1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved iexplore.exe problem

Discussion in 'Malware and Virus Removal Archive' started by bartdude59, 2010/07/02.

  1. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0
    Okay, well what should I do next? GMER gave me a BSOD and I'm reluctant to try it again.
     
  2. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download Bootkit Remover to your Desktop.

    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
    • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL+C
    • Open a Notepad and press CTRL+V
    • Post the output back here.
     

  3. to hide this advert.

  4. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0
    Note: I am currently in safe mode with networking. But here's the data:

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: aac7d8a98e39dfde27285ef395e66821

    Size Device Name MBR Status
    --------------------------------------------
    74 GB \\.\PhysicalDrive0 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>


    Press any key to quit...
     
  5. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK, your MBR is infected.

    Open Notepad
    Copy and paste following text into Notepad:
    Code:
    @ECHO OFF
    START remover.exe fix \\.\PhysicalDrive0
    EXIT
    Go FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES
    Then in the FILE NAME box type fix.bat.
    Save fix.bat to your Desktop.

    Run fix.bat by double clicking.
    You may see a black box appear; this is normal.

    When done, run remover.exe again and post its output.
     
  6. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0
    OK, here's the remover data after running fix.bat:

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: 6def5ffcbcdbdb4082f1015625e597bd

    Size Device Name MBR Status
    --------------------------------------------
    74 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


    Press any key to quit...
     
  7. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very good :)

    How is iexplore.exe issue?
     
  8. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0
    It still shows up even after I end the process.
     
  9. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Restart computer, please and post new remover.exe log.
    Check for iexplore.exe process as well.
     
  10. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0
    OK, restarted the computer. Here's the log:

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: 6def5ffcbcdbdb4082f1015625e597bd

    Size Device Name MBR Status
    --------------------------------------------
    74 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


    Press any key to quit...


    As of right now, there has been no sign of iexplore.exe.
     
  11. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Excellent!
    Let me go through our thread and see where we're at this point.
     
  12. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0

    Broni, thank you SO much for all the help. I really appreciate it.
     
  13. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Are you still getting lsass.exe error?
     
  14. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0
    I did not get it when I restarted after fix.bat. Should I still be worried about it?
     
  15. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)
    Did you read my previous reply?
     
  16. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    We're posting at the same time....LOL
     
  17. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No, no worries, if the error is gone.
    Now, couple more steps before we're done...

    1. Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.


    2. Go to Kaspersky website and perform an online antivirus scan.

    1. Disable your active antivirus program.
    2. Read through the requirements and privacy statement and click on Accept button.
    3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    4. When the downloads have finished, click on Settings.
    5. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:

    • Spyware, Adware, Dialers, and other potentially dangerous programs
      [*] Archives
      [*] Mail databases
    6. Click on My Computer under Scan.
    7. Once the scan is complete, it will display the results. Click on View Scan Report.
    8. You will see a list of infected items there. Click on Save Report As....
    9. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
     
  18. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0
    OK, I have downloaded TFC. I have to go out with my dad for a bit so I'll run it after I get back. Once again, thank you SOO much for the help!

    Edit: Oh and I forgot. There was a box that popped up that reads:

    System Settings Change
    Windows has finished installing new devices. The software that supports device requires that you restart your computer. You must restart your computer before the new settings will take effect.

    Do you want to restart your computer now?
     
    Last edited: 2010/07/04
  19. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Not a problem :)
    I believe, the worst is behind us :)
     
  20. 2010/07/04
    bartdude59

    bartdude59 Inactive Thread Starter

    Joined:
    2010/07/02
    Messages:
    27
    Likes Received:
    0
    On the Kaspersky Online Scanner, it gave me this message

    Kaspersky Online Scanner 7.0 download and operation require Java framework version 1.5 or later.
     
  21. 2010/07/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Fine...

    Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Push Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.