Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on October 17, 2014, 04:26:28 PM

Title: Virus that keeps coming back - iexplorer.exe running in the background
Post by: REDACTED on October 17, 2014, 04:26:28 PM
Hello,

I have a computer that about a month ago started to be really slow and strange things were occurring (music and voices heard, strange webpages flashing, freezing, fan running constantly).  MBAM was run and AVG and both found items and "fixed" the issue.  The computer was fine for a day but then some of the same symptoms returned and the computer was VERY slow.

I have found that iexplorer.exe is a running process in the Task Manager even though I have not opened IE.  I can kill the process but it keeps opening back up on its own in the Task Manager.  When iexplorer.exe is open the size in memory of this shoot up and the CPU shoots up as well.  I have found that if I turn off the wireless and am not connected to a network that iexplorer.exe does not show back up in the processes.

I have attached my MBAM report from 2 days ago, a jpeg of the AVG items found, and the MBAM report from today.  Whatever it is it seems like it "reinstalls" itself and cause the computer to be unusable because it is so slow.  I appreciate any suggestions you are able to offer.  Thanks in advance!
Title: Re: Virus that keeps coming back - iexplorer.exe running in the background
Post by: Eddy on October 17, 2014, 05:08:54 PM
https://forum.avast.com/index.php?topic=53253.0
Title: Re: Virus that keeps coming back - iexplorer.exe running in the background
Post by: essexboy on October 17, 2014, 05:13:31 PM
Initially run these two programmes please

Download the latest version of TDSSKiller from here (http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe) and save it to your Desktop.
 
 
(https://dl.dropbox.com/u/73555776/tdss%20report.JPG)
 
Please attach its contents on your next reply.

THEN

Please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
Title: Re: Virus that keeps coming back - iexplorer.exe running in the background
Post by: REDACTED on October 17, 2014, 07:26:16 PM
Attached are the logs from the Farbar Recovery Scan Tool.

I did run aswMBR.exe but I forgot to move the log to my jumpdrive before Avast free! antivirus software picked something up and asked for me to restart and run a boot scan.  That is running now and I have chosen to have it fix anything it finds.

I will upload the log for aswMBR.exe once I am able to access the computer again after the scan.
Title: Re: Virus that keeps coming back - iexplorer.exe running in the background
Post by: REDACTED on October 17, 2014, 09:05:11 PM
Now attached is the TDDS Report and the aswMBR log.

Please let me know what further action to take.
Title: Re: Virus that keeps coming back - iexplorer.exe running in the background
Post by: essexboy on October 17, 2014, 10:50:13 PM
Could you let me know of any problems after this run please

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
Startup: C:\Users\Joe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xwizard.lnk
ShortcutTarget: xwizard.lnk -> C:\Users\Joe\AppData\Roaming\Microsoft\Windows\IEUpdate\xwizard.exe (No File) 
2014-10-16 22:44 - 2014-10-16 22:49 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-10-16 22:26 - 2014-10-16 22:26 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Joe\Downloads\4272.tmp
Task: {084C9654-7EB5-4902-89F3-EFB924675CC1} - \Security Center Update - 1343972925 No Task File <==== ATTENTION
Task: {F2668891-E13D-4024-BD3B-CD0C54FAB2B3} - \Security Center Update - 3791862601 No Task File <==== ATTENTION
Task: {F9BBB582-A0DF-47FB-A221-89F63460C93D} - \Security Center Update - 3490729426 No Task File <==== ATTENTION
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) by Xplode onto your desktop.
Title: Re: Virus that keeps coming back - iexplorer.exe running in the background
Post by: REDACTED on October 18, 2014, 04:17:21 AM
The last 2 logs you have requested are attached.  I left the computer on and connected to the internet for a few hours and no virus pop-ups showed up.  Everything appears to be running better.  Still a bit slow but better than it was.

Should I take any further action or should I use it for a few days and see how it is?
Title: Re: Virus that keeps coming back - iexplorer.exe running in the background
Post by: essexboy on October 18, 2014, 11:51:24 AM
As we removed 1.6Gb of temp files could you now defragment the drive and see if that improves the speed