Help - Search - Members - Calendar
Full Version: Windows Media player won't open
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
stidyup
Windows Media Player won't open, it justs crashes and sends a message to Bill.

At start up, PC gives this error CMA Run-time error '-2147217865 (80040e37)': The MS jet database engine cannot find the input table or query 'Commands'. Make sure it exists and that its name is spelled correctly.

Also removed the following trojans Virus: 'Troj/DropRun-A' ; Virus: 'Dial/Top69-A' ; Virus: 'Troj/Briss-A Sophos AV definitions.

Had a look on Sophos webpage and none seem likely to be causing the problem.

Ran both spybot and Adaware, but still the problem persists.

This is my son's PC and he's obviously done something but I'm at a lost as to what.

I can't even view the windows media player folder as explorer just exits when you click on said folder.

I can gain access to windows media player folder via the command prompt, and I've ran media player setup again, but this still hasn't fixed the problem.

Can anybody shed any light on this.

Thanks

Hijack this log, this program did give a error whilst running.

Logfile of HijackThis v1.98.0
Scan saved at 20:01:09, on 11/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\TrayIcon.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\WINDOWS\System32\qttask.exe
C:\Program Files\desksite\bin\cma.exe
C:\Program Files\Filseclab\xfilter\xfilter.exe
C:\Program Files\NoAds\NoAds.exe
C:\Program Files\Common Files\Filseclab\FilMsg.exe
C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\adaware\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DisplayTrayIcon] C:\WINDOWS\System32\TrayIcon.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe
O4 - HKLM\..\Run: [XFILTER] C:\Program Files\Filseclab\xfilter\xfilter.exe
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - Global Startup: Filseclab Messenger.lnk = ?
O4 - Global Startup: InterCheck Monitor.LNK = C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: Download using Download &Express - C:\Program Files\Download Express\Add_Url.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
CalamityJane
Hi stidyup

Your log looks clean.

You just need to delete the current Windows Media Player and download a fresh copy and install. Get the security updates for it too.

http://www.microsoft.com/downloads/search....en&categoryid=4
stidyup
Thanks for the advice, I'll try it this evening when I'm at home.
Hunter
HI stidyup,

Let's talk turkey Wave.gif

starting with this


At start up, PC gives this error CMA Run-time error '-2147217865 (80040e37)': The MS jet database engine cannot find the input table or query 'Commands'. Make sure it exists and that its name is spelled correctly.


then look at this..

C:\Program Files\desksite\bin\cma.exe

and this..


O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe




What you are dealing with on that one is Desksite CMA ahah.gif



Desksite CMA with that cma.exe DeskSite CMA software - "retrieves new content from the DeskSite Data Center"

here are some..

FREQUENTLY ASKED QUESTIONS

WARNING: DeskSite software is for Microsoft Windows operating systems

this is a must read for you Wave.gif

http://www.eminem.com/desksite/faq3.html

***************************

Now I have no idea if your son download that cma.exe on purpose..many have claimed they end up with it on their PC from a silly bonus CD they get at the music store.



Quote:
Nailed it *&# "bonus" CD....(connect to so and so's website...translation they monitor where you go). It was a file hidden on a music CD my daughter played and the only way to delete it was to have the &^$* CD in the computer.


So since that is installed and trying to do its thing..but is now probably broken after his run in with those trojans...I am sure it is broken and if you read that FAQ it does hook into the Windows Media Player and i do not think it is sending a message to Bill :w00t: but rather trying to do it's thing with the CD or the DeskSite Website. crying.gif

http://www.eminemdesksite.com/



Background on the error message ..


PRB016 Microsoft JET Database Engine error '80040e37'
The Microsoft Jet database engine cannot find the input table or query 'table or procedure name'. Make sure it exists and that its name is spelled correctly.
Error Details:
Error Type:
Microsoft JET Database Engine error

Associated Error Number:
80040e37

Cause/Symptoms:
Your database is missing either a table or a stored procedure.

Fix/Workaround:
You can get whatever tables or procedures you are missing from the database download page.
http://www.aspemporium.com/aspEmporium/dow...s/myData_db.asp

Only tables and procedures used in ASP Emporium examples are available.


Is he playing games..or asp message board or doing P2P ??
http://www.mail-archive.com/asp_ecommerce@...m/msg00464.html
http://www.aspemporium.com/aspEmporium/hel...psys.asp?PRB016




Subject: Invalid object name....
Author: kelvin-at-sasdesign.co.uk
I am trying to use mssql2mysql to read a database from a mssql7 server running on NT4 server and write to a text file on my computer.
I am getting the following error when I try and run the script (I am running it from within Word2000 if that helps):

Runtime error '-2147217865(80040e37)':

Invalid object name art_Buts

This is occuring in the CopyTable subroutine. If I look at the text file output then I can see that it got as far as creating all the tables but stoped when it tried to copy the data into my art_Buts table. This is a little strange because it had no problems copying data into another table: art_Authors... At first I thought the problem might be something to do with there being an underscore (_) in the table name. If I rename art_Buts to art_Buts then the same error occurs with the next table: art_Category. So it's not just a problem with "_B" being a part of a table name either...
stidyup
Yep eminem and desksite sound familar, eminem appears several times in system restore. I've attempted to use system restore but had no joy with it.

I'll have read up on desksite and how to fix it.

If not I'll just have to burn my slipstreamed XP disc with all the patches included to CD, put it in the PC and let it run........

This is why he doesn't go on my PC ahah.gif ahah.gif ahah.gif ahah.gif

Thanks for the info.

:thumb:
Hunter
seem to me that if you get rid of these..


C:\Program Files\desksite\bin\cma.exe

and this..


O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe


see those FAQ's above...it will all go away.
stidyup
Hi Hunter

Deleted above files and registry entry, it got rid of the error message. However I still have the problem that Media Player just will not open. It appears to be working within IE, but simply will not work by clicking on the icon from the desktop.

Same with trying to enter WMP folder it just exists explorer.

I can play with folder security settings, but just can't get into the folder.

Any ideas or Format c:???

It will only take me 1hr to install it all with the patches as mentioned above with my unattended install cd.

Thanks.
toadbee
Hi StidyUp :)

Did you try the reinstall of MediaPlayer??

I recently had a very similar problem - Downloaded the latest version, and the install actually uninstalled the old for me and all is well. So if you haven't tried that yet - I'd give it a go ;)
stidyup
Tried that I'm afraid several times and no joy, I think the quickest solution is just to let the unattended install do it's job, at least I won't have to patch it and should take 1hr to install.

I knew I should have ghosted the image of the hdd, but noooooooooo I thought I'll leave it till WinXP SP2 comes out, slipstream that and then ghost it. In stead of 5mins to sort it out several hours.

Won't be making the same mistake twice.

That won't be happening till tomorrow at the earliest so if anyone has any other suggestions I'll have a go.

Thanks
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.