Вложений: 3
explorer.EXE intercept? I/O other always increasing
Hi AVZ,
I have a problem with explorer.EXE.
in task manager, the "I/O Other bytes" always increases by 4k every time task manger refreshes. all the time.
if I disconnect from the internet, it stops. the I/o is not reported or visible as network but I'm sure that is where its going. I suspect a hidden device sends my computer information out to the internet. this looks like a hidden trojan, but I am not an expert. but I am technically advanced.
my system is pretty clean except for uphclean which is resident. I have unloaded that and the problem still exists.
as long as the machine is connected to the internet, or a switch, or a router, the i/o other keeps increasing.
I have run with no page file and no restore. same problem.
problem does not happen in safe mode.
problem does not happen in safe mode with networking.
I followed all your instructions.
also scanned with mcafee stinger.
scanned with spybot 1.5 and ad-aware 2007 free.
I cant find it.
please give me a hand, I'm out of ideas.
Thank you,
James
no file in quarantine folder
I pasted that script to custom scripts and ran it.
the quarantine folder was created but no file appeared there.
I must be Own3d. here are the links.
[URL]http://i150.photobucket.com/albums/s89/computerpros/taskmgr1.jpg[/URL]
[URL]http://i150.photobucket.com/albums/s89/computerpros/taskmgr2.jpg[/URL]
look at i/o other. these two screen shots are only a few seconds apart.
the machine was idle except to copy to clip, paste, and save the files.
Thanks,
James
thanks for regmon and other ideas.
No its definately not malware. It's spyware/rootkit/idontknow.
It's hooked in good, but there it is in front of my face.
Thanks for the info on the regmon driver. I had to kill the file then rekill the legacy driver entry in the registry and make myself a debugger user and reboot before it would work. And now it does! Thank you for that. one less thing in the suspect list.
I considered {heavily} explorer was damaged in some way. through some research I was able to determine there are multiple versions of explorer. mine is a version which was issued to solve some race condition with notification balloons. I am able to verify size date time version... for my copy but can't verify its internal ntegrity...checksum or md5 or other means.
I ran that scf /sannow and It does not have a clue where to get files from. my stuff is in servicepackfiles and there is no reason to go for the cd. My cd is original before sp1 and Im not going that way ever again.
The closest I would come is to reinstall sp2.
I ran the combo fix but never got a log in an applet as they indicate,
what I got looked like boot.ini in a text file named CF-RC.txt.
That was clean. Combo-fix created some new folders with a bunch of
stuff in them, AND I now have a restore console from safe mode.
nifty. Also inherited two side affects, the clock format changed,
and it disabled the nic card. Those were easily fixed.
I didn't feel like joining another forum for that because
I've already described it all right here.
Thanks
James
legit.. possibly legit..and then again hafta prove it.
well it isnt any service, I can stop all those {sans rpc and a very few}
and the problem still persists.
Would you believe I've aleady been here too? got a bootlog of everything loaded and startup state. but could use a tool that sees which drivers
are actually used and then I can decide if I want to disable them...pretty dangerous, but hey I now have a recovery console to re-enable any that were needed...
was all over msinfo32
and performance counters
thought about autoruns but it shows them all even if not used on this box.
The feeling I get is a driver slaps data outbound to the internet; Because having disconnected the connection it stops dead right there, and the cpu useage of explorer.exe goes back to zero as well.
I agree that AVZ is a very well writen tool. I've never seen _anything_ do what it does before.
let me ask you something. you say your i/o other count is close. but is it dynamically updating while
you watch it, while the machine is idle, other than the task manager?
mine did not used to. only when I went for files/folders or invoked things did it change,
but never sitting there doing nothing.
my windows is a build 2600.xpsp_sp2_gdr.070227-2254.
Thanks
James
James