Re: 2 explorer.exe in my task manager

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 10/17/04


Date: Sat, 16 Oct 2004 21:52:29 -0400

I don't see a problem and think this is rather esoteric. Whether you have 'Explorer.exe'
loaded or 'explorer.exe' is not important. There is also nothing wrong with having 2
instances. Uppercase or lowercase first character.

As MAP noted, there are infectors that specifically use that name. Just to be on the safe
side...
1) Download the following three items...

         Trend Sysclean Package
         http://www.trendmicro.com/download/dcs.asp

         Latest Trend signature files.
         http://www.trendmicro.com/download/pattern.asp

         Adaware SE (personal free version)
         http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download sysclean.com and place it in that directory.
Dowload the signature files (pattern files) by obtaining the ZIP file.
For example; lpt202.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) Update Adware with the latest definitions.
3) If you are using WinME or WinXP, disable System Restore
        http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode
5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
        platform and clean/delete any infectors/parasites found.
        (a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
        Trend Sysclean utility and Adaware
7) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
        System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) If you are using WinME or WinXP, create a new Restore point
10) Please report back your results

Dave

"Christoph" <jcboget@yahoo.com> wrote in message
news:OR%23WLd%23sEHA.272@TK2MSFTNGP12.phx.gbl...
| I did some searching on google to see if people had a similar
| circumstance. However, what I found was that most people
| had an instance of 'explorer.exe' and 'Explorer.exe'. What I
| have is 2 instances of 'explorer.exe' in my task manager.
| Now, I know that there should only be one instance. So I
| am wondering where the other instance is coming from? I
| checked the registry keys
|
| HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
| HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
|
| but didn't find anything suspect. Also, this second instance
| does not seem to appear after I reboot but instead only after
| the system has been up and running for some time. Has any
| one else experienced this?
|
| thnx,
| Christoph
|
|



Relevant Pages

  • Re: 2 explorer.exe in my task manager
    ... If you are using WinME or WinXP, disable System Restore ... Reboot your PC into Safe Mode ...
    (microsoft.public.windowsxp.general)
  • Re: Download.Trojan
    ... If you are using WinME or WinXP, re-enable System Restore, reboot the PC ...
    (microsoft.public.security.virus)
  • Re: Notepad.exe not working properly ...
    ... If you don't have c:\i386 but have the winXP CDROM, ... |> 2) If you are using WinME or WinXP, disable System Restore ... |> 3) Reboot your PC into Safe Mode ...
    (microsoft.public.windowsxp.general)
  • Re: Request for Help VBS/Redolf.a virus
    ... | 5) If you are using WinME or WinXP, re-enable System Restore, reboot the PC ...
    (microsoft.public.security.virus)
  • Re: Lsass.exe replacement ?
    ... If you are using WinME or WinXP, disable System Restore ... Reboot your PC into Safe Mode ...
    (microsoft.public.windowsxp.security_admin)

Loading