Slow computer, desktop sometimes says "Active Desktop Recovery"

Discussion in 'Malware Help (A Specialist Will Reply)' started by smssoleimani, Feb 27, 2008.

  1. smssoleimani

    smssoleimani Private First Class

    I went through the necessary "Read & Run Me First" and there were a few malicious files found, but there are continuing problems, like the sometimes appearing "Active Desktop Recovery". I attached the files that the forum post said to attach.

    Thank you,

    Steve
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi smssoleimani,
    Welcome to the Malware Forum!

    I am not sure what you have is malware. Please do the following:


    1) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger


    2) Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O22 - SharedTaskScheduler: homina - {df8c3aed-b58e-4bcb-96b3-aa1b7bbdbbd4} - (no file)

    After clicking Fix, exit HJT.


    3) Download and install Erunt. Use it to create a backup of your registry.

    4) Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file ....make sure you let it run completely.

    abri
     
  3. smssoleimani

    smssoleimani Private First Class

    OK I did everything you directed me to do. I attached the file you requested.
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi smssoleimani,
    How is your computer doing?
    abri
     
  5. smssoleimani

    smssoleimani Private First Class

    Everything is going well, thanks for your assistance. I thought that everything was OK so I did the System Restore "disable, and enable" to make sure I can't restore (if needed) to a infected period of time.

    Thank you,

    Steve
     
  6. abri

    abri MajorGeek

    Hi smssoleimani,
    If the problem you initially had with Active Desktop is gone, then please go ahead with the final cleanup instructions:
    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds