This thread's last reply is from August 13, 2015, 8:00 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
My rig is a Pentium i7 machine, running Win 7 Professional. For the last 3 months or so, I've been advised by my ISP Comcast that I may have a bot.
I've run several scans using Malwarebytes Antimalware, ESET, MS Security Essentials, without any detection of malware. However the machine started to crash more and more often, especially while I play an online game, World of Warcraft. I did several chdsk to find out and repair any disk error but that didn't seem to help either. Finally it crashed to blue screen a couple days ago, and has since been unable to boot, giving me 2 options each time: Repair computer or Boot normally. I've tried doing the Repair computer route several times, and it's told me it's repaired a corrupted file system, but when I try restarting, it would fail to boot again normally. I've gone back to the original Windows installation disk, with similar results. Essentially I'm stuck in an endless loop of "Repair my computer", without any apparent hope of breaking out of this.
I would be very thankful if you can help me with this problem. I've looked through the website here but have not found any specific thread addressing this problem yet. If there is such.
No I was not able to do either. I believe the drive has crashed. I've pulled it out and going to try to retrieve important data from it. I'll give a report here as soon as I find out more, thank you very much for your quick response.
Thanks again, Gary! I will follow your instructions tomorrow, and hope that they will work out.
Today I took the drive to a computer repair shop, they did what they called a Level 1 recovery attempt, which failed. They then went on to a Level 2 scan, and after about 3 hours told me that they now believe they can recover up to 95% of the data. However it may be very expensive if I agree to let them do it. I will go get my drive back tomorrow, take it home and try out the Linux method. I actually have PC that's got a dual XP/Ubuntu OS. Would that work also? I'm still going to try your Puppy Linux method though, it's sounds really interesting.
Well, I shall definitely give you a report, thanks again Gary.
I don't know whether slaving your drive to your XP/Ubuntu machine would work, I've never tried to do that, but I do know that the Puppy method works in a great many cases.
Hope it's successful for you, and that you can avoid the expense of a shop recovery.
Ah, luck! I have been able to read the drive, using a boot Ubuntu DVD-ROM. I tried the Puppy Linux on a USB flash drive, but for some reason it did not boot, even after I checked everything, the downloaded ISO file, how to burn it onto the stick, verifying that I had set the boot loading sequence right on the PC I was using. I then pulled out an old Ubuntu 14.04 boot disk I'd made last year, popped it in the optical drive, and bang, it loaded, and had no trouble reading the drive. So I have been busy for the last day or so copying as many of my files on the crashed drive to a new, external USB drive as possible. As far as I can tell, a lot of them are good, i.e. I can look at photos, read my text docs, view videos, etc. I just don't know about the Windows system files or the ones needed for booting up the Windows 7 OS..
I still have a few questions, if you wouldn't mind answering them:
1. Would it be useful to copy the Program Files, Program Files (x86), Program Data folders? Would they help, or speed up a repopulating of a new drive with the programs I've been running?
2. If the crash was caused by a virus, can I still reformat the drive, using a low-level format, and be safe to re-install Windows on it?
If there is any way I can safely reformat the drive and use it again, that would be great (it's a 1TB WD drive, about 3 years old). But if you recommend against it, I will wait and get a new one.
I'm glad to hear that you had luck with the Ubuntu disk. Sorry Puppy didn't work, I can only presume your computer had hardware that Puppy isn't compatible with. That's the only trouble with Linux, you need to find a version that's compatible with your own machine. Personally, I'd love to have a play with Ubuntu, but it just doesn't run on my machine.
OK, in answer to your questions.
1. No, there's no point in copying the Program Files etc, since you won't have the corresponding Registry information to launch the programs stored in them, and it's impossible to know exactly what registry keys you'd need to back up to go with each of the programs. The only thing you can do, is make a list of the programs currently installed in both the Program Files and Program Files (X86) folders, so that you know what you need to re-install to get things back to "normal" (or as near to that as possible).
In any case, if you did have an infection, it's much more likely to be found in the executable files found in those 2 folders, than anywhere else, so you don't want to re-introduce them after you've formatted your drive. The only files you want to re-introduce to your newly formatted machine, are the non-executable data files that contain all your personal data (such as pictures, music, films, word processor documents, databases, spreadsheets, bookmarks etc. etc.)
2. If you reformat your drive, no infection will survive the process. The only way it can re-infect you is if you re-introduce it after the reformat, and if you only re-introduce data files, that's not likely to happen (if it does, come back here, and we'll see what we can do about it). Theoretically it is possible to make an infection that does survive a format, but in 10 years of dealing with infections I've never yet seen one. So go ahead and reformat, and you should be fine.
Hope that answers things for you, if not get back to me.
Alright, thanks again Gary! One last question: should I do a low-level format, i.e zero out the drive, or just a quick format, before reinstalling Windows? I need to put Win 7 back on, then will upgrade to Win 10 later.
I have reformatted the drive's partitions (one main big one, one tiny one reserved by system), deleted them, and reinstalled Windows 7 Professional on the drive. After working through and re-installing all the drivers I needed, it was great to once again be able to use the machine. I re-installed a few programs, including iTunes, and everything seemed to be humming along fine. However that same day I got another warning message from Comcast telling me they've again detected a bot on my network. There are 3 computers on our home network, mine is the most heavily used, and this warning came on right after I'd been able to get my PC back in working order. I've also done extensive malware scanning on the other two machines in the recent past, so I'm going to assume that is it my PC which somehow is still infected.
I wanted to test for this, so I re-installed the game that had given me the most visible signs of something not going well with my machine: World of Warcraft. It took some time, but I did that. I started playing the game, not doing much, just hanging around town with one of my characters and sorting through my bank items. Bang, I crashed after less than 30 minutes. I tried several more times, and gave up after having crashed 4 times in a row, each time within 10, 15 minutes. Since WoW is a 10 year old game, its graphics requirements have never been a problem for my machine (it's an i7 processor with a GTX 570 NVidia graphics card, plenty of RAM), so something is definitely still wrong.
Following the instructions on this board, I am going to run a DDS scan on the machine next, and will post the logs for you to look at here. Hopefully you'll be able to guide me thru this process and somehow find a way to eradicate this problem once and for all.
Attach.txt:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/1/2015 1:14:09 PM
System Uptime: 8/2/2015 10:53:44 PM (1 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P8P67 REV 3.1
Processor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz | LGA1155 | 2482/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 931 GiB total, 864.948 GiB free.
D: is CDROM ()
E: is CDROM (UDF)
Y: is FIXED (NTFS) - 932 GiB total, 50.887 GiB free.
Z: is FIXED (NTFS) - 932 GiB total, 445.563 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: USB\VID_0CF3&PID_3000\6&DF2EE03&0&7
Manufacturer:
Name:
PNP Device ID: USB\VID_0CF3&PID_3000\6&DF2EE03&0&7
Service:
.
Class GUID:
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_8086&DEV_1C3A&SUBSYS_844D1043&REV_04\3&11583659&0&B0
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_8086&DEV_1C3A&SUBSYS_844D1043&REV_04\3&11583659&0&B0
Service:
.
Class GUID:
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_1C22&SUBSYS_844D1043&REV_05\3&11583659&0&FB
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_1C22&SUBSYS_844D1043&REV_05\3&11583659&0&FB
Service:
.
==== System Restore Points ===================
.
RP3: 8/1/2015 1:59:56 PM - Installed Realtek Ethernet Controller Driver
RP4: 8/1/2015 2:00:58 PM - Windows Update
RP5: 8/1/2015 2:35:30 PM - Windows Update
RP6: 8/1/2015 3:19:29 PM - Installed Asmedia ASM104x USB 3.0 Host Controller Driver.
RP7: 8/1/2015 3:25:10 PM - Installed Suite
RP8: 8/1/2015 3:25:56 PM - Installed Suite
RP9: 8/1/2015 4:36:32 PM - Installed Suite
RP10: 8/1/2015 4:54:33 PM - Windows Update
RP11: 8/1/2015 9:49:47 PM - Installed Bonjour
RP12: 8/1/2015 9:50:51 PM - Installed Apple Application Support
RP13: 8/1/2015 9:52:11 PM - Installed Apple Mobile Device Support
RP14: 8/1/2015 9:53:58 PM - Installed iTunes
RP15: 8/2/2015 2:19:03 PM - Windows Update
RP16: 8/2/2015 2:38:52 PM - Windows Update
.
==== Installed Programs ======================
.
