Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Can't run programs or connect to internet  (Read 67057 times)

0 Members and 1 Guest are viewing this topic.

Dr Jay

  • Malware Removal Specialist


  • Specialist
  • Moderator emeritus
  • Thanked: 119
  • Experience: Guru
  • OS: Windows 10
Re: Can't run programs or connect to internet
« Reply #30 on: July 21, 2010, 12:27:30 PM »
See if you can run this:

Download Bootkit Remover to your Desktop.
  • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
  • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.
  • It will show a Black screen with some data on it.
  • Right click on the screen and click Select All.
  • Press CTRL C
  • Open a Notepad and press CTRL V
  • Post the output back here.
~Dr Jay

Xerinous

    Topic Starter


    Beginner

    Re: Can't run programs or connect to internet
    « Reply #31 on: July 21, 2010, 01:39:04 PM »
    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    SPTI_Read(): DeviceIoControl() ERROR 1
    ERROR: SPTI_Read() fails for \\.\PhysicalDrive0
    MD5: 6def5ffcbcdbdb4082f1015625e597bd

         Size  Device Name          MBR Status
     --------------------------------------------
       149 GB  \\.\PhysicalDrive0   OK (DOS/Win32 Boot code found)


    Press any key to quit...

    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: Can't run programs or connect to internet
    « Reply #32 on: July 22, 2010, 12:21:27 AM »
    Hmm...appears either a disk sector is damaged, or Bootkit Remover cannot read the first sector of the hard disk.

    Nonetheless, let's take a look at the kernel.

    Download Kernel Detective: http://www.kernelmode.info/ARKs/Kernel_Detective_v1.3.1.zip

    Extract the file to your Desktop.

    Enter the folder and double-click on Kernel Detective.exe to get started.

    We need four different logs, to be uploaded.

    Click on Kernel Modifications tab, then click on File > Save Current List, and give it a name. The name should be in *.txt format.

    Save the log to your Desktop.

    Do the same for the Drivers tab, System Service Descriptor Table, and the System Service Descriptor Table Shadow.

    Attach all the logs to your next reply.
    ~Dr Jay

    Xerinous

      Topic Starter


      Beginner

      Re: Can't run programs or connect to internet
      « Reply #33 on: July 22, 2010, 09:41:53 AM »
      Alright here are the logs I got, titled by the tab they came from.

      [recovering disk space - old attachment deleted by admin]

      Dr Jay

      • Malware Removal Specialist


      • Specialist
      • Moderator emeritus
      • Thanked: 119
      • Experience: Guru
      • OS: Windows 10
      Re: Can't run programs or connect to internet
      « Reply #34 on: July 23, 2010, 12:02:19 AM »
      Try this real quick:

      Please open Notepad and enter in the following:
      Quote
      @echo off
      start remover.exe fix \.\PhysicalDrive0
      exit
      Then, click File > Save as...
      Save as remove.bat to the same location as remover.exe.
      Choose Save as type... All Files.
      Click Save.

      Then, exit Notepad.

      Double-click on remove.bat.

      Please re-run remover.exe and post a new log in your next reply.
      ~Dr Jay

      Xerinous

        Topic Starter


        Beginner

        Re: Can't run programs or connect to internet
        « Reply #35 on: July 23, 2010, 11:21:49 AM »
        Here's what running remover.exe gave:

        Bootkit Remover version 1.0.0.1
        (c) 2009 eSage Lab
        www.esagelab.com

        \\.\C: -> \\.\PhysicalDrive0
        SPTI_Read(): DeviceIoControl() ERROR 1
        ERROR: SPTI_Read() fails for \\.\PhysicalDrive0
        MD5: 6def5ffcbcdbdb4082f1015625e597bd

             Size  Device Name          MBR Status
         --------------------------------------------
           149 GB  \\.\PhysicalDrive0   OK (DOS/Win32 Boot code found)


        Press any key to quit...

        remover.bat gave an error:

        Bootkit Remover version 1.0.0.1
        (c) 2009 eSage Lab
        www.esagelab.com

        CreateFile() ERROR 2
        ERROR: Can't open physical disk device.

        Press any key to quit...

        Dr Jay

        • Malware Removal Specialist


        • Specialist
        • Moderator emeritus
        • Thanked: 119
        • Experience: Guru
        • OS: Windows 10
        Re: Can't run programs or connect to internet
        « Reply #36 on: July 23, 2010, 08:57:30 PM »
        Try once more, please.
        ~Dr Jay

        Xerinous

          Topic Starter


          Beginner

          Re: Can't run programs or connect to internet
          « Reply #37 on: July 23, 2010, 10:31:32 PM »
          Nothing changes, I'm given the exact same messages once more.

          Dr Jay

          • Malware Removal Specialist


          • Specialist
          • Moderator emeritus
          • Thanked: 119
          • Experience: Guru
          • OS: Windows 10
          Re: Can't run programs or connect to internet
          « Reply #38 on: July 25, 2010, 11:46:22 PM »
                Let's try something else...

                Please download avz4.zip from
          HERE
          • Unzip it to your desktop to a folder named avz4
          • Double click on AVZ.exe to run it.
          • Run an update by clicking the Auto Update button on the Right of the Log window:
          • Click Start to begin the update
          Note: If you recieve an error message, chose a different source, then click Start again
          • Start AVZ.
          • Choose from the menu "File" => "Standard scripts " and mark the "Advanced System Analysis with malware removal mode enabled" check box.

          • Click on the Execute selected scripts.
          • Automatic scanning, healing and system check will be executed.
          • A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
            [*It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
          • All applications will work properly after the system restart.
          When restarted
          • Start AVZ.
          • Choose from the menu "File" => "Standard scripts " and mark the Advanced System Analysis" check box.

          • Click on the "Execute selected scripts".
          • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.
          Attach both virusinfo_syscure.zip and virusinfo_syscheck.zip to your next post[/list][/list][/list]
          ~Dr Jay

          Xerinous

            Topic Starter


            Beginner

            Re: Can't run programs or connect to internet
            « Reply #39 on: July 26, 2010, 03:32:13 PM »
            I can't get the files onto the flashdrive to attach them, I've tried every way I know, nothing works.

            Dr Jay

            • Malware Removal Specialist


            • Specialist
            • Moderator emeritus
            • Thanked: 119
            • Experience: Guru
            • OS: Windows 10
            Re: Can't run programs or connect to internet
            « Reply #40 on: July 26, 2010, 09:57:00 PM »
            The internet is still down on the infected machine?
            ~Dr Jay

            Xerinous

              Topic Starter


              Beginner

              Re: Can't run programs or connect to internet
              « Reply #41 on: July 26, 2010, 11:06:19 PM »
              Yes, yes it is.

              Dr Jay

              • Malware Removal Specialist


              • Specialist
              • Moderator emeritus
              • Thanked: 119
              • Experience: Guru
              • OS: Windows 10
              Re: Can't run programs or connect to internet
              « Reply #42 on: July 27, 2010, 12:05:56 PM »
              What other signs of infection are there?
              ~Dr Jay

              Xerinous

                Topic Starter


                Beginner

                Re: Can't run programs or connect to internet
                « Reply #43 on: July 27, 2010, 02:10:01 PM »
                Response times are slower than normal, files cannot be moved, by drag-and-drop or otherwise, Internet Explorer doesn't stay open for more than a second or so when the attempt is made (Firefox does, but stays at a blank page), on logging onto a user profile an error message is given:
                 "RegisterClassObjects failed: hRes = 0x800706BA
                  The RPC server is unavailable
                  Maximum retry attempts exceeded".
                Most programs that require some form of connection to the internet refuse to run, including Malware Bytes. iTunes opens but does not play anything. My taskbar has changed to the gray block-like appearance found in older versions of Windows, and icons on the desktop cannot be arranged by drag-and-drop but can by right-clicking.

                That's what I can see at least.

                Dr Jay

                • Malware Removal Specialist


                • Specialist
                • Moderator emeritus
                • Thanked: 119
                • Experience: Guru
                • OS: Windows 10
                Re: Can't run programs or connect to internet
                « Reply #44 on: July 28, 2010, 03:21:33 PM »
                That means the MBR code from the malware is still there. :|

                Whenever rootkit scanners, and antivirus software scan for the rootkit, it gets as close to the system kernel as possible. If the rootkit is beyond that point, it will not be detected.

                Problem is, you could try to replace every file on the system, but still the rootkit will show its face.

                Please download DrWeb-CureIt and save it to your Desktop. Do NOT perform a scan yet

                • Double-click on drweb-cureit.exe to start the program.
                  An Express Scan of your PC notice will appear.
                • Under Start the Express Scan Now, Click OK to start the scan.
                  This is a short scan that will scan the files currently running in memory.
                  If something is found, click the Yes button when it asks you if you want to cure it.
                • Once the short scan has finished, Click Options > Change settings
                • Choose the Scan tab and UNcheck Heuristic analysis
                • Back at the main window, click Custom Scan, then Select drives (a red dot will show which drives have been chosen).
                • Then click the Start/Stop Scanning button (green arrow on the right, and the scan will start.
                • When finished, a message will be displayed at the bottom advising if any viruses were found.
                • Click Yes to all if it asks if you want to cure/move the file.
                • When the scan has finished, look if you can see the icon next to the files found.

                If so, click it, then click the next icon right below and select Move incurable.
                (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
                • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
                • Save the DrWeb.csv report to your Desktop.
                • Exit Dr.Web Cureit when you have finished.
                • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
                • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
                ~Dr Jay