lnternet Explorer process will not end

Discussion in 'Malware Help (A Specialist Will Reply)' started by kruelo14, Dec 16, 2005.

  1. kruelo14

    kruelo14 Private E-2

    Hey guys. I have done everything I know to do tomy computer and nothing works. I have scanned with everything, I have done everything in the Read First post and everything. I have scanned my cmp with AdAware, Spybot, Mcafee Virus Scan, I have Mcafee's firewall and everything. I have scanned with Ewido and nothing works. Everytime I open up an IEXPLORER, it doesn't shut down the process. If I open up 20 IEXPLORERS over a days time, then I hit CTL+ALT+DEL, the processes are still running and I have like 80 processes running thus slowing down my computer tremendously. ANy help is greatly appreciated and anything you need just ask. Thanks.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  3. kruelo14

    kruelo14 Private E-2

    Re: DPn't know if I need help or not.

    Ok here it is, thanks again in advance.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: DPn't know if I need help or not.

    Please see the below thread on how to install and run Spy Sweeper.

    Running Spy Sweeper...
     
  5. kruelo14

    kruelo14 Private E-2

    Re: DPn't know if I need help or not.

    Alrighty here we go. I scanned with spysweeper and it fouind 4 things so here are both my logs.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  7. kruelo14

    kruelo14 Private E-2

    Re: DPn't know if I need help or not.

    Ok I scanned with Ewido but I did it Safe mode but had to Cancel before it was done. It was almost done and it found 4 things which it cleaned. When I ran i in Normal mode it found nothing. The log is attached below. Thanks again.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: DPn't know if I need help or not.

    Now please attach a HJT log from normal mode.
     
  9. kruelo14

    kruelo14 Private E-2

    Re: DPn't know if I need help or not.

    Fresh HJT log.
     

    Attached Files:

  10. kruelo14

    kruelo14 Private E-2

    Re: l

    bump, still need help with this.:)
     
  11. kruelo14

    kruelo14 Private E-2

    Re: Don

    bump, still need help with this.:)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Patience is a virtue! Please wait for BJ to get back in! We are not here 24 hours a day and we have to make time in our schedules to do this. Also note that bumping your thread will only make it take longer to get an answer. Think about it like being on hold waiting for Tech Support. Your call will be answered in the order it is received. When you bump, it is like hanging up and starting over again because you loose your position in the queue. Oldest, unanswered messages are attended to first. Bumping makes your message newer. If we are real busy, that could mean it takes hours more before you get an answer.

    You may be looking at needing to repair IE as covered in the below link. But I would wait for BJ to check in and see what he thinks. I have not looked at your whole thread.

    http://support.microsoft.com/default.aspx?kbid=318378

    Note: I changed the title of your thread to something more useful and also something easier to click on.
     
    Last edited: Dec 19, 2005
  13. kruelo14

    kruelo14 Private E-2

    Lol i'm sorry I forgot I posted that HJT log today and thought I posted it yesterday. And I couldn't find out how to change my topic, didn't even know how I changed in the first place. I will wait for BJ and thank you chaselang.
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Ewido

    Spy Sweeper

    STOPzilla!


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yah oo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yaho o.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yaho o.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yaho o.com

    O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll

    O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\STOPzilla.exe /autostart

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    After you complete the above, reboot and let me know how things are running and if your still having IE problems.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ,

    Those O18 lines should not be fixed. That is a false detection by HJT. Always ignore that particular O18 line. I have verified on many system using MSN Messenger that the msgrapp.dll file does exist. HJT is wrong!

    I also wonder why Stopzilla would be removed. Do you suspect it as the cause of the IE problems? Doesn't the user want it? If not, why isn't Add/Remove programs being used.
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Didnt know that about the O18 entries, it could be a possible cause so I decided to remove it and see if problem remains, it can be reinstalled.

    It was requested for Add/Remove, first step requested.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! And I missed the Add/Remove! Sorry!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds