Internet Explorer

  • Internet Explorer 8
  • Internet Explorer
  • All forums
Question

Internet explorer 8 (or any other browser) crashes and restarts after doing any search engine query.

I have Vista home premium 32 bit service pack 1, Intel core duo 2.33 ghz, 2 gigs RAM, Invidia gforce 9800 gt graphics card.
All started when son accidentally installed Windows Antivirus Pro.  Have used every anti-malware tool I have to remove all traces of it.  Since then:
1. Somehow all my system restore points have disappeared.
2. When I try to do a full system scan with Windows Defender or the Malicious Software Removal Tool the computer crashes and restarts in the middle of the scan.
3. I have disabled all IE add ons, but any search crashes and restarts IE8 (or Firefox), and certain websites where I type in the URL (like CNET) crash IE8 as well. 
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation
8 People had
this question

Was this helpful?

2

Votes

Answer

Hi,

Go back and try to run the other scan, can't be too careful and here are other free ones to
try. Seems you managed to catch a rootkit that was just discovered.

Free online scans
http://www.google.com/search?hl=en&source=hp&q=antivirus+free+online+scan&aq=f&oq=&aqi=g1

----------------------

This may sound strange but you have too many resident spyware programs unless you have turned
resident modes off. Please remove Adaware, Spybot, Spyware Doctor, and SpyBlaster by checking
on their site for removal tools and special instructions. You can also use the Revo Uninstaller. Later
you can reinstall these as needed however I would stop their resident modes - i.e. for SpyBot you
disable TeaTimer in its settings and STOP the SBSD Service and set it to MANUAL - then you can use
it as an on-demand scanner. Too many resident programs actually interfere with each other and can
cause strange issues to show up. Be sure to uninstall fully as remnants also cause bizarre happenings.

I would also ditch Advanced System Care if you continue with AVG, you should not have more than
one resident antivirus programs on the machine and most have remnants even when not in use.
Be sure to look for removal instructions and/or use Revo.

Ever had any other antivirus - security products on machine like Norton, McAfee and others? If so
we need to make sure their remnants are gone.

TDSSKiller.exe. - Download to the Desktop - then go to it and Right Click on it - RUN AS ADMIN
it will show any infections in the report after running - if it will not run change the name from
tdsskiller.exe to tdsskiller.com. Whether it finds anything or not does not mean you should not
check with the other methods below.
http://support.kaspersky.com/viruses/solutions?qid=208280684

SpyDLL Remover - Free
http://securityxploded.com/spydllremover.php

Advanced Windows Service Manager
http://securityxploded.com/winservicemanager.php

Run Rootkit Revealer - Free
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx

UnHackme - trial
http://www.greatis.com/unhackme/

This tells you how to use UnHackme and has a link to version 2.5 - use it as a guideline and
the current version available as above is 5.99+
http://www.oit.umn.edu/safe-computing/topics/rootkits/

IceSword - Free
http://www.antirootkit.com/software/IceSword.htm
Instructions and Pictorial
http://securityxploded.com/icesword.php
Tutorial for using IceSword
http://translate.google.com/translate?hl=en&sl=zh-CN&u=http://soft.zol.com.cn/2004/0803/145163.shtml&prev=/search%3Fq%3Dicesword%26hl%3Den%26lr%3D

Revo Uninstaller - Free
http://www.revouninstaller.com/revo_uninstaller_free_download.html

You need to run SFC and CheckDisk to clean up if you can.

Hope this helps.


Rob - Bicycle - Mark Twain said it right.

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

SpiritX MS MVP

Community Moderator
Rob Brown - Microsoft MVP - Windows Expert - Consumer : Bicycle - Mark Twain said it right.

Was this helpful?

Hi,

Do you have a Restore Point to use before that was installed?

How to Do a System Restore in Vista
http://www.vistax64.com/tutorials/76905-system-restore-how.html

What antivirus/antispyware/security product do you have on machine? Include any you have EVER has on this
machine including those you uninstalled (they leave remnants behind which causes issues). We can help you
remove the remnants and these issues can also be caused by those products you are now using as well.

Start - All Programs - Accessores - System Tools - IE with no Addons - does this work better?

IE - Tools - Internet Options - Advanced Tab - click Restore then click Reset - Apply / OK

IE - Tools - Internet Options - Security - Reset all Zones to default level - Apply / OK

Close and Restart IE and/or IE with no Addons

any better?

IE - Tools - Manage Addons (for sure disable SSV2 if it is there, this is no longer needed but Java still installs it
and it causes issues - you ever update Java go back in and disable it again.) Look for other possible problems.

Windows Defender - Tools - Software Explorer - look for issues with programs that do not look right. Permitted
are usually OK and "not permitted" are not always bad. If in doubt about a program ask about it here.

Could be a BHO - SpyBHOremover - Free - standalone program, needs no install, download -
unzip and run - not all are bad however some can cause your issue (Toolbars are BHO's).
http://securityxploded.com/bhoremover.php

Startup Programs
http://www.vistax64.com/tutorials/79612-startup-programs-enable-disable.html

I would scan with Malwarebytes and add Prevx to be sure it is gone.

Malwarebytes - free - use as scanner only. If you ever suspect malware, and that would be unusual with

Malwarebytes - free
http://www.malwarebytes.org/products/malwarebytes_free

SuperAntiSpyware Portable Scanner - Free
http://www.superantispyware.com/portablescanner.html?tag=SAS_HOMEPAGE

Prevx - Home - Free - small, fast, exceptional CLOUD protection, works with other
security programs. This is a scanner only, VERY EFFECTIVE, if it finds something come back
here or use Google to see how to remove. 
http://www.prevx.com/   <-- information
http://info.prevx.com/downloadcsi.asp?prevx=Y  <-- download

PCmag - Prevx - Editor's Choice
http://www.pcmag.com/article2/0,2817,2346862,00.asp

Try the trial version of Hitman Pro :

Hitman Pro is a second opinion scanner, designed to rescue your computer from malware
(viruses, trojans, rootkits, etc.) that have infected your computer despite all the security
measures you have taken (such as anti virus software, firewalls, etc.).
http://www.surfright.nl/en/hitmanpro

--------------------------------------------------------

If needed here are some online free scanners to help

http://www.eset.com/onlinescan/

-----------------------------------

Original version is now replaced by the Microsoft Safety Scanner
http://onecare.live.com/site/en-us/default.htm

Microsoft Safety Scanner
http://www.microsoft.com/security/scanner/en-us/default.aspx

----------------------------------

http://www.kaspersky.com/virusscanner

Other Free online scans
http://www.google.com/search?hl=en&source=hp&q=antivirus+free+online+scan&aq=f&oq=&aqi=g1

--------------------------------------------------------------------

Also do these to cleanup general corruption.

Start - type this in Search Box ->  COMMAND   find at top and RIGHT CLICK  -  RUN AS ADMIN

Enter this at the prompt - sfc /scannow

How to analyze the log file entries that the Microsoft Windows Resource Checker (SFC.exe) program
generates in Windows Vista cbs.log
http://support.microsoft.com/kb/928228


Run checkdisk - schedule it to run at next start and then Apply OK your way out then restart.

How to Run Check Disk at Startup in Vista
http://www.vistax64.com/tutorials/67612-check-disk-chkdsk.html

Hope this helps.


Rob - Bicycle - Mark Twain said it right.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

SpiritX MS MVP

Community Moderator
Rob Brown - Microsoft MVP - Windows Expert - Consumer : Bicycle - Mark Twain said it right.

Was this helpful?

To remove ANY legitimate security product be sure to check with their website for instructions and removal tools.

If you had McAfee, Norton or others on this machine you need to get their uninstall tool even if you uninstalled it
since most leave remnants.

Here is what I use :

Avast and Prevx have proven extremely reliable and compatible with everything I have thrown at them.

Avast Home Free - stop any shields you do not need except leave Standard, Wed, and Network running.

Prevx - Home - Free

Windows Firewall

Windows Defender

IE - Protected Mode

IE 8 - SmartScreen Filter ON  (IE 7 Phishing Filter)

I also have IE to always start with InPrivate Filter active if IE 8.
(You occasionally have to turn it temporarily off with the little Icon on LEFT of the + bottom right of IE)

Avast - Home - Free - stop any shields you do not need except leave Standard, Web, and Network running.
(Double Click Blue icon - details next to OK. - upper left Shields - Terminate those you do not use.)
http://www.avast.com/eng/avast_4_home.html

Prevx - Home - Free small, fast, exceptional CLOUD protection, works with other security programs. This is
a scanner only, VERY EFFECTIVE, if it finds something come back here or use Google to see how to remove. 
http://www.prevx.com/

PCmag - Prevx - Editor'a Choice
http://www.pcmag.com/article2/0,2817,2346862,00.asp

Also get Malwarebytes - free - use as scanner only. If you ever suspect malware, and that would be unsual with
Avast and Prevx running except for an occasional low level cookie (no big deal), UPDATE it and then run it as
a scanner. I have many scanners and they never find anything of note since I started using this setup.

http://www.malwarebytes.org/


Rob - Bicycle - Mark Twain said it right.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

SpiritX MS MVP

Community Moderator
Rob Brown - Microsoft MVP - Windows Expert - Consumer : Bicycle - Mark Twain said it right.

Was this helpful?

SpiritX, thank you for your time.  Finally able to do a deep scan in safe mode with both Malwarebytes and Defender, both revealed nothing.

Do you have a Restore Point to use before that was installed?
No-all gone for some reason
How to Do a System Restore in Vista
http://www.vistax64.com/tutorials/76905-system-restore-how.html

What antivirus/antispyware/security product do you have on machine? Include any you have EVER has on this
machine including those you uninstalled (they leave remnants behind which causes issues). We can help you
remove the remnants and these issues can also be caused by those products you are now using as well.
Currently using Malawarebytes, AVG free, Spyboy S&D, Advanced System care, CC Cleaner, Startup Inspector.  Have also used Adaware, Spyware Doctor, Spywareblaster.
Start - All Programs - Accessores - System Tools - IE with no Addons - does this work better?

IE - Tools - Internet Options - Advanced Tab - click Restore then click Reset - Apply / OK

IE - Tools - Internet Options - Security - Reset all Zones to default level - Apply / OK

Close and Restart IE and/or IE with no Addons

any better?
No
IE - Tools - Manage Addons (for sure disable SSV2 if it is there, this is no longer needed but Java still installs it
and it causes issues - you ever update Java go back in and disable it again.) Look for other possible problems.

Windows Defender - Tools - Software Explorer - look for issues with programs that do not look right. Permitted
are usually OK and "not permitted" are not always bad. If in doubt about a program ask about it here.

Could be a BHO - BHOremover - Free - standalone program, needs no install, download and run - not all
are bad however some can cause your issue. (Toolbars are BHO's)
http://securityxploded.com/bhoremover.php
No Change
Startup Programs
http://www.vistax64.com/tutorials/79612-startup-programs-enable-disable.html

I would scan with Malwarebytes and add Prevx to be sure it is gone.


Malwarebytes - free - use as scanner only. If you ever suspect malware, and that would be unusual with
Avast and Prevx running except for an occasional low level cookie (no big deal), UPDATE it and then run it as
a scanner. I have many scanners and they never find anything of note since I started using this setup.

http://www.malwarebytes.org/

Prevx - Home - Free small, fast, exceptional CLOUD protection, works with other security programs. This is
a scanner only, VERY EFFECTIVE, if it finds something come back here or use Google to see how to remove. 
http://www.prevx.com/

!!!!!!!!Prevx found the following 4 items:
1. ROOTKIT   kbiwkmyumwxbev.dll in c:\windows\system32
2. THREAT     kbiwkmbcqssiwm.dll   in c:\windows\system32
3. ROOKIT     kbiwkmvarocvpo.sys  in   c:\windows\system32\drivers
4. Threat       \REGISTRY\Machine\system\ControlSet001\Services\kbiwkkmiddqrvnu

Could these be the culprits? 
PCmag - Prevx - Editor'a Choice
http://www.pcmag.com/article2/0,2817,2346862,00.asp

Here are some online free scanners to help

http://www.eset.com/onlinescan/


http://www.kaspersky.com/virusscanner


--------------------------------------------------------------------

Also do these to cleanup general corruption.

Start - type this in Search Box ->  COMMAND   find at top and RIGHT CLICK  -  RUN AS ADMIN

Enter this at the prompt - sfc /scannow

How to analyze the log file entries that the Microsoft Windows Resource Checker (SFC.exe) program
generates in Windows Vista cbs.log
http://support.microsoft.com/kb/928228


Run checkdisk - schedule it to run at next start and then Apply OK your way out then restart.

How to Run Check Disk at Startup in Vista
http://www.vistax64.com/tutorials/67612-check-disk-chkdsk.html

I Will try both the ESET and Kaspersky scans as well, and let you know the results if they are different.  Now how do I remove these pests?Thank you again for your time-Zaphod

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

SpiritX, did all I could do of the above suggestions.  A Kaspersky scan crashed the computer-the ESET scan was the only one that didn't crash while online, other scans worked only in safe mode.  The sfc scan showed no issues.  I turned off all add-ons and returned all my internet settings to default.  I am having the hardest time getting a chkdsk done-so far I have tried 4 of the suggestions within the vista forums to no avail.  The ESET scan found and fixed some garden variety adware.

So where I am now is: I can't get a scndsk to run, and I have these issues:
1. ROOTKIT   kbiwkmyumwxbev.dll in c:\windows\system32
2. THREAT     kbiwkmbcqssiwm.dll   in c:\windows\system32
3. ROOKIT     kbiwkmvarocvpo.sys  in   c:\windows\system32\drivers
4. Threat       \REGISTRY\Machine\system\ControlSet001\Services\kbiwkkmiddqrvnu

I will continue to try and get a chkdsk done-let me know if you (or anyone else) has any suggestions-Zaphod
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

2

Votes

Answer

Hi,

Go back and try to run the other scan, can't be too careful and here are other free ones to
try. Seems you managed to catch a rootkit that was just discovered.

Free online scans
http://www.google.com/search?hl=en&source=hp&q=antivirus+free+online+scan&aq=f&oq=&aqi=g1

----------------------

This may sound strange but you have too many resident spyware programs unless you have turned
resident modes off. Please remove Adaware, Spybot, Spyware Doctor, and SpyBlaster by checking
on their site for removal tools and special instructions. You can also use the Revo Uninstaller. Later
you can reinstall these as needed however I would stop their resident modes - i.e. for SpyBot you
disable TeaTimer in its settings and STOP the SBSD Service and set it to MANUAL - then you can use
it as an on-demand scanner. Too many resident programs actually interfere with each other and can
cause strange issues to show up. Be sure to uninstall fully as remnants also cause bizarre happenings.

I would also ditch Advanced System Care if you continue with AVG, you should not have more than
one resident antivirus programs on the machine and most have remnants even when not in use.
Be sure to look for removal instructions and/or use Revo.

Ever had any other antivirus - security products on machine like Norton, McAfee and others? If so
we need to make sure their remnants are gone.

TDSSKiller.exe. - Download to the Desktop - then go to it and Right Click on it - RUN AS ADMIN
it will show any infections in the report after running - if it will not run change the name from
tdsskiller.exe to tdsskiller.com. Whether it finds anything or not does not mean you should not
check with the other methods below.
http://support.kaspersky.com/viruses/solutions?qid=208280684

SpyDLL Remover - Free
http://securityxploded.com/spydllremover.php

Advanced Windows Service Manager
http://securityxploded.com/winservicemanager.php

Run Rootkit Revealer - Free
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx

UnHackme - trial
http://www.greatis.com/unhackme/

This tells you how to use UnHackme and has a link to version 2.5 - use it as a guideline and
the current version available as above is 5.99+
http://www.oit.umn.edu/safe-computing/topics/rootkits/

IceSword - Free
http://www.antirootkit.com/software/IceSword.htm
Instructions and Pictorial
http://securityxploded.com/icesword.php
Tutorial for using IceSword
http://translate.google.com/translate?hl=en&sl=zh-CN&u=http://soft.zol.com.cn/2004/0803/145163.shtml&prev=/search%3Fq%3Dicesword%26hl%3Den%26lr%3D

Revo Uninstaller - Free
http://www.revouninstaller.com/revo_uninstaller_free_download.html

You need to run SFC and CheckDisk to clean up if you can.

Hope this helps.


Rob - Bicycle - Mark Twain said it right.

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

SpiritX MS MVP

Community Moderator
Rob Brown - Microsoft MVP - Windows Expert - Consumer : Bicycle - Mark Twain said it right.

Was this helpful?

SpiritX, Thanks, between the Prevx and the Unhack me I was able to remove all the rootkits and other malware, so far the system seems to be running fine.  I especially the Revo app.  Now if I could just get the chkdsk to work....
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

Hi,

Good move getting rid of those nasty critters!

Try running SFC in Safe Mode and you can also run SFC and Chkdsk from a Command Prompt using Vista DVD.
Have you tried scheduling CheckDisk at next startup?

Safe Mode - repeatedly tap F8 as you boot, select Safe Mode without Network.

Start - type this in Search Box ->  COMMAND   find at top and RIGHT CLICK  -  RUN AS ADMIN

Enter this at the prompt - sfc /scannow

How to analyze the log file entries that the Microsoft Windows Resource Checker (SFC.exe) program
generates in Windows Vista cbs.log
http://support.microsoft.com/kb/928228


Run checkdisk - schedule it to run at next start and then Apply OK your way out then restart.

How to Run Check Disk at Startup in Vista
http://www.vistax64.com/tutorials/67612-check-disk-chkdsk.html


If needed you can access a COMMAND PROMPT here :

This tells you how to access the System Recovery Options and/or use a Vista Disk
http://windowshelp.microsoft.com/Windows/en-US/Help/326b756b-1601-435e-99d0-1585439470351033.mspx

Good luck.

Rob - Bicycle - Mark Twain said it right.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

SpiritX MS MVP

Community Moderator
Rob Brown - Microsoft MVP - Windows Expert - Consumer : Bicycle - Mark Twain said it right.

Was this helpful?

I'm having the same problems as you Zap :l

I'll try going through the steps you took and hopefully it'll help
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

I love you guys, Unhackme worked perfectly

great job X!
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

Glad you sorted it out. Also you should install Prevx to be sure your are clean if you already have not done that.


Rob - Bicycle - Mark Twain said it right.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

SpiritX MS MVP

Community Moderator
Rob Brown - Microsoft MVP - Windows Expert - Consumer : Bicycle - Mark Twain said it right.
<< PreviousPage of 2 Next >>

Message marked as answers cannot be deleted

To delete this message, first unmark this message as an answer, then delete it.

Reason to remove escalation


Merge

Enter the thread ID of the thread you are merging into


Reply will be posted to a public thread

You are replying to a public portion of this thread. To reply privately, click Cancel, click the Private Messages tab, and Reply on that private message.

Don't show this message again

To report abuse, sign in or continue without signing in

Thank you.

Report abuse

Abuse type:

Details (optional):

Report abuse

Abuse type:

Details (required):
Enter the characters you see (required):
Type the numbers that you see in the picture.
Play audio and type the numbers that you hear.
Show a different picture.

Sign in

Hotmail, Xbox Live, Messenger, or msn accounts will also work.

Don't have one of the above accounts?

Signing in...
This page will automatically update after you are signed in.
If you are having problems, you can close this message and try to connect again.