Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
CiD popups and iexplore.exe using 95% system mem without using IE
![]() |
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
CiD popups and iexplore.exe using 95% system mem without using IE
This computer has been reformatted.
For new problem, Please scroll down to 5th post Last edited by yarrrheal; 05-10-2008 at 03:23 PM. |
|
#2
|
||||
|
||||
|
Hi yarrrheal and welcome to TechSpot
You will need to follow the following recommendations first Viruses/Spyware/Malware, preliminary removal instructions http://www.techspot.com/vb/topic58138.html With files like B.exe in you Windows folder, you are most certainly infected ! |
|
|
|
#3
|
|||
|
|||
|
I have already followed all of those instructions (over the past 3 days (has done nothing else)) These logs are from after all the steps in that topic.
|
|
#4
|
||||
|
||||
|
Someone will help you shortly
This time may vary, TechSpot members are helping others voluntarily so hang in there. Also I'll check back later. If no response. |
|
#5
|
|||
|
|||
|
Now for the other PC
So now that my laptop has been cleaned up, now my main pc is having the same issues.
Followed your directions in the preliminary removal guide and have the logs posted. Thank you for your time. also, Panda antiroot found 0 issues Last edited by yarrrheal; 05-10-2008 at 02:55 PM. |
|
#6
|
||||
|
||||
|
Need to tighten up security, but first - do you still use Norton AV?
Also I need to see Generate Uninstall List
|
|
#7
|
|||
|
|||
|
Norton AV is still used on this comp due to me not being able to convince my parents otherwise.
Uninstall list attached |
|
#8
|
||||
|
||||
Uninstall these from control panel -> Add/remove programs J2SE Runtime Environment 5.0 Update 7 Java 2 Runtime Environment, SE v1.4.2 Java(TM) 6 Update 2 Java(TM) 6 Update 3 Java(TM) SE Runtime Environment 6 Update 1 Messenger Plus! Live & Sponsor (CiD) After uninstalling messenger plus sponsor' 1)Setup" is now displayed. Click on the Uninstall button. Note: options displayed on the first screen are not related to the sponsor program. 2)The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen, you have to type the code that is displayed. Once you enter the code, press Uninstall. 3)If you entered the code properly, the program will ask you to confirm that you want to uninstall. You must answer "Yes" to this question, else, you won't have another chance of uninstalling. 4)Reboot your computer 5)Run another scan with Hijackthis and attach a new log |
|
#9
|
|||
|
|||
|
Quote:
New HJT log attached. |
|
|
|
#10
|
||||
|
||||
|
That should help, but you still have infections on there
Malwarebytes' Anti-Malware
Remove Viewpoint Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware. I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components :
|
|
#11
|
|||
|
|||
|
Followed instructions and have the next log posted.
|
|
#12
|
||||
|
||||
|
Run Kaspersky Online AV Scanner
Order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Also attach a fresh Hijackthis afterwards. |
|
#13
|
|||
|
|||
|
Ran the scanner, and wow it found a lot.
Scan log and fresh hjt log attached. |
|
#14
|
||||
|
||||
|
Upload a File to Virustotal
Please visit Virustotal found HERE
-------------------------------------------------------------------------------------- Launch Spybot -> click on the Recovery Icon -> Highlight everything and select the red X that says purge. ------------------------------------------------------------------------------------------------ Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Application Data\great coal love default\Platform bows.exe O4 - HKCU\..\Run: [CakeTest] C:\Document~1\Owner\APPLIC~1\GRIMEQ~1\Store Vc.exe Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present): C:\Documents and Settings\All Users\Application Data\great coal love default C:\Documents and Settings\Owner\Application Data\GRIMEQ~1 <- check this one, it will have a longer name ----------------------------------------------- FileASSASSIN
------------------------------------------------ Uninstall Combofix * Click START then RUN * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter. * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ----------------------------------------------------------------------- Cleanup using OTMoveit2 by OldTimer Now we can clear out the rest of the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. 1. Double click OTMoveIt2.exe to launch it. If using Vista Right-Click OTMoveIt and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) * When finished exit out of OTMoveIt2 ----------------------------------------------------- clear system restore points
--------------------------------------------------------------------- After all of this run another Kaspersky and attach the log along with the result from VirusTotal |
|
#15
|
|||
|
|||
|
I really appreciate your help for all of this.
Virustotal said the file was completely clean and Kaspersky didn't find anything. |
|
#16
|
||||
|
||||
|
Good deal. You now have a nice clean restore point set also.
Let me know if anything else comes up. Regards, BD |
![]() |
«
Previous Thread
|
Next Thread
»
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| iexplore.exe still running and popups | layrubr | Security and the Web | 9 | 11-08-2007 02:33 AM |
| iexplore.exe using 98% of cpu | rocks911 | Security and the Web | 1 | 02-01-2007 06:58 PM |
| Random IE Popups, Getting a TON of popups all the time | taudelt39 | Windows OS | 1 | 02-02-2005 03:04 AM |
| iexplore | enigma | Misc. Software & Utilities | 1 | 12-04-2003 07:16 AM |
| iexplore | cute12ka4 | Misc. Software & Utilities | 3 | 05-03-2003 01:15 AM |
All times are GMT -4. The time now is 11:10 PM.





