Trojan virus has corrupted my CD and DVD drives

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dalglish1, Aug 9, 2008.

  1. dalglish1

    dalglish1 Private E-2

    Hi, i hope you can help with the following...

    I turned my PC on this morning to find the CD and DVD drives not working. I looked at device manager and found they had both been corrupted and it said the following for both items :
    Windows cannot load the device driver for this hardware. The driver may be corrupted or missing. (Code 39)

    Also, the Trident Video Accelerator Blade 3D/ProMedia display adaptor was corrupted and displayed this message :
    This device cannot start. (Code 10)

    My girlfriend told me that she had seen a trojan virus which she healed using my AVG last night, so i had a look in the vault and there it was...

    so i came to this forum to see how i could remove the virus.. I used all of the tools given in the cleaning procedure, and i have attached the logs - although not the MGtools one because i can't find it on my system...

    Like i say, i hope you can help me with this - please get back to me if you need any more information
    cheers
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the other logs (the one from Malwarebytes and from MGtools) requested in the READ & RUN ME. The log from MGtools is C:\MGlogs.zip as stated in the instructions.

    Also perhaps you should undo what AVG has done. Perhaps it removed some drivers that you need.
     
  3. dalglish1

    dalglish1 Private E-2

    cheers for the quick reply..

    i had already removed the trojan that my avg found, but i've just done another complete scan and it's still there, so i guess its been put back as it was!

    i'll do the other two scans now and attach them to this thread shortly...
     
  4. dalglish1

    dalglish1 Private E-2

    here are the other two scans you need..

    fingers crossed you can help me out here and thanks for trying!!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install Kontiki yourself? I'm referring to the below which often installs without the end users knowledge.
    O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
    O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe

    Also did you setup the below Desktop Component?
    O24 - Desktop Component 0: (no name) - http://www.oopshi.com/images/pucca garu oopshi.jpg


    Your issues with your CD drive and Trident Video card will probably require that you reinstall drivers. That is a topic for the Hardware Forum.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. dalglish1

    dalglish1 Private E-2

    Cheers again for your reply chaslang!!!

    i've done everything you suggested in your most recent post and it all seemed to go smoothly..

    when i merged the quote into the registry, i did indeed get the success message, so no problems with that either..

    attached are the two logs you requested - if you need anymore info, just ask and i'll be straight onto it...

    the cd and dvd drives are still broken so i'm going to go to the drivers forum to see what i can do to mend them..

    thanks again
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. You forgot to answer my two questions.
     
  8. dalglish1

    dalglish1 Private E-2

    Whoops! Sorry about that!!

    The first question, the answer is that i didn't install it, at least intentionally...

    And for the second one, looking at the link i thought i never recognised it, but when i clicked on it, it was something my niece did about 2 years ago without telling me!!

    are these files damaging to my system then?

    i have put a message in the hardware forum about my cd and dvd drives, and am waiting for an answer to that now - problem nearly solved :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are not major problems. They are just junk you don't need. Let's remove them.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to KService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteKService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now re-start C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
    O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
    O24 - Desktop Component 0: (no name) - http://www.oopshi.com/images/pucca garu oopshi.jpg

    After clicking Fix, exit HJT.

    Now reboot your PC.

    After reboot, delete the below folders if found:
    C:\WINDOWS\kdx
    C:\Program Files\KService

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. dalglish1

    dalglish1 Private E-2

    Thanks again Chaslang..
    I've done what you asked and everything went ok.. the only thing was that the above line wasn't available for me to delete after i had done the system scan with MGTools - it simply wasn't in the list...
    I'm not sure how this will affect anything - i guess its not a problem because its not on my system??

    anyway, thanks again for your help, everything seems clear now, and a couple of other benefits are that my C drive has doubled its free space, plus my pc seems to boot up a lot quicker (although i might be imagining that second thing since i haven't actually timed it :-D )
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Not a problem.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. dalglish1

    dalglish1 Private E-2

    Hi Chaslang..
    I've now worked through steps 1-9 above and am about to have a go at number 10..

    i have a couple of points i'd like to ask you...

    1 - i was away at the weekend and spoke to a friend of mine and he said that the new version of AVG (mine is 8.0) is not very effective and if you have it, you are bound to get infected by a trojan virus.. are you aware if is this true and if so do you have any recommendations for a good quality free anti virus program?

    2 - i still have to fix my cd and dvd drives and also the trident card and i put a post in the hardware forum but haven't had a response yet.. would i be more likely to get an answer in the driver forum if i put it in there or would that be against forum rules to post in two different sections about the same thing?

    thanks very much!!
     
  13. dalglish1

    dalglish1 Private E-2

    Re: Question 1 above
    I have just noticed that you have discussed this problem already when i clicked on Step 10 in your last thread, so please disregard this question!!
    thanks, and sorry about that!!
     
  14. dalglish1

    dalglish1 Private E-2

    Hi, i now have another question with regard to uninstalling AVG FREE 8.0

    I have tried to unistall the above product from my pc but i get an error message:

    Installer initialization failed due to the following error:
    Warning: Internal error. Dialog with id "Avg4EsDlg" was not found in the setup.

    I've tried to contact the AVG help desk but because i use the free version, i am unable to receive customer support!!

    If you could help me to uninstall AVG so i can then install a different Anti-Virus programme, along with trying to help me on Question 2 above, i would be very grateful!
     
  15. dalglish1

    dalglish1 Private E-2

    a quick update about the AVG problem, i found a AVG specific forum which i used and they helped me uninstall it, so that is done.. i've now got the PCToolsAntiVirus installed from your recommendations in the 'how to protect yourself from malware' thread..

    I still would be grateful for any help about fixing the cd and dvd drives on my pc as this is the only problem i have left to sort out.. thanks in advance!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could try posting in the Software Forum to see if anyone there can help. You probably need to delete the devices and reinstall drivers but again this is best handled in a different forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds