BleepingComputer.com: Cannot see start menu files - unhide.exe didn't work

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Cannot see start menu files - unhide.exe didn't work

#1 User is offline   johnathonb 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-February 12

Posted 01 February 2012 - 02:11 PM

Hello,

I have an infected machine that has had Malwarebytes, SuperAntiSpyware and Microsoft Security Essentials ran on it and at the end of this process I ran the icons were still missing under the start menu and displayed as empty. I then ran unhide.exe but the icons were still missing.

I was hoping you could help me out a bit, just let me know what log you need me to run first.

Thanks,

John

#2 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,394
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 01 February 2012 - 02:20 PM

Can you post the resulting logs from Malwarebytes and Super Anti-Spyware?

Also did you run any registry or temp file cleaners?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#3 User is offline   johnathonb 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-February 12

Posted 01 February 2012 - 04:08 PM

Malwarebytes Log:

Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.27.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Sony Laptop :: SONYLAPTOP-VAIO [administrator]

Protection: Enabled

1/27/2012 4:36:24 PM
mbam-log-2012-01-27 (16-36-24).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 331739
Time elapsed: 2 hour(s), 26 minute(s), 42 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Users\Sony Laptop\AppData\Local\Temp\msimg32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Sony Laptop\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\36afad31-5a154bb2 (Trojan.Downloader.lb) -> Delete on reboot.

(end)


I ran SuperAntiSpyware portable so no log file was saved.

I'm not sure if we ran a temp file or registry cleaner like CCleaner on it yet, if we have I have a back up of the original machine I can pushed back to it to start the process over if needed.

#4 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,394
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 01 February 2012 - 04:11 PM

That would potentially reinfect you. Can you run SAS non-portable.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#5 User is offline   johnathonb 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-February 12

Posted 01 February 2012 - 05:20 PM

SAS No Portable Scan Log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/01/2012 at 04:17 PM

Application Version : 5.0.1142

Core Rules Database Version : 8190
Trace Rules Database Version: 6002

Scan type : Complete Scan
Total Scan Time : 00:30:56

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC Off - Administrator

Memory items scanned : 455
Memory threats detected : 0
Registry items scanned : 44364
Registry threats detected : 0
File items scanned : 56416
File threats detected : 0

#6 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,394
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 01 February 2012 - 06:01 PM

Can you navigate to c:\Program Files and see if all your applications are there also c:\Users\yourusername and find your start menu and see if its populated?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#7 User is offline   johnathonb 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-February 12

Posted 02 February 2012 - 10:36 AM

Posted Image

This is what is in the start menu.

All the files are still in the program files and program files(x86)

#8 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,394
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 02 February 2012 - 11:13 AM

Here is what mine looks like:

Posted Image

Have you reformatted?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#9 User is offline   johnathonb 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-February 12

Posted 02 February 2012 - 11:28 AM

No I haven't.

I am going to restore the backup because I believe someone ran CCleaner. I will just start the virus removal process over again. I will post in the next few hours to see if the files are back or not.

#10 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,394
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 02 February 2012 - 11:43 AM

if the applications are in c:\program files then I would reinstall the applications.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#11 User is offline   johnathonb 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-February 12

Posted 02 February 2012 - 01:36 PM

What I did was restore the backup I took before doing a virus removal and ran unhide.exe and all the applications returned to the start menu.

Thanks, site is a bunch of help, don't know where I'd be without the help you guys provide.

#12 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,394
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 02 February 2012 - 03:41 PM

So someone did run ccleaner or another temp file cleaner.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users