My Docs showing up in task manager

Discussion in 'Malware Help (A Specialist Will Reply)' started by jaccav, Feb 13, 2008.

  1. jaccav

    jaccav Private E-2

    and I don't have My Documents open. The icon that shows next to it is a program icon, not the icon normally associated with My Documents. If I right click and choose go to process, it shows the running process as explorer.exe

    I'm concerned that this is a virus or malware that has woven itself into explorer. I've never seen it before on any computer when I've opened up task manager. Has anyone ever seen this before? Recommendations?

    I've run an antivirus scan and two different spyware scans.

    Thanks.
     
  2. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    I am assuming you mean it is open under the “applications” tab and not “processes”. I doubt it is malware but something more like My Documents is opening at start up minimized – or something odd like that.

    You can check this by running msconfig in the run box and looking for and looking for something calling My Documents from the start up tab.

    If you still think you have a malware issue – Please read the removal guide here:
    http://forums.majorgeeks.com/showthread.php?t=35407
     
  3. jaccav

    jaccav Private E-2

    Thanks for the idea. When I do as you directed, there isn't any MY Documents showing up. There is an unnamed item though. Anybody ever see that?

    Anyway, I'm still trying to figure this one out. I've never seen the My documents showing up as an application in task manager unless I have the folder open. Stranger still, the icon appears different than when I have My Documents legitimately open.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. jaccav

    jaccav Private E-2

    Here are the logs from Combo Fix, AVG and MGlogs as requested.

    In the next post, I'll attach a screen capture of what is showing up in task manager.

    Thanks!
     

    Attached Files:

  6. jaccav

    jaccav Private E-2

    Here is the screen capture of the Task manager with the mystery application named My Documents. I also have the normal My Documents open. You can see how the icons are different. When I run msconfig, I have a process with no name running. Should this be, or should I kill it?

    Anyway, thanks for any help you can give.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be a malware problem.


    Why does the below file name have all of those spaces inbetween the Carcamo and the 2.doc? Did you do this on purpose?
    Code:
    "C:\Documents and Settings\us\My Documents\"
    albaca~1.doc  Feb 13 2008       25600  "Alba Carcamo                                                                  2.doc"
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you receive a message saying it was successfully added to the registry. Tell me if you get this message.

    Now reboot

    Do you still see My Documents in Task Manager? Do you still see a process with no name in MSconfig?
     
  8. jaccav

    jaccav Private E-2

    The running program with no name no longer appears.

    The My documents application unfortunately remains.

    If it helps, when I highlight it and choose end process, all desktop icons, the quick launch bar and the task bar disappear, and I can't do anything until they come back-30 seconds later-when the damn my documents thing shows up again

    Very strange indeed.

    BTW...I do appreciate the assistance!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not say whether the registry patch added to the registry. I requested that you tell me if you received a success message.

    No it is not strange. It just means that when you end that process your Windows shell (that is explorer.exe) is getting killed for a short while before the system restores it.

    Let's try a couple more things:

    Run this Using Sophos Anti-Rootkit and attach the requested log.

    Now please download Silent Runner's
    • Save it to the desktop.
    • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
    • You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
    • Once you receive the prompt All Done!, open the text file on the desktop, copy that entire log, and attach it to your next message.
    NOTE: If you receive any warning messages from your antivirus or antispyware programs about a script trying to be run , please choose to allow the script to run.
     
  10. jaccav

    jaccav Private E-2

    Here are the two logs. Thanks again.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds