Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.| Important Announcement: The winners of the BC Million Post contest have been announced. You can read who the winners are at this post. - BleepingComputer Management |
When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Aug 9 2008, 04:13 AM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 15 Joined: 16-July 08 Member No.: 223,141 |
there seems to be some problem with the mp3 files.whenever a mp3 file is played with winamp the sound seems to be skipping(fast forwarded). i recently downloaded a file from the net and it contained an two .exe files . i ran one of them .but it suddenly disappeared and was nowhere to be found. as a habit i always scan all the files that i download before running them .i have ESET smart security business edition but it did not detect any threat in them.since then the pc began to act strangely.i have windows XP sp2 and since then the shut down process had a problem.the series of events that take place during a normal shut down took place except that at the time when the pc must shut down a dark blue screen with the error message was displayed.it read "windows logon process terminated unexpectedly with status of 0x00000000 the system has shut down" i was desperate to solve the problem and ran SD fix.that solved only one of the two problems .the error message wasnt seen since then.but my audio still remains distorted.the twist in the tale is that when i play the audio with media player classic ,windows media player it seems to be ok.but when i transfer it into my portable mp3 player the the sound remains distorted.the windows environment seems to run fine except during the first two minutes. hope someone looks into this matter at the earliest . thank you |
|
|
|
Aug 11 2008, 04:35 PM
Post
#2
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 8,485 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
If you have reason to believe that you are infected, let me move you to the proper forum
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Avatar by Handplane |
|
|
|
Aug 12 2008, 02:59 AM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 15 Joined: 16-July 08 Member No.: 223,141 |
thanks garmanma
|
|
|
|
Aug 12 2008, 03:02 AM
Post
#4
|
|
|
Member ![]() ![]() Group: Members Posts: 15 Joined: 16-July 08 Member No.: 223,141 |
now that im in the proper forum i hope that someone is going to help me soon
|
|
|
|
Aug 12 2008, 11:17 AM
Post
#5
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 9,305 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Hello,is this an XP machine?
Would you post the SDFix report..copy and paste the contents of Report.txt in your next reply. Also run MBam Please download Malwarebytes Anti-Malware and save it to your desktop. alternate download link 1 alternate download link 2
-------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... |
|
|
|
Aug 12 2008, 10:13 PM
Post
#6
|
|
|
Member ![]() ![]() Group: Members Posts: 15 Joined: 16-July 08 Member No.: 223,141 |
good to hear from you boopme.yes this is an XP sp2
thanks for replying.not only mp3 but all the audio files have been corrupted.the latest sound files that i have downloaded recently from the net seem to be ok.i have a lot of mp3 songs and im unable to recover them. here is the SD fix log that you have asked for.i recently got a threat alert from eset nod32 av.it detected a new threat and used to alert me frequently.but during the last few days i did not get any threat alert of that sort .im posting the eset log too hope you might find it helpful. SDFix: Version 1.208 Run by RITU on Fri 08/08/2008 at 09:13 AM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : Trojan Files Found: C:\WINDOWS\system32\WINETN32.dll - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-08 09:17:57 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server" "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype" "C:\\WINDOWS\\system32\\dpnsvr.exe"="C:\\WINDOWS\\system32\\dpnsvr.exe:*:Disabled:Microsoft DirectPlay8 Server" "C:\\WINDOWS\\system32\\winver.exe"="C:\\WINDOWS\\system32\\winver.exe:*:Enabled:winver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Fri 8 Feb 2008 334 A..H. --- "C:\WINDOWS\Fix.reg" --- 4,263 ..SH. --- "C:\WINDOWS\windllreg1c.sys" Mon 22 Jul 2002 418,816 ...HR --- "C:\WINDOWS\system32\Tools\All.exe" Fri 19 Jul 2002 390,144 ...HR --- "C:\WINDOWS\system32\Tools\Change.exe" Fri 19 Jul 2002 574,464 ...HR --- "C:\WINDOWS\system32\Tools\CheckPath.exe" Tue 20 Aug 2002 430,592 ...HR --- "C:\WINDOWS\system32\Tools\Counter.exe" Tue 23 Jul 2002 390,656 ...HR --- "C:\WINDOWS\system32\Tools\DelFolders.exe" Fri 22 Nov 2002 399,872 ...HR --- "C:\WINDOWS\system32\Tools\DirectSetup.exe" Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RegClean.exe" Fri 19 Jul 2002 388,608 ...HR --- "C:\WINDOWS\system32\Tools\Regexe.exe" Mon 2 Dec 2002 431,616 ...HR --- "C:\WINDOWS\system32\Tools\Restart.exe" Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RunRegexe.exe" Finished! /*ESET anti virus log/* 10/08/2008 8:16:21 PM HTTP filter file http://v.freefl.info/day.js JS/TrojanDownloader.Iframe.NAQ trojan connection terminated - quarantined USER-A878673C18\RITU Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe. /*MBAM log*/ Malwarebytes' Anti-Malware 1.24 Database version: 1012 Windows 5.1.2600 Service Pack 2 9:18:58 AM 13/08/2008 mbam-log-8-13-2008 (09-18-58).txt Scan type: Quick Scan Objects scanned: 44943 Time elapsed: 5 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{a9895933-6636-4281-bc58-ee6de2af96e3} (Spyware.OnlineGames) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{da191de0-aa86-d04e-4b87-2a3d4928be99} (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) thanks again for replying boopme. This post has been edited by gggg_hhhh: Aug 12 2008, 10:50 PM |
|
|
|
Aug 13 2008, 09:09 AM
Post
#7
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 9,305 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Ok ,check for an update and rescan with the Malwarebytes. Post another log. Are all the issues still gone?
-------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... |
|
|
|
Aug 13 2008, 10:57 AM
Post
#8
|
|
|
Member ![]() ![]() Group: Members Posts: 15 Joined: 16-July 08 Member No.: 223,141 |
i updated it and performed a quick scan
here is the log Malwarebytes' Anti-Malware 1.24 Database version: 1048 Windows 5.1.2600 Service Pack 2 9:26:10 PM 13/08/2008 mbam-log-8-13-2008 (21-26-10).txt Scan type: Quick Scan Objects scanned: 46075 Time elapsed: 10 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{97421d0d-e07f-40df-8f07-99597b9585ad} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\thunderadvise.thunderhlpobj (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\thunderadvise.thunderhlpobj.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97421d0d-e07f-40df-8f07-99597b9585ad} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) thank you |
|
|
|
Aug 13 2008, 02:20 PM
Post
#9
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 9,305 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Update and run the MBam once more. Post the log again please.
-------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... |
|
|
|
Aug 14 2008, 02:26 AM
Post
#10
|
|
|
Member ![]() ![]() Group: Members Posts: 15 Joined: 16-July 08 Member No.: 223,141 |
her is the log that u have asked for
the sound still remains distorted when played on my mp4 player Malwarebytes' Anti-Malware 1.24 Database version: 1052 Windows 5.1.2600 Service Pack 2 12:53:10 PM 14/08/2008 mbam-log-8-14-2008 (12-53-10).txt Scan type: Quick Scan Objects scanned: 47468 Time elapsed: 5 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) thanks for replying /*gggg_hhhh */ |
|
|
|
Aug 14 2008, 11:10 AM
Post
#11
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 9,305 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
As it now no longer to be malware related please ask a new question in the Audio and Video forum.
-------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22nd November 2008 - 03:09 PM |