Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Unable to install anything  (Read 14501 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Unable to install anything
« Reply #15 on: November 01, 2010, 12:44:51 PM »
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was

extracted to. Open the text file and copy/paste the log here.
[/list]
Windows 8 and Windows 10 dual boot with two SSD's

dgreen

    Topic Starter


    Intermediate

    • Experience: Beginner
    • OS: Windows 7
    Re: Unable to install anything
    « Reply #16 on: November 02, 2010, 06:10:03 AM »
    SysProt AntiRootkit v1.0.1.0
    by swatkat

    ******************************************************************************************
    ******************************************************************************************

    No Hidden Processes found

    ******************************************************************************************
    ******************************************************************************************
    Kernel Modules:
    Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
    Service Name: ---
    Module Base: 8D583000
    Module End: 8D58E000
    Hidden: Yes

    Module Name: \SystemRoot\System32\Drivers\dump_msahci.sys
    Service Name: ---
    Module Base: 8D58E000
    Module End: 8D598000
    Hidden: Yes

    Module Name: \??\C:\Users\DAVIDM~1\AppData\Local\Temp\mbr.sys
    Service Name: mbr
    Module Base: A8E5C000
    Module End: A8E62000
    Hidden: Yes

    Module Name: \??\C:\Users\DAVIDM~1\AppData\Local\Temp\catchme.sys
    Service Name: catchme
    Module Base: A8E62000
    Module End: A8E6A000
    Hidden: Yes

    Module Name: \??\C:\Windows\system32\Drivers\PROCEXP113.SYS
    Service Name: ---
    Module Base: A8E6A000
    Module End: A8E6C000
    Hidden: Yes

    ******************************************************************************************
    ******************************************************************************************
    No SSDT Hooks found

    ******************************************************************************************
    ******************************************************************************************
    No Kernel Hooks found

    ******************************************************************************************
    ******************************************************************************************
    Hidden files/folders:
    Object: C:\Qoobox\BackEnv\AppData.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Cache.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Cookies.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Desktop.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Favorites.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\History.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Music.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\NetHood.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Personal.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Pictures.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Programs.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Recent.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SendTo.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SetPath.bat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\StartUp.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\SysPath.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\Templates.folder.dat
    Status: Access denied

    Object: C:\Qoobox\BackEnv\VikPev00
    Status: Access denied

    Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
    Status: Access denied

    Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
    Status: Access denied

    Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
    Status: Access denied

    Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
    Status: Access denied


    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Unable to install anything
    « Reply #17 on: November 02, 2010, 12:29:14 PM »
    That looks good. Now, I'd like to run this scan.

    I'd like to scan your machine with ESET OnlineScan

    •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
    •Click the button.
    •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
    •Check
    •Click the button.
    •Accept any security warnings from your browser.
    •Check
    •Push the Start button.
    •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    •When the scan completes, push
    •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    •Push the button.
    •Push
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

    Windows 8 and Windows 10 dual boot with two SSD's

    dgreen

      Topic Starter


      Intermediate

      • Experience: Beginner
      • OS: Windows 7
      Re: Unable to install anything
      « Reply #18 on: November 05, 2010, 08:22:20 AM »
      Hi Super Dave,

      I left the Scan running with a friend whilst I popped out.
      He told me no threats were found and no log was produced.
      Is this possible?

      Thanks

      David

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Unable to install anything
      « Reply #19 on: November 05, 2010, 12:23:40 PM »
      Hi Super Dave,

      I left the Scan running with a friend whilst I popped out.
      He told me no threats were found and no log was produced.
      Is this possible?

      Thanks

      David

      Yes. How's your computer running? Any issues?
      Windows 8 and Windows 10 dual boot with two SSD's