Infection? explorer.EXE trying to access net

Discussion in 'Malware Help (A Specialist Will Reply)' started by garglesand, Jun 20, 2008.

  1. garglesand

    garglesand Private E-2

    Hi, every now and again explorer.exe tries to access net. I know its not proper file as denying it has no effect on browser.

    I've cleaned down pc as instructed from this site and attached the logs from the various programs
     

    Attached Files:

  2. garglesand

    garglesand Private E-2

    And the combofix log...


    Thanks for any help with this problem.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing wrong with Windows Explorer trying to access the network. You can even user it to browse the internet just like IE. If you block Explorer.exe from having network access you will sooner or later run into problems. Example: If you do file sharing between PCs on a network you will have an issue when you want to copy files between the PCs.

    You don't have any infections showing in your logs. You just have questionable copy protection software for games that you appear to be playing.
     
  4. garglesand

    garglesand Private E-2

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That thread was your thread and the infection shown in your HijackThis log in that original thread is no longer present in the logs you attached here. How many sites have you been working on because it appears that you did not complete the removal process at malwareremoval.com? Where/when did you remove it?
     
  6. garglesand

    garglesand Private E-2

    It must have ben removed during the removal process on your site here:
    http://forums.majorgeeks.com/showthread.php?t=139313

    Thanks for help.



    It was this bit that caused me to worry

     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your logs. It was not in any of the logs. The only other possibility would be Spybot but I doubt it would remove it and it was run after the first two tools which are more likely to detect it.

    That is a typcial blurb used when certain kinds of malware infections are observed. There are no real guarantees that a PC is 100% clean after malware cleaning procedures. If you use a PC for important work containing sensitive data, financial info....etc, the only true safe thing to do is erase everything with no backups and start over again. However in many cases this is not really required. You have to judge the sensitivity of the information on your PC and determine your own paranoia level and decide for yourself. Also, if a PC is contains sensitive information or is use for financial type transactions, it really would be in your best interest to use another PC to change ALL passwords and account information to be safe. Also you should check with banks, credit card companies.....etc for any illegal activity.

    Again these are all warnings to ensure safety. It does not mean that any sensitive info or passwords have been stolen. We just don't know that they have not been stolen and information just has not been used yet. This is the reason why things like the below have been written:

    http://www.dslreports.com/faq/10063
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds