Solved

Explorer.exe creating many internet connections to random ip addresses

Posted on 2013-12-13
7
832 Views
Last Modified: 2014-01-05
I have a friend who received an email with a zip attachment about air line tickets.  I was able to scan the computer and remove the virus.  However now everytime he starts up his laptop, Explorer.exe runs at a hight cpu percent and there are over 100 connections to random IP addresses.  Their status is either established, time_wait, or Close_wait.  

His system is running windows 7 home premium.

On occasion, after arount 15minutes, the process will end, and system idle will be over 90%.  On most occasions it never ends.

I have disabled all startup entries, processes not microsoft, and have disabled hidden startup's with sysinternals autoruns program.

When I boot to safemode, the same thing happens.  

Not sure what to do next.  I have used Kaspersky's cd scanner too.  No virus was detected.
0
Comment
Question by:rrincones
7 Comments
 
LVL 11

Expert Comment

by:David Kroll
Comment Utility
What did you use to remove the virus?  I would definitely run a full scan with Malwarebytes.
0
 
LVL 24

Accepted Solution

by:
aadih earned 500 total points
Comment Utility
If the problem happened recently (1-2 days), restore your PC to an earlier time by booting up in safe mode with command prompt and typing rstrui.exe to restore.

Scan with:

(1) Malwarebytes Antimalware (free).

(2) TDSSKiller (free).

(3) Malwarebytes AntiRootkit (Beta) (free).
0
 

Author Comment

by:rrincones
Comment Utility
I scanned with malwarebytes twice.  1st scanned resulted in 33 registry entries, 8 values, 15 folders, and 57 files, detected with items such as funmoods, whitesmoke, visual bee.  

2nd scan had 1 detection from vid-saver.

Prior to scanning, I went to add remove programs and uninstalled several free programs and toolbar addons.

I will try system restore.  I will have to remove those programs again, but I will check for internet connections prior to removing the programs.

By the way, there are 4 instances of explorer.exe running, each using 20 to 40 % of cpu.  And the dll's are for various programs.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:rrincones
Comment Utility
Ive been monitoring explorer.exe with process explorer from sysinternals.  Every 10 minutes or so, all the dll's will end at the same time, then startup again after a few seconds.
0
 
LVL 59

Expert Comment

by:LeeTutor
Comment Utility
I've requested that this question be deleted for the following reason:

The question has either no comments or not enough useful information to be called an "answer".
0
 

Author Closing Comment

by:rrincones
Comment Utility
Sorry about the late update.  tdsskiller did the trick. after scanning the pc, no more internet ports opened up on their own.
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

This story has been written with permission from the scammed victim, a valued client of mine – identity protected by request.
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now