Emergency

Discussion in 'Malware Help (A Specialist Will Reply)' started by mizz_britain, Sep 15, 2008.

  1. mizz_britain

    mizz_britain Private E-2

    I was told to post here when I was done so here it is

    Problems: My computer at first just wouldn't let me send out-going email through outlook. Then everytime I started up the computer the monitor won't show up, it takes a few shutting on and off by pressing the button on the front of the computer to get the monitor to get going. Shutdown does this as well except I have to shut down manually, it won't shut down by itself. Then all of the sudden Internet Explorer won't open and all my other programs take about 15-20 minutes to open, everything is slow! Is it a virus, spyware, what is it? I have ran Ad-ware on it and it didn't find anything, and I'm running CA Antivirus now. Can someone please help?

    NOW - It still turns on and off when it wants to, my internet explorer and outlook express get error messages when I try to open them as well as other programs, one says that it can't find the file install_app.exe. My computer is a Compaq Presario SR1820NX.

    ------------------------
    I completed all steps that I could except MGtools couldn't finish because this error came up...

    C:\Windows\system32\cmd.exe
    System CurrentControlSet\ControlSet\Control\VirtualDeviceDrivers.VDD
    Virtual Device Drive format in the registry is invalid.

    and this error...

    Application has generated an exception that could not be handled. Process id= 0xf50 (3920), thread id= 0xd40 (3392)

    I tried the debug option but it wouldn't let me

    Attached are my logs of the other programs
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First I have to ask why you are posting here at Major Geeks when you already have a thread going on these problems at Tech Support Forums. It is a waste of precious resources in forums like this to have multiple forums tied up trying to help you. You really need to work in only one forum. Our cleaning procedures have detected and removed some malware and you appear to have more to remove but this may not be the cause of all of your problems.

    You need to read the information given in the Using MGtools link where this error and the fix was already explained.

    The other error is not a problem.

    Also note that the problem with your monitor is not an issue for the Malware Forum. This is a hardware issue and should be posted in the Hardware Forum. But you were already told this at the other site too. Not being able to send outgoing email may just be a software issue. Did you allow Outlook to have access via your firewall?
     
    Last edited: Sep 15, 2008
  3. mizz_britain

    mizz_britain Private E-2

    the other guy wasn't getting me anywhere so I thought I'd get a second opinion.

    i fixed that problems but the other error message is still stopping mgtools from finishing running.

    heres the exact message..

    Application has generated an exception that could not be handled. Process id= 0xf50 (3920), thread id= 0xd40 (3392)
    click ok to terminate and cancel to debug

    so i click cancel and this comes up...

    Registered JIT debugger is not available. An attempt to launch a JIT debugger with the following commandresulted in an error code of 0x2 (2). Please check computer settings.

    cordbg.exe !a 0xaa4

    i have my firewall turned off and it worked previously before I packed up and moved my computer.
     
    Last edited: Sep 16, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not stop it from running. Attach the MGlogs.zip file.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you are still posting there and you are also posting here. You should finish what you started at the other forum. We cannot afford the waste of resources. We are just too busy to spend the time having people helped in multiple locations. And the logs you have attached thus far are not showing any remaining malware problems so it is unlikely that your issues are malware related.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I take this back. I had a note to myself that I forgot about. There were two suspicious files I noticed. Do you have any idea what the below driver file is for that seems to have appearer on May 28th?

    S3 luD32;luD32;C:\WINDOWS\System32\drivers\luD32.sys [2008-05-25 29056]

    And also the below file which has an old date is suscpicious

    1989-12-12 14:10 510,000 -csh--r C:\WINDOWS\eueycvw.exe

    Do you recognize this hidden system file.
     
  7. mizz_britain

    mizz_britain Private E-2

    no i dont recognize these files
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still waiting for the MGlogs.zip file. ;)
     
  9. mizz_britain

    mizz_britain Private E-2

    heres the log attached ;-)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have left overs from Symantec on your PC. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Compaq_Owner.MICHELLE\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. mizz_britain

    mizz_britain Private E-2

    After running Norton Removal Tool (SymNRT) it had to restart so I let it and it had trouble restarting. I think its because of these errors I found in the Event Viewer, I've attached the errors
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything and if these are the same kind of errors you attached at the other forum. You can continue to work them there since they are not malware problems and you are still working in that forum. We will only address the malware items I saw in your logs here.

    Continue on with the other steps.
     
  13. mizz_britain

    mizz_britain Private E-2

    When I tried to "Now use your mouse to drag CFscript.txt on top of ComboFix.exe" it didnt do anything? The rest of the steps I finished with success.

    edit: oppss. i didn't post these logs at the other forum.
     
    Last edited: Sep 17, 2008
  14. mizz_britain

    mizz_britain Private E-2

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get ComboFix to run. Try again. This is the main and most important part of the fix. Make sure you exit all security software before trying to run this procedure. Your CA protection software is may be getting in the way.

    You need to attach logs here. If they are not attaching it more than likely means you are trying to attach the same logs as the last time and not new logs.
     
    Last edited: Sep 17, 2008
  16. mizz_britain

    mizz_britain Private E-2

    I double made sure my antivirus was off and I ran combo fix again and says this

    Scanning for infected files...
    This typically doesn't take more than 10 mintues
    However, scan times for badly infected machinesmay easily double

    and doesnt go any farther, I've had it running for over 2 hours and havent touched it
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's use another tool.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Compaq_Owner.MICHELLE\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds