The first thing that happened is allot of errors popped up saying hard drive failure and unable to locate sector and then just about all my desktop icons and folder/ files were gone. So I did a boot time scan and got ntcreatefile log error 0cc0000022 access denied and
File mbr 0 is infected by mbr:sstt (rtk) and it won’t let me do anything to fix it.
Someone please help me fix and recover my files please please please.
I fixed the hard drive issue but I still have the nasty virus and my files are still missing please somebody help me
follow this guide and attach (not copy and paste) Malwarebytes / OTL / aswMBR logs
http://forum.avast.com/index.php?topic=53253.0
thank you so much, im doing all that now but i have one more question. will i be able to recover my files.
The removal expert will answer that when he arrive here later today
MBAM log
otl and extras log
i downloaded the aswmbr but my computer wont run it
Try it in safe mode.
Still won’t run it
Am I going to be able to fix this and recover my files and what do I do next if a fix is possible. I’m so frustrated >:(
Now you’ve to wait for one of the malware removers. Please be patient.
Sorry I’m just very frustrated
and 3 words you should remeber …Backup, Backup, Backup … and you will be less frustrated
[*] Download RogueKiller and save it on your desktop.
[*]Quit all programs
[*] Start RogueKiller.exe.
[*] Wait until Prescan has finished …
[*] Click on Scan
http://i1224.photobucket.com/albums/ee362/Essexboy3/RogueKiller/RGKRScan.png
[*]Wait for the end of the scan.
[*] The report has been created on the desktop.
[*] Click on the Delete button.
http://i1224.photobucket.com/albums/ee362/Essexboy3/RogueKiller/RGKRDelete.png
[*]The report has been created on the desktop.
[*]Next click on the ShortcutsFix
http://i1224.photobucket.com/albums/ee362/Essexboy3/RogueKiller/RGKRShortcutsFix.png
[*]The report has been created on the desktop.
Please post: All RKreport.txt text files located on your desktop.
THEN
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:OTL
O2 - BHO: (no name) - {2EECD738-5844-4a99-B4B6-146BF802613B} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
[2012/08/31 12:19:02 | 000,000,368 | -H-- | M] () -- C:\ProgramData\4XN15ODlyiABVn
[2012/08/31 12:14:37 | 000,000,160 | -H-- | M] () -- C:\ProgramData\-4XN15ODlyiABVnr
[2012/08/31 12:14:37 | 000,000,144 | -H-- | M] () -- C:\ProgramData\-4XN15ODlyiABVn
:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
FINALLY
Download AdwCleaner from here to your desktop
Run AdwCleaner and select Delete
https://dl.dropbox.com/u/73555776/AdwCleaner.GIF
Once done it will ask to reboot, allow this
On reboot a log will be produced please attach that
rogue killer reports
otl quickscan log
it wont let me download the adw cleaner my avast keeps poping up with malicious url blocked
Try this link for AdwCleaner… The programme is clean http://www.tomsguide.com/us/download/AdwCleaner,0301-48079.html
Could you confirm that you have your files/folders/menus back now
Download the latest version of TDSSKiller from here and save it to your Desktop.
[*]Doubleclick on TDSSKiller.exe to run the application
http://dl.dropbox.com/u/73555776/TDSSFront.JPG
[*]Then click on Change parameters.
http://dl.dropbox.com/u/73555776/TDSSConfig.JPG
[*]Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
[*]Click the Start Scan button.
[*]If a suspicious object is detected, the default action will be Skip, click on Continue.
http://dl.dropbox.com/u/73555776/TDSSFound.JPG
[*]If malicious objects are found, they will show in the Scan results and offer three (3) options.
[*]Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
[*]Get the report by selecting Reports
http://dl.dropbox.com/u/73555776/TDSSEnd.JPG
[*]Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
Please copy and paste its contents on your next reply.
doing that now and yes all my files are back