XPSP3: All shortcuts broken, certain processes won't start, address bar missing

Discussion in 'Malware Help (A Specialist Will Reply)' started by kentuckythrash, Dec 30, 2012.

  1. kentuckythrash

    kentuckythrash Private E-2

    Hello,

    I'm running 32-bit XPSP3, and am going through the process of trying to remove whatever malware is causing the symptoms in the subject:

    - All shortcuts are broken on the desktop
    - All shortcuts are missing from the start menu -> Programs sub-menu,
    - Norton Ghost will not start
    - The Windows Explorer Address Bar is missing

    Following the READ ME FIRST thread, this is where I'm at thus far:

    Step 1:
    --------------------------------------------------------------------------------
    Since I've been trying to fix this for a while and know that .exe files won't run otherwise, I ran rkill from http://www.bleepingcomputer.com/download/rkill/. Otherwise I'm dead in the water.
    --------------------------------------------------------------------------------

    Step 2:
    --------------------------------------------------------------------------------
    Attempt 1 to run c:\Documents and Settings\ben\Desktop\RogueKiller.exe successfully completed. The log file is attached.
    --------------------------------------------------------------------------------

    Step 3:
    --------------------------------------------------------------------------------
    Attempt 1 to run the downloaded c:\malware_tools\mb.exe, I get the error message:

    "CoCreateInstance failed; code 0x80040154. Class not registered." 5 times, each time with an OK button. I click the OK button each time, and then check both boxes for launching and updating malwarebytes.

    I then get:

    "Run-time error '372':

    Failed to load control 'WebBrowser' from ieframe.dll. Your version of ieframe.dll may be outdated. Make sure you are using the version of the control that was provided with your application."

    I click OK and get that message again. Then the install dialog closes and the program does not get installed.
    --------------------------------------------------------------------------------

    Any help is greatly appreciated!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. kentuckythrash

    kentuckythrash Private E-2

    Ok, sorry for the lack of documentation. On http://forums.majorgeeks.com/showthread.php?t=35407 , this is what I have done:

    Step 1
    - I have read the forum rules and guidelines
    - I'm not just having browsing problems
    - I can connect to the Internet
    - I'm not having slow PC problems

    Step 2
    - I have no anti-virus programs installed (I had tried AVG, but it found nothing)
    - Windows Firewall is the only software firewall

    Step 3
    - I have 32-bit windows XP
    - Show hidden files and folders is enabled

    Step 4
    - I don't believe that I have any disk emulation software installed, but downloaded and ran Defogger from http://www.bleepingcomputer.com/download/defogger/dl/8/ just to be sure.

    Step 5
    I skipped running CCleaner as I am missing "items from your Star Menu, from All Programs....etc." When I take a second look though, I am only missing items for malware removal tools I recently tried installing. My other previous shortcuts are there, but none of them work. The only way I can get programs to run is to go to start -> run, run explorer and browse to the .exe (address bar still missing in windows explorer).

    I then went here:

    http://forums.majorgeeks.com/showthread.php?t=139313

    - Spybot is not installed.

    I successfully downloaded all the software and saved it to the recommended places.

    Step 2:
    - I successfully ran c:\Documents and Settings\ben\Desktop\RogueKiller.exe . It found 4 things. The log file is attached.

    - I attempted to run the malwarebytes installer, which I initially downloaded and renamed to c:\malware_tools\mb.exe . When I do, I get the error message:
    --------------------------------------------------------------------------------
    "CoCreateInstance failed; code 0x80040154. Class not registered."
    --------------------------------------------------------------------------------
    5 times, each time with an OK button. I click the OK button each time, and then check both boxes for launching and updating malwarebytes.

    I then get:
    --------------------------------------------------------------------------------
    "Run-time error '372':

    Failed to load control 'WebBrowser' from ieframe.dll. Your version of ieframe.dll may ne outdated. Make sure you are using the version of the control that was provided with your application.
    --------------------------------------------------------------------------------
    I click OK and get that message again, to which I click OK to a second time. Then the install dialog closes and the program does not get installed.

    - I was able to run TDSSKiller and got the "no threats found" screen.

    - I followed the directions for HitmanPro on http://forums.majorgeeks.com/showthread.php?t=260397, which found 5 threats. I attached the log file.

    - I'm not sure what "User Account Control" or "UAC" is in http://forums.majorgeeks.com/showthread.php?t=137630 . I couldn't find either of those phrases in http://forums.majorgeeks.com/showthread.php?t=35407 , or any of the other threads. I did run MGTools as described.

    - I am still having the problems I initially described, and have attached the corresponding log files.

    Any help is greatly appreciated!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. This is not a malware issue.

    You can go ahead and re-run Hitman and have it remove those unwanted programs.

    Also, use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\blekko toolbars

    You will need to post in the software forum for additional assistance.

    It's possible you broke something when using Advanced Fix 2012.

    Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  5. kentuckythrash

    kentuckythrash Private E-2

    Cool, thanks for the help. I was able to fix the other problems on my own.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds