Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Explorer.exe is using 2GIGS of memory, virus?


  • Please log in to reply
7 replies to this topic

#1 Overboosted

Overboosted

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 26 April 2014 - 06:53 PM

Windows 7

There is an extra instance of explorer.exe, and it starts a few minutes after startup and runs the memory usage of it to over 2GB.

Been messing with malwarebytes and roguekiller and they find things but the problem doesn't go away.

 

Also my Chrome is hijacked by ask.com, I change everything to defaults and it just goes right back.

 

I think I have a trojan.


Edited by hamluis, 27 April 2014 - 07:31 AM.
Moved from Win 7 to Am I Infected - Hamluis.


BC AdBot (Login to Remove)

 


#2 Overboosted

Overboosted
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 26 April 2014 - 07:07 PM

Actually, if you let the computer go, more instances of explorer open and all run up over 500MB.

 

I try to kill them as soon as they start so malwarebytes can scan, but it's kinda hard.



#3 Overboosted

Overboosted
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 26 April 2014 - 08:02 PM

So by disconnecting from the internet, the "rogue" explorer.exe's do not start.

Now MBAR is running...



#4 Overboosted

Overboosted
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 26 April 2014 - 08:30 PM

so MBAR found 2 items, cleaned

adwcleaner found a bunch, cleaned

ran again, found a few, cleaned

turned on internet, still explorer.exe issue

shut off internet, running MBAM now, 48 issues so far



#5 Overboosted

Overboosted
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 26 April 2014 - 08:42 PM

so MBAM found 111 issues, cleaned, restart, same issue....please help!



#6 OldPhil

OldPhil

    Doppleganger


  • Members
  • 4,238 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Long Island New York
  • Local time:12:37 PM

Posted 27 April 2014 - 10:18 AM

Be patient the guys that know what they are doing are pretty busy!


Honesty & Integrity Above All!


#7 Overboosted

Overboosted
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 27 April 2014 - 03:55 PM

OK so now MS security finds rovnix.

Then I use windows defender and it finds the virus but cannot get rid of it.

Here is a screen shot for reference.

 

2nk18ad.jpg



#8 Overboosted

Overboosted
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 27 April 2014 - 04:14 PM

So Microsoft says to do this

 

For Windows 7:

  1. Put your Windows 7 media in the DVD drive and restart your PC
  2. Press any key when you are prompted.
  3. Select a language, time and currency, and keyboard or input method, and then click Next.
  4. Click Repair your computer.
  5. Select the operating system that you want to repair, and then click Next.
  6. In the SystemRecovery Options dialog box, click Command Prompt.
  7. Type Bootrec.exe /fixboot, and then press Enter.
  8. Remove the Windows 7 CD from your DVD drive and restart your PC

I did. 

Then reran windows defender cd and came up clean

running MS Security essentials now so we will see if that cleared it up






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users