iexplore.exe Virus Logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by delouv, Jul 5, 2010.

  1. delouv

    delouv Private E-2

    Gentlemen,

    I am have the same problem as other posts I have read on this
    site relating to Iexplore.exe
    Namely: Unable to close Iexplore.exe from task manager, Wave
    volume turning off, Request to change default browser to
    Internet Explorer (currenlty using Firefox), pop up adds.
    I have followed the Windows XP Cleaning Procedure
    (http://forums.majorgeeks.com/showthread.php?t=139313) however
    the software was unable to locate any issues and the problem
    persists.
    I have attached the various logs as requested and would be
    grateful for any assistance. Logs attached under same heading in the software forum as I couldn't upload them here

    NB: Both AVG and Norton have been uninstalled for my computer however some signs still show up when running Combofix.

    Kind regards
     
    Last edited: Jul 5, 2010
  2. delouv

    delouv Private E-2

    MGlog attached
     
  3. delouv

    delouv Private E-2

    LOGS attached
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. delouv

    delouv Private E-2

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. I don't have priviledges to move the logs here so let's just start a fix:

    Mozilla Firefox (3.0.3) <--- You should update Firefox!

    Java(TM) 6 Update 17 <--- Uninstall this outdated version of java:

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    I suggest you run the Official AVG Removal Tool

    Make sure you also delete any AVG folders in Program Files and Documents & Settings/Application Data directories.

    Now Run Ccleaner. (Not the registry section, just the cleaner)

    C:\Documents and Settings\mark de Louvois\Desktop\MGtools.exe <--- delete this now as it is not where we requested it to be.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    SecCenter::
    {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
    {E10A9785-9598-4754-B552-92431C1C35F8}
    Driver::
    abwmb
    File::
    c:\windows\UDB.zip
    c:\windows\IDB.zip
    Folder::
    c:\program files\Spyware Doctor 
    C:\Documents and Settings\mark de Louvois\Local Settings\Application Data\dpocyswmw
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now I want you to install some antivirus. Run a full scan with it and let me know if it flags anything?

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running.
     
  7. delouv

    delouv Private E-2

    Hi There,

    Thanks very much for your reply. I have carried out all that you specified and have attached the various logs. I ran Superantispyware and it found 19 tracking cookies, Log attached.
    The symptoms are still there, namely: Pop up ads, "Interent explorer is not your default browser...", Volume turns off, IExplore.exe running in task manager and unable to cancel it.
    Hope the logs help.

    Kind regards
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this:

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe
     
  9. delouv

    delouv Private E-2

    Hi There,

    Bootkit result:


    Unkown boot cade has been found on some of your physical drives.
    To inspect the boot code manually dump the master boot sector:
    remover.exe dump <devise_name> <output_file>
    To disinfect the master boot sector, use the following command:
    remove.exe fix <device_name>

    Press any key to continue

    This text was copied manually as there was no copy/paste facility.

    Many thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You left out the part that we need.

    Yes there is. You can right click on the top bar of any command prompt type window and you will see a menu where you can select Edit functions which include the ability to Mark, Copy, and Paste. So you use Mark to highlight the info and then use Copy to get it into the clipboard. You can actually do the Mark by just right clicking anywhere in the window but if you then right click again in the window to do a copy, you will loose the marking so that is why you need to use the Edit function from the top bar.
     
  11. delouv

    delouv Private E-2

    Sorry about that. Attached file.
     

    Attached Files:

  12. delouv

    delouv Private E-2

    Sorry to drive you mad but did you have any luck with the last bit of info I posted.

    Regards
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And sorry for the late response. However I am having to consult with colleagues regarding your problems. You are infected with a type of new malware and I don't want to make any sudden moves. Please be patient. :)

    Thanks
    Kestrel13!
     
  14. delouv

    delouv Private E-2

    FYI

    I found the file IExplore.exe located in C:\WINDOWS\system32\dllcache but ws unable to delete it from the search results and also unable to locate it when I followed the path in file manager. Maybe it's something.
    Once again thanks for all your help.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do not try and delete anything on your own! I am hoping Chaslang will chime in again soon.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing wrong with a backup of Internet Explorer being in the dllcache folder. It is a backup for Windows File Protection.


    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. Again you really don't have much choice though since these infections are too dangerous to your security to leave on a PC.


    Now if you have important data backup up and understand the above warning - please do the following:
    • Click Start, Run then copy and paste the below into the Run box and click OK.
    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0
    • Now reboot your PC and after reboot continue with the below instructions.
    • Disable System Restore on all drives.
    • Look for the below folder and if if it sill exists, delete it.
      • C:\System Volume Information\Microsoft
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

      Then attach the below logs:
      • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. delouv

    delouv Private E-2

    Solution:

    In the end I download XPlite and ran it in safe mode. I was then able to turn off Internet Explorer. Job done. Created a restore point and that has stopped all the problems. May not have got rid of the virus but it has certianly stopped it operating. As far as I can ascertian.
    Thanks for your help. Your comments on the above would be appreciated.

    Rgds
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you did not repair then Master Boot Record then you are still infected and at risk for security problems. Rerun the scan that Kestrel13! gave you in message # 8 and attach the results. This will tell us if you MBR was fixed.
     
  19. delouv

    delouv Private E-2

    Thanks very much for your response.
    I carried out what you said and have attached the log.
    There is a file:C:\System Volume Information on the drive but not:C:\System Volume Information\Microsoft.

    Things are working just fine. There is no Iexplore.exe in task manager, no pop up ads or sound only adds, the volume is also working fine.

    I have also attached the bootkit result.

    Many thanks for your help.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log shows you have a second drive which may or may not be carrying the infection since it show as an unknown boot code. If your problem returns, it would likely be because the second drive is infected and needs to be cleaned.

    So if things remain okay for a few days and a few reboots, then you are likely okay and can continue on with the below final steps.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds