Computing.Net > Forums > Security and Virus > Can't access C Drive

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Can't access C Drive

Reply to Message Icon

Name: Plarin
Date: May 15, 2009 at 20:50:34 Pacific
OS: Windows XP
Subcategory: Viruses
Comment:

I foolishly opened a virus and now I have pop-ups and can't access the C Drive. I ran AVG (free version) and this is all that turned up.

[img=http://img41.imageshack.us/img41/9514/53748761.jpg]

Also, in my Windows temporary folder are 4 files called PartialTrustWpfCallingWcf_TemporaryKey. Don't know if that's important.

Thanks for any help.



Sponsored Link
Ads by Google

Response Number 1
Name: jdk (by neoark)
Date: May 15, 2009 at 20:55:43 Pacific
Reply:

Hi,
Can you please post your AVZ log:

1) To create the logfile, download AVZ by clicking HERE(http://www.z-oleg.com/avz4.zip). Please save this file to your desktop or "My Documents" folder.

2) Next, unpack the file to a new folder using the Compressed (zipped) folders wizard built into Windows XP/Vista, or a zip utility of your choice.

3) Once you have unpacked the contents of the zip archive, please launch the file AVZ.exe by double clicking on it or right clicking and selecting Open.
Note: If you are running Windows vista launch AVZ.exe by right clicking and selecting Run as Administrator

You should now see the main window of the AVZ utility. Please navigate to File->Custom Scripts. Copy the script below by using the keyboard shortcut CTRL+C or the corresponding option via right click.

begin
ExecuteStdScr(3);
RebootWindows(true);
end.

Paste the script into the execution window by using CTRL+V keyboard shortcut, or the "paste" option via the right click menu. Click on Run to run the script, the PC will reboot. After the reboot the LOG subfolder is created in the folder with AVZ, with a file called virusinfo_syscure.zip inside. Upload that file to rapidshare.com and paste the link here.


0

Response Number 2
Name: Plarin
Date: May 15, 2009 at 21:04:04 Pacific
Reply:

Uh, how do I use that link?


0

Response Number 3
Name: Plarin
Date: May 15, 2009 at 21:09:37 Pacific
Reply:

This is the message when I try to access the C Drive:

Windows cannot find 'RECYCLER/S-3-5-27-100032528-100020612-100013709-3551.com'. Make sure you typed the name correctly, and then try again. To serach for a file, click the Start button, and then click Search.


0

Response Number 4
Name: jdk (by neoark)
Date: May 15, 2009 at 21:11:41 Pacific
Reply:

copy and paste the link?


0

Response Number 5
Name: jdk (by neoark)
Date: May 15, 2009 at 21:13:27 Pacific
Reply:
0

Related Posts

See More



Response Number 6
Name: Plarin
Date: May 15, 2009 at 21:19:14 Pacific
Reply:

My computer times out before it's able to open the file.


0

Response Number 7
Name: jdk (by neoark)
Date: May 15, 2009 at 21:25:30 Pacific

Response Number 8
Name: Plarin
Date: May 15, 2009 at 21:38:21 Pacific
Reply:

http://rapidshare.com/files/2335060...

I realized that I can actually access the C Drive when I first log on until a process called "tempo-137515.tmp" starts running. Also, all the bookmarks I just made before I restarted are gone.


0

Response Number 9
Name: jdk (by neoark)
Date: May 15, 2009 at 22:10:25 Pacific
Reply:

Run this script in AVZ same way you did before:

begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
 QuarantineFile('C:\autorun.inf','');
 QuarantineFile('spnm.sys','');
 QuarantineFile('\\?\globalroot\systemroot\system32\gxvxcrpycnrueynpkmlgijnlvtnicanlaijbm.dll','');
 DeleteFile('\\?\globalroot\systemroot\system32\gxvxcrpycnrueynpkmlgijnlvtnicanlaijbm.dll');
 DeleteFile('spnm.sys');
 DeleteFile('C:\autorun.inf');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

Your computer will reboot after which check and see if you can access C drive if you can run full scan with AVG.

Also once you reboot can you send me copy of this file C:\WINDOWS\system32\drivers\udffsrec.sys to check, upload it to rapidshare and private message me the link. Thanks


0

Response Number 10
Name: Plarin
Date: May 15, 2009 at 22:24:44 Pacific
Reply:

http://rapidshare.com/files/2335141...

Thanks, I can get onto the C drive now and I'm not having pop-ups. I'm going to bed right now so I won't do a scan, but I'll do it in the morning.

So this is basically fixed now?


0

Response Number 11
Name: jdk (by neoark)
Date: May 15, 2009 at 22:31:45 Pacific
Reply:

There are few more steps i will tell you after you post your scan results.


0

Response Number 12
Name: Plarin
Date: May 16, 2009 at 10:02:30 Pacific
Reply:

Ugh, it took a real long time to load up Windows. I tried 4 times and ended up stuck on the loading screen. I gave up hope and left the room but when I came back 15 minutes later it was working.

Starting scan with AVG free now.


0

Response Number 13
Name: Plarin
Date: May 16, 2009 at 10:05:42 Pacific
Reply:

And I can still access the C drive but the pop-ups have started again.

Also, yesterday my Recycle Bin emptied without me telling it to. (But that was before I ran that AVZ code.)


0

Response Number 14
Name: Plarin
Date: May 16, 2009 at 11:44:29 Pacific
Reply:

All right, here's the result of the scan:

[File;
Infection;
Result]

"\\?\globalroot\systemroot\system32\gxvxcrpycnrueynpkmlgijnlvtnicanlaijbm.dll";
"Trojan horse Agent2.GUF";
"Infected"

"C:\Documents and Settings\Jake\Desktop\Firefox\firefox.exe (1984)";
"Trojan horse Agent2.GUF";
"Infected"

"C:\Documents and Settings\Jake\Desktop\Quarantine\2009-05-16\avz00001.dta";
"Virus found Worm/AutoRun";
"Moved to Virus Vault"

"C:\Documents and Settings\Jake\Desktop\Quarantine\2009-05-16\avz00002.dta";
"Trojan horse Agent2.GUF";
"Moved to Virus Vault"

"C:\WINDOWS\Temp\tempo-137515.tmp";
"Trojan horse FakeAlert.KH";
"Moved to Virus Vault"

"C:\WINDOWS\Temp\tempo-1432296.tmp";
"Trojan horse FakeAlert.KH";
"Moved to Virus Vault"


0

Response Number 15
Name: jdk (by neoark)
Date: May 16, 2009 at 11:49:32 Pacific
Reply:

Attach a Combofix log, please review and follow these instructions carefully.

Download it here -> http://download.bleepingcomputer.co...

Before Saving it to Desktop, please rename it to something like 123.exe to stop malware from disabling it.

Now, please make sure no other programs are running, close all other windows and pause ANTIVIRUS/SPYWARE PROGRAMS until after the scanning and removal process has taken place.

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan. Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post.


0

Response Number 16
Name: Plarin
Date: May 16, 2009 at 11:53:04 Pacific
Reply:

Thanks for responding so quickly. First a couple of questions:

1. To make sure no other programs are running, can I just close all my windows and disable Steam and IPodService?

2. To shut down my antivirus, can I just right-click it and select "Exit" from the bottom toolbar?


0

Response Number 17
Name: jdk (by neoark)
Date: May 16, 2009 at 11:56:53 Pacific
Reply:

1) Yes
2) Just disable on-access/file scanning in AVG.


0

Response Number 18
Name: Plarin
Date: May 16, 2009 at 12:38:40 Pacific
Reply:

Do you have any ideas on how to disable the scanner?

Windows Task Manager just ignores the command.
I can't find any options in the application itself.
AVG help doesn't have anything.
I even disabled AVG8_TRAY at start-up with Startup Inspector but there's still AVG tasks running. (Restarted the computer.)

I'll keep looking.


0

Response Number 19
Name: jdk (by neoark)
Date: May 16, 2009 at 12:43:01 Pacific
Reply:

That's fine combo fix will disable the rest. If you are on vista run it as admin or run it from administrative account.


0

Response Number 20
Name: Plarin
Date: May 16, 2009 at 12:48:30 Pacific
Reply:

Never mind, I got it disabled.

But,
First ComboFix asked me whether I wanted to update it. I said "yes". Afterwards, it restarted and a program called pevFind.exe failed. After that, a message came up and told me that my copy of ComboFix may be tainted and for peace of mind I should get a fresh one. I stopped there.

Help?


0

Response Number 21
Name: jdk (by neoark)
Date: May 16, 2009 at 12:50:13 Pacific
Reply:

Make AVZ log again. Response Number 1 paste me the link.


0

Response Number 22
Name: jdk (by neoark)
Date: May 16, 2009 at 12:53:05 Pacific
Reply:

Also try to re-download Combo fix don't use firefox to download.


0

Response Number 23
Name: Plarin
Date: May 16, 2009 at 13:03:50 Pacific
Reply:

Sorry for being slow, system stalled restarting.

Assuming the new log rewrote the old one, this is the one you need:

http://rapidshare.com/files/2337662...


0

Response Number 24
Name: Plarin
Date: May 16, 2009 at 13:06:39 Pacific
Reply:

I'm trying to download Internet Explorer 8 from the Microsoft Download Center but only 0 kb files get downloaded.


0

Response Number 25
Name: Plarin
Date: May 16, 2009 at 13:10:33 Pacific
Reply:

All right, I've got ComboFix downloaded with Google Chrome.


0

Response Number 26
Name: jdk (by neoark)
Date: May 16, 2009 at 13:17:07 Pacific
Reply:

Try to run it.


0

Response Number 27
Name: Plarin
Date: May 16, 2009 at 13:23:36 Pacific
Reply:

Got the same message.

pev.cfexe failed and then I was cautioned to cancel:

http://img43.imageshack.us/my.php?i...


0

Response Number 28
Name: jdk (by neoark)
Date: May 16, 2009 at 13:31:59 Pacific
Reply:

Send me these files to inspect:
c:\windows\system32\dll.dll
C:\WINDOWS\system32\MsSip1.dll
C:\WINDOWS\system32\MsSip2.dll
C:\WINDOWS\system32\MsSip3.dll
C:\WINDOWS\system32\stisvc.exe

Copy those files to desktop and private message me the download link.

Also if you have another computer near by download combox on it and transfer it via USB drive.


0

Response Number 29
Name: Plarin
Date: May 16, 2009 at 13:39:51 Pacific
Reply:

I don't have any of those files. (nor a windows folder in lower case
letters)

I do have a "mssip32.dll" though.

I have another computer so I'll download combox onto a zip drive.


0

Response Number 30
Name: Plarin
Date: May 16, 2009 at 13:42:21 Pacific
Reply:

I also have a "sti.dll" and a "sti_ci.dll".

BTW, thank you so much for the help you've given me so far.


0

Response Number 31
Name: jdk (by neoark)
Date: May 16, 2009 at 13:42:32 Pacific
Reply:

Case insensitive for directories. Look again properly go to folder option --> show hidden files. All those files should be under C:\WINDOWS\system32\


0

Response Number 32
Name: Plarin
Date: May 16, 2009 at 13:57:16 Pacific
Reply:

I "ctrl+F" searched system32 with "Search hidden files and
folders enabled" and none of those files turned up. Plus, I already have
hidden files visible. (There aren't any I that I can see in
system32.)

Where should I download combox from?


0

Response Number 33
Name: jdk (by neoark)
Date: May 16, 2009 at 13:59:16 Pacific

Response Number 34
Name: Plarin
Date: May 16, 2009 at 14:19:54 Pacific
Reply:

Same thing happened. Think I should just go ahead with it?


0

Response Number 35
Name: jdk (by neoark)
Date: May 16, 2009 at 14:25:58 Pacific
Reply:

Go ahead?


0

Response Number 36
Name: jdk (by neoark)
Date: May 16, 2009 at 14:28:01 Pacific
Reply:

Try to run combofix in safe mode. Here is tutorial:
http://www.bleepingcomputer.com/com...


0

Response Number 37
Name: Plarin
Date: May 16, 2009 at 14:28:18 Pacific
Reply:

I still have the option to continue but I've been ending it. Should I
say yes, continue?


0

Response Number 38
Name: jdk (by neoark)
Date: May 16, 2009 at 14:32:05 Pacific
Reply:

First try to run combo fix in safe mode and see if it gives you any problems. Post of screen shot of that continue window.


0

Response Number 39
Name: Plarin
Date: May 16, 2009 at 14:39:12 Pacific
Reply:

I ran it in safe mode and I got the same error+caution+continue window.

The continue window looks just like the one in the tutorial you linked.


0

Response Number 40
Name: Plarin
Date: May 16, 2009 at 14:40:44 Pacific
Reply:

The continue window is the "Combofix Disclaimer".


0

Response Number 41
Name: jdk (by neoark)
Date: May 16, 2009 at 14:43:46 Pacific
Reply:

OK continue.


0

Response Number 42
Name: Plarin
Date: May 16, 2009 at 14:44:50 Pacific
Reply:

I'm in safe mode right now. Should I keep going or switch back to normal mode?


0

Response Number 43
Name: jdk (by neoark)
Date: May 16, 2009 at 14:50:40 Pacific
Reply:

Safe mode is ok.


0

Response Number 44
Name: Plarin
Date: May 16, 2009 at 15:06:05 Pacific
Reply:

It says I don't have the "Microsoft Windows recovery console" installed and without it the program won't attempt to fix serious problems.

ComboFix also gives me the option to download it. For nox I'm going to switch out of safe mode so I have internet and then download it.


0

Response Number 45
Name: jdk (by neoark)
Date: May 16, 2009 at 15:07:12 Pacific
Reply:

Yes. Make sure you install recovery console.


0

Response Number 46
Name: Plarin
Date: May 16, 2009 at 15:11:00 Pacific
Reply:

Ack. I clicked no thinking it would exit but it kept going. Now it's saying it's detecting rootkit activity and needs to reboot the machine. It also gave me two files to copy onto paper.

The only option it gave me is OK. I assume that I should keep going and not turn off the machine.


0

Response Number 47
Name: jdk (by neoark)
Date: May 16, 2009 at 15:15:25 Pacific
Reply:

Whatever happens do not hard reboot let it finish what its doing. What were the file names?


0

Response Number 48
Name: Plarin
Date: May 16, 2009 at 15:28:10 Pacific
Reply:

C:\WINDOWS\system32\drivers\gxvxcoesowykmxobhcttypdrgrrshkdbqlrvi.sys

C:\WINDOWS\system32\gxvxcrpycnrueynpkmlgijnlvtnicanlaijbm.dll


0

Response Number 49
Name: Plarin
Date: May 16, 2009 at 15:28:58 Pacific
Reply:

Looks like it's done. Here's the log:

http://rapidshare.com/files/2338069...


0

Response Number 50
Name: Plarin
Date: May 16, 2009 at 15:29:50 Pacific
Reply:

Still have the pop-up problem.

Think I should install the recovery console and try again?


0

Response Number 51
Name: jdk (by neoark)
Date: May 16, 2009 at 15:30:18 Pacific
Reply:

Is combo fix still running? What stage is it at?


0

Response Number 52
Name: Plarin
Date: May 16, 2009 at 15:34:59 Pacific
Reply:

There's nothing related to ComboFix visible on my computer so I
assume it's over.

I'm trying to install the recovery console right now but using the
CD doesn't work since my copy of Windows is "newer" than the
one on the CD. I'll keep looking.


0

Response Number 53
Name: jdk (by neoark)
Date: May 16, 2009 at 15:43:03 Pacific
Reply:

Did it reboot? Re-read Response Number 15. "... Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post."


0

Response Number 54
Name: Plarin
Date: May 16, 2009 at 15:48:27 Pacific
Reply:

I posted the log in Response Number 49.


0

Response Number 55
Name: Plarin
Date: May 16, 2009 at 16:02:03 Pacific
Reply:

Right now I'm trying to download the recovery console, but every
image file I find seems to be missing the "winnt32.exe" I'm
getting told to use.


0

Response Number 56
Name: jdk (by neoark)
Date: May 16, 2009 at 16:12:44 Pacific
Reply:

Leave recovery console for now. Seems i overlooked your post about the log. Follow these steps:

Run this script in AVZ:


begin
CreateQurantineArchive('c:\quarantine.zip');
end.

A file called quarantine.zip should be created in C:\. Then please zip up C:\qoobox\quarantine and upload both it and C:\quarantine.zip to a filehost such as http://rapidshare.com/ Then, Private Message me the Download link to the uploaded file.

Lastly, uninstall Combofix by: pause AV > Start > run > type Metroid.exe /u > ok. Or Start > run > type Metroid /u > ok.

Also, scan with Malwarebytes' Anti-Malware and attach its log, but Please Don't fix anything yet, until the log is reviewed.


0

Response Number 57
Name: Plarin
Date: May 16, 2009 at 16:25:54 Pacific
Reply:

http://rapidshare.com/files/2338199...
http://rapidshare.com/files/2338200...

I can't seem to uninstall Combofix. The Run program says it
can't find Metroid.exe or Metroid, and if I add "C:\Documents
and Settings\ yaddayaddayadda" to the beginning it says it's
can't find "C:\Documents".

Scanning with Anti-Malware now.


0

Response Number 58
Name: jdk (by neoark)
Date: May 16, 2009 at 16:31:01 Pacific
Reply:

You named Combofix Metroid.exe correct? Try it from safe mode since you ran combofix from safe mode. Continue with Malwarebytes scan and post the log once it finishes.


0

Response Number 59
Name: Plarin
Date: May 16, 2009 at 16:51:20 Pacific
Reply:

Log file from malwarebytes:
http://rapidshare.com/files/2338283...

As for ComboFix, you're saying I should type "Metroid.exe /u"
from the Run program in Safe mode?


0

Response Number 60
Name: jdk (by neoark)
Date: May 16, 2009 at 16:58:43 Pacific
Reply:

Yes for 59 safe mode. Fix what malware byte detected.

1) If you use Windows System restore, turn it off > reboot

2) Do a full scan with Kaspersky AVP tool. http://devbuilds.kaspersky-labs.com...
Once you download and start the tool select all the objects to be scanned and hit Scan

Post me log/Screen shot of what it detects(detected window) once it finished and fix what it recommends.

3) Then turn system restore back on, if you wish; this to remove malware from system volume information files. How to turn it off/on: http://support.kaspersky.com/faq/?q...

4) Uninstall AVP tool.


0

Response Number 61
Name: Plarin
Date: May 16, 2009 at 17:04:19 Pacific
Reply:

Edit- Never mind. On it.


0

Response Number 62
Name: Plarin
Date: May 17, 2009 at 15:41:35 Pacific
Reply:

I can't post the entire log since it was 100+ MB, but here's the
important stuff. I deleted all the infected files. (It says 84%
complete because I had to turn off the computer, but when I
restarted and rescanned the entire hard drive it didn't pick up
any viruses.)

84% - Scan
----------
Scanned: 1129384
Detected: 3
Untreated: 3
Start time: 5/16/2009 7:34:07 PM
Duration: 03:09:46
Finish time: 5/16/2009 11:15:44 PM


Detected
--------
Status Object
------ ------
detected: Trojan program Trojan.Win32.Tdss.acdc File:
C:\Qoobox\Quarantine.zip/Quarantine/C/WINDOWS/system3
2/gxvxcrpycnrueynpkmlgijnlvtnicanlaijbm.dll.vir
detected: Trojan program Trojan.Win32.Tdss.acdc File:
C:\Qoobox\Quarantine\C\WINDOWS\system32\gxvxcrpycnru
eynpkmlgijnlvtnicanlaijbm.dll.vir
detected: Trojan program Trojan.Win32.Tdss.acdc File:
C:\WINDOWS\system32\gxvxcrpycnrueynpkmlgijnlvtnicanlaij
bm.bak


0

Response Number 63
Name: Plarin
Date: May 17, 2009 at 15:53:20 Pacific
Reply:

Right now my recycle bin is emptying without me telling it to, but
other than that I'm not noticing any weird behavior.


0

Response Number 64
Name: jdk (by neoark)
Date: May 17, 2009 at 15:54:47 Pacific
Reply:

ok it seems virus is removed. Those are just combofix quarantined files.


0

Response Number 65
Name: Plarin
Date: May 17, 2009 at 15:56:26 Pacific
Reply:

All right, thanks a lot!!!


0

Response Number 66
Name: jabuck
Date: May 17, 2009 at 16:22:56 Pacific
Reply:

The bolded file below does not appear to be in the Combofix quarantine folder, C:\Qoobox and should be deleted manually.

detected: Trojan program Trojan.Win32.Tdss.acdc File:
C:\Qoobox\Quarantine.zip/Quarantine/C/WINDOWS/system3
2/gxvxcrpycnrueynpkmlgijnlvtnicanlaijbm.dll.vir
detected: Trojan program Trojan.Win32.Tdss.acdc File:
C:\Qoobox\Quarantine\C\WINDOWS\system32\gxvxcrpycnru
eynpkmlgijnlvtnicanlaijbm.dll.vir
detected: Trojan program Trojan.Win32.Tdss.acdc File:
C:\WINDOWS\system32\gxvxcrpycnrueynpkmlgijnlvtnicanlaij
bm.bak


0

Response Number 67
Name: jdk (by neoark)
Date: May 17, 2009 at 16:57:00 Pacific
Reply:

C:\WINDOWS\system32\gxvxcrpycnrueynpkmlgijnlvtnicanlaij
bm.bak <-- that file is bak/residual it wasn't running on your system AVP tool took care of it. You fixed all the stuff that AVP tool detected correct? Also try to uninstall combofix.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Unable to access sites to... I need virus help!



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Can't access C Drive

I can't open any drives? www.computing.net/answers/security/i-cant-open-any-drives/21548.html

Can't access the hard drive? www.computing.net/answers/security/cant-access-the-hard-drive/5141.html

Can't access secure web pages www.computing.net/answers/security/cant-access-secure-web-pages/22960.html