Empty files appearing on desktop and problems with check disk/defrag - infection?

Discussion in 'Malware Help (A Specialist Will Reply)' started by AddyDog, Oct 16, 2011.

  1. AddyDog

    AddyDog Private E-2

    My computer is a 2007 Dell laptop running 32 bit Windows XP.

    My trouble started a few days ago when it froze and I had to turn it off using the power button. This happens occasionally and check disk runs on start up. This time, check disk ran and then some strange empty files (0 kb) showed up on my desktop with names that used unrecognized characters (they show up as squares on my machine; I understand from someone in the software forum that they look like Chinese). Some examples of these files are uploaded here http://www.gdiproductions.net/MysteryFiles.rar. The forum's file upload returned an error when I tried to upload them.

    First I deleted the files and more appeared, no more than 3 at a time. Also, check disk began running every time I booted up my computer. The first time it ran check disk listed errors it corrected. Now it does not. But, when I use the command prompt to ask if C: is dirty (fsutil), it says it's dirty. So I don't know if check disk is stuck "on," if there's a virus or malware infectino, or if perhaps my hard drive is failing. I've backed up all my files just in case.

    Next I tried to run defrag, and I got the message "Disk Defrag has detected that Chkdsk is scheduled to run on Vol C. Please run Chkdsk /f." I have not been able to run defrag.

    Now, sometimes a message will pop up saying an exe file (one I'm running at the time like mediahub.exe--and I rolled back to WMP 10 in case that was the issue) is in error. The message is "The file or drive C: is corrupt or unreadable. Please run check disk." But, my computer continues to function normally. (This message came up when I ran one of the cleaning program, Combo Fix, I believe.)

    Thinking this was a software problem, I posted in the software forum, but it was suggested I have my system checked out for malware first. I went through the read and run process. During that, MG poped up a box that says "invalid PE image found" but I ran the scan anyway. It also returned an error that I reported, as the dialogue box asked me to. But, it created a log.

    So, I am still having check disk run every time I boot up, and the mystery 0 kb files are continuing to appear. I'm saving them all in a folder. Two will not let me move them to the folder or delete them. They say "Cannot move file. Cannot read from the source file or disk."

    I'd like to find out if my computer has an infection or not and if malware isn't the issue, it would be very helpful to know if my hard drive is failing, and if that is not the problem, then what to do to fix the check disk and 0 kb files.

    Thanks!
     

    Attached Files:

  2. AddyDog

    AddyDog Private E-2

    Here is the last attachment, the MG logs zip.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on those logs, it does not look like you are having malware problems; however let's check a little further with the below to scans

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller

    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. AddyDog

    AddyDog Private E-2

    Thanks. Here are the logs.
     
  5. AddyDog

    AddyDog Private E-2

    My mistake, here they are.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also clean. I suggest that you cleanup from the READ & RUN ME as per below and then return to your other thread to work on repairing Windows or your hard disk.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
     
  7. AddyDog

    AddyDog Private E-2

    Thanks! The uninstall of the cleaning programs went smoothly. I'll go back to the other thread and keep working on it.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. In your other thread, you should test to see if the problems happen if you only boot in safe mode. Also use MSconfig for debugging and selectively disable various non-microsoft startups and service to see if you can locate which program may be the cause.
     
  9. AddyDog

    AddyDog Private E-2

    Thanks again. I'll repost your suggestions in the other thread and get back to work on it. Cheers!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good luck.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds