Trouble with wave volume

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Cuervo79, Jul 6, 2010.

  1. Cuervo79

    Cuervo79 Private E-2

    OK I've done what the "read & run me first" thread said. Attached are all the log files I got, however when I ran super antispyware it didn't find anything and thus why there isn't a log file for it.

    Now to my problem. As in similar threads I started to get the wave volume reset to 0 problem and now and then got popups from internet explorer of varying kinds, like the "internet explorer isn't the default browser" among others. So I started googling for the problem and found this page. After doing what the "read & run me first" thread said I still have the wave volume reset to 0 every couple of mins and also I have an incessant "internet explorer is not currently your default browser" window popping up every couple of seconds, I don't click on it so it disappears for a second and reappears again.

    Help....
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.
     
  3. Cuervo79

    Cuervo79 Private E-2

    Here's what it says...

    C:\>remover
    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    main(): DeviceIoControl() ERROR 1
    main(): DeviceIoControl() ERROR 1
    main(): DeviceIoControl() ERROR 1
    ERROR: No physical disks found

    C:\>
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you put it on your desktop? Do you have multiple hard drives or partitions?
     
  5. Cuervo79

    Cuervo79 Private E-2

    Its on the c: and yes I have multiple hard disks (3 in total)
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Now if you have your OS CD, boot to the recovery console and run fixmbr on it:

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Tell me how things are running.
     
  7. Cuervo79

    Cuervo79 Private E-2

    mmm I'll have to put that on hold since this is my work computer. Regarding the recovery console, when combofix ran supposedly installed a recovery console no? before XP loads there is a 2 second window where I can read text....
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like Combo did install the RC, but you would be better off to boot to the cd and then run fixmbr from there.
     
  9. Cuervo79

    Cuervo79 Private E-2

    I'm going to do this on the weekend, so I would like to have some answers before I do this.

    Say the program screws everything up and my disk becomes unbootable. What do I do? Do I install windows again? Is there a way to fix it without a clean install?

    Regarding another matter, do I execute the program on all HDs?

    What are the steps I have to take when I execute the program?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is why I suggested that you back up all your important data and personal files. If for some reason running fixmbr on your hard drive fails and you are unable to boot up, then you would need to do a clean install.
    You will only be doing the fixmbr command on the one hard drive that has your MBR. But we can first make sure that you need to do this.
    Are you referring to getting into the Recovery console? You need to boot into your bios and change the boot order to cd first so that you can boot to the XP cd.....then choose R for the recovery console. At that point you just type in the command : fixmbr.

    Let's double check:

    Download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • you must click on the top bar of the Window and then select Edit.
    • Then you will see the Select All option.
    • Open a notepad and press Control+V
    • now please copy that report to this thread
     
  11. Cuervo79

    Cuervo79 Private E-2

    OK this is what it said when I ran the program

    MBRCheck, version 1.0.2
    (c) 2010, AD

    \\.\C: --> error 1
    \\.\F: --> error 1
    \\.\G: --> error 1


    Done! Press ENTER to exit...
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hummm....each of these programs is throwing an error message for your hard drives. Is this a Dell or HP machine?
     
  13. Cuervo79

    Cuervo79 Private E-2

    None, its a build up computer
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to boot to the Recovery Console to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  15. Cuervo79

    Cuervo79 Private E-2

    Thank you for the patience attached you will find the mglogs.zip So far the volume problems have disappeared thanks to the info you guys have provided.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your log is still showing the MBR infection. Do you have any disc emulation software running? What issues are you still having?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see you have dameon tools running., please follow step 6 of the Read and Run First instructions and then get me a new MGLogs.zip once it is turned off.
     
  18. Cuervo79

    Cuervo79 Private E-2

    Sorry didn't know I had to keep the daemon tools offline I'll turn it off again and run the tests. Regarding any issues, they have stopped, the volume problem has vanished.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, the dameon tools will send a false positive regarding an MBR infection. All I need to see is a clean RunKeys log to tell if it is now resolved. But it sounds to me like everything is working correctly again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds