Suspicious Disk Activity

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SkunkMonkey, Jun 8, 2011.

  1. SkunkMonkey

    SkunkMonkey Private E-2

    First let me preface this by saying I'm far from a computer noob. I've been using computers since 1979 and have worked as a programmer for many of those years. I build my own PCs and know my way around hardware and Windows.

    Now, on to my problem. I noticed the other day that my hard drive light was blinking at 1 second intervals when system was at idle and nothing running. Looking at SysInternals task manager, I was unable to see a process that might be doing it and the only thing using CPU was services. I figured I had picked up some kind of malware/virus somehow. So I started the usual defensive maneuvers like running full A/V scan and SpyBot. These yeilded nothing unusual.

    In an effort to determine what was occurring, I tried SysInternals ProcMon and found that explorer.exe was walking the registry and trying to access shdocvw.dll. I've gone through all the remedies I know and have googled myself blue in the face trying to figure out what is happening.

    At this point I'm not sure if it's Malware, a Virus, or a bad Windows setting, but I'm down to my last possible solution, reinstalling Windows. Any help would be mucho appreciated.

    I've followed your Run Me First procedures and I'm attaching the log output of each tool as well as output from Procmon so you can see what lead me to believe something nefarious is afoot. I was unable to run MGTools for some reason. It just flashes a DOS box and dies. I have however, attached a HiJackThis log.
     

    Attached Files:

  2. SkunkMonkey

    SkunkMonkey Private E-2

    Additional Logs attached
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like to see the C:\MGlogs.zip. Please attach it for me?
     
  4. SkunkMonkey

    SkunkMonkey Private E-2

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But I do not wish for you to run any of the individual batch files. All that needs to be run is the C:\MGTools.exe (Double click to run or right click to run as admin if on Vista or Win 7) which then produces a C:\MGlogs.zip. Did you try this already? If so we will try debugging it.
     
  6. SkunkMonkey

    SkunkMonkey Private E-2

    After looking at these batch files it seems it will only work on a default installation of Windows. I've moved my Documents and Settings to drive D: and I install all my applications on drive E:. This seems to be causing the batch files to fail when they are hard-coded to drive C:.

    Specifically, it tries to copy and rename the Malware Bytes file in C:\Program Files and that's not where I've installed it. I am going to uninstall these utilities and try to install on drive C: to see if I can get it working.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK! Let me know how you get on. :)
     
  8. SkunkMonkey

    SkunkMonkey Private E-2

    Ok, everything ran as expected on the various instructional pages. Attaching newest set of files.

    I really hope we can figure out the problem. I had this happen several years ago and the only solution I found was a re-install.

    Thanks!

    Since I am limited to 4 attachments, here's the SUPERAntiSpyware log:
    ------------------------------------------------------------------------
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 06/08/2011 at 08:04 PM

    Application Version : 4.53.1000

    Core Rules Database Version : 7236
    Trace Rules Database Version: 5048

    Scan type : Complete Scan
    Total Scan Time : 00:41:27

    Memory items scanned : 446
    Memory threats detected : 0
    Registry items scanned : 5656
    Registry threats detected : 0
    File items scanned : 23540
    File threats detected : 0
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, I am not seeing any malware in those logs I'm afraid.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. SkunkMonkey

    SkunkMonkey Private E-2

    Ah crap. Thanks for the help anyway. Looks like I am just going to reinstall Windows, probably upgrade to Win7 while I'm at it.

    Cheers!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds