Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Multiple instances of iexplore.exe running in task manager
![]() |
|
|
|
Thread Tools |
|
#21
|
||||
|
||||
|
IE8 is suppose to be a big memory user and bloated. Try uninstalling IE8 and dropping back to IE7- see how much difference it makes.
The basic security should be: One antivirus program: AVG One firewall: Comodo 2 or more syware/adware programs: Superantispyware.. Of the above, consider changing the antivirus to Avira or Avast. We notice that AVG misses some malware that other AV programs find. Suggest you take SAS off of Startup. That will slow you down. Add Spywarebaslter: Recommended Free Anti Virus: Avast Free:http://www.avast.com/eng/download-avast-home.html Avira Free:http://www.free-av.com/en/products/1...antivirus.html Spyware/Adware Programs: Spybot Search & Destroy: http://www.techspot.com/downloads/14...on-update.html SpywareBlaster: http://www.techspot.com/downloads/56...reblaster.html You can apply all the "pruning" I did to your current system to the new one- some, maybe not all will be on that one also. The following is one of the best written for how you got infected and what to do to prevent malware in the future: Quote:
Run Eset NOD32 Online AntiVirus Scanner HERE Note: You will need to use Internet Explorer for this scan.
Please rescan with HijackThis and post fresh log in next reply. We'll go from there. Report any current system problems. |
|
#22
|
|||
|
|||
|
OK, I've uninstalled IE8 and rolled back to IE7 with all current security updates. I'm running AVIRA instead of AVG and downloaded Spyware Blaster (Spybot download did not work). i disabled the AVIRA and tried several times to run the Eset Scanner, but it kept hanging up at around 14%. IE7 seems to work better than IE8 and but I have made Firefox my default brower. I've attached an updated Hijackthis log.
|
|
|
|
#23
|
||||
|
||||
|
No problem. But I'd like you to run a full system scan with Avira> save the log> attach to next reply.
No malware in HijackThis> Open HJT> 'do system scan only'> check the entries below: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab Close all but HJT> click on Fix Checked Open IE> Tools> Manage Add-ons> locate the following two entries> highlight> Disable: Eset online scanner yucsetreg or yucconfig.dll. Empty the Recycle Bin. IF you are not having the original problems and the AV scan is clean, I'll have you remove cleaning tools. This was for >> (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll |
|
#24
|
|||
|
|||
|
OK the AV scan found a few items that I had it "repair" and have attached the log. Could not find Eset online scanner and yucsetreg or yucconfig.dll in IE Add-ons. While scanning with AV Comodo picked up something. I have attach a Comodo log as well. IE is working far better (I used it to reply here) and the system is fairly stable in most respects. The Comodo find was a little troubling but no ill effects yet.
|
|
#25
|
||||
|
||||
|
AV found and quarantined many Trojans. Some remain in the restore points. Do NOT use System Restore or you will reinfect the system.
Please delete the quarantined items, then Empty the Recycle Bin. One of the Trojans is a backdoor password stealer. I advise you to change all your passwords, check internet banking carefully. I might have missed this, but it appears that you are using the Comodo Internet Security program that contains both a firewall AND an antivirus program, thus the log. Basically the 2 AV found the same thing, but you need to remove one of the AV programs. You should only run one AV, Please delete anything left in quarantine by the Comodo AV> I want you to remove the infected restore points: The easiest and safest way to do this is:
Empty the Recycle Bin. After you do this, run the antivirus scan again and attach log. Are you deleting what the AV programs find and quarantine, then emptying the Recycle Bin> IF you are not, please do that, then run another scan with Avira. |
|
#26
|
|||
|
|||
|
OK I disabled the anti virus protection on Comodo, scanned with Avira deleted all quarantined items did a system restore and disc clean up and rescanned. When I delete the quarantined items in Avira, there is nothing in the recycle bin. The second Avira scan came up clean, I have attached the log. During the whole process Windows installed an update, I think. I've attached another Hijackthis log as well, just in case.
|
|
#27
|
||||
|
||||
|
There are 2 entries in the HJ log:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = First, one showed up in the HJ log in Reply #22. I had you remove that. Now there are 2 of the entries! Please do the 'system scan only' in HJ and check these 2 entries. Then click on Fix Checked. We'll see if they stay gone. 'Naked' entries like this shouldn't show up. Run one more scan and see if they stay gone. Are you having any system at all with the computer? I'm concerned about Trojans continuing to be showing up. |
|
#28
|
|||
|
|||
|
If fixed the two entries in the Hijackthis log and ran a new one attached. I also ran another AV scan and it was clean. No system problems yet.
|
|
#29
|
||||
|
||||
|
Okay. If the original problem has been resolved and there are no new problems, you can remove the cleaning tools:
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTCleanIt by OldTimer: Save it to your Desktop. Double click OTCleanIt.exe. Click the CleanUp! button. If you are prompted to Reboot during the cleanup, select Yes. The tool will delete itself once it finishes. Clean up the restore points since I had you remove them earlier: You should now set a new Restore Point to prevent infection from any previous Restore Points. The easiest and safest way to do this is:
Be sure to empty the Recycle Bin. Let me know if you need more help. You should be moving faster if you followed what I set up in Reply #18. |
|
|
|
#30
|
|||
|
|||
|
Thanks for all your help. Will do what you suggested in the last post. One last question, how do you stop the pop-up ad that come with Avira anti virus. It's very annoying and kills my network connection when it pops up. Would Avast be a better choice?
|
|
#31
|
||||
|
||||
|
Actually I think Avira is the better of the two. But can you explain what the pop-up ad is? Could it just be the splash screen. That can be disabled.
Last edited by Bobbye; 07-04-2009 at 06:34 PM.. Reason: Spelling |
|
#32
|
|||
|
|||
|
It's a pop up trying to get me to buy the full version, a big red screen with the price that stays up until I close it.
|
|
#33
|
||||
|
||||
|
The popup is easy to dismiss:
Windows XP Home (and Media Center)
|
|
#34
|
|||
|
|||
|
Thank you. This process has been a great learning experience. Techspot.com is now the number one site on my favorites list and you have been terrific. Thank you again.
|
|
#35
|
||||
|
||||
|
You're welcome. Glad to help It can be a learning experience for all of us!
|
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Help - Multiple iexplore processes using 100% cpu but iexplore not running | Virus & Malware removal | 4 | 09-19-2008 07:26 PM | |
| multiple iexplore.exe process in my task manager | Virus & Malware removal | 6 | 09-03-2007 12:07 PM | |
| Multiple IExplore instances badly need help | Virus & Malware removal | 44 | 03-12-2007 02:03 PM | |
| 2 instances of iexplore.exe running, most likely a trojan | Virus & Malware removal | 1 | 02-17-2007 04:05 PM | |
| Multiple instances of explorer.exe running | Windows OS | 3 | 08-22-2006 09:31 PM | |
All times are GMT -4. The time now is 09:08 AM.



