Need some help

Discussion in 'Malware Help (A Specialist Will Reply)' started by burnet01, Nov 20, 2009.

  1. burnet01

    burnet01 Private E-2

    Hi,
    I got two problems on my pc, I don’t know if they are related each other. One is that my antivirus avast always there are 3 items in the chest. I remove from the chest but soon appear again. I’ve done many deep scanners but they are always there. I’ve done the Cleaning Procedure from the forum, but it doesn’t remove them.

    The second problem is:
    The volume icon in the taskbar didn’t work. I removed and when trying to place again the icon in the taskbar I got this error:

    ‘Error
    Windows cannot display the volume control on the taskbar because the volume Control program has not been installed. To install it, use Add/Remove Programs in Control Panel.’

    I tried to use the System Restore to an early point to fix the problem, but System Restore doesn’t work at any point.

    I’ve checked and System Restore is ON. I got all the updates from Windows Update.

    I’m getting worried; perhaps the trouble is more serious than seems.
    Here are the logs.

    Any help would be much apreciated,
    Burnet
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not having malware problems. Your logs are all clean. What exactly does Avast say is in the chest? Perhaps it is just System Restore items you need to cleanup.

    Post about these in the Softwar Forum since you are not having malware problems.
     
  3. burnet01

    burnet01 Private E-2

    Thanks for help.
    I thought everything on the Chest are virus. The 3 items are in Avast Chest; in System files. Here are the files:

    kernel32.dll located in C:\WINDOWS\system32
    winsock.dll located in C:\WINDOWS\system32
    wisock32.dll located in C:\WINDOWS\system32

    The Chest always used to be clean. These 3 items only appear recently. I thought perhaps they are caught by the Resident Protection

    Burnet
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only if the scanner is not having false detection issues.;)

    First the last file would be an infection if it existed but I'm guessing that you just type it in wrong and that the file you saw was wsock32.dll. If so all 3 of the above are valid files. But I don't want to know what is in the system32 folder. I want to know what is in the chest and what the sizes of and dates of those files in the chest are. Things in the chest are not in the locations they came from anymore unless they are coming back after being deleted which is what these files would do if they were deleted since Windows needs them to run properly.

    You could test to see if your files that are in the system32 folder are infected by scanning them at the below link:

    http://www.virustotal.com/
     
    Last edited: Nov 24, 2009
  5. burnet01

    burnet01 Private E-2

    Hi,
    I got concern because the Chest always used to be empty, only recently I got these 3 files all the time on the Chest.
    I’ve scanned these files on Virus Total. I got only one positive on Kernel32.dll
    Only one antivirus (Only McAfee-GW-Edition) gives Heuristic.Lookslike.Trojan.Patched.O

    What do you think?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just a false detection from McAfee that occurs on the SP3 version of kernel32.dll.

    I would say your 3 files are all clean.
     
  7. burnet01

    burnet01 Private E-2

    Just to thank you for your help and time. You guys are doing a great job.

    Best regards,
    burnet
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  9. burnet01

    burnet01 Private E-2

    I’ve done the advised. Thanks again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds