TechSpot

IEXPLORER.EXE even when i'm not running internet explorer

By DeZahid
Feb 3, 2007
  1. today For some reason i kept getting a IEXPLORER.EXE in my taskmanager,
    i used methods that is suggested here.
    it didnt work, is there a way to remove this without reformating, coz i'm on a laptop.
     
  2. jobeard

    jobeard TS Ambassador Posts: 9,330   +622

    well there are some things that I would address; two types
    A) bogus and B) unnecessary

    B) C:\WINDOWS\System32\snmp.exe ; I don't have one on XP/home sp2 and
    if a true MS product, you don't need it running --
    SNMP (Simple Network Management Protocol). SNMP is used to perform remote administration of network hardware such as Routers and Hubs.

    B) should be deleted
    R1(3)
    O2 - BHO: Windows Live Sign-in Helper
    O2 - BHO: (no name)
    O3 - Toolbar: &Google caused me all kinds of problems
    O17 (two) entries

    disable startup
    O20 Winlogon Notify: igfxcui

    A) real issues
    O4 - (two of these!) HKLM\..\Run: [startkey] C:\WINDOWS\svchort.exe
    O4 - HKLM\..\Run: [DRam prosessor] dll.exe
    O4 - HKLM\..\RunServices: [DRam prosessor] dll.exe
     
  3. DeZahid

    DeZahid TS Rookie Topic Starter

    thanks anyway but i'v fixed it, it was a file called setup.exe, taskman.exe and setup.dat file in my c:\windows directory, i started windose in safe mode, and deleted those files and also deleted the iexplorer file that was also "infected"
     
  4. tomrca

    tomrca TS Rookie Posts: 1,000

    you have within your log, evidence of a worm "C:\Program Files\Network Monitor\netmon.exe"(MIMAIL-A WORM, W32/codbot-A backdoor) and Troj/Ciadoor-M and more i would suggest that you do go HERE follow all the instructions, then do another scan and post the hjt log, but you must first change the name of hjt! place hjt in it's own folder within my docs or programme files, there you MUST change the hjt to analyser 1991, as there are now bug that will hide from it.
    when you post your log do it as an attachment. look at, additional options and attach files, you will find these below the reply box
     
  5. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Your system is infected with a variety of nasties.

    Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

    If after reading the above, you wish to clean your system, do the following.

    Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT and AVG Antispyware logs as attachments into this thread, only after doing the above.

    Regards Howard :wave: :wave:

    This thread is for the use of DeZahid only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...