Solved Explorer.exe causes Iexplore to open multiple instances and high mem

This is a shot from the Bitdefender scan. these are the I/O errors it lists so far.
this scan runs in Linux live cd so it really should not have any permission errors right?
*sigh* looking bad right now. I hate having to tell them this kind of news.
Seagate reported no issues with the drive after 2 runs each of the short and long dst.
 

Attachments

  • IMAG0935.jpg
    IMAG0935.jpg
    456.6 KB · Views: 2

My Computer My Computer

At a glance

Windows 7 Professional x64AMD Athlon II x4 3.00 GHz16GB Kingston DDR3Nvidia 8600 (dual DVI out for 2 monitors)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
Well for my two cents worth try these if you haven't already

http://www.superantispyware.com/

http://www.malwarebytes.org/products/malwarebytes_free/

http://www.bleepingcomputer.com/download/adwcleaner/

download from bleeping computer – delete any rubbishthese find.

If these do not come up with anything try one of these



KASPERSKY RESCUE DISK

Download Kaspersky Rescue Disk 10

You will need to make a bootable disk > set the BIOS toboth from either the optical (my preferred way) or a USB stick - again asyou are having problems there stay with the optical. The rest I haven'tyet tested yet so am not sure how good they are and I run paid for Kaspersky onall my machines anyway.

What this will do is to scan from power on and checkliterally everything as it starts up.

Now it does take a fair while to run but just may picksome rubbish malware on it's way into the system.

There are the rootkit scans too any one of these but the TDSS Killer is the usual one to go with.
Five free portable rootkit removers - TechRepublic

One can go on to heavier stuff too but try thee first.

 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK

My Computer My Computer

At a glance

Win-7-Pro64bit 7-H-Prem-64biti7-5930K 2nd i9-9940x both water blocked VRM'...Trident-z 3200C14 2nd Trident-z 3600C16EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
Hi,
In malwarebytes there's the option to search for rootkits Settings/ Detection and Protection/ Check the box to scan for rootkits,
Then Scan Custom scan !
Use the Custom scan and make sure rootkits is activated be also sure you don't use the machine during the can be very long scan ;)
http://www.sevenforums.com/tutorials/338716-malwarebytes-anti-malware-free.html
Mmm TZ must check my settings as I just plonked the paid for on some time ago and didn't think to check them out:)
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Hi,
Yea I thought Bill's tutorial I posted walked through that part but he doesn't :(
It's a pretty long scan with rootkits enabled on a custom scan so be ready to sit for a while :)
 

My Computer My Computer

At a glance

Win-7-Pro64bit 7-H-Prem-64biti7-5930K 2nd i9-9940x both water blocked VRM'...Trident-z 3200C14 2nd Trident-z 3600C16EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
Checked mine out and it set up by default I reckon because I haven't been into settings since putting it on.
Funny thing is with the paid for the scans have never come up with much at all nit that they did with the free but there were a few sometimes.
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
The paid for version running active doesn't let bad things in, so it finds less.
The free version just cleans up the mess after things get in.
 

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
So they mbam says you should only have to do one custom scan with scan for rootkits enabled ?
To avoid any ssd or hdd scan thrashing ;)
 

My Computer My Computer

At a glance

Win-7-Pro64bit 7-H-Prem-64biti7-5930K 2nd i9-9940x both water blocked VRM'...Trident-z 3200C14 2nd Trident-z 3600C16EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
The Paid for version has the rootkit scan already enabled. While it is active there are quite a few pop ups that say IE is trying to access several different sites like vacumeDOTcleanDOTcom among many others. I know this is an infection. Cant seem to figure out what is infected or how to remove it. Very frustrating indeed. :banghead::banghead::banghead:
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Professional x64AMD Athlon II x4 3.00 GHz16GB Kingston DDR3Nvidia 8600 (dual DVI out for 2 monitors)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
Did you start a fresh thread in Security forum and google for specialized tools for that infection? They don't always check More Help Needed.
 
Did you start a fresh thread in Security forum and google for specialized tools for that infection? They don't always check More Help Needed.


I am starting a new thread there now. Google has few results and I am suspicious of Comodo's answer as far as this particular infection. Could it be a cidoxVBR-A infection? Maybe but there is so little available on the search engines it is either really fresh or impossible to clean. Neither answer makes me feel too hopeful.

I am of a state of mind to start fresh and look at the logs again with a clear head and see if anything stands out. Obviously Malwarebytes see's something going on just not what it is. There is so little about IE multiple instances and memory over run.
 

My Computer My Computer

At a glance

Windows 7 Professional x64AMD Athlon II x4 3.00 GHz16GB Kingston DDR3Nvidia 8600 (dual DVI out for 2 monitors)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
Some thoughts: If you must reinstall then they should understand some infections cannot be cleaned up. They should pay a premium for such serious work and even more if they complain.

I'd Tell them you'll throw in a backup image of a perfect install so they never have to reinstall again. They should be pleased that added MBAM protection is so cheap.

Doing the right thing here: Priceless. (That's a problem I'd imagine if you do it for a living as I've never been able to price it. But some gifts I get tell me its very valuable.)
 
Did you start a fresh thread in Security forum and google for specialized tools for that infection? They don't always check More Help Needed.


I am starting a new thread there now. Google has few results and I am suspicious of Comodo's answer as far as this particular infection. Could it be a cidoxVBR-A infection? Maybe but there is so little available on the search engines it is either really fresh or impossible to clean. Neither answer makes me feel too hopeful.

I am of a state of mind to start fresh and look at the logs again with a clear head and see if anything stands out. Obviously Malwarebytes see's something going on just not what it is. There is so little about IE multiple instances and memory over run.
Without running the risk of repeating myself I would run this first
http://support.kaspersky.com/4162 it will run form power up and avoid he Windows system as such.
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Did you start a fresh thread in Security forum and google for specialized tools for that infection? They don't always check More Help Needed.


I am starting a new thread there now. Google has few results and I am suspicious of Comodo's answer as far as this particular infection. Could it be a cidoxVBR-A infection? Maybe but there is so little available on the search engines it is either really fresh or impossible to clean. Neither answer makes me feel too hopeful.

I am of a state of mind to start fresh and look at the logs again with a clear head and see if anything stands out. Obviously Malwarebytes see's something going on just not what it is. There is so little about IE multiple instances and memory over run.
Without running the risk of repeating myself I would run this first
Download Kaspersky Rescue Disk 10 it will run form power up and avoid he Windows system as such.

No problem my friend. I have run the following live cd's. Kaspersky rescue, AVG Rescue, Bit Defender rescue, Norton Rescue. All of which do not see an infection. all scans are clean. I am running rkill right now so I can look at the logs. Mbam full scan with rootkits found 4) forged physical sectors so it is definitely a rootkit involved.
 

My Computer My Computer

At a glance

Windows 7 Professional x64AMD Athlon II x4 3.00 GHz16GB Kingston DDR3Nvidia 8600 (dual DVI out for 2 monitors)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
Hi,
Did you scan all drives and all partitions with custom and rootkits ?
Post all scan reports here and on your new thread if created ?
 

My Computer My Computer

At a glance

Win-7-Pro64bit 7-H-Prem-64biti7-5930K 2nd i9-9940x both water blocked VRM'...Trident-z 3200C14 2nd Trident-z 3600C16EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Hi,
Did you scan all drives and all partitions with custom and rootkits ?
Post all scan reports here and on your new thread if created ?

Thrash I am having an issue with time on this and when I was trying to create a new thread in security It timed out 3 times and would not let it post. I am going to restore this machine right now so I will be offline a few hours. I am thinking that the infected machines hard drive might have infected this one when I scanned the drive. I'll be back later. if it isn't one thing its another.
 

My Computer My Computer

At a glance

Windows 7 Professional x64AMD Athlon II x4 3.00 GHz16GB Kingston DDR3Nvidia 8600 (dual DVI out for 2 monitors)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
Hi all I got the S.O.B. out. Turns out I got a call from another tech here in town that has also run into this issue. after collaborating for an hour we hit on the answer. It worked for Both of us but there is a trick. Kaspersky Rescue needs to be run first. It may or may not show an issue. (mine did not but his shows minor Java issues). Then boot in safe mode with networking. Run Hitman pro. Now this seems to be a 64bit infection only. The way I figured that out is that if I kill all instances of IExplore And Explore.exe the machine mellowed out. I could then open the 32 bit version of IExplore without issue. However If I opened the 64bit version of IExplore the infection took off trying to call home again

Hitman pro was able to see a file that was in the MBR pointing to the CidoxVGR-A with a Kaspersky Icon and marked for repair.
Now why Kaspersky didn't show it or try to repair must have to do with the rootkit itself somehow. I have contacted MS and Kaspersky with the logs to see if it can be caught faster. Now all I have to do is repair the damage to IExplore and we are good.
 

My Computer My Computer

At a glance

Windows 7 Professional x64AMD Athlon II x4 3.00 GHz16GB Kingston DDR3Nvidia 8600 (dual DVI out for 2 monitors)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
File in the MBR? Isn't MBR code? You mean in hidden System partition? Not scanned due to hidden? Found in memory?
 
File in the MBR? Isn't MBR code? You mean in hidden System partition? Not scanned due to hidden? Found in memory?

You are correct Greg however that is how Hitman pro listed it. I will run hitman again on another machine that is acting the same way and get a screenshot for you. I am also going to write a tutorial for brink to look at on this pita. hitman says mbr infected, the options are ignore, replace, add exception.

**edit**
I ran hitman on this machine(my main one) and found the cidoxVBR-a as well but it had not infected the coding of the mbr as yet probably because I haven't rebooted yet. I will run hitman again after I reboot to be sure
**end edit**
 

My Computer My Computer

At a glance

Windows 7 Professional x64AMD Athlon II x4 3.00 GHz16GB Kingston DDR3Nvidia 8600 (dual DVI out for 2 monitors)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
Back
Top