Blank Desktop? No Icons or taskbar

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Puddy7, Aug 17, 2010.

  1. Puddy7

    Puddy7 Private E-2

    Hi

    Followed the link and done everything I was told on my original thread which is here: http://forums.majorgeeks.com/showthread.php?t=221225 but I've still got the same problem.

    I've attached the relevant logs to this thread so someone can view them.

    Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Was there any particular reason that you did not run combofix?
     
  3. Puddy7

    Puddy7 Private E-2

    On the link it said the following:

    "If you are using a 64 bit version of Windows skip this step with ComboFix because it is not compatible with x64 systems.

    See: How to check for 32 bit or 64 bit Windows"

    According to the link 'How to check for 32 bit or 64 bit Windows' I am running at 64bit system unless I missread it.

    That being the case I was under the impression that I didn't need to run it?

    Is that not right?
     
  4. Puddy7

    Puddy7 Private E-2

    Just double checked and I used method 1 to check which seems to show a 64bit version.

    I've just tried Method 2 which shows a 32bit version.??

    I'm slightly confused now?? Unless I've again misread something.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just try and run Combofix and we'll see what gives.
     
  6. Puddy7

    Puddy7 Private E-2

    Just ran combofix and here's the log
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We have a good bit to get through:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\winlogon.exe | c:\windows\system32\winlogon.exe
    C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\explorer.exe | c:\windows\explorer.exe
    
    File::
    C:\WINDOWS\0
    C:\WINDOWS\system32\0
    C:\Documents and Settings\Frank.FRANK-222825085\Local Settings\Temp\238.tmp
    C:\Documents and Settings\Frank.FRANK-222825085\Local Settings\Temp\239.tmp
    C:\Documents and Settings\Frank.FRANK-222825085\Local Settings\Temp\23A.tmp
    C:\Documents and Settings\Frank.FRANK-222825085\Local Settings\Temp\248.tmp
    C:\Documents and Settings\Frank.FRANK-222825085\Local Settings\Temp\72y548.tmp
    C:\Documents and Settings\Frank.FRANK-222825085\Local Settings\Temp\8my1E3.tmp
    
    DirLook::
    c:\documents and settings\Frank.FRANK-222825085\Application Data\7C1ED922CDD11E053E6FCAE53A2A6B33
    C:\Documents and Settings\Frank.FRANK-222825085\Local Settings\Application Data\Windows Server
    
    Folder::
    C:\Documents and Settings\Frank.FRANK-222825085\Local Settings\Temp\7zS26DA
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    IMPORTANT: Let me know how things are running now! :)
     
  8. Puddy7

    Puddy7 Private E-2

    Followed your instructions exactly and here is what has happened.

    Deleted all possible files from the temp folders except 2 that it wouldn't let me delete (jetc776.temp & perflib_perfdata_464.dat)

    Ran Combofix exactly as you said by dragging the saved CFscript.txt file. I also clicked Yes on the Microsoft Windows Recovery Console pop up window that asks you to install it. I assumed this was correct as it also said do this in the original instructions.

    After it had finished it rebooted and then produced the log which I saved and attached. My desktop and taskbar reappeared at this point and are still there at the moment.

    Then ran the GetLogs.bat file and attached the zip log here.

    Still having a few issues though.

    1. I reactivated my Virus/Firewall software (Norton) to go back on net so I could log back into the forum, now Norton Auto-Protect keeps coming up saying "Auto Protect detected a Security Risk Suspicious.Mystic". Then about 20 odd seconds later it pops up and says it has removed it and your computer is secure. Problem is at time of writing this it has done it about 30 times one after another and still going. Looked in view details and it's showing it in there along with a Trojan Horse that it quarantined yesterday (but I knew nothing of this Trogan and never had an alert to my knowledge)

    2. I've had a widows file protection pop up come up which I've screen grabbed and attached also to this.

    3. If I click on My Computer on my desktop I get the following pop up box with this message "The file does not have a program associated with it for performing this action. Create an association in the folder options control panel.

    4. CPU usages seems to be constantly running at 100%. now.

    I've not touched or done anything else and won't do until I hear back from you.

    Thanks
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      winlogon.exe
      explorer.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  10. Puddy7

    Puddy7 Private E-2

    Do I need to disable Anti Virus & Firewall while I run it?
     
  11. Puddy7

    Puddy7 Private E-2

    System look ran and attached log
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this folder:
    Do you have your XP Operating System CD handy?? I have a feeling we are going to need it as it's looking like winlogon.exe and explorer.exe are infected, and so are each of their only back up files in other locations.

    let's do this before we move onto the next plan of action, but do answer my question about your XP disk.

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\winlogon.exe
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below files and also let me know the results:

    Code:
    c:\windows\system32\winlogon.exe
    c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\explorer.exe 
    c:\windows\explorer.exe
     
    Last edited: Aug 19, 2010
  13. Puddy7

    Puddy7 Private E-2

    Tried to delete the Windows Server folder you said to do but it isn't there anymore?? Not sure why this is. All my files and folders are not hidden so not sure why this is?

    Anyway Copied and scanned the first code and here is the scan result link:
    http://virusscan.jotti.org/en-gb/sc...f9ac/1caf527c7e765a531d57aca8e2d29601e92654c3

    Here's the links for the other 3

    http://virusscan.jotti.org/en-gb/scanresult/f4b3067098738cc70291f5c82fe6965cb2299a79

    http://virusscan.jotti.org/en-gb/sc...37d7/0c3df01d7b4804333f98ce92e7dd00f12d5cec43

    After entering the :c\windows\explorer.exe it just gave me a pop up window saying File not Found, Please Verify the correct file name was given. So I looked manually in the Windows folder and couldn't find Explorer.exe. I did find a file named explorer.scf. I scanned this one (don't think you need this one but I scanned it anyway) here is the results from that scan

    http://virusscan.jotti.org/en-gb/sc...fd92/7ad971584b1218dedd2069d7dbb7adf248142a5b

    Oh and yes I do have the Original XP windows installation disk handy.

    My desktop and Taskbar have vanished again today but I'm assuming that this is down to the malware/virus still being present.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Complete the below in safe mode:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\winlogon.exe | c:\windows\system32\winlogon.exe
    C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\explorer.exe | c:\windows\explorer.exe
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now back to normal mode.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. Puddy7

    Puddy7 Private E-2

    Followed your instructions and attached the logs

    Same thing happen as yesterday though

    I reactivated my Virus/Firewall software (Norton) to go back on net so I could log back into the forum, now Norton Auto-Protect keeps coming up saying "Auto Protect detected a Security Risk Suspicious.Mystic". Then about 20 odd seconds later it pops up and says it has removed it and your computer is secure. It's come up about 4 times so far..

    I've had a widows file protection pop up come up which I've screen grabbed and attached also to this.

    If I click on My Computer on my desktop I get the following pop up box with this message "The file does not have a program associated with it for performing this action. Create an association in the folder options control panel.


    Would it be better for me to wipe the lot and start again with a fresh install of windows??

    My Hard drive is partitioned and all my files and data are saved on D Drive and not on C Drive.
     

    Attached Files:

    Last edited: Aug 20, 2010
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, not yet, not if you want to hang on a little longer, I believe we could use the recovery console and your XP CD to correct everything. Bear with me, I will reply back very soon.
     
  17. Puddy7

    Puddy7 Private E-2

    Ok I'll give it a little longer
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this:

    Get into your bios and change the boot up order to cd as first device, insert your OS cd and reboot. When you boot to your cd, go into the Recovery console and type this:

    cd
    D:
    cd i386
    copy userinit.exe c:\windows\system32 (Enter)
    copy winlogon.exe c:\windows\system32 (Enter)
    EXIT
    After putting in the third and fourth command, you should receive the message 1 file copied which will indicate that the operation succeeded.
    Now take out the CD and reboot your computer to normal mode.

    Now re-run ComboFix and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
    Last edited: Aug 20, 2010
  19. Puddy7

    Puddy7 Private E-2

    Right not quite how to change the boot up order...

    I tried F8, F2, F1 and F10 to get into my bios but they didn't seem to work. Think I've got into it now by doing Shift F10

    I'm presented with the the following 4 options:

    Network Boot Protocol: PXE or PPL
    Boot Order: Int 18h, Int19, PNP/BEV(BBS) or ROM Disable
    Show Config Message: Enable or Disable
    Show Message 1, 3 or 5 seconds

    If this is the correct menu Any idea what I need to alter?

    Also before when I was getting the Auto Protect detected a Security Risk Suspicious.Mystic". Then about 20 odd seconds later it poped up and said it has removed it and your computer is secure.

    Well now the Suspicious.Mystic has gone and been replaced with Trojan.Bamital!inf. Same thing happens it keeps looping round saying it's detected it then removed it then detected, then removed and so on....
     
  20. Puddy7

    Puddy7 Private E-2

    I seem to have another problem now. The pc will now not even boot up. It just gets to the windows xp logo then just resets and tries to reboot again. So im guessing i'll need to wipe c drive and start a fresh now? All my data and files are stored on the partitioned drive d
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have all your data and personal files on partition D, then it may be best to format the C drive and reinstall. Once that is done, I would suggest you go through the Read and Run first instructions again to make sure nothing in the backup partition is infected.
     
  22. Puddy7

    Puddy7 Private E-2

    Sorry been away on holiday and only just got back. I gave my PC to a friend to try and sort out for me while I was away. He's formatted the C: drive and reinstalled everything.

    All seems to be working fine now.

    Thanks to all that has helped me with this problem..
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds