Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

VBS/Autorun.worm.zo, Yuyun_Cantix and no connectivity.


  • Please log in to reply

#31
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Okay, according to what I saw, the newest .lnk files were from March 28. The oldest are from 2009.

I'll perform a search for the Thumb.db files. I listed the locations of the .lnk files in a notepad for future reference.

Gotta add something though...

The partitions were not listed. What do I do about them?

Edited by Greki, 31 March 2010 - 01:12 AM.

  • 0

Advertisements


#32
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
OTL shows a lot of them:

Copy the text between the lines of stars by highlighting and Ctrl + c
***************************************************************************************************
:OTL

:Files
C:\Documents and Settings\Utilisateur\Bureau\[000611].jpg
C:\Documents and Settings\Utilisateur\Bureau\[000609].jpg
C:\Documents and Settings\Utilisateur\Bureau\Recuva.lnk
C:\WINDOWS\tasks\Thumb.db
C:\WINDOWS\tasks\New Harry Potter and....lnk
C:\WINDOWS\tasks\Microsoft.lnk
C:\WINDOWS\System32\1036.lnk
C:\WINDOWS\System32\1033.lnk
C:\WINDOWS\System32\1031.lnk
C:\WINDOWS\System32\1028.lnk
C:\WINDOWS\System32\1025.lnk
C:\WINDOWS\System32\Thumb.db
C:\WINDOWS\System\Thumb.db
C:\WINDOWS\System\New Harry Potter and....lnk
C:\WINDOWS\System32\New Harry Potter and....lnk
C:\WINDOWS\System\Microsoft.lnk
C:\WINDOWS\System32\Microsoft.lnk
C:\WINDOWS\Thumb.db
C:\WINDOWS\New Harry Potter and....lnk
C:\WINDOWS\Microsoft.lnk


:Commands
[purity]
[emptytemp]
[Reboot]

*******************************************************************

then run OTL and Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the Run Fix button at the top
Let the program run unhindered, OTL will reboot the PC when it is done.

Probably be a good idea to run TFC (Temp File Cleaner) from http://www.geekstogo...uide-t2852.html again.

If there are any .lnk or .db files left after this last OTL run then you can delete them by right click and Delete or you can use the cmd sequence cd to the folder then remove the read only, system and hidden attributes with attrib -r -h -s *.lnk then del *.lnk.

I've probably told you this already but make sure you can see hidden and system files:

If using Windows XP:

* Close all programs so that you are at your desktop.
* Double-click on the My Computer icon.
* Select the Tools menu and click Folder Options.
* After the new window appears select the View tab.
* Put a checkmark in the checkbox labeled Display the contents of system folders.
* Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
* Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
* Remove the checkmark from the checkbox labeled Hide protected operating system files.
* Press the Apply button and then the OK button and exit My Computer.
* Now your computer is configured to show all hidden files.


If using Windows Vista or Windows 7:

* Close all programs so that you are at your desktop.
* Open the Control Panel menu and click Folder Options.
* After the new window appears select the View tab.
* Put a checkmark in the checkbox labeled Display the contents of system folders.
* Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
* Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
* Remove the checkmark from the checkbox labeled Hide protected operating system files.
* Press the Apply button and then the OK button and exit My Computer.
* Now your computer is configured to show all hidden files.

Ron
  • 0

#33
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
To do a search of another partition using the command window you have to first switch to the partition then repeat the cd \ and dir /a /s *.lnk

To switch to D: you just type:

d:

for E:

e:

Ron
  • 0

#34
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
OTL killed everything asked. Running TFC now.
  • 0

#35
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
If I got all paths listed down, could I remove them using OTL?

When I try deleting them by the cmd, its says that they're impossible to find and the Windows Explorer just closes for some reason, if I try to delete them.

Edited by Greki, 31 March 2010 - 02:01 AM.

  • 0

#36
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Nevermind, I can delete them now.
  • 0

#37
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Hmmm, I think the program shorcuts from desktop disappeared. I'm not sure if any good files were deleted.

All .lnk files were deleted successfully, though.

I'm not sure how to proceed with the Thumb.db files. According to the search there are some other files ending with .db other than Thumb.db, so a general deleting of those files can't be done. Plus, when I search specifically for the Thumb.db file, it does appear; however, when I try to delete it, it says access denied.

Edited by Greki, 31 March 2010 - 03:00 AM.

  • 0

#38
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Okay, I understand now... "attrib -r -s -h" only works on a specified path, not in general.
  • 0

#39
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Whoops, I just discovered something.

All program accesses through Start==>All Programs disappeared. That is, you can see the folders for each Program, but when you move the cursor over anyone, it says empty. The only way to access the programs is by going directly to C:\Program Files

How do I restore the Start shortcuts?
  • 0

#40
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
OOPS.

.lnk are shortcuts. To replace them find the .exe file they point to (In \Program Files\"program name" and right click and select Create Shortcut. This will create a shortcut in the same folder. Move the shortcut to \Documents and Settings\All Users\Start Menu\Programs\ (Sometimes there is a folder with the same name. Put the shortcut in there. If not just put it under Programs.) It will go faster if you open up two explorer windows. (Right click on Start and select Explore - then make sure they are both not maximized so will fit on the same page. Then drag the new shortcut over to the correct folder.)

Ron
  • 0

Advertisements


#41
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Fiiiiinally. I managed to delete all Thumb.db files.

I'll now restore the shorcuts.
  • 0

#42
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Bah. x.o

Where can I find the Accessories Programs shorcuts?
  • 0

#43
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Do you think I could restore them if I use the same shortcuts from my own pc?
  • 0

#44
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Worth a shot. Might not get all of them and there may be a few that don't exist on the sick PC but might save some time.

Accessories is a folder under Program Files so click on Program Files then find Accessories in the right pane and right click and create shortcut.

Ron
  • 0

#45
Greki

Greki

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Well, the copied Accessories shortcuts from my PC worked...

What I did not take into account for is that my PC is in Spanish and hers is in French. So now she's got some nice Accessories folders in French with Spanish shortcuts. xD

I tried looking for the Accessories folder within Program Files, but they weren't there. It only appears on the Start Menu documents.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP