Logged on, Desktop had Disappeared...

Discussion in 'Malware Help (A Specialist Will Reply)' started by aclark88, Jan 18, 2013.

  1. aclark88

    aclark88 Private First Class

    Logged on and the desktop had disappeared and came up with some error windows then restarted and it was back to normal, ran the scans and have uploaded them to see if there is anything wrong or it was just a one off.

    I think RogueKiller was the only scan that picked up something and HitMan Pro didnt produce a scan log?

    Thank you...
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-898199155-3521637707-3960584212-1000\$3eabdd521e069bd34dafb54243696002\n.) -> FOUND
      [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$3eabdd521e069bd34dafb54243696002\n.) -> FOUND
      [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$3eabdd521e069bd34dafb54243696002\n.) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now click the Files/folders tab and locate these detections:

    • [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$3eabdd521e069bd34dafb54243696002\@ --> FOUND
      [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-898199155-3521637707-3960584212-1000\$3eabdd521e069bd34dafb54243696002\@ --> FOUND
      [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$3eabdd521e069bd34dafb54243696002\U --> FOUND
      [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-898199155-3521637707-3960584212-1000\$3eabdd521e069bd34dafb54243696002\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$3eabdd521e069bd34dafb54243696002\L --> FOUND
      [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-898199155-3521637707-3960584212-1000\$3eabdd521e069bd34dafb54243696002\L --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Now reboot and re-run both RogueKiller and Hitman and attach both of those logs as well.
     
  3. aclark88

    aclark88 Private First Class

    Think I messed up, thought I only had what you said checked, but it deleted everything in rogue killer?!

    What do I do?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Probably not a problem, but attach the resultant log.
     
  5. aclark88

    aclark88 Private First Class

    Ok just ran the 2 programs you asked for.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you still having, if any?
     
  7. aclark88

    aclark88 Private First Class

    None now, when I ran rogue before it'd give me an internet pop up with a video of how to get rid of a problem, it doesnt do that now.

    All good?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All good.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds