Hidden desktop files + google redirect

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wheelie46, Jun 6, 2011.

  1. wheelie46

    wheelie46 Private E-2

    Greetings,
    I got this virus where there are pop ups warning me there is a bad sector on my hard drive and ask me to refragment and a bunch of stuff, so I did a full malwarebyte's scan.
    Infections were detected and I deleted them.

    Once I restarted my computer, my desktop is now blank. I tried to unhide the hidden files but the icons are now in faded form.

    So I went online to google a way to fix this and noticed I also have google redirect problem, then I came across this website. I am in following the steps this website provided after I registered my account.

    Also, there are some invisible ad sound last night, but it hasn't occur yet today.

    Now I am in the first step which is fixing the google redirect problem using GooredFix.

    It be great if someone could help me fix my problems.
    Thank you.

    See attachment mbam, gooredfix logs.

    My os: Vista Business SP1 32 bit
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Did that help with the hidden files?

    Follow the rest of the instructions in the Read and Run Me First:

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide

    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. wheelie46

    wheelie46 Private E-2

    This is bad, the unhide program fixed the hidden files problem, but my taskbar and startup menu are still empty. then a few minutes later another virus hit my computer it's a malware protection virus with the red blue green yellow shield icon.

    I also tried to run tdskiller but it wouldn't run. I tried change the name but nothing.
     
    Last edited: Jun 6, 2011
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If something does not run then skip that step and continue on.
     
  5. wheelie46

    wheelie46 Private E-2

    Im gonna be busy for a few days and will be back on Thursday.
    Thanks for your help so far.
     
  6. wheelie46

    wheelie46 Private E-2

    So I finished all the scans in READ & RUN ME FIRST but I can't get the RootRepeal log.

    PROBLEMS
    The unhide program you told me to run unhidden most files on my desktop, but there are still 2 files hidden.

    My taskbar and startup menu are empty.

    Google direct problem still exist

    Im on safemode so Im not sure if the invisible ad sound problem is fixed.

    Malware protection virus icon on my desktop was removed, but not sure if it still around cause im on safemode.

    RootRepeal
    I was able to install and run the scan, but about 10 seconds into the scan my comp will get the blue screen of death. Tried three times, same result.

    See 4 attachments
     
  7. wheelie46

    wheelie46 Private E-2

    oops, forgot to attach. Here you go. Thanks
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which files? Tell me.

    Please try and complete the below in normal mode if at all possible.

    Try running C:\MGTools\FixAttr.bat and tell me if that corrects anything.

    Java(TM) 6 Update 23 <--- uninstall old Java.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\ProgramData\32825080
    C:\ProgramData\~32825080
    C:\ProgramData\~32825080r
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    I had asked you to run TDSSKiller. ;) Did you run it? If not please do so.

    Reboot
    your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  9. wheelie46

    wheelie46 Private E-2

    Oh yeah forgot to mention tdsskiller. I cant run it, i renamed it tttt1234.com and still won't run.

    The 2 hidden files are:
    desktop.ini
    ZillaTube

    Im gonna reboot and try running C:\MGTools\FixAttr.bat now.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm... try this version and tell me what happens. (Just in case it's an updated version to the copy you have)

    TDSSkiller - How to run
    Ahhh desktop.ini is meant to be be hidden anyway, not sure about the other... this is least of our concerns as I suspect there's a chance you could have an MBR infection.

    OK, and then follow my other instructions including TDSSKiller.
     
  11. wheelie46

    wheelie46 Private E-2

    r u asking me to uninstall java? I tried to do so in READ & RUN ME FIRST clean up procedures but could not. I don't remember what the error message was and my comp is scanning now so I cant check.

    BTW I am in normal mode and I can hear invisible ad.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh... then it is time to repair your MBR.

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    Now reboot and try and run TDSSKiller now.
     
  13. wheelie46

    wheelie46 Private E-2

    What does this do BTW? I finished running it and not sure what changed.
     
  14. wheelie46

    wheelie46 Private E-2

    I don't have the vista installation CD:(
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It was to try and correct any remaining hidden files, but I think we ought to just focus on the rest of the instructions for now and deal with that after.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem! Not got your Vista boot CD? Try the below :)

    Vista and Win7 Recovery disc
     
  17. wheelie46

    wheelie46 Private E-2

    but if I restart and go to the boot menu, there is an option that says Repair Your Computer, can I do it this way?
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to do it exactly the way it states in my instructions.
     
  19. wheelie46

    wheelie46 Private E-2

    Im having trouble following those steps.
    I burned the vista recovery on a cd-r, then put the disc in my computer, then I restarted but i was never prompted.

    Then I went to the boot menu then set CD drive as first priority. Still nothing.

    Is it because I am using vista business? or is there anything I forget to do?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not download TDSSKiller.exe to your Desktop. You downloaded TDSSKiller.zip . Please see the instructions again and download the EXE file and see if you can run it.
     
  21. wheelie46

    wheelie46 Private E-2

    nah, I downloaded the zip file first then i realized i made a mistake and downloaded the exe file. I tried to run it and nothing happens, so I changed the name to a .com file as suggested and still nothing.
     
  22. wheelie46

    wheelie46 Private E-2

    yep, i tried again just now and nothing's running.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you try again please?
     
  24. wheelie46

    wheelie46 Private E-2

    Sure, I will try now. I remember I did something a few days ago in READ & RUN ME First and i disabled cd driver or something like that, do i need to reenable it first?
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, shouldn't be any need. Can try if you like to see if it helps get done what we need to get done.
     
  26. wheelie46

    wheelie46 Private E-2

    hmm... no good. I actually got the vista recovery to work and followed the steps but tdsskiller still not running.

    Just want to clarify those last 2 steps.

    I typed in Bootrec.exe then I hit enter
    then i typed in Bootrec.exe/fixmbr
    and it was really quick like as soon as I hit enter it says operation complete... on the following line.
    is this correct?
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes that should be correct. I know the redirects have ceased but I am not happy about TDSSKiller failure to run. Let me have a word with the others and seek further advices on this? Hang in there. :)
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay then move the TDSSkiller.exe file ( or redownload it ) to your root folder so that you have C:\TDSSkiller.exe to make it much easier to run.

    Then reboot your PC with your DVD and then get into the command prompt window. The enter the below and hit enter ( it is case insensitive ):

    C:\tdsskiller.exe

    Hopefully it runs okay. Then reboot normally and see if things are working better of not. Attach the log from TDSSkiller if it made one in your root folder.
     
  29. wheelie46

    wheelie46 Private E-2

    wait a minute, when I open up the command prompt it's in boot drive (X: )
    I typed in C: then hit enter
    then type tdsskiller.exe

    is this the correct procedure? I scanned it and it finished rather quickly and did not find any infection.

    EDIT:
    NVM this was a stupid question I'll attach the log in a minute
     
    Last edited: Jun 9, 2011
  30. wheelie46

    wheelie46 Private E-2

    Where do I find the log?

    BTW when I reboot normally I get the blue screen. Twice. I am in safe mode now.
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Should be on the root folder of your windows boot drive ... C:\
     
  32. wheelie46

    wheelie46 Private E-2

    I dont see one:confused
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh well, if you say it found nothing, and your redirections have ceased, we are ready to wrap up, would you concur? :)
     
  34. wheelie46

    wheelie46 Private E-2

    hmm... there's nothing else i can do? do u have any recommendation as to what i should do now?:(
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    About what? I am confused. Redirects stopped, hidden files no longer hidden and TDSSKiller was run ... Tell me what issues remain? :)
     
  36. wheelie46

    wheelie46 Private E-2

    My bad, I guess I am confusing you. I am actually very confuse myself because it has so many problems.

    I don't remember when, but that malware protection virus, shield icon and a bunch of pop ups warning me about malware, came back when I restart in normal mode.

    When in normal mode, my comp is very unstable and keep getting the blue screen of death.

    I just checked, Google redirect is not fixed.( I google something then click on one of the links, it keeps bring me to another random website)

    My startup menu is still empty.

    Im freaking out, i think my computer is dying man.

    but thanks for being so patient and spend so much time working with me really appreciate it.
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh so basically I have made no progress then... :(

    Let's start all over. You had better run the following in NORMAL mode if possible.

    • Malware Bytes
    • SUPERantispyware
    • Combofix
    • MGTools
      TDSSKiller


    Attach logs.
     
  38. wheelie46

    wheelie46 Private E-2

    I really need to use my laptop for school. I decided to do a system restore (restore system files and settings). It's not a complete pc restore. The restore point is from April which was a month before I got those viruses.

    Now it seems like my laptop is running great. Is there any problem doing this? Would the virus still be on my harddrive? Should I be running all those scans you listed just in case?
     
  39. wheelie46

    wheelie46 Private E-2

    ok google redirect problem is still here. Firefox only. IE doesn't have this problem
    Ill attach logs in a bit
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please run Combofix again followed my TDSSKiller then MGTools. Attach the logs from them. :)
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    We are going to be uninstalling your current copy of FireFox, deleting folders from it and then installing a new copy. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.

    After reboot, delete the below folders:
    C:\Program Files\Mozilla Firefox
    C:\users\UUU\AppData\Roaming\Mozilla\Firefox

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Are you still having redirection problems with Firefox??


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    Also attach the new ComboFix and TDSSKiller logs that Kestrel13! asked you to attach in message # 40.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds