Smart HDD some files still hidden

karae

New Member
Thread author
Apr 20, 2012
6
Everything appears to be working, but the start menu. The icons are back on the desktop and they are working.

karae
 

Attachments

  • Extras.Txt
    38.2 KB · Views: 323
  • aswMBR.txt
    2.2 KB · Views: 129
  • OTL.Txt
    67 KB · Views: 159

malwarekiller

New Member
Mar 30, 2012
688
Hi,right there aswMBR has highlighted a TDL infection.

  • Download RogueKiller  and save it on your desktop.  
  •    Quit all programs  
  •    Start RogueKiller.exe.  
  •    Wait until Prescan has finished ...  
  •    Click on Scan
 
RGKRScan.png

   
  • Wait for the end of the scan.   
  •    The report has been created on the desktop.   
  •    Click on the Delete button.
 
RGKRDelete.png

   
  • The report has been created on the desktop.
 
   
  • Next click on the ShortcutsFix  
    RGKRDelete.png
     
  • The report has been created on the desktop.
 
  
Please post:  
All RKreport.txt text files located on your desktop.

NEXT

  • Download the latest version of TDSSKiller from here and save it to your Desktop.
http://support.kaspersky.com/viruses/utility
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
tdss_1.jpg

  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
tdss_2.jpg

  • Click the Start Scan button.
tdss_3.jpg

  • If a suspicious object is detected, the default action will be Skip, click on Continue.
tdss_4.jpg

  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
tdss_5.jpg


  • [*]Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.If TDSS File system is found it can be deleted.

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
 

karae

New Member
Thread author
Apr 20, 2012
6
Ran Roque Killer and TDSSkiller, TDSSkiller found a lot of threats, nearly all the objects it found it said they were suspicious. It did not offer cure for any of the threats. When I restarted my wallpaper was back and some of the start programs had partial items in them. Accessories had most of its items back but communication only had fax. The programs themselves are still empty. Another thing I am noticing is that desktop.ini is everywhere. Its in the start button, and when the computer starts up, a little window comes up about the desktop.ini.


Karae
 

Attachments

  • RKreport[1].txt
    1.9 KB · Views: 203
  • RKreport[2].txt
    2.1 KB · Views: 137
  • RKreport[3].txt
    1.2 KB · Views: 134
  • TDSSKiller.2.7.28.0_20.04.2012_12.40.15_log.txt
    237 KB · Views: 176

karae

New Member
Thread author
Apr 20, 2012
6
Sorry, I am so late in returning the logs I was away for a few days. I reran the aswmbr. I have attached the log.

Thanks for all your help.
karae
 

Attachments

  • aswMBR.txt
    2.2 KB · Views: 136

karae

New Member
Thread author
Apr 20, 2012
6
I reran aswmbr and fixed mbr, I then restarted the machine. The start menu is still showing empty for programs. I am attaching the aswmbr logs for after fixing mbr and after reboot of the pc.
 

Attachments

  • afterfix_aswMBR.txt
    2.1 KB · Views: 159
  • restart_aswMBR.txt
    2 KB · Views: 160

malwarekiller

New Member
Mar 30, 2012
688
Restore Accessories Program Files Menu

Please download this tool here.
http://www.winxptutor.com/download/accrestore.zip

You will need to unzip the tool first.

Once you've unzipped the tool, please double-click on it to run it.

Ensure that the following check boxes are checked (as seen in this image below):

restore-start-menu-accessories-folder.png


Once they are, click on the Restore button.

NEXT:

Restore Admin Tools Program Files Menu

Please download this tool here.
http://www.winxptutor.com/download/admintools.zip

You will need to unzip the tool first.

Once you've unzipped the tool, please double-click on it to run it.

Click on the Restore Administrative Tools Items button.

As seen in this image below:
RestoreAdministrativeTools.png
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top