Solved

explore.exe using 100% usage on folder browse

Posted on 2011-02-11
13
363 Views
Last Modified: 2012-05-11
This one is rough. My grandparents PC (ug right?) has XP SP3 on it. They have a genealogy program on it that installs to c:\legacy.

I did my usual cleanup with malware bytes and cc cleaner, as well as removed the dozen or so toolbars and useless programs that are inevitably on this type of box.

The problem they were having still persists. If I browse to c:\legacy and scroll down a bit my explorer.exe jumps to 100%. Keep in mind I'm not actually clicking or launching a thing. I can end it, restart it using new task run explorer and everything resumes normal performance. Odd thing is I can browse other folders perfectly fine. I can even start > run and open c:\legacy\data fiine. Heck I can even start > run to c:\legacy (as long as I don't scroll) everything is fine. As soon as I scroll down it jumps.

What possible mechanisms could be at play at this basic level? Nothing is being opened or even clicked on just a file list (detail view) displayed. Thought maybe it could be a virus scan, but MS Security Essentials is the only program they have, and it is still sitting at 0% CPU. I could understand if it were in thumbnail view or something, but this is detail view.

I'm honestly stumped and I've seen some odd stuff in my day, but I have no idea what OS mechanisms can even be at play here.  Anecdotally they think it all started happening when they upgraded to IE8 in November, but I've already rest it to no avail.
0
Comment
Question by:bhieb
13 Comments
 

Author Comment

by:bhieb
ID: 34875428
To add to it explore.exe is the CPU culprit, it just gets stuck in a loop consistently increasing its memory usage as well.
0
 
LVL 17

Expert Comment

by:houssam_ballout
ID: 34875447

did you remove your antivirus & try?

also try to do sfc /scannow


or


try windows repair:

http://michaelstevenstech.com/XPrepairinstall.htm
0
 
LVL 30

Expert Comment

by:Wayne Barron
ID: 34875466
There is something bad inside of the folder, if not found and deleted it can cause Explorer to crash.
Check in the EventViewer and see if there is anything recorded there.

Suggestions from my own personal experiance with a video file that was bad.

Option #1:
Create another folder.
c:\legacy_backup
Open up
c:\legacy
And start copy the files from the top of the folder into the Backup folder.
Continue to do this until you reach the area that is spiking your CPU
Then you can start attempting to track down the bad file and [delete] it.

Option #2:
Do the same as above, create a folder c:\legacy_backup
And copy everything from the c:\legacy folder.
Go into the c:\legacy_backup folder and see if it spikes the CPU.
If it does not, then [Delete] then c:\legacy folder
And then rename the c:\legacy_backup to c:\legacy

Good Luck
Carrzkiss
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34877198
Dl Process Explorer to find out what's really using the Cpu...

http://live.sysinternals.com/procexp.exe

Doble click explorer.exe, and hit the Threads tab. Paste a screenshot.

Then, double click the biggest cpu hog again, and paste those results as well. Might be a corrupted shell extension, menu handler etc...

That should pinpoint it well enuff...
0
 
LVL 3

Expert Comment

by:goldsix
ID: 34878096
1. try to perform an full scan of your anti-virus programs in Safe Mode
2. if still not work, try new account
3. if you are familiar with system tools, you can use procexp or ShellExView to remove add-on or dll files attached to your Windows Explorer
0
 

Author Comment

by:bhieb
ID: 34889613
@John6767

Attached is the screen shot. Here is the thread detail from the thread in question.


ntkrnlpa.exe!KiUnexpectedInterrupt+0x8d
ntkrnlpa.exe!PsLookupThreadByThreadId+0x4abc
ntkrnlpa.exe!KiDeliverApc+0xb3
ntkrnlpa.exe!KiUnexpectedInterrupt+0xbe
ntdll.dll!KiFastSystemCallRet
QtCoreRebit4.dll!QFSFileEngine::drives+0x2d1

process.bmp
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 

Author Comment

by:bhieb
ID: 34889633
@ others

I have completely removed all AV products and it still happens. Also I have completely removed this application from add/remove. Then deleted the folder in question. Then reinstalled. Still same result.

Don't have time atm to copy them one by one into the folder, but I will if John's efforts don't pan out. Thing is this program worked fine until November (interestingly the same time they installed IE8).
0
 

Author Comment

by:bhieb
ID: 34889669
Ok the sfc /scannow came back with.

Files that are required to run properly have been replaced by unrecognized files.. blah blah insert Windows XP Pro SP3 disk. Problem is they don't have such a disk as they installed SP3 via windows update.

Do I have to slipstream it onto an XP Pro install and mail it to them or is their an easier way?
0
 
LVL 66

Accepted Solution

by:
johnb6767 earned 500 total points
ID: 34889718
Whats this file belong to?

QtCoreRebit4.dll Dont see anything solid on a quick search about it....

Take it and scan it here if needed....

http://www.virustotal.com

0
 

Author Comment

by:bhieb
ID: 34889772
Aww now it is becoming clearer. The path is a Segate Replica folder. It is a replication program that came with a Seagate backup drive. I will check to see if they have anything on their support site, or possibly a new version.
0
 
LVL 2

Expert Comment

by:jatremillo
ID: 34890020
Run Spybot in safemode and also run this program called: SmitFraudFix: http://siri.urz.free.fr/Fix/SmitfraudFix.exe  

That should take care of your problem.
0
 

Author Comment

by:bhieb
ID: 34906846
Well it definitely was the Seagate Replica software. I've made a simple batch file to backup their data instead, and uninstalled it. Everything is smooth now. Thanks John for the tip on using the expanded process viewer. I've used it before, but not this in-depth, I'm sure it will come in handy in the future.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34907069
Glad it helped......
0

Featured Post

Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

Join & Write a Comment

Suggested Solutions

Most of the time we are in fix when all of sudden our systems behave weirdly.  Such problems cost time and effort... so it's best to take some preventive actions so that we can avoid such issues or overcome such problems more easily. Preventive M…
cPanel is a Unix based web hosting control panel that provides a graphical interface and automation tools designed to simplify the process of hosting a web site. cPanel utilizes a 3 tier structure that provides functionality for administrators, rese…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now