HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mute

Discussion in 'Malware Help (A Specialist Will Reply)' started by gopsr, Jul 20, 2010.

  1. gopsr

    gopsr Private E-2

    Hello,

    I have the same virus/malware issue that several others have encountered. I have followed the "READ ME FIRST" section and am attaching all required items here.

    SYMPTOMS:
    1. Multiple instances of iexplore.exe running. Even when stopped using the task manager, they reappear right away.
    2. Wave volume control continually resets to zero. Not mute, but the volume on that slider is all the way down.
    3. Ads keep popping up in Internet Explorer even though i don't have it running.
    4. When i fix the wave control volume, the sound from ads plays in the background with no apparent window open.
    5. The highlighted window deactivates. This is very annoying while typing because if I'm not looking at the screen, I type nothing for a while until i realize it and re-click on the window to make it active.


    STEPS TAKEN SO FAR:
    1. Deleted any unknown programs in the program manager
    2. Ran my useless virus scanner program
    3. Followed the "read me first" steps in this forum place. Including running the following programs:
    a. SuperAntiSpyware
    b. Malwarebytes
    c. combofix
    d. rootrepeal
    e. mgtools


    PLEASE HELP....
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  3. gopsr

    gopsr Private E-2

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Hi Tim,

    I can not download the MBRcheck.exe program. The error " 403 Forbidden
    Access to this resource on the server is denied!" continues to pop up.

    Attached is the screen shot that i took of the error.

    Thanks.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Well, that's new!! Rat's!!


    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.
     
  5. gopsr

    gopsr Private E-2

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    BOOTKIT POST: PLEASE SEE BELOW






    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: b19ee33a0168d5f0bb9afbe12e2bc035
    \\.\D: -> \\.\PhysicalDrive1
    MD5: b19ee33a0168d5f0bb9afbe12e2bc035
    \\.\G: -> \\.\PhysicalDrive2
    MD5: b19ee33a0168d5f0bb9afbe12e2bc035

    Size Device Name MBR Status
    --------------------------------------------
    149 GB \\.\PhysicalDrive0 Unknown boot code
    465 GB \\.\PhysicalDrive1 Unknown boot code
    931 GB \\.\PhysicalDrive2 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>


    Press any key to quit...
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    You should be able to download MBRCheck now:

    Here is the download MBRCheck

    Tell me what each physical drive is. Are they partitions or slave drives?
     
  7. gopsr

    gopsr Private E-2

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    MBRcheck complete. Please see attached.

    The (3) drives are actually real attached drives.

    149 GB \\.\PhysicalDrive0 Unknown boot code
    - This is my C drive where my programs and OS are located.


    465 GB \\.\PhysicalDrive1 Unknown boot code
    - This is my D drive that I use to store videos and backups. I do some non-linear video editing. This is my drive for that.


    931 GB \\.\PhysicalDrive2 Unknown boot code
    - This is my G drive. It is a USB attached 1TB drive used only for storage and backups. Like pictures, etc.


    Thanks again.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.


    Now if you wish to continue and fix the malware - please do the following:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 0 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please repeat that for physical drive1 and then again for physical drive2.

    Now please re-run MBRCheck.exe and attach that log also.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  9. gopsr

    gopsr Private E-2

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Okay, all done. Please see attached. Are we getting close to the point of getting rid of the virus?

    Thanks,

    David

    PS: I zipped the MBRFix files because there was 6 of them. Also, I couldn't run the MBRcheck on my third drive since it's just a USB attached storage drive.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Looks good. Just a few items left to remove. Did you set this:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80

    If not, follow these instructions to reset your proxy settings:
    Change Proxy Settings.

    Now use windows explorer to find and delete:
    C:\WINDOWS\Temp\100.dat
    C:\WINDOWS\Temp\JET882.tmp

    Now run CCleaner and afterward, make sure these folders are cleaned out:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Mom and Dad\Local Settings\temp\

    Now tell me what issues you are still having.
     
  11. gopsr

    gopsr Private E-2

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Okay. Getting closer. The thing is running noticeably better. A couple more items, please see below.

    1. I could not find C:\WINDOWS\Temp\JET882.tmp after doing a search. Is that an issue?

    2. See the attached screen shots. I could not delete these files from the TEMP folders.

    3. My windows auto update is going crazy trying to do a ton of updates I've been ignoring. Which, looks like came back after something we reset. Should i go ahead and install them?

    4. All the extra function keys on my keyboard are no longer working. Volume, play, mute and all the other little "program open" buttons. The stuff came with my PC preloaded and I cannot find any drivers for them to update or replace whatever happened during the infection.

    5. What is the point of anti-virus software like Norton if viruses get through anyway?
     

    Attached Files:

    • 1.jpg
      1.jpg
      File size:
      8.2 KB
      Views:
      1
    • 2.jpg
      2.jpg
      File size:
      11.9 KB
      Views:
      1
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    I have no idea as to why your extra function keys are not working, but I don't think it is related to the malware. Why don't you get me a new MGLogs.zip to check.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  13. gopsr

    gopsr Private E-2

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Done. But it looks like the virus deleted the keyboard drivers and they were somehow replaced with generic window's drivers. The keyboard functions worked before the virus two weeks ago.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Your logs are clean. Did your keyboard come with any install disc's? If so, you may need to reinstall the drivers for it. If not, you may need to post in the software forum for assistance in getting the keyboard functions working again.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  15. gopsr

    gopsr Private E-2

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    Thanks Tim,

    We're all set. I'll figure out the keyboard thing later. I appreciate the help. It looks like everything is rocking and rolling. In fact, the computer hasn't run this fast since i bought it. Sweet. I kept adding RAM and it didn't get faster...turns out it was junk all along.

    Thanks again,

    David
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: HELP: same error as others: IEXPLORE.exe, ad pop-ups, wave audio control goes mu

    You are most welcome. Safe surfing. :)



    Support MajorGeeks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds