System Explorer Crash

Hello, yesterday i sudenly had Explorer of my system crashing
(giving the message “Explorer found a problem and have to be closed”).

I scaned with Avast and Malwarebytes to see what could be the problem but
only “Spybot Search and Destroy” found a trojan that was probably messing with my system explorer?
Seems i have an unknown spyware around…

Everytime i open the Recycle or open a folder, the Explorer gives an error message
saying it found a problem and will close, maybe i should use SuperAntiSpyware too…?

Here is the report in detail of the trojan found by spybot: (but its probably another unknown spyware…)

This might be an S&D false positive, see http://www.threatexpert.com/files/eiunin21.exe.html, so you need to confirm the detection, see below.

Though there are other hits on this file name, that give a different story, so confirmation is essential.

Eiunin21.exe is Trojan/Backdoor. Kill the process eiunin21.exe and remove eiunin21.exe from Windows startup

Thought it seems strange it would have this impact on the recycle bin or opening folders.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page.

Program & Tutorial - Also useful as a diagnostic tool - [url=http://filehippo.com/download_hijackthis/][b]FileHippo Download - HiJackThis[/b][/url] and post the contents of the HJT log file here. - HJT Information [url=http://www.bleepingcomputer.com/forums/tutorial42.html][b]HiJackThis Tutorial[/b][/url].
Download and run HJT and post the contents of the log file (cut and paste or attach the log file) into this topic, you may need to split it over two or more posts depending on how large it is.

>>>>
Yes I think you should also run SAS and MBAM (again) but from safe mode.

Ok i started with SuperAntiSpyware and detected this:

2 Registrys

Summary : Rootkit.TDSServ

Company : Unknown/Varies

Description : Rootkit.TDSServ-Trace.Process

Now going to use Hijackthis and post here the log
(only experienced people can tell me what to remove ._. with this)

Log updated on Next post*

Hi Otaku Ichise,

I would like you to fix this one: R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com
It is flagged is Adware-Sweetbar,
The removal of mDNSResponder.exe because it connects out to the Internet is optonal, it will free some memory resources, and will make the computer react better. It is not malware:
removal - it’s not part of windows, if you’ve installed photoshop cs3 it comes with that, there’s a tool TurnOffBonjour that can disable it, download it from here > http://download.gizmoproject.com/jasmine/TurnOffBonjour.exe

polonus

Thanks^^ done everything, just didnt understood this part:

The removal of mDNSResponder.exe because it connects out to the Internet is optonal, it will free some memory resources, and will make the computer react better. It is not malware:

Your telling me to remove that with some other program or something? i didnt find that in the log.

Thanks very much again for the support.

Editing the HJT log (stripping out the header info) doesn’t help us to help you as it provides useful information.

Your JAVA is way out of date and as such vulnerable to exploit.
Ensure you have the latest version of JRE (JAVA Runtime Environment) because older versions can be vulnerable to malware. First remove All Older Versions From Add/Remove Programs.
Then get the latest update from here http://java.sun.com/javase/downloads/index.jsp
Or JRE version 6 update 11 http://www.majorgeeks.com/Sun_Java_Runtime_Environment_d4648.html

Close all browser windows, run HJT again.
Fix:
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
See, http://www.mywot.com/en/scorecard/sweetim.com.

– TDSS Rootkit - http://www.malwarebytes.org/forums/index.php?showtopic=7194 - Spyware.ISpynow may also be associated with this. Also see http://forum.avast.com/index.php?topic=40618.0
Also try

Another way to get around the inability to access your antivirus program is to check your system for the presence of a particular rogue device driver:

• Step 1: Click Start, Control Panel, Performance and Maintenance (in Categories view), System.
• Step 2: Select the Hardware tab and click Device Manager.
• Step 3: Choose the View menu and select Show hidden devices.
• Step 4: Scroll to the Non-plug and play drivers section and expand the tree.
• Step 5: If you see an item labeled TDSSserv.sys, right-click it and select Disable.

After you reboot your computer, you’ll be able to access your antivirus program and browse to anti-malware sites to remove the pest from your PC. Once you’ve cleaned your system, make certain that you update your antivirus software every day to avoid reinfection.

Ok here is updated and complete log now, i did everything as you said and now going to Check TDSS Rootkit and the quoted you mentioned to try too.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:45:17, on 13-02-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Java\jre6\bin\jqs.exe
C:\Programas\Microsoft LifeCam\MSCamS32.exe
C:\Programas\PC Tools Firewall Plus\FWService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Programas\PC Tools Firewall Plus\FirewallGUI.exe
C:\WINDOWS\vVX3000.exe
C:\Programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Programas\Internet Explorer\iexplore.exe
C:\Programas\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programas\Free Download Manager\iefdm2.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [VTTimer] VTTimer.exe
O4 - HKLM..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM..\Run: [00PCTFW] “C:\Programas\PC Tools Firewall Plus\FirewallGUI.exe” -s
O4 - HKLM..\Run: [lifeCam] “C:\Programas\Microsoft LifeCam\LifeExp.exe”
O4 - HKLM..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM..\Run: [SunJavaUpdateSched] “C:\Programas\Java\jre6\bin\jusched.exe”
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [MsnMsgr] “C:\Programas\Windows Live\Messenger\msnmsgr.exe” /background
O4 - HKUS\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SERVIÇO LOCAL’)
O4 - HKUS\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘Serviço de rede’)
O4 - HKUS\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘Default user’)
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Programas\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Programas\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Programas\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Programas\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230220920484
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1230220905218
O20 - Winlogon Notify: !SASWinLogon - C:\Programas\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programas\Ficheiros comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programas\Java\jre6\bin\jqs.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Programas\PC Tools Firewall Plus\FWService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


End of file - 6437 bytes

My great friends, this is like taking a shot in the Dark :-\

MBAM and Avast doesnt detect anything, only SperAntiSpyware could detect those 2 registrys.

IE Explorer or Firefox worked fine while my system = everything is up to date.

I only recieve a crash on my system explorer if i go to control panel (closing it) wich gives me the message “explorer found a problem and it will close” same goes if i open a folder and close it (by clicking close on top window of the folder) same will hapen.

Im going to scan again with SAS that detected 2 Registrys “Rootkit.TDSServ-Trace.Process” and see if its still there too…

Ok i even scaned again with SAS and theres nothing detected on my system, theres single nothing i can detect and this still hapens when i open folder/ close it or go control panel/ close it.

Any other idea to what this can be ??? ??? ???

Hi Otaku Ichise.

If you encounter tdsserv without a bootable antimalware disc you can use GMER to find, disable and delete it, please follow the removal instructions for this nasty vundo variant here:
http://www.geekstogo.com/forum/Adware-Vundo-Variant-and-Rootkit-TDSServ-t221340.html

polonus

The additional information I offered was basically to check if there might be anything else there. perhaps something that might possibly cause the issues you mention with the explorer crash.

So it looks like SAS was cleaning up remnants from the registry, which without any associated files aren’t a problem. However, since this is rootkit related I would suggest trying these tools.
Also see, anti-rootkit, detection, removal & protection http://www.antirootkit.com/software/index.htm. Try these as they are some of the more efficient and user friendly anti-rootkit tools.

Did you pay a visit to the Secunia software inspector site ?

Hi DavidR and Otaku Ichise,

Haven’t you forgotten the mention the best anti-rootkit tool, IceSword, download from here:
http://majorgeeks.com/Icesword_d5199.html

polonus

I haven’t forgotten any anti-rootkit, just that the greatest majority are very complex and user unfriendly and require a degree of user knowledge or they could do some serious damage.

As for the best I would think that would be GMER but that isn’t too user friendly either. Or even RootkitRevealer also unfriendly.

The three suggested are of the more user friendly ones with any known degree of success.

Yes only 3 or 4 things were outdated, im going to try those sugestions now, its so freaky weird when we cant even detect this nasty unknown thing :o

maybe this can help…

online virus scanner… with many antivirus… such as KAV, AVG, ZA, BitDefender

http://scanner.fudsonly.com/

Sorry but I don’t see how this would help the original posters problem.

It also has a script association to this IP 64.22.126.18 and there is nothing more suspicious as hiding behind an IP address rather than a domain name (I wonder what they are trying to hide). Doing a whois search on that IP times out without result.

Not to mention there doesn’t seem to be any language choices.

Ok since i was tired already of not detecting anything anymore (hopefuly it should have been free from spyware)
I went to search more info by typing on google “explorer crash by closing control panel” and found this:
http://www.helpwithwindows.com/techfiles/explorer-crashes.html

seems an unknown shell was screwing my system everytime i would close a folder, at least it stoped hapening now by disabling this unknown extension o.o; (my good god it seems finaly fixed my problem)

I still am very thankfull for the help as i still had javascript out of date and all
Thanks for the help Polunos andd DavidR :slight_smile:

You’re welcome.

I didn’t think the folder issue in this particular case was malware related as it seemed so out of context, as malware really doesn’t want to draw attention to itself in this way; although it does happen, but with the battery of scans you did, that was more or less ruled out.

Good job in tracking it down though and this may help others in the future.