Go Back   Cyber Tech Help Support Forums > Operating Systems > Older Windows Versions > Windows Vista

Notices

Windows Vista Problem solving for the Windows Vista Operating System. Please remember to state which edition of Vista you are using - Home Basic, Home Premium, Business, Ultimate etc. and whether you are using the 32-bit or 64-bit version if you know.

Reply
 
Topic Tools
  #31  
Old March 27th, 2011, 06:10 AM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
Ok I d/loaded a Norton uninstall tool and that fixed the problem, also I shifted that CEC_main.exe out of the program group in the meantime so the machine complains each time I restart
Reply With Quote
  #32  
Old March 28th, 2011, 02:03 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,284
Good - you are clearing up some issues. Better if you put the file back for now though. Seeing an unusual entry in a Gmer scan log isn't anything we should act on right now. Just need to take a look. But not seeing any upload from you at the SpyKiller site. Could you double-check the steps again, please?
Reply With Quote
  #33  
Old March 28th, 2011, 10:37 AM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
I am having a heap of problems with the Spykiller forum.
I am following the instructions
When I hit "post" It takes ages to upload the file then
Forbidden you do not have permission to access "index.php on this server additionally a 404 not found was encountered while trying to use an error document................
Reply With Quote
  #34  
Old March 28th, 2011, 10:39 AM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
I put that CEC_Main back where I found it for the mean time...
I wonder if there is some other place I can upload a copy of the file to?
Reply With Quote
  #35  
Old March 29th, 2011, 01:30 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,284
I did a test upload at that site, but didn't run into those errors. The ComboFix log shows a few files we need to put back, and a few others we need to verify, so still need some file copy moving done. What problems are occurring there now, with Norton uninstalled? We so far are not seeing malware, so don't want to go to far along without purpose.


Zip a copy of that CEC_Main file, as well as the following two files, and email them as attachments, one at a time, to jintan@malwarecrypt.com as an attachment. Please place "Submitted Files -Jaytee/cth/files" as the email Subject.

C:\qoobox\Quarantine\C\program files\webserver\PdvrParser.ax.vir
C:\qoobox\Quarantine\C\program files\webserver\PdvrServer.dll.vir
Reply With Quote
  #36  
Old March 29th, 2011, 08:54 PM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
The only problems that I am aware of are broken or disabled Firefox a user went missing possible cause for that is a system restore that occurred when the machine failed to boot.
Windows update is failing and java update is also failing..
Reply With Quote
  #37  
Old March 29th, 2011, 08:55 PM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
I sent those files. Hope they are ok
Reply With Quote
  #38  
Old March 30th, 2011, 02:42 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,284
I received the files, thanks. What did you use to zip them - they are reduced nicely?

Sure enough, that camera CEC_MAIN.exe incorporates quite a bit of what it refers to as "debug" in it's functions. And the code show what Gmer reflects as well, so not a malware action.

As for the other files, the code in them suggests streaming video, audio/graphics use. Release_codec3Dll references as well. No indication of malicious actions in them. And no indication of the vendor or source. Korean sourced. One file you have, WebServer.ocx, does web search to Corel Paradox use, so a thin tie with the "pd" of the files. This scan indicates two scanners see one file as part of a rogue security install, but those two hits are too few to verify malware.

But the uploads raise a different questioning. The folders were named ."pdf". Was this something you chose? Wondering if many items there are acquiring that extension, which would mess things up. if you did not name them .pdf, did you make sure earlier you have an accurate view of files there, make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"
Reply With Quote
  #39  
Old March 30th, 2011, 03:29 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,284
I checked an analysis of that PdvrParser.ax file. It also uses the same Renos malware reference, shows the source as Korean, and includes a "Pdvr Http Push" function (info here). Given the check on that camera file, and these file's busy video related functions, I am leaning towards "pdvr" meaning "portable digital video recorder", likely from some Korean device software. Any devices on that system match that? We can check for some of the analysis info on that system, though admittedly, this is just to verify what those files do. Not seeing them as having caused problems there.


Download Nirsoft's RegScanner from here (scroll down - select "Download self-install executable for installing RegScanner with uninstall support") to your desktop. Then right click that regscanner_setup.exe, select "Run as administrator, and follow the prompts to install RegScanner.

When the display opens, copy/paste the following into the "Find String" box, then click OK:

F9C69F34-2CD3-4769-A414-C3AB121FDF94

Once that scan completes go to Edit - Select All. Then again Edit - Copy All.

Open Notepad (go to Start Search, type notepad.exe and hit Enter), and right click Paste the log results there. Save that to your desktop by any name you choose, and post the contents here in your next reply please.
Reply With Quote
  #40  
Old March 30th, 2011, 10:14 AM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
I just have time to respond to the "zip" questions.
The files I sent you were in fact the three files with the names you reqested
I was unsure how to zip files in windows vista environment so I copied the files to a flash drive and compressed them with my Linux system as it has a lot of zip extensions .tar .jar.bz etc. However the files were identified as windows executables and would not compress so I renamed them .pdf to compress them then when compressed I renamed the actual files back to there original state and tested them on the Win machine for readability. I think it is unlikely that any information would remain hidden as Linux uses hiding for a different purpose as far as I am aware.
The machine is a Toshiba laptop with a built in camera at the top centre of the screen.
I will attempt to get the output from Reg scan tomorrow evening...
Reply With Quote
  #41  
Old March 31st, 2011, 02:12 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,284
That clears up the extension issue, thanks. FYI - if you right click a file in Vista (same as XP) and select "Send to" -> Compressed (zipped) Folder, that will create a zipped copy in the same location as the target file. Not as nicely compressed though. Yes, let's check the Registry search results, then if nothing from that, see about correcting the update issue, then check reinstalling Firefox and Norton.
Reply With Quote
  #42  
Old March 31st, 2011, 02:15 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,284
Actually, go here and download and run the BITS Repair Tool. Reboot after, and see if the updates work then please. No reason to wait on that.
Reply With Quote
  #43  
Old March 31st, 2011, 11:01 AM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
Reg scan came back with a nil result on the key you gave me.
BITS came back with a not required at this time type statement.
I am trying windows update again but not confident of the outcome..
Reply With Quote
  #44  
Old March 31st, 2011, 11:11 AM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
Negative outcome... The o/s will not boot. I am going to bed in disgust!!!
Reply With Quote
  #45  
Old March 31st, 2011, 09:16 PM
Jaytee's Avatar
Jaytee Jaytee is offline
Senior Member
 
Join Date: May 2002
O/S: Linux
Location: Hamilton New Zealand
Age: 76
Posts: 3,620
Yet another system restore and the machine is back to its pre-updates stage.
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Topics
Topic Topic Starter Forum Replies Last Post
How to get back my bookmarks into Firefox/IE? rivrbyte Windows 7 1 July 22nd, 2011 11:27 PM
very slow laptop and broken sounds (moved from Cyber Safety Forum) vit Windows XP 11 January 21st, 2009 11:50 PM
Broken CD drive? (Moved from Vista Forum) cbartholomew Hardware 2 October 9th, 2008 04:19 PM
New to FireFox...Norton PWD question? garyz Internet / Browsers 0 April 4th, 2007 04:05 AM
Firefox went back to default mkvl3 Internet / Browsers 9 January 23rd, 2006 06:51 PM


All times are GMT +1. The time now is 01:55 AM.