PDA

View Full Version : Malware? What folders should iexplore be in?


pally01
09-13-2008, 04:16 PM
Hi all. On an XP machine, where should iexplore.exe reside?

I ask because I have a p.c. with:
iexplore.exe and iexplore.exe.mui located in folder: C:\8cfb253cr53a1a67939890cc219 (What is this folder anyways?)

iexplore.exe in folder: Program files\internet explorer\en-US

iexplore.exe TWICE in folder: C\Windows\Softwaredistribution\download\0eda838ef8ec599d8221155030a70ecac\SP2QFE

iexplore.exe in folder: C\Windows\servicepackfiles\i386

iexplore.exe in folder: C\Program files\internet explorer

IEXPLORE.EXE-27122324.pf in folder: C\Windows\Prefetch.

I'm having pop-up trouble with this p.c. The pop-ups vary but "CID" appears in the banners of the ads.

glc
09-13-2008, 05:08 PM
Have you run Malwarebytes and SuperAntispyware yet?

pally01
09-13-2008, 05:33 PM
Hi GLC.

Yes - I ran both in safe mode. Have also ran avg and spybot too. I'm running trend micro on-line scanner right now.

Trend Micro has finished and it found quite a few things
- TROJ_SWIZZER.NW
- DIALER_FREECONNECT
- DIALER_WINMOVIE
- ADWARE_180SOLUTIONS
- ADWARE_ISTBAR
- ADWARE_BHOT_MIRAR
- ADWARE_MEDLOAD
- ADWARE_YOURSITEBAR
- DIALER_PORNDIAL
- ADWARE_VISTAINTERACTIVE
- DOWNLOADER_SXLOAD
- DIALER_SKYMASTER
- ADWARE_MSINFO
- ADWARE_MEDIAMOTOR
- ADWARE_BESTOFFERS
- HTTP COOKIES

That's the most stuff I've gotten a hit about of any on-line scan I've ever run.

Negeva
09-13-2008, 06:01 PM
Hi all. On an XP machine, where should iexplore.exe reside?

I ask because I have a p.c. with:
iexplore.exe and iexplore.exe.mui located in folder: C:\8cfb253cr53a1a67939890cc219 (What is this folder anyways?)

iexplore.exe in folder: Program files\internet explorer\en-US

iexplore.exe TWICE in folder: C\Windows\Softwaredistribution\download\0eda838ef8ec599d8221155030a70ecac\SP2QFE

iexplore.exe in folder: C\Windows\servicepackfiles\i386

iexplore.exe in folder: C\Program files\internet explorer

IEXPLORE.EXE-27122324.pf in folder: C\Windows\Prefetch.

I'm having pop-up trouble with this p.c. The pop-ups vary but "CID" appears in the banners of the ads.

Really wouldn't worry about the prefetch foolder - if you want you can delete it's contents.

Those locations are fine, IE is found within the Programs and Windows folders. The other folder on the C drive is probably from an update such as moving from IE6 to IE7 or maybe even a service pack that hasn't cleaned up after itself correctly.

If you're really concerned over malware then a HJT log would be better.

Hi GLC.

Yes - I ran both in safe mode. Have also ran avg and spybot too. I'm running trend micro on-line scanner right now.

Trend Micro has finished and it found quite a few things
- TROJ_SWIZZER.NW
- DIALER_FREECONNECT
- DIALER_WINMOVIE
- ADWARE_180SOLUTIONS
- ADWARE_ISTBAR
- ADWARE_BHOT_MIRAR
- ADWARE_MEDLOAD
- ADWARE_YOURSITEBAR
- DIALER_PORNDIAL
- ADWARE_VISTAINTERACTIVE
- DOWNLOADER_SXLOAD
- DIALER_SKYMASTER
- ADWARE_MSINFO
- ADWARE_MEDIAMOTOR
- ADWARE_BESTOFFERS
- HTTP COOKIES

That's the most stuff I've gotten a hit about of any on-line scan I've ever run.

I've become inclined to take what Trend Micro's site states with a large pinch of salt: it seems to scare more than anything these days - at least in my experience over the last year or so.

What did malwarebytes and SAS find? Did you clean out junk files before scanning? If they found anything did you continue scanning until clean?

pally01
09-13-2008, 06:12 PM
What did malwarebytes and SAS find? Did you clean out junk files before scanning? If they found anything did you continue scanning until clean?

Hmmm. I can't find the logs. Neither log appears on their respective tabs in either program?!?! I can recall that both found "stuff", but didn't appear to be anything too noteworthy. Also - I ran ccleaner before I started any scans etc.