Virus - most items hidden

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chiepler, May 24, 2011.

  1. chiepler

    chiepler Private First Class

    To begin with, my keyboard & touchpad on my laptop weren't functioning. I had to do a hard reset to get them to work again. After I finally got logged on, I noticed the desktop and C: drive items are hidden, as well as many of the start menu items. Virtually none of the normal Windows programs (DVD Maker, Windows Update, Media Player, etc.) show up in the start menu - only IE and IE-64bit. Under the All Programs menu, I can see the folders that are supposed to contain the programs to execute, but most of them say 'empty'. It's the same in safe mode. When I check the Add/Remove programs utility, all the programs show up & are available to uninstall. I can unhide a folder & subfolders by removing the checkmark, but not everything will show up again. The SAS & MBAM scans found a few items, but Combofix would not run. It gave an error message, "C:\ Folder is not accessible", again, even in safe mode. The quick launch area beside the start menu button just show blank file (paper) icons. Hopefully someone can help me with this one! Here's my logs...
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\ProgramData\39902968
    C:\ProgramData\~39902968
    C:\ProgramData\~39902968r

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands ( in bold black ) at the command prompt each followed by the enter key. Try each command!!!! The bold black are commands. The purple/brown is merely informational.

    cd \ <-- this changes to the root folder and the prompt should change to C:\>
    attrib -s -h -r c:/*.* /s /d <-- this will try to remove the hidden and system attributes on all files and folder. Note there are spaces before -h, before -s, before * and before each /

    Let me know if this helps.

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe


    Now run it. Did that help?

    Now please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :folderfind
      smtmp*
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  3. chiepler

    chiepler Private First Class

    Thanks for your prompt reply!
    I did the things you mentioned. Running the 'unhide' program helped, but not completely. I can see things via windows explorer now, but most of the items in the start menu still don't show up & the folders that contain the programs mostly say 'empty'. The quick launch bar still shows the blank paper icons. I can see more items on my desktop now as well. If I open a Word document, for example, Word will open. However, the folder in the start menu doesn't show the MS Office programs that are available.

    When I ran the commands in the command prompt, most if not all items said 'Access Denied'. It scrolled by so fast that I didn't see if any were successful.

    Here's the updated logs...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the MGTools folder and run the FixAttr.bat. Tell me if that helps.
     
  5. chiepler

    chiepler Private First Class

    Nope. Still not seeing the program shortcuts in the start menu.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you can create a new user account ( with Admin. privileges ) and tell me if that account works.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And for the affected account try this:

    Please download RogueKiller.exe and save it to your desktop.
    • Now quit all running programs.
    • Double click RogueKiller.exe to run it.
    • When prompted, type 1 and hit Enter.
    • A RKreport.txt should appear on your desktop.
    • Note: If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe .
    • Please post the contents of the RKreport.txt in your next Reply.
     
  8. chiepler

    chiepler Private First Class

    Creating a new admin account gave me a new set of quick launch icons in the task bar, but the start menu shortcuts at the top of the list & in the folders still won't show up. Here's the roguekiller log...
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  10. chiepler

    chiepler Private First Class

    I was able to remove the icons from the taskbar (unpin them) and then add them again. Doing this made the icons reappear and function correctly. Is there a way to do this to the start menu items without reinstalling the programs?
     
  11. chiepler

    chiepler Private First Class

    Sorry, I didn't notice the post you just made. It appears we both posted replies at about the same time! I'm running a sfc /scannow scan. When that completes, I'll run the scans you suggested. Thanks for keeping on this!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  13. chiepler

    chiepler Private First Class

    Here's the log for TDSS...

    I ran the ESET online scan, but (stupidly:-o) forgot to save a log file before removing the program. I have another computer on my network network that is experiencing almost the same thing, but that is an XP machine. I attached the ESET log file for that machine because it found similar items.

    The SAS online scan didn't find anything.

    One strange thing I noticed is that the desktop.ini file is showing up in various places in the start menu programs, the desktop, and default windows folders like the Libraries folders (Documents, Music, Videos, Pictures) - sometimes twice in the same location!:confused I even tried hiding the hidden files & folders, but they still show up.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you re run Malware Bytes?
     
  15. chiepler

    chiepler Private First Class

    yes - nothing was found.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you do a system restore to before this infection?
     
  17. chiepler

    chiepler Private First Class

    No. System restore was turned off. :cry I only have a couple recent restore points.

    I've been able to reinstall/repair the software from add/remove programs. Some items require the original disks which I'll have to find. I think I'll just go that route from this point. It's not that much work as I didn't have very many programs to begin with. Thanks for all your help!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let us know if you have any other issues that need addressing.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds