Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

IE process keeps popping up.


  • Please log in to reply
12 replies to this topic

#1 Doomtrack

Doomtrack

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:59 PM

Posted 16 July 2015 - 07:21 AM

I got a new computer less than a week ago but the last few days i have seen a IE process and application pop up that i cannot bring to the front and it keeps going to different addresses every few seconds and it stops on adsites that blares out random audio.

I have tried malwarebytes, ccleaner, running windows security essentials and RKiller to get rid of it but nothing works. The only things i have downloaded since i got the computer is windows updates, several steam games, skype, chrome and said programs i have used to attempt to kill this thing, please help me.

 

Edit: I forgot to mention i am on windows 7 pro.


Edited by Doomtrack, 17 July 2015 - 06:15 AM.
Moved from Win 7 to Am I Infected - Hamluis.


BC AdBot (Login to Remove)

 


m

#2 mikey11

mikey11

  • Members
  • 996 posts
  • OFFLINE
  •  
  • Local time:05:59 AM

Posted 16 July 2015 - 07:56 AM

click on the gear icon in the top right corner of IE

 

internet options

 

advanced tab

 

click on reset, then reset again

 

restart your computer



#3 dc3

dc3

    Bleeping Treehugger


  • Members
  • 29,991 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:02:59 AM

Posted 16 July 2015 - 10:39 AM

What website did you use to download the Steam games?

 

Did you use the suggested method of installation, or did you use the Custom method?

 

If resetting Internet Explorer doesn't resolve your issue let me know and I will post a couple of scans that may produce results if this is a browser hijacker.


Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#4 Doomtrack

Doomtrack
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:59 PM

Posted 16 July 2015 - 11:29 AM

I used the steam client but i have been keeping an eye on it and so far it hasnt popped back up. It seems to be random when it happens so i will keeping an eye on it for a while.



#5 Doomtrack

Doomtrack
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:59 PM

Posted 17 July 2015 - 06:05 AM

It happened again overnight so i am now trying the reset route.

 

Edit: No it dd not work, i could really use some help as i am very close to just formatting the entire thing in frustration.


Edited by Doomtrack, 17 July 2015 - 06:16 AM.


#6 Doomtrack

Doomtrack
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:59 PM

Posted 17 July 2015 - 06:07 AM

Double post, sorry.


Edited by Doomtrack, 17 July 2015 - 06:16 AM.


#7 dc3

dc3

    Bleeping Treehugger


  • Members
  • 29,991 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:02:59 AM

Posted 17 July 2015 - 07:22 AM

As new as this computer is it may actually be best just to do a System Recovery.

 

What is the make and model of this computer?


Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#8 Doomtrack

Doomtrack
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:59 PM

Posted 17 July 2015 - 08:04 AM

Its custom built through a store, what information are you looking for?



#9 Doomtrack

Doomtrack
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:59 PM

Posted 17 July 2015 - 09:23 AM

Additional info about my IE, i can browse with it normally after a few tests it does not redirect me anywhere or do anything sketchy. It is just the IE application that goes to different sites that i cannot use end task on nor open the actual window. So far it seems to be hours between each incident and sometimes longer.



#10 Doomtrack

Doomtrack
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:59 PM

Posted 17 July 2015 - 09:15 PM

Any other ideas?



#11 dc3

dc3

    Bleeping Treehugger


  • Members
  • 29,991 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:02:59 AM

Posted 18 July 2015 - 08:45 AM

Please run Malwarebytes AntiMalware
 
Please download Malwarebytes Anti-Malware.  After clicking on the link the download will start automatically.
 
1)  Double-click on mbam-setup.exe, then click on Run to install the application, follow the prompts through the installation.
 
2)  Malwarebytes will automatically open.  If this is the first time you have run this version of Malwarbytes you will see an image like the one below.
 
mbam1_zps95cc812c.png
 
Click on Update Now, after Malwarebytes is updated click on Scan.
 
If this isn't the first time you have run this version, then you will see an image like the one below.  Click on Scan
 
mbam1_zps98e7fba9.png
 
You will be prompted to update Malwarebytes, to do so click on Update Now.
 
 mbam2_zps85f38f0c.png
 
3)  The scan will automatically run now.
 
malwarerun_zps9abd4ef1.png
 
4)  When the scan is complete the results will be displayed.  Click on Delete All.
 
malwarenew_zps34b58fdc.png
 
5)  Please post the Malwarebytes log.
 
To find your Malwarebytes log,download mbam-check.exe from here and save it to your desktop.
 
To open the log double click on mbam-check.exe on your desktop.  Copy and paste the log in your topic.

 
================
 

Please run TDSSKiller.
 
Please download TDSSKiller from here and save it to your Desktop.
 
The log for the TDSSKiller can be very long.  If you go to the bottom of the log to where you find Scan finished you will see the results of the scan.  If it shows Detected object count: 0 and Actual detected object count: 0, this means that nothing malicious was found and you will not need to post the log.
 
1.  Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
 
tdss1_zps90132559.png
 
2.  Check Loaded Modules, Verify Driver Digital Signature, and Detect TDLFS file system.
 
If you are asked to reboot because an "Extended Monitoring Driver is required" please click Reboot now.
 
tdsskillermultiple_zps472c18eb.png
 
3.  Click Start Scan and allow the scan process to run.
 
tdss4_zps6792a13c.png
 
4.  If threats are detected select Cure (if available) for all of them unless otherwise instructed.
 
***Do NOT select Delete!
 
Click on Continue.
 
tdss5_zps98fc5887.png
 
5.  Click on Reboot computer.
 
Please copy the TDSSKiller.[Version]_[Date]_[Time]_log.txt file found in your root directory (typically c:\) and paste it into your next reply.
 
Note:  The log may be very long.  You may need to break it into parts to post the whole log.
 
================

Emsisoft Emergency Kit

Please download Emsisoft Emergency Kit and save it to your desktop. Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop. Leave all settings as they are and click the Extract button at the bottom. A folder named EEK will be created in the root of the drive (usually c:\).

  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.
  • When update is complete, click Malware Scan. When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes. Emsisoft Emergency Kit will start scanning.
  • When the scan is completed click Quarantine selected objects. Note: This option is only available if malicious objects were detected during the scan. If this is the case select Delete selected.
  • When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

Edited by dc3, 18 July 2015 - 08:48 AM.

Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#12 Doomtrack

Doomtrack
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:59 PM

Posted 20 July 2015 - 01:50 PM

Update: I found a program hiding called Elroar which had been there from before i got the computer. I tried tracking down what program this was but i only found extremely suscpicious websites so i removed it.

After i removed it 2 days ago there has been no new instances of this process popping up again.



#13 dc3

dc3

    Bleeping Treehugger


  • Members
  • 29,991 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:02:59 AM

Posted 20 July 2015 - 02:28 PM

Glad to hear you found what sound like the source of your problem.

 

Let us know if you need any further help. :thumbup2:


Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users