File Recovery program rules my computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bluemooze, Jul 14, 2012.

  1. bluemooze

    bluemooze Private E-2

    1 - A "File Recovery" program has appeared and I can't close it.
    2 - Getting many "System Message - Write Fault Error" windows.
    3 - All of my files were hidden.
    4 - Task bar was cleared.
    5 - Start menu was emptied.
    6 - Desktop was emptied.
    7 - Desktop color is now black instead of blue.
    8 - Many and various error message pop ups such as "serious disk error writing drive c"
    9 - Can't run Task Manager.

    By following majorgeeks directions I've unhid my files and restored desktop icons.

    I've attached the 4 log files as requested.
     

    Attached Files:

    Last edited: Jul 14, 2012
  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, bluemooze :)

    [​IMG] Open RogueKiller again.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now press the Delete button.
    Now press the Fix Shortcuts button.
    When it is finished, there will be a few new new logs on your desktop.
    Attach RKreport[4].txt and RKreport[5].txt to your next message. (How to attach)

    __

    Please attach the above log to your next message. (How to attach)

    __

    Use Windows Explorer to delete the following files:

    • C:\ProgramData\-SadoT60UVS7jw1
    • C:\ProgramData\-SadoT60UVS7jw1r
    • C:\ProgramData\rblHWXUPUUNqIJn.exe
    • C:\ProgramData\SadoT60UVS7jw1
    • C:\ProgramData\SadoT60UVS7jw1.exe

    __

    [​IMG] From Programs and Features (via Control Panel), please uninstall the below:
    • Java(TM) 6 Update 26

    __

    [​IMG] Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)

    __

    Let me know what problems remain after you have completed these steps.
     
  3. bluemooze

    bluemooze Private E-2

    Sorry to take so long to reply; was busy for a few days.

    I am happy to tell you that I have been able to boot up normally and am not experiencing the problem.

    Thank you very much for providing this service and advice.

    Here are the attachments you requested:
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    No problem and you're welcome :)
    Your latest logs are clean.

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds