Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Like Tree6Likes
  • 4 Post By Panama Red
  • 1 Post By rjfvillarosa
  • 1 Post By Panama Red

Reply
 
LinkBack Thread Tools Search this Thread Rating: Thread Rating: 3 votes, 5.00 average. Display Modes
Old 05-12-2011, 05:56 PM   #1
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
Solution for missing start menu shortcuts

Some of you may have encountered malware lately that hides the files from view, removes the desktop background and/or removes all the shortcut icons from the start menu. Unhide.exe will expose the hidden files again and a registry change will give your desktop back. Now, I'm happy to say, I found the missing shortcuts. Several threads on the web have discussed this without resolution. Some even concluded that you have to create all the shortcuts yourself or do a repair install of XP. I stumbled upon the solution quite by accident. The Accessories>System Tools folder was empty (except for IE with no addons) so I tried a search, including hidden files, for Disk Cleanup. Low and behold, it was in a folder in Documents & Settings>User name>Local Settings>Temp>smtmp. Inside smtmp I found three numbered folders containing the missing shortcuts. Simply moved them to the User's Start Menu Folder and voila! - All is good again. I don't know if the same folder is used by each rogue malware so you may want to do a Search (include System and Hidden files) for Disk Cleanup or Disk Defragmenter. Then just browse to that file location and see what you find. This sure is easier than creating new shortcuts for each Program or doing a Repair Install!

Edit: As noted in a post I made below, the smtmp folder has a new hiding spot. I have a pc in for repair right now that doesn't have that folder in the Local Settings. Instead, it is in Windows/Temp.
quartet-man, Petef56, jdeb and 1 others like this.

Last edited by Panama Red; 11-21-2011 at 07:38 PM.
Panama Red is offline   Reply With Quote
Old 05-12-2011, 09:26 PM   #2
Moderator
Staff
Premium Member
 
jdeb's Avatar
 
Join Date: Nov 2008
Location: Detroit, MI
Posts: 3,804
you sure do bring a lot of value to this forum Panama Red
jdeb is offline   Reply With Quote
Old 05-25-2011, 12:03 PM   #3
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
Update: Folder 1 in the hidden tmp folder as noted above should be moved to your Start Menu folder under the user's name. Folder 2 contains the Quick Launch icons such as Show Desktop. Those icons will need to be moved to: C:/Documents and Settings/User name/Application data/Microsoft/Internet Explorer/Quick Launch. I believe Folder 4 is desktop icons but I'm not certain of that.
Panama Red is offline   Reply With Quote
Old 06-06-2011, 02:55 PM   #4
Stop winking at me!!!
 
Iman74's Avatar
 
Join Date: Dec 2001
Location: CT
Posts: 1,482
Send a message via Yahoo to Iman74
Panama,
What about the desktop itself like the chose background for example?
Iman74 is offline   Reply With Quote
Old 06-06-2011, 03:02 PM   #5
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
Quote:
Originally Posted by Iman74 View Post
Panama,
What about the desktop itself like the chose background for example?
Running unhide.exe has been clearing that one up. If not, it may take a registry change. Do a search in regedit for "No Desktop". If it shows up, change the number in the data area from 1 to 0 (or visa versa, I'm not positive).
Panama Red is offline   Reply With Quote
Old 06-06-2011, 03:04 PM   #6
Stop winking at me!!!
 
Iman74's Avatar
 
Join Date: Dec 2001
Location: CT
Posts: 1,482
Send a message via Yahoo to Iman74
Yeah, my gut tells me it's the registry like you suggested "NoDesktop". So far haven't found it worked, but maybe next time I will search the registry instead of manually going there. Thanks for the input.


Going to Google unhide.exe but if you haven't already referenced it I would like to know more.
Iman74 is offline   Reply With Quote
Old 06-06-2011, 03:11 PM   #7
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,782
Virus Cleaned - All files, folders HIDDEN SYSTEM - SOLVED!
glc is offline   Reply With Quote
Old 06-09-2011, 09:59 PM   #8
Member (7 bit)
 
Join Date: Sep 2009
Posts: 66
well im not real good with this stuff, I may have to pay someone to find it. Again I can open powerpoint items but cant find it...And most of the program files sem missing and the ones that are there say empty.....
cvcman is offline   Reply With Quote
Old 08-11-2011, 07:18 AM   #9
Member (1 bit)
 
Join Date: Aug 2011
Posts: 1
Registered in order to post. Wanted to say thank you.

Thank you for the very useful information. I too stumbled across what the virus had done - it was also by accident. The computer had a whole bunch of files in local settings/temp, so I went to delete them. Noticed some strange ones created recently. But your instructions made it much easier to repair.

Things to note.

Win Sec Essentials was used to perform initial scan/removal after pulling HDD and scanning from secure machine via external enclosure.
Malwarebytes was used to perform flash scan to remove 4 more infected items after HDD was reinstalled into user's laptop.
Malwarebytes was used on full scan to ensure that no particles remained.

Virus behavior notes:
1. The virus does not simply move all of your icons. It moves MOST of them but leaves many behind. When you do ProgramRed's trick (looking for folder "smtmp" in "local settings/temp", "1"=programs/startmenu, "2"=quicklaunch, "3" =desktop), you will get a lot of "file already here, overwrite?" prompts. DO NOT overwrite. say "no" to those and write down the names of those folders. you will have to manually go into the smtp version of that folder and move those icons over to the startmenu, quicklaunch, or desktop folders. I believe he does this expressly to prevent fixes to be easily implemented. took about 10 minutes for me to do.
2. the virus not only hides files, but also adds a read-only tag to them. attempting to use attrib will result in "access denied". Unhide.exe was successful in making things visible, but was less successful in making those folders virus-marked read-only visible. fortunately, only the root directory folders are this way affected. (the ones in c:\). simply highlight everything in your root directory in explorer (make sure "view hidden files and folders" is enabled), and uncheck hidden. I have left them read-only for now because I'm not certain if removing R or S properties from files that should have them will cause any problems.

thank you so much for the users of this forum, and for all of the time and effort put out there to combat this virus designed to rip off the vulnerable.

kevin

Last edited by duenor; 08-11-2011 at 07:47 AM.
duenor is offline   Reply With Quote
Old 09-15-2011, 06:43 AM   #10
Member (2 bit)
 
Join Date: Sep 2011
Location: Northern Ireland
Posts: 2
moving folders 1, 2 and 4 got me back my desktop icons and menu icons but not the actual program shortcuts in the start menu. When I press the start button, Sage Accounts and all the rest are listed but when you go to any of them the sub menu appears and says `empty`. Going to try windows repair install.
Kilsally is offline   Reply With Quote
Old 10-07-2011, 03:01 PM   #11
Member (1 bit)
 
Join Date: Oct 2011
Posts: 1
I moved the folders under the all users Start Menu Folder
vcvogel is offline   Reply With Quote
Old 10-08-2011, 01:20 AM   #12
Member (11 bit)
 
rwest's Avatar
 
Join Date: Mar 2006
Location: Columbus, OH
Posts: 1,388
GLC, maybe you or any mod can link the threads together? I was thinking of that thread when I saw your post. That things such a bugger, be nice to have all the solutuins in one place huh?
__________________
Gigabyte 880GA-ud3h / 3.1 Phenom II x2 550 BE Callisto(4 cores and OC to 3.4) / Corsair Vengence 2x4gb DDR3 1600 / 640gb WD Black 2ea./HIS 6870/ 650 EarthWatts / Win 7 64bit
rwest is offline   Reply With Quote
Old 10-08-2011, 08:10 AM   #13
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,782
There are too many posts in each one all spread out over different dates - if I merge them it will be VERY confusing.
glc is offline   Reply With Quote
Old 10-08-2011, 09:14 AM   #14
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
Quote:
Originally Posted by rwest View Post
GLC, maybe you or any mod can link the threads together? I was thinking of that thread when I saw your post. That things such a bugger, be nice to have all the solutuins in one place huh?
Quote:
Originally Posted by glc View Post
There are too many posts in each one all spread out over different dates - if I merge them it will be VERY confusing.
I will have a look at creating a "sticky" thread with a little introduction and links to both threads and any other relevant threads.
jdeb likes this.
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta.
rjfvillarosa is offline   Reply With Quote
Old 10-08-2011, 10:09 AM   #15
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,782
I think that would be an excellent idea.
glc is offline   Reply With Quote
Old 10-25-2011, 10:36 PM   #16
Member (9 bit)
 
Join Date: Mar 2004
Posts: 313
Send a message via AIM to daveyp225
Hey all, been years since I logged in, but google brought me back

This thread helped a lot. Appreciate it. In Vista, the shortcuts are stored in:

Users\*user*\AppData\Local\Temp\smtmp

Thanks guys.
Dave
__________________

Thermaltake Swing | 550W Corsair PSU | Asus P5K DLX/WiFi | Intel C2D E8400 @ (???)ghz | 2x2GB G.Skill DDR2-1000 | eVGA 8800GT Superclocked | 400GB Seagate 7200.11 (32mb) | 20x ASUS DVD-RW with Lightscribe | 20x Samsung DVD-RW | Black Floppy (just in case) | 52-in-1 Card Reader | UV lights & cables


Enermax CS-800TA | 400Watt Antec PSU | Asus P4c800 Deluxe | P4 2.8c @ 3.5ghz | 2x512 KHX pc4000 | ATI 9800pro AIW 128mb | 120GB 7200RPM WD Hard Drive | 8x NEC DVDRW | 16x sony dvd-rom | sony silver floppy

daveyp225 is offline   Reply With Quote
Old 10-26-2011, 03:56 AM   #17
Ride 'em Cowboy
 
EzyStvy's Avatar
 
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,109
The unhide.exe file helped me yesterday
__________________
Stand Up 2 Cancer - SU2C
EzyStvy is offline   Reply With Quote
Old 11-21-2011, 07:35 PM   #18
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
Just discovered a new variation for hidding the Program Shortcuts. Instead of using the Temp file under Local Settings, the pc I have here right now has the smtmp file hidden in the Window/Temp folder. I'm going to edit my earlier entry to include this optional hiding spot. Must be the bad guys can read our "fix" threads too.
jdeb likes this.

Last edited by Panama Red; 11-21-2011 at 07:38 PM.
Panama Red is offline   Reply With Quote
Old 11-28-2011, 01:12 PM   #19
Member (1 bit)
 
Join Date: Nov 2011
Posts: 1
Just stumbled on this thread while trying to remove this virus at work. Unfortunately, one of the first things I do when combating a Fake AV is to boot the computer into TRK and remove any suspicious files in APPDATA, followed by doing a Windows Junk File cleaning that clears out Temp Files, Temporary Internet Files, etc. That totally blasted any backups of shortcuts the virus may have made.
fluffman86 is offline   Reply With Quote
Old 11-28-2011, 02:31 PM   #20
Mondsreitersmann
 
Nuclear Krusader's Avatar
 
Join Date: Jul 1999
Location: Skingrad
Posts: 8,781
Guess I should stop clearing out the contents of the temp folders when dealing with this infection.
__________________
Darum still, füg' ich mich, wie Gott es will. Nun, so will ich wacker streiten, und sollt' ich den Tod erleiden, stirbt ein braver Reitersmann.
Nuclear Krusader is offline   Reply With Quote
Old 01-28-2012, 11:50 AM   #21
Member (2 bit)
 
Join Date: Jan 2012
Posts: 2
missing start menu shortcuts

i too had the malware hit. i ran unhide and it brought my files back into view, but am still not finding my shortcut icons for the start menu. i ran a search for smtmp and disk cleanup, which turned up nothing. any ideas?
rbm328 is offline   Reply With Quote
Old 01-28-2012, 12:10 PM   #22
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
Did you look in the two folders I mentioned for the smtmp folder? One is in the Windows > Temp folder. The other, in XP, is in Docs & Settings > (your user name) > Local Settings > Temp folder. The Local Settings folder is a hidden folder so you'll have to use the Folder Options in the Control Panel to select Show Hidden Folders.
Panama Red is offline   Reply With Quote
Old 02-08-2012, 01:00 PM   #23
Member (2 bit)
 
Join Date: Feb 2012
Posts: 2
Hi, many thanks for the fantastic help here, I got rid of this virus and have managed to unhide all my files and get my start menu back.

However, I have not been able to get my desktop back - right clicking on it is still disabled. I could not find a registry key called 'Noviewcontextmenu' or anything similar, even after lots of searching Regedit.

My shortcuts are there when I explore to the Desktop folder, but the desktop itself is blank and can't be clicked on.

Does anyone have any ideas about this?

Thanks again for all the help on this site!
Korov is offline   Reply With Quote
Old 02-08-2012, 02:59 PM   #24
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
See posts 9 & 12 in this thread.

No icons - right-click does nothing.
Panama Red is offline   Reply With Quote
Old 02-08-2012, 04:17 PM   #25
Member (2 bit)
 
Join Date: Feb 2012
Posts: 2
Solved! Many thanks Panama Red.
Korov is offline   Reply With Quote
Old 02-11-2012, 09:48 AM   #26
Member (2 bit)
 
Join Date: Jan 2012
Posts: 2
panama red- i had originally given my box to an IT friend, who cleaned the virus' AND (i found out last week) purged all the temp files, thats why i couldn't find the files you mentioned. i sent him this link so hopefully, in the future, he won't jump on the temp purge.

is there any way i can get my start menu links back besides reloading all the software?
thanks
rbm328 is offline   Reply With Quote
Old 02-11-2012, 11:45 AM   #27
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
Go to the Programs folder and look up the .exe file for each Program. Right click the .exe and send it to a folder on your Desktop temporarily. Once you have all the shortcuts created, move them to the Startup folder under All Users (for XP) or your user name if you're the only one on the pc. Recreating the Windows features shortcuts is similar, you just have to know where the .exe files are located. If you can get another pc with the same operating system, find the shortcuts you want to add in the other pc's start/all programs menu. Right click the shortcut and select Properties. The click the Show Target or Open location button. That will tell you where to look on your computer for the same Windows file locations. Use the same recreation method I outlined for the Programs.
Panama Red is offline   Reply With Quote
Old 02-11-2012, 11:55 AM   #28
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,782
Minor clarification:

Quote:
Right click the .exe and send it to a folder on your Desktop temporarily.
Don't send the .exe, select "create shortcut" and send it. I recommend you uncheck "hide extensions for known file types" in your folder options, it makes it easier to find the correct file.
glc is offline   Reply With Quote
Old 02-11-2012, 12:18 PM   #29
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
Quote:
Originally Posted by glc View Post
Minor clarification:



Don't send the .exe, select "create shortcut" and send it. I recommend you uncheck "hide extensions for known file types" in your folder options, it makes it easier to find the correct file.
Right you are, G. I meant to send the shortcut to the desktop folder. Brain and fingers weren't working together! (again!!)
Panama Red is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 08:53 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2