2 processes of IEXPLORE.EXE in my task manager.

Status
Not open for further replies.

Vudew

Posts: 17   +0
Okay, I have 2 processes of IEXPLORE.EXE in my task manager, and they wont go away when I try to end process on them. I ran AVG Anti-Spyware and cleaned what it found, also ran AVG Free Anti-Virus, it found nothing, I ran HIJACKTHIS. And well need a little help with it, I attached the log file. I tried as I saw in another post somewhere to go into the Internet Explorer folder and rename IEXPLORE.EXE and it just recreated the file soon after. Thanks in advance

Joe.
 

Attachments

  • hijackthis.log
    10.3 KB · Views: 30
Hello and welcome to Techspot.

Your system is infected with several nasties.

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

If after reading the above, you wish to clean your system, do the following.

Download LSPFix from http://cexx.org/lspfix.htm
1. Disconnect from the Internet, go to the LSPfix file and extract/unzip LSP-Fix into its own folder [C:\lspfix].
2. Open the lspfix folder and double-click on LSPFix.exe to start the program.
3. Check the "I know what I am doing" checkbox.
4. Select (highlight) all instances of 'rlls.dll' in the left column under "Keep".
5. Click the arrow >> so it goes over to the right column under "Remove".
6. Click "Finish" and LSPfix will remove references to the file and restore the chain numbers.
7. Restart your computer

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

Locate and delete the following bold file(if there).

C:\Windows\System32\rlls.dll

Rehide your protected OS files and reconnect to the net.


Then, go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT and AVG Antispyware logs as attachments into this thread, only after doing the above.

Regards Howard :wave: :wave:

This thread is for the use of Vudew only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
My active processes

Vudew said:
Okay, I have 2 processes of IEXPLORE.EXE in my task manager, and they wont go away when i try to end process on them. i ran AVG Anti-Spyware and cleaned what it found, also ran AVG Free Anti-Virus, it found nothing, i ran HIJACKTHIS. And well need a little help with it, i attached the log file. i tried as i saw in another post somewhere to go into the Internet Explorer folder and rename IEXPLORE.EXE and it just recreated the file soon after. Thanks in advance

Joe.

I have 2 and XP.Thats what makes your computer operate.
I think they have to be running.
My cpu useage is 1 to 3 % right now.
What problems do you think this is causing ?
If you mean named ? Iexplorer ?
 
Ok, firstly in reply to Howard, I followed all the intructions, except for one, near the end where it says to download http://download.bleepingcomputer.com/sUBs/combofix.exe when I finish downloading it it brings up a txt file that is attached ( notice.txt ). Thanks and sorry took so long to reply.. that stuff takes a LONG time in safe mode, lol, oh and virus scan found nothing. but the two IEXPLORE.EXE processes are still running. as far as firewall, I am behind a Sonicwall Pro 3060 Hardware firewall currently.

Now in reply to Zipperman. IEXPLORE.EXE is not what runs windows, EXPLORER.EXE is. IEXPLORE should only be running when internet explorer is. and should not re-run itself when you close it in task manager.
 

Attachments

  • hijackthis.log
    9.9 KB · Views: 9
The situation with Combofix was only discovered yesterday. See this info HERE.

You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

Delete all files in AVG Antispyware quarantine.

Go to add remove programmes in your control panel and uninstall anything to do with(if there).

Viewpoint
Viewpoint Manager

Close control panel.

Click start/run and type services.msc into the run box and press the enter key.

When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

Viewpoint Manager Service

Close the services window.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

ViewpointService.exe
AXISNEW.exe
ViewMgr.exe

Close task manager.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

R3 - URLSearchHook: (no name) - - (no file)

O4 - HKCU\..\Run: [book ante] C:\DOCUME~1\Vudew\APPLIC~1\ELSEPL~1\AXISNEW.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\Program Files\Viewpoint<Delete the entire folder.
C:\DOCUME~1\Vudew\APPLIC~1\ELSEPL~1<Delete the entire folder.

Reboot into normal mode and rehide your protected OS files.

Post a fresh HJT log.

Regards Howard :)

This thread is for the use of Vudew only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Your HJT log is now clean as a whistle.

If you have any further virus/spyware problems, please post in this thread.

Regards Howard :)

This thread is for the use of Vudew only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Yay, thanks heaps! and both the iexplore processes are gone! YAY.. ok now the question is, how would be best to go about keeping it clean?.. and is there anything i can do to keep tabs of what people like my wife and her friends install on the comp when i'm not there? ... oh and one last thing, am gunna run HJT and such on my desktop at home and was wondering if i should post it here or make a new thread since its a diff comp? thanks in advance.

Joe.
 
Please feel free to post your HJT log from your desktop into this thread.

For info on how to keep your computer safe, see this thread HERE.

Regards Howard :)

This thread is for the use of Vudew only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
OOPS I missed the tiny i before e

Vudew said:
Ok, firstly in reply to Howard, i followed all the intructions, except for one, near the end where it says to download http://download.bleepingcomputer.com/sUBs/combofix.exe when i finish downloading it it brings up a txt file that is attached ( notice.txt ). Thanks and sorry took so long to reply.. that stuff takes a LONG time in safe mode, lol, oh and virus scan found nothing. but the two IEXPLORE.EXE processes are still running. as far as firewall, I am behind a Sonicwall Pro 3060 Hardware firewall currently.

Now in reply to Zipperman. IEXPLORE.EXE is not what runs windows, EXPLORER.EXE is. IEXPLORE should only be running when internet explorer is. and should not re-run itself when you close it in task manager.

Yes your right,i was here when i checked.When i close my browser their not listed.Sorry i can't be of more help.
 
ahh... for some reason my laptop isnt detecting my wireless network... i cant figure it out, please help.
 
Post a fresh HJT log and I`ll see if any nasties are present.

Regards Howard :)

This thread is for the use of Vudew only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
i cant.. cant connec to the inet on my laptop, lol, am on the desktop now.. for some reason it wont detect any networks, i thought it was just at work and was gunna take a look at our wireless router ( i'm the only one who ever uses it so i didnt make a priority of it ) but i get home and its the same thing, as if nothing is around, then i click to change preffered networks to see if thats it and it gives me the authentication tab on the properties of the connection. i never messed with this part beforesays EAP: Type Smart card or other certificate. and to enable IEEE 802.1x authentication for this netowrk.
 
Ok, I think you need to open a new thread for your problem in our Mobile Computing forum.

Regards Howard :)

This thread is for the use of Vudew only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
I havn't seen any mention of what problems this is causeing with
Browsing with Internet Explorer.
What are you trying to "end" ?
 
sorry, i meant iexplore.exe. when i go into task manager and click processes theres two iexplore.exe running, one uses more memory than the other and they keep continuing to use more. when i try to end the one that uses the most memory nothing happens. when i try to end the one that uses the least it goes away then comes back up again. =/ its quite annoying bc ive been trying to install stuff and it says it cant bc internet explorer is running (which it isnt. and i use firefox anyway).
 
I know you meant iexplorer.Just want to be sure we are talking about you Internet Browser.Does it affect firefox.
What is listed in Applications ?
Is it there twice ?
Check and set your default Browser.
 
firefox isnt affected in any way whatsoever. infact i was unaware untill i tried to install something and it said it couldnt install bc internet explorer was open (which it wasnt). its there twice. my defaults are set to custom and everythings set to use the current web browser/email programme...etc.

edit: internet explorer isnt listen in applications
 
The real problem i see

You are haveing problems installing software.
Why have you concluded it was IEx listed twice ?
It's an install problem .Start a new post on this problem with details
and error messages.
:rolleyes:
 
well...im concluding its that bc it says internet explorers open when its not and ive tried to install exactly the same software on my old laptop and the one before that and the one before...etc and it installed fine. and iexplore.exe wont end so i just kinda figured...
 
Hi Guys !
I have just found Iexplore.exe running twice on a PC i was sorting for a customer,
They were running even though i didn't have iexplorer browser open ! ?
after some searching i found that the program that was starting them was
called "sizemeowmemo.exe" i googled it and came up with nothing !
So Here's how i got shut of it ! :OP
( Ho ! I comes in with a virus called Swizzor)
First i did a search on the PC for "sizemeowmemo.exe"
I found 2 files..... "I Deleted them"
Then i serched the redg (Find ---> "sizemeowmemo.exe")
I found about 5 entrys and deleeted them,
then you can stop the prosseses in task maneger,
Then do a search for a folder called "lies-dvd-funk" ..Delete them.
reboot and that seemed to sort it... :O)
I hope this info helps someone.
Thanx.
The cOffin dOdger
 
Thought on 2 processes of iexlporer

i belive it has something to do with IE8 because when i had IE7 it wasnt running 2 of the same procesees, so my guess is after you install IE8, IE7 still runs along side of IE8 for some odd reason the only way to fix this would be to uninstall IE7 before you ever install IE8,but i have not found a opiton anywhere to uninstall IE7. I dont even use internet explorer that often anymore anyways,fire fox has a much smaller footprint and only one process :)
 
i belive it has something to do with IE8 because when i had IE7 it wasnt running 2 of the same procesees, so my guess is after you install IE8, IE7 still runs along side of IE8 for some odd reason the only way to fix this would be to uninstall IE7 before you ever install IE8,but i have not found a opiton anywhere to uninstall IE7. I dont even use internet explorer that often anymore anyways,fire fox has a much smaller footprint and only one process :)
 
Okay, I have 2 processes of IEXPLORE.EXE in my task manager, and they wont go away when i try to end process on them. i ran AVG Anti-Spyware and cleaned what it found, also ran AVG Free Anti-Virus, it found nothing, i ran HIJACKTHIS. And well need a little help with it, i attached the log file. i tried as i saw in another post somewhere to go into the Internet Explorer folder and rename IEXPLORE.EXE and it just recreated the file soon after. Thanks in advance

Joe.

i belive it has something to do with IE8 because when i had IE7 it wasnt running 2 of the same procesees, so my guess is after you install IE8, IE7 still runs along side of IE8 for some odd reason the only way to fix this would be to uninstall IE7 before you ever install IE8,but i have not found a opiton anywhere to uninstall IE7. I dont even use internet explorer that often anymore anyways,fire fox has a much smaller footprint and only one process :)
 
Status
Not open for further replies.
Back