Windows explorer non-responsive after 2 days

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by C1B3R5NYP3R, Jul 1, 2011.

  1. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Ok guys, I have a doozy. I recently helped a friend out with recovering some files. (attached their HDD as a slave to my pc) In the process norton 2011 detected some things in the files. It took care of them, or so I thought. Anyway, to go on with my issues. I have noticed after my pc is running for a couple of days windows explorer becomes unresponsive. For instance, I click on the IE icon on the task bar and the icon looks as though it is going to open (lines form around icon and is gray) then fades out like I never clicked the icon. Same with anything on my desktop regardless of file type. I restart my computer (usually forced restart) and all is ok for a few more days. I have done full system scans with norton and MBAM and it has not found anything. As for the items detected here is a list:

    (norton deleted these items I think)

    Bloodhound.Exploit.314
    Suspicious.Cloud.5
    Bloodhound.olexe
    Trojan Horse
    Packed.Generic.99
    armaccess.dll (Trojan.Gen)

    When trying to get a HJT log file, I am getting a pop up saying for some reason your system denied write access to the host file. gives a command line to try. Tried it but didnt see anything other than an example pop up.

    Ok now here are some issues I ran into while following the READ ME FIRST guide.

    I was running SAS and got a popup error stating an unexpected error has occured. I left it running overnight. The second time it finished and but when I went to run the cleanup my computer would not respond and would not finish the cleanup. The third time I used the portable version and kept an eye on it. Once it got into my S:\ drive it hung on a .dll file and I got the error yet again. Finally Ran the installed version on C drive only and was able to get a log file from that.

    Had a hard time with MG tools. Did not want to create a log file. After 3 or 4 attempts I went into the Tools folder and double clicked on one of the files in there. dont remeber the file but it was mentioned in the read me first guide. And it finally created the log file.

    I appreciate any help anyone can give. I am at a loss on this one.

    Thanks in advance......

    Specs:
    Windows 7 x64
    G. Skill 4GB (DDR2 800)
    2x 360 GB (raid0)
    1TB Seagate
    C2Q Q6600 2.40GHz
    DFI X48 T2R
    GTX460
    Tuniq 120 Extreme
    Antec TP-650
    hd dvd rom
    dvd drive
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Based on all of your logs being clean, I don't think you are having malware problems, but let's check a couple more scans to be sure.

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller



    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Here are the logs requested. Doesn't look like its infected. So what could be causing windows to act this way?
     

    Attached Files:

  4. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any number of things like:
    • Memory leak from some piece of software your run
    • hardware/software conflict ( i.e., driver issue )
    • hardware issue ( memory problem, overheating.... )
    You many want to try booting your PC in safe boot mode and let it run like that for a few days ( if that is how long it takes ) to see if it still occurs. If it does not, then you need to investigate which software that you load in normal mode but not in safe mode is a possible cause. Since you imply it takes a few days before it hangs, testing is going to be tedious/long.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  6. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Thanks again for the help. I have reset all my settings back. I was reading about turning off autorun. It seems there isnt anything on windows7. Does the steps for vista also apply for 7? I was looking at the update for vista but there is no mention for 7.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds