Solved

Explorer.exe creating many internet connections to random ip addresses

Posted on 2013-12-13
7
849 Views
Last Modified: 2014-01-05
I have a friend who received an email with a zip attachment about air line tickets.  I was able to scan the computer and remove the virus.  However now everytime he starts up his laptop, Explorer.exe runs at a hight cpu percent and there are over 100 connections to random IP addresses.  Their status is either established, time_wait, or Close_wait.  

His system is running windows 7 home premium.

On occasion, after arount 15minutes, the process will end, and system idle will be over 90%.  On most occasions it never ends.

I have disabled all startup entries, processes not microsoft, and have disabled hidden startup's with sysinternals autoruns program.

When I boot to safemode, the same thing happens.  

Not sure what to do next.  I have used Kaspersky's cd scanner too.  No virus was detected.
0
Comment
Question by:rrincones
7 Comments
 
LVL 11

Expert Comment

by:David Kroll
ID: 39717583
What did you use to remove the virus?  I would definitely run a full scan with Malwarebytes.
0
 
LVL 24

Accepted Solution

by:
aadih earned 500 total points
ID: 39717593
If the problem happened recently (1-2 days), restore your PC to an earlier time by booting up in safe mode with command prompt and typing rstrui.exe to restore.

Scan with:

(1) Malwarebytes Antimalware (free).

(2) TDSSKiller (free).

(3) Malwarebytes AntiRootkit (Beta) (free).
0
 

Author Comment

by:rrincones
ID: 39717617
I scanned with malwarebytes twice.  1st scanned resulted in 33 registry entries, 8 values, 15 folders, and 57 files, detected with items such as funmoods, whitesmoke, visual bee.  

2nd scan had 1 detection from vid-saver.

Prior to scanning, I went to add remove programs and uninstalled several free programs and toolbar addons.

I will try system restore.  I will have to remove those programs again, but I will check for internet connections prior to removing the programs.

By the way, there are 4 instances of explorer.exe running, each using 20 to 40 % of cpu.  And the dll's are for various programs.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:rrincones
ID: 39717625
Ive been monitoring explorer.exe with process explorer from sysinternals.  Every 10 minutes or so, all the dll's will end at the same time, then startup again after a few seconds.
0
 
LVL 59

Expert Comment

by:LeeTutor
ID: 39758266
I've requested that this question be deleted for the following reason:

The question has either no comments or not enough useful information to be called an "answer".
0
 

Author Closing Comment

by:rrincones
ID: 39758267
Sorry about the late update.  tdsskiller did the trick. after scanning the pc, no more internet ports opened up on their own.
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Best Way to Clone 256GB SSD Boot Drive to New 512GB SSD in Windows 7 PC 17 81
forgot pst password 2 38
Authenticated Users 5 26
Botnet detection help me please 21 79
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now