Windows XP Restore removed, but leftover problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by becolt, Jun 15, 2011.

  1. becolt

    becolt Private E-2

    Hey guys-
    Last night the Windows XP Restore malware showed up and tricked me into a fake scan while I was browsing online, 4 or 5 tabs open in FF. Was able to immobilize it with Spybot and by deleting the program files.
    -Ran avast overnight and fixed what turned up.
    -Desktop was still missing all icons & quicklaunch, programs menu empty.
    -Ran Unhider.exe and that fixed a few things but still missing a few desktop icons and all quicklaunch. Most folders in the program menu are still listed as empty.
    -Just ran through the malware removal thread and combofix was the only one that returned a result. MG didn't even bother to create a log file.

    I'm on XP-mce SP3.
    Any help getting this guy back up to par would be excellent.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may have to reinstall those apps.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  3. becolt

    becolt Private E-2

    That's the weird thing, all the programs are still there and will open if I do it from explorer. Guess I'll have to sort through and try to remember what Icons I had on the desktop, create new, etc.
    The quicklaunch is stranger: there isn't even a "show desktop" icon.

    Got it to the right prompt, but both GetRunKey & ShowNew gave me a response of "The system cannot find the path specified." I see the folder is right there, and it obviously found the path to that - Just tried running those batch files from explorer, they both flashed prompt windows at me but they were too fast to read.

    Side note: Gotta hand it to them, this has been a harder, longer fix than others I've had to do.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:
    Next, re-download MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. See if it won't run now.
     
  5. becolt

    becolt Private E-2

    aHa! The new exe got MG up and running, log attached. Thanks.
    On the quicklaunch: a possibly related thing I just noticed is that there are still some files and folders that are classified as hidden. One of those was the Local Settings folder for this user, so before I start on a defaultification trip I'll search around and see what I can find that the unhider left behind.
    btw: one promising thing is that I can create new QL icons, so it's not fully broke. Will report back
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The malware is gone, but we can clean up a few things. Otherwise, you need to use explorer to repopulate your start menu.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  7. becolt

    becolt Private E-2

    Great, thanks!
    Oh crap. Not sure how to do that aside from performing a messy/incomplete copy and paste job. Any method for this or am I SOL?

    Regedit: successful

    Thought maybe that removing "hidden" attributes from everything in the documents and settings and programs folders might do the trick--no dice--but at least found the "show desktop" icon here: "C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch" in case anyone goes looking for it in the future.

    Thanks for all your help on this, I can't imagine how people get along without knowing about sites like this one.
     
  8. becolt

    becolt Private E-2

    First, Thanks Tim for all your help. I think I've gotten my Programs directory restored (one by one manually). A note in case anyone doesn't know: There are two Unhide.exe programs, that one and one called Unhider.exe. The first uses a command prompt window and can be found in the 1st reply in this thread http://answers.microsoft.com/en-us/...ams-menu/0135a535-aa76-e011-8dfc-68b599b31bf5
    The second, I don't remember where I got it, but it's out there. This one runs entirely in the background.
    Neither one fully worked for me, but I saw many posters claiming they did for them.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are already using that program, which I didn't give you a link to since you said you ran it in your first post. The one I gave you was to see if that program could fix what leftover issues you had with the hidden folders and files.

    Good to know you have healed things. Safe surfing!!;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds