Internet Explore not working

Discussion in 'Malware Help (A Specialist Will Reply)' started by C Denise, Sep 8, 2013.

  1. C Denise

    C Denise Private E-2

    Hi, I am getting a message that says that a program has caused IE to stop working. It then goes to a window trying to assess the problem but nothing ever opens up, just keeps on white screen and trying.
    My son had just installed Total War Rome II and downloaded "Steam" as part of the required process. in trying to add the Greek Cultures Pack which he got as a bonus on his receipt from Game Stop, IE stopped working and we had to use Google Chrome to complete. His game has a black screen only when started but you can hear the sound and there is a working cursor on the black screen.
    He has apparently gone to sights that I've said not to thinking I'd not know and, I'm sure, thus this problem. I run all the programs for Read and Run Me First and all logs are attached. Can you help me? Please send any e-mails to (snip) as I cannot get to my MSN Hotmail account.
    Thank You, C Denise
     
    Last edited by a moderator: Sep 8, 2013
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs did not attach. Also no need to include your email address, all advices are given publicly via the forums. ;)
     
  3. C Denise

    C Denise Private E-2

    Sorry about that, let me try again.
    C Denise
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The version of MGTools you used is WAY out of date!!


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [V2][SUSP PATH] Funmoods : C:\Users\Denise\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE - /Check [x] -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Re run Hitman and have it delete Potential Unwanted Programs.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
    • O18 - Protocol: linkscanner - (no CLSID) - (no file)
    • O20 - AppInit_DLLs: c:\progra~3\browse~1\25976~1.107\{c16c1~1\mngr.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix exit HJT.



    Delete these if they show:

    • C:\Program Files (x86)\Common Files\Spigot
    • c:\progra~3\browse~1
    • C:\Users\Denise\AppData\Roaming\Funmoods


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.


    Run the new MGTools.exe and attach the new MGlogs.zip
     
  5. C Denise

    C Denise Private E-2

    OK. I did everything you said to do. I had a couple of problems. Hitman Pro ran the scan but would not let me delete anything unless I purchased it. I have saved and attached the log anyway. Having trouble with my mouse not wanting to work like it should when you click on something. IE is still not working. I am worried.
    C Denise
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you miss the last part of my instructions about MGTools?
     
  7. C Denise

    C Denise Private E-2

    No, I didn't forget. I'm having all sorts of hassles. Before I wrote to you, I called the toll free number given on my help and support. I spoke to a technician who came into my computer and was showing me all these things going on. Said I had 41,000 things doing something and there should only have been like 200. Said a whole bunch of files are corrupt and wanted me to pay a fee to clear it all up for me. I would rather do this myself and you all are always so wonderful as I've come to you with things before.
    I've never had all this stuff not wanting to cooperate. Hopefully, I've gotten the file to attach and it's the correct one.
    Sorry,
    C Denise
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sounds like a crook to me.

    Did you delete all the PUP's with Hitman? To be sure, when you rescan, does it find any Potential Unwanted Programs?

    OK, with regards to what you posted at the very start, how is the computer running now? :confused
     
  9. C Denise

    C Denise Private E-2

    Well it was thru Microsoft Help and Support so I don't know and I would rather do this with You guys.
    Hitman would NOT let me delete anything because it wanted me to purchase the program. I sent you the log anyway even tho' I could not delete those things on it.
    IE is still not working at all.
    When launched the address bar says: http://my.msn.com/ as it should but it just keeps running and nothing but a white screen and a box shows up sayin:
    "Internet Explorer has stopped working. A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available." So there's a "close" button you click and another box comes up that says "Windows is checking for a solution" then it goes back to the "Internet Explorer has stopped working" box again.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahhh, pardon me, I misunderstood.

    Hopefully it will be after this.



    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
    C:\ProgramData\Babylon
    C:\Users\Denise\AppData\Roaming\Funmoods
    
    :reg
    [-HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}]
    [-HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}]
    [-HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh]
    [-HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj]
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}]
    [-HKLM\SOFTWARE\Wow6432Node\DataMngr]
    [-HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh]
    [-HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}]
    [-HKU\S-1-5-21-699811111-2446923022-3757014278-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B}]
    [-HKU\S-1-5-21-699811111-2446923022-3757014278-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKU\S-1-5-21-699811111-2446923022-3757014278-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    [-HKU\S-1-5-21-699811111-2446923022-3757014278-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Now re run Hitman again and attach the log. I want to see if anything remains.
     
  11. C Denise

    C Denise Private E-2

    I hope I did this correctly.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
    • Reboot the machine.
    • Re run Hitman again and attach log.
     
  13. C Denise

    C Denise Private E-2

    Here's the HitMan log
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am seeking some advice. Hang in there. :)
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. Can you disable AVG and IOBIT Malware Fighter please and re run my reg patch in post # 12 again.
     
  16. C Denise

    C Denise Private E-2

    I did what you said and the fixME.reg said it was successful. I reboored my machine.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, when you re run Hitman now, do they reappear? Does it still detect PUP's?
     
  18. C Denise

    C Denise Private E-2

    Re-Ran HitMan. Yes it detected PUPs. Gave me the option this time for a free product activation form30 days to delete what it found. I took it, hopefully deleted and re-booted. Log is attached.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm interesting. Rescan again now and attach new log.
     
  20. C Denise

    C Denise Private E-2

    Check. New log attached.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. :) Do any other issues remain?
     
  22. C Denise

    C Denise Private E-2

    Yes. My Internet Explorer is still doing what it was in the beginning. Nothing has changed.
    My mouse is very erratic, having to move it around on an item several times and click before it finally does.
    I need to know if I'm supposed to enable my UAC again and what do I do with all of the programs I have on my desktop.
    I also need to know, besides my AVG (paid), Ccleaner, and Advanced System Care 6, what other programs should I have as firewall or protection?
    What should I do about my son's game? We have sound and no picture.
    Also, is Steam safe to use as it was something the game itself had us register with?
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then because I have done all I can in the way of removing junk, I am going to have to suggest that you post about this in the software forum.

    Again, not topic for the malware forum.

    We're coming to that now in the final steps. :)

    Vista upwards, I suggest using the windows own firewall, however if your version of avg includes a firewall, you may as well utilise that.

    I would advise you to keep hold of SUPERantispyware or Malware Bytes to run scans with on a reg basis.

    You can ask about this in the software forum too.

    Yes Steam is safe.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds