Virus/trojan problem

[Closed]
Report
Posts
4
Registration date
Sunday December 4, 2011
Status
Member
Last seen
December 6, 2011
-
 Anonymous User -
Hello,

I noticed that this forum seems to have very willing and helpful users so I thought I'd ask.

Sorry for my previous thread if I sounded selfish/greedy, definitely wasn't my intention :).

Someone had a similar problem and it seems the solution given by Ambucias was wonderful and worked for me to so thankyou very much!

The previous thread: https://ccm.net/forum/affich-613761-a-trojan-virus-wiped-my-computer-out

The problem for me is you know when you typically press the start icon you can see "My Computer", "My documents", "Control panel" etc. well I have absolutely nothing there :S. Is it possible to get it back? I tried searching for control panel and stuff but it is not found :(.

I would be very gratful if anyone would be able to help me out.

Thankyou in advance for your time! I will be super grateful regardless if its possible because my main problem is already solved :).

5 replies


IMPORTANT:

Go to run and type

%temp% and click ok

If you find a folder called smtmp ,copy it to a safe location.

If you do not find it,check here

C:/windows/temp

If you still do not find it,leave it




Please boot into safemode with networking

Download this

https://download.bleepingcomputer.com/sUBs/dds.scr

Save it on desktop,run it ,a command prompt window will pop up ,

after that you will get two logs

dds.txt
attach.txt

Please upload the dds.txt file to

https://authentification.site

and paste the link here


Download

https://support.kaspersky.com/downloads/utils/tdsskiller.exe

Cure the infections

Go to C drive,there should be a TDSSkiller log file,open it and post the contents here

Let me know after this
Posts
4
Registration date
Sunday December 4, 2011
Status
Member
Last seen
December 6, 2011

My mistake I haven't been home much last few days, sorry for my late'ness.

Also thanks for the detailed response! and heres the files:

Archive copy of both the files: http://speedy.sh/NesjD/DDS.Attach-Files.rar

Also, I could not find the smtmp folder.

Here is the TDSSkiller log files: http://speedy.sh/9QxeW/TDSSKiller-files.rar

There were 3 files there. Two of them looked very similar and different, so I uploaded all 3 and archived.

Once again, thanks in advance !
Posts
4
Registration date
Sunday December 4, 2011
Status
Member
Last seen
December 6, 2011

"There were 3 files there. Two of them looked very similar and different, so I uploaded all 3 and archived. " I meant and one different*

Step 1:

Download

https://ccm.net/download/download-105-malwarebytes

Install and launch it

Select '' perform a full scan option,and scan

Remove infections,make sure you get a clean LOG


Step 2:

Go to start and type


cmd


Right click on the command prompt and select run as administrator
Run this command now

attrib -h c:\*.* /s /d

Unhide your files.

Step 3:

Try this only if you are missing startmenu,desktop icons


Go to these paths

c:\program data/microsoft/windows/start menu

C:\Users\user_name\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch

C:\Users\Public\Desktop


Right click on the respective folders-for example

startmenu,quicklaunch,desktop


Right click on these folders-Click on restore previous versions tab

Restore it to a date before you got infected

Let me know after you get back your icons
Anonymous User
Right click on these folders-properties-Click on restore previous versions tab
Posts
4
Registration date
Sunday December 4, 2011
Status
Member
Last seen
December 6, 2011

Thanks so much! The first part worked perfectly my files are all back.

only the second part on restoring the start menu didn't work.


c:\program data/microsoft/windows/start menu - I found this but sadly my previous versions are all when I still had the virus.

C:\Users\user_name\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch

C:\Users\Public\Desktop


^ Those two I cannot find. Well I can't find the users folder at all :S.

sakibd

I guess that you followed the steps.You got your MBAM scan clean right?

//c:\program data/microsoft/windows/start menu - I found this but sadly my previous versions are all when I still had the virus. //

that doesnt matter,if your startmenu looks empty,then go ahead and restore to a previous version

Make sure to remove SYSTEM FIX or SYSTEM restore OR DATA recovery rogue icon or folder after you restore them


//Those two I cannot find. Well I can't find the users folder at all :S.//


https://download.bleepingcomputer.com/grinler/unhide.exe


Just launch it and wait for it to complete unhiding files.Make sure you get back your users folder and retry them


Let me know after that