Jump to content

Sound Card Virus?


jeesonus
 Share

Recommended Posts

Hello... I could not find this topic already addressed. I was listening to music on my computer when I opened a Zip file I had downloaded... my Windows Media player shut down, followed by my whole computer shutting down. When I re-booted everything was fine except the computer did not recognize my sound card (C-Major Sigma Tel Audio.)

In Control Panel my Volume Control is greyed out and lists "No Audio Device." The Audio tab is greyed out: "No Playback Devices, No Recording Devices, No Midi Devices." On the Hardware tab I highlight my soundcard: "PCI Bus 0, device 31, function 5- This device is working properly" Under Audio Codecs & Legacy Audio Drivers I get "Location Unknown" but "These devices are working properly." I have tried uninstalling the sound card and re-installing, restarting the audio Services under the Administrative Options tab, and more... the sound was working again for five minutes until I turned the computer off.

I can't get it going again since I turned it back on... any suggestions?

Thanks!

Link to comment
Share on other sites

Thanks Pat... I am running Windows XP on a Dell Laptop. My Anti-Malware program is Malwarebytes... my last scan is yesterday... here is the Logfile:

Malwarebytes' Anti-Malware 1.34

Database version: 1890

Windows 5.1.2600 Service Pack 3

3/26/2009 8:51:02 AM

mbam-log-2009-03-26 (08-50-36).txt

Scan type: Full Scan (C:\|)

Objects scanned: 150728

Time elapsed: 58 minute(s), 11 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 1

Files Infected: 15

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa (Rootkit.Bagle) -> No action taken.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

C:\Documents and Settings\Mike Liberty\Application Data\m (Trojan.Agent) -> No action taken.

Files Infected:

C:\Documents and Settings\Mike Liberty\Application Data\drivers\srosa2.sys (Rootkit.Bagle) -> No action taken.

C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP557\A0186014.sys (Rootkit.Bagle) -> No action taken.

C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP557\A0186102.sys (Rootkit.Bagle) -> No action taken.

C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP558\A0187102.sys (Rootkit.Bagle) -> No action taken.

C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP559\A0187171.sys (Rootkit.Bagle) -> No action taken.

C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP559\A0187228.sys (Rootkit.Bagle) -> No action taken.

C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP559\A0187248.sys (Rootkit.Bagle) -> No action taken.

C:\Documents and Settings\Mike Liberty\Application Data\m\data.oct (Trojan.Agent) -> No action taken.

C:\Documents and Settings\Mike Liberty\Application Data\m\list.oct (Trojan.Agent) -> No action taken.

C:\Documents and Settings\Mike Liberty\Application Data\m\srvlist.oct (Trojan.Agent) -> No action taken.

C:\Documents and Settings\Mike Liberty\Application Data\drivers\winupgro.exe (Trojan.Agent) -> No action taken.

C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> No action taken.

C:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> No action taken.

C:\Documents and Settings\Mike Liberty\Application Data\m\flec006.exe (Trojan.Agent) -> No action taken.

C:\Documents and Settings\Mike Liberty\Application Data\drivers\wfsintwq.sys (Rootkit.Bagle) -> No action taken.

Any suggestions?

Link to comment
Share on other sites

Definitely let Malwarebytes quarantine/get rid of that Rootkit/Trojan ASAP

I have tried... Malwarebytes will delete the infected files and promise to delete the rest on re-boot. After re-booting I run a full system scan only to find the virus has completely regenerated. I have Norton antivirus but the attack has rendered it unusable (I get an error message when I try to open the program). Is there anything else I can do? Anyone?

Link to comment
Share on other sites

Hi there,

You could install the free trial version of "a-squared" (google it) Check for any updates. Do a deep scan and then try and quarantine the infected flies, and see if that helps.

This is a good bit of software.

Let us know how you get on.

Link to comment
Share on other sites

You could install the free trial version of "a-squared" (google it) Check for any updates. Do a deep scan and then try and quarantine the infected flies, and see if that helps.

Rather than the free trial version referred to above - just use this - a-squared Free 4.0 (freeware) :-

http://www.emsisoft.com/en/software/free/

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy