Weird Symptoms persist

Discussion in 'Malware Help (A Specialist Will Reply)' started by elmerbumpkin, Oct 10, 2005.

  1. elmerbumpkin

    elmerbumpkin Private E-2

    Hello,
    I followed the guide to get the computer back to operational, and in safe mode, was able to find and eliminate alexa and the elitetoolbar, or so I think. One symptom that is still present is the window for the folder view options never populates. I follow these instructions:

    Windows XP
    - Right Click Start.
    - Select Explore
    - Select the Tools menu and click Folder Options.
    - Select the View Tab.

    When the View tab displays, it is blank, as in empty, completely white. So I can't know for sure that all files are displaying and therefore able to be scanned.

    Also, when I would open My Computer and hit the Search toolbar, the frame on the left side of the window would populate with a NetZero search window to search the web, not the computer!?!? After running the processes y'all recommend, now the left frame is blank.

    Any ideas, or further info or data I should provide?

    Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. elmerbumpkin

    elmerbumpkin Private E-2

    Thanks chaslang, the laptop is at home, but I'll run the HijackThis procedure during lunch and post the results.

    Yes, I am able to log in with Admin priviledges.


    If it matters (in this forum anyway), the Outlook Express on that machine has become corrupted, or some of the .dbx files are, and without being able to view all system and hidden files, I can't even back those up for any OS-related maintenance....but we'll get to that soon enough, thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you have Admin priviledges before when trying to configure viewing of hidden files?
     
  5. elmerbumpkin

    elmerbumpkin Private E-2

    here is the log......

    I also noticed that the Recycle Bin is no longer on the the desktop...

    thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ok! I'll ask the same question again:

    Your system would appear to be al messed up. None of the typical stuff one would expect to find loading at start is there.

    Have you been experimenting on your own and having HJT fix lines?
    Or is this HJT log edited?
    Or are you using HJT's filter to filter lines?
    Was the log from Safe mode?

    Your antivirus application is not even running.

    Also did you do something to corrupt or try to uninstall Internet Explorer? HJT cannot even determine the version info for Internet Explorer.

    Seem more like you have a corrupted installation right now!

    You can have HJT fix the below lines (make sure no browsers are running when you click Fix):
    O13 - DefaultPrefix:
    O13 - WWW Prefix:
    O13 - Home Prefix:
    O13 - Mosaic Prefix:
    O13 - FTP Prefix:
    O13 - Gopher Prefix:
    O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
    O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
    O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
    O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)

    Then exit HJT. And post a new log. I doubt the above has anything to do with your reasons for posting here.
     
    Last edited: Oct 12, 2005
  7. elmerbumpkin

    elmerbumpkin Private E-2

    >>But did you have Admin priviledges before when trying to configure viewing of hidden files?

    yes

    >>Have you been experimenting on your own and having HJT fix lines?

    yes, before I found this site I ran HJT, used a couple of on-line analysis sites, and fixed some of the lines. I also ran WinPatrol to stop some of the startup stuff, pokapoka.exe, etc.

    >>Or is this HJT log edited?

    no

    >>Or are you using HJT's filter to filter lines?

    no

    >>Was the log from Safe mode?

    no

    >>Also did you do something to corrupt or try to uninstall Internet Explorer?

    no, IE seems to work (launch, surf) just fine.

    >>may be corrupted!

    maybe so, weird things like the programs submenu under the start menu just says (empty), even though I can navigate through MyComputer to the programs, and they are all there.


    Even now, when I run HJT, and check the boxes next to those items, the button for 'fix checked' never 'enables' so I can perform that action!?

    thanks for the help so far
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly what did you remove! There is a load of standard stuff missing from your log. If you had HJT installed properly you may be able to restore from the Backups.

    Disable WinPatrol?

    After doing the above post a new HJT log.
     
  9. elmerbumpkin

    elmerbumpkin Private E-2

    HJT was not configured correctly to backup, now it is. No backups to choose from, and I didn't keep record of what actions I took.

    WinPatrol disabled.

    New log attached.

    Thanks for the help.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange! Are you sure about that? The default is to always make backups and it saves them into a Backup folder where HJT is running from. Where did you have HJT running from before coming here to Majorgeeks? Perhaps you have backups there.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixIT.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixIT.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes!
    Now post a new HJT log.
     
  11. elmerbumpkin

    elmerbumpkin Private E-2

    there are no other folders/directories within the HJT directory.....I've always had it in a folder within Program Files directory. ??

    did the regfix you described, ran HJT again, log attached.


    I was able to finally get OE working correctly, and have backed up all the mail and address books. That was the only thing on the machine I still needed to backup.

    I can always do a clean install of XP at this point if that's easiest, but I'd like to get this diagnosed if possible.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Part of the registry patch did not work. Download and try this one.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixIT2.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixIT2.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes!
    Let me know if you get any error messages. What problems are you still having?
     
  13. elmerbumpkin

    elmerbumpkin Private E-2

    alright, got that one done, new HJT log generated after scanning....

    at this point, the only weird things (that I know of) are:

    the start menu programs tab still says "empty", even though, if I right click on the start menu and select 'explore', I'm able to see all the program directories and the shortcuts. When I switch to XP start menu (I still like the "classic"), and hit "All Programs", nothing pops up or out or anything.

    when I navigate to Folder Options and select view, the window of choices (like show hidden files, etc) does not populate. If I randomly click the mouse within that window, the 'apply' button goes active, but I don't select it.

    when I go to start menu and hit search (btw, from what I can tell, everything else works under the start menu except for the programs tab), the window now comes up with the normal 'computer-based' choices to search, and the little dog appears. Right when a lot of this started, the left hand pane would populate with a netzero websearch window, and go online. Even though I can enter files and search the local drives, as soon as I hit search I get a small error box with a yellow triangle/exclamation point, and nothing else happens.

    those are the main anomolies at this point.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think most of your problems are due to deleting things with HJT that should not have been deleted. You may want to try creating a new user account and see how it looks and works. If it looks okay, you could delete the old one. You also will need to uninstall and then reinstall (in the new account) a few items (like Symantec for one and maybe your printer tools/drivers).

    I'm not sure what is blocking the fixing of those O15 lines but they are still there. Do you have any items running that could be blocking registry changes. I do see RegCompact. Also does your user account have Administrator priviledges?
     
  15. elmerbumpkin

    elmerbumpkin Private E-2

    I made a new admin account and logged in, same symptoms were there for that user as well.....really weird. I don't doubt that I screwed things up with the HJT actions I took.....

    I don't see anything peculiar running that would block the reg changes, my user account does have admin priviledges.....

    I'm gonna run XP setup and see if that takes care of the remaining things...all the data is backed up and safe.

    I really appreciate all your help and ideas. Thanks.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You did! That is obvious based on what we see running and loading in your log. Whether it is the cause of all your problems, I do not know.

    You could first try
    sfc /scannow from a command prompt window

    If that does not help, you could boot from your WinXP CD and use the repair option. You definitely need it. There seem to be a bunch of things not loading and running at startup and your Internet Explorer not showing a version is a bad sign too. If this does not fix your problems, I would reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds