Win XP - Desktop toolbars & icons do not appear

Discussion in 'Malware Help (A Specialist Will Reply)' started by musicgold, Jul 15, 2008.

  1. musicgold

    musicgold Private E-2

    Hi,

    For last two days I have been battling with a malware/virus that as infected my computer. I tried most of the things suggested in Read and Run me First, but still facing the problem. Can you please suggest some remedy?

    System specifications: Windows XP, SP2, Intel Celeron processor, 256 MB RAM, 4GB Hard disk.

    Symptoms: When the machine boots up, it just displays a blank screen, desktop without any toolbars or file icons.
    The operating system is running fine in the background. How I know that? I am able to bring up the task manager by hitting Alt-Ctrl-Del and open a new task; from the new task I can browse files on the system and run any program I wish to run.

    Actions taken so far:

    1. Spybot. Downloaded a fresh copy of Spybot S&D, and scanned the system; found a couple of malware /key loggers. Spybot is able to delete all of them except a malware called Spybuddy, that sits in the memory. Even after a restart, the Spybot scan is giving the same message.

    2. Ad-aware. I had Lavasoft’s Ad-aware on the system from before. It scanned the system and found a few problem files and deleted them.

    3. CCleaner. Downloaded CCleaner and scanned the system. It deleted a whole bunch of files; Did not give any specific message.

    4. System restore. Unfortunately the system restore option of my system was turned off when this problem started. So there are no restore points to go back.

    5. Add remove programs: I could not find anything suspicious to remove in the list provided by this program.

    6. MSConfig has been set up for the Normal startup mode.

    Thanks,

    MG.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes you actually need to finish doing what is requested in the READ & RUN ME if still infected. And that is you need to attach the logs from the 4 scans as requested. You need to attach the logs from the below scans

    • SUPERAntiSpyware
    • Malwarebytes Anti-Malware
    • ComboFix
    • MGtools
    Sounds to me like you did not finish running all of READ & RUN ME. See step 3 and click the links as requested to run the cleaning procedure for your Windows version.
     
  3. musicgold

    musicgold Private E-2

    Hi all,

    Just wanted to inform you all that I ran all the tests recommended by Major Geeks, and was sucessful in removing the malware last weekend. Thank you very much!

    However, my pc has become quite slow after the recovery.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you asking for our help? If so then attach the 4 logs requested multiple times.
     
  5. musicgold

    musicgold Private E-2

    Malware removed; computer gone very slow

    Hi,

    The following link points to my earlier post on the malware problem I had (all icons and toolbars on the desktop had disappeared) . http://forums.majorgeeks.com/showthread.php?t=164526&highlight=musicgold

    I ran all the tests specified by the forum and was able to remove the malware. I am attaching herewith three of the four required log files. I am not able to find SASlog.txt log from SuperAntiSpyware. I had to remove SASpyware from my system as it was having conflicts with MGtools or Combofix. I am assuming that I should not run SASpyware again to generate that file. I also have a log file from hijackthis.

    System specifications: Windows XP, SP2, Intel Celeron processor, 256 MB RAM, 4GB Hard disk.

    Please let me know what I should do to speed up my system?

    Thanks,

    MG.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware removed; computer gone very slow

    There are no known conflicts between SUPERAntiSpyware and MGtools or ComboFix. If there were, hundreds of people would be complaining each week.

    You need to immediately disable Spybot's Teatimer as requested in the READ & RUN. See this: How to disable Spybot's TeaTimer


    Uninstall the below old versions of Sun Java as requested in step 1 of the READ ME:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_08
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {241BA435-10B9-4C1F-B5CC-F68D5EFDC3D3} - (no file)
    O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
    O2 - BHO: (no name) - {4F43126C-0B98-46A5-9845-B396D0600EFA} - C:\WINDOWS\system32\mlJBRKEv.dll (file missing)
    O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: AOL Instant Messenger (TM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. musicgold

    musicgold Private E-2

    chaslang,

    Thanks a lot for your help. Please see the attached logs.

    Is there a way to compare my system's performance with some standard? I don't feel that my system has reached to its original performance yet.

    Thanks again,

    MG.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want your PC to return to how it worked when it was shipped to you then restore it to the configuration that was shipped from the factory. But as soon as you start installing additional software, your performance is going to change as each application is installed. You have a slow PC and have 1/4 of the amount of RAM that I would recommend for properly running Windows XP. Your system is going to run slowly.

    Even what we did in my last steps had nothing to do with malware. I was just tweaking to remove unnecessary junk to help improve performance.

    Your logs are all clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. musicgold

    musicgold Private E-2

    Thanks a lot.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds