I'm using a Dell Inspiron 580, Windows 7 and AVG. When I turned the computer on yesterday and clicked FAVORITES, it was blank. I then went to Windows Explorer, and discovered all the files I had in my Library folder (photos, letters, etc.) were also gone, as were most of the icons I had on my Desktop and Shortcuts that were on my Start menu. The virus didn't seem to get to the operating system, since I can go online and Internet Explorer is normal.
I immediately ran a full scan with AVG (free version) and it found absolutely no threats. How can this be?
I had been getting a lot of notifications from AVG lately that threats were blocked and requests to move them to Vault, remove all unhealed, etc. But I assumed AVG was doing its job.
I have the 2 SYSTEM RESTORE DVDs that I made just after I got this computer in 2010. Do I need to use them? Do they completely format my hard drive and re-install Windows 7? That might not be a bad idea since it seems to have started running slower recently. I'm sure some files have gotten corrupted in the last 2 years.
First and foremost, do NOT run any "temp file cleaners" (such as Windows Disk Cleanup, or CCleaner), as it's possible that the missing files have been moved to a "temp" area and hidden. If you run a temp file cleaner, you risk permanently deleting them.
One-on-one Malware Analysis/Removal is no longer done at the Dell Forums.
Please follow the directions at http://spywarehammer.com/simplemachinesforum/index.php?topic=12262.0 to register and post the requested logs at spywarehammer.com ; there are expert helpers there who can "walk you through" procedures to analyze your system, and clean-up the infection. All help provided there is FREE. If you decide to go for help there, please wait for a response, and do NOT attempt to run any other scans/removers on your own --- do exactly what they instruct you to do, no more, no less.
I will try to call this to the attention of Bugbatter, who volunteers here, and is an administrator at SpywareHammer. Please be patient.
EDIT: for what it's worth, I just tried going to spywarehammer's registration screen, and words were there for me in the CAPTCHA box. I guess you can try again... or else wait for Bugbatter to reply here.
Thanks, I just checked the spyhammer site out and I'm sure they can help.....IF I can register. I've tried 5 times. It lets me enter my chosen user name, email address, and chosen password. I agree to the conditions, check the box that says I'm over 13, and hit register. I get an alert which says "The letters you typed don't match the letters that were shown in the picture." I go back and there's a VISUAL VERIFICATION section on the registration form but no picture. I can't type in the letters in the picture if there's no picture showing.
I can't get help with this until I register, but I can't register if the verification picture isn't showing. I'm wondering if their site has been hacked, too! If you can get a message to them that there's a problem with their visual verification section I'd appreciate it.
We have been working on some updates to the site. Issues that you are having will be corrected soon. If you are on Facebook, you can always contact SpywareHammer here: www.facebook.com/SpywareHammer
For now, I will get you set up for posting over there, and do as much as I can here at Dell. SpywareHammer will need to see some additional information about what is happening in your machine.
Please download DDS and save it to your desktop from here or here or here. Disable any script blocker, and then double click dds.scr to run the tool.
Copy/paste both logs to your reply on this forum. Do not attach them. After you are able to register at SpywareHammer, you can include a link to this topic so they can see what we have done so far.
Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE.
Scroll down the page about halfway to "Automated Removal Instructions for System Repair using Malwarebytes' Anti-Malware" Follow the instructions precisely from #1 through #22. Let us know if that helps. You won't need to register there just to use the removal guide, but I would be curious if you have registration problems there as well.
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Works
MSVCRT
Multimedia Card Reader
OpenOffice.org 3.2
Ralink RT2860 Wireless LAN Card
Realtek High Definition Audio Driver
Roxio Burn
Security Update for CAPICOM (KB931906)
ShopAtHome.com Toolbar
SiteRanker
Skype Toolbars
Skype™ 4.2
Visual Studio 2008 x64 Redistributables
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
.
==== Event Viewer Messages From Past Week ========
.
4/19/2012 9:46:41 AM, Error: Service Control Manager [7023] - The Peer Name Resolution Protocol service terminated with the following error: Access is denied.
4/19/2012 9:46:41 AM, Error: Service Control Manager [7001] - The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: Access is denied.
4/19/2012 9:46:41 AM, Error: Microsoft-Windows-PNRPSvc [102] - The Peer Name Resolution Protocol cloud did not start because the creation of the default identity failed with error code: 0x80070005.
4/19/2012 9:46:40 AM, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
4/19/2012 9:46:24 AM, Error: Microsoft-Windows-WMPNSS-Service [14346] - A new media server was not initialized because RegisterRunningDevice() encountered error '0x80070005'. Restart your computer, and then restart the WMPNetworkSvc service.
4/19/2012 9:46:12 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
4/18/2012 10:12:41 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
4/18/2012 10:12:27 AM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
4/17/2012 9:47:42 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800035c13fa, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041712-37221-01.
4/17/2012 7:08:21 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff8000325d703, 0x0000000000000000, 0x000000007ef60000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041712-20514-01.
4/16/2012 2:56:18 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800035793fa, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041612-34476-01.
4/15/2012 8:21:58 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80003257703, 0x0000000000000000, 0x000007fffffa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041512-42978-01.
4/15/2012 8:07:44 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800035b13fa, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041512-35006-01.
4/13/2012 7:06:05 PM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
4/12/2012 11:43:08 AM, Error: Schannel [36888] - The following fatal alert was generated: 40. The internal error state is 107.
4/12/2012 11:43:08 AM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
4/12/2012 11:03:27 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800035bb3fa, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041212-23743-01.
Thanks. I went to the link but I'm again having problems. I got up to step 5, clicked the iExplore.exe download link but it never asked me if I wanted to save it to Desktop. I just selected Save and it appears to have saved it to Notepad. The following appears:
This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish.
Rkill was run on 04/19/2012 at 11:54:18. Operating System: Windows 7 Home Premium
Processes terminated by Rkill or while it was running:
I'm supposed to now double-click on the iExplore.exe icon but the icon is not appearing on my desktop. Everything is expanded out in the Safe Mode with Networking mode so maybe the icon is on the hidden edge of my desktop and I'm not seeing it. I can't figure out how to bring it into view.
ky331
5 Journeyman
•
15627 Posts
•
45058 Points
927
0
Posted April 18th, 2012 08:00
First and foremost, do NOT run any "temp file cleaners" (such as Windows Disk Cleanup, or CCleaner), as it's possible that the missing files have been moved to a "temp" area and hidden. If you run a temp file cleaner, you risk permanently deleting them.
One-on-one Malware Analysis/Removal is no longer done at the Dell Forums.
Please follow the directions at http://spywarehammer.com/simplemachinesforum/index.php?topic=12262.0 to register and post the requested logs at spywarehammer.com ; there are expert helpers there who can "walk you through" procedures to analyze your system, and clean-up the infection. All help provided there is FREE. If you decide to go for help there, please wait for a response, and do NOT attempt to run any other scans/removers on your own --- do exactly what they instruct you to do, no more, no less.
Good luck!