Ask a question Report

A trojan virus wiped my computer out. [Solved]

iwteachpk - Latest answer on Oct 27, 2011 11:46PM
Hello,
A trojan virus wiped my computer out. I tried to do a system restore with no luck. I keep getting error messages that say--
Failed to save all components for the file\System 32---This error may be caused by a PC hardware problem.
It will pop up about 20 times every few minutes. I just reactivated Norton internet security but that is not helping with the remaining 12 issues my computer says I have.
I get a data recovery screen that pops up as well but I want to make sure it is legit before i type in my credit card info.
Any help would be appreciated.
Thanks!
Read more 
Answer
+8
moins plus
@fersuapin,

Here is how to get rid of this scam rogue virus designed to get to your credit card account and it is a good thing you did not fall for it.

Please follow the following procedure carefully and to the letter.

You have a rogue virus Trojan Horse which is self protective, thus it will prevent any antivirus from fonctionning.

You must kill the evil processes which the virus is presently running amd preventing you from running any antivirus. If you don't it will keep reproducing the files for ever.

To kill the processes:

1. Download to your desktop and run Rogue Kill:

http://download.bleepingcomputer.com/grinler/rkill.com

2. You should now see a window that shows all of your desktop icons, including the rkill.com program.

3. Double-click on the rkill.com in order to automatically attempt to stop any processes associated with the Rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step.

If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by the Horse when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate the processes . So, please try running Rkill until malware is no longer running.

As a matter of a fact, if you get messages, it is a sign that the virus is agonizing with excrutiating pain, so you can just grin while it is suffering!:)))

Please, DO NOT REBOOT your computer or the processes will come back to haunt you!

Download to your desktop Malwarebyte.

http://en.kioskea.net/telecharger/telecharger-105-malwarebytes-anti-malware

Once on your desktop, we must still outwit the virus.

Right click on the MBAM icon and click on rename. Rename it kioskea.exe.

Install Malwarebyte and launch it. From the second tab, update it.

Pretty please, request a FULL system scan which should take more than hour. Once the scan is finish, delete all of item that were found.

It is very important that you let Malwarebyte run for as long as it takes, in some cases the creators of Malwarebyte suggest that you go do something like watch a rerun of "Gone with the Wind" or read Tolstoy's "War and Peace".

Once your computer is clean and working normally just to be on the safe side
*Turn off system restore and wait 30 seconds,
*Turn it back on and create a new restore point.

This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.
It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.

(Malwarebyte may reboot your computer, don't be alarmed. Should it happened, relaunch Malwarebyte to complete the FULL scan)

Once all this is completed, I always suggest to delete Malwarebyte as some people have reported that it may interfere with other antivirus applications.

Please let us know about the results or I may throw a curse on your system which will cause to bark all the time.:)))

Best regards
Anonymous User - Sep 23, 2011 09:03AM
I will also suggest to run tdsskiller after these steps

http://support.kaspersky.com/downloads/utils/tdsskiller.zip

Most of the times i could find rootkits on recovery rogue affected PC.
Reply
Anonymous User - Sep 23, 2011 09:06AM
@fersuapin
If you clean the infections, we can help you out on recovering your files.What is your OS?
Let us know
Reply
Add comment
Answer
+3
moins plus
Hi Everyone, so i got this exact same problem but i have no idea what to do, what do you guys recommend me? I do not want to type my credit card info, but it actually made me believe i had a hardware problem, I just cant find out how it got infected... so please, how do I find my files? all the files in the C drive are there, but my documents etc appear blank...
Add comment
Answer
+0
moins plus
To help you, I must make a diagnostic and to do so, I require a log.

Open this link and download ZHPDiag :

http://telechargement.zebulon.fr/telecharger-zhpdiag.html


Register the file on your Desktop.

Double click on ZHPDiag.exe and follow the instructions.

the tool created two icons ZHPDiag and ZHPFix (we will use ZHPFix at the next step).

Double click on the short cut ZHPDiag on your Destktop.

Click on the Magnifying glass and run the analysys.

Wait for the tool to finished (maybe a long time)

Close ZHPDiag.


To transmit the report, click on this link :

http://www.speedyshare.com/

Click on Parcourir and search the directory where you installed ZHPDiag (usually C:\Program Files\ZHPDiag).

Select the file ZHPDiag.txt.

Click on "upload »

Copy the url and post it here
Add comment
Answer
+0
moins plus
IMPORTANT:

Dont type in your credit card info.Data recovery is a Rogue software

Its easy to recover your files.Your files have been hidden.

Go to run and type

%temp%

Now if you find a folder called smtmp,just copy the folder to somewhere other than temp folder

Now upload the log as per amubcias instructions
Pachu- Sep 21, 2011 04:58PM
A client's computer came in with the exact same problem, and even though this might be a solution, the problem lays within the fact that the Hard Drive is BLANK, meaning that nothing shows up.
If you type something into the search box of the start menu, nothing shows up either, so running the Run tool is also not possible.
I believe that is what makes this Rogue Data Recovery Tool so convincing; the fact that it actually makes you believe everything is gone.
I did run Super AntiSpyware on safe mode and the files are all there (It took a long while to do the sacn), but they're just not visible.
Reply
kieferschild 1559Posts Sunday October 5, 2008Registration date ContributorStatus April 24, 2015Last seen - Sep 21, 2011 06:13PM
I assume the infection set all your files to hidden?
Reply
Anonymous User - Sep 22, 2011 12:16AM
@pachu

TDSSkiller will find a rootkit(tdl3 or tdl4) ,malwarebytes will remove the trojan infections.
Super antispyware is not needed for this recovery rogue.

We can unhide the files using attribute command or unhide.exe software.

Desktop,startmenu and quick launch icons can be recovered from smtmp folder created by virus itself.Its location is in temp folder .If we lose the smtmp folder we can recover it using recuva
Reply
Add comment
Answer
+0
moins plus
I got the same problem.
I run rogue kill, malwarebyte and the kaspersky tool and remove the virus.
However, my desktop has not recovered yet and its black. What should i do to recover it? I tried to rename the explorer.exe but i was not allowed. Please help me guys
Add comment
Answer
+0
moins plus
@loukas78


For xp

Go to run and type

cmd and press ok

Now copy and run this command

Echo y | reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoDesktop


Now go to task manager-click on explorer.exe and end the process and relaunch it

Go to file-new task and type

explorer and click ok

This should bring your desktop back


For vista and 7 open command prompt as administrator and run the command
Add comment
Answer
+0
moins plus
Sorry but it seems i can not follow your instructions.

I have Windows Vista installed in my PC.

I tried to open command prompt as administrator.
A black window opened up (like DOS environment).
C\Windows\system 32 was written.
I tried to copy paste the command.

I coudn't.

So i typed it and then i got an answer: The system was unable to find the specified registry key or value.

What should i do? I think your instructions are right but i can not follow them.
Add comment
Answer
+0
moins plus
No probs lets try this

open the registry(go to run and type regedit and click ok)

Navigate to the following key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

Remove the following key

NoDesktop

or

If you find this key

No view context menu >>> set it to 0


Reboot the system.

If you do not find these keys ,Check here

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer


Now if you can right click on the desktop

go to VIEW >> select '' show desktop icons ''
Add comment
Answer
+0
moins plus
I did not find the first two keys but i found this
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

What should i do? Should i delete it?
Add comment
Answer
+0
moins plus
No never delete it.

Navigate to this

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

Search for the keys on the right pane.If you are getting no desktop or no view context menu,say me what else do you find there?



IF YOU ARE ABLE TO RIGHT CLICK ON THE DESKTOP


Right click >>> view >>> show desktop icons


If you are unable to right click on the desktop

go to run and type

gpedit.msc

User Configuration -> Administrative Templates -> Windows Components -> Windows Explorer. In the right hand pane, find "Remove Windows Explorer's default context menu", open its properties by double clicking it. If it's enabled or not configured, disable it

Now reboot the PC


If that doesnt work


Just say me the entries you find on the right pane of this key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer


Also check for these folders

go run and type

%temp%

C:/windows/temp

Do you find something called smtmp folders?

Let me know
Add comment
Answer
+0
moins plus
The entries i find on the right pane are the default and the Bind directory to property set storage.
And i searched and found the smtmp folder. It contains folders 1, 2,4.

I am able to right click on the desktop and see 70% of the stuff i had there before. However, the background screen is still black and i "miss" some folders Moreover, when i click start i see only the computer folder (on the folders right side)
loukas78 19Posts Thursday October 20, 2011Registration date November 3, 2011Last seen - Oct 21, 2011 10:37AM
I meant binddirectlytopropertyset storage
Reply
Add comment
Answer
+0
moins plus
//I am able to right click on the desktop and see 70% of the stuff ///


You should have said this to me before..previous tricks are for NO DESKTOP and not for this

You are very lucky because you have the SMTMP folder,now do this


1. Copy the entire content of this folder:
C:\Users\user_name\AppData\Local\Temp\smtmp\1
and paste it to this folder:
c:\program data/microsoft/windows/start menu

2. Copy the entire content of this folder:
C:\Users\user_name\AppData\Local\Temp\smtmp\2
and paste it to this folder:
C:\Users\user_name\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch


3.Copy the entire content of this folder:
C:\Users\user_name\AppData\Local\Temp\smtmp\4
and paste it to this folder:
C:\Users\Public\Desktop



You have to manually PIN THE START MENU ICONS if you cant find it


Let me know how it works
Add comment
Answer
+0
moins plus
Steps 1 and 2 done.
Step 3 not cause the Public folder doesn't have a desktop folder...So i can't paste the stuff...
Desktop stil black...it contains all the folders that i can see through windows explorer HOWEVER i think (not sure) i am missing some files compaired to the pre-virus state...
Add comment
Answer
+0
moins plus
loukas78

You need to run unhide command ,You should have created a new thread which would not have brought a confusion in procedure,anyway


Go to start and type

cmd and right click on it and select '' run as administrator''

Now run this command

attrib -h c:\*.* /s /d

Wait for files to be unhidden.

I dont think you may need to copy the files from smtmp for desktop.It will automatically come up on running this command

Let me know
Add comment
Answer
+0
moins plus
Access denied - C:\WINDOWS\twain_32.dll
Access denied - C:\WINDOWS\twunk_16.exe
Access denied - C:\WINDOWS\twunk_32.exe
Access denied - C:\WINDOWS\winhelp.exe
Access denied - C:\WINDOWS\winhlp32.exe
Access denied - C:\WINDOWS\winsxs
Access denied - C:\WINDOWS\WMSysPr9.prx
Access denied - C:\WINDOWS\_default.pif
Not resetting system file - C:\$RECYCLE.BIN
Not resetting system file - C:\boot
Not resetting system file - C:\bootmgr
Not resetting system file - C:\hiberfil.sys
Not resetting system file - C:\IO.SYS
Not resetting system file - C:\MSDOS.SYS
Not resetting system file - C:\pagefile.sys
Not resetting system file - C:\System Volume Information

C:\Windows\system32>

These are SOME of the LAST lines that i got after running the command...
Anonymous User - Oct 21, 2011 05:38PM
ignore access denied warnings,how does your desktop look now
Reply
Add comment
Answer
+0
moins plus
I think the run finished. The above written lines were the last ones.

I have not seen any change. I am sure i am still missing some desktop items (not to mention the black screen...)

I rebooted but no change...
Anonymous User - Oct 21, 2011 05:46PM
.Copy the entire content of this folder:
C:\Users\user_name\AppData\Local\Temp\smtmp\4
and paste it to this folder:
C:\Users\Public\Desktop
Reply
Add comment
Answer
+0
moins plus
Just before you message me i deleted all temporary files. So the smtmp are not there! I emptied the recycle bin.
I think i just suicide!!!!
Is there a way to recover them???
Add comment
Answer
+0
moins plus
Try this

Download Recuva

http://en.kioskea.net/download/download-1437-recuva

Install it and when you get the recuva screen

Click Cancel on the wizard.
Click on Options... >> Actions Tab. Check "Restore folder structure."
Run a regular scan on the system drive.

When complete, use the filter box in the upper right to filter and type

*.lnk

Select all the files and recover them to a folder of your choosing.
Now you should get back the smtmp folder
guto- Oct 27, 2011 10:30PM
~the file file are OCULT -
on porpertis set no ocult
Reply
Add comment
Answer
+0
moins plus
I am not getting the smtmp folder...
I am getting other kinds of stuff. Please think that On the "recovered folders path" given by the software NO FILE SEEMS TO HAVE BEEN recovered from a place like C:\Users\user_name\AppData\Local\Temp\smtmp

I found several tmp documents coming from C:\Users\user_name\AppData\Local\Temp

BUT NONE FROM the smtmp folder.....
Anonymous User - Oct 22, 2011 09:56AM
Did you get lot of lnk files after running recuva? If yes then one of recovered folders should contain smtmp folder in it.

Click on Options... >> Actions Tab. Check "Restore folder structure."

Did you do this? and search

C:\Users\user_name\AppData\Local\Temp

Dont look for this specific path.Browse through each recovered folder


else type

smtmp in filter box and then give a search
Reply
guto- Oct 27, 2011 10:32PM
after remove de malware set the explorer porperty -> see my files and directories hidden
the files are hidden
Reply
Add comment
Answer
+0
moins plus
No smtmp folder exists.... :(
Add comment
1 2 Next
This document entitled « A trojan virus wiped my computer out. » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the license, as this note appears clearly.

Not a member yet?

sign-up, it takes less than a minute and it's free!

Members get more answers than anonymous users.

Being a member gives you detailed monitoring of your requests.

Being a member gives you additional options.