Apple Application Support
Apple Mobile Device Support
Asmedia ASM104x USB 3.0 Host Controller Driver
Battle.net
Bonjour
Curse Client
Google Chrome
Google Update Helper
iTunes
Malwarebytes Anti-Malware version 2.1.8.1057
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Mozilla Firefox 39.0 (x86 en-US)
Mozilla Maintenance Service
NVIDIA 3D Vision Controller Driver 301.42
NVIDIA 3D Vision Driver 301.42
NVIDIA Control Panel 301.42
NVIDIA Graphics Driver 301.42
NVIDIA HD Audio Driver 1.3.16.0
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.0213
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.8.15
NVIDIA Update Components
Realtek Ethernet Controller Driver
Software Update Wizard (Redistributable) 4.5
SplashID Safe 6.2
SplashShopper Desktop 3.1.0
VLC media player
World of Warcraft
.
==== Event Viewer Messages From Past Week ========
.
8/2/2015 2:55:04 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
8/2/2015 2:55:04 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Network Inspection System Error Code: 0x80070005 Error description: Access is denied. Reason: The system is missing updates that are required for running Network Inspection System. Install the required updates and restart the computer.
8/2/2015 2:47:35 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Network Inspection System Error Code: 0x80070005 Error description: Access is denied. Reason: The system is missing updates that are required for running Network Inspection System. Install the required updates and restart the computer.
8/2/2015 2:29:22 PM, Error: Service Control Manager [7024] - The Superfetch service terminated with service-specific error The operation completed successfully..
8/2/2015 10:41:46 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk4\DR5.
8/2/2015 10:35:01 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2.
8/2/2015 1:19:18 PM, Error: Service Control Manager [7030] - The Web Update Wizard Service V4 service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
8/1/2015 5:51:03 PM, Error: Service Control Manager [7023] -
8/1/2015 5:43:31 PM, Error: Service Control Manager [7034] - The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s).
8/1/2015 5:43:30 PM, Error: Service Control Manager [7034] - The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
8/1/2015 5:43:11 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
8/1/2015 5:43:11 PM, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/1/2015 5:43:10 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/1/2015 5:43:10 PM, Error: Service Control Manager [7023] - The Windows Font Cache Service service terminated with the following error: The process cannot access the file because it is being used by another process.
.
==== End Of File ===========================
Nothing of any concern showing in your DDS logs from a Malware standpoint, but the following lines indicate you may have potential hard drive problems (or the start of potential hard drive problems) ...
8/2/2015 10:41:46 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk4\DR5.
8/2/2015 10:35:01 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2.
... DDS doesn't really show how your drive is partitioned, so it's not clear whether DR5 and DR2 are separate drives, or different partitions on the same drive. If the latter, then it looks like your hard drive needs checking out properly.
That's outside the scope of this forum, we specialise in Malware problems, however the following forums all have hardware support sections, where they can help you with any drive problems you might have ...
After browsing some of the posts on bleepingcomputer, I downloaded CrystalDiskInfo and did a scan of my drives. Indeed there is a problem. The software tells me that my main drive, the WDC 1TB on which Win 7 is installed, has a lot of unrecoverable sectors, and is rated "Caution". The 2nd, 2TB Hitachi drive is OK. I will therefore be cautious and store all new data onto the second drive, and try to replace the main drive as soon as I can.
I still have a problem, I think, in that Comcast keeps on sending me notices that they detect a bot on my network. I have 2 more desktop PCs that are on the network. Does running a DDS scan on a PC truly allow you to eliminate the possibility of an infection? I've been told before that Comcast sometimes sends out these notices, and all they are are falso alarms. Have you come across such incidents? I would like to do scans of my other 2 PCs and submit them as well, for you or someone else here to help me determine if they're infected. Should I create another topic for each of them, or post the logs for both machines on this thread?
I realize that I've taken up a lot of your time already, again I'm very grateful for your patient and kind assistance!
DDS is by no means exhaustive, it just gives me a look at a number of locations that are commonly used to launch malware. There are a number of other things we can do to check your machine, but as you've just formatted your drive, my gut feeling is that we're not going to find any signs of infection on your machine.
I'm happy to look through scans of any other machines that you have on your network, so that we can eliminate them as a source of problem, and if we're going to do that, I'd prefer to deal with them one machine at a time.
So, rather than use DDS, I'd prefer it if you run a scan on the first of the other machines using a tool called FRST.
DownloadFRST to your Desktop (for 32 bit systems).
DownloadFRST64 to your Desktop (for 64 bit systems).
Double click Frst.exe to launch it.
FRST will start to run.
When the tool opens click Yes to disclaimer.
Press the Scan button.
When finished scanning 2 logs will open on your Desktop, FRST.txt and Addition.txt
Please post them in your next reply.
✨ Ask AI about this thread
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.