malwarebytes not finding malware, issues with running scan and bluescreen

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i see ur offline, i will check back in the a.m. for the link.. i get ur msgs on delay for some reason..
 

Fiery

Level 1
Jan 11, 2011
2,007
Use this one: <a title="External link" href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" rel="external"><>Link 1</></a>

Sometimes if you hit the refresh button, you'll see my replies sooner
 
Last edited by a moderator:

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Fiery said:
Use this one: <a title="External link" href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" rel="external"><>Link 1</></a>

Sometimes if you hit the refresh button, you'll see my replies sooner


that sooo did not go well.. i copied the CFscript to ComboFix as u told me, and it tried to run.. and u said not to run it so i stopped the run and I ended up having to do system restore just to get my internet back... I don't see a ComboFix.txt so I will repeat these steps if u wish but i need to know how to stop it from running after i copy it to combofix.. it is an auto scan.. and i dont know how to stop it w/o messing things up
 
Last edited by a moderator:

Fiery

Level 1
Jan 11, 2011
2,007
Apologies for the confusion. By "do not run Combofix" I mean don't double click it.

You can let it run after you drag the CFscript onto Combofix. It shouldn't take too long. It will produce a very short log.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Fiery said:
Apologies for the confusion. By "do not run Combofix" I mean don't double click it.

You can let it run after you drag the CFscript onto Combofix. It shouldn't take too long. It will produce a very short log.

Sorry it took me a minute to figure out how to get IE to work again.. it did what it did earlier and wouldn't let me to connect to the internet.. I just had to disconnect from the network and reconnect this time w/o System Restore. The Log is as follows:

C:\Qoobox\Quarantine\C\ProgramData\SymUpdate.exe.vir -> C:\ProgramData\SymUpdate.exe

Not sure what this is....
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
The webcam is still saying No Video device detected, please plug a video device into your computer. If you are using an integrated camera please make sure that it is turned on..... so I have to still be missing a driver.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Gbaby614 said:
The webcam is still saying No Video device detected, please plug a video device into your computer. If you are using an integrated camera please make sure that it is turned on..... so I have to still be missing a driver.

Also I searched what updates are missing..
 

Attachments

  • hp_update.JPG
    hp_update.JPG
    71.2 KB · Views: 84

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
I need to add I continue to try to figure out why my webcam stopped working, my daughter used it up until a few days before I requested help from malwaretips.com so I know that its not a hardware issue.. also QUICKPLAY has disappeared from my pc.. I did see that there are a cpl folders called RK_quarantine.. so maybe roguekiller is stopping me from using the webcam? can u pls go thru everything we have done and all the logs I have posted to u and see if u can find my quickplay, cyberlink and hp mediasmart apps and restore them.. I have the application and driver recovery cd here if u know how to restore these apps that came loaded on my pc. I also have dl'ed youcam and hp mediasmart webcam from hp.com.. I am not sure if there is something I am forgetting but I have tried everything I can think of to do.
 

Fiery

Level 1
Jan 11, 2011
2,007
Have you tried this? Also, check your PM inbox :)

http://h20614.www2.hp.com/ediags/gmd/GMNGoogleChromePluginInstall.aspx?lc=en&cc=uk
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Fiery said:
Have you tried this? Also, check your PM inbox :)

http://h20614.www2.hp.com/ediags/gmd/GMNGoogleChromePluginInstall.aspx?lc=en&cc=uk

this didnt find any HP products, the webcam isnt detected, it doesnt even show in the device mgr
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i replied to the pm, but also, iha ve been dl'ing drivers from HP.com so i hope it doesnt overwhelm the pc when u send the fix to read those qoobox quarantined files.. :s:huh::(
 

Fiery

Level 1
Jan 11, 2011
2,007
Please ignore the last PM from me.

Open notepad and Copy & paste the following:

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdatePDIRShortCut"="\"C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\PowerDirector\" UpdateWithCreateOnce \"SOFTWARE\CyberLink\PowerDirector\7.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="\"C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\Power2Go\" UpdateWithCreateOnce \"SOFTWARE\CyberLink\Power2Go\6.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdatePSTShortCut"="\"C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\DVD Suite\" UpdateWithCreateOnce \"Software\CyberLink\PowerStarter\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="\"C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\LabelPrint\" UpdateWithCreateOnce \"Software\CyberLink\LabelPrint\2.5\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UCam_Menu"="\"C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\" update \"Software\Hewlett-Packard\Media\Webcam\""

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"

save it a fix.reg onto the Desktop. Then right-click > Merge. Press Yes if there is a prompt.

Also, are there any files left in C:\Qoobox\Quarantine\C?
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Fiery said:
Please ignore the last PM from me.

Open notepad and Copy & paste the following:

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdatePDIRShortCut"="\"C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\PowerDirector\" UpdateWithCreateOnce \"SOFTWARE\CyberLink\PowerDirector\7.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="\"C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\Power2Go\" UpdateWithCreateOnce \"SOFTWARE\CyberLink\Power2Go\6.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdatePSTShortCut"="\"C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\DVD Suite\" UpdateWithCreateOnce \"Software\CyberLink\PowerStarter\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="\"C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\LabelPrint\" UpdateWithCreateOnce \"Software\CyberLink\LabelPrint\2.5\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UCam_Menu"="\"C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\" update \"Software\Hewlett-Packard\Media\Webcam\""

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"

save it a fix.reg onto the Desktop. Then right-click > Merge. Press Yes if there is a prompt.

Also, are there any files left in C:\Qoobox\Quarantine\C?

I have no idea what to do after creating the fix.reg file so I will just pause here until tomorrow..I dont have a merge option.. would it be named something else? and where am I merging? :huh:
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
I didn't wanna give up.. I sae the only file that says merge and it is one called tcpip and it was quarantined on 1/29/13, is that what u want me to right click. here is an attachment of what i see///
 

Attachments

  • reg.JPG
    reg.JPG
    103.6 KB · Views: 99

Fiery

Level 1
Jan 11, 2011
2,007
Next instructions below: It may seem like the same but they are different.

Open up Notepad and paste the following:

DeQuarantine::
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe.vir
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe.vir
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe.vir
C:\Qoobox\Quarantine\C\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe.vir
C:\Qoobox\Quarantine\C\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe.vir

Quit::
  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    CFScript.gif
  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below




Next, open notepad again and copy & paste the following:

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdatePDIRShortCut"="\"C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\PowerDirector\" UpdateWithCreateOnce \"SOFTWARE\CyberLink\PowerDirector\7.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="\"C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\Power2Go\" UpdateWithCreateOnce \"SOFTWARE\CyberLink\Power2Go\6.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdatePSTShortCut"="\"C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\DVD Suite\" UpdateWithCreateOnce \"Software\CyberLink\PowerStarter\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="\"C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\CyberLink\LabelPrint\" UpdateWithCreateOnce \"Software\CyberLink\LabelPrint\2.5\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UCam_Menu"="\"C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe\" \"C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\" update \"Software\Hewlett-Packard\Media\Webcam\""

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"

Click File > Save as. Under Save as Type choose, All files. Under file name, type fix.reg and save it to the desktop. The icon for the file should look like this:
jBV4eYq.png


Right-click it and select merge. Press Yes if there is a prompt.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
ok thx, I understand this a little better,:p...
I deleted the fix.reg.txt that I created this morning so it didn't interfere with me finding the one I am about to create.. It will take a sec after I drag CFscript to Combofix as it will have to restart so I will be back soon with the results..
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
okay I have done these steps, and merged the fix.reg. Is there a log or anything we need? Or a next step?
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
well it still loads the program but it is still not turning on the webcam itself...it should show I am posting some attachments and maybe you can see the problem.. I will be opening all the programs (ie: cyberlink, mediasmart, silverlight) and keep trying until u respond back.. I also found a link that states this:

Installing new webcam driver in Vista with Service Pack 1 ›
See also ›
This document pertains to HP Notebook PCs with Windows Vista
Understanding the error message
The camera preview screen may be blue or black. There may also be a message that says The webcam is being used by another program . This depends on what software is being used to access the webcam.
Installing new webcam driver in Vista with Service Pack 1
This issue should be resolved by updating your Windows Vista with Service Pack 1. Anytime you are experiences problems with your webcam, the first thing you should check is to see that you are using Vista with Service Pack 1. Service Pack 1 includes a new webcam driver that resolves many of the webcam errors.
The HP Webcam built into certain notebooks can be used to capture video motion or still images. A webcam is an input device, like a scanner, and does not do anything by itself. There is no free-standing webcam application or program. To test or use the webcam, you must use a video recording or instant messaging program. For HP notebooks with Vista, the available video recording programs are: QuickPlay or YouCam (depending on the model), and you can download the Windows Live instant message (IM) program from Microsoft.
If you install a third-party video application and that application does not display an image from the webcam, you can test the basic operation of the webcam by opening one of the video recording programs that were pre-installed on your computer. After verifying that the webcam is operational, you can configure and troubleshoot the application.
NOTE:Before attempting to resolve any webcam issues you should use Windows Update to install Microsoft Vista Service Pack 2.
Click Start , enter system in the search field, and select System from the listing.
Click Windows Update , and then when the link is displayed, click Check for updates .
------------------------
Im also trying this again now that we replaced the missing things.. until u msg me.
 

Attachments

  • webcam1.JPG
    webcam1.JPG
    43.3 KB · Views: 73
  • webcam2.JPG
    webcam2.JPG
    41.9 KB · Views: 81
  • webcam3.JPG
    webcam3.JPG
    198.5 KB · Views: 82
  • webcam4.JPG
    webcam4.JPG
    86.8 KB · Views: 86
  • webcam5.JPG
    webcam5.JPG
    126.4 KB · Views: 81

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top