Here are my logs attached/Problem with PC soung:(

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by elli, Jun 16, 2011.

  1. elli

    elli Private E-2

    Good morning everyone

    I don`t know if the problem I have is anyway connected to the malwares, but as I got advice in other thread,I decided to run through the malware removal instructions.

    The problem began after reinstaling windows Windows XP 2002. SP3, v.3300 (I haven`t done it myself),after reinstaling everything is working properly but only there is no sound. (Of course speakers are connected correctly,turned on and are not muted )
    The other problem is that I can`t access Device Manager to check my devices,I don`t know either I have sound device or not.I don`t get any errror Device Manager just doesn`t open:(

    I tried to follow all the steps from Malware Removal Guide,Here is the steps I have made:
    1.Uninstalling Multiple Protection Applications

    2.House Cleaning
    Updated Sun Java
    Removed files from AntiVirus Quarantine

    3.Configuration & Setup
    Enabled viewing of hidden files, system files and file extensions
    Set MSconfig for Normal Startup mode

    4.From the Known Malware and Unwanted Software list on my programs I only found Ask Toolbar, but I couldn`t uninstal it.While uninstaletion process I get the error like this: [error 1722:There is a problem with this windows installer package.A program run as part of the setup didn`t finish as expected.Contact your support personnel or Package vendor.Action uninstallTaskScheduler,location:
    C:/WINDOWS/INSTALLER/MS130.tmp,command:/U]
    As it was said in Windows XP Malware Removal/Cleaning Procedure I downloaded and installed all the needed software.
    SUPERAntiSpyware - running & getting a log
    After the scan i got two logs Under Scanner Logs,both are attached below as SASlog.txt1.txt and SASlog.txt2.txt
    Malwarebytes Anti-Malware
    The scan detected only 2 Files Infected (mbam-log-2011-06-15 (23-38-39).txt is attached)
    whats about combofix.exe ,I downloaded it many times,from all possible links and tried to run but all time I get same error:[NSIS ERROR:Installer intergitly check has failed.Common causes include incomplete download and demaged media. Contact the installer`s author to obtain a new copy]
    RootRepeal
    I have attached the log RRlog.txtas well

    View attachment SASlog.txt1.txt

    View attachment SASlog.txt2.txt

    View attachment mbam-log-2011-06-15 (23-38-39).txt

    View attachment RRlog.txt
     
    Last edited by a moderator: Jun 16, 2011
  2. elli

    elli Private E-2

    As for MGTools.exe program,it extract a bunch automatically,but it didn`t start running three batches automatically,as it was said.I opened analyse.exe and click "Do a system scan and save a log file".
    I couldn`t attach the hole MGtools.zip file to the massage, as it failed each time so I attached the hijackthis.log here View attachment hijackthis.log

    the device manager is not working still:(

    Any advice will be appreciated

    waiting for your reply and thanks beforhead :)
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try again to attach the C:\MGlogs.zip, perhaps using another browser.

    Otherwise upload the whole zip to Mediafire.com and share the link with me.
     
  4. elli

    elli Private E-2

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have attached the whole folder instead of just the MGLogs.zip hence you had issues uploading to our forums.

    Please attach the C:\MGlogs.zip as requested. :)
     
  6. elli

    elli Private E-2

    I realized that I was doing something wrong))))))))))))

    but don`t know what to do with this MGtools , as I have read here "It will the automatically start running three batch ( .bat files are batch programs ) programs in that folder" but it isn`t

    what should I do rolleyes

    thanks in advance
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Got a C:\MGLogs.zip now?
     
  8. elli

    elli Private E-2

    Hello Kestrel13

    unfortunately I couldn`t get C:\MGLogs.zip anyway
    the first command succeeded ,but after second and third command I got the error massage like this: `find` is not recognized as an internal or external command,operable program or batch file :(
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just try double clicking on the C:\MGTools.exe (it has to be right click and run as admin for vista/win7 users) See if the program then runs and produces the very much needed C:\MGlogs.zip, if it does NOT then you will need to use a similar tool because I need to gather inmformation before I can help you.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  10. elli

    elli Private E-2

    Kestrel13,

    when I click MGtools.exe it only extracts files to MGtool folder which I have attached earlier nothing more.

    I downloaded OTL and here are the log files:
    View attachment OTL.Txt
    View attachment Extras.Txt

    hope I`ve done it in correct way:)
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can uninstall the below as they are garbage.

    • ParetoLogic PC Health Advisor
    • Ask Toolbar

    You should definately uninstall this if you want my help. ;)

    • NOD32 v3.x FiX 1.1 by TemDono_is1" = NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)

    Warning about Porn, Keygens, Cracks, and other Illegal Software

    Run OTL again and attach the log.
     
  12. elli

    elli Private E-2

    I have uninstaled ParetoLogic PC Health Advisor

    But I can`t uninstal Ask Toolbar and NOD32 v3.x FiX 1.1 by TemDono_is1" = NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050) from Control panel ->add/remove programs

    While uninstaling Ask Toolbar I get the same error as earlier: [error 1722:There is a problem with this windows installer package.A program run as part of the setup didn`t finish as expected.Contact your support personnel or Package vendor.Action uninstallTaskScheduler,location:
    C:/WINDOWS/INSTALLER/MS130.tmp,command:/U]
    and what`s about NOD32 the remove button just don`t works,nothing happens.
    is there any different way to uninstal them?:confused
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Try Revo Uninstaller.

    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.
     
  14. elli

    elli Private E-2

    Kestrel I could uninstal NOD32 by Revo Uninstaller,but while uninstaling Ask Toolbar I get the same error as before:( and also I can`t open add/remove programs folder any more I get massage that windows can not find C\WINDOWS\system32\rundll32.exe
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rename C:\MGTools.exe so you have C:\sc7y.com instead. (Make sure you have hidden files and folders set to show before hand so you do not end up with a double file extension such as sc7y.exe.com )

    To display hidden files and folders


    Does it run now? Try in safe mode if necessary.
    Let me know.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also run this even if MGTools does not run

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run
     
  17. elli

    elli Private E-2

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run OTL again and attach the log.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think the version of TDSSKiller you ran was outdated! I need to be away from the computer for a little while so get rid of the version you have and redownload. ( Note: To make it easier for you make sure you download the TDSSKiller.exe file and not TDSSKiller.zip )
     
  20. elli

    elli Private E-2

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You badly need to clean out this temp folder:
    • C:\Documents and Settings\YOUR USERNAME\Local Settings\Temp
    Delete everything that you are able to in there.

    Tell me what is inside of this folder please.
    • C:\Documents and Settings\Administrator\Local Settings\Application Data\.#

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "DisableCAD"=-
    
    :files
    C:\WINDOWS\nod32fixtemdono.reg
    C:\WINDOWS\System32\D7FE86
    C:\WINDOWS\system32\6AAE8F
    C:\Documents and Settings\Administrator\Local Settings\Temp\dcnl.exe
    C:\Documents and Settings\Administrator\Local Settings\Temp\nhml.exe
    C:\WINDOWS\system32\E32BF6
    
    :Commands
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    How about now? Any improvement?

    Run OTL again and attach the log please.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      rundll32.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  22. elli

    elli Private E-2

    Kestel I have deleted files from the Temp folder,but I couldn`t delete three of them:
    1)E_4
    2)winacues
    3)winuoyci.
    I get error that access is denied
    As for the second folder,Application Data consist of different sub folders as:
    Adobe
    Ask Toolbar-I have deleted this file
    ESET->Quarantine
    Help
    Identities
    Microsoft
    Microsoft Help
    Opera
    Package Aware
    GDIPFONTCACHEV- DAT File
    this colored folders are empty,I had only deleted Ask toolbar folder

    I downloaded OTM and run it but it didn`t help me with add/remove programs.I still get the same error:
    "windows can not find C\WINDOWS\system32\rundll32.exe"
    Here are the OTM and OTL log files
    View attachment 06252011_124350.log
    View attachment OTL.Txt
    but SystemLook is not working,when I try to run it I get error that "this application has filed to start because the application configuration is incorrect.Reinstalling the application may fix this problem":(
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is this?

    C:\fkfi.exe

    Does this file exist?

    C:\WINDOWS\system32\rundll32.exe

    Is it really missing?


    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the Image textbox. Do not include the word Code
    Code:
    :OTL
    
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
    O33 - MountPoints2\{32e70ff0-9d91-11e0-9a75-00195b692f6b}\Shell\AUToplAy\COMMand - "" = F:\auhl.pif
    O33 - MountPoints2\{32e70ff0-9d91-11e0-9a75-00195b692f6b}\Shell\AutoRun\command - "" = F:\auhl.pif
    O33 - MountPoints2\{32e70ff0-9d91-11e0-9a75-00195b692f6b}\Shell\expLorE\CommaND - "" = F:\auhl.pif
    O33 - MountPoints2\{32e70ff0-9d91-11e0-9a75-00195b692f6b}\Shell\oPen\cOMmaNd - "" = F:\auhl.pif
    O33 - MountPoints2\{32e70ff1-9d91-11e0-9a75-00195b692f6b}\Shell\AUtoplAy\commANd - "" = G:\rfjpjo.exe
    O33 - MountPoints2\{32e70ff1-9d91-11e0-9a75-00195b692f6b}\Shell\AutoRun\command - "" = G:\rfjpjo.exe
    O33 - MountPoints2\{32e70ff1-9d91-11e0-9a75-00195b692f6b}\Shell\explorE\CoMMANd - "" = G:\rfjpjo.exe
    O33 - MountPoints2\{32e70ff1-9d91-11e0-9a75-00195b692f6b}\Shell\open\comMaNd - "" = G:\rfjpjo.exe
    O33 - MountPoints2\{57af89d0-9121-11e0-9a4e-00195b692f6b}\Shell\aUToPLay\comManD - "" = F:\yqdt.exe
    O33 - MountPoints2\{57af89d0-9121-11e0-9a4e-00195b692f6b}\Shell\AutoRun\command - "" = F:\yqdt.exe
    O33 - MountPoints2\{57af89d0-9121-11e0-9a4e-00195b692f6b}\Shell\exPLoRe\ComMand - "" = F:\yqdt.exe
    O33 - MountPoints2\{57af89d0-9121-11e0-9a4e-00195b692f6b}\Shell\opeN\COmMand - "" = F:\yqdt.exe
    O33 - MountPoints2\{f3f5c891-903e-11e0-9a42-00195b692f6b}\Shell\aUtopLaY\CommaNd - "" = F:\vpbsv.exe
    O33 - MountPoints2\{f3f5c891-903e-11e0-9a42-00195b692f6b}\Shell\AutoRun\command - "" = F:\vpbsv.exe
    O33 - MountPoints2\{f3f5c891-903e-11e0-9a42-00195b692f6b}\Shell\expLORe\CoMmAnD - "" = F:\vpbsv.exe
    O33 - MountPoints2\{f3f5c891-903e-11e0-9a42-00195b692f6b}\Shell\open\cOmMAnd - "" = F:\vpbsv.exe
    
    :files
    C:\Documents and Settings\Administrator\Local Settings\Temp\winmterja.exe 
    C:\Documents and Settings\Administrator\Local Settings\Temp\winooybgp.exe 
    C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ЎЎЎЎЎЎ.lnk
    :commands
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    Open OTL again to run it and attach the log in your next reply.

    How are things running?
     
    Last edited: Jun 25, 2011
  25. elli

    elli Private E-2

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  27. elli

    elli Private E-2

    Ok I see it`s something serious and it`s up to me to fix it myself,i`d better ask somebody for a help:)

    Thank you very much for your attention and help,I think this information you give me would be very helpful for future steps;)
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The infection you managed to pick up is so severe that you are better off with reinstalling. Not much more can be done apart from that. I dug and dug and then the ESET scan showed me the bad news.
     
  29. elli

    elli Private E-2

    you mean that reinstalling the windows may fix this problem yes rolleyes??
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It will fix it, yes. Have you got important data backed up? You can further discuss all of this in the software forum if you need to.
     
  31. elli

    elli Private E-2

    thank you Kestrel very much:) I don`t know if I have backed up important data
    :(
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Any further questions you may have can be asked in the software forum regarding reformatting etc. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds