Possible infection - Need help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wormgod, May 30, 2011.

  1. wormgod

    wormgod Private E-2

    Hi All.

    A couple of days ago, I think I was infected with some malware/trojan(s). I have tried to clean it, and I am now appealing for help. Here is the series of events:
    1. Got a popup telling me that my hard drive had experienced some sort of failure. I don't remember the exact wording, but it was something along those lines.
    2. At the same time >50% of my desktop shortcuts and Start Menu/All Programs entries disappeared.
    3. I figured something wasn't right with the whole situation, so I rebooted, and ran a scan with Malwarebytes Anti_malware. It found a couple of trojan.FakeAlert entries and removed them.
    4. I then ran a scan with SAS (my normal av software along with Comodo FW), and it found something called trojan.gen-allo and removed it.
    5. My desktop and Start Menu/All Programs shortcuts were still missing, so I searched for a solution and tried Unhide. This recreated the Start Menu/All Programs Folder names, but not the actual shortcuts within those folders.

    At this point, I am looking for the following:
    1. I want to confirm that the infection is actually all gone.
    2. I would also like to confirm that there is no other lingering infection on my system.
    3. If it is at all possible to restore those shortcuts to the Start Menu/All Progems, I would like to do that as well.

    I went through the listed procedure, and the logs are attached. Any help is much appreciated.

    Thanks!
     

    Attached Files:

  2. wormgod

    wormgod Private E-2

    And here is the MGTools log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As long as you did not run any disk/temp file cleaning programs, the below may be able to restore them.

    If these are still missing then please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find your Programs?
     
  4. wormgod

    wormgod Private E-2

    I have already run that, but all it did was restore the "folders" (e.g. "tart/All Programs/QuickTime), but the actual shortcuts seem to have been deleted, so "Start/All Programs/QuickTime" HAS NOTHING IN IT.

    It looks like everything under "All Users" has been deleted and is gone.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you run any disk cleaning programs ( like CCleaner or similar ) ?
     
  6. wormgod

    wormgod Private E-2

    No. No cleaners. ComboFix said it would empty the Recycle Bin (and it looks like it did).

    Also, forget to mention that I restored my registry using ERUNT/ERDNT to an uninfected copy from last week (would have been step 4.5 below).
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have to reinstall your programs to get them to show up again because it looks like all the info for them has been deleted. Normally the malware was saving copies in temp folders, but unhide.exe would have restored them if they existed.

    Have you checked to see if other items like the ones under Start, All Programs, Accessories are missing or not? This one we can likely fix.
     
  8. wormgod

    wormgod Private E-2

    Some are there, and some are not (e.g. Notepad is there, but Accessories/Entertainment is empty). How do we go about restoring those?

    Also, any thoughts about the current state of infection?

    Thanks!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member



    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:
    Seem to be gone.
     
    Last edited: Jun 11, 2011
  10. wormgod

    wormgod Private E-2

    I did that and got my Accessories back. Now I am trying to re-install everything else. At least this is giving me the opportunity to eliminate some of those apps that I don't really need.

    Thanks for all your help!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
    I did not put toggling of System Restore off and then back on in the above. Give yourself another couple days and if all is still good, then toggle system restore to remove old restore points that may carry infections.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds