Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Windows explorer steals focus on "p" keystroke: infection?


  • Please log in to reply

#31
clearly

clearly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Hi Ron,

I ran the SIW software, temperatures are in the attached image (I couldn't extract a text log, sorry). I watched three minutes of a video and the only change I noticed was the temperature of the two cores went up slightly and seemed to be stable at either 73'C or 74'C. I'm not sure if any of this is normal.

I think it's worthwhile me re-posting my investigations from my longer post yesterday. If you've already read this and I added nothing useful then please ignore.

Thank you,
Morgan

------------------ repost ------------------------

Posted Yesterday, 07:37 AM
Hi Ron,

Thank you for your help.

1. I have run chkdsk on my C:\ drive, log follows:

Event Type: Information
Event Source: Winlogon
Event Category: None
Event ID: 1001
Date: 2011-03-15
Time: 12:24:37 AM
User: N/A
Computer: MORGAN
Description:
Checking file system on C:
The type of the file system is NTFS.
Volume label is Local Disk.

A disk check has been scheduled.
Windows will now check the disk.
Cleaning up minor inconsistencies on the drive.
Cleaning up 139 unused index entries from index $SII of file 0x9.
Cleaning up 139 unused index entries from index $SDH of file 0x9.
Cleaning up 139 unused security descriptors.
CHKDSK is verifying file data (stage 4 of 5)...
File data verification completed.
CHKDSK is verifying free space (stage 5 of 5)...
Free space verification is complete.

90886288 KB total disk space.
80836704 KB in 188218 files.
81308 KB in 16498 indexes.
0 KB in bad sectors.
247020 KB in use by the system.
4096 KB occupied by the log file.
9721256 KB available on disk.

4096 bytes in each allocation unit.
22721572 total allocation units on disk.
2430314 allocation units available on disk.

Internal Info:
b0 9d 03 00 b6 1f 03 00 17 7e 04 00 00 00 00 00 .........~......
bb 1d 00 00 02 00 00 00 8a 08 00 00 00 00 00 00 ................
e0 40 85 13 00 00 00 00 4a 5c fb da 00 00 00 00 [email protected]\......
2a 07 14 1f 00 00 00 00 50 41 e4 e2 0b 00 00 00 *.......PA......
bc 2a e2 21 01 00 00 00 6c 0e 31 19 0e 00 00 00 .*.!....l.1.....
99 9e 36 00 00 00 00 00 a0 39 07 00 3a df 02 00 ..6......9..:...
00 00 00 00 00 80 e1 45 13 00 00 00 72 40 00 00 .......E....r@..

Windows has finished checking your disk.
Please wait while your computer restarts.


For more information, see Help and Support Center at

http://go.microsoft....ink/events.asp.

I have previously noted disk errors in my Event Viewer. However, these errors appear to occur at random across all my drives. They began occuring even on a new 2TB purchased four months ago. I downloaded various manufacturers low-level hard drive checker utilities and scanned exhaustively all my drives. No errors were ever found, yet the event log still has disk errors to this day. There are 18 such errors from the 8th of March until the 14th of March. Here is the most recent error in the "System" section of the Event Viewer:

Event Type: Warning
Event Source: Disk
Event Category: None
Event ID: 51
Date: 2011-03-14
Time: 05:13:51 AM
User: N/A
Computer: MORGAN
Description:
An error was detected on device \Device\Harddisk4\D during a paging operation.

For more information, see Help and Support Center at http://go.microsoft....ink/events.asp.
Data:
0000: 03 00 68 00 01 00 b6 00 ..h...¶.
0008: 00 00 00 00 33 00 04 80 ....3..€
0010: 2d 01 00 00 00 00 00 00 -.......
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: 4d 5c 25 00 00 00 00 00 M\%.....
0030: ff ff ff ff 03 00 00 00 ÿÿÿÿ....
0038: 40 00 00 09 00 00 00 00 @.......
0040: 00 20 0a 12 40 03 20 40 . ..@. @
0048: 00 10 00 00 0a 00 00 00 ........
0050: 00 00 00 00 60 9d 69 89 ....`�i‰
0058: 00 00 00 00 30 aa 0a 8a ....0ª.Š
0060: 00 00 00 00 87 fe 55 00 ....‡þU.
0068: 28 00 00 55 fe 87 00 00 (..Uþ‡..
0070: 08 00 00 00 00 00 00 00 ........
0078: 00 00 00 00 00 00 00 00 ........
0080: 00 00 00 00 00 00 00 00 ........
0088: 00 00 00 00 00 00 00 00 ........

Strangely, my DVD drive/burner has become rather unreliable of late, going back some two or three months. I had to trash several attempts at burning the .iso to run the memory checker bootable software. Even then, after a failed burn the burning software (Nero), says the disk is blank, even though it failed during the track writing stage. One of these "failed" burn DVDs that Nero said was blank actually had the Microsoft Memory checker software on it because when I rebooted with this "blank" disk in, the Memory testing software booted and ran.

2. I ran the Microsoft Memory checker from a bootable DVD and there were no errors. I also ran the extended memory tests without errors.

3. Azureus.exe was uninstalled just after those errors. I mentioned I had uninstalled several apps. Azureus I had running to extract my settings before an uninstall. This application can "flood" the TCP/IP connections as noted. I do find it useful, am very aware of potential problems, but have uninstalled to eliminate it as a possible cause of my system problems.

4. Avira problems accessing certain files (ebooks). I think this is caused because at the time Azureus was actually downloading those files which were not completely downloaded yet. Azureus has a lock on the file/s while they are downloaded, preventing Avira from scanning the file/s.

5. I have stopped the FolderSize service for now. This is a tiny application that runs as a service and provides what one would think is core Windows functionality: a column in Windows Explorer showing the size of the folder.

6. Microsoft Update is not a big problem. I update manually via windowsupdate.com fairly often. Often I have the yellow system tray icon for Microsoft Update which says "Downloading Updates... 0%" when I hover over it. This never seems to change. It used to say "Downloading Updates... 9%", and never go anywhere. There are no options and double-clicking the system tray icon does nothing. Now that I have hidden that stubborn .net 1.1 update that wouldn't download I don't have the "9%" problem. An update in the past used to cause similar microsoft update symptoms but that also disappeared (along with the option to "Install Updates and Shut down", which never installed) when I hid the update on windowsupdate.com. I have mentioned this in an earlier post.

7. Malware proxy - I followed your steps to ensure proxy servers were turned off in my internet browsers.

8. DNS hijack - I followed your steps changing the TCP/IP settings on my Network Connection. I use an ADSL router/modem and so have changed my default gateway to the address of my router (192.168.0.1), with an alternate as 8.8.8.8. I use strong security on my router, with no defaults, no DHCP and MAC address-based access only.

Thank you so much,
Morgan

Attached Thumbnails

  • sensors_temp.gif

  • 0

Advertisements


#32
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
Is this a desktop PC? Seems to be running a bit hot for a desktop. Laptops tend to run a bit hotter.

I saw your original post. The disk check found some stuff and corrected it. I'd wait a week and run it again and see if it still finds something to fix. Since we have ruled out memory and the extended test work fine then it doesn't sound like a disk or disk controller problem I thought checking the temp might be a good idea.

An error was detected on device \Device\Harddisk4\D during a paging operation.

This error does not always mean what it says. Sometimes it is caused by a blank CD in the CD drive or similar.

Ron
  • 0

#33
clearly

clearly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Hi Ron,

Thank you for your time and effort.

This is a laptop mounted into a docking station (HP).

An error was detected on device \Device\Harddisk4\D during a paging operation.

This error notice changes. For example, the last few days it was Harddisk2 and for some days before that it was Harddisk4. I get between six and none of these per day. These Event Viewer errors got me running manufacturer's hard drive health utilities in the past and all found nothing. While the errors I described with my DVD drive are much more obvious, they occur with the burning software, I don't use the DVD drive daily. There were three such "Harddisk2" errors yesterday while I was away from the computer with nothing in the DVD drive. I left the computer running a MalwareBytes scan during this time.

Apart from these mystery Event Viewer disk warnings, the "Windows - No Disk" popup errors continue to occur frequently and seemingly at random. They occur often shortly after startup and seem to be linked to exploring hardware. So when I'm working in a Notepad file only, I can't recall any of these errors. But when I ran the tool to check the temperatures I got a few and when I use Windows Explorer or do file operations I can get this error (although I just tried now and got none so it's not predictable).

The "p" keyboard focus shifting problem has not returned thankfully.

Thank you,
Morgan
  • 0

#34
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
You might try the ideas in this site:

http://www.consuming...processing.html
  • 0

#35
clearly

clearly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Hi again Ron,

Well I've tried almost every idea and technique mentioned in that blog post as well as several linked forums and blogs. The thing is, I don't want to say the problem has gone away until I've rebooted a few times (the error often but not always occurs shortly after booting into Windows), as well until I've used the computer for some time on a given login (the error can occur randomly). I have been trying to access my storage devices using Disk Management and Device Manager. Sometimes this will trigger it.

The last effort I made seems to have stopped the error so far. But I thought that after some changes two days ago and it came back. Hopefully this will stick now. If not, I'm going to be forced to apply the registry edit to suppress the error message for the sake of my sanity.

Thank you for all your dedicated assistance with these problems I've been having that definitely seem different to the usual virus and spyware problems.
I really appreciate all your time and effort.

Best regards,
Morgan
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP