What is the process of iexplore.exe in WinXP system?

  
                

When we use WinXP, when we open the task manager and want to check the task process, we will find that one process is running, that is, the iexplore.exe process. What is the process of iexplore.exe? Can you end it? Then let's take a look at the process of iexplore.exe with Xiaobian!

The steps are as follows:

1. What is iexplore.exe

iexplore.exe is the main program of Microsoft Internet Explorer. This Microsoft Windows app lets you surf the web and access the local Interanet network. This is not a pure system program, but if it is terminated, it can lead to an unknown problem. Iexplore.exe is also part of the Avant web browser, a free Internet Explorer-based browser. Note that iexplore.exe may also be the Trojan.KillAV.B virus, which will terminate your anti-virus software, and some Windows system tools, the security level of the process is recommended to remove.

Second, iexplore.exe virus judgment

This thing can be said to be a virus, it can be said that it is not a virus.

Because Microsoft's browser is IEXPLORE.EXE, it is generally installed with C:\\Program Files\\Internet Explorer. Then, if you find this file is in this directory, the general situation is not a virus, of course, does not include the situation that has been infected; there is a case, IEDPLORE.EXE is under C:\\WINDOWS\\system32\\, then this There are nine out of ten viruses.

Third, iexplore.exe process - virus

system process - disguised virus iexplore.exe

Trojan.PowerSpider.ac destruction method: password to solve V8. 10. Also known as "password stuttering"

Stealing user passwords, including: game password, LAN password, Tencent QQ account and password, POP3 password, Win9x cache password and dial-up account. The Trojan has a wide range of passwords and has a huge potential threat to Internet users.

Fourth, iexplore.exe virus phenomenon:

1. The system process has iexplore.exe running, note that it is lowercase letters.

2. Search the program iexplore.exe, not in the PROGRAMME folder under the C drive, but in the WINDOWS32 folder.

Five, how to clean up the iexplore virus

The first solution to the iexplore.exe virus::

1. Find iexplore.exe under C:\\WINDOWS\\system32 Psinthk.dll is completely removed.

2. Go to the registry and find HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run “mssysint”= iexplore.exe and delete its key value.

The second solution to iexplore.exe virus: you can reinstall the system, or you can repair it in winpe!

Sixth, iexplore.exe virus third solution (recommended):

Step 1, use the resource manager to view the process, pay attention to winrpcsrv.exe, winrpc.exe, wingate.exe, Syshelp.exe, rpcsrv.exe, iexplore.exe, winVNC.exe… are viruses (or backdoor software generated by viruses), and even other uncommon processes are possible. If you are not sure, find a server. The process on the monitor (the server should not be infected).

Step 2. End the process of the virus program (backdoor). For those that cannot be ended, you can use the pskill.exe in the attached file to end (command format & ldquo; pskill process name & rdquo;).

Step 3. Open “Service", in the list of services, there will be no "description" service to filter whether there is "Browser Telnet" “Event Thread” “Windows Management Extension” …… service, delete the

in the registry [HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BRWWTELK]

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\prom0n.exe]

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Windows Management Extension]

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Window Remote Service]

[HKEY_CURRENT_USER\\Software\\Microsoft \\Windows\\CurrentVersion\\Run(Run Services]

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run(Run Services]…… related health values ​​(and WinVNC processes, no notes What is the value of living?)

Step 4. Delete [HKEY_LOCAL_MACHINE\\SYSTEM\\Cur rentControlSet\\Services\\dll_reg]

[HKEY_CLASSES_ROOT\\Applications\\winrpc.exe]'s health value,

Step 5, and modify the right side of [HKEY_CLASSES_ROOT\\txtfile\\shell\\open\\command] The default health value is “ %SystemRoot%\\system32\\NOTEPAD.EXE %1”, at this time. The txt file can't be opened normally. You can click the right button of the text file to select other methods, and choose to use Notepad.

Step 6. Delete the following programs in the system32 directory (most executables are 78,848 bytes): winrpcsrv.exe, winrpc.exe, wingate.exe, syshelp.exe , rpcsrv.exe, iexplore.exe, prom0n.exe (note the middle is the number 0), irftpd.exe, irftpd.dll, iexplore.exe, reg.dll, task.dll, ily.dll, Thdstat.exe, 1 .dll , winvnc.exe

Step 7. Clear “C:\\Documents and Settings\\Default User (or Default UesrWINNT)\\Local Settings\\Temporary Internet Files\\Content.IE5” in addition to “desktop All files of .ini”, under the path, found some backdoor software.

Step 8. Close the full sharing of all directories! - This is the way to close the program and also be infected through the network.

Step 9. Restart the computer and see if there are similar processes, especially irftpd.exe. This program is automatically generated by the "Services" program in step 3 above.

About the process of iexplore.exe in WinXP system, I will introduce it to you in detail. If you still don't know what process iexplore.exe is, you can refer to the above content first, the above has detailed content, you will understand after reading.

Copyright © Windows knowledge All Rights Reserved