Desktop blacked out, empty start menu, no internet

Discussion in 'Malware Help (A Specialist Will Reply)' started by stejampzy, Sep 2, 2012.

  1. stejampzy

    stejampzy Private E-2

    Hi there,
    I am running a 32-bit Vista PC. Currently and suddenly, I have a blacked out Desktop with almost no icons and the Start Menu is empty. I also cannot access the internet other than when running during Safe Mode With Networking. I have ran all through the Read Me First sticky, and completed all of the requested scans (during Safe Mode With Networking). My Desktop icons have now reappeared (after running MGTools) but they're all greyed out. Is it possible someone can please help with this predicament? I also have a 500GB external HD which I immediately turned off when these issues started occurring, just on the off-chance this would affect the drive and it's contents (300GB of music and pictures). Here are my initial logs. Thank you so much for reading this note!

    -Steve
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You used a more than 2 year out of date version of MGtools. Please download and use the correct version given in the READ & RUN ME and attach the new log. Run it in normal bootmode if possible. Also attach the requested log from Hitman Pro.
     
  3. stejampzy

    stejampzy Private E-2

    Ah, I dl'd a new copy of MGTools but must have ran the old one by accident. Here is a fresh log as well as my Hitman Pro log. Thanks chaslang!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    run RogueKiller and run a scan. After it finishes the scan, select the Registry tab and then select any of the below that exist and then click the Delete button.

    Then immediately reboot your PC.

    Now please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it ( if you are running Vista or Win 7, use right click and select Run As Administrator ). Did that help with your missing items?


    Now uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 7
    Java(TM) 6 Update 21

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. stejampzy

    stejampzy Private E-2

    Hi there. A few things:

    -I ran a Rogue Killer scan and none of registry items in question were found.
    -I did a reboot.
    -I ran Grinler/Unhide and my desktop/start menu items reappeared. (Thanks!)
    -When I tried to uninstall the old software versions, I got a note for each saying "The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance."
    -The current version of Java link lists several Linux and Solaris versions, as well four Windows versions but they're x86 and x64. When I attempted to download, it said something to the effect of them not matching my system and that I need to find a x32 version.
    -Because of these troubles, I didn't run an MGTools log. Is that OK?

    Thanks for your help to this point. Very useful stuff.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then we will come back to this later.

    Please continue and attach the log.
     
    Last edited: Sep 6, 2012
  7. stejampzy

    stejampzy Private E-2

    Log attached. Thank you.

    -Steve
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need an MGlogs.zip from normal boot mode. Can you run in normal boot mode?
     
  9. stejampzy

    stejampzy Private E-2

    Normal mode log attached. Thanks! :)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These logs look fine. From normal boot mode, see if you can now uninstall those old Java versions. If not, use the below to uninstall it:

    Revo Uninstaller


    Then install the current version.
     
    Last edited: Sep 10, 2012
  11. stejampzy

    stejampzy Private E-2

    OK, cool. I was able to uninstall the old Java files in normal mode, and then installed the new version successfully. Here's a log, just in case. Still no internet access in normal mode, but I feel we're getting there.

    Thanks chaslang!!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your last logs which are from normal boot mode, your internet access is just fine. The logs show I can ping google by both IP addresss and by URL
    Code:
    Pinging 74.125.113.106 with 32 bytes of data:
    Reply from 74.125.113.106: bytes=32 time=70ms TTL=49
    Reply from 74.125.113.106: bytes=32 time=70ms TTL=49
     
    Ping statistics for 74.125.113.106:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 70ms, Maximum = 70ms, Average = 70ms
    
    ================================================================= 
    
    Pinging [URL="http://www.google.com"]www.google.com[/URL] [74.125.139.99] with 32 bytes of data:
    Reply from 74.125.139.99: bytes=32 time=49ms TTL=46
    Reply from 74.125.139.99: bytes=32 time=53ms TTL=46
     
    Ping statistics for 74.125.139.99:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 49ms, Maximum = 53ms, Average = 51ms
    
    ================================================================= 
    Doing nslookup google.com 
    Server:  cdns02.comcast.net
    Address:  75.75.76.76
    Name:    google.com
    Addresses:  2607:f8b0:4009:800::1003
       74.125.139.101
       74.125.139.100
       74.125.139.139
       74.125.139.102
       74.125.139.138
       74.125.139.113
     
  13. stejampzy

    stejampzy Private E-2

    Interesting. Something is certainly blocking me from accessing the internet in normal mode via both IE and Firefox. It's the standard "Cannot Display this Page" error message. I guess something must be turned off or misdirected in my Internet Options? I'm not sure what's going on then.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try uninstalling Avast and rebooting. It seems to have a broken firewall which could be an issue.
     
  15. stejampzy

    stejampzy Private E-2

    Hmmm. I uninstalled Avast and restarted, and now the internet does indeed work! Weird. I don't have an antivirus on now though. :confused
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So redownload and install a current version and see what happens.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  17. stejampzy

    stejampzy Private E-2

    Yes, I did try this however it caused my internet to not work in normal mode again. There must something wrong with my settings? Or possibly a combination of the antivirus being on and having UAC disabled?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    UAC would not have anything to do with it. If Avast is causing you continued problems then use something else (like Avira).
     
  19. stejampzy

    stejampzy Private E-2

    Awesome. I dl'd and installed Avira and my internet is now accessible in normal mode. I went through the final steps and toggled system restore with a reboot in between as was suggested.

    At this point (and maybe this is a question for the hardware forum?) I'm only having issues with my external HD. I turned it back on and reconnected it now that my computer is functioning normally, but it seems the computer isn't able to locate any of the files on the external drive. When I hover over the F: drive it says "Space Free 206GB, Total Size 465GB", which seems about right, but when I click on the F: icon it says Folder Empty inside of it.

    Is there something I can do to search for and find (recover?) these files? To repeat, I didn't run any of the previous antivirus or malware scans on this external drive.... though in retrospect maybe I should have?

    Thanks chaslang.
    -Steve
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running the unhide program with the external harddisk plugged in. Otherwise you may need to run a manual change for file/folder attributes from the command prompt.
     
  21. stejampzy

    stejampzy Private E-2

    Yep, that worked. I ran Unhide and it showed all my F: drive info (external HD). Thanks again, chaslang, for all of your time and help!

    -Steve
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds