IExplorer.exe error message on shut down, is this a Trojan??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by armansrsa, May 17, 2008.

  1. armansrsa

    armansrsa Private E-2

    Hi

    I did the removal procedure however two things happened that im not sure were supposed to.

    1) Combofix rebooted my machine saying that it is doing a log but never quite finished, it just hung around with the blue screen for a long time until i cancelled it and moved on

    2) MG tools ran into an error message "processDLL failed to initialise" at the end

    THe reason why i did these scans in the first place was to remove something called IExplorer which gives an error message everytime i shut down. I dont know what it is and i dont use Internet explorer that often. I have looked at the other threads but nothing appeared too helpful

    Attached are the following logs from the cleaning procedure

    thanks for your help
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please delete these items:

    C:\qjatw9aj.exe
    C:\qpe6.com
    C:\uqb0julr.bat
    C:\ka1nk.bat

    Reboot and tell me how things are. :)

    If they won't delete:

    download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Attach the Avenger log.
     
  3. armansrsa

    armansrsa Private E-2

    THanks, i see the files you mean, they were hidden files although i did uncheck the hidden files as instructed, why dont any of the scans pick them up??

    thanks for your help
     
  4. armansrsa

    armansrsa Private E-2

    AAAAAgh, what has happened, windows wont load, in safe mode or normal mode...... i deleted the files as instructed and when i rebooted it just kept looping the intro screen....

    HELP HELP!!!!!!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your xp cd? Do you know how to do a repair installation? At what point is the loop - at the login screen?
     
  6. armansrsa

    armansrsa Private E-2

    No i dont. I have the cd that came with the laptop but it was a spanish version of windows so i had to put an english version of windows on it. I currently am running the XP version without a CD. Whats happening to my PC??

    I turn the computer on and up comes the toshiba logo where i would push F8 to go into safe mode, it doesnt get past this screen..... i tried in safe mode but it just loops back to the beginning

    what can i do!! i dont have a back of my data or anything :(
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How did you put an English version on it without a cd? Do you have a legit key? If so, you can borrow a cd as long as it is the same product....home/pro/etc.
     
  8. armansrsa

    armansrsa Private E-2

    the man that works at the place i bought my computer installed it from another cd that he had because the one that came with the computer is spanish and that spanish version ofcourse is legit with a key. the spanish version i have on cd is the same version of windows that is on my computer but in spanish. i dont have the cd that was used to install the english version that is on my pc. Does that matter?

    what is happening to my pc?? could you please explain to me

    thank
    Arman
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You probably have had the malware corrupt some system files.....try using the spanish version to do a repair install ....then we can switch it to English with the Regional and Language settings.
     
  10. armansrsa

    armansrsa Private E-2

    look i really apprecate the help but do you know what you are doing, even i know that you cannot change the os language, if i could have done that i would still have my spanish version installed, the reason why i dont is beause i spent one week trying to put the english version on there after i bought my pc. If malware caused this to my computer then why was it working fine yesterday? I only deleted the four files that you instructed me to
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you delete those files? Did you manually delete them or did you use Avenger to delete them?

    The act of removing malware can sometimes cause problems like this. Malware can hook into your operating system in such ways that when the malware is removed, a PC can become unbootable. Those files that Tim had you remove were problems but they are not know to cause issues like this. If no other scanners were run and no other protection software that you already had installed removed anything additional on their own (which you may not know about) then it would be unlikely that removing the listed files would make your PC unbootable. They were all part of the infection you had related to the kavo.exe file seen in SUPERAntiSpyware's log. This infection is this:

    http://www.symantec.com/security_response/writeup.jsp?docid=2007-082706-1742-99&tabid=2

    It may be necessary to do a registry repair to get your PC to boot up. The below procedure would be the normal steps. You will need a Windows XP SP2 bootable CD to do this. Can you borrow one from a friend?

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     
  12. armansrsa

    armansrsa Private E-2

    well im sure i could but could i use my own one? its the spanish version that was given to me when I bought my computer? Its a XP sp 2 but only in spanish, wil this work? i dont want to lose my data and work is all on there

    I am 99% sure that removing those 4 files caused this problem, however i understand that removing malware can mess thing up.I had a friend recommend load ubuntu osystem and put those files back in the c drive where they were, what do you think of that solution?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Using the Recovery Console procedure should work okay with this CD and it will not cause any of your own data to be lost. That procedure is just replacing possibly corrupted registry files with ones from a good restore point.

    Maybe and maybe not. It depends on whether there are orther issues at hand. If it is only due to the files being deleted which remains to be seen then that may get your PC to be bootable. Do you still have copies to the files to do this? I did ask how you deleted them but you did not reply. However, those files still would need to be remove again since they are part of your infection.
     
  14. armansrsa

    armansrsa Private E-2

    To answer your previous question, i deleted the files by putting them in the recycle bin. I was instructed to delete them, i assumed this was the way to do it because if you look above it says "only if files wont delete" use the application, i think its called avenger or something. The files should be in my recycle bin but i may have deleted them from there, fearing that they may cause problems for me, ofcourse theres no way to tell this now.

    Anyway back to the problem at hand

    When you buy a new laptop nowadays, more often than not it comes with an image cd to restore your Windows system to how it was new (not a copy of windows itself), unfortunately my laptop came with such a cd, its a toshiba installer cd, like an image of the windows system as it was when i bought my computer. This means that i cannot do anything with this CD except restore my system to the very beginning of time when all that there was was windows system and some applications,

    so the big question is, what do i do know?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can get together with a friend who has a bootable Windows XP CD and then create the disk mentioned hereUBCD4Win This is a great utility to have (your friend should create one for himself too). Using this CD you can boot up to a a Windows like environment that is running from the CD and you will have many useful utilities available for copying files between windows and much more. You can use this to run that Windows Procedure I linked to try to go back to a registry copy from an older restore point. Using this CD is a much easier way to do the steps that Microsoft mentioned since you can actually bypass steps and copy restore point registry hives directly. You could also look to see if the files are still in the Recycle folder of your hard disk.

    However have you tried using your Spanish CD to boot to the Recover Console to see if you can run the procedure in that same link.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds