Wave Sound Muting and IE run by "SYSTEM"

Discussion in 'Malware Help (A Specialist Will Reply)' started by chriscez, Jul 13, 2010.

  1. chriscez

    chriscez Private E-2

    This problem is similar to the others if not the same problem. "Wave" under volume control automatically mutes itself on computer start-up and periodically when the computer is on, causing no sound to come out. And IE opens up under "Processes" by "SYSTEM" which I think causes the random audio pop-ups that you can't see and also the random clicking noises, although I use Mozilla Firefox all the time. And there are times where it seems as if a window opens in front of whatever I am using (I.E. Firefox) and I would have to click the window I was using to use it again. This problem started about 2 days ago, and I remember installing AdBlock Plus add-on and this problem came about pretty much out of nowhere. I've tried some of the malware and anti-virus programs at my disposal but to no avail. I hope someone can help me as it would be much appreciated! :) Thanks!

    *I've attached the logs, thanks again.
     

    Attached Files:

  2. chriscez

    chriscez Private E-2

    the MGlogs.zip is attached. Thanks!
     

    Attached Files:

  3. chriscez

    chriscez Private E-2

    Don't mean to bump! Sorry!

    But here is what comes up from the "remover.exe" from bootkit_remover that I've seen from other posts. I hope this may help a bit!

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: d4b876239615e81ab805b6a9431ee920

    Size Device Name MBR Status
    --------------------------------------------
    37 GB \\.\PhysicalDrive0 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>


    Press any key to quit...
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, chriscez.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You have an infection in your Master Boot Record (MBR).

    I need to ask some questions:
    1. Do you have any drives that has a non-windows installation on them?
    2. Are all drives NTFS formatted?
    3. Do you have any non-standard or special MBRs which can occur from companies like Dell or HP who frequently install additional partitions used for recovery partitions in lieu of giving CD/DVDs?
    4. Is any program like Grub ( see:http://www.gnu.org/software/grub/ ) being used?
    5. Is drive-encryption being used?
    6. Are any drives external USB pen drives or external hard drives being used?
    VERY IMPORTANT: Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    dr.m
     
  6. chriscez

    chriscez Private E-2

    Thanks for the reply, and as to your questions my answers are best to my ability, which isn't too great as I'm computer savvy to an extent, sorry!

    Answers:


    1. Not that I know of, no.
    2. From what I can see, yes, all are NTFS.
    3. I don't think I do, but my computer is a Dell Desktop. I haven't used any disks that were given to me by Dell.
    4. I don't think so, but the link was broken, so I couldn't see what this is, sorry!
    5. Im not sure exactly what this is, but I'm pretty sure I am not.
    6. No, no USB/Pen/External drives are being used, as of right this moment, but I have used some flash drives in the past if that was what you were asking.

    *If I can check any of this and provide better answers please let me know!

    And by important data backed up do you mean files and documents that I find are are important? Because if so, then yes I do.

    Thanks again for taking the time to help me!:) Much appreciated!
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, chriscez.

    Now - please do the following:

    • Click Start, Run > then copy and paste the below into the Run box and click OK.
    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0

    • Now reboot your PC and after reboot continue with the below instructions.
      Using Windows Explorer, check to see if this folder still exists, if so - delete it:
      • C:\System Volume Information\Microsoft
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. chriscez

    chriscez Private E-2

    ok, so I ran what you gave me and the cmd screen came up and told me to press any key to exit, and I did. I then rebooted my computer and something came up telling me that restarting it helped successfully install something and told me restart again and I clicked no. I then tried looking for the system volume information folder and when I got to it it told me access denied. So I couldn't check that. And I didn't get the MGlog because of all this. Sorry! Should I get the log anyway?
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    System Volume Information is a folder protected by the operating system and is used for System Restore. You need to first disable system restore on all drives. Then see if you can access the folder and delete the folder I referenced, if found.

    Then run the C:\MGtools\GetLogs.bat file per my instructions.
     
  10. chriscez

    chriscez Private E-2

    ok, I disabled system restore but it is still saying access is denied, so I can't even look through or access it.

    *just random information if its related: My antivirus (Norton) which was fine a while ago had turned from a green check indicating all is fine to a red x shwoing something was wrong. this occurred after I had run the characters in the "Run" application.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I suspect Norton is protecting your system (but interfering) with our steps.

    Try physically disconnecting your internet connection and shutting down Norton.
    Then repeat my instructions from post#7.

    Also - please then double-click the remover.exe file to run the program again.

    Attach or post inline here, the output from remover.exe and the new C:\MGlogs.zip.

    {Remember to re-start Norton before reconnecting to the internet.}
     
  12. chriscez

    chriscez Private E-2

    Ok, well I still couldn't access the System Volume Information folder even with Norton disabled and the internet disconnected. But I did try to type in the directory of "C:\System Volume Information\Microsoft" and it said that it wasn't found or that the path wasn't found or needed internet connection.

    Here's what comes up from "remover.exe":

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: 6def5ffcbcdbdb4082f1015625e597bd

    Size Device Name MBR Status
    --------------------------------------------
    37 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


    Press any key to quit...

    The MGlogs is attached.

    *Sorry, some of this seems to be not going the way you wanted, but thanks for the ongoing help! I appreciate what you're doing. Let me know and I'll do what I can.

    EDIT: Well I've looked in the "processes" tab of task manager and I've found no IE run by system, at least for now, and my volume hasn't gone down yet either, and its been about 5-7 min. now.
     

    Attached Files:

    Last edited: Jul 15, 2010
  13. chriscez

    chriscez Private E-2

    Little Extra Info:
    My Norton seems to be acting up now (well nothing is really popping up or anything, there is the "One Click Support" thing that occasionally pops up and i just close it,) as in it seems to be disabling some of its own features without me doing so such as "Intrusion Prevention" and "Email Protection" and also this "SONAR" thing. It wasn't like this at all before. Just extra information.

    I may fall asleep so I'll take this on again later today with your help again hopefully, as it is around 1:30 A.M. here. I'm sorry, I'm just getting a little tired. I'll be back
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, chriscez

    Ok - now that we've got your MBR taken care of, let's finish up.

    NOTE: You'll have to post in our Software Forum about your Norton software issues.

    * You should upgrade your install RAM, as we recommend a minumum of 1GB for running Windows XP without experiencing performance lagging.
    Please look in Add/Remove Programs for the following and uninstall if found.
    Using Windows Exporer - navigate to and delete this folder:
    c:\documents and settings\All Users\Application Data\Viewpoint

    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Now install the latest Sun Java Runtime Environment

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  15. chriscez

    chriscez Private E-2

    Thanks so much dr. moriarty! Ever since early this morning up until now I have not experienced the problems! (knock-on-wood.) And Norton suddenly decided to comply and become a "Green Check" again indicating all is well. But I will continue on with your instructions.

    • I'll try to upgrade my ram when I can.
    • Uninstalled "Ask Toolbar", and the "Java Updates."
    • Deleted "the Viewpoint" folder.
    • Ran CCleaner
    • And installed the latest Sun Java Environment as according to the link.

    1. I will keep the 2 programs. Thanks.
    2. Will do.
    3. Did not need to do this.
    4. None except the bootkit_remove.rar, which I'll delete.
    5. Did not need to do this.
    6. Not running Vista.
    7. "HijackThis" isn't installed so I did not do this.
    8. Will do.
    9. Will do.
    10. I definitely will look this thorugh.

    Thanks again for all your help! I appreciate you taking time out of your schedule to help me and all the others out there! And I hope if anything were to occur again, I hope you or anyone in this forum will be willing to help me again. (Hopefully this won't happen.*In a good way.)

    *Last note (sorry), since I have Norton Anti-Virus installed already, should I just use it until the subscription expires then look for another anti-virus program? I'll still install some other firewall-type programs though aside from an Anti-Virus Program. Thanks again!
     
  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your gratitude adds encouragement to all malware fighters everywhere, to continue doing what we do.

    This new infection seems to slip past alot of anti-virus programs - I don't see the need to change from Norton, if you're satisfied with it.

    dr.m

    EDIT: Please delete this last file - C:\WINDOWS\Temp\100.dat
     
    Last edited: Jul 15, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds