Computer Security & Viruses/Possible Virus?
Expert: Lorry - 10/15/2008
QuestionRelevant Information:
OS: Windows XP Professional Edition
2 GB RAM
System-Controlled Page File size
Norton 360 Anti-Virus Software
For the last 5 days or so, my computer's page file has slowly filled to capacity and essentially crashed the PC. Windows Task Manager reveals no obvious program consuming an abnormally large amount of memory. As i write this, the page file is growing, and in about 5 hours, it will maxed out at 5GB, and the PC will need to be rebooted again. My first thought was a memory leak, but then earlier today I observed more specific unusual behavior in the PC.
Today:
Norton found and disabled a tracking cookie. (The last malware file Norton has found on this PC was over 8 months ago.)
I found in task manager a process running that I've never seen before, 31jSjk2y.exe. It is in the sys32 folder, and I can find no information as to it's purpose online or otherwise.
IEXPLORE.EXE consistently opens, even after I end the process it will re-open after a brief delay, (not an actual IE window, but merely the process is activated and shown in Task Manager).
Note: Due to some troubleshooting of my own so far, after I disable 31jSjk2y.exe and then disable IEXPLORE.EXE, it STAYS closed.
This leads me to question if 31jSjk2y.exe is a virus, yet i have no reference to compare it to because i haven't found any information about it anywhere. Could you tell me what this file is and if it is a virus? If not, do you have any other suggestions as to the problem with my PC's Page File filling up?
I appreciate your help.
Tristan
AnswerHi Tristan,
Even though you Norton 360 installed, try using Internet Explorer, go to:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
Click the GO button, then under Virus Detection, click Start. You might be told that you need to download and install ActiveX Controls for the scan to work, answer Yes.
Write down exactly anything it finds, then go to:
http://www.symantec.com/search/ and do a search for what was found. Symantec usually has a removal tool and/or directions for removing manually. Make sure that you follow the instructions for removal, step by step, especially the part regarding disabling System Restore.
Hope this helps!
Lorry