malwarebytes not finding malware, issues with running scan and bluescreen

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Im not sure if u want this one, it wasnt combofix.txt but in DeQuarantine was
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe
 

Fiery

Level 1
Jan 11, 2011
2,007
Gbaby614 said:
Im not sure if u want this one, it wasnt combofix.txt but in DeQuarantine was
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe

Ah, that's the log I wanted.

Have you tried restarting your PC?
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i can try again.. it restarted earlier tho not sure if irt was b4 or after this log... restarting now..brb
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Fiery said:
Gbaby614 said:
Im not sure if u want this one, it wasnt combofix.txt but in DeQuarantine was
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe
C:\Qoobox\Quarantine\C\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe.vir -> C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe

Ah, that's the log I wanted.

Have you tried restarting your PC?

I restarted and no video device detected.. also I looked in device manager under display adapters and it will NOT let me update it, I have an update in my windows update and it WILL NOT let me update it from there either.. seeing it is an integrated webcam could this be part of the problem? Is something else in the logs or quarantine preventing this??


I should be seeing Imaging Device in the device manager and I still dont
 

Fiery

Level 1
Jan 11, 2011
2,007
I have basically restore everything except the bad entries from combofix's quarantine folder.. Can you open the files below with notebad again and copy the content?

C:\Qoobox\Quarantine\Registry_backups\SafeBoot-WudfRd.reg.dat
C:\Qoobox\Quarantine\Registry_backups\SafeBoot-WudfPf.reg.dat
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
did quarantine remove anything IDT?? i looked it up and that is Integrated Device Technology


Fiery said:
I have basically restore everything except the bad entries from combofix's quarantine folder.. Can you open the files below with notebad again and copy the content?

C:\Qoobox\Quarantine\Registry_backups\SafeBoot-WudfRd.reg.dat
C:\Qoobox\Quarantine\Registry_backups\SafeBoot-WudfPf.reg.dat

yes.. one sec.. again this msg did not show until i posted my last post...
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd]
@="Driver"


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf]
@="Driver"
 

Fiery

Level 1
Jan 11, 2011
2,007
Ok, let's restore that too. Open notepad and copy the following:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd]
@="Driver"

Choose all file type and save as fix2.reg and merge it like last time. Then restart

Now we have restored everything CF deleted.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
I hope I didnt hurt anything, I found an Intel driver reinstall from the recovery mgr.. it was the closest thing to the one I could update in windows update.. if not i will be back after reboot
 

Fiery

Level 1
Jan 11, 2011
2,007
Please try that in safe mode (restart your laptop and tap F8 continuously until you get to the advance boot option and select[/b] Safe mode [/b]

Then try to merge again then restart your laptop
 

Fiery

Level 1
Jan 11, 2011
2,007
Gbaby614 said:
I hope I didnt hurt anything, I found an Intel driver reinstall from the recovery mgr.. it was the closest thing to the one I could update in windows update.. if not i will be back after reboot

The list in recovery manager includes all the software, even if you already have them.

Did you do a reinstall?
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Fiery said:
Gbaby614 said:
I hope I didnt hurt anything, I found an Intel driver reinstall from the recovery mgr.. it was the closest thing to the one I could update in windows update.. if not i will be back after reboot

The list in recovery manager includes all the software, even if you already have them.

Did you do a reinstall?

it said it reinstalled a driver but i dont see any difference in anything.al. so i did a few important updates from microsoft as a search gave the idea if i did the updates a fix may have been in there.. going to do the above in safe mode now.. will return to let u know if it worked..
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Fiery said:
Please try that in safe mode (restart your laptop and tap F8 continuously until you get to the advance boot option and select[/b] Safe mode [/b]

Then try to merge again then restart your laptop

it wouldnt merge in safe mode either, i had safe mode w networking tho.. It keeps saying a file is open or being used that is preventing the merge?
 

Fiery

Level 1
Jan 11, 2011
2,007
Let's try this:

Open OTL. Under custom scan/fixes, copy and paste the following:

:reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd]
@="Driver"

:commands
[reboot]

Then click Run Fix. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
is there anything in the quote that shouldn't have gotten copied to the fix.reg2??


Fiery said:
Let's try this:

Open OTL. Under custom scan/fixes, copy and paste the following:

:reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd]
@="Driver"

:commands
[reboot]

Then click Run Fix. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.

ok i will try this
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i have two files on my desktop both named desktop.ini are those the logs? i dont see the new OTL.Txt but the one from a few days ago is there, would it be inside that log???
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i just found this log on C:/

========== REGISTRY ==========
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf\\@|"Driver" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf\\@|"Driver" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd\\@|"Driver" /E!
Unable to set value : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd\\@|"Driver" /E!
========== COMMANDS ==========

OTL by OldTimer - Version 3.2.69.0 log created on 02032013_231708
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top