Solved Storage Device Issues, virus related?

Sayix

New member
Local time
12:11 AM
Messages
30
Alright, I have started a thread in the Crashes and Debugging section, and it seems this issue has been pointed towards a virus that has not yet been properly gotten rid of.

A lot of the problems that it's caused are mentioned in this thread, so it would be a bit useful to read up on what has been attempted to fix this issue and what problems persist.

I've done some troubleshooting and attempts to determine the problem, being searching for drivers/services not starting properly within the registry and such.

If you have not checked out the thread linked above, some things I have taken note is:
- Removable Disk Drives are completely gone, missing from Disk Management and explorer, not to mention external storage devices do not appear in device manager. This will put USB drives in a non-responsive state to newly plugged in devices.

- Once USB drives are put in this "non-responsive" state, they will cause a BSOD upon shutting down. (BUGCODE_USB_DRIVER, 0xFE)

- It seems that cscript.exe (Which I have noticed is connected to several worms) seems to be running at all times, hiding from task manager. (Thanks for DDS for find that out.) I don't know if this is normal or not, however.

- Typical common Anti-viruses fail to install. (Ex: Spyware Doctor and Kaspersky)

- Upon ending a random number of processes, Task Manager goes into a non-responding state, making the computer useless when it comes to opening/closing programs. This requires a hard shut off.

- A generic looking windows popup with a title of "You're about to be logged off." and saying "Windows will now shut down in less than a minute." appears whenever I ran a certain removal tool. It used to appear everyday at one random point, however a few virus scans in safe mode changed that.

I've got a few thing determined:
- My USB devices are working fine, the missing removable disk drives in Disk Management causes an issue when a device with any bit of storage is plugged in.

- This is not a "hardware issue." (as Microsoft's support tried suggesting...) External Drives show up in my BIOS.

- This problem has also appeared on my other hard drives. (Their Windows installations also have no removable disk drives.)

If anymore information is needed, let me know and I will obtain it for you. Any suggestions?
 

My Computer

Computer Manufacturer/Model Number
Custom Made
OS
Microsoft Windows 7 Ultimate 64-bit
CPU
AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Motherboard
ECS Elitegroup - RS485M-M
Memory
2.00 GB
Graphics Card(s)
Radeon X1600/X1650 Series
Sound Card
Realtek AC'97 Audio
Screen Resolution
1680x1050
Hard Drives
ST3120827AS ATA Device
ST3320418AS ATA Device
(Third drive became missing from Disk Manager and Windows Explorer, fixes upon restart.)
Other Info
BIOS: Phoenix - Award WorkstationBIOS v6.00PG
Sayix,
Run Windows Defender Offline, WDO. Link in my signature.
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
I have done that previously, however should I do it again just to be safe?
 

My Computer

Computer Manufacturer/Model Number
Custom Made
OS
Microsoft Windows 7 Ultimate 64-bit
CPU
AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Motherboard
ECS Elitegroup - RS485M-M
Memory
2.00 GB
Graphics Card(s)
Radeon X1600/X1650 Series
Sound Card
Realtek AC'97 Audio
Screen Resolution
1680x1050
Hard Drives
ST3120827AS ATA Device
ST3320418AS ATA Device
(Third drive became missing from Disk Manager and Windows Explorer, fixes upon restart.)
Other Info
BIOS: Phoenix - Award WorkstationBIOS v6.00PG
yes
Be sure to click on WDO in my signature.

This is NOT the same thing as turning on Windows Defender.

Once again, MS has done a very poor job of naming programs.
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
I know, I have used Windows Defender Offline before.

Anyway, no infections were found with the scan.
 

My Computer

Computer Manufacturer/Model Number
Custom Made
OS
Microsoft Windows 7 Ultimate 64-bit
CPU
AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Motherboard
ECS Elitegroup - RS485M-M
Memory
2.00 GB
Graphics Card(s)
Radeon X1600/X1650 Series
Sound Card
Realtek AC'97 Audio
Screen Resolution
1680x1050
Hard Drives
ST3120827AS ATA Device
ST3320418AS ATA Device
(Third drive became missing from Disk Manager and Windows Explorer, fixes upon restart.)
Other Info
BIOS: Phoenix - Award WorkstationBIOS v6.00PG
and is your mysterious cscript still showing up?
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Do the removable drives show up in the systems BIOS?
 

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Home Premium 64 bit at home and Windows 7 professional at school.
Memory
4gig
Graphics Card(s)
2: 2gig each
Monitor(s) Displays
1
Screen Resolution
1366/768
Internet Speed
40.6 Mps
and is your mysterious cscript still showing up?
Yep, DDS still picks it up.

Code:
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Users\Auku\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Users\Auku\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler64.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\Java\jre7\bin\javaw.exe
C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7\firefox.exe
C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7\plugin-container.exe
C:\Windows\system32\taskeng.exe
[U][B]C:\Windows\SysWOW64\cmd.exe[/B][/U]
C:\Windows\system32\conhost.exe
[U][B]C:\Windows\SysWOW64\cscript.exe[/B][/U]
C:\Windows\system32\wbem\wmiprvse.exe

The javaw.exe running was just Minecraft, not any other application.

Do the removable drives show up in the systems BIOS?

Removable drives showing up in the BIOS? Things like external drives are shown as storage in my BIOS. If that is what you mean, then yes.
 

My Computer

Computer Manufacturer/Model Number
Custom Made
OS
Microsoft Windows 7 Ultimate 64-bit
CPU
AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Motherboard
ECS Elitegroup - RS485M-M
Memory
2.00 GB
Graphics Card(s)
Radeon X1600/X1650 Series
Sound Card
Realtek AC'97 Audio
Screen Resolution
1680x1050
Hard Drives
ST3120827AS ATA Device
ST3320418AS ATA Device
(Third drive became missing from Disk Manager and Windows Explorer, fixes upon restart.)
Other Info
BIOS: Phoenix - Award WorkstationBIOS v6.00PG
I'm just gonna build a new and improved computer, there seems to be absolutely no solution to this.
 

My Computer

Computer Manufacturer/Model Number
Custom Made
OS
Microsoft Windows 7 Ultimate 64-bit
CPU
AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Motherboard
ECS Elitegroup - RS485M-M
Memory
2.00 GB
Graphics Card(s)
Radeon X1600/X1650 Series
Sound Card
Realtek AC'97 Audio
Screen Resolution
1680x1050
Hard Drives
ST3120827AS ATA Device
ST3320418AS ATA Device
(Third drive became missing from Disk Manager and Windows Explorer, fixes upon restart.)
Other Info
BIOS: Phoenix - Award WorkstationBIOS v6.00PG
Back
Top