jeesonus Posted March 26, 2009 Report Share Posted March 26, 2009 Hello... I could not find this topic already addressed. I was listening to music on my computer when I opened a Zip file I had downloaded... my Windows Media player shut down, followed by my whole computer shutting down. When I re-booted everything was fine except the computer did not recognize my sound card (C-Major Sigma Tel Audio.)In Control Panel my Volume Control is greyed out and lists "No Audio Device." The Audio tab is greyed out: "No Playback Devices, No Recording Devices, No Midi Devices." On the Hardware tab I highlight my soundcard: "PCI Bus 0, device 31, function 5- This device is working properly" Under Audio Codecs & Legacy Audio Drivers I get "Location Unknown" but "These devices are working properly." I have tried uninstalling the sound card and re-installing, restarting the audio Services under the Administrative Options tab, and more... the sound was working again for five minutes until I turned the computer off.I can't get it going again since I turned it back on... any suggestions?Thanks! Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted March 26, 2009 Report Share Posted March 26, 2009 Welcome to the Windows Forum.Did you scan your system for malware?What anti-malware applications do you have, and are they up-to-date with definitions?And what OS version, by the way? Quote Link to comment Share on other sites More sharing options...
jeesonus Posted March 26, 2009 Author Report Share Posted March 26, 2009 Thanks Pat... I am running Windows XP on a Dell Laptop. My Anti-Malware program is Malwarebytes... my last scan is yesterday... here is the Logfile:Malwarebytes' Anti-Malware 1.34Database version: 1890Windows 5.1.2600 Service Pack 33/26/2009 8:51:02 AMmbam-log-2009-03-26 (08-50-36).txtScan type: Full Scan (C:\|)Objects scanned: 150728Time elapsed: 58 minute(s), 11 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 1Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 1Files Infected: 15Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa (Rootkit.Bagle) -> No action taken.Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:C:\Documents and Settings\Mike Liberty\Application Data\m (Trojan.Agent) -> No action taken.Files Infected:C:\Documents and Settings\Mike Liberty\Application Data\drivers\srosa2.sys (Rootkit.Bagle) -> No action taken.C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP557\A0186014.sys (Rootkit.Bagle) -> No action taken.C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP557\A0186102.sys (Rootkit.Bagle) -> No action taken.C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP558\A0187102.sys (Rootkit.Bagle) -> No action taken.C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP559\A0187171.sys (Rootkit.Bagle) -> No action taken.C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP559\A0187228.sys (Rootkit.Bagle) -> No action taken.C:\System Volume Information\_restore{5B569949-7F2C-4454-8B46-89D4173A3CB8}\RP559\A0187248.sys (Rootkit.Bagle) -> No action taken.C:\Documents and Settings\Mike Liberty\Application Data\m\data.oct (Trojan.Agent) -> No action taken.C:\Documents and Settings\Mike Liberty\Application Data\m\list.oct (Trojan.Agent) -> No action taken.C:\Documents and Settings\Mike Liberty\Application Data\m\srvlist.oct (Trojan.Agent) -> No action taken.C:\Documents and Settings\Mike Liberty\Application Data\drivers\winupgro.exe (Trojan.Agent) -> No action taken.C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> No action taken.C:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> No action taken.C:\Documents and Settings\Mike Liberty\Application Data\m\flec006.exe (Trojan.Agent) -> No action taken.C:\Documents and Settings\Mike Liberty\Application Data\drivers\wfsintwq.sys (Rootkit.Bagle) -> No action taken.Any suggestions? Quote Link to comment Share on other sites More sharing options...
Boris Posted March 26, 2009 Report Share Posted March 26, 2009 Definitely let Malwarebytes quarantine/get rid of that Rootkit/Trojan ASAP Quote Link to comment Share on other sites More sharing options...
jeesonus Posted March 26, 2009 Author Report Share Posted March 26, 2009 Definitely let Malwarebytes quarantine/get rid of that Rootkit/Trojan ASAPI have tried... Malwarebytes will delete the infected files and promise to delete the rest on re-boot. After re-booting I run a full system scan only to find the virus has completely regenerated. I have Norton antivirus but the attack has rendered it unusable (I get an error message when I try to open the program). Is there anything else I can do? Anyone? Quote Link to comment Share on other sites More sharing options...
Boris Posted March 26, 2009 Report Share Posted March 26, 2009 Rather than as you have presumably already run it, run Malwarebytes in Safe Mode - hold down F8 as you boot. Quote Link to comment Share on other sites More sharing options...
brambell Posted March 26, 2009 Report Share Posted March 26, 2009 Hi there, You could install the free trial version of "a-squared" (google it) Check for any updates. Do a deep scan and then try and quarantine the infected flies, and see if that helps.This is a good bit of software. Let us know how you get on. Quote Link to comment Share on other sites More sharing options...
Boris Posted March 26, 2009 Report Share Posted March 26, 2009 You could install the free trial version of "a-squared" (google it) Check for any updates. Do a deep scan and then try and quarantine the infected flies, and see if that helps.Rather than the free trial version referred to above - just use this - a-squared Free 4.0 (freeware) :-http://www.emsisoft.com/en/software/free/ Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.