Malware that removes start menu and icons

Discussion in 'Malware Help (A Specialist Will Reply)' started by MSmith19, Aug 3, 2007.

  1. MSmith19

    MSmith19 Private E-2

    Hi, I have somehow acquired a a virus that upon startup (after every program loads) it removes the icons and start menu (I can then only use programs that I previously opened). I have looked at the GUIDELINES BEFORE POSTING LOGS or whatever it is, tried as much as I could with limited access to my computer. I will post the log in hopes of someone being able to help me. I have ran one click maintenance, spyware blaster, spybot and NOD32 virus scan with no infected files showing but I am almost positive this is malware.
     

    Attached Files:

  2. MSmith19

    MSmith19 Private E-2

    I can also not system restore- upon reboot a blue error message comes up 'system has shut down' but the computer does not reboot. This makes me sick to the stomach because this is a new computer! Thanks for anyones time.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You must rename HijackThis.exe as requested of certain infections will not show up. Please try to do this now.

    If you boot into safe mode, do you have the same problems.

    In normal boot mode can you open Task Manager?

    Is the below something you installed?
    C:\Program Files\AGLOCO Viewbar\Viewbar.exe


    Let's remove a bad service. Make sure you only do what is requested below and match exactly the services mentioned. There are other similarly named services with the words Remote Procedure Call and RPC in them that are valid and you must not touch them.
    • Open Task Manager by pressing CTRL-SHIFT-ESC
    • Select File, New Task (Run...) and enter services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Remote Procedure Call (RPC) MO
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteRPCSE into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    Any change to your status? Attach a new HJT log from a renamed HijackThis.
     
  4. MSmith19

    MSmith19 Private E-2

    Thanks for the help but I've actually managed (by miracle) to figure it out so far, but hopefully you may be able to help me ensure it is fully gone. I located the source- in the few seconds of startup, I opened task manager and saw 'Intel' which I've never seen there before. I ended that task and my toolbar and icons no longer disappeared. I then went on to restore my system- rebooting it and 'Intel' does not appear and my computer seems to be fully functional. Now there is 'C:/Program Files/Intel' but it is merely a readme notepad document that seems to be produced by intel the company- not the covering malware. I ran an online scanner from this site, Kaspersky online scanner and my own NOD32, spywareblaster, spybot and one click maintenance now that my computer is working and there still comes up with nothing. Is it gone? Is there some way to insure it's not laying dorment in my system? Thanks.
     
  5. MSmith19

    MSmith19 Private E-2

    I just walked through your steps (although problem seems to be fixed) and RPC was set on manual (but now 'stopped'), I changed that to disable. There are two RPC's- a locator (which I can't change the startup or status of- locked grey boxes) and another which I disabled. Would the system restore have restored this setting to a functional one (about 5 days ago) anyways? Thanks.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you read my bold print red warning?
    Along with the rest of the text. If you stop and disable the other services, you would be in big trouble.

    Yes a System Restore may have help get around the problem but it would not necessarily remove the infection from your PC.


    Are you saying everything is OK now?
     
  7. MSmith19

    MSmith19 Private E-2

    Everything is working fine now but I am wondering if the malware is actually cleared out or if it might be reactivated. I didn't follow your steps as it seems functionally fixed (I just browsed/explored them persay).

    Have you ever heard of 'Intel' in TM causing such an error/malfunction? Because as soon as I closed that- my system was completely fixed and I was able to system restore and now 'Intel' no longer appears.

    Thanks for the fast help- you guys here are great.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to know if you are clean, run ALL steps in the READ ME because HijackThis logs are not valid indications of a PC's malware status. They are not even close.

    NOTE: SpywareBlaster is not a spyware/malware scanner.

    Malware can and does name itself anything it wants. It will especially try to name itself the same as things that could be valid. It make is easier to hide from you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds