explorer.exe using over 70,000k of memory..Virus?

Fatal1ty

New member
Local time
6:15 AM
Messages
29
Location
Chester, UK
Hey im wondering if someone can give some advice as I think I might have a virus. I read this on bull-guard forum (my antivirus software)

The explorer.exe is a process; however, it is also a Trojan. cexx.org has an excellent removal process at this link: Advertising Spyware: DLDER.EXE, Explorer.exe trojan (ClickTillUWin)

We've found multiple infections in a few machines over the years. It's known as the dlder.exe Trojan and it drops another "explorer.exe" file in a separate folder, normally in 'C:\Windows\explorer\Explorer.exe'.

Please note that you have a legitimate original "explorer.exe" in 'C:\Windows\explorer.exe'

It also drops a startup file in your registry so it will run silently at startup...normally in your Local Machine Registry: [HKLM\SOFTWARE\games\Clicktilluwin]. However; we have also found the Clicktilluwin entry in ‘HKCU’ over the past few months. That said, you should do a search find on your total registry for the phrase 'Clicktilluwin'. Go to the link above and follow cexx.org's manual removal, then search your regedit for the 'Clicktilluwin' reg-key and you should be fine.

Anytime that you have explorer.exe running over....say....25,000K to 30,000K in the task manager, it's usually indicative of infection.

Hope this helps.

Max








Please can anyone give me any info? I am currently using bullguard anti virus registered and MBAM Free version
 

Attachments

  • explorer.jpg
    explorer.jpg
    164.7 KB · Views: 151

My Computer My Computer

At a glance

64BitIntel core I7 2600k (Stock)16GB G-Skill ripjaws 1600MHzZotac gtx 560 amp edition
Computer Manufacturer/Model Number
Custom
OS
64Bit
CPU
Intel core I7 2600k (Stock)
Motherboard
Asrock Fatal1ty z68 professional Gen3
Memory
16GB G-Skill ripjaws 1600MHz
Graphics Card(s)
Zotac gtx 560 amp edition
Sound Card
Asrock cougar point high definition
Monitor(s) Displays
LG Flatron W2261VP
Screen Resolution
1920X1080
Hard Drives
1TB Samsung HD103UJ 7200RPM
500GB TOSHIBA
500GB WESTERN DIGITAL
PSU
OCZ ModXtreme 700w Pro Modular Bronze certified psu
Case
sharkoon T9 red
Cooling
CiT Vantage liquid cooling system
Keyboard
Microsoft sidewinder x6
Mouse
roccat kone
Internet Speed
3mbps
It's relatively easy in this case. Open task manager> Right click on explorer.exe and choose properties> On the General tab, the Location should be C:\Windows (assuming C:\ is the drive where the OS is installed)

qzggba.jpg


You can also click on the details tab which should identify it as a Microsoft product.

rwj5v9.jpg


Mine is running at 51k to 52k, so take things you read with a grain of salt.

32znk9d.jpg


Usually there will be 2 explorer.exe's if there is an infected one, and the spelling will be slightly different, and it won't be located in the root of Windows. It may show up as being in C:\Windows\explorer\exporer.exe, for instance.

Resource usage will vary by machine. You can get more info using a program like Process Explorer, but it's hard to say exactly what is using resources. If you have windows customizations like shell32.dll enhancements, there will be increased usage.

When in doubt, scan with Malwarebytes, or other antivirus/antispyware applications.

A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
I havent got two explorer.exe and also scanned with malwarebytes and bull guard anti-virus and also superAntiSpyware and my pc came up clean. Don't know why it was using so much memory but thanks for the help.
 

My Computer My Computer

At a glance

64BitIntel core I7 2600k (Stock)16GB G-Skill ripjaws 1600MHzZotac gtx 560 amp edition
Computer Manufacturer/Model Number
Custom
OS
64Bit
CPU
Intel core I7 2600k (Stock)
Motherboard
Asrock Fatal1ty z68 professional Gen3
Memory
16GB G-Skill ripjaws 1600MHz
Graphics Card(s)
Zotac gtx 560 amp edition
Sound Card
Asrock cougar point high definition
Monitor(s) Displays
LG Flatron W2261VP
Screen Resolution
1920X1080
Hard Drives
1TB Samsung HD103UJ 7200RPM
500GB TOSHIBA
500GB WESTERN DIGITAL
PSU
OCZ ModXtreme 700w Pro Modular Bronze certified psu
Case
sharkoon T9 red
Cooling
CiT Vantage liquid cooling system
Keyboard
Microsoft sidewinder x6
Mouse
roccat kone
Internet Speed
3mbps
You can also always upload any suspect file to Virus Total for inspection. A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Doesn't seem unusual to me. For example, I opened Task Manager and explorer was just over 50k. I then opened Windows Explorer, bounced around some of my large drives, check some drive properties - every new action caused the task manager explorer memory to go up. In no time I was over 66K.

HOWEVER, when "left alone" for a while the explorer memory footprint does begin to drop.

Regards,
GEWB
 

My Computer My Computer

At a glance

Linux Mint / XP / Win7 Home, Pro, Ultimate / ...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
(7 different computers booting up to 10 systems)
OS
Linux Mint / XP / Win7 Home, Pro, Ultimate / Win8.1 / Win10
Other Info
Four desktops, two laptops, one notebook and one tablet
You cannot be serious....You seriously cannot be serious...my god I wish I had as much RAM as you...yet here you are complaining about 70 MBs of your RAM being used...You cannot be serious!

Hahaha lol yes. Never seen it use that much memory before though lol my bad
 

My Computer My Computer

At a glance

64BitIntel core I7 2600k (Stock)16GB G-Skill ripjaws 1600MHzZotac gtx 560 amp edition
Computer Manufacturer/Model Number
Custom
OS
64Bit
CPU
Intel core I7 2600k (Stock)
Motherboard
Asrock Fatal1ty z68 professional Gen3
Memory
16GB G-Skill ripjaws 1600MHz
Graphics Card(s)
Zotac gtx 560 amp edition
Sound Card
Asrock cougar point high definition
Monitor(s) Displays
LG Flatron W2261VP
Screen Resolution
1920X1080
Hard Drives
1TB Samsung HD103UJ 7200RPM
500GB TOSHIBA
500GB WESTERN DIGITAL
PSU
OCZ ModXtreme 700w Pro Modular Bronze certified psu
Case
sharkoon T9 red
Cooling
CiT Vantage liquid cooling system
Keyboard
Microsoft sidewinder x6
Mouse
roccat kone
Internet Speed
3mbps
Back
Top