Computer Issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by Megamouth, Feb 17, 2007.

  1. Megamouth

    Megamouth Private E-2

    I have two remaining obvious problems with my computer which happened at the same time. One, my cd/dvd rom drive cannot read cd's that are in it. It can boot xp. Two, multiple network adapters with exclamation points appeared. Direct Parallel, WAN Miniport (IP), WAN Miniport (PPPOE), WAN Miniport (PPTP). I did try and follow Major Attitudes' Read Me First instructions. I had trouble running getrunkey & shownew. Not sure what went wrong there other than the programs did not produce the expected file name but numerous fragmented files. Afraid I did fix some things before creating the captured logs and as a result Panada Active Scan and CounterSpy no longer report issues. Definitely blew it. I did write down two virus names I encountered WIN32:CTX & WIN32/Vxidl.gen!B. I do remember seeing a trogan along the line also but do not have the name. Hopefully my issues can still be addressed. I appreciate all the effort. Nice to know there are great people to counter the malicious.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First before going any further! Hardware problems with CD/DVD drives are almost never related to malware. Most frequently it is a hardware failure (drive is bad or corrupted drivers).

    If you want to continue to pursue a malware course (which I repeat is probably not your problem) then you need to follow the directions exactly as written on the download pages for GetRunKey and ShowNew and you need to observe whether you are getting any of the error messages indicated. We need thes logs especially since you neglected to follow the directions in the READ & RUN ME and did not save logs from CounterSpy and Panda.
     
  3. Megamouth

    Megamouth Private E-2

    Run Keys does not produce the file it is supposed too. I went thru all the senarios and file searched for runkeys.txt. It does spawn numerous text files which I zipped and attached. There is one last file called xlmsysc.txt which is over the 600k limit.

    I did try another cd drive and my cd/dvd drive will boot xp.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not following the directions on the download pages for GetRunKey and ShowNew properly. Note that the below files belong in your c:\windows\system32 folder which is the default folder that the fix you downloaded even specifies when you run it. The are from the fix given on the download pages if you receive a specific error message.
    Code:
    "E:\Program Files\Major Geeks\GetRunKey & ShowNew\"
    autoexec.nt   Jul 21 2001        1688  "autoexec.nt"
    command.com   Aug 17 2001       50620  "command.com"
    config.nt     Jul 21 2001        2577  "config.nt"
     
  5. Megamouth

    Megamouth Private E-2

    I did extract them to the default location first and they remain there. I later put them in the shown folder as well in an effort to get the desired results. When I run GetRunKey.bat a black command prompt window opens and runs for a few seconds before displaying: xtmpsysccs.txt, xtmpsyscs1.txt, and xtmpsyscs3.txt, 1 file copied before disappearing. Unfortunately it creates numerous files in the root of the c drive. Believe me I want nothing more than for my computer to be cured. If I am doing something wrong I fail to realize it. Perhaps I can find the Author site and look for some more detailed instructions in an effort to better understand what exactly is taking place?

    Thanks for your time.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are taking to the author. And all the instructions are on the download pages. Are you receiving either of the error messages mentioned.

    And yes all the temp files are supposed to be created in your root folder while it is running. During the finishing steps it will format everything into a single properly formatted file and it will delete all temp files. However if it does not run properly, those files will be left behind and the final log will not be created.

    I think the problem may be due to the unfortunate folder name you used. You should have used what was recommend. You used this:

    E:\Program Files\Major Geeks\GetRunKey & ShowNew

    I believe the ampersand ( & ) is the problem. Change the above to:

    E:\Program Files\Major Geeks\MGTools

    Now run both programs and see if you get proper logs.
     
  7. Megamouth

    Megamouth Private E-2

    Originally I did use the recommended C:\MGtools folder with the same results. No, I was not getting an error the first time I ran the program. Believe I put in the xp profile and did the suggested fixes for errors after that even though I did not have them. Seems like I did get one of the errors when I ran from the & folder, in one of my latest attempts, so I edited the registry still no go. This last series of attempts I renamed my folder and even changed it to the recommended and still the same result. No errors being reported but still numerous fragmented files. I definitely am not on your level so I do not understand what is going on but wonder if having a RAID 0 array has anything to do with it? Is it imperative that I once again dload the files and extract them to the proper locations? or should simply having moved them into the right folders work? I'll try anything you suggest. I do appreciate your efforts.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you allow XPprofile to extract to the system32 folder as the default shows. If not it does not resolve the problem suggested in that error message.

    You should be able to just move ALL files to the C:\MGTools folder Do it now and leave it that way. You should have the below files in the MGTools folder and nothing else.
    GetRunKey.bat
    grep.exe
    locate.com
    ltime.exe
    Shownew.bat


    Then click Start , Run and enter cmd and click OK to open a command prompt. Then enter the below commands at the command prompt.
    cd c:\MGTools
    GetRunKey

    Does that work? If not, do you get an error message of any type. If so, what does it say.

    Now run the below from the command prompt and again note any error messages.
    ShowNew


    Make sure the autoexec.nt, command.com, and config.nt files have been copied to you c:\windows\system32 folder.
     
  9. Megamouth

    Megamouth Private E-2

    I did everything you suggested. Extracted the XP Profile to the sys32 folder making sure the files are in the right folder, put the needed files in the c:\MGTools folder, and ran using a command prompt window. Since the window stays open using this method it looks exactly like this:

    C:\MGTools>GetRunKey
    C:\xtmpsysccs.txt
    C:\xtmpsyscs1.txt
    C:\xtmpsyscs3.txt
    1 file<s> copied.
    The system cannot find the file specified.

    Still not the desired results....sorry.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run ShowNew the same way (from the command prompt) and tell me what happens!

    You do realize that none of this probably has anything to do with your CD/DVD drive problem? It is just strange that you cannot run these batch scripts when hundreds of people do it each week. Not sure yet why but it does not seem to be the typical user problem with not reading the error messages on the download pages and it is not the other typical problem where the files were not extracted from the ZIP files.

    Also download the GRKdeb.zip file from the below link and extract it into the same folder as GetRunKey.bat. Then run the GRKdeb.bat file. It will produce a log named C:\GRKdebug.txt Attach this file here!

    GRKdeb.zip
     
  11. Megamouth

    Megamouth Private E-2

    Both show new and grkdeb appear to execute and show: The system cannot find the file specified in the cmd prompt window. I now have two files in the c: that are rather large in size. pagefile.sys with is 1.5 gig and hiberfil.sys which is 2 gig. Both are system files. Hope these are normal files as I don't remember seeing them before.

    Actually I did not realize that this does not have anything to do with the drive issue. I had hoped that something in windows was corupt causing both the drive and the multiple WAN Miniport adapters problem.

    Like I said I appreciate your help and advice and if you think it is a lost cause I certainly understand. I am about ready to slam the tower on the floor anyway..heh eh
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Neither of them ran properly.

    From a command prompt window type the below two commands and tell me what you get after each one is entered:

    ver
    find



    They were always there and are normal. They were hidden before.

    Well I doubt whatever is causing GetRunKey and ShowNew to not run could cause hardware problems like you described. However something is definitely wrong within your OS to prevent the two batch files from running. Right now I'm betting that the find.exe file is missing from your system32 folder.

    You should try your DVD drive in another PC to see if it works. If it, does not, then you know the drive is bad.
     
  13. Megamouth

    Megamouth Private E-2

    Ver 5.1.2600
    FIND: Parameter format not correct

    find.exe is in the windows sys32 folder at approximately 9kb

    I did try another known good drive in my computer plus the XP CD will boot from my drive in my machine. Doesn't that indicate it somewhat works? Wanted to reply to your instructions. Will try that tomorrow.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the new attached version of GRKdeb.zip and extract the file and run it. When finished attach both the C:\GRKdebug.txt and the C:\runkeys.txt log it creates (if any is created). The debug log should look like below if it run completely:
    Code:
       Finished Regedits 
       Start grep's for SmitFraud  
       falcon19 SmitFraud test point 
       quake10 SmitFraud test point 
       troj8 SmitFraud test point 
       Finished grep's for SmitFraud 
       Begin NT File Search 
             NT File Search point 2 
             NT File Search point 3 
             NT File Search point 4 
             NT File Search point 5 
         END NT File Search 
          Begin rkeysxxx creation 
            END rkeysxxx creation 
         Hit Exit Label 
         Hit End Label 
    
    It just means you can read original CDs. It does not mean you can read CD-R or CD-RW or even DVD-R +R or -RW or +RW. I have strange problems like this on many drivest. Just replaced one for a friend two weeks ago. A little different than your problem, he could no play original DVDs (would not even see them in the drive) but if he put in a DVD-R, +R or +/-RW they all were recognized and played. Tried the drive in another PC and got the same results (thus drivers and other hardware conflicts were eliminated).
     

    Attached Files:

  15. Megamouth

    Megamouth Private E-2

    The log was missing the last two lines.

    Hit Exit Label
    Hit End Label

    I ran grkdeb from a cmd prompt window.

    It showed:

    c:\xrkey00.txt
    c:\xrkey01.txt
    c:\xrkey02.txt
    etc..
    xrkey05
    xrkey06
    xrkey07
    xrkey10
    xrkey11

    Will try my drive in another machine this evening...thanks
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From the command prompt enter the below command and tell be the exact output you get:

    ver | find "Windows XP"
     
  17. Megamouth

    Megamouth Private E-2

    I first tried them together verbatim with a a space then the shifted slash key above, a space, and entered the find info. The version number was returned. The cursor went back to the end of the line information and was flashing. No error.

    Microsoft Windows XP [Version 5.1.2006]

    I then entered the ver command on a single line with the same version result.

    I entered the find command on a single line by itself and waited from 6:09 PM to 6:22 PM and the cursor had just gone down a line and remained flashing. It was not back at the end of the c:\Documents and Settings\David line. Should I be more patient? Did not seem like much HD activity was happening...
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now we understand what was causing GetRunKey and ShowNew to not complete. Let see if can find out why!! This should work without a problem.

    Use Windows Search to look for matches to find.exe and find.com. I think you may possibly have another executable named find in your path.

    If you don't know how to use search, see this: Searching for Hidden Files on WinXP


    Note: I will be out of town until next Monday evening! So unless another
    malware helper is around to pick this up, you will have to wait until I return.
     
  19. Megamouth

    Megamouth Private E-2

    FIND.EXE-0EEAD1A7.pf c:\windows\Prefetch
    find.exe c:\windows\system32
    find.exe c:\windows\system32\dllcache

    Nothing on find.com

    The DVD drive does function properly in another machine.

    No problem about the wait tis I who appreciates your patience.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think I misunderstood your message the other day. Now after re-reading, it does not sound like anything was wrong. I still not sure why we are having problems getting GetRunKey and ShowNew to run but it does seem like it is in the area where I use the ver and find commands to determine the Windows Version information, I'm going to try making a modified version of GetRunKey that assumes only Windows XP and see if it will run for you I will attach it to another message as soon as I can, I still not back from my trip and have limited access.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay give this a try. Download the attached GRKtest,zip file and extract the GRKtest.bat file from it into the same folder as you previously extracted GetRunKey.bat or ShowNew.bat

    Then run the GRKtest.bat file. Does it run and pop up a runkeys.txt log? If so attach the log, Even if it does not popup a log, check to see if c:\runkeys.txt exists and attach it,
     
  22. Megamouth

    Megamouth Private E-2

    I do not see the attachment.

    Also I tried a different motherboard. Same manufacter and model; Abit IC7 G. Same symptoms as before so we can rule that out.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I attached it here.

    Also tell me something. Do you see the below file on your PC?

    C:\xtemp999.txt
     

    Attached Files:

  24. Megamouth

    Megamouth Private E-2

    I ran grktest from a command prompt. It did not open a text file. It did say all finished getting run keys. Attached is the file it created in the root.
     

    Attached Files:

  25. Megamouth

    Megamouth Private E-2

    Oh no..no xtemp999.txt. There was an xtemp98.text file from previous runnings...but none after this last bat u had me run.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was not supposed to open a file. I deleted that part of the program. It appears to have run okay too.

    Now delete the c:\runkeys.txt log and download the current version of Using GetRunKey and extract it to C:\MGTools and run GetRunKey.bat from this C:\MGTools folder.

    What happens?
     
  27. Megamouth

    Megamouth Private E-2

    Same as before. No runkeys.txt. Numerous files generated all starting with an x and the last file in the sequence alphabetically is xtemp98.txt. I think I am going to try and have windows xp repair itself. If that fails perhaps reload Windows entirely. Definitely want to be able to game this weekend. Going on close to three weeks. I just can't take it much longer..heh eh Will wait to hear what you suggest before attempting this.

    I do very much appreciate your time and efforts along with the great malware removal instructions.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well as I said earlier none of this has anything to do with the problems you are having with your DVD player. It is just strange that you cannot get this to run when I put in the Windows Version check tests. It's almost like something is wrong with your Windows version number but based on what you have given me, it looks okay. So I'm not sure exactly what it is, but it does seem to be unique to you since hundreds of people run these tools every week without a problem. And for the few that do have a problem it is normally due to improper install, the error messages mentioned on the download pages, or an improperly setup environment path. Your problems seem more like something in your OS but I cannot tell what. Thanks for spending the time to try and help me debug what is going on. Too bad we could not find the exact root cause although I know where it was failing to continue to run.

    Run the GRKtest.bat version now and it should cleanup all the temp files for you unless you already deleted them yourself.

    You should also uninstall the CounterSpy trial if you have not already done so.

    Also do the below to cleanup left overs from having Symantec AV on your system at one time.

    First look in Add/Remove programs and uninstall anything for Symantec or Norton.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Core LC
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymantec Core LC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot if it tells you it needs to.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below file and delete it if found:
    C:\WINDOWS\System32\NavLogon.dll

    Attach a new HJT log now!


    Again the problems with your DVD player may or may not be fixed by repairing Windows. It still could be a hardware problem.
     
  29. Megamouth

    Megamouth Private E-2

    Thanks again for your time, efforts, and expertise. I have learned a great deal and like I said previously it is comforting to know that for all the evil doers there are people like you who offset them. If there is a way to donate to your cause please let me know. Keep up the excellent work.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I do have a PayPal account if you want to contribute. It's purely optional. Just PM me with an email address if you want.


    You HJT log is okay now, but I would assume your DVD drive still is not.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds