We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

iexplorer.exe is it a virus?

24

Comments

  • been running fo 2 hrs 37 min so far, still going

    Ouch, done any general PC maintenance recently?

    http://lifehacker.com/294189/top-10-ways-to-clean-up-your-pc

    Good tips on there!
    :exclamatiTo the internet.. I need to complain about something!
  • shandypants5
    shandypants5 Posts: 2,124 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    3 Hours 25 min and still running...:(
    “Careful. We don't want to learn from this.”
  • shandypants5
    shandypants5 Posts: 2,124 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    edited 20 October 2010 at 2:41PM
    Ok, log as requested.



    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org
    Database version: 4889
    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385
    20/10/2010 15:17:32
    mbam-log-2010-10-20 (15-17-32).txt
    Scan type: Full scan (C:\|D:\|E:\|)
    Objects scanned: 431265
    Time elapsed: 3 hour(s), 47 minute(s), 29 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 21
    Registry Values Infected: 2
    Registry Data Items Infected: 0
    Folders Infected: 3
    Files Infected: 8
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_CLASSES_ROOT\mysearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\TypeLib\{014da6c0-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{014da6c4-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{014da6c6-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{014da6ca-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{014da6cc-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{014da6c2-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{014da6c3-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{014da6c5-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{014da6c7-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{014da6cb-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\mysearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Search Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\MySearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    C:\Program Files (x86)\MySearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\MySearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\MySearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    Files Infected:
    C:\Program Files (x86)\MySearch\bar\1.bin\S4BAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.


    C:\Program Files (x86)\MySearch\bar\1.bin\MYSEARCHPLUGINPROXY.CLASS (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\MySearch\bar\1.bin\NPMYSRCH.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\MySearch\bar\1.bin\PARTNER.BMP (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\MySearch\bar\1.bin\PARTNER.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\MySearch\bar\1.bin\S42NS.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\MySearch\bar\1.bin\UNINSTALL.INF (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    “Careful. We don't want to learn from this.”
  • Has it detected anything?
  • shandypants5
    shandypants5 Posts: 2,124 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Has it detected anything?

    Well it found lots and deletet it for me, but this log means nothing to me.

    Am I still infected?
    “Careful. We don't want to learn from this.”
  • Chimpofdoom
    Chimpofdoom Posts: 806 Forumite
    edited 20 October 2010 at 2:38PM
    Has it detected anything?

    Well it says it quarantined and deleted a few things! ;)
    Well it found lots and deletet it for me, but this log means nothing to me.

    Am I still infected?

    I'll assume no. But to be sure you should do another run.

    But first, general PC house keeping to help speed up the system!

    http://lifehacker.com/5413223/how-to-fix-your-relatives-terrible-computer

    skip the first section and read Clogged with crapware. Some good tips on how to clean up ol' faithful.

    Then run another scan!
    :exclamatiTo the internet.. I need to complain about something!
  • shandypants5
    shandypants5 Posts: 2,124 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    CPU useage seems a lot lower now (hovering around 10%) but I still have 3 "iexplore.exe" showing in task manager.?

    Is that right?
    “Careful. We don't want to learn from this.”
  • Post log from malwarebytes here please so we cna further advise you. When you open malwarebytes, LOG tab at the top, pick the scan which found the infections and post log here.
  • CPU useage seems a lot lower now (hovering around 10%) but I still have 3 "iexplore.exe" showing in task manager.?

    Is that right?

    Well the cpu usage sounds about right.. is it iexplore.exe or IEXPLORE.EXE?
    :exclamatiTo the internet.. I need to complain about something!
  • shandypants5
    shandypants5 Posts: 2,124 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Post log from malwarebytes here please so we cna further advise you. When you open malwarebytes, LOG tab at the top, pick the scan which found the infections and post log here.

    Already posted it at post #14.
    “Careful. We don't want to learn from this.”
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.