another Iexplore.exe wave mute/popups malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by tomaek, Jul 14, 2010.

  1. tomaek

    tomaek Private E-2

    Hello there,

    I'm suffering from the same problem many people are currently reporting which is named in the title. I'm running through the READ AND RUN ME FIRST sticky at the moment but I'm fairly sure that I'll have to use the bootkit_remover.rar . My problem is that I have a Dell E6400 laptop and I also have linus installed on it. So from this list
    points 1 (yes, linux on same drive, different partition), 2 (no, have ext3 format), 3 (dell laptop) and 4 (using grup) are a problem. What will I have to do?

    Many thanks for any support. This forum is awesome :clap
     
  2. tomaek

    tomaek Private E-2

    Okay, i went thought the READ & RUN ME FIRST. Malware Removal Guide and then the Windows XP Cleaning Procedure. I have finished the first two steps. 4 logs are attached, MGtools will follow in a minute.

    As mentioned in my first post, I have IEXPLORE.exe processes starting even though I never use internet explore. I get random sound-ads playing in the background and I hear occasional clicking sounds in the background. Occasionally an Internet Explorer window opens with an ad.
     

    Attached Files:

  3. tomaek

    tomaek Private E-2

    And here is the MGlogs report. The problem started occuring about 2 days ago
     

    Attached Files:

  4. tomaek

    tomaek Private E-2

    Hi, I have some more information. Apparently it is not possible to edit posts here, so I have write a reply. Hope this is not seen as a bump...

    I ran the Bootkit Remover and got the following output:

    In addition to that, I now have the problem that something keeps on writing on my harddrive and I constantly have to delete files. Rather annoying. The folder which is being writing in is
    C:\System Volume Information\
    Is that perhaps causeb by something I've done whilst going through the step-by-step guide?

    Many thanks
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can edit posts but only within a 5 minute time limit. Sorry but every post is actually a bump intentional or not.




    We need to ask some questions:
    1. Do you have any drives that has a non-windows installation on them
    2. Are all drives NTFS formatted
    3. Do you have any non-standard or special MBRs which can occur from companies like Dell or HP who frequently install additional partitions used for recovery partitions in lieu of giving CD/DVDs.
    4. Is any program like Grub ( see:http://www.gnu.org/software/grub/ ) being used
    5. Is drive-encryption being used?
    6. Are any drives external USB pen drives or external hard drives being used?
    7. VERY IMPORTANT: Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.
    Based on your logs I see you do have a Dell PC and have 1 physical hard disk with the below 4 partitions. Which thus looks like you have a multi-boot type system since your Windows boot drive is on 28.78 GB and is almost out of free space too!!!!! What are you running on the other partitions? I''m guessing that the 478.50 MB one is a Dell Restore partition.
     
  6. tomaek

    tomaek Private E-2

    Hi, thanks for helping me.

    The 478.50 MB partition is indeed a Dell Restore partition. I have Linux installed on the other ones. I know, in principle, how to reinstall Grub in order to access Linux again if I have to overwrite the MBR. So hopefully that wouldn't be a problem. I've answered your 7 questions in my first post. The Windows partition is indeed almost out of free space. I think the reason is
    I think i had about 1.2 GB of free space before.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still inadequate for proper operation of Windows.



    Now if you have important data backup up and understand the above warning - please do the following:
    • Click Start, Run then copy and paste the below into the Run box and click OK.
    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0
    • Now reboot your PC and after reboot continue with the below instructions.
    • Disable System Restore on all drives.
    • Look for the below folder and if if it sill exists, delete it.
      • C:\System Volume Information\Microsoft
    • If you don't see this Microsoft folder or are denied access to the System Volume Information folder, just continue on
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
      Then attach the below logs:
      • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. tomaek

    tomaek Private E-2

    Okay, I've executed the bootkit remover command and disabled System Restore. Now I have 2.9 GB of free space. How much would you recommend?

    Since I did the above, the pop-ups and sound ads are gone. The system feels much quicker now, however, I also had 2 crashes since then (have used the computer for 5, maybe 6 hours).

    The MGtools logs are attached.

    Many thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You always want to have about 4 GB available to avoid performance issues. As soon as you reenable System Restore it will create a restore point which will use a large amount of disk space and at each reboot another restore point will be made. Also when you do Windows updates and certain other software installations, they will also create restore points. You need more disk space for your Windows partition or you need to delete a bunch of stuff you have there. 29 GB for a Windows partition is rather small unless you plan on not installing or doing too much with it.

    You should post about crashes in the Software Forum and provide exact word for word error messages.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. Re-enable System Restore
    10. After doing the above, you should work thru the below link:
     
  10. tomaek

    tomaek Private E-2

    done.

    thanks for all your help, hope my computer is safe now :major
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds