No icons on Desktop & Windows Installer wont stop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LocalLoot, Jun 8, 2011.

  1. LocalLoot

    LocalLoot Private E-2

    SO this is my first to use a forum. I think i followed all the isntructions and attached the logs.
    Details.
    6//1/11- got jacked. typical pop-up kept trying to sell me their AV. i saw that my entire desktop had no icons and my start menu and all my programs were gone. I went to C:DocumentsSetting/myname/ and all was gone..nothing showing. The first thing i did was logout and log back in as an admin under another user profile. I loaded MB and MS Security Essentials and ran them. They removed the Trojan (see MB log attached) and then loggeg back on to my profile. Found the malware gone but all of the same symptoms above - no programs or icons. I contacted my IT person from work and logged into my desktop and did some poking around and saw that all the data folders were still there, just hidden by adjustments to permissions. He made some changse that returned my profile (my documents, favorites, etc) but nothing to get my desktop icons or all my program icons working.
    6/1/11 - 6/7/11: performed the steps in MG for malware. (ie Purchased full version of MB and SuperASpyware). See logs attached. Issues:
    1. Don't have my desktop icons
    2. I get Windows Installer pop-ups for Norton everytime i open a new program or try to right click while cursor over any file (like to reanme or view propperties) I am forced to cancel the windows installer several times to get it to stop attempting to install...or it errors out b4 completion. I tried uninstalling Norton using AddRemove but it failed. I went to the main program file folder and removed the Symnatic folder and did the same for each profile on C drive. I tried using a utility on Noron site for removing all Norton and it failed.
    3. Windows Intaller pop-up for HP Smart Web printing.I tried removing HP software and it failed.
    4. My Adobe documents don't display the typical icon for known adobe docs.
    5. I cannot open MS Word or any Adobe program without an error. Adobe Acrobat 8.0 says i need to first open PS first - similar to when you first purchase and load...however this is CS3 suite that's been loaded and used frequently for 18 mos.
    Please addvise.
    Please help me get
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Last edited: Jun 8, 2011
  3. LocalLoot

    LocalLoot Private E-2

    forgot to include the logs!! duh.
    Also, my IT guy from work ran the bleeping computer exe file. that's how i think i got my files back. they were all hidden in 4 Temp Internet folders.
     

    Attached Files:

  4. LocalLoot

    LocalLoot Private E-2

    Also, my IT guy from work ran the bleeping computer exe file. that's how i think i got my files back. they were all hidden in 4 Temp Internet folders.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sure. That's good! Be sure to attach the rest of the requested logs please. :)
     
  6. LocalLoot

    LocalLoot Private E-2

  7. LocalLoot

    LocalLoot Private E-2

    which logs am i missing?
     
  8. LocalLoot

    LocalLoot Private E-2

    I never found the MSlog.zip in the C:\MGtools folder. I ran MGtools twice to be sure and no zip file was created. ?? ...so i grabbed all the .txt files and the hijackthis.log out of the Mgtolls folder andd copied and zipped them. see attached. I also attached the most recent RR log.

    let me know if anything is missing.

    Thanks in advance for your help. Trying to juggle this fix with a new baby!

    Have a Big day.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See the instructions again!!!!! We specifically tell you the log is not in the C:\MGtools folder. It is C:\MGlogs.zip


    You need to attach the log from ComboFix
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: The first instructions in the READ & RUN ME tell you that you must not have more than one antivirus program installed. You have the below 3 installed:
    • Microsoft Security Essentials
    • Symantec AntiVirus
    • Trend Micro Internet Security
    Due to doing this, you now need to uninstall ALL of them. Then you need to reboot. After reboot, you need to do the below. Do not do the below until all of the above are uninstalled. If you have problems uninstalling any of them then use this to uninstall them >> Revo Uninstaller

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt that has previously been requested.
    • C:\MGlogs.zip
    Make sure you tell us what problems you still are having.
     
  11. LocalLoot

    LocalLoot Private E-2

    I am so sorry. I am inexperienced. I thought i only had one anti-virus (MS Security Essentials) and one firewall (Trend Micro, pre-installed by Dell).
    Re:
    MS Sec Essentails -- When pulled up thru Start\programs menu, MS Security Esentials says that it is not activated (turned off) and when i try to change the status to active it is denied via an error. So i thought this meant it was turned off.

    Trend Micro -- i went to the security settings in control panel and turned the firewall off. It indicated the firewall was Trend Micro. I assumed this was only a firewall - not a anti-virus. Maybe they are one in the same? please advise.

    Symantic -- I thought this also was not active - i had trouble getting it to uninstall thru standard control panel\add remove programs. and i tried tirelessly to remove all the folders in each of the program files and so thought it was mostly gone and not active.

    I forgot to put this in the previous post: When i attempted to run MGTools it said MS Security Essential was still active and it was a risk to continiue...i by-passed the first warning but when the 2nd warning came up I close it out w/out continuing. THerefore there is no log from MGTools from 6-2-11.

    HOWEVER...since backing up my core files, i decided just now to run it anyway. See attached log of MGTools. When it was complete, the desktop icons came back! :-D ...but the windows installer keeps popping up (still) each time i open any program or attempt any right click funtion on a file or folder. Its an HP system triggering it.

    Thanks in advance. I am trying to follow the instructions but I guess not very well. There are so many notes andd sub-notes to the instructions, you have to almost print them if you are not at all familiar with the jagon. I'm getting used to it though. Bear with me please.

    My next step...
    I will use the REVo Uninstaller to remove all three of the mentioned APs and then run the C:\MGtools\GetLogs.bat as advised in your last message.

    Again thank you. I appreciate your patience.
     

    Attached Files:

  12. LocalLoot

    LocalLoot Private E-2

    I used REVO to remove Symantic and MS Essentials. I was not able to find Trend Micro in the add remove menu, therefore REVO was not able to help.
    However, i ran the MGtools anyway and attached the new log file.

    Let me know if anything else is needed.

    Thank you.
     

    Attached Files:

  13. LocalLoot

    LocalLoot Private E-2

    Should have mentioned:
    MS Office programs still wont open. I went to the Start\programs\microsoft office tab and selected Excel andd then Woerd and recievced error. Microsoft Installer opens each time and then Probelm with Shortcut error says:

    "This patch package could not be opened. Verify the patch package exists and that you can assess it, or contact the appliccaiton vendor to verify Windows installer patche package."

    Unfortunately i don't have the installation disc. it was put on by the previous company's IT and then the company was bought out so no one has the disc or key. :(

    A similar issue happen when i open Adobe Photoshop. Says i need to repair or re-install.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    The point here is not whether it is off or on. The problem is that you have more than one AV installed which is a very bad thing to do.

    Your logs show TrendMicro Internet Security which is a full security suite that includes antivirus, antispyware, firewall and more. Even if you some how only have the firewall active, you have the security suite and it is not recommended to have multiple security suites trying to control Windows Security Center.

    Again, it is whether it is installed at all that we are concered with and it is in your logs.

    MGtools does not do this. I believe you mean ComboFix.

    No this is a log from ComboFix. ComboFix and MGtools are not the same thing.

    Most likely this will be something you need to work out in the Software Forum as it is an issue with Windows Installer not malware. You may have a broken or incomplete uninstall or install that is causing this problem.


    I'll take a look at you logs and other messages now.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to this MGlogs.zip file you attached. MS Essentials is still running in your logs. You should have made sure you completed the uninstall and you should have rebooted afterwards before running MGtools. You still even had Revo running. You need to attach a new log from MGtools. That is, you need to rerun C:\MGtools\GetLogs.bat and then attach the new MGlogs.zip file. But make sure that you have rebooted since uninstalling everything and do not have Revo running anymore.
     
  16. LocalLoot

    LocalLoot Private E-2

    Thanks for the info/education on the AV -- re Trend Micro. ;)

    Your correction regarding ComboFix is spot on. I got mixed up with MGTools.

    Getting the AV back in order:
    I want to be able to have just the one AV once all this is fixed.

    Removing Trend Micro: The issue is that there is nothing in the Add/Remove utility to be able to use REVO or windows add/remove utility to remove it. According to the Windows Security Center, Trend Micro is the firewall and is active. So where is the program?? I checked and there are folders in the C:program Files folder.

    Microsoft Security Esentials; Although i used REVO to remove this AV is shows in Security Center that MS Security Essentials is the AV and active. ??? not sure how this is possible if it was all removed by REVO.

    Symantic_ One of the Winddows installer pop-ups indicated it was still attempting to install Symantic. Again not sure where this file could be hidden since running REVO. ???
     
  17. LocalLoot

    LocalLoot Private E-2

    Just saw yuour post. Will do as advised.

    However, i did reboot and reran REVO again since the windows installer indicated Symantic still trying to load. it found another file. but then i didn't reboot after that so REVO was running when MGTools was run the 2nd time.

    Will send log very shortly.
     
  18. LocalLoot

    LocalLoot Private E-2

    Other possible issues:

    WIndows Secutity says that AV is "ON" and yet REVO has been run removing MS Security Essentials. It might be the Trend Micro Systems?? however, it notes that the program is MS Security Essentials. ??

    Thanks again for your expertise. I appreciate it.
     

    Attached Files:

  19. LocalLoot

    LocalLoot Private E-2

    From my cursory (and novice) review of the logs, it appears that REVO did not completely remove the MS Secrutity Essentials. As well, the Trend Micro AV/firewall is also present and running.

    As mentioned in earlier post, there is no Trend Micro displayed in the C:\control panel\add and remove programs folder making it tough to remove. I tried usng REVO but was only able to search/find and find programs with presence in the Add and Remove folder. However, there is at least one folder related to Trend Micro in the C:\Program Files folder.

    Is there possible another program that safely and completely removes AV programs that I can use to remove Trend Micro and Ms Security Essentials.

    What about this idea: download a trail version of Trend Micro so that it displays properly in Add adn Remove Programs and then use something like REVO to remove it completely??

    Any suggestions and feedback are appreciated. Thanks in advance.

    Randy
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Refer to the below link for removing Trend Micro. I'll clear up some more from the other two AV's. Plus remove a little bit of malware.

    How to uninstall my Trend Micro program using the Trend Micro Diagnostic Toolkit

    Java(TM) 6 Update 25
    <--- uninstall outdated java.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O15 - Trusted Zone: *.picnik.com
    O15 - Trusted Zone: *.wellsfargo.com
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    SavRoam
    ccEvtMgr
    ccSetMgr
    SNDSrvc
    
    File::
    C:\Documents and Settings\All Users\Application Data\17293092
    C:\Documents and Settings\All Users\Application Data\~17293092
    C:\Documents and Settings\All Users\Application Data\~17293092r      
    c:\windows\system32\NavLogon.dll
    c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{184F7BF4-4F64-41B6-B77C-A913B40CB036}\mpengine.dll
    c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    
    Folder::
    c:\program files\Symantec AntiVirus
    c:\program files\Microsoft Security Client
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A621B45A-D138-4A95-BE10-7CABA05EF94E}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSC"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
    Last edited: Jun 11, 2011
  21. LocalLoot

    LocalLoot Private E-2

    OK. I had to take a break from this for a couple days. But back in action tonight.

    I followed the instructions and attached both the combofix.txt and Mglogs.zip files.

    However some surprises:
    Trend Micro Uninstall removed Trend Micro. But did not help to remove any remnants of MS Security Essentials. Logs show it is still present and active. There is no MS Security Essentials in the Add and Remove utility.

    When ComboFix warned about having MS Security Essentials running I went forward with the process anyway. Tired of dealing with this. if it ruins something at this point it can't be any worse.

    When loading Java6 an error occurred, even after attempting to load 3-4 times including downloading program to desktop and attempting to load from there. Error message:

    Error 1317 - An error occurred while attempting to create the directory C:\Program Files\Java

    Thanks again for all the assistance. I am sure we will find the combination for success soon.

    Updates on performance:
    MS Office WOrd, Excel still not loading/working. Problem w/Shortcut error. Even when attempts to open are done from Start-->All Programs-->Microsoft Office. However Outlook opens w/no issue.
    Still getting the window installer errors looking for Symantic somewhere in programs file.

    Have a Big day.
    Randy

    Side note - prior to running any of the steps suggested in the last post, my mouse pad stopped working. Called Dell Support and they verified (as I did) that he drivers were current/updated. They then ran some diagnosis thru F12 reboot that indicated the mouse pad was available and working. Then the hadd me check the bios which indicated there was an error some where. Not that this has anything to do with what we're working on, but thought i should mention.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Will post an additional fix down below.


    Possible a permissions issue within your files/folders. Try running the below and rebooting and then see what happens:

    Resetting Registry and File Permissions

    Yes C:\WINDOWS\system32\msiexec.exe (which is Microsoft Installer ) is showing as running in your logs and this should only be running when an install or uninstall is being performed. Hence you likely have one or more broken/incomplete installations or uninstalls. This is not necessarily a malware issue and you may need to address these and similar issue in the Software Forum. However you can try running the below to see if it picks up on anything.

    Windows Installer CleanUp Utility


    Now let's run one more fix with ComboFix to cleanup a few more leftovers.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  23. LocalLoot

    LocalLoot Private E-2

    Here are the 2 new logs.

    Notes:
    Had an issue downloading Resetting Registry Permission file to C:\program files. SO i downloadded it to the C:\drive. Also same prob downloading the Windows Installer Cleanup to c:\program files\windows resource kits. So instead i installed to C:\ and had no issue.

    still having windows installer attempts and MS Office programs won't load as before.

    How would i best transfer this thread to the software forum?

    Thank you again for all the detailed help.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You should post about this in the Software forum. It is much better to start a new thread. If this were moved there, many people would ignore it since there are a lot of posts in it already. You should only state the exact problems you are currently having in your new thread, but you can put in a link to the fact that you just had malware removed here.

    I'm going to give you final instructions but I'm not going to have your clear System Restore by toggling it as we would normally do because you still may need to use a restore point.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds