Disk Antivirus Professional- two programs left in control path notification area icon

Discussion in 'Malware Help (A Specialist Will Reply)' started by cassandra1, Mar 15, 2013.

  1. cassandra1

    cassandra1 Private E-2

    Downloaded Malware Bytes and Hitmanpro. ran both. Malware only found 3 and hitman only found 1. Concerned my computer still infected for two reasons.

    1. in the control panel icons-under customize, two virus are still showing but only lets me turn notification on / off, NOT DELETE. first one is called: DED1DC88D656...Disk Antivirus Professional 3.7.25

    and second one is called: 44377152.exe

    2. When I reboot and start computer not in safe mode, the windows explorer doesn't load properly and it takes about 20 minutes where it won't let me do anything until explorer gets itself sorted out (not kidding).

    Believe it must still be infected. Cant seem to get rid of the virus. Help!
    Cassandra
     
  2. cassandra1

    cassandra1 Private E-2

    Disk Antivirus Professional- imbedded into explorer /zeroaccess possibly involved.

    Was infected with Disk Antivirus Professional. Went online and downloaded Malware Bytes and Hitman Pro. Ran both. Still experiencing 2 issues: slow to load, with DLL file loading error at start up, folowing by 20 minute (!!) waiting for explorer to load.

    Then found your fabulous site. Went through the steps recommended Windows7 malware removal. LOaded the 5 softwares recommended and went through the steps. ATTACHED 5 logs.

    RogueKiller took me to a screen on ZeroAccess (Max++) CLSID Variante (But the video tutorial was super fast and all in French on the screens, so it didn't match up).


    Operating in SAFE MODE NOW. Still have Explorer loading issues.

    Two problems.
    First the audio service isn't running.

    Second, the Control Panel > Notification area icons>

    two files that are malicious appear:
    -> DED1DC88D65678F30000DED0FDBD7E99... Disk Antivirus Professional
    -> 44377152.exe

    I don't know how to remove. They only appear here where you can either turn on or off viewing the icon. But in the computer program area, they must be hidden. HOW CAN I REMOVE?

    Please help?
    Thank you so much in advance. I have now spent 20 hours on this and don't know what else to do.
    Thank you in advance,
    Cassandra
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Disk Antivirus Professional- two programs left in control path notification area

    Welcome to Major Geeks!

    See our instructions again. You should not be fixing anything with RogueKiller during initial scans. You deleted/fixes things that were normal!!! Yes the Zero Access items were problems but not the others.

    Make sure that you have disabled UAC as requested in the READ & RUN ME. Per your logs, you have not done this. Please do that now and then reboot into normal mode to continue with the below.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\cassandra.THEARF\AppData\Roaming\Microsoft\Windows\Templates\56kgoqxx153683v2h17e12r78
    C:\ProgramData\DED1DC88D65678F30000DED0FDBD7E99
    C:\Windows\Tasks\SpeedyPC Pro.job
    C:\Windows\Tasks\SpeedyPC Update Version3.job
    C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job
    C:\Windows\Tasks\SpeedyPC Registration3.job
    C:\Windows\Tasks\SystemToolsDailyTest.job
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.
    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 16, 2013
  4. cassandra1

    cassandra1 Private E-2

    Re: Disk Antivirus Professional- two programs left in control path notification area

    chaslang,
    First let me say you are an angel of mercy and a mortal God! Thank YOU!! I can now log on not having to use safe mode....and explorer seems to be working again.

    Had to reboot once due to a super long loading time for windows that kept in spin mode without loading.

    PROBLEM: Under "hidden icons" on the bottom right of the screen, option "customize" .... unfortunately found the two virus documents still listed.
    -> DED1DC88D65678F30000DED0FDBD7E99... Disk Antivirus Professional
    -> 44377152.exe


    Attaching the logs requested as well. Had to run the fix below in safe mode since the virus wasn't letting explorer load previously.
     

    Attached Files:

  5. cassandra1

    cassandra1 Private E-2

    Re: Disk Antivirus Professional- two programs left in control path notification area

    Chaslang, First let me say you are an angel of mercy and a mortal God! Thank YOU!!

    Ran through your fix below. Most of it had to be done in safe mode because I could get explorer to work in normal mode and it wouldnt stop trying to load.

    Things seem to be working great with the reboot now!

    Only PROBLEM is under "show hidden icons" on bottom right of control panel, when you click "customize" > Notification area icons>

    the two files that are malicious STILL appear:
    -> DED1DC88D65678F30000DED0FDBD7E99... Disk Antivirus Professional
    -> 44377152.exe

    How may I get rid of these? Thank you again so much!!

    Attaching two logs as requested.
    cb
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Disk Antivirus Professional- two programs left in control path notification area

    You're welcome.
    See the below and let me know if that helps:

    http://windows.microsoft.com/en-us/windows-vista/remove-icons-from-the-notification-area-system-tray


    We have one more left over from Speedypro to remove.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  7. cassandra1

    cassandra1 Private E-2

    Re: Disk Antivirus Professional- two programs left in control path notification area

    OK one down- one to go. Successfully adding text below to the registry and received confirmation. That part is good.

    The first part doesn't look like it worked.- it doesn't remove it- it just "hides" the icon from notificaiton. Seems like if those files are still listed and all I do is hide them, they'll come back. Do you know if I can actually REMOVE them permanently/delete them forever?

    http://windows.microsoft.com/en-us/windows-vista/remove-icons-from-the-notification-area-system-tray

    Thanks again!
    cb
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Disk Antivirus Professional- two programs left in control path notification area

    I'm not sure. I have never seen this before. Can you attach a snapshot that shows exactly what you are seeing?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds