Greeting! IEXPLORE.exe, ad pop-ups, wave audio control goes to 0

Discussion in 'Malware Help (A Specialist Will Reply)' started by hikahuza, Jul 12, 2010.

  1. hikahuza

    hikahuza Private E-2

    - IEXPLORE.exe starts in the background as soon as I boot into Windows XP
    - I get random sound-ads playing in the background. These ads stop when I open the task manager and stop the IEXPLORE.exe process. However, the IEXPLORE.exe process re-appears just seconds later.
    - I hear occasional clicking sounds in the background (the sound is that of clicking a link in Internet Explorer)
    - My wave control is muted every few minutes, sometimes seconds. I'm guessing this is done so I don't hear the clicking sounds made in the background
    - Occasionally an Internet Explorer window would open with an ad.

    Same as many other threads, will scan with combofix.exe, RootRepeal and MGtools tomorrow.

    I also did this "Use windows explorer to find and delete:
    C:\WINDOWS\Temp\100.dat

    Now use add/remove programs to uninstall:
    Java(TM) 6 Update 14
    Java(TM) 6 Update 6
    Java(TM) SE Development Kit 6 Update 14

    Reboot and download and install:
    Java Runtime 6" from the thread http://forums.majorgeeks.com/showthread.php?t=218977

    Got this trojan today and i would be very happy if you guys could help me get rid of it. :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!



    Your infection is in your Master Boot Record (MBR). We need to see the below log before creating a fix.
    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe
    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.


    Also I need to ask some questions:
    1. Do you have any drives that has a non-windows installation on them
    2. Are all drives NTFS formatted
    3. Do you have any non-standard or special MBRs which can occur from companies like Dell or HP who frequently install additional partitions used for recovery partitions in lieu of giving CD/DVDs.
    4. Is any program like Grub ( see:http://www.gnu.org/software/grub/ ) being used
    5. Is drive-encryption being used?
    6. Are any drives external USB pen drives or external hard drives being used?
    7. VERY IMPORTANT: Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Now follow the directions in the below link for running MGtools It also explains possible reasons for not being able to run MGtools
    Attach the requested MGlogs.zip file.
     
  3. hikahuza

    hikahuza Private E-2

    Questions:
    1. how do i know that?
    2. how do i see that?
    3. I have a dell and a cd to reset the cumputer with. i tried reboot it with the cd but when the computer has read everything on the cd i get a bluescreen. Ive tried 3 times, any idea how to fix that?
    4.No
    5. No idea, how do i see that?
    6. N0
    7. I have everything backed up, i just want to reset it but that damn bluescreen is stopping me.
     

    Attached Files:

  4. hikahuza

    hikahuza Private E-2

    Questions:

    1. How do i see that?
    2. How do i know that?
    3. I have a dell inspiron 9200 and i tried to reset the computer but when the computer has read everything on the pc i get a bluescreen.
    4. Not what i know of.
    5. How do i see that?
    6. No
    7. I have everything i need backed up, i just want to reset the computer but that damn bluescreen is stopping me.
     

    Attached Files:

  5. hikahuza

    hikahuza Private E-2

    Mglogs
     

    Attached Files:

  6. hikahuza

    hikahuza Private E-2

    the Bluescreen error is 0x0000007b.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Talk to Dell but it could be due to the Master Boot Record infection that you have.

    You did not run the program I asked you to run. You ran their TDSS Remover tool. Let's use a different program which does a better job any way.



    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds