hotmail blocked and new browser download blocked

Discussion in 'Malware Help (A Specialist Will Reply)' started by cassandra1, Nov 7, 2013.

  1. cassandra1

    cassandra1 Private E-2

    Perplexed! Im Not able.to access hotmail from my computer only my phone. Cant download any new browsers or software from the net right now. Every download Ive attempted (chrome, anti malware, firefox) gives me the same error message, that the download has a virus, program deleted and then under more info takes me to a fake windows explorer 11 page. Not sure if you have heard of this one, but please lmk if you have and possible solution? I can access other sites. Just not dowload other browsers and wont let me access hotmail, Says my password is not correct (but it works on phone access to hotmail and I have reset it). Help please? and Thank you!!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What operating system are you using?
     
  3. cassandra1

    cassandra1 Private E-2

    Windows 7 on PC
    appears to be Luhe.sirefef.a virus
    Appears to have now dowloaded additional trojan virures.
    Still appears to be infecting woth new viruses while battling with old one.
    So far have used AVG 2014, combofix, hitmanpro, esetsmartin..., Rogue kiler, malwarebyte Nti malware, Tdss root kit, emsisoft emergency kit.
    All programs run, found some viruses but didnt remove them.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh, I didn't think you were able to download anything. If you indeed CAN, then you need to follow our procedures linked below:

    READ & RUN ME FIRST - Malware Removal Guide



    Also, run this please:

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  5. cassandra1

    cassandra1 Private E-2

    Thanks- here's the situation. Can only download in safe mode. Tried rebooting in normal mode and computer goes to black screen for 10-15 minutes and then to regular background but with spinwheel loading for more than an hour! Something seems to be triggering it from explorer. As soon as I go to task manager to try to shut down running programs, the screen goes black in the background again with no option to access internet. Safe mode is the only way at present.

    I Went through the advised steps one by one on each of the linked pages and attached log files. TDSSKiller shows 504 objects scanned with 0 / no threats. When I click on details after "processed" it show a completely blank/ empty window.

    I notice an unfamiliar icon on my desktop: iexplore.exe It appears to have the same brand identification/coloring/logo as TDSSKiller with the red K and downward grey arrow on the right side of the "K."

    Problems began one week ago on 11/4, 11/5. I kept receiving update messages from explorer and java. I always closed out the update windows. However, I noticed when I closed my computer and didn't go through the formal shut down procedure, that one of the updates processed as it was on a time reminder. So in the morning when I reopened the laptop the update took place and the computer ran incredibly slowly. Then I couldn't access hotmail from explorer. Then I couldn't download other software to access the internet from explorer (it blocked me downloading chrome and firefox with messages on the bottom of the load window saying virus found. When I clicked on further explanation, I was directed to a windows explorer 11 page that appeared to be real until I noticed ads popping up around underlined words, only the ads weren't for microsoft products, they were for all kinds of merchandise like furniture, clothes, etc.)

    Finally got chrome downloaded through safe mode. and have been able to follow your initial steps on the 5 pieces of software to obtain logs. I followed the instructions, turned off UAC and ran the scan on them all, but didn't correct the virus' found in RogueKiller, as per instructions.

    Thank you- just spent another 6 hours on this tonight tallied with 3 this morning. ArghhhhH!
    Cassandra
     

    Attached Files:

  6. cassandra1

    cassandra1 Private E-2

    Upload from running FRST.exe attached here.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Cassandra. :)

    There should be another log from running FRST >>> FRST.txt could you attach that for me please?
     
  8. cassandra1

    cassandra1 Private E-2

    Hi! Sorry for the delay, Got on in regular mode yesterday and I ran the programs again for the logs and then computer restarted and went dark. After more than an hour when it loads, error windows appear for explorer 11 saying not connected and do I want to restart or shut down. As soon as I click one of those windows the computer goes into an eternal pinwheel of loading with nothing happening.
    Appears to only load now in safe mode. So I re-ran the FRST in safe mode and saved the text file to my external flash. Please find it attached.

    Another recent problem is the wireless connection. It's not loading or connecting.
     

    Attached Files:

  9. cassandra1

    cassandra1 Private E-2

    Is iexplorer.exe a virus loaded software? Tried to attach a photo in word or pdf, both above the forums 97 KB restriction. Kaspersky lab listed with Nov 7 as the creation date.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    iexplorer.exe or iexplore.exe?


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:
    • [RUN][SUSP PATH] HKLM\[...]\RunOnce : 5E8A08FD-22AB-4613-97CB-CC8FE41E64EC (cmd.exe /C start /D "C:\Users\CASSAN~1.THE\AppData\Local\Temp" /B 5E8A08FD-22AB-4613-97CB-CC8FE41E64EC.exe -activeimages -postboot [x][-][x]) -> FOUND

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.





    Do you see these? Can you delete them? If so, when you reboot, are they still gone?

    C:\Users\cassandra.THEARF\AppData\Roaming\wjjsbteu
    C:\ProgramData\SMRResults311.dat

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.


    How are things running now?
     
  11. cassandra1

    cassandra1 Private E-2

    iexplore.com
     
  12. cassandra1

    cassandra1 Private E-2

    Thank you! I followed your instructions. Deleted the two files. Attached the logs.

    FYI - In RogueKiller after running scan, a large number of files are listed under drivers tab that could be deleted. But I didn't delete them. Should I?

    Also, a few days ago I did the following two things that enabled the computer to start in regular mode rather than safe mode, with a minimal start time of a minute:
    (1) I removed internet explorer from my startup menu and put it in the recycle bin. While I didn't empty the recycle bin, it appears to have completely emptied upon previous rebooting. I noticed in the MGlogs, that explorer seems to still be listed but it is not on my desktop or in my startup. However when I go to program files under C drive, explorer is still listed.

    (2) I also moved the TDSS rootkit removing tool Kaspersky Lab iexplore.exe into the recycle bin.
     
  13. cassandra1

    cassandra1 Private E-2

    correction: iexplore.exe


    Thank you! I followed your instructions. Deleted the two files. Attached the logs.

    FYI - In RogueKiller after running scan, a large number of files are listed under drivers tab that could be deleted. But I didn't delete them. Should I?

    Also, a few days ago I did the following two things that enabled the computer to start in regular mode rather than safe mode, with a minimal start time of a minute:
    (1) I removed internet explorer from my startup menu and put it in the recycle bin. (using Google chrome exclusively now) While I didn't empty the recycle bin, it appears to have completely emptied upon previous rebooting. I noticed in the MGlogs, that explorer seems to still be listed but it is not on my desktop or in my startup. However when I go to program files under C drive, explorer is still listed.

    (2) I also moved the TDSS rootkit removing tool Kaspersky Lab iexplore.exe into the recycle bin.


    Lastly- and bizarrely, all desktop files and downloads files seem to have copied themselves under Pictures! including some files that I am unsure of like: JRT.exe, OTM.exe, aswMBR.exe, RK_Quarantine, unknown. Imagine most of these are ok, but wanted to make sure. I scanned "unknown" file with malwarebytes anti malware and it came up with no threats.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, everything in the RogueKiller log looks just fine. Leave those entries where they are. :) I am not seeing anything else to tend to here, so any other questions you might have can be addresssed in the software forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds