iexplore.exe keeps running

Discussion in 'Malware Help (A Specialist Will Reply)' started by Carolyn1116, Aug 5, 2010.

  1. Carolyn1116

    Carolyn1116 Private E-2

    Hi All,
    I have seen iexplore.exe copy itself and run as many as 7 times in Task Manager. Sometimes there is a faint clicking noise in the background. Since so many others here have had this same problem, I have gone ahead with some of the suggestions. Per another thread I downloaded bootkit_remover.rar and extracted the remover.exe file (attached). Also attached is the C:\MGlogs.zip file. MalwareBytes has been run and came out clean. Super AntiSpyware has been run.

    When I try to delete the empty C:\System Volume Information folder, I receive the following message..."Cannot delete System Volume Information: Access is denied. Make sure the disk is not full or write-protected and that the file is not currently in use." I have gone through the steps of Read & Run Me First.

    Thanks in advance for your help!!!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Where is the log from:

    • combofix
    • SUPERantispyware <-- you have not run this yet!
    • Malware Bytes

    After running what you haven't already run as you should have done, (Run SAS first, then Combofix if you haven't already) do the below and then attach all the logs I need.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. Carolyn1116

    Carolyn1116 Private E-2

    I've attached the logs from MalwareBytes, Super AntiSpyware and ComboxFix. I also went ahead and ran Root Repeal and attached the log. Hope that is okay.

    There is now a problem with MG Tools. When I try to run it, nothing happens except a brief flash on the screen of a C:\Log??? That's it...so obviously no MGlog.zip is attached. Now what?

    Thanks a million for all your help!!!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You missed this bit. :)

     
  5. Carolyn1116

    Carolyn1116 Private E-2

    I didn't miss it; just couldn't double-click it to run.:-o Anyway, it worked now, and I have attached the MGlogs.zip file.

    Thanks again!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Also I need to ask some questions:
    1. Do you have any drives that has a non-windows installation on them
    2. Are all drives NTFS formatted
    3. Do you have any non-standard or special MBRs which can occur from companies like Dell or HP who frequently install additional partitions used for recovery partitions in lieu of giving CD/DVDs.
    4. Is any program like Grub ( see:http://www.gnu.org/software/grub/ ) being used
    5. Is drive-encryption being used?
    6. Are any drives external USB pen drives or external hard drives being used?
    7. VERY IMPORTANT: Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.
     
  7. Carolyn1116

    Carolyn1116 Private E-2

    Iexplore.exe is running 6 copies in Task Manager today. The computer had slowed down significantly so I'm running in Safe Mode now.

    As requested, attached is the MBRCheck log.

    Answers to your questions are as follows:

    1. No
    2. Yes, all drives are NTFS formatted
    3. Yes, Dell has installed a partition on the hard drive for restoring - PC Restore
    4. No
    5. No, drive encryption is not being used as far as I know
    6. No, there are no external drives
    7. Yes, all important data is backed up

    Thanks a million!!!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run MBRCheck as your log was truncated and did not have the info we need.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The full log should be on the Desktop ( automatically generated ). Just attach that file.;)
     
  10. Carolyn1116

    Carolyn1116 Private E-2

    Attached is the MBR Check log.

    Thanks a million for all your help!!!:)
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. First let me suggest that you download and install Firefox and use it to see if the same issues happen. After we confirm the situation, I will probably ask you to uninstall IE8.

    Get it here: Mozilla FireFox



    Is FireFox working okay now?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    IE8 is a tabbed browser. The more tabs you have open the more iexplore.exe processes will appear in Task Manager. Even with only one real tab having a URL connection a secondary tab is already there which means at lease two iexplore.exe processes.

    Your slow PC is due to the below memory inadequacies. You cannot run Windows XP with so little memory
    Code:
    Total Physical Memory 256.00 MB 
    Available Physical Memory 23.21 MB 
    You need at least 4 times ( 1GB ) this much memory but 8 times ( 2GB ) is a much better idea.

    You cannot have McAfee running on this PC with so little memory. McAfee is a pig.
     
  13. Carolyn1116

    Carolyn1116 Private E-2

    So far Firefox is working just fine. There are no iexplore.exe processes popping up in Task Manager. Actually, I think I'm going to love it!;) As suggested, I'm going to increase the memory on my computer.

    Please let me know if I should delete all of the downloads from this site now sitting on my Desktop. Also, uninstall IE8?

    Thanks so much. You guys are great!:cool
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You don't need to uninstall IE8, as long as you are aware that there will be a new IE process for each tab you have open.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  15. Carolyn1116

    Carolyn1116 Private E-2

    All is well right now. No additional problems. Thanks again for all your help!
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds