Bad Virus? Most Start Programs Empty & Missing Icons

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ustrueblues, May 17, 2011.

  1. ustrueblues

    ustrueblues Private E-2

    Great forum here, first time poster. Week ago was on the internet & Avast popped up and warned of a malicious trojan & malicious url then a window look alike program started scanning for spyware then computer shutdown with a harddrive error. Rebooted & when clicking on any programs error came up c:\windows\system32\rundll32.exe=application not found. Restarted & all the icons and desktop disappeared. Booted into safe mode & ran malware byte scan & 2 trojan.age showed & 2 spyware.p showed, then did a full scan with malware & rogue.inst, trojan.fak, rootkit.td, & 2 trojan.qho showed. First 3 were in documents & settings & last 2 were in reg. value & reg. data. Then ran gmer & finally icons & desktop came back. Then ran microsoft security essentials & it found root kit trojan:dos/alureon.A, then tried tdss root killer & it seemed to get rid of this trojan. I found this site and went through the read first step by step except I unistalled maleware bytes so I could change the file name & when I tried to download combofix the site would lock up at 95% of the download. When I start the computer now avast pops up with a malicious file c:\documents & settings\allusers\application\c2302be7-619f-4d53 & has the option to ignore or delete. I click delete but it pops up when restarted. Also most of the start programs on the right side like office and others when clicked on are empty. Sorry for the long post, I have attached most of the logs from the sequence. Any help would be appreciated. Thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the following logs:
    ComboFix
    C:\MGLogs.zip --- From running the C:\MGTools.exe
     
  3. ustrueblues

    ustrueblues Private E-2

    Tim,
    Thanks for the reply. I am attaching the mg zip log flle. I don't know what the problem was with downloading the combofix. I followed the link that this forum had and tried both links and it would reach 95% of the download and then a window would come up that said the download was timed out. Is there another spot that I can get the combofix download? Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Quite possibly it is due to not following the early instructions in the READ & RUN ME and also not following later instructions in the area of ComboFix and the other scanning tools.

    The first instructions in the READ & RUN ME specified that you must not have multiple antivirus programs installed and you have both Avast and Microsoft Security Essentials installed. And later we stated that issues can arise with scanning tools including ComboFix and also sometimes MGtools if you do not disable protection software. You have all of your protection running when you ran MGtools and likely had them running when you tried to download ComboFix.

    You must uninstall all but one antivirus, and in fact since you may have corrupted some things on your system by installing more than one, it would be best if you uninstall both of them now and then reboot. Do not reinstall yet. Then try to download and run ComboFix.


    Also please attach the below log file since you appear to have run FixAttr.bat on your own.

    C:\MGTools\FixAttr.txt
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and one more thing you need to run based on what I see in your logs to fix some broken file associations. Run the below by double clicking on it. It will run very quickly.

    C:\MGtools\FixFa.bat


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
     
  6. ustrueblues

    ustrueblues Private E-2

    Chaslang,

    Thanks for the reply. I did not realize that Microsoft Essentials was a virus program & I needed to deactivate all the virus software when doing all the scans. I will go back through per your directions. I will repost those logs later. Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. ustrueblues

    ustrueblues Private E-2

    Chaslang,
    Thanks for the good advice. I uninstalled both virus programs & turned my firewall off. I was able to get combo fix to download. I hope I did this in the right order. I ran the two MGtool files that you mentioned then I ran the combo fix. I am attaching these two logs. Thanks Again.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are these and why are they in your documents:
    C:\Documents and Settings\Jeff\My Documents\nhgfovgz.exe
    C:\Documents and Settings\Jeff\My Documents\brt5f1mb.exe

    If you don't know, delete them or add them to the file fix in combo.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Jeff\2gweorjqjutp92vjy9gake
    C:\Documents and Settings\Jeff\Local Settings\Application Data\6lr8qybjn13oh6xyp8ivrd2x86m5wp
    C:\Documents and Settings\Jeff\Local Settings\Application Data\{B367BC18-DC5D-4F83-B828-2EB6704AAD81}
    C:\Documents and Settings\All Users\Application Data\6lr8qybjn13oh6xyp8ivrd2x86m5wp
    C:\Documents and Settings\All Users\Application Data\cP28276DgFjE28276
    C:\Documents and Settings\Jeff\Templates\6lr8qybjn13oh6xyp8ivrd2x86m5wp
    C:\WINDOWS\Ifuxexuri.dat
    C:\WINDOWS\Ibitoza.bin
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else! Make sure you clean out these folders:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Jeff\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. ustrueblues

    ustrueblues Private E-2

    Tim,
    Thanks for the reply. I forgot to mention that my system is XP Home Service pack 3. I did the steps that you gave me today & I deleleted those two files in my jeffs my document files. I also deleted the C:\Documents and Settings\Jeff\Local Settings\Temp\. When I tried to clean out the C:\WINDOWS\Temp\ an error message came up that it couldn't delete webshlock.txt it is being used by another person or program. Tried to delete some of the other files in this folder and similar message kept coming up. It appears that the computer turns on alright but all the main programs on the start menu when selected show empty folders. Another couple of items are that outlook is not on the left side of the start menu & if in the control panel you try to open the administrator folder it is empty. So still some unusual things going on. One thing I am wondering is I saw an article on your site saying that once a system is compromised you can't really trust your privacy as far as credit cards etc. They more or less said wipe the hard drive. Or I wonder if the hidden partition to restore would be compromised at this point also.See what you think thanks again for your time and help.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run both of these that Chaslang asked you to run:
    C:\MGtools\FixFa.bat
    C:\MGTools\FixAttr.txt

    I am not finding any other malware in your logs. But use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\cP28276DgFjE28276

    If you are worried about your security, it might be best to restore using the partition drive. You would need to post in the software forum for advice on doing that.

    The only thing I can suggest about the empty start programs is to right click each and choose properties. There you can re-enter the target for each. That is a real PITA, but if you have done the two fixes by Chaslang, it is all I can suggest. You can wait and see if Chaslang has some other suggestions when he logs in.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tim meant FixAttr.bat for this second item to run. However we already know it was run because the FixAttr.txt log exists which we need to have attached.

    But please do tell us whether you ran FixFA.bat
     
  13. ustrueblues

    ustrueblues Private E-2

    Tim,

    Thanks for looking through all this information. I'm not sure if I ran FixFA.bat or not. When I right click on properties it does not show that it has been accessed. Would it be a good ideal to run that program again in case I did not? The only other thing when I start the computer a notepad window pops up after launch and says desktop.ini with some text talking about win32 shell something. Never seen that before. Tried the right click for restoring the target on the programs and there were no options to set the target. Thanks for all your efforts.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it would not hurt.

    You need to attach the requested FixAttr.txt log. Also I suggest re-running C:\MGtools\GetLogs.bat and attaching the new C:\MGlogs.zip file so we can see the effects of the FixFA.bat command.
     
  15. ustrueblues

    ustrueblues Private E-2

    Chaslang,

    Here are the other two files that you asked for. Thanks for helping on this.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay if you still have files/folders hidden, please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Then double click on the file to run it ( use right click and Run As Administrator if you are running Win 7 or Vista ).
     
  17. ustrueblues

    ustrueblues Private E-2

    Chaslang,
    Thanks for taking another look at my ongoing computer glitch. I downloaded the grinler/unhide exe that you linked to and ran it on my desktop. Rebooted and still the empty program files. Some of them still have the program but most don't have the progam launch where they used to be. The outlook shortcut on the left side of the start menu is gone and the internet explorer icon says (no add ons). When I start the computer notepad launches and says desktop.ini at the top with the text in the document saying: [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787. I have uploaded a screen shot so you can see the program file problem. Don't know if I'm at a dead end here.Thanks for all your time and tips.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is unlikely you will be able to fix this easily. The only thing you may be able to do is reinstall various programs and create startup entries and program entries yourself since the problems caused by the malware cannot be fixed now since the shortcut were deleted. Unhide.exe would have restored them if possible.

    You may want to try just creating a new user account, then login to the new user account. You may find that some items may appear in the new user account. The next alternative, would be as I said above, to reinstall all applications. Other alternative, reinstall Windows and all applications from scratch.


    This is just from the desktop.ini file on your Desktop now.
     
  19. ustrueblues

    ustrueblues Private E-2

    Chaslang,

    Thanks for all your efforts and advice on this problem. I will try some of your final suggestions and see what happens. Thanks Again.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this:


    • Open Command Prompt. Click Start>Programs>Accessories>Command Prompt
    • type the following command:
      • attrib -h ";C:\*.* /s /d
    • Close Command Prompt by typing the following command:
      • exit
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  21. ustrueblues

    ustrueblues Private E-2

    Tim,
    Here is the log that you requested after typing in the formula attrib -h ";C:\*.* /s /d. When I typed this in at the command prompt I hit enter & it said the formula was not a recognized format. Then I typed exit and hit enter again. I hope I typed this correct. Thanks.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, it didn't work. Let me do some more investigating and I will get back to you.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      [I]smtmp[/I] *
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  24. ustrueblues

    ustrueblues Private E-2

    Tim,

    Thanks for looking into my virus problem again. I ran the system look program that you linked for me. I am attaching the log from that scan. It looked like there were no files found. Sorry for the delay getting back to you. Been a little busy. Thanks Again.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download RogueKiller.exe and save it to your desktop.
    • Now quit all running programs.
    • Double click RogueKiller.exe to run it.
    • When prompted, type 1 and hit Enter.
    • A RKreport.txt should appear on your desktop.
    • Note: If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe .
    • Please post the contents of the RKreport.txt in your next Reply.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After doing what Kestrel asked you to do, try creating a new user account ( with Admin. privileges ) and tell me if that account works.
     
  27. ustrueblues

    ustrueblues Private E-2

    Kestrel,
    Thanks for your reply. I ran the rogue killer program that you linked to and I am attaching the log that it made. Thanks.
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    [*]Double-click SystemLook.exe to run it.
    [*]Copy the content of the following codebox into the main textfield:
    Code:
    :folderfind
    smtmp*
    
    Click the Look button to start the scan.
    When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  29. ustrueblues

    ustrueblues Private E-2

    Tim,
    Here is the log that you requested after running system look. Also I tried setting up another user account with administration and when I tried to open the new account it hung at setting up internet explorer on the first splash page as it started up. Thanks for the help.
     

    Attached Files:

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only other idea I can suggest is that you try to do a system restore to before this happened. Let me know if you are able to do that.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds