Os, task manager and programs not working

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by katy45, Aug 22, 2011.

  1. katy45

    katy45 Private E-2

    Computer malfunction 7-16-11:

    Not positive of sequence of events.

    1. Programs disappeared from the start menu

    2. Task Manager disabled

    3. Administrative tools --- gone.

    4. Desktop icons --- gone

    5. The desktop would not clear off after closing window.

    6. Could not shut down computer, had to pull electric cord.


    For clarification:

    original unit = Shuttle, Running Win Xp SP2, 512 MG RAM

    Secondary unit = GW, Running Win Xp sp2 (this is fresh install and upgrade from XP Home), 384 MG RAM,

    recently added 1TB drive. Browser = Mozilla Firefox


    When this problem began, on the Shuttle machine, I was in a forum and had just responded to a pm and gone back to reading a thread, briefly, as the unit did either a shutdown or reboot. Since the unit was totally unresponsive, I pulled the hard drive and put it into the GW as a slave, in order to move data files off of it and onto the 1TB.

    NOTE: ALL tests have been run on the GW unit. Internet activity has been limited to basics --MajorGeeks & CNet.

    Something was found and quarantined (CUZ 134).

    GOAL: To have a clean machine and to run FDISK on the Slave drive, that has at least a portion of an OS on it. And to put that slave drive back into the Shuttle box, probably as the C:| drive.

    I don't know what you call this, but to me it's a MAJOR HEADACHE. Please help. Logs attached.
     

    Attached Files:

  2. katy45

    katy45 Private E-2

    For last attachment, and to say Thanks for being here.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?

    ( I will look at your logs while you do the above. )
     
  4. katy45

    katy45 Private E-2

    Hello Tim, So nice to see you. I ran the Unhide but cannot verify everything, due to the fact that what is now D:\ was the initial victim in all of this. C:\ has a fresh install, which does have some kind of problem, just not necessarily visible at this time. Unhide did say that it had done it's magic on C:, D: and E:.

    By accident I failed to mention a couple of things in earlier post, but hoped you'd spot them. Think it was Combo that got hung up on the TB, so I had to run it a second time. Is SASCore part of SAS.exe ? At any rate it could not be removed from the Task Manager long enough to run the tests. There is also a "plugin-container.exe" running that I've NOT seen before.

    I'm brewing coffee and ready to clean this monster, thanks.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I am confused. You do not appear to have any malware issues on the C: drive if that is what you ran the scans on. Are you planning on making the D: drive the boot drive? What issues are you having with that drive?
     
  6. katy45

    katy45 Private E-2

    Yes, D: is to become the boot drive again, in another box. The issues with it are/were the Task Manager, Desktop Icons and the Admin Tools, all either gone on non functional. One concern was, that in moving the drive to another unit it could infect even a fresh install.

    Now that I think about it, Qoobox may have been created at the first run of ComboFix, hence you would not have seen it, sorry. At any rate here is the file from it. Not sure the second file is relevant, better safe than sorry. Thanks
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to reinstall the D: drive as the boot drive and run the scans on it. Remove the C: drive and run Unhide on the master D: drive. Your C: drive is clean.
     
  8. katy45

    katy45 Private E-2

    Will do, Tim but wish me luck, I'm pretty sure that I had not been able to get on the net previously with the D:, but it sounds like a plan. Will be back. Thank you.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. ;)
     
  10. katy45

    katy45 Private E-2

    Oh this is not going so well, one more thing that I had forgotten is that initially when hit, the monitor seemed to go dead/black. So when I moved the GW (Gateway) into play I used the same monitor, no problem.

    First I simply unplugged the C: drive from the GW, and tried to boot to the old D: drive, no dice, it said HD not found. Booted to the CD and asked for Repair of Windows, via Recovery Console, it said to type exit and it would reboot normally for me, wrong ! Says no HD, finally remembered the jumper pins and tried booting again, nothing. Disconnected D: and put C: back in, it's fine.

    Took the D: back to its original Shuttle box, hard to see w/o a monitor...........

    Now what ? Am I just missing something ?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay, we have been stuck at the hospital all day.

    Now to recap, it won't boot to the D: drive. It will boot to the C: drive but you are having problems seeing the files on the D: drive? Can you access the D: drive when it is slaved to the computer?
     
  12. katy45

    katy45 Private E-2

    Hi Tim, Sorry about your time at the hospital, hope in the end it was an improvement. Emergency rooms do that well.

    On the recap, Yes I can access the files on D:, but ONLY when it is slaved and in the Gateway. 2 complete units here. Wish I had a way to decipher info from a COM log, which has a portion that is part ascci and part code, when it should be only ports and ip addresses.

    Is there any way to check D: while it is a slave ? On the Shuttle machine, the case fans are running, the CPU fan runs, but no lights for the CD's nor the floppy, and the monitor is getting a signal, just not the right one ? When there is no signal the monitor has a floating box that reminds one to check signal cable.

    And BTW when you say that C:\ is clean, does that mean, that any found and quarantined items will be deleted at uninstall of cleaning programs ?

    Thanks, glad you're back.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have D: slaved, then re-run SAS and MBAM and make sure they are set to scan both drives. Also re-run Unhide. Then see if you can re-run both ComboFix and MGTools ( C:\MGtools\GetLogs.bat ).

    Attach the new logs.

    It sounds like you have a hardware issue on the Shuttle.
     
  14. katy45

    katy45 Private E-2

    D:\ Will be slaved ASAP and re-runs started. Thanks.
     
  15. katy45

    katy45 Private E-2

    Tim, I sure hope it's your evening to work late. lol

    Anyway there may have been a problem or two, not sure. One the start menu wouldn't clear off after running Combo. I was off line for most of this. Then the naming situation came up, so resolved it, best I could be renaming old ones. Here's hoping for good news.
     

    Attached Files:

  16. katy45

    katy45 Private E-2

    For MG Tools log.:)

    Almost forgot, Combo said it was out of date, but would run minimally (?), anyway that was my choice. do I need to get fresh copy and do it again ?
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I suggest you do is to transfer any important files or data to the C: drive and then reformat and reinstall your OS on the D: drive in the Shuttle. I am not finding any malware in your logs.

    You may wish to post in the software forum for further assistance.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds