Still having some problems, could somebody read this log for me?

Discussion in 'Malware Help (A Specialist Will Reply)' started by pace, Dec 5, 2004.

  1. pace

    pace Private First Class

    On the windows Audio, the path to executable is blank.

    On the Vaio Media the path to execution is:

    "C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application)"

    "C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP"

    C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

    The Windows audio and the vaio products are all set on automatic. I also noticed the following is stopped:

    Windows Image Acquisition (WIA)
    Windows Installer
    Windows Management Instrumentation
    WMI Performance Adapter
    Universal Plug and Play device host
    Uninterruptable Power Supply
    Smart Card
    Smart Card Helper
    ZeSoft Driver
    Sony SPTI Service

    Thanks,

    Shannon
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do these 3 files exist on your PC:

    C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

    Windows Image Acquisition (WIA) <-- should be stopped and Manual
    Windows Installer <-- should be stopped and Manual
    Windows Management Instrumentation <-- should beStarted and Automatic
    WMI Performance Adapter <-- should be stopped and Manual
    Universal Plug and Play device host <-- should be stopped and Manual
    Uninterruptable Power Supply <-- should be stopped and Manual
    Smart Card <-- should be stopped and Manual
    Smart Card Helper <-- should be stopped and Manual
    ZeSoft Driver <-- should be stopped and Disabled and Deleted from your PC. It's malware.
    Sony SPTI Service <-- should beStarted and Automatic
     
  3. pace

    pace Private First Class


    The three files do exist. Also, I made sure all the settings are correct and I restarted Sony SPTI Service, but still cannot start the Windows audio, it still shows no path to executable.

    Thanks,

    Shannon
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying the Windows audio service (seen from services.msc) is blank in the box for Path to executable?

    If the answer is yes, paste the below in the Path to executable box:
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    Then click Apply and make sure Startup type is Automatic. If Service status does not say Started, click Start. Let me know what happens. If still no sound, reboot and see what happens.
     
    Last edited: Jan 12, 2005
  5. pace

    pace Private First Class

    Yes the path to executable box is blank and the start parameters box is also blank. The startup type box says automatic.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I edited and add something to do below! Check the previous message again.
     
  7. pace

    pace Private First Class

    It will not let me type or paste in the path to executable box. I can type in the start parameters box, I can get a cursor to flash in the executable box but it will not let me add anything.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try entering that in the Startup box and click start.
     
  9. pace

    pace Private First Class

    I tried that before and just tried it again and I get the same error message saying it cannot start Windows Audio on local computer.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you click the LogOn tab: what do you see? When buttons are checked and at the bottom in the Hardware Profile box, is the service enable for the Profile 1
     
  11. pace

    pace Private First Class

    The LogOn tab has:

    Log On as:

    Local System Account is on
    Allow Service to interact with desktop is not checked

    This Account is not checked
    password: box is empty.

    Hardware Profile:
    profile1 is enabled.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Regedit and navigate to the below key:

    HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\Root\LEGACY_AUDIOSRV\0000

    What is in the right window pane for
    Class
    ConfigFlags
    DeviceDesc
    Legacy
    Service

    Then repeat for
    HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv

    Repeat for
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AudioSrv
     
  13. pace

    pace Private First Class


    For:

    HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\Root\LEGACY_AUDIOSRV\0000

    What is in the right window pane for
    Class REG_SZ Legacy Driver
    ConfigFlags REG_DWORD 0X000000(32)
    DeviceDesc REG_SZ WINDOWS AUDIO
    Legacy REG_DWORD 0X00000001 (1)
    Service REG_SZ AudioSrv

    For:
    HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv

    (Default) REG_SZ (Valute not set)
    DependonService REG_MULTI-SZ PlugPlay RPCSs
    Description REG_SZ Manages audio devices in windows
    Display Name REG_SZ Windows Audio
    Error Control REG_DWORD 0X00l System000001(1)
    GROUP REG_SZZ Audio Group
    Object Name REG_SZ Local System
    Start REG_DWORD 0X00000002(2)
    TYPE REG_DWORD )X00000020(32)

    For:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AudioSrv[/QUOTE]

    (Default) REG_SZ (Valute not set)
    DependonService REG_MULTI-SZ PlugPlay RPCSs
    Description REG_SZ Manages audio devices in windows
    Display Name REG_SZ Windows Audio
    Error Control REG_DWORD 0X00l System000001(1)
    GROUP REG_SZZ Audio Group
    Object Name REG_SZ Local System
    Start REG_DWORD 0X00000002(2)
    TYPE REG_DWORD )X00000020(32)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there an ImagePath subkey in either of those last two registry keys and is it blank? Or does it not exist at all.
     
  15. pace

    pace Private First Class

    I dont see an image path subkey in either directory.

    Shannon
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also do you have another key like HKEY_LOCAL_MACHINE\System\ControlSet001
    but called ControlSet002 or ControlSet003
     
  17. pace

    pace Private First Class

    I have one named ControlSet002
     
  18. pace

    pace Private First Class


    I just reviewed the right pane of the editor and ControlSet002 has the same entries as ControlSet001

    Shannon
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is what I want you to do for each of the below three keys! Get to the key an make sure it is selected (it will show in the bottom of the window what I show below). Then click File, Export and give it a file name (indicated in red below) and save it where you can find it.

    My Computer\HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AudioSrv .....save to CCS-Audio
    My Computer\HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv .....save to CS001-Audio
    My Computer\HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AudioSrv .....save to CS001-Audio

    When saved the system will add a .reg to the end of each. Goto the directory where you saved them and put them all in a ZIP file and upload it here. Hopefully you know how to use WinZIP.
     
  20. pace

    pace Private First Class

    I have attached the Zip files.
     

    Attached Files:

  21. pace

    pace Private First Class

    Here is the third file of ControlSet002.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had a typo! You need to copy ControlSet002 to CS002-Audio and post it to in a ZIP.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I see you figured that out!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! This may take awhile to look at. And I want to have you backup your registry since we will be making changes to it. Download Erunt and use it to get a registry backup. Let me know when you complete that and I'll get back to you when I get finished figuring out what we need to do.
     
  25. pace

    pace Private First Class

    I backed it up and double checked the file to make sure the back-up was in there.

    I am going to have to get off of here and get some sleep, so I will talk at ya tomorrow. Thanks for all your help with this.

    Shannon
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Talk to you later tomorrow (today)!
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay download the attached ZIP file and extract the fix-audio.reg file from it. Then double click on it and say yes when asked about merging into the registry. Then reboot and take a look at the Windows Audio service now. Has it changed? If so, any sound?
     

    Attached Files:

  28. pace

    pace Private First Class

    That Got It! The sound plays great and the following is listed in the Windows Audio path to executable file:

    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Thank you for the help with this, I really do appreciate it.

    Shannon
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm happy we got that all worked out!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds