"Disk Doctor"

Discussion in 'Malware Help (A Specialist Will Reply)' started by Karthalin, Dec 3, 2010.

  1. Karthalin

    Karthalin Private E-2

    I went to install a program called "Auto Hot Key" and as I was installing Bitdefender (my default virus protection) kept asking me if I wanted Java to connect to the internet. I kept hitting yes and eventually this nasty little bigger called "Disk Doctor" popped up. It was scanning my hard drive telling me I have tons of viruses and infections. Now I can not access the task manager (Says its an administrater option only, I am logged on as the administrator) and Disk Doctor will not stop running. Also I am getting fake windows security alerts telling me "HDD is not found" and "Critical error found - Click here now" and "Damaged hard drive clusters detected".

    I am running Windows 7 x64bit and I performed the read me actions. Attached below are the logs generated. I did not run Combofix or Rootrepeal due to the x64bit version.

    Also, while running SuperAntiSpyware my computer shutdown and I had to restart it. When I did that my desktop background and all my icons have disappeared. Now I only have a black screen. If I go to my "desktop" directory all the program shortcuts are there, I just can not see them on my literal desktop. Thank you for any and all help.

    Also, my Bitdefender 2010 program finds nothing wrong. So glad I payed for it..
     

    Attached Files:

  2. Karthalin

    Karthalin Private E-2

    I ran SuperAntiSpyware again and posted the logs here.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Complete the below in NORMAL mode not safe mode.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "saElAiSHfe.exe"=-
    
    :files
    C:\Users\Casey Jennings\Local Settings\TEMP\11871520.exe
    C:\Users\Casey Jennings\Local Settings\TEMP\11871520
    C:\Users\Casey Jennings\Local Settings\TEMP\11871520.bmp
    C:\Users\Casey Jennings\Local Settings\TEMP\AgYYEJqpXv.dll
    C:\Users\Casey Jennings\Local Settings\TEMP\dfrg
    C:\Users\Casey Jennings\Local Settings\TEMP\dfrgr
    C:\Users\Casey Jennings\Local Settings\TEMP\Low
    C:\Users\Casey Jennings\Local Settings\TEMP\saElAiSHfe.exe
    C:\Users\Casey Jennings\Local Settings\TEMP\tmp24D2.tmp.exe
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running now.
     
  5. Karthalin

    Karthalin Private E-2

    I performed all actions you layed out in normal mode. OTM rebooted the comuter and the "Disk Doctor" is gone. I am not getting any weird hard disk errors either.

    I ran MGtools and I included the .zip file as well as the OTM results file in this response. This time around MGTools ran much, much slower. I have not noticed if any other programs are running slower.

    My desktop background is still blank (just a black screen) and I still can not see any of my desktop icons. They are still available in the desktop folder though as long as I access it with windows explorer. Thank you for your help so far! Hopefully this background thing is an easy fix now that disk doctor is (hopefully) out of the picture.
     

    Attached Files:

  6. Karthalin

    Karthalin Private E-2

    I am able to change my desktop background, but I can not see or place new icons on my desktop. I tested some programs and everything seems to be running smoothly.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seems we are not entirely out of the woods yet. Let's continue.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.


    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "11871520"=-
    
    :files
    C:\Users\CASEYJ~1\AppData\Local\Temp\11871520.exe
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. Karthalin

    Karthalin Private E-2

    I performed the steps you oultined below and ran into a problem, which you can readily see in the logs.

    Both HiJackThis and OTM did not find the file "11871520.exe"

    I attached the first HiJackThis log from when I ran Analyser from MGTools (the first step).

    The second attachment is the OTM log and the third attachment is the MGTools zipped file.

    Everything seems to be running fin on my computer except the desktop is still not showing my file shortcuts
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is the desktop back to normal after using this below reg patch?

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  10. Karthalin

    Karthalin Private E-2

    I performed the patch using notepad and saving the file as "all files" like you instructed. The desktop still will not show any of the shortcuts placed either directly onto the desktop screen or any files placed inside the desktop folder using windows explorer.

    I did recieve a registry edit success window after I ran the patch.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete file/folder
    Press Start->Run, copy/paste the following command into the box and press OK:
    A blank command window will open on your desktop, then close in a minute or two. This is normal.
    A file called look.txt should appear on your Desktop. Please post the contents of this file.
    Do they appear in safe mode?

    Run this and attach the results.

    Using ESET's Online Scanner
     
  12. Karthalin

    Karthalin Private E-2

    Still no desktop icons. I copied and pasted the line into my run box. A command window opened and closed quickly. No text file appeared on my desktop and I did a search for "look.txt" and came up empty on my C:\

    No icons apear on my desktop in safe mdoe either.

    Attached is the ESET Scan results. It found 4 files and removed then. Three of the files were in the OTM quarentine folder and 1 was an MGTools application.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your Windows 7 CD? I am thinking that your explorer.exe file may be corrupted and might need replacing.
     
  14. Karthalin

    Karthalin Private E-2

    Yes I do. I could use some help figuring out how to replace the explorer.exe. file if thats what you would like me to do.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    EDITED!!! Follow the below

    First open an elevated command prompt like so:
    Click Start and type cmd in Start Search.
    When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.

    Highlight and Copy the contents of the code box below, then right click inside the command window and select Paste.
    press <Enter>
    type exit to close the command window.

    Next.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      explorer.exe.*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt[/QUOTE]
     
    Last edited: Dec 7, 2010
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I edited my above post.
     
  17. Karthalin

    Karthalin Private E-2

    *deleted*
     
  18. Karthalin

    Karthalin Private E-2

    I ran the cmd window as administrator. It opened to the windows/system32 directory vice the users\me directory (that where it should have opened, correct?) I copied the file to the c:\

    I attached the system look notepad file to this post below.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to replace a file using the Windows 7 System Recovery Option.
    Please follow these instructions carefully then give me an update on the redirects.

    Restart your computer and begin tapping the F8 key to enable the Advanced Start menu > select Repair your computer
    At the System Recovery options screen select Command prompt .

    Type the following at the first prompt and hit Enter.
    Then type the following and hit Enter
    You should receive a message that "1 file" has been copied.

    Finally type exit > hit Enter > click Restart at the main screen, and restart the pc normally.

    Next...

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running now?
     
  20. Karthalin

    Karthalin Private E-2

    Still no desktop icons.

    I got to the windows repair and opeend a command prompt. I typed in the two lines you told me to. The second line did say "1 file copied".

    I restarted the computer and still no desktop icons.

    When I ran MGTools one thing different did happen. I got a "steelworx whoami program has stopped working" error which has never happened before (might be due to ESTScan taking away that MGTools program a step back). I clicked close the program which is what MGTools said to do when this error popped up.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try posting in the software forum about this then. It does not appear to be malware related.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. Karthalin

    Karthalin Private E-2

    I performed all those actions. The computer is running flawlessly and I have a good, brand new restore point. Thank you SO MUCH for your help.

    And now the really ridiculous part. I right-clicked on my dekstop and went to the VIEW option and turned on "View Icons". They are all there. Cant believe thats an actual option in Win7. All is right with my PC again. Thank you!
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hey you are most welcome! :)

    *Slaps head*!!! I feel awful too! I guess I was thinking too far out the box. I'm sorry that we went through uneccesary procedures to replace that file. But I am very glad you are rid of DiskDr ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds