Please help, a virus or worm or something has changed my desktop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Scrubkillers, Dec 25, 2007.

  1. Scrubkillers

    Scrubkillers Private E-2

    My desk top changed about two or three days ago ... i think it was when i downloaded a video and some "active x" requirement...later that day i had a some new icons and popups about spyware removal programs.... after running adware, nortan and sb S&D, they were gone..but my desk top back ground turned red with something about more spyware downloads...since then ... i ran all the above agaian. My desk top is just white and when i right click > properties... a screen that comes up says everything is unavailable.... ithink i followed all the malware sticky..please help

    i dont have anything in my folder though called "MGlogs.zip" ?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the part of the READ ME that explains downloading and Using MGtools? We need this log inorder to help you. If you ran MGtools, please explain what happened and where are you looking for the MGlogs.zip file?
     
  3. Scrubkillers

    Scrubkillers Private E-2

    yes i did run the read me file.... the log just simply isnt in the folder
     
  4. Scrubkillers

    Scrubkillers Private E-2

    also while i am sitting here playing warcraft.... "securepccleaner.com" randomly pops up
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In what folder?

    I cannot help you properly clean your PC until I get the required logs.
     
  6. Scrubkillers

    Scrubkillers Private E-2

    c/MGtools folder
     
  7. Scrubkillers

    Scrubkillers Private E-2

    here they are
     

    Attached Files:

  8. Scrubkillers

    Scrubkillers Private E-2

    think this is it?
     

    Attached Files:

  9. Scrubkillers

    Scrubkillers Private E-2

    not sure if you need all these but here they are
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the procedure again!!! It tells you that the log is C:\MGlogs.zip It does not say it is in the C:\MGtools folder. You are supposed to be attaching the C:\MGlogs.zip file not the individual logs.

    Also we did not say to download MGtools.exe here: C:\protect\MGtools.exe
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You appear to have missed another very important part right at the beginning of the READ & RUN ME which I will quote:
    You need uninstall either Avast or Norton immediately before doing anything else.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: BDEX System - {0EF38B85-63BB-4A3C-B96D-43D8D6C42DBD} - C:\WINDOWS\ttvbonqld.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O3 - Toolbar: The leosrv - {73959F2B-EB03-41D1-8F69-694B7B80D699} - C:\WINDOWS\leosrv.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O21 - SSODL: hjoqor - {A70E04F0-26DE-4B75-8EE2-98B4EBFC1010} - C:\WINDOWS\hjoqor.dll (file missing)
    O21 - SSODL: xcvwer - {FEAC6BEA-983B-4FF3-AFD7-6E6367B0DA88} - C:\WINDOWS\xcvwer.dll

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Owner\Local Settings\Temp\

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  12. Scrubkillers

    Scrubkillers Private E-2

    ok, followed your directions to the T.....
     

    Attached Files:

  13. Scrubkillers

    Scrubkillers Private E-2

    my desktop is still solid white and when i right click the desktop then go to properties.. a box still shows with everything "unknown"
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I hightly suggest that you begin by removing all of the unnecessary junk (media files and more) from your Desktop. Be careful with some of these items you are downloading. They are major sources of infections like you have!!!!!


    Please install Spybot as was requested in the READ ME. Make sure you uncheck the option to install Teatimer. Then run a full scan. After the scan is complete, right click in the scan window and save the log. Attach the log here.

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
  15. Scrubkillers

    Scrubkillers Private E-2

    as requested
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot. Any change to your Desktop problems?
     
  17. Scrubkillers

    Scrubkillers Private E-2

    all that changes is from windows xp view to classic view
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that thumbnail from right clicking on your Desktop??

    There is no General tab on the Properties form and when you right click on the Desktop and select Properties the form should say Display Properties. It looks to me like you are clicking on something other than the Desktop.

    Click Start, select Control Panel, and now select Display. What do you get?
     
  19. Scrubkillers

    Scrubkillers Private E-2

    That is what comes up when i right click on nothing but the desktopthen properties... that is what comes up. Im careful not to be clicking on something.

    when i go to start, control panel - display ... the normal options come up... but no matter what i change the back ground to, it is still solid white.

    its almost like the malware put some sort of screen infront of the desktop to post its own background on if that doesnt sound crazy?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below.


    Fixing Locked Desktop
    • Click Start, select Control Panel, and now select Display
    • Then click the Desktop tab
    • then click the Customize Desktop button.
    • Now in the next window that comes up click the Web tab.
      • Make sure at the bottom that Lock desktop items is unchecked.
    • Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too.
    • Then click OK.
    • Click Apply. And click OK.
    Did that help?
     
  21. Scrubkillers

    Scrubkillers Private E-2

    this worked, what exactly does that do?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does exactly what it says. It unlocks your Desktop. You had a web page locking your Desktop and showing what it want to to show. Now you don't.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds