Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Alright, I'm going to try to be as specific as possible, but I'm new to this so let me know if i'm leaving anything off.
When I first turn on my computer, it is taking longer than normal to startup. Before i open or touch anything, I'll open my task manager and see that there are a lot of weird looking processes running that i've never noticed before (i usually pay attn to those kinds of things) One including iexplorer.exe, sometimes there are even 2 named this. Though Internet explorer IS NOT open or running....Also, if i leave my DSL cable unplugged when i start up, it will pop up the box saying "web page cannot be viewed offline, and gives me the option of connect or try again" like it's trying to open something without me even doing anything...After a few minutes of my laptop being on, The CPU usage jumps all the way to 100% and stays there...even if i have NOTHING open and will not go back down until i completely shut down my computer and then the whole cycle starts again.
I've ALWAYS make it a point to delete my temp int files and cookies on a reg basis.I currently have Norton, Spybot, and the free version of a squared on my computer, and have done a complete scan with all three.
Norton hasn't found any type of virus, a squared found 3 different malware files which i've removed, and spybot solved my winfixer problem along with a couple others...but my computer continues to do this.
I've just now run all three scans again and nothing is coming up.I'm not sure what to do, or what the problem may be.
If anyone has any suggestions, it'd be greatly appreciated.
--Thanks a bunch :)

It looks like something is still lurking in there for explorer to open on start up.
Try Ewido in safe mode.tap F8 on start up.
http://www.ewido.net/en/
you could also try downloading hijackthis
http://www.spywareinfo.com/~merijn/downloads.html
Do a scan and paste the file into the url below it will tell you what the services are.
http://www.hijackthis.de/index.php?langselect=english
Good Luck

It's a virus and nothing to do with explorer. Let me explain:
explorer.exe is the main "Windows" Explorer file (valid).
iexplore.exe is the main "Internet" Explorer file (valid).
iexplorer.exe is bogus (trying to make you think it is something to do with one or other of the two explorers). Note that it starts with an i and ends with an r.
It's not an easy one to cure and I'm no expert in dealing with it. While you are waiting, type iexplorer.exe in Google - there are a lot of hits.
Here is one of them:
IEXPLORER.EXEUse of a HijackThis log is suggested in this instance and it warns you not to start deleting things. It has probably disabled your AV (and a few other things).
DerekW

... a bit more.
Clover's suggestions are a good start. If you are not familiar with using HJT you might find it easier to try putting your log in here first:
HJT DETECTIVEThis concentrates on the nasties only. Let HJT remove anything reported as malicious.
Afterwards run HJT again and then put the log in Clover's link, this one:
HJT ANALYSISThis shows all running processes (good or bad) and takes a bit of wading through. Google can help with any dubious ones.
DerekW

Just found this. Seems like the best thing to try for starters (use the other suggestions if this doesn't do the trick)
Symantec removal instructions (down page)
DerekW

Derek,
Good point about the 3 EXEs; 2 legit and 1 bigus.
How about just deleting iexplorer.exe?
If at first you don't succeed, you're about average.M2

Mechanix2Go
Some websites are guarded about deleting stuff, so I'm a bit guarded about when you do that. There seem to be procedures to follow.Taryn
I'd add that whenever removing any malware/spyware/trojan turn off system restore before doing so and put it back on again afterwards. Seems this one is trojan.DerekW

Thanks, yall...I've tried mostly everything suggested...here's some new info.
I just typed all this one time but my computer froze so here we go AGAIN...I'll make it quick.
The iexplorer.exe is not showing up in my processes now. I ran another complete a2 scan again and this is what it is telling me.
C:\WINDOWS\system32\mllml.dll Trojan.Win32.Crypt.o
C:\WINDOWS\system32\pmnll.dll Trojan.Win32.Crypt.oI don't think these are trojans because I went to symantec, downloaded the virus definition for that specific trojan in case i didn't have it already, ran the scan again and it STILL didn't find anything.
I googled the file names and found this in a dell support forum:
http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=11645It seems that his anti spyware program listed it as a trojan also, and his HJT log lists those same 2 processes that were also found in mine.
In my HJT log, the two were completely unknown which is why I didn't delete them until i got the results from the a2 scan. Once I delete them, using HJT or a2..they still show up if i runthe scan again...
so do these
C:\Documents and Settings\TarynS\Cookies\taryns@as-us.falkag[2].txt Trace.TrackingCookieC:\Documents and Settings\TarynS\Cookies\taryns@computing[1].txt Trace.TrackingCookie
C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll Adware.ToolBar.MyWay.v
None of it seems to be going away, however, when i delete/fix them.
I'm assuming I'll have to manually do it, like the unfortunate one on the dell forums did, even though i'm totally clueless on how to. And i'm so skeptical about trusting just anything some website tells me when i google it. I can't mess up my computer.
Advice?
Thanks again.

Well...
I posted the problem on the Dell support forums and looks like this was just a common winfixer infection.I used Vundofix, worked like a charm, everything seems to be back to normal, and my HJT logs look okay FINALLY.
For anyone else with the problem,
http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=43550
There's where I was walked through it.
Thanks for yalls' time. I appreciate it. <3

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |