Desktop Disappears every 30 seconds

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ashkisher, Jul 9, 2008.

  1. Ashkisher

    Ashkisher Private E-2

    OK I really need help before I lose my mind. I dont know what happened, but my desktop flashes and then goes away. The start bar, all icons, and any windows program that is open will close and will need to be re opened, but will close again when it "flashes" and the icons go away. Internet works if I log off and log back on, but only if I quickly click on the button before it flashes. I really just want my desktop back and I have no idea what steps to take to fix this. Please help me!!! I have windows XP.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We have to determine if this is a malware problem or if Windows Explorer is crashing on you. It Explorer was crashing I would expect you to see an error message about the crash though. So since you did not mention any error messages, please proceed with the below.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not. If your problems block you from running steps in normal boot mode, try running all steps (or as many as possible) in safe boot mode.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Ashkisher

    Ashkisher Private E-2

    OK- so- I did everything you said. I downloaded everything, and then ran the very first one. SUPERAntispyware. Now my computer seems fine. Should I continue with the rest, or let it be? I attatched the log from the scan. Let me know what I should do!! and Thanks sooooooooooooo very much for your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you are strongly advised to finish ALL of the instructions and attach the other 3 requested logs.
     
  5. Ashkisher

    Ashkisher Private E-2

    OK here are the next 3 logs. I have just the very last step to run, and I am going to do that now. Thanks again!
     

    Attached Files:

  6. Ashkisher

    Ashkisher Private E-2

    K. here is the MGlogs file. Hope this works! Let me know if there is anything else i need to do!!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I advise you to cleanup all the clutter on your Desktop. It should be used for shortcuts not to store everything you download. A cluttered Desktop is malware playground.
    What is the below file? Why do you need 3 copies? And why is it save in these folders? If you need it, keep one copy and save it somewhere else in a properly named folder showing what it is.
    Code:
    2007-11-15 18:07 77,824 ----a-w C:\Documents and Settings\Owner\acv_tool.exe
    2007-11-15 18:07 77,824 ----a-w C:\Documents and Settings\New Folder\acv_tool.exe
    2007-11-15 18:07 77,824 ----a-w C:\Documents and Settings\Default\acv_tool.exe
    Do you know what the below files are for? Are they for a game? If unknown, you should rename them until you are sure you don't need them and then delete them. Whatever is saving them here, should not be!!
    Code:
    "C:\WINDOWS\"
    data2a.dll    Jun  8 2008     1355871  "data2a.dll"
    data3a.dll    Jun  8 2008       20480  "data3a.dll"
    data4a.dll    Jun  8 2008       34310  "data4a.dll"
    data5a.dll    Jun  8 2008       44039  "data5a.dll"
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall Viewpoint Media Player as requested in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {FC8DDC12-AD36-618C-3142-CDBEAC6D353B} - C:\PROGRA~1\COMMON~1\System\accocdec.dll
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Burn Dvd Mail More] C:\Documents and Settings\All Users\Application Data\Part title burn dvd\Intra grey.exe
    O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} (WildTangent Control) - file://F:\games\WebDriverFullInstall.exe

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. Ashkisher

    Ashkisher Private E-2

    Hello, I am back. I got rid of windows messenger, and viewpoint. (sorry I didn't see it in the add/remove section before) I cleaned up my desktop, and will make folders for other things that don't need to be on there. To answer this question:



    I have no idea what these are. When renaming them, does it matter what I call them, and where should I save them to?

    As soon as I find the acv_tool I will delete 2 of the copies. I was playing around with something and tried different things. I will save it in a better place, I guess I just forgot about it.

    The fixme.reg worked. It dinged and asked if I wanted it added to the registry and I clicked yes. Now, do I delete that shortcut? I saved it to my desktop.

    My computer seems to be working much better, thank you very much. It has a slower start up now, and sometimes explorer doesnt open. It will after a few times, but I think it was because somehow a program called "Antivirus XP 08" got installed on my computer yesterday. I googled it and found out that it was malware and got rid of it instantly, but it took a while to figure it out because of all of the other programs I installed through you guys. It said I had 496 viruses and some were threatening the government etc. Scary stuff. It was all fake, or so I read on google but it changed my background, and wouldnt let me on the internet. Since i got rid of it though all seems to be working good. I do have another question. When I restart my computer, it shuts down, turns back on to a blue screen where it checks a file FAT 32 for consistancy. What is that? Why do I have to have that checked every time I reboot? Also, I was reading through my logs, and noticed that AOL seems to be on the logs quite a bit. I do not use AOL at all and it seems like everytime I uninstall one of the components, it doesn't stay gone. Is there any help for that?

    Anyways, thank you for all of your hard work and help. It is very much appriciated!!! Let me know if there is anything else I should do.

    Here are the requested logs.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just rename them so that the .dlll is .ddd

    It is right where I showed you. Not sure what you mean by finding it.

    You either have hard disk issues or you have something plugged into a USB port that is formatted with FAT32. Check drive K. What is it with TomTom? Also why did you format your Windows boot drive as FAT32. You should be using NTFS. Did you upgrade from an older Windows version to XP? This is not a malware problem. I suggest that you unplug any external drives and see if it still happens and if it does then you should post in the Hardware Forum.

    You still have something from AOL installed. You need to uninstall all of it.

    You need to delete the C:\WINDOWS\MGtools.exe which you put in the wrong place.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Jul 17, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds