Solved

Explorer.exe creating many internet connections to random ip addresses

Posted on 2013-12-13
7
857 Views
Last Modified: 2014-01-05
I have a friend who received an email with a zip attachment about air line tickets.  I was able to scan the computer and remove the virus.  However now everytime he starts up his laptop, Explorer.exe runs at a hight cpu percent and there are over 100 connections to random IP addresses.  Their status is either established, time_wait, or Close_wait.  

His system is running windows 7 home premium.

On occasion, after arount 15minutes, the process will end, and system idle will be over 90%.  On most occasions it never ends.

I have disabled all startup entries, processes not microsoft, and have disabled hidden startup's with sysinternals autoruns program.

When I boot to safemode, the same thing happens.  

Not sure what to do next.  I have used Kaspersky's cd scanner too.  No virus was detected.
0
Comment
Question by:rrincones
7 Comments
 
LVL 11

Expert Comment

by:David Kroll
ID: 39717583
What did you use to remove the virus?  I would definitely run a full scan with Malwarebytes.
0
 
LVL 24

Accepted Solution

by:
aadih earned 500 total points
ID: 39717593
If the problem happened recently (1-2 days), restore your PC to an earlier time by booting up in safe mode with command prompt and typing rstrui.exe to restore.

Scan with:

(1) Malwarebytes Antimalware (free).

(2) TDSSKiller (free).

(3) Malwarebytes AntiRootkit (Beta) (free).
0
 

Author Comment

by:rrincones
ID: 39717617
I scanned with malwarebytes twice.  1st scanned resulted in 33 registry entries, 8 values, 15 folders, and 57 files, detected with items such as funmoods, whitesmoke, visual bee.  

2nd scan had 1 detection from vid-saver.

Prior to scanning, I went to add remove programs and uninstalled several free programs and toolbar addons.

I will try system restore.  I will have to remove those programs again, but I will check for internet connections prior to removing the programs.

By the way, there are 4 instances of explorer.exe running, each using 20 to 40 % of cpu.  And the dll's are for various programs.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:rrincones
ID: 39717625
Ive been monitoring explorer.exe with process explorer from sysinternals.  Every 10 minutes or so, all the dll's will end at the same time, then startup again after a few seconds.
0
 
LVL 59

Expert Comment

by:LeeTutor
ID: 39758266
I've requested that this question be deleted for the following reason:

The question has either no comments or not enough useful information to be called an "answer".
0
 

Author Closing Comment

by:rrincones
ID: 39758267
Sorry about the late update.  tdsskiller did the trick. after scanning the pc, no more internet ports opened up on their own.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

By default the complete memory dump option is disabled in windows . If we want to enable the complete memory dump for a diagnostic purpose, we have a solution for it. here we are using the registry method to enable this.
While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
This Micro Tutorial will teach you the basics of configuring your computer to improve its speed. It will also teach you how to disable programs that are running in the background simultaneously. This will be demonstrated using Windows 7 operating…
This Micro Tutorial will give you basic overview of the control panel section on Windows 7. It will depth in Network and Internet, Hardware and Sound, etc. This will be demonstrated using Windows 7 operating system.

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question