Desktop Icons and Start Menu Icons gone (Smart HDD???)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by enimrac1206, Oct 24, 2012.

  1. enimrac1206

    enimrac1206 Private E-2

    My wife was looking at a website and clicking on random links. Apparently she downloaded the wrong think to our laptop. We are getting the following message which, after researching, appears to be the Smart HDD virus.

    "A write command during the test has failed to complete. This may be due to a media or read/write error. The system generates an exception error when using a reference to an invalid system memory address."

    I have attached the necessary logs. Please help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You neglected to run TDSSKiller. Please do so.

    In the meantime:
    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : dIwngBIBGkKB.exe (C:\ProgramData\dIwngBIBGkKB.exe) -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-1721611782-460635201-2206628158-1005[...]\Run : dIwngBIBGkKB.exe (C:\ProgramData\dIwngBIBGkKB.exe) -> FOUND
      [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\Michelle\AppData\Local\{3134b32e-4b99-2ad0-5fae-34ef70bc1a2a}\n.) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    Now click the Files/folders tab and locate these detections:

    • [ZeroAccess][FILE] @ : C:\Users\Michelle\AppData\Local\{3134b32e-4b99-2ad0-5fae-34ef70bc1a2a}\@ --> FOUND
      [ZeroAccess][FOLDER] U : C:\Users\Michelle\AppData\Local\{3134b32e-4b99-2ad0-5fae-34ef70bc1a2a}\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\Users\Michelle\AppData\Local\{3134b32e-4b99-2ad0-5fae-34ef70bc1a2a}\L --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Rescan with HitmanPro.
    Choose to Delete these files if they are detected:


    • C:\Users\Cory\AppData\Local\Temp\FileBulldog.exe
      C:\Users\Cory\AppData\Local\Temp\SetupDataMngr_Searchqu.exe
      HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ (SearchQU)
      HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ (SearchQU)
      HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ (SearchQU)
      HKU\S-1-5-21-1721611782-460635201-2206628158-1005\Software\DataMngr_Toolbar\ (SearchQU)
      HKU\S-1-5-21-1721611782-460635201-2206628158-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}\ (SearchQU)
    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    After the reboot, rescan with both RogueKiller and Hitman and attach both those logs as well.

    Please also attach the log from TDSSKiller.
     
  3. enimrac1206

    enimrac1206 Private E-2

    Tim, the system wouldn't allow me to run TDSSKiller....I will do the rest now.
     
  4. enimrac1206

    enimrac1206 Private E-2

    Thanks for the help. I really appreciate it.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like you are good to go, but let me just take another look at the MGLogs. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the C:\MGLogs.zip.
     
  6. enimrac1206

    enimrac1206 Private E-2

    Log attached as requested. Thanks.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.

    Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
    Code:
    :processes
    :killallprocesses
    :files
    C:\ProgramData\-l5s5VB4nDKTQo9
    C:\ProgramData\-l5s5VB4nDKTQo9r
    C:\ProgramData\l5s5VB4nDKTQo9
    C:\Windows\TEMP\datEB38.tmp
    C:\Windows\TEMP\datEB49.tmp
    C:\Windows\TEMP\datF5B3.tmp
    C:\Windows\TEMP\datF612.tmp
    C:\Users\Michelle\AppData\Local\Temp\1511610099236403.tmp
    C:\Users\Michelle\AppData\Local\Temp\1682576119153795.tmp
    C:\Users\Michelle\AppData\Local\Temp\2094199836237605.tmp
    C:\Users\Michelle\AppData\Local\Temp\2147483647.dat
    C:\Users\Michelle\AppData\Local\Temp\3397051458230647.tmp
    C:\Users\Michelle\AppData\Local\Temp\3590660602230850.tmp
    C:\Users\Michelle\AppData\Local\Temp\6798164.od
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.

    Now run this:
    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )
    http://download.bleepingcomputer.com/grinler/unhide.exe
    Now run it. Now see if you can find the items that seemed to be missing?

    If you are still missing items, see this link for further assistance:
    http://www.smartestcomputing.us.com...tart-menu-and-files-hiddendeleted-by-a-virus/

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the logs from OTL and C:\MGLogs.zip
     
  8. enimrac1206

    enimrac1206 Private E-2

    Tim, the link for OTL isn't working for me. I click on it and it opens another tab but gives me "this webpage cannot be found".
     
  9. enimrac1206

    enimrac1206 Private E-2

    I was able to go to bleeping computer to get OTL...however...I closed out of the log and am not sure where to get it again. I attached the other logs you requested. Thanks again.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me how things are running now and if you got your desktop icons back.
     
  11. enimrac1206

    enimrac1206 Private E-2

    My desktop icons are back but my taskbar doesn't have all of the items it did before. It only has IE and that's only because my wife added it. The computer seems to be running normally.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may have to manually restore them.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall
      RogueKiller and HitManPro.
    2. Go back to step 6 of the
      READ ME
      and renable your Disk Emulation software with Defogger if you had disabled
      it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and
      deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the
      C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to
      run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds