Quick Launch icons unclickable in XP

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrfike, Jul 30, 2013.

  1. mrfike

    mrfike Private E-2

    Hello,
    The quick launch icons on my desktop taskbar will only open when right clicked, selecting open. I recently downloaded some software that was hacker/mal/spyware, and was able to remove it, but I think some elements or registry entries might have remained.
    There are a few other things that have been buggy too, but this is the main problem.
    I read a few other threads and tried some of the software fixes, but to no avail. Here is my Speccy file for my cpu.

    Operating System
    Windows XP Professional 32-bit SP3
    CPU
    Intel Pentium 4 640
    Prescott 90nm Technology
    RAM
    1.00GB Dual-Channel DDR2 @ 265MHz (4-4-4-11)
    Motherboard
    Hewlett-Packard 09F8h (XU1 PROCESSOR) 65 °C
    Graphics
    Default Monitor (1024x768@60Hz)
    Default Monitor (1024x768@60Hz)
    Intel 82945G Express Chipset Family (HP)
    Hard Drives
    37.3GB Western Digital WDC WD400BD-75LRA0 (SATA) 37 °C
    Optical Drives
    HL-DT-ST DVD-ROM GDR8164B
    Audio
    Realtek High Definition Audio
     
  2. sasha1976

    sasha1976 Private E-2

    did u go into ur control panel and uninstall??
     
  3. mdonah

    mdonah Major Geek Extraordinaire

    As you said, there may be remnants of that malware left behind. Head here and run the programs and post the results as directed.

    @Sasha1976

    The "built-in" Add or remove Programs tends to leave remnants behind. I and other contributors to the forums use Revo Uninstaller which gets rid of registry items and folders left behind by the program's uninstaller.
     
  4. mrfike

    mrfike Private E-2

    Thank you for the qui ck reply. i used the control psnel and also '" should j remove it" software which found some things which weren't on. adx/remove. i will post the results when i am able to run the programs you recommended. Thanks agaun
     
  5. mrfike

    mrfike Private E-2

    I tried the Revo uninstaller, it didn't find anything else.
    I regularly run CCleaner, and did so again (a few times).

    I have attempted to complete the steps for "Read & Run Me First...", for Windows XP with some issues:

    1. Both versions of Hitman give me the same error message "...is not a valid WIn32 application" (Running XP 2002, 32 bit)

    2. Malware Bytes gives co-creation error (I did have an old version, which I uninstalled), and then after installing the new version get this error:"Runtime error 372 Failed to load control WebBrowser from ieframe.dll. Your version of ieframe.dll may be outdated. Make sure you are using the version of the control that was provided with your application."

    I am including the following which I was able to run:
    RKreport[1].txt log from RogueKiller.
    TDSSKiller log
    MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe
    Screenshot showing win32 info

    Thanks again for any help/ideas!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have a little junk on your system. I will have you do the following and then return this thread to the software forum.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Cheers TimW for looking at this thread in regards to malware.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below very old versions of software:
    Java 7 Update 13

    Now install the current version of Sun Java from: Sun Java Runtime Environment Make sure that when you see the form asking about installing Ask Toolbar that you uncheck this.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=Ve...e={installDate}
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=Ve...e={installDate}
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=Ve...e={installDate}
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=Ve...e={installDate}
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Documents and Settings\Crystal Freese\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll (file missing)
    O2 - BHO: TBSB07898 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll (file missing)
    O3 - Toolbar: Coupons.com CouponBar - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll (file missing)
    O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - (no file)

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Documents and Settings\Crystal Freese\Application Data\BabSolution
    C:\Documents and Settings\Crystal Freese\Application Data\Babylon
    C:\Documents and Settings\Crystal Freese\Application Data\DSite
    C:\Documents and Settings\Crystal Freese\Local Settings\Application Data\Strongvault Online Backup
    C:\Documents and Settings\All Users\Application Data\2b28273026333427272731_c"
    C:\Documents and Settings\All Users\Application Data\Babylon"
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{8660E5B3-6C41-44DE-8503-98D99BBECD41}"=-
    "{ae07101b-46d4-4a98-af68-0333ea26e113}"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "bProtectTabs"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. mrfike

    mrfike Private E-2

    Hi chaslang, thank you for your help with this problem!
    I have attempted to uninstall the Java 7 Update 13, however, encountered this error, which according to Microsoft "This behavior does not occur in fhe following products: Windows XP ..."

    The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode or the Windows Installer is not correctly installed.

    * I followed the instructions here without any success. System account has full permissions, no security tab on root drive and other solutions (I think) not applicable.

     
    Last edited: Aug 3, 2013
  10. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi some info below to help with logs files

     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just skip the installation of Java for now and continue with the rest.

    The fix I gave needs to be run but it may not cure your problem with items being unclickable. There may be other work to do that has nothing to do with this junkware.
     
  12. mrfike

    mrfike Private E-2

    These log files are attached. Thanks everyone for helping out with these problems!!!!

     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Any change to your problem?
     
  14. mrfike

    mrfike Private E-2

    Yes and no. The quick launch icons still don't work without right-clicking and selecting open, however it appears that the desktop icons are clicable now.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely this is not a malware issue. What happens if you create a new quick launch item? For example, drap and drop one of the links from y our Desktop ( that you say now work ) onto the quick launch bar to create a new quick launch item. Is it now clickable to run?
     
  16. mrfike

    mrfike Private E-2

    Creating a new quick launch item gets same results, unclickable, but openable via right-click and selecting open. The items- files, programs etc- on the desktop that ARE clickable are actually located on the desktop, so appears to be shortcuts that are not working properly. Shortcuts located on the desktop are still unclickable, but will open via the right-click/open method.


     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below but make sure you disable all protection software and also shutdown all browsers before running this fix.

    Now run the C:\MGtools\FixFA.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    This will run very quickly. If prompted about the a registry change/patch being added to your registry, make sure that you allow it.

    Then reboot and see if there is any change to Desktop links and Quick Launch links.
     
  18. mrfike

    mrfike Private E-2

    No changes after running mgtools/fixfa.bat

     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay a few more things to try and then I will have to send you to the Software Forum for this non-malware problem.

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the Windows fix from here >> http://support.microsoft.com/fixit/

    Now click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    Now reboot your PC again and see if there is any change. If not, I suggest that you post about this in the Software Forum now.
     
  20. mrfike

    mrfike Private E-2

    Sorry it's been so long to reply to this thread! I've been very busy with work and family issues.
    I ran the tweaking windows repair, and it ran fine ,a couple error messages from ipconfig (unable to start), and the computer did not restart, it began to shut down and then just stopped shutting down, I waited about 7 minutes and manually restarted.

    The microsoft fixit page tools were not helpful, each of them (except the automatic update tool) gave me this error:
    "This troubleshooter does not apply to your system
    We're sorry, but this trouble shooter is not compatible with your current system's configuration"

    The microsoft automatic update fixit tool initialized. but then repeatedly gave me this error: "The troubleshooter has experienced an unexpected error and cannot continue".

    The sfc /scannow asked for the xp disc which I haven't ever seen for this cpu, which was bought from a friend who builds computers about 6 years ago!

    So I suppose I should go to the software forum, and post there, as some malicious software must have been installed on my computer, or existing software manipulated in some way?
    Thanks for all the time and effort you've put in to work with me on this problem!

     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You need to get the proper Windows version disc that it is requesting. You could need more than one because it will sometime ask for a very specific service pack level disc. You need to do this before even bothering to go to the software forum becuase without repairing the system files that are either corrupted or missing, it would be a waste of time to continue.

    You only had minor nuisance adware/junkware. None of these would cause damage to your Windows files. This damage was caused by something else. Possibly crashes, power hits while PC is running due to storms or other, turning off Windows improperly ( i.e., holding in the power button until it shuts down )....etc.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds