Bkdr Haxdoor.bc

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Lemboskities24, Mar 30, 2005.

  1. Lemboskities24

    Lemboskities24 Private E-2

    156 virus found
    151 deleted
    5 cleaned

    I'll test out my stuff now? unless you want me to do something else first?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    See if that took care of the problem, I have one at my office that has this SAME problem.
     
  3. Lemboskities24

    Lemboskities24 Private E-2

    No good, if you can think of anything else I'll try nearly anything.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I am having this same problem with a computer at work, I have tried everything I know of and cant come up with anything. I am testing registry values and some others things. I will come up with anything I will let you know ASAP.

    Also, if you come up with anything let me know.
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Lets give this a shot, let me know if this works for you.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file desktopfix.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the desktopfix.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge, click YES!
     
  6. Lemboskities24

    Lemboskities24 Private E-2

    Ok I did that part, what should I do now...restart? or try and install the game now?
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I dont think its going to work because its been tested twice, we are trying to come up with something. Hang in there!
     
  8. Lemboskities24

    Lemboskities24 Private E-2

    will do, I've done too much to this machine to give up now.
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Same here, I have 2 at my office that has this and 2 more users here who have this. Its something in the registry, I do know this much and its related to C:\Desktop. I have been researching this new baddie and havnt came up with anything yet. Will let you know as soon as something comes up. Thank you for your patience:)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try looking at this!

    Click Start, Run, and enter regedit and click OK. This will bring up the registry editor.

    I want you to navigate first to the below key and find out what the Data value is set to:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

    then in the right pane locat the key name "Desktop" then look at what the Data value is! It should be:

    %USERPROFILE%\Desktop

    Then navigate to the below key and find out what the Data value is set to:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

    then in the right pane locat the key name "Common Desktop" then look at what the Data value is! It should be:

    %ALLUSERSPROFILE%\Desktop

    Its sounds to me like both of them are set to point to the same place (profile).
     
  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I have figured it out! :D

    Click Start > Run > type in regedit

    Navigate to and modify the registry entries below:

    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

    Select "Desktop" and change the value to %USERPROFILE%\Desktop



    HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

    Select "Desktop" and change the value to %USERPROFILE%\Desktop



    HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

    Select "Desktop" and change the value to %USERPROFILE%\Desktop



    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

    Select "Desktop" and change the value to %USERPROFILE%\Desktop



    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

    Select "Desktop" and change the value to %ALLUSERSPROFILE%\Desktop



    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

    Select "Common Desktop" and change the value to C:\Documents and Settings\All Users\Desktop




    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

    Select "Desktop" and change the value to %USERPROFILE%\Desktop



    HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

    Select "Desktop" and change the value to C:\Documents and Settings\LocalService\Desktop



    HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

    Select "Desktop" and change the value to C:\Documents and Settings\NetworkService\Desktop



    Now, with the viewing of hidden files & folders enabled per the tutorial go into C:\ and delete the folder C:\DESKTOP. Reboot and problem should be resolved!
     
  12. Lemboskities24

    Lemboskities24 Private E-2

    When I try to delete C:\DESKTOP I get an error saying
    "Desktop is a Windows System folder and is required for Windows to run properly. It Cannot be deleted"
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You must delete ALL the registry entries first. Then after the LAST one is deleted then you reboot and delete it.
     
  14. Lemboskities24

    Lemboskities24 Private E-2

    When I try to delete C:\DESKTOP I get an error saying
    "Desktop is a Windows System folder and is required for Windows to run properly. It Cannot be deleted"

    Also under HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

    shouldn't that value be changed too? I have it as C:\Desktop right now
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes! that should be set to:

    C:\Documents and Settings\NetworkService\Desktop

    Remove ALL of the keys, reboot and then delete the folder.
     
  16. Lemboskities24

    Lemboskities24 Private E-2

    Did what you said but I still can't delete that folder. However I was assuming that by "remove" you meant "modify" those registries that could be why.
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    All your supposed to do is edit them and change the values.

    Try this:

    Download the attached file to a folder where you can locate it. And then extract the fixdesktop.reg file from the ZIP file. Double click on the fixdesktop.reg file and when prompted to add the changes into registry say yes.


    Edit by chaslang: To change to my more recent version of fixdesktop.zip
     

    Attached Files:

    Last edited by a moderator: Apr 7, 2005
  18. Lemboskities24

    Lemboskities24 Private E-2

    I should restart after doing this?
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    After editing the keys I requested OR downloading the fix. Reboot and delete C:\DESKTOP
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know BJ is in the process of replying but make sure you have the current version of the attachment that I just recently uploaded. Download it again to be sure.
     
  21. Lemboskities24

    Lemboskities24 Private E-2

    It worked!!!...All of my desktop icons are back from the dead. I still have to see if I can work my games though.
     
  22. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The games wasnt the problem we was after, the desktop problem is what we was after!!!!!!!!

    We Won Chas! :D

    Was it the .zip file that did it for you?
     
  23. Lemboskities24

    Lemboskities24 Private E-2

    Oh...yeah it was the .zip file.

    Well about the games, you got anything for that?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now on to the other problem threads! Make sure you post the current ZIP file as posted here. If I add to it, I will let you know. Right now it looks like we do not need to add anything.
     
  25. Lemboskities24

    Lemboskities24 Private E-2

    I would really appreciate if you could find something out about why my games don't run, I am starting to go through withdrawls.
     
  26. Lemboskities24

    Lemboskities24 Private E-2

    nvm problem solved
     
  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Glad you got it fixed!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds