Hey guys, first time poster, long time unregistered lurker.
I have been fighting the virus for a month or so now and am throwing in the towel and asking for help. Here is what I know:
explorer.exe is infected with something (I dont think anything else is, but I could be wrong)
Symptoms: Internet Explorer popups constantly, sometimes 20-30 of them within a few minutes
Unauthorized downloads attempted but stopped by UAC
Huge amounts of resources taken up.
What I have hit it with:
Avast
Hitman Pro 3.5
AdAware
Spybot Search and Destroy
AVG Free
Combofix
Malwarebytes
Windows Defender
Reinstalling Vista SP2 (to hopefully rewrite architecture and replace explorer.exe)
Nothing has succeeded in killing the virus, some of them picked up other little things but never the main explorer.exe virus, although I regularly get pop ups from Avast/AVG/AdAware about harmful sites being accessed all referencing explorer.exe as the source.
I have resorted to running everything from task manager and using an alternate file browser.
I have also run through just about every explorer.exe virus thread or writeup online but none of them seem to help nor be exactly what my problem is.
Please help me! Im all ears guys, I wasnt sure if I should post Hijack This (OTL) logs straight away or if I should wait, so I held off.
To avoid using multiple post with copy and paste you have to attach the log`s
Lower left corner: Additional Options > Attach ( OTL.Txt and Extras.Txt. and Malwarebytes scan log)
Yes, you are infected with several types of malware. I wish you had come to us sooner, but we will help you out.
In the meantime, do you have another machine you can use to check the forum and use for email?
Please limit (or do not use as much as possible) this infected machine, especially for any social networking, syncing of devices, etc.
If you are on a network, disconnect this machine from the network.
If this machine is connected to a router, please reset the router.
Please do not make any further changes to your machine now that you have provided the logs.
I am going to refer you to our Certified Malware expert, named Essexboy. He will also review your logs and give you further instructions, however he comes on the forum late UK time. He will respond to you in this thread, so remember to check this thread daily. I will continue to provide assistance in the meantime, then remain in the background while he works with you.
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN
Delete your current copy of combofix and download a fresh one
Everything appears to be acting normal, resource consumption of explorer.exe looks normal, ill sit on it for a day or so and see if any symptoms pop up and report back regardless. Thanks again Essexboy.
Lets see if windows detects a problem with explorer
Go to start > All Programs > Accessories
Right Click Command Prompt and select run as administrator
When the prompt opens type the following bolded text and press enter
sfc /scannow (Note: There is a space between sfc and /scannow)
It will download as an 8 digit file save it to your desktop
Restart in safe mode and run
Accept the enhanced version
Then run the quick scan
About halfway through you will be prompted to buy - just X the box closed
Once finished it will generate a log please attach that
Yes it is still around I got it on IE9, could no get rid of it, and returned to IE 8, no problem. Reloded IE9 again, and the same problem startet over now back to IE 8.
I also got hit by a ransome virus program antivirus soft, got rid of that tough, but it left 3 files pup d11host.exe.
Avast close down as I was hit, and could only be activated after the clean up with other programs, and now i fails to find the left pup d11host.exe in 3 location, i can get at them, seach dont reveal, advice is welcome.
I shut off explorer.exe yesterday and have been running everything from task manager. I turned it back on and within 5 minutes im back to getting ie popups. No alerts yet however…
Clear Cache/Temp Files
Download TFC by OldTimer to your desktop
[*] Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
[*]It will close all programs when run, so make sure you have saved all your work before you begin.
[*]Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
[*]Once it’s finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.