Rogue anti-virus removed by MBAM left a big mess - Detailed explanation

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by twistedweb, Jan 26, 2012.

  1. twistedweb

    twistedweb Private E-2

    My PC recently suffered from XP Security 2012. I removed this myself, after 5 seconds with Google I found a registration key, I entered this key, let the program "uninstall itself" I booted the computer into safe mode and deleted the randomly named exe file from the application data folder. I then installed MBAM, updated to current database, and ran the scan. About an hour later it completed and I removed the infected items. Upon restart and normal bootup I noticed the following

    • no desktop icons
    • no right click on start menu
    • no accessories in start menu
    • no administrative tools in control panel
    • task manager disabled
    • IE, Firefox, Chrome crash when started
    • Google search hijack
    • Nothing opens
    • Absolutely no program shortcuts in start menu

    What I've done so far
    - Starting off I had FixNCR on a flash drive, I ran this to be able to open EXE's.

    - Ran rKill, nothing found.

    - After this I ran TDSKiller, nothing was found.

    - I ran AVG command line scanner, nothing found.

    - Edited "DisableTaskMgr" in registry to 00000000 to enable task manager

    - Ran an EXE found on the web to restore Accessories shortcut and administrative tools shortcuts.

    - Ran disk cleanup

    - Made sure HOSTs hasn't been modified

    - Gave up :(


    Current Problems
    • computer is running much slower than before infection
    • browsers crash
    • browser hijack


    Computer Info

    Inspiron 6400
    1.86GHz Cpu
    1GB Ram
    Windows XP Professional SP2, current updates.

    Using AVG 2012 for Anti-Virus


    HiJack This - If it helps.

    I am looking for help to finish this disaster. I can provide any more additional info upon being asked.
     
    Last edited by a moderator: Jan 26, 2012
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?

    If you are still missing some item:

    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:



    Now please follow these instructions:

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds