Question about Microsoft Windows XP Home Edition

1 Answer

IExplorer.exe -virus taking all my cpu power

How do I get rid of this trojan? There are several IExplorer.exe instances running in taskmgr. Can not stop the process - it returns

Posted by on

1 Answer

  • Level 3:

    An expert who has achieved level 3 by getting 1000 points

    Superstar:

    An expert that got 20 achievements.

    All-Star:

    An expert that got 10 achievements.

    MVP:

    An expert that got 5 achievements.

  • Microsoft Master
  • 2,794 Answers

You will probably have to go to the store and pick up an anti virus program such as Norton or McAfee.

Unless you can download one.

Posted on Jul 15, 2008

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

What is 'vmhost.exe*32' and is it necessary?? Its using upwards of 70 CPU Usage making my pc VERY sluggish.


The file VMHOST.EXE is identified as the Trojan Program that is used for stealing bank information and users passwords. DO NOT PUT ANY PERSONAL INFO IN ANYWHERE. Run virus scans or take to a professional

Jul 01, 2014 | Acer Aspire Computers & Internet

Tip

Trojan Horse Removal


A virus is program that has malicious content in it and replicates itself and a Trojan horse is program that will only work if the user executes it. Sometimes, a Trojan horse covers itself as a fake folder while in fact, it's an .exe file.
The good thing about Trojan horse is that it is not that hard to get rid of them. But the bad thing about Trojan horse is that it is a little bit difficult to find them.
Although, it does not corrupt files or delete data stored on your hard disk until you execute it. Once executed, it will allow the hackers to indentify your credit card number, social security number, bank account details or some other private information.
You can delete or remove the hidden Trojan horse with the help of antivirus software. Either, you can also try the manual process to delete it or you can follow these steps:
STEP 1 Open the System Information Utility (msinfo32.exe). You can find the System Information Utility by typing “msinfo32.exe” in ‘Run’. This program lists all the processes running on any Windows system, even those processes that are hidden from the task list. Now open your virus scanner and run the executable or .dll through it.
STEP 2 Open your antivirus software and run a virus scan. If you don't have a antivirus software installed, download AVG Anti-Virus Free Edition 7.5. And run a scan using it. After the scanning process is completed, delete the value that was detected from the registry (before doing this step, take a backup of the registry files):
A) Click ‘Start’ > ‘Run’.
B) Type "regedit".
C) Click "OK".
D) Go to the subkey:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServices
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices

E) Now delete any value from the right pane that was detected during the scan process.
F) Exit the Registry Editor.

on Mar 16, 2010 | Computers & Internet

2 Answers

Is the file wmipruse.exe a virus or something that can be used to disrupt my laptop?


To avoid stopping all the services when a provider fails, providers are loaded into a separate host process named Wmiprvse.exe. Multiple instances of Wmiprvse.exe can run at the same time under different accounts: LocalSystem, NetworkService or LocalService. The WMI core WinMgmt.exe is loaded into the shared Local Service host named Svchost.exe.
Note: wmiprvsw.exe is the Sasser worm!
Note: The wmiprvse.exe file is located in the folder C:\WINDOWS\System32\Wbem. In other cases, wmiprvse.exe is a virus, spyware, trojan or worm!

May 25, 2014 | Microsoft Windows 7 Ultimate for PC

1 Answer

My dell mini is displaying lsass.exe - system error everytime i boot it up


HI gafleming27...

lsass.exe is a process which is registered as a trojan. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system.
Do the following to get rid of the trojan
*********************************************************************************************************************
To remove a virus,trojan,worm,etc from your computer...do it the EASY way...let someone else do it for you.
Start your computer, as the computer is starting keep tapping the F8 Key.
This will start the computer in the Safe Mode.
Once in the safe mode go to the following webage below and download,install, and run Microsoft Safety Scanner for FREE.
Once you run the Microsoft Safety Scanner (it may take quite a while depending on the size of your hard drive) it will remove all the virus's,trojans,worms,etc it finds, if it does not completely remove them all you will be given a chance to chat with a Microsoft Professional thru a pop open window and he will take control of your computer (with your permission) and finish removing all the rest of the virus's, trojans, or worms that are on your computer for FREE!! Can't beat FREE!!
Please take time to rate me thumbs up
http://www.microsoft.com/security/scanner/en-ca/default.aspx

Sep 10, 2011 | Dell Inspiron Mini 10 Notebook

2 Answers

Hi! my comp is nfected with a trojan masquerading as a security tool. it keeps popping dlhost.exe is infected with virus DOS.Jeff.812 this worm is trying to send our credit card details using dlhost.exe...


First try this but be careful:
To remove Trojan, you must first stop any Trojan processes that are running in your computer's memory. To stop all Trojan processes, press CTRL+ALT+DELETE to open the Windows Task Manager. Click on the "Processes" tab, search for Trojan, then right-click it and select "End Process" key.

To delete Trojan registry keys, open the Windows Registry Editor by clicking on the Windows "Start" button and selecting "Run." Type "regedit" into the box and click "OK." Once the Registry Editor is open, search for the registry key "HKEY_LOCAL_MACHINE\Software\Trojan." Right-click this registry key and select "Delete."

Finally, to completely get rid of Trojan, you must manually remove other Trojan files. These Trojan files can be in the form of EXE, DLL, LSP, TOOLBAR, BROWSER HIJACK, and/or BROWSER PLUGIN. For example, Trojan might create a file like
%PROGRAM_FILES%\Trojan\Trojan.exe. Locate and remove these files.

OR

If you can pass to the Windows interface you can run a Trojan remover like this one Trojan Remover at cNET. If not do it manually, instructions HERE

If your OS is Windows go to this link by Microsoft Online Scanner
also this one is a good one from TenMicro HouseCall

Oct 03, 2010 | Intel Computers & Internet

8 Answers

I have virus av.exe and cannot remove it


This trojan runs as a rootkit, so you won't see it when it's running. It is a single file in C:\Users\username\AppData\Local (Vista), or C:\Documents and Settings\username\Local Settings\AppData (XP), It is marked as a system file, so you'll need to use the Folder Options in the control panel, to unhide hidden and system files and folders. As I said, with the rootkit loaded, you still won't see it there until you unload it. It runs by changing the registry so that any .exe run, will instead load the trojan. Attempts to run Internet Explorer or Mozilla Firefox will also instead run it. If you delete the file, or your antivirus finds it and deletes it, the changes to the registry will mean that from then on, whenever you try to run a program, you'll get a windows message asking you to select the file you want to use to open the .exe. (if this is the case, you'll need to use regedit in safe mode with command prompt, or rename regedit.exe to regedit.com).

To defeat the trojan, you must undo the registry changes, then reboot to reveal the file, then delete it. Here's how.

Run regedit. The trojan will load and give you all the fake warnings hassle. Do Ctrl-Alt_Del, and find the process 'av.exe'. End the process. Now in the registry editor, search for 'av.exe'. You should find a section HKEY_CLASSES_ROOT\.exe, where the (Default) REG_SZ has been set to 'secfile'. Edit this back to 'exefile'. Keep searching and you'll find HKEY_CLASSES_ROOT\secfile. Delete the whole secfile section. Keep searching - you'll find the odd line where it may be a recently 'searched for' item, where you can just delete the line, and you'll find it in a command line to run Internet Explorer. The full path to the trojan will be specified before the path to Internet Explorer. Edit this line to remove the path to the trojan, leaving just the path to Internet Explorer. A similar edit may be required for Mozilla Firefox. Find any other occurences of av.exe and deal with them in the same way.

Now, reboot the PC, and the trojan will not start up. Display system and hidden files, then go to the location of the trojan. Now you can see the little swine. Delete it, and empty the recycle bin.

Problem solved.

Enjoy!

Feb 07, 2010 | ASUS Eee PC 900 Notebook

4 Answers

Trojan virus on new computer


Do a virus scan and then remove the virus/trojan

If your saying as soon as you turned on the new pc this trojan warning appeared i would take it back
let me know

Mar 08, 2009 | Dell Inspiron 1525 Notebook

1 Answer

Acer Laptop - virus


try to boot in safe mode. if it does not work :
try 2 get a norton antivirus on DVD/CD. 2008 or 2009 edition.
and auto start setup will detect the virus and remove it.

if it still not solves ur problem insert ur vista installation disk and autorun Vista setup will start. Format ur drive when setup asks you.

Jan 10, 2009 | Acer Computers & Internet

1 Answer

Unknown file


In software Svchost.exe is a generic host process name for services that run from dynamic-link libraries (DLLs) within the Microsoft Windows operating system.
At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. Multiple instances of Svchost.exe can run at the same time. Each Svchost.exe session can contain a grouping of services. Therefore, separate services can run, depending on how and where Svchost.exe is started. This grouping of services permits better control and easier debugging, but it also causes some difficulty for end users wishing to see the memory usage or vendor legitimacy of individual services and processes. End users in Windows XP Professional (and derivatives, such as Windows Server 2003 and Windows XP Media Center Edition) can run the following command at the system prompt to get a breakdown:
tasklist /svc /fi "imagename eq svchost.exe" (NB: This command does not work in Windows XP Home.)
Due to being widespread among running processes, svchost.exe has long been a common disguise used by malware to hide its presence from the user. (One of the common trojan horses deceptively uses scvhost.exe). Users may then run tasklist with no arguments and match the reported PIDs with the previously shown Svchost instances. If memory usage appears abnormal, the user can look up the service names shown by their command on the internet to see if it is a known service or malware.
The Svchost.exe file is located in the %SystemRoot%\System32 folder. The main registry key involved at bootup is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost (values in this key will show the user at least a partial list of the actual processes behind instances of svchost).
The 30 April, 2007 release of WSUS 3.0 led to reports of svchost.exe issues, including 100% CPU usage, memory hogging, and excessive laptop fan/power usage.[1]

[edit] See also

Oct 29, 2008 | Microsoft Windows Server Standard 2003 for...

1 Answer

Svchost


"Svchost.exe" (Generic Host Process for Win32 Services) is an integral part of Windows OS. It cannot be stopped or restarted manually. It manages 32-bit DLLs and other services. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. In normal conditions multiple instances of Svchost.exe run at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging. The svchost.exe file is located in the folder C:\Windows\System32. In other cases, svchost.exe is a virus, spyware, trojan or worm! To detect if it's a virus sometimes it will add letters to the Svchost to read thus SSVCHOST or SVCCHOST or something like that, thus making multiple services to run and slow down the computer, if that is the case the current antivirus you are using is not removing the virus, this can be done in the registry, its a complicated process if you do not know how to do it, so i would suggest you purchase a registry cleaner. NOTE: remember to backup the registry before you clean it

Aug 15, 2008 | Microsoft Windows XP Professional

Not finding what you are looking for?
Microsoft Windows XP Home Edition Logo

Related Topics:

102 people viewed this question

Ask a Question

Usually answered in minutes!

Top Microsoft Computers & Internet Experts

micky dee

Level 3 Expert

2642 Answers

Les Dickinson
Les Dickinson

Level 3 Expert

18354 Answers

Brian Sullivan
Brian Sullivan

Level 3 Expert

27725 Answers

Are you a Microsoft Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...