Adobe Issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by killwa, Aug 22, 2010.

  1. killwa

    killwa Private E-2

    hello

    i made a topic in software forum where i told them about my issue that i get security error when i try to install Lightroom 3

    says " Error 1326.Error getting file security:
    C:\ProgramData\Adobe\CameraRaw\CameraProfiles\Camera\GetLastError: 5"

    here is the topic link:
    http://forums.majorgeeks.com/showthread.php?t=221374
    Please check it out

    Satrow told me i might have malewares although my Anti doesnt read any of that in my system I'm using Avira

    he said that after he saw my Even Viewer Logs:

    http://www.mediafire.com/file/uaqnso...wer Logs.rar
    or
    http://www.mediafire.com/?uaqnsoz7q7azibe

    he told me there is something messing with my system and causing me this problem

    so i came here to check on it and ask if there is any thing wrong(malwares) with my system i can fix

    Thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. killwa

    killwa Private E-2

    ok this has been a loong journey i'v never thought i have malwares but it seems xD
    any way

    here is the logs
    i did every step every point every order but one
    the RootRepeal it didnt even want to run correctly when i open it i get error
    and then i go to file scan and i mark both partitions and i still get error it cant scan like 5 errors :s

    Start error : FOPS -DeviceIoControl Error! Error Code = 0xc0000024 Extended Info (0x0000000dc)

    Scan errors: "Could not initialize driver! Please contact the author!"
    2 or 3 times
    then :
    "Could not scan drive D (error 0xc0000024)"

    as for MGtools it did run automaticlly a CMD dos loger i didnt really do any thing but double clicking the file
    and it automaticly asked me if i accept to run the hijack and i did accept and it created the log file

    after that i tried to install lightroom 3 once again and guess what xD same error i doubt it has something to do with malwares but who knows well its my only issue i have nothing else to worry about

    all other adobe softwares working fine so even the lightroom 2.5 before i uninstalled it
    any thing u need to know just ask i'm ready to do any thing to make this software run xD PeaCe^^
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please read this:
    Warning about Porn, Keygens, Cracks, and other Illegal Software

    Please use add/remove programs to uninstall:
    Messenger Plus! Live --> should have been done earlier.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FCopy::
    C:\Windows\ERDNT\cache\userinit.exe | C:\Windows\System32\userinit.exe
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. killwa

    killwa Private E-2

    okay i did something wrong

    i closed the browser then moved the txt file to overlap the exe file it loaded then asked me if i want to continue then i remembered i didnt remove the massenger live plus yet so i pressed no then it kept loading so i ended the progress then removed the live plus then when i redone the operation it didnt ask me if i want to continue it just loaded then closed it didnt even open the cmd window
    and when i double click comfix it loads then it closes and then error from windows to close program :/ i think i messed up
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Delete it off your desktop and then download a new copy and without running it, drop the txt file on the new copy and attach the resultant log.
     
  7. killwa

    killwa Private E-2

    i've done that nothing changed the same thing happens
    so i'm assuming it already deleted the file or something i'm attaching the log here
    it seems like i cant attach the combofix log it says
    You have already attached this file in thread : Adobe Issue
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  9. killwa

    killwa Private E-2

    here it is, sorry i missed that before
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FCopy::
    C:\MGtools\temp\userinit.exemg | C:\Windows\System32\userinit.exe
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Then attach the below logs:

    * C:\ComboFix.txt
     
  11. killwa

    killwa Private E-2

    ok i've done it all exactly as u said
    and still the combofix doesnt open any windows it just loads and the thats it
    i'm gonna try to attach the txt if it didnt work i'm going to upload it on mediafire

    ComboFix.txt:
    You have already attached this file in thread : Adobe Issue

    http://www.mediafire.com/?9s58pjxikm6bsgu
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How rude of it!!

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  13. killwa

    killwa Private E-2

    lol seems like this software field xD
    here r the logs
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start / run / and type cmd.

    Once the command prompt opens, type:
    copy C:\MGtools\temp\userinit.exemg C:\Windows\System32\userinit.exe
    You should get a message saying 1 file copied. Tell me if you do or not. ( Type exit to leave the command prompt).
     
  15. killwa

    killwa Private E-2

    done man and it asked if i want to overwrite and i typed in Yes
    and got the 1 file copied

    now whats next ? :D:D
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me just recheck you logs. So re-run ComboFix and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  17. killwa

    killwa Private E-2

    this combofix is started to be annoying it doesnt want to run it starts the loading bar and after it finish nothing happens :s
    u still want the MGtool log?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I need to know is whether or not Combo is still reporting the userinit file as being corrupted. When you run it, what happens? Are you disabling your AV software first? You may also need to disable your firewall software.
     
  19. killwa

    killwa Private E-2

    yes man i disable the AV Guard and i dont have firewalls not even windows i turn it off and i close the browser too
    when i double click the combofix it loads in that bar like in the .GIF pic
    but it doesnt start any thing like the first time when it asked me if i want to continue or not i even tried to right click right as admin , didnt work either

    by the way the folder in my C called combofix is empty , i just wanted u to know maybe it has something to do with that

    and yes i run it from my desktop :D
    my AV is Avira maybe u would need to know that
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click Combofix and delete it. Then try downloading a fresh copy and disable Avira before you try to run it. Let me know what happens but do also get me the new MGLogs.zip

    And tell me what issues you are still having, if any.
     
  21. killwa

    killwa Private E-2

    about that :D i think we are gonna delay this a lil bit :D
    here is what just happend
    i just loged in windows today
    and i got an error from the file userinit.exe that something cant be found i didnt understand what is that i pressed ok and when it loaded i loged to black screen no start up taskbar nothing i just pressed alt+CTRL+DEL to open the task mang
    i tried to run combo fix from it and i noticed that the start up progress is working since avira was opened already and every thing else (in the task mang)
    any way
    combo fix didnt want to complet the run as usual so i used the task mang to open firefox to post this :D
    i'm gonna try to reboot now may be its gonna fully load in this time

    PeaCe
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can get into task manager, type explorer as a new process and see if you get your desktop back. I would really like to know what the error message was as it could be related to your userinit file.
     
  23. killwa

    killwa Private E-2

    o yeah that worked :D
    but the taskbar looks weird a bit itsnot transparent
    any way when i rebooted i wrote down the error here it is:

    "userinit.exe Entry point not found

    The procedue entry point spoolerlnit could not be located in the dynamic link library winspool.DRV."

    its in the old errors form like in xp and so where u have to just press "OK"
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start / run / and type:
    sfc /scannow.....have your OS cd handy and run it at least twice. Tell me what happens.
     
  25. killwa

    killwa Private E-2

    i ran it once now and it finished and closed automatically should i run it again?
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, run it again. But also get me a new C:\MGLogs.zip.
     
  27. killwa

    killwa Private E-2

    ok this is the log i've just made

    ah btw it didnt open up the error it used to open every time and i had to click close program to continue

    does that mean my pc is clean? xD
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Please tell me what issues you are still having, if any. You will probably need to post in the software forum for any leftover issues.
     
  29. killwa

    killwa Private E-2

    :'( my issue is still an issue

    well Adobe lightroom 3 wont install

    every time i run the installer it keeps loading till it starts creating files

    i noticed this time what it writes while loading

    fast flash updating complements then creating folders
    and it gives me error right away

    so is Itunes same issue i forgot about it since i dont really care about iTunes
    but i need the lightroom 3 :(

    i was in the software section they sent me to here cuz they found that there is something wrong with me pc according to my logs i've shown them (links in the first post of the topic)
    they said there is something playing with my system and told me it got to be malware and if its not ur OS needs a priest with holy water to get rid of the error xD
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then it is time for holy water. :(

    There was nothing in your system to indicate a problem with Adobe. I am afraid you will need to go back to your software thread. There must be an operating system issue.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  31. killwa

    killwa Private E-2

    ok all done thank you very much and sorry for wasting ur time

    ah i couldnt find hijack in the uninstall menu :/
    anyway
    i'm gonna reboot any way to get my restore points back

    thanks again

    PeaCe^^
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still think you are having system problems. The only thing I can suggest is that you run a repair install. You may want to include these new issues in your software thread.
     
  33. killwa

    killwa Private E-2

    well i'm not having any other issues but not finding hijack in the uninstall list
    every thing else work fine after the reboot i got my windows as it was
    actually the start up is bit faster now i guess the malwares i had is what made it slow a bit , i didnt even know i have malwares xD its just working fine for me to notice that xD

    thanks man for every thing this forum is super awesome :D
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Hope you get the other issues resolved.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds