1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Two iexplorer.exe running in task mgr. Trojan?

Discussion in 'Malware and Virus Removal Archive' started by Tebow, 2010/11/05.

  1. 2010/11/07
    Tebow

    Tebow Inactive Thread Starter

    Joined:
    2010/11/05
    Messages:
    14
    Likes Received:
    0
     
  2. 2010/11/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OTL Cleanup will remove most of them, including itself.
    Whatever is left, delete manually.
     

  3. to hide this advert.

  4. 2010/11/07
    Tebow

    Tebow Inactive Thread Starter

    Joined:
    2010/11/05
    Messages:
    14
    Likes Received:
    0
    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 66016 bytes
    ->Temporary Internet Files folder emptied: 33172 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Stover's
    ->Temp folder emptied: 1394565 bytes
    ->Temporary Internet Files folder emptied: 3903051 bytes
    ->Java cache emptied: 1848844 bytes
    ->Flash cache emptied: 902 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 1786 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 393275 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 507360 bytes

    Total Files Cleaned = 8.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService

    User: NetworkService

    User: Stover's
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.17.3 log created on 11072010_174551

    Files\Folders moved on Reboot...
    File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

    Registry entries deleted on Reboot...

    This is the file from step 1. You have been a great help, broni, I really appreciate you. I feel like I'm learning quite a bit throughout this process. Working on the rest...
     
  5. 2010/11/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Cool :)
    Let me know...
     
  6. 2010/11/07
    Tebow

    Tebow Inactive Thread Starter

    Joined:
    2010/11/05
    Messages:
    14
    Likes Received:
    0
    After downloading Secunia - 3 things that needed updated were found. Two Adobe programs and one macromedia flash (or something like that). I updated those things and the following appeared.

    Note: You have updated all of the programs installed on your PC that exposed it to security threats and which were easy to patch. Normally, these programs are also the ones exposing your PC to the greatest security risks. However, you should be aware that 6 other program(s) were also found on your PC requiring attention as well. Unfortunately, these programs are likely more difficult to patch. If you feel comfortable with uninstalling software and deleting files on your PC, then you may enjoy the "Advanced" interface (see top right) showing more in depth details about the programs found on your PC. If you are not comfortable doing this, we recommend that you seek technical assistance in updating the rest of the applications detected.
     
  7. 2010/11/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It's not always easy to make Secunia 100% happy.
    Do, what you can and you should be good to go.
    We already checked and patched the most important programs.

    How is computer doing?
     
  8. 2010/11/07
    Tebow

    Tebow Inactive Thread Starter

    Joined:
    2010/11/05
    Messages:
    14
    Likes Received:
    0
    Comp seems to be doing better. I guess I should try to get some memory so that it'll be a little faster, but it is doing well.

    Thank you so much for your help! :)

    By the way, I'm not sure if I deleted everything that I needed to. Should I leave Security check on my desktop, or delete?
     
  9. 2010/11/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You can delete it.
    None of those programs install, so they can be just deleted.

    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.