![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I got a virus that makes my computer appear that all my programs and files are gone. Even in safe mode nothing shows up. Avast still loads and runs and I can see it scanning through the files so I know they're still there but can't access anything. Avast found a root kit virus and I clicked move to chest and it wouldn't work and any other action has the same result. How can I get this out? Thanks for your help.
|
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks!
Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing ) http://download.bleepingcomputer.com/grinler/unhide.exe Now run it ( if you are running Vista or Win 7, use right click and select Run As Administrator ). Did that help with your missing items? Even if the above restore missing items, it highly recommended to run the below cleaning processs as Unhide is not removing the malware. It is just trying to restore missing items. Please follow the instructions in the below link: READ & RUN ME FIRST. Malware Removal Guide
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
Thanks so much. So far so good it seems. I just finished running all the tools you said and hitman found 12 suspicious items which I chose to ignore as instructed. I've attached the logs here so you can take a look before I finish up.
|
|
#4
|
|||
|
|||
|
Update: I'm having problems at restart in that I'm getting the blue screen that suggests a corrupt driver. I think it might be the linksys wireless adapter because the blue screen comes up right after the adapter loads in the tray. It doesn't happen when I start in safe mode. I have a few weeks of system restore points so I can do that if I need to but I'll wait until you've had a chance to review my logs. Thanks.
|
|
#5
|
||||
|
||||
|
You're welcome.
Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
Please download OTM by Old Timer and save it to your Desktop.
Code:
:Processes
explorer.exe
:Files
C:\Documents and Settings\All Users\Application Data\IEEhbDnrDIeqnkP.exe
:Reg
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
"IEEhbDnrDIeqnkP.exe"=-
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}]
:Commands
[purity]
[EmptyTemp]
[start explorer]
[Reboot]
saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Unfortunately after I sent my last message everything returned to the way it was with all my files missing again and I had to do the entire process all over again. I got back to the point where I was when I last posted but the kapersky thing won't run. I renamed it as instructed and I get an error that it can't run in safe mode. That is the only mode I can get into as it just keeps rebooting over and over if I try to boot up normally. As I said I have a month of system restore so maybe I should try to do that. Suggestions?
|
|
#7
|
||||
|
||||
|
Please skip just the part with TDSSKiller and continue with the rest.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#8
|
|||
|
|||
|
I did the rest and here are the logs. Avast is still finding the rootkit and thinking its deleting it but I know it isn't. Kaspersky still doesn't run and occasionally I get a blue screen on reboot and then the second boot goes through ok. Thanks for your help.
|
|
#9
|
||||
|
||||
|
Do you have your Windows XP boot CD? If not, try making the below CD and test to see if you can boot into the Recovery Console with it. This is just a test at this point.
Using ARCDC to get the Recovery Console Command Prompt
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
|||
|
|||
|
I don't have the boot cd and unfortunately the link didn't work for me. When I attempted to run the exe and make the cd I kept getting an error that said it had a failed connection to microsoft. Is there another link that I can try to use to make a boot cd?
|
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Please disregard the last message - the process is working so I'll proceed with the burn and reply with the results soon.
|
|
#12
|
||||
|
||||
|
Quote:
![]()
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#13
|
|||
|
|||
|
Ok I'm back. Sorry for the delay but had a family crisis that took precedent. But I just now followed the instructions and everything booted fine from the windows cd. I'm ready for the next step.
I have noticed something though that might matter. On the first boot the pc tries to load the wireless device in the tray and then craps out to a blue screen. That is not the normal loading sequence. On second reboot, it loads it last and everything loads fine and then runs ok for a while until I get the notice from Avast that the root kit virus is present. Don't know if that is caused by the root kit or not but just thought I'd mention it. Thanks for your patience. |
|
#14
|
||||
|
||||
|
Quote:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#15
|
|||
|
|||
|
That's correct. It boots fine from the CD. I'm referring to the normal boot process. When I boot from Windows I notice that the first time around the wireless device loads first in the tray, it halts and then goes to a blue screen. Then I shut it down and boot a second time and then it works ok the second time and the wireless device loads last in the tray. That might be a corrupt driver from the virus but once it boots ok I can get online fine so it doesn't appear to be affecting it too much. And I keep trying to run that kaspersky kill app but its still not working.
|
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
Quote:
Now we need to remove an infected partition from your harddisk. You will need to make another special boot CD to to this. Please download: gparted-live-0.13.1-2.iso (124 MB) Create a bootable CD for GParted. You can use ImgBurn to accomplish this. If you need help on how to use ImgBurn, please view this guide by dr.m -- Using ImageBurn to Burn an ISO image Now boot off of the newly created GParted CD. ![]() You should be here... Press ENTER ![]() By default, do not touch keymap is highlighted. Leave this setting alone and just press ENTER. ![]() Choose your language and press ENTER. English is default [33] ![]() Once again, at this prompt, press ENTER You will now be taken to the main GUI screen below ![]() According to your logs, the partition that you want to delete is 2.48 MiB (2.48 MB) Click the trash can icon to delete and then click Apply. You should now be here confirming your actions: ![]() Now you should be here: ![]() Is boot next to your OS drive? According to your logs, your OS drive is the 1.36 TB sized partition. ![]() If boot is not next to your OS drive under Flags, right-mouse click the OS drive while in Gparted and select Manage Flags In the menu that pops up, place a checkmark in boot like the picture below: ![]() Now press the Close button to save these changes. Now double-click the button.You should receive a small pop up like this: ![]() Choose reboot and then press OK. Now reboot from the WindowsRecovery Console using the ARCDC cd and execute the following commands at the command prompt pressing ENTER after each:
Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#17
|
|||
|
|||
|
Everything ran just as described and here are the logs. No error on boot and so far no avast report of rootkit.
|
|
#18
|
||||
|
||||
|
Your MGlogs.zip file is still always coming out incomplete. Are you shutting down Avast before running it? Are you seeing an errors while running it? We need to get a complete log.
Also why are you running MGtools.exe when I asked you to run C:\MGtools\GetLogs.bat
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#19
|
|||
|
|||
|
I'm sorry I didn't remember to disable Avast but I did run the correct file so I'm not sure why they were incomplete. I deleted all the previous folders and reloaded the mgtools from scratch and ran the runbat again so hopefully this time it will look better. And I disabled avast this time. Thanks for your help and patience.
|
|
#20
|
||||
|
||||
|
You're welcome. Looks good now.
Is everything still working okay?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Strange virus, makes it look as if my files were deleted. Possible registry issue? | pfairclough | Malware Removal | 1 | 05-04-11 12:33 |
| Think I'm ok, but hidden files in Root Repeal... | rbt | Malware Removal | 9 | 07-26-10 14:37 |
| Malware in C:/ root; batch,txt, and exe files - help | kdt2121 | Malware Removal | 1 | 01-20-09 01:55 |
| Anti virus 2009 reinstalling deleted files? | greybuffalo | Software | 8 | 12-23-08 20:28 |
| Root kit files | tester36 | Malware Removal | 7 | 03-18-06 20:07 |