Windows XP/Vista Recovery rogue - Desktop icons missing - Empty program files

AID: 6209
  • Status: Published

35965 points

  • Byrpggamergirl
  • TypeGeneral
  • Posted on2011-06-14 at 06:55:03
Awards
  • Community Pick
  • Experts Exchange Approved
  • Editor's Choice
Most PC repair technicians (if not all) always start their cleanup process by emptying the temp folders before running any removal tools. It makes sense because temp folders are common places for malware installers to lurk and removing all the junk also cuts down the removal tools scanning time. With this known info, malware writers created rogues that move files to that directory.

So now we have rogue software that will move user's files to the %temp%\smtmp folder.
Infected with this malware, you must NOT empty your temp folders nor run CCleaner or any temp file cleaners until you have fully removed the rogue and everything is back to normal.

So far, the Windows Recovery and Windows Restore rogues are the culprits but there could be other variants that do the same thing.
These rogues hide files and move desktop shortcuts and Programs startmenu shortcuts into this folder --> %temp%\smtmp, it then creates 4 subdirectories:

%Temp%\smtmp\1\ => Allusers Start Menu
%Temp%\smtmp\2\ => Allusers Quick Launch
%Temp%\smtmp\3\ => Quick Launch\User Pinned\TaskBar
%Temp%\smtmp\4\ => AllUsers Desktop

If you did not empty your temp folder you can just retrieve those files from there. Or using restoresm.zip which will restore all the missing shortcuts. restoresm.zip
Extract the file, open the restoresm folder and doubleclick on restoresm.bat to run it.


The Cleanup:

Grinler at Bleepingcomputer wrote an excellent tutorial for the removal of this infection, check it out here. http://www.bleepingcomputer.com/virus-removal/remove-windows-recovery
The tools mentioned below also work for most of the family of rogues not just for the rogues that hides files.


Tools needed: (If unable to download tools, use another PC to download into a USB or burn to a CD).
FixNCR.reg – executables are blocked so you need to run this registry fix so programs will launch.
RKill – run this to kill malware processes (to be sure, use the renamed RKill "iexplore.exe" or other renamed RKill)
RogueKiller – this is another alternative you can use to kill malware processes before running MalwareBytes.
MalwareBytes - this is the scanner that removes the infection.
Unhide.exe – use this tool to remove the hidden flags of files as this infection hides files on your computer from being seen. The drawback of running unhide.exe is, it unhides ALL files even windows system files with default hidden attributes.
TDSSKiller - run this tool if google searches are redirected as this is often bundled with TDSS rootkits.


NOTE: Do Not reboot after running RKill or RogueKiller otherwise the malware processes will start up again. Straight after killing the malware processes, you need to immediately run MalwareBytes to remove the infection.


If file association is borked after the removal of the infection, you can use these fixes:
Dougknox XP .exe file association fix.
Vista – File association fixes.
Windows 7 file association fixes


*** UPDATE ***

Instead of running all the above-mentioned tools(with the exception of MalwareBytes and TDSSKiller) you could also just run "TheKiller".

Download TheKiller by maliprog
http://maliprog.geekstogo.com/explorer.exe

Note that "TheKiller" is renamed as explorer.exe
Double click on it (If running Vista or Windows 7, right click on it and select "Run as an Administrator")
Press OK when the program finished.
Do not restart your system after this step. You then run other tools like MalwareBytes, TDSSKiller or ComboFix.

NOTE: If malware blocks TheKiller from running please try to run it again.



So you used CCleaner and the %temp%\smtmp folder is gone, what now?
If the temp folder has been cleaned and the shortcuts are gone, all is not lost, you can recover those default shortcuts using Ramesh Srinivasan's fixes, or manually restore all by using Noviciate’s repair.zip (scroll down to post #30).

* To Restore Accessories Program Files Menu
Download accrestore.zip, unzip, doubleclick on AccRestore.exe to run it and click the "Restore" button.

* To Restore Admin Tools Program Files Menu
Download admintools.zip, unzip and doubleclick on "Restore Administrative Tools items" button.

* To Restore each program shortcut, the repair.zip by Noviciate works. The extracted repair.vbs when run produces needed shortcut links which you can then cut and paste into your start menu folder.

* In Windows 7 - How to restore missing startmenu default shortcuts
http://www.sevenforums.com/tutorials/135246-start-menu-all-programs-windows-7-restore-default-shortcuts.html

* In Vista -  How to restore missing startmenu default shortcuts
http://www.vistax64.com/tutorials/159034-start-menu-restore-missing-default-shortcuts.html

For XP tutorial images of the above, go to this link below.
http://www.geekstogo.com/forum/topic/302235-all-icons-and-programs-gone/page__p__2022670#entry2022670


If you need assistance removing this infection, post a question in the Virus & Spyware zone or post a comment here and I will try to help if I can.

Hope you find this article helpful.
Asked On
2011-06-14 at 06:55:03ID6209
Tags

Windows Recovery

,

windows Restore

,

missing files

Topic

Anti-Spyware

Views
6344

Comments

Expert Comment

by: younghv on 2011-06-14 at 09:23:39ID: 28654

This is excellent work.
We must have 10-15 questions a day that this will help solve.
Very timely.
(Yes vote above)

Author Comment

by: rpggamergirl on 2011-06-15 at 06:37:39ID: 28701

Thanks for the Yes vote, :)

Expert Comment

by: cs97jjm3 on 2011-06-15 at 14:59:33ID: 28719

Great, this will help me a lot with family computers

Expert Comment

by: Jsmply on 2011-06-15 at 23:01:43ID: 28735

RPG is always unbelievably helpful.  This is just another example of what an asset she is to EE!

Author Comment

by: rpggamergirl on 2011-06-16 at 06:01:06ID: 28738

cs97jjm3,
Thanks for the Yes vote and for your feedback.

Jsmply,
Thanks for voting Yes and for the kind words, much appreciated, :)

Expert Comment

by: Jsmply on 2011-06-16 at 11:32:53ID: 28743

Your very welcome.  I've said many times, being able to access your articles and contact you for tricky malware issues is worth the EE subscription/membership price alone.  

Author Comment

by: rpggamergirl on 2011-06-17 at 07:00:07ID: 28769

Reading your comments really makes my day! thanks again.

Expert Comment

by: SSharma on 2011-06-20 at 11:16:17ID: 28929

Great article rpggamergirl, however I have few question for you if you may answer them. I have seen few users complaining about the IE Favorites also gone after the infection. Is there any fix for it yet?

Further there was an instance where user has reported that using System Restore has fixed his issue with missing Start Menu shortcuts. Is this still a concrete solution to the problem?

Thanks .......!!!!!!!!

Again ......... great article....

You got my vote.

Sudeep

Author Comment

by: rpggamergirl on 2011-06-21 at 05:11:52ID: 28954

SSharma,

The unhide.exe should've taken care of the hidden favorites folder, if unhide.exe was already run and IE favorites are still showing empty then maybe the folder also has been moved. If the contents of the favorite folder exist yet not showing in IE then it's just the reg values that need to be restored to point back to that folder. I can post a reg file if needed.

"Further there was an instance where user has reported that using System Restore has fixed his issue with missing Start Menu shortcuts. Is this still a concrete solution to the problem?"

Definitely not to my knowledge... I have seen reports where System restore failed in restoring the missing shortcuts... I participated on a thread where system restore supposedly have restored them. But one success out of many failed attempts don't really mean much. That one time could've been just a fluke. Let me know if you see reports where system restore was successful in restoring those shortcuts.

Thanks for your comment and the Yes vote.

Expert Comment

by: SSharma on 2011-06-21 at 23:10:07ID: 28980

>>>>if unhide.exe was already run and IE favorites are still showing empty then maybe the folder also has been moved

Do we know if the Favorites also been to %temp%/smtmp under some subfolder, just like Allusers Start Menu and Allusers Desktop?

Thanks for answering

Author Comment

by: rpggamergirl on 2011-06-25 at 20:48:13ID: 29130

So far, I haven't heard of the favorites shortcuts being moved to temp\smtmp subfolder. Just the reg value pointing somewhere instead of the favorites folder. There was also a case of an smtmp folder created somewhere else C:\temp\smtmp

Expert Comment

by: yobri on 2011-06-30 at 17:13:16ID: 29357

Excellent and very thorough. This is indeed an excellent article and resource, rpggamergirl.

Expert Comment

by: Tigzy on 2011-07-01 at 01:04:21ID: 29362

Hello

Notice that RogueKiller will remove the rogue's registry keys (mode 2) and restore the files from smtmp folder plus hidden files (mode 6)

This is important cause with one tool, you get back full access to your computer for safe cleaning with AM software (MBAM)

Author Comment

by: rpggamergirl on 2011-07-01 at 02:38:09ID: 29363

Thanks yobri, :)

Hi Tigzy,

Thanks for your input, much appreciated. Thanks again for the RogueKiller tool.
Does RogueKiller remove hidden flags on all files in the system even files with default hidden attributes like unhide.exe does?

It seems some variant of this rogue also modifies the value of "Favorites" in Current User.....\Shell folder so it no longer point to the favorites folder. I'm just wondering if RogueKiller takes care of that too since unhide.exe doesn't seem to do it.
Thanks!

Expert Comment

by: Tigzy on 2011-07-01 at 04:59:40ID: 29368

Does RogueKiller remove hidden flags on all files in the system even files with default hidden attributes like unhide.exe does?


Yes it does.
I speak sometimes with grinler via MBAM forums, so our tools take care about the same things basically.

Never heard about the favorites key...
However, the favorites folder (in the personal folder) is hidden by the rogue too, are you sure this is not the problem?

Expert Comment

by: Tigzy on 2011-07-01 at 05:13:23ID: 29369

I add we are not able to make the difference between the files hidden by the rogue and the ones previously hidden by the system. So all are treated equally.

I you want to hide some with "system" attribute, the user can use my tool:
http://tigzy.geekstogo.com/Tools/forceHide.exe

Author Comment

by: rpggamergirl on 2011-07-02 at 23:13:07ID: 29394

Tigzy,

The tool sounds good but when I run it I get this "The application failed to initialize properly" error.

Expert Comment

by: Tigzy on 2011-07-03 at 00:52:20ID: 29395

I forgot to say you need to have the .net framework 3.5 at least. Usually users have it, but I understand It could not be the case on a vm :)

Author Comment

by: rpggamergirl on 2011-07-06 at 02:38:14ID: 29517

Hi Tigzy,

I downloaded .net framework 3.5.
Dropped folder into the Forcehide window and yes it will check and uncheck the hidden attribute of the folder but it doesn't actually hide it. I can still see it even though explorer.exe is set not to show hidden files and folders.
Did I do it correctly?
Thanks.

Expert Comment

by: Tigzy on 2011-07-06 at 10:08:59ID: 29530

Yes, that's all...
Is the display of hidden files activated?

May you try F5 on the desktop?

Author Comment

by: rpggamergirl on 2011-07-09 at 07:10:07ID: 29626

Hi Tigzy,

Sorry for much delayed reply.

"Is the display of hidden files activated?"

If you mean explorer is set to display hidden files and folders then yes it is. In the folder properties, the hidden attribute is also unchecked.

However, the Forcehide tool works on files, it's only on folders and sub-folders that it doesn't even though it still check or uncheck the system and hidden attributes. What I mean is, there's no effect on folders only on files.

Expert Comment

by: Tigzy on 2011-07-10 at 08:47:23ID: 29628

Yes, if you select a folder, only the folder himself will be affected.
but I can improve my tool to affect subfolders and files recursively...

Author Comment

by: rpggamergirl on 2011-07-11 at 06:10:40ID: 29641

That would be great!

Expert Comment

by: tigermatt on 2011-07-25 at 10:42:04ID: 30045

Voted yes. Thanks, rpg!

Author Comment

by: rpggamergirl on 2011-07-25 at 17:51:36ID: 30057

Thanks Matt! :)

Expert Comment

by: grtraders on 2011-09-24 at 01:59:01ID: 31763

Brilliant, as always. Cast my Yes vote.

Ravi.

Expert Comment

by: jburgess_isit on 2012-01-25 at 15:26:12ID: 34778

I did all of this, and my folders are still empty.  In all programs, the folders are there, but the contents inside of the folders are gone.  I did not delete any temp files.

Expert Comment

by: younghv on 2012-01-25 at 15:41:19ID: 34779

jburgess_isit,
Please post your comment back in your original question (http://www.experts-exchange.com/Q_27554941.html) and I will continue to try to help you.

I posted a reference to this article only about 8 minutes ago, but if you have already run all of the programs recommended, be sure to post all of the log files that were generated.

Expert Comment

by: willcomp on 2012-03-09 at 12:53:52ID: 45145

@rpg and tigzy -- enjoyed the discussion. Have been using RogueKiller since Vic recommended it some time back and much prefer it to RKill.

Yes vote for rpg.

Author Comment

by: rpggamergirl on 2012-03-09 at 15:44:37ID: 45154

jburgess_isit,

It's okay to post here since it is a relevant topic, and it keeps this thread active.
Even though you didn't delete your temp files yourself doesn't mean those smtmp folders weren't deleted. Most cleanup/virus scanners these days will empty the temp folders but only selected scanners are updated to check for smtmp folders.

So in your case those smtmp folders that stored the shortcuts were gone and recreating the shortcuts was needed.

At willcomp - Roguekiller is great,  there's also another tool great  "TheKiller" which has features that RogueKiller doesn't have, :)
It's good to have selection of tools.

Thanks for the yes vote, :)

Expert Comment

by: willcomp on 2012-03-09 at 16:36:46ID: 45156

@rpg -- I've seen where you recommended TheKiller in other posts. Will download and give it a try. Thanks.

Author Comment

by: rpggamergirl on 2012-03-09 at 18:12:27ID: 45157

Thekiller is also pre-cleanup tool like RogueKiller that stops malicious and non-esential running processes and perfect for rogues like this one that hide files and moves shortcuts to smtmp folder, among its other features.

Add your Comment

Please Sign up or Log in to comment on this article.

Join Experts Exchange Today

Gain Access to all our Tech Resources

Get personalized answers

Ask unlimited questions

Access Proven Solutions

Search 3.2 million solutions

Read In-Depth How-To Guides

1000+ articles, demos, & tips

Watch Step by Step Tutorials

Learn direct from top tech pros

And Much More!

Your complete tech resource

See Plans and Pricing

30-day free trial. Register in 60 seconds.

Loading Advertisement...

Top Anti-Spyware Experts

  1. younghv

    61,741

    Master

    5,500 points yesterday

    Profile
    Rank: Genius
  2. rpggamergirl

    42,015

    0 points yesterday

    Profile
    Rank: Genius
  3. SSharma

    32,708

    0 points yesterday

    Profile
    Rank: Genius
  4. Russell_Venable

    22,738

    0 points yesterday

    Profile
    Rank: Wizard
  5. Run5k

    14,664

    0 points yesterday

    Profile
    Rank: Genius
  6. tzucker

    10,984

    0 points yesterday

    Profile
    Rank: Wizard
  7. willcomp

    7,196

    0 points yesterday

    Profile
    Rank: Genius
  8. DaveBaldwin

    6,064

    0 points yesterday

    Profile
    Rank: Genius
  9. nobus

    5,300

    0 points yesterday

    Profile
    Rank: Savant
  10. MASQUERAID

    4,136

    0 points yesterday

    Profile
    Rank: Genius
  11. thinkpads_user

    3,740

    0 points yesterday

    Profile
    Rank: Genius
  12. David-Howard

    3,692

    0 points yesterday

    Profile
    Rank: Genius
  13. 9660kel

    3,659

    0 points yesterday

    Profile
  14. ve3ofa

    3,600

    0 points yesterday

    Profile
    Rank: Genius
  15. Anuroopsundd

    3,000

    0 points yesterday

    Profile
    Rank: Sage
  16. youngrmy

    2,840

    0 points yesterday

    Profile
    Rank: Master
  17. cwstad2

    2,837

    0 points yesterday

    Profile
    Rank: Guru
  18. StoneG

    2,800

    0 points yesterday

    Profile
    Rank: Wizard
  19. Netman66

    2,800

    0 points yesterday

    Profile
    Rank: Genius
  20. Jonvee

    2,800

    0 points yesterday

    Profile
    Rank: Genius
  21. ArmyGroo

    2,800

    0 points yesterday

    Profile
    Rank: Guru
  22. jcimarron

    2,775

    0 points yesterday

    Profile
    Rank: Genius
  23. Tymetwister

    2,668

    0 points yesterday

    Profile
    Rank: Master
  24. Scissors85

    2,500

    0 points yesterday

    Profile
    Rank: Master
  25. breadtan

    2,443

    0 points yesterday

    Profile
    Rank: Genius

Hall Of Fame