Is an Explorer.EXE a virus?And ... possible MBR infection?!

Discussion in 'Malware Help (A Specialist Will Reply)' started by stew, Nov 16, 2009.

  1. stew

    stew Private E-2

    Hello !

    This is my first post in the forum.I am very glad that there are such places in an Internet like that.
    So,maybe I am a man in trouble or not.I am not sure therefore I took the decision to write here.
    I had 2 IEXPLORER.EXE (capital letters) process running in Task Manager a few days ago.Thanks to a-squared and AVG 8 free I managed to remove some malware.Now iexplorer.exe is normal.However I saw that my explorer.exe is changed to Explorer.EXE.Sometimes second process Explorer.EXE appears in Task Manager.One of them I can close without crash of the system.Also I saw that there is "explorer.exe" on multiple locations ,not only in WINDOWS folder (see MGlogs.zip).Sometimes after start of the system I saw it slow down and HDD works hard without I do anything.

    So,is there any malware as concern Exploerer.EXE in my computer?:confused

    I did "READ & RUN first" procedure and I attached the files that required.I saw in ComboFix report that it is possible MBR (Master Boot Record) infection?!

    So,do I need really to fix it as combofix recommends via Recovery Console and command "fixmbr"?Because I boot from HDD without any problems for now.Is it possible something to get wrong if I try to fix it or if I leave it behind???:confused
    If I need to fix it please specify exactly the procedure!Is it possible to lose any data or settings???:confused

    Also I would like to add that RootRepeal crashes everytime I try to do scan shortly it started.I looked for ways to stop AVG but only its Resident Shield I managed to stop

    I will be very glad if someone takes the attention to my situation and can help to resolve it.

    Thanks very much in advance!:wave
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to double your RAM:
    Общо физическа памет 512,00 МБ
    Свободна физическа памет 172,45 МБ

    Yes, you need to let explorer.exe run!! You already know that if you stop it, your system will crash.

    What is this:
    C:\!!!!!!!!!!!!!!

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\cgminivw.ini

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. stew

    stew Private E-2

    Hi Tim,

    Thank you very much for the reply!I accept your advices.

    Yes,I know that I do need to let explorer.exe running,but as I said before by me this process is Explorer.EXE not explorer.exe.Also I have another processes with capital letters :CRSS.EXE,SMSS.EXE,RUNDLL32.EXE...I don't know if this is normal?!Sometimes (rarely) 2nd process Explrer.EXE is appeared in Task Manager.

    The procedure you recommended me does not change that above.

    The folder C:\!!!!!!!!!! is created by me and I store there the files that I got to do "READ & RUN ME FIRST" procedure here in forum.

    Yes, I cleaned the desktop out as much as I can afford it.

    Yes,I received a success message about adding fixME.reg

    However,one major problem described in my previous post is still not concerned:

    "I saw in ComboFix report that it is possible MBR (Master Boot Record) infection?!
    So,do I need really to fix it as combofix recommends via Recovery Console and command "fixmbr"?Because I boot from HDD without any problems for now.Is it possible something to get wrong if I try to fix it or if I leave it behind???
    If I need to fix it please specify exactly the procedure!Is it possible to lose any data or settings???"


    I repeat that I boot my PC without any problem for now.


    And one additional question,please:as a preventive measure in the future,is it a good idea to use that host file:
    http://www.mvps.org/winhelp2002/hosts.htm

    Thanks again!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's have you do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Folder::
    C:\Documents and Settings\pc_\Desktop\Virus Removal Tool
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^pc_^Start Menu^Programs^Startup^is-17RIG.lnk]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^pc_^Start Menu^Programs^Startup^is-EPQHP.lnk]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Yes you do have a Master Boot Record (MBR) infection that needs to be removed which we will get to below. You will need to boot to the Recovery Console that you have installed (perhaps when you installed ComboFix) to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Now re-run ComboFix and also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  5. stew

    stew Private E-2

    Hi Tim,

    It doesn't work.I follow all of your instructions but the procedure failed.
    After I droped the .txt file and combofix starts to operate my pc restarts automatically 2 times.First time a massage says that there is rootkit activity and combofix needs to restart the computer,after reboot the second message tells me that cd-emulations drivers are running and combofix will temporaly disable them and immediately pc reboots.Finally the combofix window appears and freezes at "combofix is preparing to run".I waited it nearly 3 hours but it does not run!I repeat the procedure 2 times without success.

    I did not complete the Recovery Console's procedure because the first step failed.Even more,in microsoft support's link that you provide me it says that:"Microsoft recommends that you use the Recovery Console only after Safe mode and other startup options do not work.".As I said my pc still boots successfuly in Normal mode and Safe mode.Therefore I still wonder whether is there REALLY any rootkit and master boot record infection like combofix points or it does wrong?!?!:confused:confused:confused

    As concern the CFscript.txt , "virus removal tool" is "Kaspersky virus removal " and I can manually uninstall it whenever I want.There is no problem,when I need it I will reinstall it.The registry keys that you point combofix script to kill them I can find them via "regedit" in "Run...".So, may I delete them manually???What are they actually?

    And also you said nothing about :"And one additional question,please:as a preventive measure in the future,is it a good idea to use that host file:
    http://www.mvps.org/winhelp2002/hosts.htm"
    in my previous post.

    Meanwhile I followed your advice about RAM in your first post and I bought 1GB RAM Kingston and now I have 1,5 GB installed.

    Now what....???:tired:confused

    Thanks again!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can only check the rootkit problem if you would at least get me a new MGLogs.zip.

    You can do this for the registry fix:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    It is very possible that Combo is wrong. But we will recheck.

    As to your link to the host files, what are you asking? They are giving examples for you and if you want to reset your host file you can use this:
    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
     
  7. stew

    stew Private E-2

    Hi TimW,

    O'k,I implemented the registry procedure and received a success message.Also I provide you the required MGLogs.zip that I grabbed after the completion of registry editing procedure.

    Do you see something suspicious?Is there a root kit problem?


    As to "17RIG.lnk" and "EPQHP.lnk",what are they actually??


    I would like let you know how look my Task Manager (look at the attached screenshot IMAGE134.JPG) at the moment of writing this.As you can see most of the processes (including explorer.exe) are with capital letters.I noticed the change 5-6 days ago.Even explorer.exe that was Explorer.EXE now it is "EXPLORER.EXE" and also double.I can switch off the one of them.I don't know whether this is normal and what is the cause for this.But as I said the pc boots normal and fast without any problem,even now with 1,5 GB RAM it operates much better than with 512KB.
    I don't know whether to be worrisome or not?!Hope you help all to be clear!
    Now I am trying to do my emergency disk CD (Reatogo,BartPE) in case if I am in real trouble in the future.

    Waiting for your response...
    Thanks again!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. However, you need to clean out your temp files as they are a good place for malware to hide.

    These should be deleted:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\temp\236636f1-6d5c-4647-8978-7a34f93c6bea.tmp
    C:\Documents and Settings\pc_\Local Settings\temp\mus19.tmp
    C:\Documents and Settings\pc_\Local Settings\temp\20b6e99a265a4dc3aa92b5f16884b13f.tmp
    C:\Documents and Settings\pc_\Local Settings\temp\213c90e16e6040268f28e31bb2f5f341.tmp
    C:\Documents and Settings\pc_\Local Settings\temp\5ba4151a8c714739b5fcb416359a6fc2.tmp
    C:\Documents and Settings\pc_\Local Settings\temp\TempREA.cmd
    C:\Documents and Settings\pc_\Local Settings\temp\jkos-pc_
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach the combo log and we should be ready to give you the final cleanup.
     
  9. stew

    stew Private E-2

    O'k I did that you recommended.

    I have to let you know that I had to launch 2 times Combofix.exe because the first time it freezed at "preparing log file" ,but I am sure that it deleted the files pointed on CFscript.txt because I observed the combofix process.So the attached report (log) is grabbed after second launch of Combofix.exe

    As you can see combofix shows possible MBR infection again.
    **************************************************************************

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A2B6A10]<<
    kernel: MBR read successfully
    detected MBR rootkit hooks:
    \Driver\Disk -> CLASSPNP.SYS @ 0xf763bfc3
    \Driver\ACPI -> ACPI.sys @ 0xf758ccb8
    \Driver\atapi -> 0x8a2b6a10
    IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0084
    ParseProcedure -> ntoskrnl.exe @ 0x8056f07e
    \Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0084
    ParseProcedure -> ntoskrnl.exe @ 0x8056f07e
    NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7869bc3
    PacketIndicateHandler -> NDIS.sys @ 0xf7875b21
    SendHandler -> NDIS.sys @ 0xf7869d33
    Warning: possible MBR rootkit infection !
    user & kernel MBR OK

    **************************************************************************


    But I do not believe that.

    Also during combofix process the following message has been displayed:

    "PEV.EXE has encountered aproblem and need to close"

    What does it mean?

    Also you can see on the second attachment the view of my Task Manager is still unchanged -most of the processes are still in capital.That is my main dilemma!

    Tim, I really need to know whether my PC is 100 % clean,because I am planning to do HDD image via Acronis True Image or something like that and if I have any big trouble in the future I will be able easy to recover my PC.

    Thank you for the support!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There was no evidence of a rootkit still existing in the MBR. Combo is throwing a false positive. PEV.exe is part of Combo, so if one of your AS or your AV program deleted it, that would be the reason for the error message.

    I think you can go ahead an image your HHD.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. stew

    stew Private E-2

    Hi TimW,

    thank you very much for all of your advices.I really apreciate them!

    I completed final steps that you pointed me.
    Only one thing remained a mystery to me:why most processes in Task Manager are in capital letters incl. EXPLORER.EXE that was Explorer.EXE?!?! I use this computer more than 3 years and they always were in small letters.I established that change last month.

    However I REALLY hope that wouldn't be any danger for me (my PC) in the future.
    Again thanks a lot,and I will recommend this forum to all my friends in trouble in the future.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I really can not explain why things have changed form lower to upper case. It could be an update for all I know. But you dont need to be concerned. Your system is clean. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds