Right Click Kills Desktop

Discussion in 'Malware Help (A Specialist Will Reply)' started by zelda2727, Oct 5, 2009.

  1. zelda2727

    zelda2727 Private E-2

    Hi there,

    I've been having this problem for just over a month and tried to work it out on my own but so far no luck. What happens is, if I Right Click anywhere on the desktop everything (icons, start menu) will disappear and just leave the wallpaper. I can then only access the task manager via ctrl+alt+del. Once the desktop goes poof the only thing I've found to bring it back is by doing a system restore. I run restore from the RUN prompt in task manager and select a date and let the restore go. And every time it will say that the restore didn't really work and nothing has been changed and I'll just click ok and exit the restore and then I'll have my desktop back.

    I also have problems accessing lot's of files. I read somewhere that I should try to rename explorer.exe and then change it in the registry however when I tried to rename it I got an error that I didn't have permissions. I've also been gettin an error when trying to run Super Anti Spyware. When I click on the shortcut I get an error that says I may not have the appropriate permissions to access the file. I use Avira Antivir and lately it also refuses to start. If I try to start it manually it will just sit there with the hourglass for a min or two and finally do nothing. Although, in a day or two I will probably noticed that it is finally running again.

    Today I noticed a virus or something that kept redirecting me to other websites if I was using google. I typically only use google as my search engine so I'm not sure if this was also a problem with any others. I then ran Mbam and I think that fixed the redirect issue but I'm not entirely sure because I accidentally right clicked my desktop sometime after (I think) and had to do system restore again *sigh* so I'm not sure if mbam fixed the problem or if it was the restore point.

    And NOW since then I cannot run Mbam or Super Anti Spyware. I tried unistalling SuperAntiSpyware and reinstalling it but I keep getting this error

    " error 1321 windoes installer has insufficient privileges to modify this file c:program files\superantispyware.exe

    abort retry ignore"

    if I click retry the error message still stays.. if I click ignore it appears that it is installing the program but afterward I cannot access it.

    I'm not sure what is going on with my pc but I sure could use some help. I'm fairly certain I did all the steps except for running Mbam and SuperAntiSpyware.

    Oh, I also got error #4 while using combofix. I downloaded the .Net frameworks but did not run it again as the instructions don't specify to do so.

    here are all my logs thus far.

    Thank you so much for taking a look!
    Nichole
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Totally incorrect. It has nothing to do with your problem.

    Please DO NOT use System Restore anymore unless we request it. You would only be restoring the malware problems and removing anything we have fixed with scans.



    Please run Win32kDiag as instructed below:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r



    Now weneed to reset the permissions altered by the malware on some files.
    • Download this tool and save it to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). While this is running, you will get several/many popups that have a title FInish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKUS\S-1-5-21-1690550294-2564294346-1321446302-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')

    After clicking Fix, exit HJT.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now uninstall the below old version of software:
    Java(TM) 6 Update 15

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now see if you can run new scans with Malwarebytes and SUPERAntiSpyware.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Then attach the below logs:
    • the win32kdiag.txt log
    • C:\avenger.txt
    • logs from Malwarebytes and SUPERAntiSpyware if they ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Oct 10, 2009
  3. zelda2727

    zelda2727 Private E-2

    ok I think I did it all!

    And just to mention this evening, before I ran any of the steps I accidentally right clicked on my desktop and it did not go poof like before. I'm going to test that again right after I send you the logs just as a precaution.

    I had no problem running Mbam or SAS except.. it takes SAS a really, really long time to open. In fact while opening it the computer freezes for a bit but it does eventually open.
     

    Attached Files:

  4. zelda2727

    zelda2727 Private E-2

    ZOMG, hallelujah!!! I can Right Click again!

    thank you, thank you, thank you!!!!!

    Everything seems to be running ok. I am now able to enable and update Avira (however I think I had avira back before doing this 2nd set of steps. I just hadn't tested it out yet but I do know it did load and appeared active).

    I tried to open Super Anti Spyware a couple more times and it still takes forever for it to open but I'm thinking maybe it just didn't install properly from before when I was having all the problems. So once you give me the go ahead I will uninstall and reinstall it.

    Thanks again for your super help and let me know if there's anything else I should do or any other little creatures attacking my system.

    Nichole ^^

    p.s. sorry it took me a couple days to get online and perform these taskes, I was out of town all weekend.
     
  5. zelda2727

    zelda2727 Private E-2

    Avira has been alerting quite a bit today. I only saw/heard the alert box a few times but upon checking the event queue I saw several more. I did not choose a specific action for any of them, I believe avira responded to them all with "deny access." I'm attaching a log of the events.

    Nichole
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing to be concerned with. This is just things in System Restore which we will cleanup during final instructions.


    You are way out of date with your version of SUPERAntiSpyware. So just to be safe, let's get the current version installed and run another scan.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    Also I want you to run the Win32kDiag again exactly like you did in me previous fix so that we can be sure that all permissions in the Windows folders were fixed. Attach this new log too.

    Now delete the below file:
    C:\WINDOWS\Tasks\Symantec NetDetect.job



    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the new SUPERAntiSpyware log
    • the new Win32kDiag log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. zelda2727

    zelda2727 Private E-2

    Hello again,
    here are my new logs.

    Thanks,
    Nichole
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds