Minor? Errors on W7 startup

Discussion in 'Software' started by Dumb_Question, May 23, 2014.

  1. Dumb_Question

    Dumb_Question Sergeant Major

    I have a couple of errors come up whenever I start Windows 7 (consistently every time I boot up)

    The first one has always been there (ever since I inherited the computer). It seems to be an issue with Apple software but as I don't use that, I'm ignoring that message (unless a Geek tells me that I shouldn't...). I find it a bit annoying to have any errors come up but I can live with that one (screen shot attached, 1stErrorOnStartingW7.jpg)

    The other error has started appearing maybe a couple of months ago or more recently, it doesn't appear to do anything, but it looks more sinister to me. It's title is RegSvr32. I would like some comments on this one please along the lines of why it's there, what it means, any consequences, how to fix it... (attached screenshot 2ndNewErrorOnStartingW7.jpg)

    Dumb_Question
    23.May.2014

    HP Pavilion dm4 1050ea - 8GB RAM - Windows 7 "Home Premium" 64-bit
     

    Attached Files:

  2. _nullptr

    _nullptr Major Geeky Geek Geek

    As you're not using iTunes, uninstalling iTunes should get rid of the first error.
    The second error looks like a registry remnant from an undesirable file. Have you had any malware or potentially unwanted programs detected around the time you started getting that error?
    If you have CCleaner installed, have a look under Tools-> Startup->Windows tab and see if it's listed.
     
  3. Dumb_Question

    Dumb_Question Sergeant Major

    Thanks for taking the trouble to answer, -nullptr

    I would prefer to leave the computer much as I 'found' it, I know I am able to iTunes from the user I created for myself with Administrator privileges but I don't want to (iTunes is there, created by another account/user [the former] of the PC)

    I now do have CCleaner. I can't remember if I'd had malware certainly none found in scans using AVG or msert.exe, but maybe some that instantly spotted and dealt with by AVG's real time protection ? I have not removed any "procedurally".

    I don't understand "Tools-> Startup->Windows tab" - in my Explorer toolbar/menu under Tools there isn't a Startup item and in CCleaner under Tools also there is not a Startup item.

    Dumb_Question
    23.May.2014
     
  4. _nullptr

    _nullptr Major Geeky Geek Geek

    Download Autoruns, create a directory and extract the content of the zip file to the directory. Right click on Autoruns.exe and 'Run as administrator'. When it has finished scanning, Go to File -> Save and save AutoRuns.arn to somewhere convenient like your documents folder. Zip Autoruns.arn and attach to your post.
     
  5. Dumb_Question

    Dumb_Question Sergeant Major

    OK I found Tools > Startup > Windows tab (it was obvious after I max'ed the CCleaner window)

    There, I matched the error
    it's enabled, KEY=HKCU:Run Program=Ympack Publisher=Microsoft Corporation File=regsvr32.exe C:\Users\EdwardAppData\Local\Ympack\igldev.wmv

    Dumb_Question
    23.May.2014
     
  6. _nullptr

    _nullptr Major Geeky Geek Geek

    It's up to you, either disable the entry or delete it.
    Do you have any anti-malware software installed, e.g Malwarebytes' Anti-Malware? If you do, update the definitions and run a scan.
    If anything is detected, post the log but don't have MBAM fix anything at present.
     
  7. Dumb_Question

    Dumb_Question Sergeant Major

    Thank you for your suggestions _nullptr
    I ran msert.exe and JRT.exe before running malwarebytes (free)
    JRT came back apparently blank, msert came back with 5 infections, but only 3 listed
    Exploit:Java/CVE-2013-1493
    Trojan:Win32/Miuref
    Trojan:Win32/Miuref.C
    all of which were "partially removed" but showed again in a second scan

    Malware bytes detected 20 registry items, 3 file items and 1 other registry item
    I've attached screenshots of the msert findings and the mbam log file (text)

    Dumb_Question
    14.May.2014

    (may be something odd has happened when I try to attach those files ?)
     

    Attached Files:

  8. falconattack

    falconattack Command Sergeant Major

  9. Dumb_Question

    Dumb_Question Sergeant Major

    Thanks for answering my plea falcon attack. However the reports from msert do not say that I have Miuref gen A only Miuref.C (do you have a trusted reference for that ?) and Miuref...no variant or type. You may have deduced A from my mbam log of course. But I'm not certain what I should do. Also if this is a serious and known problem, why isn't AVG detecting it ? Is it just that no antivir program is perfect ?

    Dumb_Question
    24.May.2014
     
  10. falconattack

    falconattack Command Sergeant Major

  11. Dumb_Question

    Dumb_Question Sergeant Major

    np falcon attack,

    thank you for the further info, I should be able to tackle that one now, though I am dreading it.

    Dumb_Question
    24.May.2014
     
  12. Dumb_Question

    Dumb_Question Sergeant Major

    I have done some preliminary work (just searching for the items) on following the removal procedure of Miuref.C as given in the link by Falcon Attack, and none of the files or registry entries outlined for deletion in that procedure can be found on my PC. (here I remind peeps that msert.exe was "partially " successful in removing the 3 infections it found including Trojan:Win32/Miuref.C)

    Given that I also still have the items detected by malwarebytes hanging over me, what now ? Please advise.

    Dumb_Question
    25.May.2014
     
  13. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi DQ

    Knowing that you still have these references listed in MBAM I would run the below and start a tread in our malware forum area and let Charlie, Tim and Emma et al review your logs and advise as they see these things day in day out, and it may just need some manual removal instruction to get rid as some malware is not easily removed automatically.


     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds