Author Topic: I need help with internet explorer problem. recurring error message  (Read 2515 times)

Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
I hope someone has an easy solution. I have been having trouble with Internet Explorer for a few days. When I click on a search from google my choice seems to get redirected somewhere else, not the website I wanted. In addition I get random Internet Explorer error messages (Internet Explorer has encountered a problem and needs to close blah blah blah) even though I don't even have IE open. I am currently using Chrome and it also gets redirected but no error messages. Some type of malware?

Here is a log from Hijack this:

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\RealVNC\VNC4\winvnc4.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
\Fp\geovista\GEOVISTA.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SDMSSplash] "C:\Program Files\HP_SDMS\SDMSSplash\launcher.exe" "launchdir=C:\Program Files\HP_SDMS\SDMSSplash"
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FEXeTWLLHYgf.exe] C:\Documents and Settings\All Users\Application Data\FEXeTWLLHYgf.exe
O4 - HKCU\..\Run: [18iEe6Rvc2dGi] C:\Documents and Settings\All Users\Application Data\18iEe6Rvc2dGi.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1287271111156
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = HO.LOCAL
O17 - HKLM\Software\..\Telephony: DomainName = HO.LOCAL
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = HO.LOCAL
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = HO.LOCAL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\winvnc4.exe

--
End of file - 8424 bytes

Offline quadzilla

  • Car Crazy
  • *****
  • Posts: 23599
  • Carma: +391/-634
  • Gender: Male
    • View Profile
  • Cars: 2022 Rock'n Rolla Nightstalker
Re: I need help with internet explorer problem. recurring error message
« Reply #1 on: January 11, 2011, 11:18:37 am »
Read through this thread, it sounds similar.

http://www.canadiandriver.com/forum/index.php/topic,71318.0.html

Offline blur911

  • Car Crazy
  • *****
  • Posts: 13698
  • Carma: +244/-779
  • Nasty Weasel
    • View Profile
  • Cars: and bikes by age:BMW, Porsche, Subaru, Suzuki, Suzuki, Mazda, Jaguar, Kawasaki, Porsche, GMC, Suzuki
Re: I need help with internet explorer problem. recurring error message
« Reply #2 on: January 11, 2011, 11:27:56 am »
I think it's this trojan, it's a new one.

http://www.mcafee.com/threat-intelligence/malware/default.aspx?id=349240


http://www.prevx.com/filenames/51016235668081112-X1/FEXETWLLHYGF.EXE.html


File Behavior

FEXETWLLHYGF.EXE has been seen to perform the following behavior:

    * Adds a Registry Key (RUN) to auto start Programs on system start up
    * This process creates other processes on disk
    * This Process Deletes Other Processes From Disk
    * Executes a Process
    * Writes to another Process's Virtual Memory (Process Hijacking)
    * Can communicate with other computer systems using HTTP protocols
    * Found on infected systems and resists interrogation by security products

FEXETWLLHYGF.EXE has been the subject of the following behavior:

    * Added as a Registry auto start to load Program on Boot up
    * Created as a process on disk
    * Executed from Temporary Folders
    * Executed as a Process
    * Deleted as a process from disk
« Last Edit: January 11, 2011, 11:31:15 am by blur911 »
Mr Pickypants

Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
Re: I need help with internet explorer problem. recurring error message
« Reply #3 on: January 11, 2011, 12:15:27 pm »
Update:

Please bear with my lack of tech knowledge.

I tried to run Rrocket's link. I was able to download and extract the TDS root killer but the .exe file will not open ?

I then downloaded and scanned using the prevxcsifree program and it detected nothing.

I then downloaded the Microsoft security essentials and it detected a Trojan. After cleaning I still got redirected once on a google search but the endless IE warnings seem to have stopped.

Update 2: Nope still got issues. Double ugh.

ugh.
« Last Edit: January 11, 2011, 12:23:35 pm by ktm525 »

Offline wing

  • Big Wig
  • Administrator
  • *****
  • Posts: 26910
  • Carma: +279/-320
  • Gender: Male
  • If you ain't first ... you're last!
    • View Profile
    • Drivesideways
  • Cars: 2009 Lexus ISF, 2009 Lexus LX570,2011 Audi A5 Touring Car
Re: I need help with internet explorer problem. recurring error message
« Reply #4 on: January 11, 2011, 12:56:45 pm »
check your DNS, I had this problem (on my mac of all things).  The DNS was redirecting.

Your DNS server should be pointing to your ISP or something like openDNS or googleDNS or something (8.8.8.8)  Mine was pointing to 205.x.x.x which was some russian dns site.  The DNS entries were getting over written.

In windows you should be able to do an ipconfig /all to see what the DNS entries are, then google those DNS numbers and see.

Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
Re: I need help with internet explorer problem. recurring error message
« Reply #5 on: January 11, 2011, 01:10:14 pm »
check your DNS, I had this problem (on my mac of all things).  The DNS was redirecting.

Your DNS server should be pointing to your ISP or something like openDNS or googleDNS or something (8.8.8.8)  Mine was pointing to 205.x.x.x which was some russian dns site.  The DNS entries were getting over written.

In windows you should be able to do an ipconfig /all to see what the DNS entries are, then google those DNS numbers and see.

Wing, you might as well be speaking Russian... ;D

Update: I think I may have it licked now. It was hiding as a GIF file..

Update II: No still screwed. >:(

« Last Edit: January 11, 2011, 02:05:29 pm by ktm525 »

UmroAyyar

  • Guest
Re: I need help with internet explorer problem. recurring error message
« Reply #6 on: January 11, 2011, 05:13:20 pm »
Download Malwarebytes. Run full scan. http://www.malwarebytes.org/mbam-download.php
Download Superantispyware.com. Run full scan. http://superantispyware.com/

Offline rrocket

  • Car Crazy
  • *****
  • Posts: 76161
  • Carma: +1254/-7213
    • View Profile
Re: I need help with internet explorer problem. recurring error message
« Reply #7 on: January 11, 2011, 05:27:43 pm »
Download Mozilla Firefox. 
How fast is my 911?  Supras sh*t on on me all the time...in reverse..with blown turbos  :( ...

Offline blur911

  • Car Crazy
  • *****
  • Posts: 13698
  • Carma: +244/-779
  • Nasty Weasel
    • View Profile
  • Cars: and bikes by age:BMW, Porsche, Subaru, Suzuki, Suzuki, Mazda, Jaguar, Kawasaki, Porsche, GMC, Suzuki
Re: I need help with internet explorer problem. recurring error message
« Reply #8 on: January 12, 2011, 12:07:54 am »
FEXETWLLHYGF.EXE
Trojan.Agent/Gen-FraudWare

The file FEXETWLLHYGF.EXE was first observed on Jan 09 2011. 
FEXETWLLHYGF.EXE has an MD5 Hash of : C22336B75290154E4386B68ED86F6044
 
The file FEXETWLLHYGF.EXE was observed with the following file sizes.
472,576 bytes

http://www.superantispyware.com/malwarefiles/FEXETWLLHYGF.EXE.html

Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
Re: I need help with internet explorer problem. recurring error message
« Reply #9 on: January 12, 2011, 11:44:25 am »
Download Malwarebytes. Run full scan. http://www.malwarebytes.org/mbam-download.php
Download Superantispyware.com. Run full scan. http://superantispyware.com/

Downloaded and ran both. No threats found.  ???

Firefox here I come.

Offline wing

  • Big Wig
  • Administrator
  • *****
  • Posts: 26910
  • Carma: +279/-320
  • Gender: Male
  • If you ain't first ... you're last!
    • View Profile
    • Drivesideways
  • Cars: 2009 Lexus ISF, 2009 Lexus LX570,2011 Audi A5 Touring Car
Re: I need help with internet explorer problem. recurring error message
« Reply #10 on: January 12, 2011, 11:46:35 am »
If it's a DNS problem firefox won't help.  Let us know, and you can try babblefish on my Russian ;)

Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
Re: I need help with internet explorer problem. recurring error message
« Reply #11 on: January 12, 2011, 11:53:32 am »
If it's a DNS problem firefox won't help.  Let us know, and you can try babblefish on my Russian ;)

I tried the ipconfig and googled the the DNSnumbers. It came up that they were unknown?


This is what I know:

In  explorer a google search result gets redirected from target site to something else. I also get random IE error messages even if IE is not open.

In Google Chrome I also get redirected like in IE, although not all the time.

I am currently trying Firefox to see if it is affected.


Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
Re: I need help with internet explorer problem. recurring error message
« Reply #12 on: January 12, 2011, 12:56:29 pm »
Firefox seems to be fine.

I am trying to remove Explorer from my computer. I try to delete a file called iexplore.exe and it comes back a few seconds later. It just re-establishes itself? Is this normal?

Offline wing

  • Big Wig
  • Administrator
  • *****
  • Posts: 26910
  • Carma: +279/-320
  • Gender: Male
  • If you ain't first ... you're last!
    • View Profile
    • Drivesideways
  • Cars: 2009 Lexus ISF, 2009 Lexus LX570,2011 Audi A5 Touring Car
Re: I need help with internet explorer problem. recurring error message
« Reply #13 on: January 12, 2011, 01:15:29 pm »
That's also your stuff like your start button you can't just delete IE from windows unfortunately.

Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
Re: I need help with internet explorer problem. recurring error message
« Reply #14 on: January 12, 2011, 01:21:02 pm »
I am going to have to call in a geek.

Offline blur911

  • Car Crazy
  • *****
  • Posts: 13698
  • Carma: +244/-779
  • Nasty Weasel
    • View Profile
  • Cars: and bikes by age:BMW, Porsche, Subaru, Suzuki, Suzuki, Mazda, Jaguar, Kawasaki, Porsche, GMC, Suzuki
Re: I need help with internet explorer problem. recurring error message
« Reply #15 on: January 12, 2011, 01:29:39 pm »
I am going to have to call in a geek.

Have you found and deleted the trojan file yet?  Might work until Symantec catches up and adds it to it's updates.  I'm assuming you've downloaded the latest updates and scanned already.  It should show up as Trojan.FakeAV!gen28 in Symantec-speak if it finds it.

O4 - HKCU\..\Run: [FEXeTWLLHYgf.exe] C:\Documents and Settings\All Users\Application Data\FEXeTWLLHYgf.exe
« Last Edit: January 12, 2011, 01:31:55 pm by blur911 »

Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
Re: I need help with internet explorer problem. recurring error message
« Reply #16 on: January 12, 2011, 02:38:38 pm »
I am going to have to call in a geek.

Have you found and deleted the trojan file yet?  Might work until Symantec catches up and adds it to it's updates.  I'm assuming you've downloaded the latest updates and scanned already.  It should show up as Trojan.FakeAV!gen28 in Symantec-speak if it finds it.

O4 - HKCU\..\Run: [FEXeTWLLHYgf.exe] C:\Documents and Settings\All Users\Application Data\FEXeTWLLHYgf.exe


I scanned yesyterday.. Scanning today using superantispyware. I am going to scan network drives too this time.


Offline mrthompson

  • Car Crazy
  • *****
  • Posts: 9830
  • Carma: +70/-42
  • Gender: Male
    • View Profile
  • Cars: 2008 Honda CR-V (The Green Machine)
Re: I need help with internet explorer problem. recurring error message
« Reply #17 on: January 12, 2011, 03:10:12 pm »
I've had good results using MalwareBytes and Combofix.  These trojans are terribly annoying (cue Saf).  Good luck!

Offline ktm525

  • Car Crazy
  • *****
  • Posts: 15962
  • Carma: +117/-442
  • Just walk away!
    • View Profile
  • Cars: Land Rover LR4, Honda Ridgeline, Husqvarna FE501
Re: I need help with internet explorer problem. recurring error message
« Reply #18 on: January 12, 2011, 04:18:52 pm »
Still getting random IE explorer error messages. Just ran a full scan of superspyware and microsoft security essentials.

yuck



Offline rrocket

  • Car Crazy
  • *****
  • Posts: 76161
  • Carma: +1254/-7213
    • View Profile
Re: I need help with internet explorer problem. recurring error message
« Reply #19 on: January 12, 2011, 05:58:47 pm »
Still getting random IE explorer error messages. Just ran a full scan of superspyware and microsoft security essentials.

yuck




Any reason you won't run Firefox?  I've found Firefox to be less problematic to stuff like this than IE...