Fake Windows Security Center Icon Problem Again

Discussion in 'Malware Help (A Specialist Will Reply)' started by Maverick10, Jan 26, 2009.

  1. Maverick10

    Maverick10 Private E-2

    Hi All,

    I have a problem that seems to becoming more common. I've run the cleaning steps recommended in this thread:
    http://forums.majorgeeks.com/showthread.php?t=159787

    I'm attaching my own logs and am hoping you can help me finish the job. Please let me know next steps when you can. Thank you very much in advance.
     

    Attached Files:

  2. Maverick10

    Maverick10 Private E-2

    Here's the final log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Viewpoint Media Player
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 7"
    Java(TM) SE Runtime Environment 6 Update 1

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    c:\program files\AskBarDis

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  4. Maverick10

    Maverick10 Private E-2

    Thanks for the response. I followed the steps you recommended. The only issue was that I couldn't delete Askservice.exe - The error message reads:
    "Cannot delete AskService.exe: Access is denied.

    Make sure the disk is not full or write-protected and that the file is not currently in use."

    Other than that -- looking promising I think. New log is attached.
     

    Attached Files:

  5. Maverick10

    Maverick10 Private E-2

    TROUBLE! I now have a boot up problem .... Please help. Windows XP won't load now --- Error message states:

    "Windows could not start because the following file is missing or corrupt:
    <Windows root>\system32\hal.dll"

    Please help resolve. I thought things were going well but clearly not now.

    Thanks in advance.
     
  6. Maverick10

    Maverick10 Private E-2

    Nevermind last post ... I've got windows back up and running from OS CD.
     
  7. Maverick10

    Maverick10 Private E-2

    Check that -- getting same error message when I attempt to boot. Please advise.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to go to the recovery console with your cd and change the directory to d ( or whatever your cd drive is) then use these commands.

    expand d:\i386\hal.dl_ c:\windows\system32\hal.dll. Substitute d: for the drive letter of your CD. Once you have expanded the file type "exit" to exit the Recovery Console and restart the computer.
     
  9. Maverick10

    Maverick10 Private E-2

    The expand command fails and the only way to boot up is through the Recovery console with DVD / CD. My next guess is to grab my important docs and files, and try a Windows XP repair installation?

    Please let me know if you agree or disagree or what you'd recommend now... Thanks for all the help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try this:

    Boot from your CD and follow the directions to start Recovery Console. Then:

    Attrib -H -R -S C:\Boot.ini
    DEL C:\Boot.ini
    BootCfg /Rebuild
    Fixboot

    (enter after each command).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds