Windows Explorer is now freeked out

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by oddjob777, Aug 29, 2004.

  1. oddjob777

    oddjob777 Private E-2

    I used your hijack last week and followed the instructions about making a backup of the log file before fixing. after the changes I noticed that my pc was acting funny so I went back and restored mychanges. That did not help. Here is what it is doing- rclick mycomputer-search =nothing,start-search-files and folders= nothing,windows update =nothing, some links on the internet the current window will freeze for about 1 min then reset(i can open another window). I read throught your software section and tried every thing that I could find that seemed to be related to this issue, so far no luck.

    Here is my systems Intell 2.4 gig, 1gig mem, two 74.5 gig HDD, radeon 9700 pro 128m video card, windows 2000 pro Sp4, last but not least "ONE FRIED BRAIN".

    Good luck Geeks: I am counting on you to help me win this war!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean you used HijackThis! Exactly what did you attempt to fix using it. Note, HijackThis is not the first step. It is the last step.

    Please work thru this all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal > If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
    Last edited: Aug 30, 2004
  3. oddjob777

    oddjob777 Private E-2

    I followed your advice and step by step for my 2000 pro
    1. windows was up to date before problem.
    2. Win 2Kpro does not have system restore.
    3. network security service is not running.
    4. Extensions are enabled.
    5. I have full ver. of norton that scan weekly.
    I used ccleaner, adware, and spybot and found 4 items to be fixed

    I then booted into safe mode and re-ran everything.

    My windows explorer search worked fine in safe mode, Restarted in normal mode and followed your ins for hijackthis. I then compaired my file on line and it was clean.

    I am stumped now any suggestions?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please tell me what problems still remain and post your HijackThis log as a text file attachment.
     
  5. oddjob777

    oddjob777 Private E-2

    "Problems" rclick mycomputer-search=nothing, rclick in empty window to past a copy will freeze that window, clicking some links on the internet will freeze that window, new windows can be opened and the frozen one will refreash at about 3 min. I am not able to attach the file because when I click that attachment button it freezes the window. windows update is still not working. I have also noticed that when I am vewing my c: drive and navagating through folders it will also freeze. It looks like I might have to do a reinstall of windows. I will send you my e-mail address
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try attaching your log as inline text (the old way). One of us will change it to an attachment for you.
    I need to see this log. Make sure you mention in your message just before the log that I asked you to post it this way due to having a problem posting attachments.
     
  7. oddjob777

    oddjob777 Private E-2

    Here is the fil that you ask me to post
     

    Attached Files:

    Last edited by a moderator: Sep 1, 2004
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As soon as I get a chance I will be moving this thread to the Spyware Forum were it belongs. So if you don't see it here, you know where to look.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that was your whole log? There was nothing further than the O4 lines?
    I don't see anything bad in this (other than a lot of stuff running).

    Try doing the below.

    Reset Web Settings by opening Internet Explorer. Then click Tools, Internet Options, Programs, and click the Reset Web Settings button. Then go back to the General tab and set your home page back to what you like (i.e., www.majorgeeks.com).
     
  10. oddjob777

    oddjob777 Private E-2

    I have reset my websettings several times. I also noticed today that my windows update quit working again.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was that your full log? Nothing beyond the 04 lines? Check again.

    Do you mean you just reset web settings now? Or before the HJT log you posted?
     
  12. oddjob777

    oddjob777 Private E-2

    Before During And After the install
     
  13. oddjob777

    oddjob777 Private E-2

    Yes that was my complete log
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What install? HJT does not install?

    Please answer all my questions?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What did you set your home page to?
     
  16. oddjob777

    oddjob777 Private E-2

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And if you run a HJT scan right now, do you see any R0 or R1 lines?
    And is there any thing after the O4 lines?
     
  18. oddjob777

    oddjob777 Private E-2

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And right now you still have the problems! Correct?

    Want to try shutting down some applications and see if the problem goes away?
     
  20. oddjob777

    oddjob777 Private E-2

    I am up for trying anything
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Bring up Task Manager by hitting CTRL-ALT-DEL then select the Processes tab. Click the Image Name column to sort the processes. Now one at a time select each of the below and end the process:

    GhostStartTrayApp.exe
    SMAgent.exe
    nopdb.exe
    stisvc.exe
    mspmspsv.exe
    qttask.exe
    InCD.exe
    GhostStartTrayApp.exe
    realsched.exe
    pptd40nt.exe
    ocrawr32.exe
    minimavis.exe

    See if you still have your problems
     
    Last edited: Sep 2, 2004
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If still having the same problems after ending that first group of processes, trying ending these too:
    vsaccess.exe
    pptd40nt.exe
    Disk_Monitor.exe
    launchpd.exe
    ATIX10.exe
    atiptaxx.exe

    Now do you still have the same problems.?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have a third and fourth set to try ending too. These are sequential (building off each other) so that as you kill each of these processes, you have fewere and fewer things left running. Until only bare bones items are left. I'm going to post those 3rd and fourth groups below. Note before doing the fourth group you must be offline and for even greater safe I recommend disconnect your modem or ethernet cable from your PC.

    Group 3
    =========
    Adobe Gamma Loader.exe
    IndexSearch.exe
    tfswctrl.exe
    sgtray.exe
    NeroCheck.exe
    qbupdate.exe
    OSA9.EXE
    type32.exe
    point32.exe
    pctspk.exe

    Now do you still have problems?

    Group 4
    ==========
    Only kill these if you are off line (disconnect your modem or ethernet cable from you PC)
    vsmon.exe
    zonealarm.exe
    navapsvc.exe
    NPROTECT.EXE
    SymTray.exe
    ntvdm.exe
    ccApp.exe
    ccEvtMgr.exe

    Now do you still have problems?

    Reconnect your cables and reboot.
    Now come back and tell me the results.
     
  24. oddjob777

    oddjob777 Private E-2

    I followed your advice and on the first group the following said access denied
    smagent.exe
    nopdb.exe
    stisvc.exe
    mspmspsv.exe
    Problem Still Here

    Group 2:
    Stop all listed processes no change

    Group3:
    tfswctrl.exe (access denied)
    all others stop no change

    Group 4:
    un-plug cable modem
    vsmon.exe (access denied)
    navapsvc.exe (access denied)
    NPROTECT.EXE (access denied)
    ccApp.exe (access denied)
    all others stoped

    Still No change
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what else to try here and I do not believe this is related to spyware. At least not from what we can see. It must be a configuration type problem. Perhaps you should try presenting this question with you exact problems in the Software Forum.
     
  26. oddjob777

    oddjob777 Private E-2

    Just wanted to let noy know that I reinstalled windows, It was less time consuming that troubleshooting. Thanks for all your help
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Thank for letting me know. Sorry we could not work this one out! Make sure you get the new install updated to all Microsoft's Critical Updates as soon as possible to help avoid additional problems.

    Here are some simple steps you can take to reduce the chance of infection in the future. I strongly encourage you to do them all.

    1. Visit Windows Update:
    Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly
    patched OS.
    a. Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp
    Do this at least once a month.
    b. Never add any site to your Trusted Sites Zone.

    2) Anti Virus: make sure you have one and keep it updated. Here are some good free ones:
    http://majorgeeks.com/download1968.html Avast
    http://majorgeeks.com/download886.html AVG
    The top two hands down. Better than Norton or McAfee!
    Only run ONE AV!

    3) Firewall: if you don't have one get one of these below. The last two are free versions:
    Don't care if your on dial up or High Speed....you must have a firewall
    http://majorgeeks.com/download738.html Kerio Personal Firewall
    http://majorgeeks.com/download3356.html Sygate Personal Firewall Free
    http://www.majorgeeks.com/download388.html ZoneAlarmFree

    4) Get a Temp File/Cookies/index.dat cleaner
    http://majorgeeks.com/download4191.html CCleaner (Crap Cleaner)

    5) SpyWare Prevention (These prevent, they are not scanners. Scanners are listed later.)
    http://majorgeeks.com/download2859.html SpyWare Blaster
    http://majorgeeks.com/download3045.html SpyWare Guard

    6) SpyWare Scanners/Removers
    http://majorgeeks.com/download2471.html SpyBot (Use the Immunize feature. I don't activate the TeaTimer)
    http://majorgeeks.com/download506.html Ad-aware SE
    http://download.lavasoft.de.edgesuite.net/public/plvx2cleaner.exe VX2 Cleaner Plug-In for Ad-Aware
     
  28. Agahnim

    Agahnim Private E-2

    Maybe AVG will help me on my stupid Trojan problem.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give it a try!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds