<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: C:\Windows\Explorer.exe is acting as a Virus, Windows 7	</title>
	<atom:link href="https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/feed/" rel="self" type="application/rss+xml" />
	<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/</link>
	<description>Troubleshooting Helps and Tips for the Geek</description>
	<lastBuildDate>Wed, 08 Jul 2015 15:37:17 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>
	<item>
		<title>
		By: noypi		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4961</link>

		<dc:creator><![CDATA[noypi]]></dc:creator>
		<pubDate>Wed, 08 Jul 2015 15:37:17 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4961</guid>

					<description><![CDATA[Thank you; the manual deletion of {F6BF8414-962C-40FE-90F1-B80A7E72DB9A} registry keys as well as of the folder worked for me.]]></description>
			<content:encoded><![CDATA[<p>Thank you; the manual deletion of {F6BF8414-962C-40FE-90F1-B80A7E72DB9A} registry keys as well as of the folder worked for me.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Merlin Halteman		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4831</link>

		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Tue, 26 May 2015 13:17:36 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4831</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4802&quot;&gt;taylor&lt;/a&gt;.

Hello Taylor, thanks for submitting a comment. I have had good success removing malware using RogueKiller. Try running that program and let me know your results.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4802">taylor</a>.</p>
<p>Hello Taylor, thanks for submitting a comment. I have had good success removing malware using RogueKiller. Try running that program and let me know your results.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: taylor		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4802</link>

		<dc:creator><![CDATA[taylor]]></dc:creator>
		<pubDate>Thu, 21 May 2015 19:49:53 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4802</guid>

					<description><![CDATA[One of our explorer.exe is  1,153,172 K in memory. We do have a folder called C:\ProgramData\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A} but it has no hidden URL&#039;s. We have tried MSSE and Avast already. We do not have any of the above registry entries in the solution posted above. We also don&#039;t have any duplicate .dlls of the names listed above. Any suggestions?]]></description>
			<content:encoded><![CDATA[<p>One of our explorer.exe is  1,153,172 K in memory. We do have a folder called C:\ProgramData\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A} but it has no hidden URL&#8217;s. We have tried MSSE and Avast already. We do not have any of the above registry entries in the solution posted above. We also don&#8217;t have any duplicate .dlls of the names listed above. Any suggestions?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Merlin Halteman		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4547</link>

		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Mon, 02 Feb 2015 23:10:54 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4547</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4546&quot;&gt;Peter&lt;/a&gt;.

Peter,

Thanks for taking time to relate your story and troubleshooting tips. I&#039;m sure someone will find this comment very useful! It is very encouraging to me, as the author when readers comment, thanks again!]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4546">Peter</a>.</p>
<p>Peter,</p>
<p>Thanks for taking time to relate your story and troubleshooting tips. I&#8217;m sure someone will find this comment very useful! It is very encouraging to me, as the author when readers comment, thanks again!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Peter		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4546</link>

		<dc:creator><![CDATA[Peter]]></dc:creator>
		<pubDate>Mon, 02 Feb 2015 22:29:22 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4546</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4545&quot;&gt;Peter&lt;/a&gt;.

Just gonna add some more detail in case this helps future readers.

I first noticed this through Comodo when I saw explorer.exe sending in/out small packages of data (66B and most of it out-going) that made me suspicious. Before reading this guide i was using Comodo Killswitch instead of Process Explorer/Monitor, which showed a child program of explorer.exe called explorer.exe. The child version was using up to 800MB of memory, whereas Task Manager showed it only using approx 200MB, and around 5-10% of my CPU. 

First response, Kill and Block process: Access Denied Seek Admin Assistance/Permission (I am the admin and only user).

Tried other things, &quot;Set priority&quot;, &quot;Properties&quot;, &quot;Delete&quot; all came up with Access denied.

Then tried &quot;Terminate Tree and Reverse&quot; Surprisingly this was allowed, it brought the explorer.exe down to 17MB mem usage (it then began climbing again) and it also revealed the child process cfmon.exe (Mentioned in your guide).

Poked around with this new process, couldn&#039;t figure out what to do next. Whacked it into google along with exploere.exe and high mem usage and found this page. Followed steps and both child programs are gone.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4545">Peter</a>.</p>
<p>Just gonna add some more detail in case this helps future readers.</p>
<p>I first noticed this through Comodo when I saw explorer.exe sending in/out small packages of data (66B and most of it out-going) that made me suspicious. Before reading this guide i was using Comodo Killswitch instead of Process Explorer/Monitor, which showed a child program of explorer.exe called explorer.exe. The child version was using up to 800MB of memory, whereas Task Manager showed it only using approx 200MB, and around 5-10% of my CPU. </p>
<p>First response, Kill and Block process: Access Denied Seek Admin Assistance/Permission (I am the admin and only user).</p>
<p>Tried other things, &#8220;Set priority&#8221;, &#8220;Properties&#8221;, &#8220;Delete&#8221; all came up with Access denied.</p>
<p>Then tried &#8220;Terminate Tree and Reverse&#8221; Surprisingly this was allowed, it brought the explorer.exe down to 17MB mem usage (it then began climbing again) and it also revealed the child process cfmon.exe (Mentioned in your guide).</p>
<p>Poked around with this new process, couldn&#8217;t figure out what to do next. Whacked it into google along with exploere.exe and high mem usage and found this page. Followed steps and both child programs are gone.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Peter		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4545</link>

		<dc:creator><![CDATA[Peter]]></dc:creator>
		<pubDate>Mon, 02 Feb 2015 21:41:50 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4545</guid>

					<description><![CDATA[Thank you so much, been reading up on this and have had nothing but suggestions that it was a completely normal process or that deleting your temp folder would work. 

After following your method malwarebytes found a fake trojan called FntCache.dll instead of your rdpencom.dll.

I love it when people are able to get one up on malware. You are a life saver and a genious, thanks again.]]></description>
			<content:encoded><![CDATA[<p>Thank you so much, been reading up on this and have had nothing but suggestions that it was a completely normal process or that deleting your temp folder would work. </p>
<p>After following your method malwarebytes found a fake trojan called FntCache.dll instead of your rdpencom.dll.</p>
<p>I love it when people are able to get one up on malware. You are a life saver and a genious, thanks again.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Tyler		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4522</link>

		<dc:creator><![CDATA[Tyler]]></dc:creator>
		<pubDate>Tue, 27 Jan 2015 20:04:18 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4522</guid>

					<description><![CDATA[Had a client that has DSL with a max 767kbps upload.  Sporadically the internet would seem to halt.  Traceroutes and ping test indicated that it was the DSL dropping.  Att found no issues.  Customer also stated that when this happened she was also having quickbook and data access issues to and from the server.

Remoted into her pc and discovered MASSIVE incomming/outgoing tcp connections being initiated from explorer.exe.  Found a few sights that pointed me towards c:/programdata.  Looked in there and found a alphabetsoup file that had a d3d10.dll (assuming this is directx) that identified it self as part of Microsoft IIS.  Looked in regedit for that alphabet soup name and found an entry where inprocserver32 was calling that file.  Did some searching on google and found your post.  Was able to run unlocker and rename the file then deleted it.  Manually deleted the entries from regedit (after backup ofcourse) then rebooted.  File was gone and system has thus been back to normal.  Ran malwarebytes and found other unsignificant entries (over 2000).

Probably never would have even known the issue was there had they not had really crappy DSL.

Good show my man.  A+]]></description>
			<content:encoded><![CDATA[<p>Had a client that has DSL with a max 767kbps upload.  Sporadically the internet would seem to halt.  Traceroutes and ping test indicated that it was the DSL dropping.  Att found no issues.  Customer also stated that when this happened she was also having quickbook and data access issues to and from the server.</p>
<p>Remoted into her pc and discovered MASSIVE incomming/outgoing tcp connections being initiated from explorer.exe.  Found a few sights that pointed me towards c:/programdata.  Looked in there and found a alphabetsoup file that had a d3d10.dll (assuming this is directx) that identified it self as part of Microsoft IIS.  Looked in regedit for that alphabet soup name and found an entry where inprocserver32 was calling that file.  Did some searching on google and found your post.  Was able to run unlocker and rename the file then deleted it.  Manually deleted the entries from regedit (after backup ofcourse) then rebooted.  File was gone and system has thus been back to normal.  Ran malwarebytes and found other unsignificant entries (over 2000).</p>
<p>Probably never would have even known the issue was there had they not had really crappy DSL.</p>
<p>Good show my man.  A+</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Rob Shore		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4487</link>

		<dc:creator><![CDATA[Rob Shore]]></dc:creator>
		<pubDate>Sat, 17 Jan 2015 04:27:33 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4487</guid>

					<description><![CDATA[Hey - I was having the exact same problem. My file was also not called rpdencom.dll - I forgot what it was, but it was also a valid windows file, but in the wrong location and had a different original file name. And the files were in the same hidden directory in programdata. 

Anyway, I followed your steps and it worked perfectly. I don&#039;t even know how long I&#039;ve had this problem, but I can&#039;t remember when my computer worked as well as it does now.  

I can&#039;t thank you enough. This article was brilliant.]]></description>
			<content:encoded><![CDATA[<p>Hey &#8211; I was having the exact same problem. My file was also not called rpdencom.dll &#8211; I forgot what it was, but it was also a valid windows file, but in the wrong location and had a different original file name. And the files were in the same hidden directory in programdata. </p>
<p>Anyway, I followed your steps and it worked perfectly. I don&#8217;t even know how long I&#8217;ve had this problem, but I can&#8217;t remember when my computer worked as well as it does now.  </p>
<p>I can&#8217;t thank you enough. This article was brilliant.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Merlin Halteman		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4484</link>

		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Fri, 16 Jan 2015 17:42:44 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4484</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4465&quot;&gt;Alex Romp&lt;/a&gt;.

Thanks for your comment. I&#039;m glad I was able to be of help!]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4465">Alex Romp</a>.</p>
<p>Thanks for your comment. I&#8217;m glad I was able to be of help!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Tips to Identify and Remove Poweliks Virus &#124; techspeeder		</title>
		<link>https://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/#comment-4483</link>

		<dc:creator><![CDATA[Tips to Identify and Remove Poweliks Virus &#124; techspeeder]]></dc:creator>
		<pubDate>Fri, 16 Jan 2015 17:40:27 +0000</pubDate>
		<guid isPermaLink="false">http://techspeeder.com/?p=1256#comment-4483</guid>

					<description><![CDATA[[&#8230;] more new malware that is hitting computers today. Thankfully there is a tool that can remove this one (or at least in my case). This blog post is about the Poweliks virus. You can find more detailed [&#8230;]]]></description>
			<content:encoded><![CDATA[<p>[&#8230;] more new malware that is hitting computers today. Thankfully there is a tool that can remove this one (or at least in my case). This blog post is about the Poweliks virus. You can find more detailed [&#8230;]</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 

Served from: techspeeder.com @ 2026-07-22 04:00:43 by W3 Total Cache
-->