Started with not being able to open IE

Discussion in 'Malware Help (A Specialist Will Reply)' started by aatmwilson, Sep 15, 2010.

  1. aatmwilson

    aatmwilson Private E-2

    Ok... It started out with not being able to open IE. Sigh....

    What happens when I try is it pops up, asks if I want to restore my session. Then no matter what I click it instantly closes.

    So I posted in the general "software issues" forum.
    Original thread:
    http://forums.majorgeeks.com/showthread.php?p=1535199#post1535199

    So I was told to come to the Malware forum. I went thru the read me first and did the steps, downloaded the programs and here ya go....

    When I changed start up to normal I keep getting wordperfect office 12 popups saying its installing. I click cancel and it just comes back. No matter how many times I click cancel it still comes back.

    Started with SUPERAntiSpyware... Ran the scan....It completed the scan. Asked me to reboot I said yes then a blue screen popped up and said "STOP: C000021a {Fatal System Error}" I did attach the log for this.

    Malwarebytes Anti-Malware: Try to run and I get a pop up saying "Not a valid Win 32 application" My current OS is Windows XP 32 bit (dont know if that is relevant to that)

    combofix.exe: Will not open. I get the error "Incompatible OS only works for work stations windows 2000 & XP" like I said My OS is XP 32 bit. Tried a couple more times and it went past that and said "Comodo" is active. I closed comodo down before I started the process. So I opened task manager and tried to end the process. States access denied. Could not go any further.

    RootRepeal: Log attached

    MGtools: Log attached
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Try and run ComboFix again at this point, if it fails again try renaming it to 123.com and if it will still not run in normal mode, please try safe mode.

    Now run this: Using MGtools


    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. aatmwilson

    aatmwilson Private E-2

    Ok I was able to run the programs this time. Here is what I got....
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What are you currently using from Symantec? I see a service running and Symantec KB-DocID:2003093015493306 in your add/remove progs listing. ...as well as a leftover service from adaware 2007 which we need to clean up.

    Do you deliberately have this site set as your start page?

    If not include it in our fixables below:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Delete this file if you do not know what it is:
    C:\qehjlhawlh

    Now go to VirusTotal and upload the following files for analysis, report back to me the results.

    • C:\windows\system32\A4F07C317C.sys[/B]

    Could you please get this: A4F07C317C.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    The zipped file will be found at C:\collect.zip.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    Extract avenger.exe from the Zip file and save it to your desktop
    Run avenger.exe by double-clicking on it.
    Do not change any check box options!!
    Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).


    Run ComboFix at this point by double clicking it's icon on your desktop. Run it as per the instructions in the Read and Run Me First, do not mouse click or touch the keyboard whilst it is running.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Address my question regarding symantec and also include the VirusTotal results. Also the C:\collect.zip
     
  5. aatmwilson

    aatmwilson Private E-2

    I am not aware of anything I am using from symantec... I have no clue.

    Tried to do everything.... When I ran Avenger it ran then rebooted. When it rebooted I got this message "Windows can not clean up file. You do not have appropriate permission" Which I am the admin of the computer.

    When I run Combofix it still states that Comodo Antivirus is running (I try to end process and it says acces is denied) but it continues to complete the scan.

    So now I am attaching the combofix log, MGlogs, Collect.zip and the total virus "log" I created.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just an FYI. This file is just part of DIVx. Notice that it and the KGyGaAvL.sys file for DIVx came together too.
    It is believed to be part of DIVX registration.
    Code:
    "C:\WINDOWS\system32\"
    a4f07c~1.sys  Sep 13 2010         104  "A4F07C317C.sys"
    kgygaavl.sys  Sep 13 2010        6686  "KGyGaAvL.sys"
    
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I thought so, was just checking! :)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I see this service:
    A left over from once using BlackIce protection software?

    Navigate to the below, and rename the following files to DISinclude the .vir extension, then move them back to their original location of:

    Uninstall these:
    • Viewpoint Media Player
    • Symantec KB-DocID:2003093015493306

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    WPRO_40_1340
    Ad-Aware 2007 Service
    File::
    c:\windows\system32\drivers\WPRO_40_1340.sys
    Folder::
    C:\Program Files\Lavasoft
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How're things running?
     
  9. aatmwilson

    aatmwilson Private E-2

    Yes at one time I had BlackIce....

    I could not find this to uninstall it:
    Symantec KB-DocID:2003093015493306

    And I still cant open IE.... When I open ComboFix it still says Comodo Antivirus is running... And Task Manager still wont let me close it completely.

    Is Comodo my problem?
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hard to say.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    black
    Ad-Aware 2007 Service
    Symantec Core LC
    File::
    c:\windows\system32\drivers\BlackDrv.sys
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    Folder::
    C:\Program Files\Lavasoft
    C:\Program Files\Common Files\Symantec Shared
    C:\Program Files\Viewpoint
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. aatmwilson

    aatmwilson Private E-2

    I have a question about ComboFix.... It says after it reboots the computer to not run any programs. However since its in "normal start up mode" it automatically loads several programs. Is that an issue? Or should I not worry about it for now?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No. Not an issue...
     
  13. aatmwilson

    aatmwilson Private E-2

    Alright attached logs...........Still no IE
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click the IE icon on your Desktop and select Start Without Add-ons

    Does that allow it to start?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Besides trying what was in my last message, you need to do the below.

    First I suggest that you delete the below "copy of files" that you probably made by mistake
    Code:
    "C:\Documents and Settings\Tiffany\"
    co15ab~1.pnf  Feb 16 2007        7546  "Copy (3) of oem35.PNF"
    co1d9b~1.pnf  Feb 16 2007       15690  "Copy (3) of oem33.PNF"
    co35ab~1.pnf  Feb 26 2007       15770  "Copy (4) of oem35.PNF"
    co3d9b~1.pnf  Feb 26 2007        7074  "Copy (4) of oem33.PNF"
    co6207~1.pnf  Feb 11 2007        7546  "Copy of oem26.PNF"
    co62fa~1.pnf  Feb 12 2007       14198  "Copy of oem42.PNF"
    co63c9~1.inf  Feb 26 2007        6061  "Copy of oem24.inf"
    co6607~1.pnf  Feb 11 2007        7074  "Copy of oem27.PNF"
    co66f4~1.pnf  Feb 12 2007       45400  "Copy of oem33.PNF"
    co66fa~1.pnf  Feb 12 2007       12546  "Copy of oem43.PNF"
    co67c7~1.inf  Feb 12 2007        9232  "Copy of oem35.inf"
    co6a07~1.pnf  Feb 11 2007       15770  "Copy of oem28.PNF"
    co6a09~1.pnf  Feb 26 2007       14230  "Copy of oem18.PNF"
    co6bbd~1.inf  Feb 12 2007        7080  "Copy of oem42.inf"
    co6e09~1.pnf  Feb 26 2007       12836  "Copy of oem19.PNF"
    co6ef4~1.pnf  Feb 12 2007       13698  "Copy of oem35.PNF"
    co6ef6~1.pnf  Feb 11 2007       15690  "Copy of oem25.PNF"
    co6fb7~1.inf  Dec 13 2006       29856  "Copy of oem33.inf"
    co6fbd~1.inf  Feb 16 2007        9842  "Copy of oem43.inf"
    co6fc9~1.inf  Feb 12 2007        4477  "Copy of oem27.inf"
    cof4ab~1.pnf  Feb 12 2007       15690  "Copy (2) of oem35.PNF"
    cof891~1.pnf  Feb 16 2007        7074  "Copy (2) of oem42.PNF"
    cofc91~1.pnf  Feb 16 2007       15770  "Copy (2) of oem43.PNF"
    cofc9b~1.pnf  Feb 12 2007       12524  "Copy (2) of oem33.PNF"
    cofd66~1.inf  Feb 26 2007        9842  "Copy (2) of oem35.inf"
    copy(2~1.inf  Feb 11 2007        9842  "Copy (2) of oem28.inf"
    copy(2~1.pnf  Feb 12 2007       30362  "Copy (2) of oem24.PNF"
    copy(2~2.inf  Feb 12 2007        6109  "Copy (2) of oem33.inf"
    copy(2~2.pnf  Feb 11 2007        7546  "Copy (2) of oem26.PNF"
    copy(2~3.inf  Feb 16 2007        4406  "Copy (2) of oem42.inf"
    copy(2~3.pnf  Feb 11 2007        7074  "Copy (2) of oem27.PNF"
    copy(2~4.inf  Feb 26 2007        9232  "Copy (2) of oem27.inf"
    copy(2~4.pnf  Feb 11 2007       15770  "Copy (2) of oem28.PNF"
    copy(3~1.inf  Feb 16 2007        9232  "Copy (3) of oem33.inf"
    copy(3~1.pnf  Feb 12 2007        7762  "Copy (3) of oem24.PNF"
    copy(3~2.pnf  Feb 12 2007       16010  "Copy (3) of oem26.PNF"
    copy(3~3.pnf  Feb 12 2007        7322  "Copy (3) of oem27.PNF"
    copy(3~4.pnf  Feb 12 2007       12836  "Copy (3) of oem28.PNF"
    copy(4~1.pnf  Feb 16 2007       14230  "Copy (4) of oem24.PNF"
    copy(4~2.pnf  Feb 16 2007       12836  "Copy (4) of oem26.PNF"
    copy(4~3.pnf  Feb 16 2007       12762  "Copy (4) of oem27.PNF"
    copy(4~4.pnf  Feb 16 2007       12356  "Copy (4) of oem28.PNF"
    copy(5~1.pnf  Feb 26 2007       12762  "Copy (5) of oem24.PNF"
    copy(5~2.pnf  Feb 26 2007       12356  "Copy (5) of oem26.PNF"
    copy(5~3.pnf  Feb 26 2007       15690  "Copy (5) of oem27.PNF"
    copy(5~4.pnf  Feb 26 2007        7546  "Copy (5) of oem28.PNF"
    copyof~1.inf  Feb 11 2007        6061  "Copy of oem23.inf"
    copyof~1.pnf  Feb 11 2007       14230  "Copy of oem21.PNF"
    copyof~2.inf  Feb 11 2007        9232  "Copy of oem25.inf"
    copyof~2.pnf  Feb 11 2007       12836  "Copy of oem22.PNF"
    copyof~3.inf  Feb 11 2007        9842  "Copy of oem28.inf"
    copyof~3.pnf  Feb 11 2007       12762  "Copy of oem23.PNF"
    copyof~4.inf  Feb 11 2007        6921  "Copy of oem26.inf"
    copyof~4.pnf  Feb 11 2007       12356  "Copy of oem24.PNF"
    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. aatmwilson

    aatmwilson Private E-2

    Ok... IE is still not opening. Even when I try and open it without add-ons.

    Here are the logs.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problem with IE, does not appear to be a malware problem.

    According to your logs which have a process list, IE is running. Your logs show:

    C:\Program Files\Internet Explorer\IEXPLORE.EXE


    Open Task Manager and kill all instances of iexplore.exe make sure that they all terminate and that none come back.

    Then retry running IE without Add-Ons. If this does not work, I suggest that you uninstall IE8 and then reboot. After reboot, see if your fall back to IE7 is working.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. aatmwilson

    aatmwilson Private E-2

    Ok. I have gone through all of this. And uninstalled and reinstalled IE8. It still is not working.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My point was to uninstall IE8 and see if IE7 ( or whatever you originally upgrade from ) was working before trying to reinstall IE8. ;)
     
  21. aatmwilson

    aatmwilson Private E-2

    Ok... IE7 not working.... IE8 not working....
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly what happens when you try to run it?
     
  23. aatmwilson

    aatmwilson Private E-2

    I click on it it pops open and instantly closes. I have tried running without add-ons and it doesnt work. I can open it in safe-mode fine. Dont know if that matters....
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you say IE instantly closes, does it still appear in Task Manager?

    This is not sounding like a malware problem. If you can run it in safe mode, seems like something you are running in normal boot mode (either a program or some drivers or even an addon, are the cause). First suggestion would be to uninstall Comodo and see what happens.

    If that does not help, I suggest that you use the Software Forum to debug. You can make use of MSconfig to use Diagnostic Mode and slowly enable drivers, processes, services ...etc to see if you can locate which is causing the problem.

    Also the below may or may not be of use:

    http://support.microsoft.com/kb/932540
     
    Last edited: Oct 8, 2010
  25. aatmwilson

    aatmwilson Private E-2

    Thx. I tried the software forum first. But now that we have established its not Malware maybe I can get more help over there. Thx for trying!
     
  26. aatmwilson

    aatmwilson Private E-2

    Just wanted to let you know that I uninstalled Comodo and IE works now. So my next question (hopefully you can help)

    What are the best free virus and security programs I should have? It seems like every program I have tried ends up causing some issue.... *sigh*
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Comodo is a very good program, but like many programs, you need to be a little bit of a system administrator when installing programs and in configuring them. If you block things from running that need to run then the result is what happened to you with IE. I have Comodo on many PCs and have no problems with it, but it does need to be told what to do many times when it pops up with questions. ;) You can find other programs we recommend in the link given as part of the final instructions below.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds