Windows cannot find C:\windows\system32\vturs.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by kkwilson5, Mar 16, 2009.

  1. kkwilson5

    kkwilson5 Private E-2

    I'm on XP Home and whenever I log into 1 of my accounts, I get the 'Windows cannot find c:\windows\system32\vturs.exe'.... If I click on Ok, I get the 'Could not load c:\windows\system32\vturs.exe as specified in the registry'. This only happens on 1 of my particular accounts which I don't often log into. On my main account, I don't receive the message. I have Symantec antivirus software and it is up to date. I have also ran a scan on both accounts with nothing found. Any ideas on where I should start?
     
  2. kkwilson5

    kkwilson5 Private E-2

    I have completed the Malware removal guide (logs attached). I am still getting the same error message logging into 1 of my accounts. I usually don't use this account. While logging into my main account, I was getting a acrobat.come.exe folder that was popping up when logging in, but haven't gotten it again since running all of the malware removal steps. The first potion has been happening for the past few months. Any help would be appreciated. I was also unable to upload the combofix.txt file because it was too large.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Had you sometime in the past ran ComboFix and didn't delete its folder? Have you ran it more than once?

    Please zip the combofix.txt file that was ran during this removal session and attach it.

    Thanks
     
    Last edited: Mar 21, 2009
  5. kkwilson5

    kkwilson5 Private E-2

    Here is the combo fix log zipped up. I also notice in the msconfig on that user account where the error comes up, that the vturs.exe is listed in the startup. Not sure if that helps any. Thanks.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, kkwilson5


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.


    Step 1:
    First - Navigate to C:\Qoobox and delete all SnapShot.dat files. <---- This is the cause of your huge ComboFix.txt log, brought on by NOT following instructions from last year's malware thread.


    Step 2:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 4:
    Now run CCleaner

    Step 5:
    Re-boot and log into the "problem account"
    Update the definitions and run all scanners on this account

    Step 5:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • SAS log
    • MBAM log
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  7. kkwilson5

    kkwilson5 Private E-2

    Attached are the logs. Everything ran fine. After a reboot, I am still getting the error logging into the one user account. Thanks.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, kkwilson5

    Pre-instructions: Make sure that you are logged into the "problem account".


    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 2:
    Now we need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Step 3:
    Run Ccleaner

    Step 4:
    New versions of SAS & MBAM has been released.
    Uninstall SAS > run CCleaner > download and update the latest version. Also - update MBAM, then run both scanners.

    Step 5:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • SAS log
    • MBAM log
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  9. kkwilson5

    kkwilson5 Private E-2

    Attached are the logs from running the last set of instructions. After running those and doing a restart, the problem error message did NOT pop up when logging into the problem account. Let me know if there is anything else hiding in the logs.

    Thanks!!
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello again, kkwilson5

    One last thing to do - let's see if this registry key is now found on your pc.


    Now download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a permanent folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independent) and click Ok... option, enter the below string (use copy and past)
      • FarStoneFireWallDrive
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds