Did cleaning process after significant system melt down (software) and rebuild

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bold Eagle, Jun 21, 2008.

  1. Bold Eagle

    Bold Eagle MajorGeek

    I am just trying to recover after having a significant system corruption which was mentioned in this thread, please excuse the dramatics:

    WARNING!! TuxGuitar 1.0 Final is the nastiest software EVER

    After "rebuilding" the OS I have been going through and uninstalling and reinstalling my apps (not exactly sure how many are corrupted, but the vast majority are showing impairment at minimum). I am finally achieveing a level of functionality again but most old apps (non-reinstalled) wont work. I have completed all Windows updates, reinstalled drivers, MOBO Chipest, Video Card, and onboard Audio, but I have lost all sound. This occured once during the process of re-installing apps so I uninstalled k-lite Mega Codec pack and re-insatlled and had sound again. After that I was busy uninstalling apps and reinstalling (about another 5-6 at least after this) and have lost all sound. I am running the maleware scan attempting to ensure there are no nasties causing this issue.

    Well here are results.

    SUPERAntiSpyware found nothing but as it ran NOD32 went off and quarrentined this object.

    Apart from NOD32 nothing has been found, ComboFix wont run on 64Bit environemnt and MGtools has stopped as well but generated a HijackThis log and GetUnkey text.
     

    Attached Files:

  2. Bold Eagle

    Bold Eagle MajorGeek

    Im really dreading doing the whole re-format, re-install (coarse) approach but will if needed as the registry seems significantly corrupted. Other logs attached. This is all that I could obtain from MGtools.

    I suppose essentially I dont want to inadvertanly save and reinstall some nasty if I do have to adopt the coarse approach, any assitance would be greatly appreciated.

    To resolve Audio I have;
    -All Windows Updates
    -Updated MOBO Chipset Drivers
    -Reinstalled with latest Realtek Audio Drivers
    -Used MS Help exploring most avenues for audio
    -Explored Realtek Audio HD Manager
    -Explored Windows Volume Controls
    -Explored Device Manager with no alerts

    I have no system sounds, no movie sound and no audio sound.
     

    Attached Files:

  3. Bold Eagle

    Bold Eagle MajorGeek

    To add to this I have processes still "populating" via "Process Explorer" even though the application in theory has been removed from my system, i.e. avgwdsvc.exe and avgemc.exe.

    I removed AVG because it would not populate with the current registry (corruption somewhere) and yet these 2 processes persist.

    Any advice would be greatly appreciated.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have any malware issues based on these logs. As you noted you do have an issue in that multiple antivirus programs installed. You must never install a second one while a first is still installed.
    • Does AVG8 still show in Add/Remove programs?
    • Did you uninstall it using Add/Remove programs?
    • Was NOD32 installed before AVG8 was uninstalled?
    It may be best to uninstall NOD32, reboot and then reinstall AVG8. Now reboot again.
    Now after this last reboot, uninstall AVG8 and then reboot a 3rd time. After reboot, check to make sure everything was uninstalled and that no services for AVG8 are showing in you HJT log. Your current log showed the below:

    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe

    If all of AVG8 is cleaned up, then you can reinstall NOD.

    You will also notice in your HJT log that it shows a load of system32 files/services as missing. You should work in the software forum to correct this. You may need to restore a bunch of files if they are really missing. Does System File Checker run on x64 systems? If yes, you should try running sfc /scannow from a command prompt to see if it can repair any issues. It may ask for your Windows CD so be prepared to provide it.
     
  5. Bold Eagle

    Bold Eagle MajorGeek

    Thank you Chaslang.

    AVG is nowhere to be found and I believed that I had fully removed it before installing NOD32 but then noted these 2 processes remaining. I will follow your advice, uninstall NOD32 and reinstall AVG and then remove, but this time ensuring a complete removal via Process Explorer. The whole system went haywire for lack of better words and had become significantly crippled, are undertaking the System File Checker and it does work and has asked for the CD.

    At least there are no nasties in the system, thank you again.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Process Explorer is not a program uninstaller and it will not remove services if they are still trying to load. You will have to use other steps to removing left over services. After you complete this, run the C:\mgtools\analyse.exe program which is really HijackThis and save a new log and attach it. This way we can check for left overs.


    Did it help fix any issues you were having? Yes I would expect you system had major problems based on the services that were shown to be missing in your HJT log.
     
  7. Bold Eagle

    Bold Eagle MajorGeek

    I agree I was just using Process Explorer as a means to see if those services kept populating, which they did and thus confounded the fresh installation of AVG8.0 (it would not do it while those services were running, so I had to "disbale them" from start up and reboot and then reinsatll AVG8.0. Finally it is functioning normally again (AVG). I have left it installed for now as it is behaving normally.

    Tried the sfc /scannow to attempt to repair issues but for some reason it "could not read the disk" (gave it a clean as well) when it came to those particualr files during the process, all I could do was cancel it each time and let it progress further. Will have to resolve another approach for the file replacement.

    Have just re-installed MOBO Chipset Drivers, then uninstalled RealTek and K-Lite Mega Codec Pack and VLC, then conducted a fresh install of all these components and I Finally have sound back, played around in the RealTek sound management. So maybe Im moving forward now after being able to function with a single AV!

    Have been able to get MGtools to progress a little further as well but it didn't like the 64Bit environment for some of the stages.

    It's all baby steps but system is getting back to normal, even found my Oblivio Game folder and have that back to where it should be, yippee.

    Thank you very much for your observations, now it is the clinical approach of trying to reinstall these specific files/xxx.dll/xxx.exe.
     

    Attached Files:

  8. Bold Eagle

    Bold Eagle MajorGeek

    Just a quick question I still have several apps on the PC which are significantly corrupted, slowly getting to them and making restore points if things are going well, could any of these have files within the "WINDOWS/system32" or is that purely for the OS. I would assume that this is the case (OS only) but I like to never assume anything.

    One of the apps is Office (seems very functional at the moment) and also WoW (completely corrupted) as examples.

    Researching Microsoft for the missing files now.
     
  9. Bold Eagle

    Bold Eagle MajorGeek

    A bit of research and I have found a thread with someone who has XP Professional x64 and seems to mirror the "exact" same missing files in his hjt log (for Windows/services32 that is), Im still digesting this but it looks to similar to be coincidence:

    http://www.geekstogo.com/forum/Win32-p2p-cant-get-rid-it-t59320.html

    Just letting you know that their is a specfic issue here so you dont waste anytime with it.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No many programs put things into the Windows and system32 folder. This is a major short coming of the design of Windows which has open the door for malware issues and corruption of OS files due other programs overwriting them with incorrect versions.

    Anything for your OS, you should be able to get from your CD or from installation update folders on your hard disk.

    You are really outside the realm of the Malware Forum. You do not have any malware problems for us to address. It would be best for you to continue working and ansking any further questions in the Software Forum.

    By the way, as stated in the Using MGtools link, it is not compatible with x64. While some scans work, others only work partially and some not at all. I have created an x64 version of GetRunKey.bat but have not found an easy way to get ShowNew.bat to do what I need on x64 since tools being used will not run on x64.
     
  11. Bold Eagle

    Bold Eagle MajorGeek

    Thank you again, I am progressively removing all of my corrupted apps as I believe this was causing issues with the "sfc /scannow" causing WINDOWS to search for files that weren't part of the original OS. Google Earth was completely shot as an example, just taking baby steps and ensuring "Restore Points along the way. From what I gathered in the last thread I linked the HJThis Log will show some false positives for missing files in a 64Bit environment and that may explain most of the missing xxx.exe appearing in my log.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes HijackThis has issues with sometimes showing files to be missing when they are not. Thus you should really first just check to see if the files are really missing. Then if not missing check the status of the services themselves using services.msc to see how they are configured and if they are configure properly.
     
  13. Bold Eagle

    Bold Eagle MajorGeek

    All services present and accounted for, with half being Automatic some Manual, even started 1-2 to ensure they functioned and it all "seems" okay at the moment., thanks.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that sounds good. Good luck with the rest of your issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds