Shortcuts don't work

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DaveSch, Aug 8, 2011.

  1. DaveSch

    DaveSch Private E-2

    I'm working on a friends computer, running XP.
    He called for help after he got a pop-up window saying he had lots of malware and offering to clear it for money.
    I booted into safe mode, then updated and ran MalWareBytes. Several malware were found and cleared.
    I ran it again, and found and cleared 3 more.
    On a 3rd run, nothing was found.

    When booting into normal mode, every Desktop and Start Menu shortcut causes the window to open which says "Which program do you want to use to open this file?" No selection actually allows the application to start.

    In Safe mode, shortcuts work properly.

    I have performed all the steps in the sticky message titled "Windows XP Malware Removal/Cleaning Procedure" and am attaching logs in this message and the next.

    Dave S.
     

    Attached Files:

  2. DaveSch

    DaveSch Private E-2

    I'm attaching additional logs.

    Dave S.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. :)

    Try this (IN NORMAL MODE NOT SAFE MODE) considering you have already ran MGTools. C:\MGtools\FixFA.bat <--- Navigate to the FixFA.bat and double click it to run it.

    Now see if short cuts are accessible.

    Also you did not run Combofix which is part of the Read and Run Me First procedures. Please do so now and then also run the below.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Attach all of those requested logs please.
     
  4. DaveSch

    DaveSch Private E-2

    Done.
    It did not fix the behavior.
    I should explain it a little clearer than last time.
    I double-click on WINWORD, for example, and get the window "Choose the program you want to use to open the file".
    If I then choose "Microsoft Word for Windows 95, Word will actually start, and the document within it is full of symbols, perhaps Winword.exe. I can close the document, and then use Word normally..


    Actually, I did run it, but the log didn't turn out as expected. Perhaps because AVG was still active.
    Doing it again:
    Getting an error when I try to uninstall AVG from safe mode.
    I'll upload the log file.
    When I try in normal mode, I can get into Control Panel, but when I double-click on Add or Remove Programs, I get an error "C:\Windows\system32\rundll32.exe Application not found"
    In safe mode, I cannot stop the two AVG services.
    I can and do terminate the avg processes in Task Manager.
    ComboFix says AVG is still running, but I continue.


    Done. Thank you for your efforts.

    Dave S.

    Oops! AVGinst.log won't upload. It is over 6 MB in size.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    try this.

    http://www.dougknox.com/xp/file_assoc.htm scroll down to the 9th fix, an EXE file fix.

    Are you able to uninstall these outdated java versions?

    • Java(TM) 6 Update 2
    • Java(TM) 6 Update 20
    • Java(TM) 6 Update 3
    • Java 2 Runtime Environment, SE v1.4.2_03
    • J2SE Runtime Environment 5.0 Update 6

    Delete this file.
    C:\Documents and Settings\All Users\Application Data\wvt617p653s1oh

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. DaveSch

    DaveSch Private E-2

    Did that.
    Behavior didn't change.

    No. In normal mode, it can't find application rundll32.exe.
    In safe mode, I get a "Add or Remove Programs" popup that says "The Windows Installer Service could not be accessed. This can occur if you are running windows in safe mode, or if the windows Installer is not correctly installed."

    Done.

    Downloaded, but can not install from normal mode because of pop-up window "Which application do you want to use?".
    From safe mode, "Windows Installer" says "The system administrator has set policies to prevent this installation."

    Done and attached.

    No change so far.

    Dave S.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't know if it will help or not (I am thinking not) but try this anyway and see if it changes anything. I will review the logs in the mean time.

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Did that help?
     
  8. DaveSch

    DaveSch Private E-2

    Sorry - no it didn't.
    Though the program did say that anti-virus program could interfere with its effectiveness.

    Dave S.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hang in there. I will get my colleagues to take a look at this for you. :)
     
  10. DaveSch

    DaveSch Private E-2

    I suspect at some point someone will decide that it's not effective use of time to pursue this rather than formatting the hard drive and re-installing everything.

    The owner of this machine is not in that big a hurry to get it back, and for me this is a valuable learning experience - I've dealt with lots of computer malfunctions, but never one this difficult.

    Thanks for pressing on.

    Dave S.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We will persevere don't you worry. ;)
     
  12. DaveSch

    DaveSch Private E-2

    The owner of this computer has contacted me, and we have decided to wait one more day for a solution.

    Tomorrow, if a solution can't be found to fix this, I will save the data, format the hard drive and re-install everything (except the malware, hopefully).

    Dave S.
     
  13. DaveSch

    DaveSch Private E-2

    I dropped in to my local computer store (360 Computers in Winnipeg) and asked the tech support guy about the behavior I was experiencing.

    He referred me to a web site and program.
    He says what I'm seeing is damage to the user profile caused by the malware.
    It is possible that Kestrel13 had me run this program, but the key is, it has to be run from the user profile that is experiencing the problem.
    When I was in safe mode, I was logged in as Administrator, not the user who logs in to normal mode.

    www.doughnox.com/xp/file_assoc.htm
    Download and run EXE File Association Fix
    This will write into the registry.
    Reboot, and I'm in great shape!

    Dave S.

    Thanks again, Kestrel13
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I had conferred with Chaslang and was just typing up a response to your thread. :) Now, are you really positive that everything is running well again? Are there no outstanding issues to be dealt with?
     
  15. DaveSch

    DaveSch Private E-2

    Confirm. I have returned the computer to its owner.

    Dave S.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is what I was hoping you would do, I should have been more specific.
    Very well. :) They can follow final steps.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds