Help!! My desktop has changed!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by The Punisher522, Mar 22, 2006.

  1. The Punisher522

    The Punisher522 Private E-2

    My desktop picture has recently changed to just plain blue and most of my icons are gone. I have already run all the programs that are listed in the malware removal guide. I will post my hijackthis log file. Any help is greatly appreciated.
     

    Attached Files:

  2. The Punisher522

    The Punisher522 Private E-2

    I also can not end any of the system processes in the task manager. It says "the operation could not be completed. Access is denied." I am also posting my ewido scan report as well.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You must complete ALL steps in the READ & RUN ME sticky. This includes step 6 and the two logs from the online scanners must be attached. Also you appear to have ignore step 3 of the READ ME. You have both Avast and Symantec installed.

    Also I have a question. Do you know what the below process is?

    C:\WINDOWS\arservice.exe
     
  4. The Punisher522

    The Punisher522 Private E-2

    The only reason i have two anti virus programs installed is because i ran norton and it found some viruses and then i installed avast and it also found other viruses. I am not sure of what that process is that you posted.
    Thanks.
     
  5. The Punisher522

    The Punisher522 Private E-2

    here is my log for the bit defender virus scan. The panda scan is still going.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But step 3 clearly tells you this is unacceptable. You must uninstall one.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next time please post the log according to the instructions (which would not be a Word file).

    There is one file you should delete that BitDefender could not remove. This is Kazaa!
    C:\Documents and Settings\Garrett\Desktop\My Shared Folder\kmd210_en.exe
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To help keep you moving along, I'm not waiting for the Panda log.
    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the newdotnet7_22.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move newdotnet7_22.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,drjcgvb.exe
    O2 - BHO: Yvakt Class - {DAAC59E5-093D-4D24-A105-55BFE4ACDE14} - C:\WINDOWS\system32\w9seq.dll
    O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad3.exe
    O4 - HKLM\..\Run: [newname] C:\windows\newname3.exe
    O4 - HKLM\..\Run: [q8lg] "C:\WINDOWS\system32\slk8x2peu.exe"
    O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22.dll' missing
    O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Garrett\Desktop\My Shared Folder\kmd210_en.exe
    C:\WINDOWS\system32\drjcgvb.exe
    C:\windows\newname3.exe <--- delete any files using the starting with the text newname and ending in .exe (like newname1.exe, newname2.exe...etc)
    C:\windows\mousepad3.EXE <--- delete any files using the starting with the text mousepad and ending in .exe (like mousepad1.exe, mousepad2.exe...etc)
    C:\windows\KEYBOARD3.EXE <--- delete any files using the starting with the text KEYBOARD and ending in .exe (like KEYBOARD1.exe, KEYBOARD2.exe...etc)
    C:\windows\GIMMYSMILEYS3.EXE <--- delete any files using the starting with the text GIMMYSMILEYS and ending in .exe (like GIMMYSMILEYS1.exe, GIMMYSMILEYS2.exe...etc)
    C:\WINDOWS\system32\slk8x2peu.exe
    c:\program files\newdotnet\newdotnet7_22.dll
    C:\WINDOWS\system32\w9seq.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Mar 23, 2006
  9. The Punisher522

    The Punisher522 Private E-2

    here is my panda log.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing all instructions in message # 8, also do the below.


    C:\WINDOWS\Temp <--- delete all files in this folder
    C:\WINDOWS\keyboard31.dat <--- delete this file
    C:\WINDOWS\newfrn.exe <--- delete this file
     
  11. The Punisher522

    The Punisher522 Private E-2

    Here is my hijack log file after I did all that you said. I still can't change the desktop image. Thanks!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this!

    Fixing Locked Desktop
    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.

    If the above does not work, try applying the registry patch in step 8 of the below link:

    SpySheriff (aka SpywareNo) Removal

    Only do step 8!
     
  13. The Punisher522

    The Punisher522 Private E-2

    Ok I have followed step 8 for the spysheriff removal and i have now unlocked the desktop. I am posting my hijackthis log just to so you can make sure everything is gone. Thanks for all your help!!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  15. The Punisher522

    The Punisher522 Private E-2

    Thanks again for all of your help!!! I just couldn't find out what was causing this problem. So yeah thanks for all your help. You guys are great!
     
  16. The Punisher522

    The Punisher522 Private E-2

    Hey I have one more problem. I can't end any system processes in the task manager. it says access is denied. I don't know what is causing this. And the computer still acts as if there is still a virus or worm on it.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to check to make sure your account has admin priviledges. Instead of using Task Manager, try the Process Manager in HijackThis's Misc Tools. Does it work?

    What does this mean? You need to describe the behavior that makes you say this.

    Run a full scan with Ewido and attach the log from Ewido.
     
  18. The Punisher522

    The Punisher522 Private E-2

    I will be putting up an ewido log in a few moments. I think that there might be some windows components missing because some of my programs on the computer won't start. It says "This application has failed to intialize properly (0xc0000005) Click on OK to terminate the application." It says this for many of my programs but it is only programs that were installed prior to getting the virus.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could try the below but if it does not help, I would suggest you post a question in the Software Forum and provide them the complete details of exactly when you get the error messages and give the FULL error message.

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the below command.
    sfc /scannow

    This may ask for your Windows CD if any system files are corrupted/missing and it cannot find replacements on your hard disk. Let me know what happens.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds