Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Iexplore.exe... about to wipe entire system
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Iexplore.exe... about to wipe entire system
1. i use firefox. uninstalled internet exploder through add/remove <though i'm sure it's still there.>
2. iexplore.exe appears in my task manager on its own, preceded by several <clicks> as though i'm browsing the web, no visual, though sometimes audio of an advert. 3. tried avg, mccafee, trojanhunter,spybotblaster, and addaware...to no avail. 4. Can not enter safe mode through windows, starts safemode text cascade, then warmboots back to initial boot sequence... searched multiple forums and found several posts in regards to this malware/spyware/megapain and nothing has yet to work, anyone willing to give it a wack, it would be much appreciated, thank you in advance. Ferret |
|
#2
|
|||
|
|||
|
log files
Apparently in my haste to alleviate my annoyance, i missed the preliminary 8 step program >.<
here r the logs Ferret |
|
|
|
#3
|
||||
|
||||
|
IE8 provides additional Windows security and is part of Windows core files. If you have removed it, you have crippled Windows security... It is partially because you use Firefox without some security add-ons and cookie handlers that you are in this mess. Please fix or delete these entries in the hijackthis log, and we will continue from there:
"C:\Program Files\Search Settings\SearchSettings.exe" "R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll" "F3 - REG:win.ini: load=C:\WINDOWS\system\svchost.exe" "O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)" "O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll" "O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll" "O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe" "O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe" "O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll" "O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll" You have been infected by some serious virus/malware that were caught or detected, but there is no guarantee that they are totally gone. So we may require more serious cleaning help Last edited by Tmagic650; 11-21-2009 at 01:47 AM.. |
|
#4
|
||||
|
||||
|
DealioAu.exe, "Dealio Toolbar is a free shopping comparison toolbar that allows users to search for a wide range of consumer products" . this should be an optional removal.
Reference: http://blog.auctiontips.com/ebay_community/ The Search Setting is 'foistware' installed without the users knowledge or permission. Viewpoint is also considered 'foistware'. I would rather have you run Combofix for this and some of the other entries, including F3 - REG:win.ini: load=C:\WINDOWS\system\svchost.exe You also have restrictions placed as follows: O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present This can be a result of the malware. Please disable TeaTimer temporarily:
It would be safer to have Combofix fix it: Please download ComboFix HERE:
Notes:
Attach the Combofix report to your next reply. Rescan with HijackThis and paste that log into the next reply. Tmagic, I think this is a safer way to go. |
|
#5
|
||||
|
||||
|
DealioAu.exe, "Dealio Toolbar is a free shopping comparison toolbar that allows users to search for a wide range of consumer products"...
and it is a great spyware and malware magnet. Just what keeps Bobbye in business ![]() "Tmagic, I think this is a safer way to go"... No argument here |
|
#6
|
|||
|
|||
|
ok
alrighty then ~.<
b4 tmagic reposted i followed through...i ran combofix, log attached, then ran hijack and cleaned out the rest tmagic suggested....log attached...also attached was an error message that occurred when i ran HJT..don't know relevevance..and while running combofix..i explore opened itself and an advert popped into my headset... >.> restarted comp and hung on shutdown....warm booted back and here i am...i await your wisdom ![]() Ferret |
|
#7
|
||||
|
||||
|
"i explore opened itself and an advert popped into my headset... >.>
An audio popup? How is the system running now? Your Hijackthis log looks much better |
|
#8
|
|||
|
|||
|
reply
after the reboot...iexplorer almost immediatly opened itself up...this is what alerted me to a problem..and it still exists...
Ferret |
|
#9
|
|||
|
|||
|
some steps
i've even gone into the registry and did a search for "iexplore.exe" and nothing of note....my deletion or add/remove of IE was in an attempt to eliminate the problem <ergo no ie..no explorer to open> yet it still does...there is no apparent tie to my internet connection as if i unplug my modem it will still self start...there hasn't been a scan/deletion yet that has had an effect on it, and even more, it will even pop open while i'm running a diagnostic/scanning tool...i'm at a loss..
Ferret |
|
|
|
#10
|
||||
|
||||
|
Reinstall IE8 and apply all the waiting updates using Windows Update with the Custom option
|
|
#11
|
|||
|
|||
|
ok..thanx for your patience
i tried to do updates...over 50% were failing, so i cancelled..and on reboot windows froze. went to windows cd and 'repaired' windows. ran combofix and HJT and logs are attached. also iexplorer has yet to rear it's ugly head. please scan logs and i await further assistance. in the meantime, i might try to do the windows updates again, but anything else i'll wait for u to pervue the logs. thanx again
Ferret |
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Entire system lagging sporadically while playing left 4 dead | PC Gaming and Consoles | 1 | 10-14-2009 09:44 PM | |
| CiD popups and iexplore.exe using 95% system mem without using IE | Virus and Malware Removal | 17 | 06-02-2009 02:08 PM | |
| How do you hide the Entire system tray? | Software and Utilities in General | 10 | 06-29-2008 11:11 AM | |
| How to wipe a sata hard drive without an ooerating system | General Hardware | 2 | 06-28-2005 03:16 AM | |
| Geforce 6600 gt and entire system | Audio and Video | 9 | 04-19-2005 01:11 AM | |
All times are GMT -4. The time now is 11:37 PM.






