Help!! Virus - No desktop, start button or anything

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by letsgojets, Mar 26, 2008.

  1. letsgojets

    letsgojets Private E-2

    OK... I need some major help.... I clicked on a button on a website yesterday and AVG instantly alerted me of a Trojan, so I chose to remove it or quarantine it, I really don't remember what the option was exactly. I then was getting an AVG pop-up warning frequently. So I launched Ad-aware and downloaded the updates so I could scan for problems...... I decided to reboot my computer to run Ad-aware fresh, but my computer bootsed to a Java-runtime error (actually two errors) and when I clicked ok, the only thing visible is the wallpaper: no icons, no start button, nothing - and when I hit ctrl-alt-del, it tells me "Task manager has been disabled by your administrator"

    I tried rebooting in safe mode and I still get no desktop icons nor the start button. I was able to get a DOS prompt and ran Ad-aware that way (but in safe mode). Ad-aware did find a couple of things and the Idiot I am, I didn't write them down. I do think one was a Trojan32 or something similar.

    I do not get the Java runtime error anymore, because I saw that both of those erroes mentioned Roxio and I think it was through msconfig that I unchecked everything I could find labeled Roxio.

    I can't seem to do anything with the infected pc because of the booting problem, so I'm not sure if I can go through the "Read & Run Me First" thread......

    If someone could please help me out, I would be so grateful........ ugh

    Thanks,
    John
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try running as much of the READ & RUN ME as possible. You may be able to open up Task Manager and run things from it by using New Task (run...). Also if necessary you may have to download files onto another PC and copy to this PC via a CD, flashdrive...etc.
     
  3. letsgojets

    letsgojets Private E-2

    Ok.... I ran through as much as I could with the limitations I have.... Here is what I did, which was in safe mode, because I can't do anything in normal mode:

    Ran ccleaner (accessed via cmd prompt)..... used ccleaner to fix registry issues and uninstall programs not needed

    launched Disk Defragmenter via dos, but when I click 'analyze' or 'defragment,' it is unresponsive

    downloaded Diskeeper Lite to a flash drive from good computer and tried to install on infected computer, but ger the following msg "The system administrator has set policies to prevent this installation"

    Used task Manager to launch msconfig and changed tartup to normal
    - rebooted per the prompt to have msconfig changes effective
    - tried normal reboot, but got the Java Runtime error (its back)- 2 errors, both mentioning Roxio and only wallpaper showing
    - booted in safe mode

    Ran ccleaner again

    couldn't figure out how to launch explorer to change view to show hidden syste, files & folders

    tried to move on to the cleaning procedures: saved SuperAntiSpyware, Malwarebytes and MGtools to flash drive from good pc (alreadt have Spybot), but can't install anything, getting same msg as when tried to install Diskeeper Lite

    running Spybot now (although I can't search for updates)

    I need to go to sleep, but I'll post results from Spybot and I'll run Ad-Aware, which I updated yesterday, and I'll post those results tomorrow

    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not requested in the READ ME. Please only do what we ask you do.

    Also not requested in the READ ME. Please only do what we ask you do. If you don't follow our instructions we cannot help you.

    From Task Manager you can click File, New Task (Run...) and enter explorer and click OK. It may or may not run. Depends on all of your problems.

    MGtools does not install anything. Did you actually try running it?
     
  5. letsgojets

    letsgojets Private E-2

    I tried running Disk Defragmenter and Diskeeper Lite because in the "Read & Run Me First" thread, at the very top is -"Try these tips first for slow PC issues: Basic computer maintenance everyone should do"......... I followed the steps in that link, which included the defragging...... I didn't realize I was not supposed to to go through that

    Spybot was running when I went to bed last night and this morning, there was a warning window up that said "There were problems in the include file C:\Program Files\Spybot-Search_Destroy\Includes\Trojans.sb: See 'Includes errors.log' for details"....... I clicked ok and it finished - the result: "No immediate threats were found"....... I accessed the "Includes errors.log" and it contained the following: "C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Zlob.DNSChanger | (85\.255\.11[0-9]\.[1-2]?[0-9]{1,2}[,]?\s?)(85\.255\.11[0-9]\.[1-2]?[0-9]{1,2}[,]?\s?)+"



    I tried opening Explorer through Task Manager, but it tells me "Windows cannot find 'explorer'

    I had not tried MGTools, because I thought it would give the same error I ws getting from other progs I tried to run: "The system administrator has set policies to prevent this installation"

    I have copied MGTools from the flash drive to c:\ and am now running it........ it has finished and I have attached the MGlogs.zip file.

    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are only there for people complaining that their PC is slow. They have nothing to do with malware removal. We only put them here because many people post slow PC problems in the Malware Forum and as stated in that part of the READ ME, slow PC's are not always due to malware.


    Yes and I can see why in your MGlogs.zip file. A copy of Windows Explore is not where it needs to be. See if you can do the below.
    • From Task Manager, select File, New Task (Run...) and enter cmd and click OK
    • if the above works properly, a command prompt window will open
    • in the command prompt window enter the below command and hit enter. Note there are spaces after the word copy and after the first appearance of explorer.exe
    copy C:\WINDOWS\ServicePackFiles\i386\explorer.exe c:\Windows\explorer.exe
    • if the above all worked without a problem, then try to open explorer again from Task Manager per my previous instructions.
    • If explorer is found and runs, your Desktop should return.
    • Any luck? Based on my information below, I'm not too sure the above will help.
    However based on your logs, I can see something you did before coming here has either stopped or removed many key Windows Services. As such, you are in the wrong forum. You will need to get your Windows Services started again and that is a job for the Software Forum. If the files are really missing, you may have to try a repair install (you need your Windows CD) or you could be looking at a reinstall depending on what is really wrong. Sometime similar issues occur when someone improperly stops and disables the Remote Procedure Call (RPC) service which many other services rely on.
     
  7. letsgojets

    letsgojets Private E-2

    Just got home from work and followed your instructions...... The explorer.exe file successfully copied to c:\Windows\ and the dektop has returned!!

    What do you suggest I do from here?

    Thanks
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your Windows XP SP2 CD?
     
  9. letsgojets

    letsgojets Private E-2

    The CD I have is "Windows XP Home Edition Including Service Pack 1a"

    I have the Dell sticker on the side of the PC with the serial and it says "Windows XP Home Edition"
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before trying the second step further down, try step 1.

    STEP 1 - Try System Restore

    Please try using System Restore to return your PC to a point in time before these problems began. If this works, it may be the best solution. I System Restore does not work, move on to Step 2.


    STEP 2 - Only if the above does not work.
    Okay but you now have SP2 installed, thus your CD while still having uses, is less useful then actually needed. If the below procedure winds up asking for your CD, it will revert your system back to SP1a level. That means you will have to redownload and install SP2. You don't have too much of a choice though since your system is really messed up and could possibly require a reinstall. What exactly was done to this PC before coming here? As I said before, you don't normally see a problem like this unless someone has been playing with disabling services that they should not be touching.

    Try the below.

    Click Start, Run, and type sfc /scannow into the run box and click OK. There is a space after the sfc. This will run System File Checker which attempts to repair or replace missing or corrupted System Files. While doing this, it may or may not ask you to insert the Windows CD. Don't insert the CD, unless it asks for it.


    Let me know the results.
     
  11. letsgojets

    letsgojets Private E-2

    I tried to run system through msconfig (I don't have the Start menu, so I accessed it through Task Manager) and I got the following msg " System Restore is not able to protect your computer. Please restart your computer, and then run System Restore again."

    I rebooted in normal mode to see if I could do this and it just goes to the desktop background - no icons or start button (like before)

    So, I rebooted into Safe mode with Command Prompt and tried again, but received that same message above

    Should I proceed with Step 2?... and if so, I don't have the Start button, so can i run sfc /scannow through Task Manager?
     
  12. letsgojets

    letsgojets Private E-2

    I just got my hands on:

    Reinstallation CD - Windows XP Professional Service Pack 2

    Will this CD be helpful?

    Also, I tred to do the scannow through the comman prompt since I don't have the Start menu, but get the following message:
    windows file protection could not initiate a scan of protected system files. error code 0x000006ba [RPC server unavailable]

    Is there a way I could run scannow?

    Thanks
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really since it is not the same as your installed Windows version. You will have to use your XP Home Edition SP1a disk to repair or reinstall but as stated below, you need to continue this in the Software Forum.

    No! This is happening due to all the services that have been stopped. You need to post in the Software Forum. You are probably looking at a reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds