Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

iexplore.exe stays active... 1

Status
Not open for further replies.

DaveRS575

Programmer
Aug 20, 2003
60
CA
Has anyone had this problem?

I open up explorer, and close it using the "X" top right, and for some reason iexplore.exe stays resident in memory and is holding anywhere from 23 to 30MB. Eventually, I cannot open another IE window until I kill that process. Once I kill it, everything is fine. Until I close the window again.

I am running Windows XP SP1 home edition and IE6 (6.0.2800.1106.xpsp2.030422-1633) I have applied all of the Windows update critical patches and bug fixes, but have not seen any change. I also have the most up to date Norton 2002 with live update and it has been completely scanned.

I have searched technet and other Microsoft resources to no avail. Any input would be appreciated.

Thanks in advance!

Dave

No rest for the Wicked.
 
It is lekely that some other process is using the iexplore.exe process. This is quite often something undesirable, but could be nothing to worry about! Download Hijack This from and generate a startup log from Misc Tools in the Config section. Then post that log here for assistance.

Greg Palmer

----------------------------------------
Any feed back is appreciated.
 
Thanks Greg,

Here is the startup text it generated..

I appreciate the help!

Dave




StartupList report, 11/10/2003, 4:18:08 PM
StartupList version: 1.52
Started from : C:\Documents and Settings\Technical Ecstasy\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\CFusionMX\runtime\bin\jrunsvc.exe
C:\CFusionMX\db\slserver52\bin\swagent.exe
C:\CFusionMX\db\slserver52\bin\swstrtr.exe
C:\CFusionMX\runtime\bin\jrun.exe
C:\CFusionMX\db\slserver52\bin\swsoc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\MSMGT.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Technical Ecstasy\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
hp psc 1000 series.lnk = ?
hpoddt01.exe.lnk = ?
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
AdaptecDirectCD = "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
NAV Agent = C:\PROGRA~1\NORTON~1\navapw32.exe
DellTouch = C:\WINDOWS\DELLMMKB.EXE
REGSHAVE = C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
WinStart001.EXE = C:\WINDOWS\System\WinStart001.EXE -b
MemoryMeter = C:\Program Files\MemoryMeter\MemoryMeter.exe
MSMGT = C:\WINDOWS\MSMGT.exe
WINSTA~1.EXE = C:\WINDOWS\System\WINSTA~1.EXE -b
ZingSpooler = C:\Program Files\Common Files\Zing\ZingSpooler.exe
nwiz = nwiz.exe /install

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
NVIEW = rundll32.exe nview.dll,nViewLoadHook

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\SSTEXT3D.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

Natural Language Navigation - C:\WINDOWS\System\BHO001.DLL - {60E78CAC-E9A7-4302-B9EE-8582EDE22FBF}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

--------------------------------------------------

Enumerating Task Scheduler jobs:

FRU Task #Hewlett-Packard#hp psc 1200 series#1062989708.job
ISP signup reminder 3.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM32\Macromed\Director\SwDir.dll
CODEBASE =
[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
CODEBASE =
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yinsthelper.dll
CODEBASE =
[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE =
[RdxIE Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\RdxIE.dll
CODEBASE =
[ZingBatchAXDwnl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\batchdwnl.dll
CODEBASE =
[Symantec RuFSI Utility Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
CODEBASE =
[MSN Chat Control 4.2]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MSNChat42.ocx
CODEBASE =
[WebLine Browser Integration Classes]
InProcServer32 = C:\WINDOWS\System32\MSJAVA.DLL
CODEBASE =
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE =
[Microsoft Office Tools on the Web Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\OUTC.DLL
CODEBASE =
--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

--------------------------------------------------
End of report, 7,651 bytes
Report generated in 0.125 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only


No rest for the Wicked.
 
You have a couple of Adware programs that you ought to remove both repated to MemoryMeter

MSMGT = C:\WINDOWS\MSMGT.exe
WINSTA~1.EXE = C:\WINDOWS\System\WINSTA~1.EXE -b


Download Spybot from and adaware from and run both of their scans.

Hopefully this should sort your problem out.

Greg Palmer

----------------------------------------
Any feed back is appreciated.
 
Greg,

Thanks a million. There was a ton of stuff on the machine. I cant believe how many to be honest. Scary.

Thanks you got my vote!

Dave

No rest for the Wicked.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top