XP - No Task Bar/Desktop Icons

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cylon5, Jan 3, 2008.

  1. cylon5

    cylon5 Private E-2

    Trying to fix my brother-in-law's XP machine... Original problem was no task bar. no desktop icons, no task manager in normal or safe modes. I have followed the XP cleaning procedure detailed by Chaslang in these forums, and now can access task manager in both normal and safe modes... However, still no desktop icons or task bar appearing in normal mode. Task manager reports 98 to 100% usage of Sprtcmd.dll.

    In safe mode, the desktop icons and task bar will appear momentarily, followed by a dialog box requesting a response regarding continuation in safe mode. If I respond with YES, then the icons and task bar appear momentarily, and the pattern repeats.

    Also, Spybot reported 23 occurrences of Smitfraud-C. After requesting cleanup, I ran the "Smitfix" registry fix, and see no more reports of this particular malware.

    Attached is the MGTools log file.

    Thanks for any help!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Viewpoint Media Player

    Now download and install:
    Java Runtime 6

    Please empty all that is in this folder:
    C:\Documents and Settings\Administrator\Local Settings\Temp\

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  3. cylon5

    cylon5 Private E-2

    Thanks for your response. Since I can't get to a stable task bar even in safe mode, how can I access the add/remove programs function in the control panel to uninstall Viewpoint Media Player? Can I run a command line to do so, or is their some other way?

    Thanks!
    Cylon5
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't worry about that ...it's minor ...just do the rest. :)
     
  5. cylon5

    cylon5 Private E-2

    TimW,

    Okay... I downloaded Java Runtime 6 to the desktop of the affected machine. I've tried to run it in both normal and safe modes, but get absolutely no reaction from the system. To make sure that the installer was not corrupt, I launched it on another PC and it started as it should. Seems its not my day.

    Any concerns with this, or should I move on to running MGTools\analyse.exe?
    Thanks again,

    Cylon5
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just move on ....:(
     
  7. cylon5

    cylon5 Private E-2

    Attached is the new MGlogs.zip created after performing requested tasks. Below is the text of the Avenger log:

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Services\kxamvnxy

    *******************

    Script file located at: \??\C:\WINDOWS\qfvxaabu.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:



    Could not open file C:\Documents and Settings\Administrator\Application Data\??sks\r?gsvr32.exe for deletion
    Deletion of file C:\Documents and Settings\Administrator\Application Data\??sks\r?gsvr32.exe failed!

    Could not process line:
    C:\Documents and Settings\Administrator\Application Data\??sks\r?gsvr32.exe
    Status: 0xc0000033

    File C:\WINDOWS\plite731.exe deleted successfully.
    File C:\WINDOWS\plite7~1.bat deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean ....are you still having any problems? Can you now download the Java files? Your anti-virus program may be blocking the install ...make sure it is disabled when you go to install the Java ...or try in safe mode.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I forgot to add:

    Delete this:
    C:\WINDOWS\0.log

    And empty all of this:
    C:\Documents and Settings\Administrator\Local Settings\Temp\
     
  10. cylon5

    cylon5 Private E-2

    At this point I still have no task bar or desktop icons in normal mode, and explorer is not running when I check task manager. In safe mode, the desktop appears briefly, followed by a dialog box asking if I want to continue in safe mode, or launch system restore. If I answer "yes", then the desktop again appears briefly, and the pattern repeats. If the logs show "clean", then perhaps the malware has borked windows files/registry.

    I'll try installing the Java files again and go from there. If you have any other suggestions, please let 'em fly.

    Thanks.
    Cylon5
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try pressing CTRL+ESC to access the taskbar.

    If CTRL+ESC didn't make it come back, then the program that displays the task bar most likely isn't running.

    Press CTRL+ALT+DEL to fire up the task manager. Now on the File menu, select New Task (Run...). Type in "explorer" and press OK.

    Does that bring it back? If so, go to start / run / type "sfc /scannow" without quotes and have your xp cd handy. Run it twice.
     
  12. cylon5

    cylon5 Private E-2

    Okay...

    I have booted twice into normal mode, once seeing the task bar and start button appear for about 30 seconds, not seeing it at all the other time. In both cases, opening task manager reveals that the process "sprtcmd.exe" is using 98 to 100% cpu utilization. Waiting 20 minutes after booting does not reduce this utilization. The system is so tied-up, I can't reliably access task manager.

    In safe mode, every time a try to enter a New Task (run) item, the task manager closes down on me just as I finish entering "explorer". I cannot overcome this situation at present.

    I feel like we're getting closer... Do you think the "sprtcmd.exe" is a problem that should be removed?

    Thanks!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    sprtcmd.exe is a process from Belgacom belonging to SupportSoft sprtupdate. This is installed by some ISPs ...you can safely kill it in the task manager ...disconnect from the internet (physically remove the cable) and reboot...tell me what happens.
     
  14. cylon5

    cylon5 Private E-2

    Killed "sprtcmd.exe" from starting via task manager and rebooted with no internet connection... No task bar/icons appeared after waiting 10 minutes. At that point after trying CTRL-ESC with no luck, I launched explorer.exe from the task manager and the task bar w/start button (no desktop icons) appeared for about 15 seconds, at which point explorer.exe application quit running (according to the task manager". I could launch explorer.exe again via the task bar, but after 15 seconds it died once more.

    Cylon5
     
    Last edited: Jan 4, 2008
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Humm....try this and tell me what happens.

    Bring up task manager and hit new task ...type "restore" without quotes ...if it gives you a window ...double click the restore exe ...see if you can restore to a time before this happened.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can do the same thing with "sfc /scannow" ---(without quotes and note the space).
     
  17. cylon5

    cylon5 Private E-2

    Arghh ! :confused As soon as I clear the entry line for Start Task (run) under Task Manager, I get a Dr Watson message now that kills the Task Manager application. If I can browse to the location of restore.exe, I might be able to launch it that way. Where might I find it?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The folder is in your system32 files ....but since you can't get to run or search or start or keep task manager up long enough ...?

    You may be stuck with doing a repair installation ( assuming that you originally didn't remove any registry items).

    Boot to xp cd / choose install (not R for recovery) / f8 to the agreement / when it finds the previous install, then choose R for repair and let it rip ...it will not remove any of your data.
     
  19. cylon5

    cylon5 Private E-2

    Looks like I'm out of luck... My brother-in-law does not have the original copy of XP for his PC, so a repair install will not be possible. I told him he'll need to buy a new copy of XP if he wants his PC to run again.

    Thanks for your help on this !

    Cylon5
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If he has the product key (often on the bottom or back of the computer) he can use a borrowed cd as long as it is the same edition of xd ...(Home, pro ....OEM, etc.)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds