System crashing/redirects/missing files

Discussion in 'Malware Help (A Specialist Will Reply)' started by aura5195, Sep 4, 2012.

  1. aura5195

    aura5195 Private E-2

    Hey there,

    Windows 7/64.

    Couple days ago, noticed my system lagging and then it would crash for no reason. Now missing desktop icons and system files with internet explorer redirects (annoying!!). Did the Malware cleaning steps already (files attached). Thanks for any help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. aura5195

    aura5195 Private E-2

    I've tried to run TDSS and the program will not open. The instructions provided advise that some rootkits will prevent the program from opening and that if this is the case, to skip and go on to the rest of the steps (which I did), but I guess I missed where it says what to do with the program after your finished....

    Thanks!

    : )
     
  4. aura5195

    aura5195 Private E-2

    And just for clarification, I double click on the icon, my little hourglass thingy pops up and then disappears and nothing happens. No windows, no error messages...just nothing.

    Thanks again for any help!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I apologise for not getting back to you sooner. I have had a hectic couple days.

    Can you attempt to run TDSSKiller in safe mode please.
     
  6. aura5195

    aura5195 Private E-2

    No worries! Honestly, I'm just grateful for the help.

    So.

    I tried to run TDSS in safe mode and the only difference is that a window popped up asking me if I wanted to run the program. (I clicked yes and see previous post for the results)

    Any other suggestions?

    :)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, can you rename TDSSKiller.exe to 6fd43s.com and try again?
     
  8. aura5195

    aura5195 Private E-2

    File has been so renamed and same result. Tried it in safe mode with the new name also.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these files -
    • C:\ProgramData\-yicBEI8Bwhkgai
    • C:\ProgramData\-yicBEI8Bwhkgair
    • C:\ProgramData\yicBEI8Bwhkgai

    Tell me what's inside thisfolder?

    C:\ProgramData\OEM_E471269A730D

    What options does HitManPro give you with this that it is finding?

     
  10. aura5195

    aura5195 Private E-2

    Hey again,

    Files deleted.

    This is what is in that OEM folder:

    Netflix256n.ico
    StartURL.exe
    Version.txt

    As for HitmanPro the option for the Master Boot Record is replace, ignore, show information, or report that the file is safe. The options for the Volume Boot Record is only to replace or ignore.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you let Hitmanpro replace for you and then re run and show me the new log please?
     
  12. aura5195

    aura5195 Private E-2

    Did the replace option for the Master Boot record (and ignore for the other one), rebooted and rescanned and HitmanPro is saying NO THREATS FOUND now.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's good. :) Any issues remain?
     
  14. aura5195

    aura5195 Private E-2

    Well I just browsed all over the place and no redirects. I'll start using the computer again this weekend and keep my fingers crossed. Thank you!

    :)
     
  15. aura5195

    aura5195 Private E-2

    Just for giggles, I ran RogueKiller and it's still popping up with some Reg entries. Anything I should still be worried about?
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, not at all. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. aura5195

    aura5195 Private E-2

    Ack!!

    I had a bunch of desktop icons that had turned transparent. I cleared out the system restore points and rebooted and all the friggin icons on my desktop are now gone. I'm assuming they are gone forever now...?

    :cry
     
  18. aura5195

    aura5195 Private E-2

    ..my bookmarks are gone, my Picasa has been totally cleaned out...it's almost like I've got a new computer here. This is getting really depressing...could this all be from the stupid malware?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    First of all, what icons were they? Have you tried right clicking on your desktop and choosing Show desktop icons?

    Bookmarks from which browser? And what do you mean{icasais cleared out? You've lost photos?
     
  20. aura5195

    aura5195 Private E-2

    About half of all my desktop icons are gone. Everything ranging from photos I had downloaded to the desktop to programs (interestingly enough also including all of the programs I downloaded from this website excepting the renamed TDSS and the CCleaner). The show desktop icons is checked when I right click on the desktop.

    Picasa is a program that catalogs and sorts all picture files on your computer. It is now only showing one picture that I scanned in yesterday. Everything else is gone.

    All of my bookmarks from my Explorer are gone. I've also tried to create a system repair disc and to create a system image through windows and both operations will not complete. I keep getting told that required files are missing.

    All the missing icons/programs/photos were transparent since this whole mess started with the malware, so I don't think it had anything to do with the malware removal. Everything only disappeared after I cleared out the system restore.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please ask about this in the software forum. :) Nothing we did here in the malware removal forum would have been the cause of all this.
     
  22. aura5195

    aura5195 Private E-2

    I think it was the malware, which is now gone, so thank you!

    :)
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  24. aura5195

    aura5195 Private E-2

    OMFG! They're back!!!

    I would be taking you out to dinner (lunch/breakfast...don't know what country/time zone you're in) if I could!

    Even if everything isn't back, the pictures are and that was my main concern.

    You absofu**inglutely rock!

    Thank you!

    :):):)
     
  25. aura5195

    aura5195 Private E-2

    Whoops. Got so excited I forgot to attach the file.

    If you still need it for whatever.

    Thanks again!!
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What else is missing? :)
     
  27. aura5195

    aura5195 Private E-2

    I haven't found them all, I'm sure, but wierd little things. My soundcard is having issues (hardware can't detect it and the driver is missing..). Some of my Explorer bookmarks are missing their icons or are ONLY icons. Nothing that can't be easily fixed so far. :)
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK! Sounds good! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds