|
|
|
|
![]() ![]() |
Apr 26 2008, 04:52 PM
Post
#1
|
|
|
Member [Level 2] ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 80 Joined: 20-October 05 Member No.: 13,144 |
i already tried looking this up on the internet but to no avail since most of the literature there seems to be outdated.
A lot of the literature i read after googling "iexplore.exe virus" says that it can be a virus if it's not run from the C:\Program Files\Internet Explorer\ folder. What's happening to my system is that iexplore.exe runs from that folder however, it does so when internet explorer is not actually running! Furthermore, i have a new process running in my processes list, rundll32.exe. I know this for a fact because I actually committed to memory all the processes in my task manager before I encountered this problem which is making my computer slow. Another problem I am encountering is that whenever I type in something in my firefox address bar, say google.com, there are times when just a blank page shows up even though the internet is on and that i would have to refresh it five times so that google will actually appear on screen. Any help would be appreciated. |
|
|
|
Apr 26 2008, 05:16 PM
Post
#2
|
|
|
$p4m 0n j00 $h4m3 m3 0nc3 $p4m 0n m3 $h4m3 m3 7\/\/1c3 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 6,071 Joined: 21-September 04 From: 9r33|\| 399$ 4|\|D 5P4/\/\ Member No.: 1,218 ![]() |
Well first off rundll32.exe is a normal process as it is used to run DLL's, it is not uncommon to have two of those process to be running though. I think your problem is that your RAM is at its breaking point if your displaying lag times with your internet explorer, and the same with firefox it has to be a lag time with your connection in some way. What I suggest is download, install, update, and then Run spybot and see if it picks up any trojans or malware that is installed in your computer, and if it does odds areit will help solve your problems.
|
|
|
|
Apr 26 2008, 05:42 PM
Post
#3
|
|
|
Newbie [Level 1] ![]() Group: Members Posts: 19 Joined: 25-April 08 Member No.: 61,289 |
Have you tried to use a malware-detection software. There are plenty of those out there, but I think there are only few that worth the effort to download, run and keep.
I used to work with Spybot and Adaware, but both have a limited rate of success. For an almost-perfect fully-automated malware solution I personally recommend the one that is called "Superantispyware". Yes, I know, it has a name that might remind those scams that are actually malware. However, it is very good. They have two flavors of their software: a commercial one and a free one. The free one is good enough for a one-time disinfection. If you are still in doubt for using it, it is always a good idea to read its reviews at those reputable malware forums out there. If they satisfy you, then go for it. You can download it from here. Another piece of software that might interest you is HijackThis. It is not automatic and in order to take advantage of it you must have certain technical knowledge. But it is great for removing some difficult-to-find infection and their traces. Again, use it until you feel it is safe after reading its reviews. Its homepage is this one. Hope they help. |
|
|
|
Apr 26 2008, 05:46 PM
Post
#4
|
|
|
Member [Level 2] ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 80 Joined: 20-October 05 Member No.: 13,144 |
Well first off rundll32.exe is a normal process as it is used to run DLL's, it is not uncommon to have two of those process to be running though. I am putting off the problem with rundll32 right now coz I am looking at my process window and I have four instances of iexplore.exe! whoa! haha.and I am not even using Internet Explorer. Any insights? Another piece of software that might interest you is HijackThis. It is not automatic and in order to take advantage of it you must have certain technical knowledge. But it is great for removing some difficult-to-find infection and their traces. Again, use it until you feel it is safe after reading its reviews. Its homepage is this one. I'll try to take a look at the malware removers you just said. Unfortunately I am not that advanced to use HijackThis. Rawr. Sometimes I wonder how people even get it. For me it's like cricket, I don't get how it's played lol. Is there a formal course that studies how to use HijackThis, be a registry mole etc? |
|
|
|
Apr 26 2008, 06:26 PM
Post
#5
|
|
|
$p4m 0n j00 $h4m3 m3 0nc3 $p4m 0n m3 $h4m3 m3 7\/\/1c3 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 6,071 Joined: 21-September 04 From: 9r33|\| 399$ 4|\|D 5P4/\/\ Member No.: 1,218 ![]() |
Just end the processes for those iexplore.exe that is all you can really do. I did do some searching when you and it seems these trojans are common for your IE problem; "Trojan-Downloader.Win32.Small.acp" or "Trojan-Dropper.Win32.Small.nz. I recommend googing those two trojans and see how to remove, and then run them and see if it solves your problem. A question though what are your system specs and how old is your computer?
|
|
|
|
Apr 26 2008, 07:21 PM
Post
#6
|
|
|
Member [Level 2] ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 80 Joined: 20-October 05 Member No.: 13,144 |
I did do some searching when you and it seems these trojans are common for your IE problem; "Trojan-Downloader.Win32.Small.acp" or "Trojan-Dropper.Win32.Small.nz. That's some neat searching techniques you have in your repertoire! QUOTE A question though what are your system specs and how old is your computer? My computer is 4 months old. AMD Athlon Dual Core Processor,2.2 Ghz 1 GB Ram. Windows XP. |
|
|
|
Apr 26 2008, 07:40 PM
Post
#7
|
|
|
Newbie [Level 3] ![]() ![]() ![]() Group: Members Posts: 49 Joined: 24-April 08 Member No.: 61,260 |
@Jeune
I don't know cricket either NEways.. I am writting down steps to your problem.. I was having a similar issue few years back.. Its a trojan, I can be 50% sure of that. . to confirm I'll need you to post something for me 1.) STEP 1 Daphne : http://www.drk.com.ar/daphne.php HijackThis : http://www.trendsecure.com/portal/en-US/to...ckthis/download download and install both of them .. 2.) STEP 2 Run both of them.. they are both executibles and will not install so you don't need to restart your system.. 3.) STEP 3 in HijackThis > do a Scan and Save log (if you can't find it.. its in main menu: button below the white listing space) 4.) STEP 4 Post that log here. .. so we all can see and find out whats causing the problem 5.) STEP 5 meanwhile.. you can use Daphne to kill all your IExplore.exe while you are NOT using your Internet Explorer If they keep popping back up.. (I LOVE THIS ONE).. then probably i was right that its a trojan .. If its a trojan then it would would most probably be hiding in System32 folder.. I'll try to guide you how to do that , but first post the log from HijackThis.. P.S. PM me if possible, I keep forgetting things btw.. |
|
|
|
Apr 26 2008, 07:48 PM
Post
#8
|
|
|
$p4m 0n j00 $h4m3 m3 0nc3 $p4m 0n m3 $h4m3 m3 7\/\/1c3 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 6,071 Joined: 21-September 04 From: 9r33|\| 399$ 4|\|D 5P4/\/\ Member No.: 1,218 ![]() |
Nothing really special just used keywords fro myour description and google this search:multiple iexplore.exe processes to find out see what kind of stuff would show up and odds are I would have find something about trojans in the first couple of links, which I did. I should warn you that there are so many ways to help fix this problem, and since I am sticking with spybot I would check this thread out.
Also some other questions I should have asked early, what software do you have installed that way we could find out who it is that got you this little problem, most likely a download from a P2P program. Of course curious as to what antivirus software you have as well for this system, and maybe that will determine why nothing was picked up. |
|
|