Cannot remnove iexplore.exe infection on XP (possibly sodabot worm?)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ComputerFixerKeyWest, May 14, 2011.

  1. ComputerFixerKeyWest

    ComputerFixerKeyWest Private E-2

    This one has me stumped.
    I have read and followed the instructions used by others for this type of infection, however the solution seems different for each case.
    PROBLEM:
    • iexplore.exe process starts without a window, usallay 2, even in safe mode
    • internet voice ads play without a window
    • many other secondary infections present (and removed)
    • all links to programs in the StartMenu->Programs deleted
    • after running multiple removal programs, I still have iexplore.exe starting randomly.
    WHAT I HAVE DONE
    1. booted in Safe Mode
    2. ran MalwareBytes, SpyBot, SuperAntiSpyware, ComboFix, Avast
    3. CCleaner first to clean up temp files, then after scans
    4. scans are coming up clean, but there is still an infection
    5. removed Java manually
    6. deleted IE temp files manually.

    attached are HiJackThis and ComboFix logs.

    Thank you so much for any help. I have had to remove a lot of malware/virus over the years, but I rarely find one this resistant. At this point I usually re-format, but the user has medical software installed that he no longer has the disks for.

    Computer is XP pro SP3; 3GB RAM; IE8 and FireFox4
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. ComputerFixerKeyWest

    ComputerFixerKeyWest Private E-2

    Thank you for your response. I will review and follow the procedures, then post the additional log files. I may not get to the computer until tomorrow, but I will definitely post once I get these steps done.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will be here. We need these logs:
    SAS
    MBAM
    RootRepeal --- If it runs.
    ComboFix --- From the proper location
    C:\MGLogs.zip
     
  5. ComputerFixerKeyWest

    ComputerFixerKeyWest Private E-2

    I reviewed the XP protocol pages for removing spyware/malware/virus and tried to follow the steps accurately.

    Attached are 2 zip files: (1) is MGlogs.zip and the other (2) is Scan_Logs.zip (which contains the logs from RootRepeal, MalwareBytes, SAS and CoboFix).

    Note: before running these applications, I did download and run the current version of McAfee Stinger. It did locate and remove several items that had not been detected before. I included the Stinger log.

    I did not have much time today to check the computer after running Stinger and all the other scans, BUT, it appeared the iexplore.exe process was not starting. I assume the damage done to the Start Menu links (all program links are missing except for newly installed items - like all the scanning software) will have to be manually repaired once the system is clean.

    Thank you in advance for your review and any advice. And I really appreciate all the guidance and work MG does!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. What stinger found would have shown up in your newfiles log. Did you run MGTools in safe mode? Please re-run it in normal mode and attach the new log.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run this and get me a log:
    TDSSkiller - How to run

    You likely just need to change the attribytes of your files and folders. They have probably been changed by your infection to be Hidden. You can right click on the folder and select Properties and then change the Hidden attribute. Make sure you apply this to all subfolders too when asked. You may have many folders ( if not all ) that you need to do this to.

    Also something else that may help could be doing the below.



    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.

    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands ( in bold black ) at the command prompt each followed by the enter key. Try each command!!!! The bold black are commands. The purple/brown is merely informational.

    cd \ <-- this changes to the root folder and the prompt should change to C:\>
    attrib -h -s * /S /D <-- this will try to remove the hidden and system attributes on all files and folder. Note there are spaces before -h, before -s, before * and before each /
    attrib -h -s *.* /S /D <-- a redundant command match possibly other file names and folders due to using *.*

    Let me know if this helps.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds