VIRUS in IE11; Please Help !!!

OK…I’m stumped on need some of the experts help here.
I have six PCs in the house and only one has this problem.
All W7 64bit, all updates, latest everything.
I have Avast & MBAM Pro active shields and run daily scans…nothing today (clean).
I’ve run Adware Cleaner (clean).

So, when I log into IE11 and go to Yahoo and pic and article some have pictures in the article with “gallery” function.
On all the other PCs the gallery pops up and I can scroll thru.
On this one PC no luck.
I can launch FireFox and no problem on same sites.
I even went and did a RESET within IE11 and went to default settings…same issue.

Any thoughts ? …the reason I’m posting here is the #1) Very Smart Folks here…2) if issue is virus then right place.
I attached FRST logs.

Thx in advance for any help.

Update:

Thing are really seeming mucked up…my home page on IE11 was finance (dot) yahoo (com) and it gives me errors opening IE to that. I have to set my start page to Google.
I went ahead and uninstalled IE11, leaving me with IE10 hoping that may help nut no luck.
Also saw on the FRST log above a lot of items on “policies” so I removed the CrytoPrevent policies.
Attached is new FRST, MBAM, ADWARE…if I could find Avast log I’d post but ran FULL SCAN with no threat.

I see “SearchScopes” in the FRST file…isn’t this an issue/virus ?

Help !!!

Does resetting IE11’s settings clear the cache? Clear the cache again just for the heck of it. I dont even think uninstalling clears the folders out because it doesnt really “uninstall” anthing

How do you clear the cache ?

control panel > internet options > delete… just make sure files and cookies are deleted

Done, no help.
IE seems Very unstable now…a lot of weird things happening…not connects, then connect when retry.
Firefox stable.
Hoping Virus Expert can look at logs and provide guidance.
Will try to re-upgrade to IE11.

have you got a system image you can go back to?

Yes, I use Macrium and have one from this morning and couple days ago…keep two.
But, not sure how far back this problem may go…don’t want to even attach my USB HDD with those images yet.
Hoping someone can look at FRST log.
I’m about to restart PC after re-upgrading to IE11.
I’ll then run ASWMBR scan and post…running MBAM scan again now.

Ugh !!!

Why not post in the Virus and Worms Forum?

https://forum.avast.com/index.php?board=4.0

I should have…sorry…can this one be moved instead of me starting another post ?

Probably could, but not by me.
No worries, Just thought the experts spend more time there then here…usually.
See how it pans out. :slight_smile:

Latest FRST, MBAM, Adware logs…CryptoPrevent policies un-applied, IE11 re-installed.
Avast FULL SCAN run…shows No Threat…can’t seem to find the Avast TXT “scan logs” or I would post as well.

Help ? :-X

patient … when essexboy is home from work :wink:

OK…thx !

BTW…I had done a Avast FULL Scan with no threat…went back and created a Custom Scan with only Full Rootkit (since Avast Default FULL Scan only has “Quick” Root Kit) and ran…No Threat found on Full Rootkit scan.
If you can tell me how to export to TXT file the Avast “scans” I would gladly post…cannot find them on HDD…can’t export from with Avast GUI it seems…not sure what they’d tell you except nothing was found. :slight_smile:

No apparent malware, retry after this run and let me know if the problem persists

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-4121731150-3748954045-3468760984-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-4121731150-3748954045-3468760984-1000 -> {80A190B6-D7E6-48BA-9C21-A3E337458320} URL = SearchScopes: HKU\S-1-5-21-4121731150-3748954045-3468760984-1000 -> {85E6381D-524F-43FE-A409-64175FBE4682} URL = SearchScopes: HKU\S-1-5-21-4121731150-3748954045-3468760984-1000 -> {C13FBFF8-EFC9-4DAA-B99C-AC31DC1A6698} URL = SearchScopes: HKU\S-1-5-21-4121731150-3748954045-3468760984-1000 -> {CE127195-B34B-4FDA-91D4-77B174EA4E11} URL = BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File Toolbar: HKLM-x32 - No Name - {A50F643C-3C5B-4D99-B68C-21A13C81E50E} - No File Toolbar: HKU\S-1-5-21-4121731150-3748954045-3468760984-1000 -> No Name - {A50F643C-3C5B-4D99-B68C-21A13C81E50E} - No File EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

Here is fixlog and I ran new FRST scan logs after. Thx !

IE11 the issue of pics & video still remains.
On Yahoo the article for example…
Baseball Hall of Fame voters elect four: Randy Johnson, Pedro Martinez, John Smoltz, Craig Biggio
…has picture gallery…on every other PC I can click on it and the gallery come up and I can scroll thru.
On the suspect PC I see the “gallery” icon but click on and nothing happens.
I go to some other Yahoo articles and the videos don’t play even though I get the > (play) icon.
I can go to YouTube and play no problem.
My Adobe Flash & Shockwave is all latest, per the above thread I un-installed IE11 down to IE10 and re-installed IE11 and even did a RESET on IE11.

I looked at the FRST log…SeachScopes still there ?

I do not have the issue on FireFox (latest v34.x) on this same PC…above works fine.

Search scopes look OK

Now try this small programme http://www.tweaking.com/content/page/repair_internet_explorer.html

OK…ran the util…it did its thing…did not reboot PC but re-launched IE11…same issue. :frowning:

Reboot as it re-registered all the dll’s etc