I've been battling this virus (what I now know to be System Fix) for a couple days now. When I first received the virus my spybot was run and deleted my temp folders. I was on this site following a guide from a guy named "Gringo" to see what steps I should take to restore my computer. After following that thread (http://www.bleepingcomputer.com/forums/topic443982.html) I was able to remove the virus and restore my system to somewhat normal functionality. I did not run DDS, however.
Things I've done:
I followed along with what was done in that thread almost to the "T" (sans DDS as I didn't notice it before). I Ran Defogger, ComboFix, Tdsskiller, aswMBR, I then had to do a CFScript to Combofix because it wasn't running properly. I've tried to run Unhide.exe but since my AppData/Smtmp folder are apparently missing I haven't been about to complete this successfully. I've uninstalled my old Java suite and reinstalled new ones, as with Adobe reader.
I also ran Photorec to try and recover files that were deleted by this monster and I've saved what I've found to a folder on my desktop. These files include everything from registry entries to jpegs. I have not messed with any of the found files.
Here are the issues I'm still having: My Appdata folder and smtmp folder are not where they should be and it's causing all kinds of headaches. My computer *can sort-of* find the smtmp folder but when I type "smtmp" into a search bar in my C:\ drive I see it located here > Temp (C:\Qoobox\Quarantine\C\Users\Richelle\AppData\Local). No idea what that means.
Also, all of my shortcuts from my start menu (the ones that appear on the LEFT in the white area) are missing. "All Programs" is still there, but everything above it is missing. As for the contents of "All Programs" most of the items are in there now but a TON of the folders have (empty) beneath them. I do not know if these files were removed when spybot cleared the temp files or what. I have made sure to show hidden files, too, and still can't see anything in these folders. I've checked my installs and a great many of my programs still work if I dig far enough for the .exe's, however, a lot of program associations are all messed up now. Another weird thing is that all the icons I hover over now have this little checkbox that appears next to them in the upper-left corner of the icon. No idea how that happened.
Whatever this virus did it also took out my Restore Points in System Restore so going back to a previous date (as far as I know) is impossible. I even had a Norton Ghost backup/partition that is now missing. (I think this was done when I got my new HDD).
Any assistance would be -greatly- appreciated!
Edited by Vallius, 30 March 2012 - 05:58 PM.