![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi, i was infected about a week ago by XP Total Security 2011. It appeared to had deleted everything off my computer (desktop files, ect). For a while i would have to use a registry file every time on start up to use executable files. I managed to finally run combofix by using an AVG removal program, thus allowing full control of my computer and everything appearing back on the desktop. Still, i believe i am infected or files are corrupt. I cannot connect to the internet, when i go into All Program in the start menu i can see all my folders but the majority of the folders contain nothing. My computer is also still running very slow. I tried going to Bleepingcomputer for help but i have been waiting for a reply for awhile. I now come to you, majorgeeks.com, begging for help in solving these problems. If i do not answer quick enough i am sorry, it is 10 at night and i have work till 3 tomorrow (i live on the east coast, new york). any help would be great. thanks!
|
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks!
I want you to run TDSSKiller so refer to the below for how to do so. TDSSkiller - How to run Please read ALL of this message including the notes before doing anything. Pleases follow the instructions in the below link: READ & RUN ME FIRST. Malware Removal Guide and attach the requested logs when you finish these instructions.
Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
Here are the first 4 logs (tdskiller, super antispyware, malwarebytes, and combofix) attached
|
|
#4
|
|||
|
|||
|
here are the last 2 (rootrepeater and mgtools) attached.
i might also add that my internet came back when i unplugged my switch and plugged it back in. for some reason it decided it would come back to life. |
|
#5
|
||||
|
||||
|
Quote:
Uninstall outdated Java:
Now we need to use ComboFix
Code:
KILLALL:: File:: C:\Documents and Settings\Antonio1\Local Settings\Application Data\6lr8qybjn13oh6xyp8ivrd2x86m5wp C:\Documents and Settings\All Users\Application Data\19586852 C:\Documents and Settings\All Users\Application Data\6lr8qybjn13oh6xyp8ivrd2x86m5wp C:\Documents and Settings\All Users\Application Data\~19586852 C:\Documents and Settings\All Users\Application Data\~19586852r RenV:: c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe c:\program files\Common Files\Ahead\Lib\nmbgmonitor .exe c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe c:\program files\iTunes\ituneshelper .exe c:\program files\Java\jre6\bin\jusched .exe c:\program files\QuickTime\qttask .exe c:\program files\Winamp\winampa .exe
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Reboot your machine and install the most current and up to date version of Java available here at the below link: Java Runtime 6 Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Quote:
http://download.bleepingcomputer.com/grinler/unhide.exe Now run it. Did that help?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#7
|
|||
|
|||
|
I told them i was seeking help elsewhere. also here are the next two files. the unhide.exe did not work, unfortunately. on a good note i'm pretty sure my computer is running smoother now.
*EDIT* when i start my computer it keeps saying launching applications...i don't know if this means anything. |
|
#8
|
||||
|
||||
|
Quote:
Now please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2
Navigate to the C:\MGtools\FIxAttr.bat and double click it to run it. Has that made a difference at all?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#9
|
|||
|
|||
|
None of it worked =/ I think it's weird that it cannot find the source for these files.
|
|
#10
|
||||
|
||||
|
Hang in there. I am having a think about this. There is no easy fix for this problem.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
EmeraldX (05-27-11) | ||
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
It's fine, take your time. You've been such a big help as it is, and you're doing this on your own time. I'm not going to be one to rush you.
|
|
#12
|
||||
|
||||
|
It is very possible that the infection you had has cause shortcuts and links for Startups and Programs under the Start menu to be deleted. If this is what has happen, there is no real fix. You could attempt reinstalling applications to repair this or you could attempt to manual drag the items you with to have in your Start Menu onto the Start button. This would not put them into folders though so you would manually have to create folders.
What is the complete set of problems that you are still having? Is it that some folders like C:\Program Files or C:\Documents and Settings do not even show?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#13
|
|||
|
|||
|
Those are showing, it's just that when i go to all programs and go into the individual folders i don't see my icons. it's not something i'm really stressing over (except my calculator is missing, i really loved that thing), but if that's all that is left to be wrong with my computer i can deal greatly. i have been helped so much on this site and it makes me happy to know that my computer is up and running again. i'm more than grateful for the help that has been given to me. if there is no fix for this particular problem i'll deal and move on with life, and do as suggested with moving the files into their respected folders.
|
|
#14
|
||||
|
||||
|
Well let's see if we can find any backup copies from other user accounts that we may be able to use to restore some items.
Download OTL to your desktop.
Code:
%userprofile%\..\*. %userprofile%\*. /S %userprofile%\Desktop\*.* /S %userprofile%\Local settings\Temp\smtmp\*.* /S %userprofile%\Start Menu\*.* /S %userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\*.* /S %userprofile%\Application Data\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.* /S %TEMP%\smtmp\*.* /S %allusersprofile%\*. /S %ALLUSERSPROFILE%\Desktop\*.* /S %ALLUSERSPROFILE%\Local settings\Temp\smtmp\*.* /S %ALLUSERSPROFILE%\Start Menu\*.* /S %ALLUSERSPROFILE%\Application Data\Microsoft\Internet Explorer\Quick Launch\*.* /S %ALLUSERSPROFILE%\Application Data\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.* /S %AppData%\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.* /S %systemdrive%\Documents and Settings\Antonio1\Desktop\*.* /S %systemdrive%\Documents and Settings\Antonio1\Local settings\Temp\smtmp\*.* /S %systemdrive%\Documents and Settings\Antonio1\Start Menu\*.* /S %systemdrive%\Documents and Settings\Antonio1\Application Data\Microsoft\Internet Explorer\Quick Launch\*.* /S %systemdrive%\Documents and Settings\Antonio1\Application Data\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.* /S %systemdrive%\Documents and Settings\LogMeInRemoteUser\Desktop\*.* /S %systemdrive%\Documents and Settings\LogMeInRemoteUser\Local settings\Temp\smtmp\*.* /S %systemdrive%\Documents and Settings\LogMeInRemoteUser\Start Menu\*.* /S %systemdrive%\Documents and Settings\LogMeInRemoteUser\Application Data\Microsoft\Internet Explorer\Quick Launch\*.* /S %systemdrive%\Documents and Settings\LogMeInRemoteUser\Application Data\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.* /S %systemdrive%\Documents and Settings\Administrator\Desktop\*.* /S %systemdrive%\Documents and Settings\Administrator\Local settings\Temp\smtmp\*.* /S %systemdrive%\Documents and Settings\Administrator\Start Menu\*.* /S %systemdrive%\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\*.* /S %systemdrive%\Documents and Settings\Administrator\Application Data\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.* /S %systemdrive%\Documents and Settings\Default User\Desktop\*.* /S %systemdrive%\Documents and Settings\Default User\Local settings\Temp\smtmp\*.* /S %systemdrive%\Documents and Settings\Default User\Start Menu\*.* /S %systemdrive%\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\*.* /S %systemdrive%\Documents and Settings\Default User\Application Data\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.* /S
(If the folder is empty or doesn't exist just let me know and continue with the next one) C:\Documents and Settings\LogMeInRemoteUser\Local settings\Temp\smtmp
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#15
|
|||
|
|||
|
I have deleted logmein, so that folder does not exist and as for the other files i can not find them. also, it will not allow me to upload the txt document, and every time i try to post it here it freezes up on me.
|
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
You really are only supposed to be doing what we ask you to do per the READ & RUN ME. This user account may have had some files you could have used.
Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing ) http://download.bleepingcomputer.com/grinler/unhide.exe Now run it. Now see if you can find any of those folders I was asking about. It may be too large. Put it into a ZIP file and attach that.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#17
|
|||
|
|||
|
i'm sorry, i know it hurts me and i wasn't thinking. i got happy when i had all my files back and wanted to do some cleaning on my computer.
i still cannot find the files when i used unhide.exe The file is attached now, though. |
|
#18
|
||||
|
||||
|
So you are saying that you cannot locate any of the smtmp folders?
It would be a good idea to uninstall AVG10 to avoid having it get in our way. So uninstall it now while I look through your OTL.txt log.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#19
|
|||
|
|||
|
Yes, i cannot locate any of the files.
|
|
#20
|
||||
|
||||
|
Based on your log, we will not be able to restore from other accounts since the links to programs are missing from all user accounts. Let's try a couple things to see if we can fix a few links just by reinstalling. Download and reinstall each of the below and after reinstalling, tell me if these all now show in your All Programs menus.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Tags |
| connection, infected, malware, spyware, virus |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| infected computer 64bit. logs attached. system file infected | f_glover2011 | Malware Removal | 5 | 05-14-11 13:45 |
| urgent help needed (infected computer) | unk045 | Malware Removal | 5 | 11-04-10 21:53 |
| Avast! reported 1256326501.exe infected with alureon-DR, COMRES.DLL infected? | LouGeek | Malware Removal | 6 | 11-20-09 01:20 |
| System infected! Please URGENT HEEEELP !! | Maggie_61 | Malware Removal | 9 | 07-04-07 21:55 |
| Urgent Help!!!! | big_problem | Hardware | 1 | 08-04-06 07:22 |