  4. Thomas12345

    Thomas12345 Private E-2

    One more attachment to post, the TDSSkiller Log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure that you have rebooted your PC one more time after running TDSSkiller as it appears that it has found and fixed your problem. Let me know how it works after the reboot.
     
  6. Thomas12345

    Thomas12345 Private E-2

    I have rebooted the computer. When I open Internet Explorer with task manager open their are instantly two iexplorer.exe's open, now looking at it there are a total of 3 running although I have only one window and one tab open. Should this be happening?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal. Are you having any actual malware symptoms/problems?
     
  8. Thomas12345

    Thomas12345 Private E-2

    No I do not see any visible symptoms but I am afraid to use anything because I do not want my information stolen. Passwords, credit cards, etc, are these things I should be worried about in your opinion? Are there any extra steps I can follow? To assure that my system is secure?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Question: Have you had any illegal activities on any credit cards, bank accounts.....etc? Have you checked with your financial institutions?

    Well actually the safest thing to do when a PC is used for financial type actions is to format and reinstall to have a higher confidence level. Your PC was very very badly infected (likely due to not havng it properly protected and due to the fact that you never properly updated Windows). And it still is infected which we will address below.

    There are never any guarantees that a PC is 100% clean once it has been infected. And the same can be said once it has even been connected to the internet especially if proper protection is not in place before connecting to the internet.

    However we will continue with some cleaning because your Master Boot Record (MBR) showed that it was not standard and this could be due to an infection. Do you have your Windows Boot CD? And also very important, do you have all of your important data backed up as repairing the MBR can sometimes cause problems?

    Please rerun MBRCheck and attach a new log since you attempted to fix it in message # 1 and I want to see if the results are still the same as you had stated.

    Also please redownload the current version of TDSSkiller and run a new scan with it and attach the new log. I want to see if it really did fix what it found.

    Now see step 4 of the READ & RUN ME and put your PC into Normal Startup mode with MSconfig as requested.


    Uninstall the below software:
    Java(TM) 6 Update 17
    Java(TM) SE Runtime Environment 6 Update 1
    LiveUpdate 3.2 (Symantec Corporation)
    Viewpoint Media Player <-- should have been uninstalled in step 5 of the READ ME
    Whitesmoke Translator

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [?????????] ??????????????e
    O4 - HKUS\S-1-5-18\..\Run: [Rvahisayiko] rundll32.exe "C:\Windows\system32\config\systemprofile\AppData\Local\NlsyDa.dll",Startup (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Rvahisayiko] rundll32.exe "C:\Windows\system32\config\systemprofile\AppData\Local\NlsyDa.dll",Startup (User 'Default user')
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Users\Owner\AppData\Local\Temp
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 8, 2011
  10. Thomas12345

    Thomas12345 Private E-2

    I do have all my important data backed up. However I do not have a Windows Boot CD.

    I reran MBRcheck and this was successful I have attached the requested logs.

    I redownloaded tdsskiller and ran it and also attached the log. It showed that it did not detect any threats.

    I set my computer in normal startup mode and rebooted it.

    I then uninstalled the requested programs.

    I then ran C:\MGtools\analyse.exe, closed all browsers and fixed the requested items.

    I then created CFscript.txt, closed all browsers, spyware, antivirus and firewall programs and dragged CFscript.txt onto combofix.exe.

    I then went to reopen internet explorer to dl the new version java. However I am getting the following error when I tried to open it. Illegal operation attempted on a registry key that has been marked for deletion.

    I then continued to C:\MGtools\GetLogs.bat and received the same error notice. It is saying, "Illegal operation attempted on a registry key that has been marked for deletion."

    I then put the completed logs onto a flash drive and posted this post and uploaded them with my laptop. I am unable to run any programs on my computer we are working on.

    What is causing this and can we correct it?



    Combofix then ran, restarted my computer and produced a log. I have attached the log.
     

    Attached Files:

  11. Thomas12345

    Thomas12345 Private E-2

    I actually checked this post and another user was having similar problems.

    http://forums.majorgeeks.com/showthread.php?t=200478

    I am no longer receiving the error message. I will now complete the remainder of your directions and post my results.

    Thank you.
     
  12. Thomas12345

    Thomas12345 Private E-2

    I rebooted and installed an updated version of java.

    I then deleted all files and subfolders in the folders below:
    C:\WINDOWS\Temp
    C:\Users\Owner\AppData\Local\Temp

    I then ran Ccleaner.

    I then ran C:\MGtools\GetLogs.bat

    I then tried to attach the requested logs:
    ComboFix.txt , however I received the following error message.

    "Upload Errors
    ComboFix.txt:
    You have already attached this file in thread : Multiple IExplorer.exe Virus "

    I do not see where I have uploaded this file in the thread.

    C:\MGlogs.zip

    Thank you again for the follow ups, your help is greatly apprecaited.
     

    Attached Files:

    Last edited: Jan 8, 2011
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already attached the combofix log from the last fix in message # 10.

    Now we need to see if we can get your MBR fixed. Since you do not have a CD, you will have to make a CD having the Vista Recovery Environment on it. You can download the Windows Vista 32-Bit (x86) Recovery Disc Torrent from the below site and follow instructions of burning the ISO file to create a bootable CD.

    http://neosmart.net/blog/2008/windows-vista-recovery-disc-download/


    When you have finished making the CD, make sure you can boot from it into the Recovery Enviroment. You will need to make sure that in your BIOS you have set the boot order to allow booting from the CD first. When you boot this CD you will eventually see a list of Recovery Options. ( This link http://www.bleepingcomputer.com/tutorials/tutorial142.html shows some illustrations ) You will be choosing Command Prompt. Once you get to the Command Prompt, you will type bootrec.exe /fixmbr and then press ENTER. ( Note: There is a space after bootrec.exe ) Hopefully this is able to rewrite your MBR.
     
  14. Thomas12345

    Thomas12345 Private E-2

    I followed the directed steps and typed the command you requested and received the message that the fix was completed.

    I then rebooted my computer are there any logs or anything you need me to upload to verify if it worked as you hoped?

    Your efforts are greatly appreciated.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Run a new scan with MBRcheck and attach the new log so we can see if the MBR was fixed.
     
  16. Thomas12345

    Thomas12345 Private E-2

    I ran a new scan with MBRcheck and it appears to be fixed.

    I have attached the log.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is much better. ;) Now you need to get this PC properly update and properly protect which the below will address.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. Thomas12345

    Thomas12345 Private E-2

    Ok thank you for the positive news. I am going to dilligently follow each step outlined below. The only other information I wanted to provide is that over the last few days in between following directions I have ran SAS Full Scan a few times and every two or three times there will be only one infection titled Rogue Palladium(sp). SAS will then remove it then a day later it will reappear. Does this raise any concerns to you?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach the logs that show this. The logs are all in the below folder.

    C:\Users\Owner\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs
     
  20. Thomas12345

    Thomas12345 Private E-2

    I have attached the requested log.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rogue.Pallidium is a false detection by SUPERAntiSpyware.

    The SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS#WARNONPOSTREDIRECT registry key is a valid key always present on all systems and the default value is 0
     
  22. Thomas12345

    Thomas12345 Private E-2

    Thank you for addressing my concern about this one false detection.

    After receiving that confirmation I went along with the "Final Steps" instructions to completion. I then continued along to follow the "How to Protect yourself from malware!" Link to protect myself in the future. I began following all instructions.

    I was working on Step Number one, updating windows. I clicked the appropriate link and an update began downloading. After the update dl'd it prompted me to restart my computer. When my computer restarted it was on some screen showing that updates were being installed. I walked away from my computer for a few minutes and then returned. I then completed a few other tasks and returned to my computer 10 mins later. It was still on the same black screen with a combination of numbers and letters that I do not remember. I then at that point just manually restarted my computer.

    When the computer restarted I was prompted with:
    "Windows Error Recovery"
    Windows failed to start. A recent hardware or software change might be the cause.

    I was then given the following selections:
    -Launch startup repair (recommended) or
    -Start windows normally

    I chose to launch startup repair. After that it went to the next screen, with the green loading bar that usually come up when windows is starting, this scrolls for one full scroll then my computer goes to a blue screen.

    The blue screen says the normal blue screen stuff and at the bottom has this notice:

    Technical information:
    ***** STOP: 0x0000c1F5


    This appears to be the issue, but there is not a solution in there that I understand:
    http://support.microsoft.com/kb/946084

    How can I use this "hotfix" if my computer will not start? Any information would be greatly appreciated. If this is the wrong forum to post this I apologize in advance.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Jan 15, 2011

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds