My Explorer bar and desktop icons are playing up - please help!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chocolateflowers, Sep 19, 2008.

  1. chocolateflowers

    chocolateflowers Private E-2

    Hello everyone I am a completely noob when it comes to computers and software and I'm really pulling my hair out over my windows xp software.

    I have scoured the internet and I've gone through dozens of forums in aid of help to fix this bugger once and for all but I still have not managed to find a solution to the disappearing desktop icons and explorer bar.

    These are the methods I have tried:

    Ctrl Alt Delete and typing explorer.exe in File + Run - It will only let me use explorer for a while till it disappears again.

    Right clicking my desktop to show icons (won't work as I can't access the right click facility)

    Downloading SuperAntiSpyware,Spybot Search and Destroy, Virtumondo, Combofix, Abexo Free registry cleaner... and all the software you could possibly think of

    I have tried a system restore

    I have also changed and retyped in the value of explorer.exe in my shell registry list...

    The only method that I have not yet tried is the pasting of a log etc - I simply do not know how to do this!

    Please help me out, I would be very grateful. I think I may have ruined my father's laptop :S
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. chocolateflowers

    chocolateflowers Private E-2

    Hello

    I cannot locate my combofix log but this is what I have from SuperAntiSpyware:

    (attached)
     

    Attached Files:

  4. chocolateflowers

    chocolateflowers Private E-2

    To add:

    Before I encountered the explorer disappearing I had a BIG issue with something called 'MS Antivirus and also Micro Antivirus or something like that, I managed to get rid of that manually by going into regedit and deleting their sources. Soon after when I restarted my pc the whole explorer fiasco started :S

    I am also not sure if its a software issue i.e. registry values etc
     
  5. chocolateflowers

    chocolateflowers Private E-2

    I hope somebody can help, I really can't see myself forking out 60 pounds at a repair shop :S
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you were messing with the registry without a back up..then yes it could be that.

    You still need to go thru all the instructions so that we can see what is going on in your computer.
     
  7. chocolateflowers

    chocolateflowers Private E-2

    I have done everything and it still keeps disappearing and reappearing ... :S
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have done everything, then you need to attach the resultant logs. I can not help you with out seeing them!
     
  9. chocolateflowers

    chocolateflowers Private E-2

    I attached the SuperAntiSpyware log above
    here is my Combifix log :
     

    Attached Files:

    • log.txt
      File size:
      14.5 KB
      Views:
      1
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Need still the MalwareBytes log and the C:\MGLogs.zip

    In the meantime:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\WINDOWS\System32\msvcrt2032.dll

    Now continue on and get me the other logs.
     
  11. chocolateflowers

    chocolateflowers Private E-2

    I installed the MalwareBytes but after the installation had completed nothing happened? I will try the fixME etc now
     
  12. chocolateflowers

    chocolateflowers Private E-2

    I tried to delete the msvcrt2032.dll but a popup came up and read:

    'Cannot delete access is denied' Make sure the disk is not full or write protected'
     
  13. chocolateflowers

    chocolateflowers Private E-2

    Oh, I've managed to get Malwarebytes running, will post a log in a sec :)
     
  14. chocolateflowers

    chocolateflowers Private E-2

    attached is the Malwarebytes
     

    Attached Files:

  15. chocolateflowers

    chocolateflowers Private E-2

    Can anybody help?:(:cry
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run Malwarebytes, only this time, have it fix everything it finds!

    Then, assuming you have run the MGTools as instructed, run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the new log from MWGrun the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the new log from MWB's.
     
  17. chocolateflowers

    chocolateflowers Private E-2

    I am pretty sure I did select the option to fix the objects infected, but I maybe wrong so I'll do that again. I am not sure if a log is needed for Malware?

    And in the mean time I'll download the other programs you asked for :)
     
  18. chocolateflowers

    chocolateflowers Private E-2

    I have now attached both files as requested...
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You downloaded MGTools to your desktop and ran it from there ----> the instructions where to move it or install it on the C drive as in C:\MGTools.exe. Had you just followed all the instructions that were clearly laid out to you, we would have been done and you clean about 10 posts ago.

    Now you have to uninstall/ delete all the MGTools items. Download it again and this time put it directly on the C:\ drive.

    But first:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\ATHAN
    C:\WINDOWS\System32\msvcrt2032.dll
    C:\WINDOWS\Fonts\F14DD386.EXE

    Now download MGTools as instructed and run it and attach the C:\MGLogs.zip.
     
  20. chocolateflowers

    chocolateflowers Private E-2

    Hello again

    Sorry for the late reply.

    I tried to delete the msvcrt2032.dll again and still a popup came up and read:

    'Cannot delete access is denied' Make sure the disk is not full or write protected.'

    I also tried to delete the Fonts\F14DD386.EXE but a pop up came up which read that somebody is using the program or something to that effect...

    What to do?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds