Closed Thread
Results 1 to 13 of 13

Thread: can't click start menu

  1. #1
    Pro Member Kratt is an unknown quantity at this point
    Join Date
    Nov 2004
    Posts
    323

    Exclamation can't click start menu

    think I have some virus. there was a popup wanting me to buy some software, which I got rid of, and deleted a rogue avp.exe file and strange folder in \program files\
    Deleted these from registry run keys.
    but still something wrong, PC very slow, can't click anything on taskbar, and gf who (still) insists on using IE (it's her PC) finds it v.slow.
    Found some links on google saying it could be this or that, but can't find a 'cleaner' or instructions for it?

  2. #2
    Doot Do Do Do bigperm is a name known to allbigperm is a name known to allbigperm is a name known to allbigperm is a name known to allbigperm is a name known to allbigperm is a name known to allbigperm is a name known to all bigperm's Avatar
    Join Date
    Apr 2001
    Location
    mmmhmmm
    Posts
    3,033
    Have you tried anti-virus software? That's step number one if you think you have a virus.
    ---

  3. #3
    Pro Member Kratt is an unknown quantity at this point
    Join Date
    Nov 2004
    Posts
    323
    AV can't find it. In fact I've found the 2(?) files responsible. Problem is they are 'in use' by winlogon.exe and lsass.exe, both system files. I can't delete them.
    Autoruns by sysinternals shows them. Tried to delete the startups, but the winlogon.exe and lsass.exe recreates them every second, as shown by processmon.
    Safe mode doesn't help as winlogon.exe and lsass.exe is running even in basic command line only.
    No system restore points prior to those files strangely.

  4. #4
    #anonymous Decker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond repute Decker's Avatar
    Join Date
    Dec 2003
    Location
    West Yorkshire, Englandshire
    Posts
    10,145
    Your going to have to do it by hand, you need to find the key that keeps recreating them first in the registry, find the trigger file then all the other 'bits' - basically you need to kill the parent virus to stop it respawning.

    What messages does your AV throw up?
    /\__/\ We Do Not Forgive!
    (- o *) We Do Not Forget!
    (")_(") Expect Us!
    IT Help for everyone @ Scotia-IT.com - when it's finished

  5. #5
    Pro Member Kratt is an unknown quantity at this point
    Join Date
    Nov 2004
    Posts
    323
    AV shows nothing, adaware etc shows nothing.

    In the end stopped it using recovery console command line.
    Disturbed that Safe mode is no longer 'safe' nowadays...

  6. #6
    #anonymous Decker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond repute Decker's Avatar
    Join Date
    Dec 2003
    Location
    West Yorkshire, Englandshire
    Posts
    10,145
    Quote Originally Posted by Kratt View Post
    In the end stopped it using recovery console command line.
    Disturbed that Safe mode is no longer 'safe' nowadays...
    So is it fixed
    /\__/\ We Do Not Forgive!
    (- o *) We Do Not Forget!
    (")_(") Expect Us!
    IT Help for everyone @ Scotia-IT.com - when it's finished

  7. #7
    Pro Member Kratt is an unknown quantity at this point
    Join Date
    Nov 2004
    Posts
    323
    It seems mostly fixed. But PC very slow. Sometimes explorer takes 20-30s open new folder. Lots of HD activity sometimes when nothing should be doing anything.

    And sometimes, can't click start menu again. Checking autoruns shows nothing.

  8. #8
    Pro Member Kratt is an unknown quantity at this point
    Join Date
    Nov 2004
    Posts
    323
    Also, maybe not related, but fonts stuffed. eg Task manager, the headers instead of 'user name' it would say 'us*****me' where the * seem to be taking characters from wingding or symbol. Seems like fonts corrupted?

  9. #9
    freezoka.net TSO is a name known to allTSO is a name known to allTSO is a name known to allTSO is a name known to allTSO is a name known to allTSO is a name known to allTSO is a name known to all
    Join Date
    Dec 2006
    Location
    East Coast, USA
    Posts
    3,536
    ^^ The only way to get rid of this is to reformat. It sounds like you have some form of this ( http://www.spywareguide.com/spydet_2...antivirus.html ), which comes in many forms, some of which are very destructive and impossible to remove.
    hostizzo.com - free hosting

  10. #10
    Cross Industries Schmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud of
    Join Date
    Jun 2007
    Location
    United States
    Posts
    3,416
    Try this:
    http://www.safer-networking.org/

    Go there and download Spybot: Search & Destroy. Its excellent for removing spyware.
    Sean Marvin Cross Industries - Affordable technology solutions Glacier Host - Affordable Web Hosting Services
    E-mail: contact@x-ind.com Phone: (843) 879-8293 Hours: Weekdays, 8AM-6PM EST; Saturday, 10AM-5PM EST

  11. #11
    freezoka.net TSO is a name known to allTSO is a name known to allTSO is a name known to allTSO is a name known to allTSO is a name known to allTSO is a name known to allTSO is a name known to all
    Join Date
    Dec 2006
    Location
    East Coast, USA
    Posts
    3,536
    ^^ Ah, yes, but it does not remove WinAntivirus. (...if that's the problem). In fact, Norton has a tool that appears to remove WinAntivirus, but it only "hides" for 20 minutes and re-appears. It truly is the malware from hell.
    hostizzo.com - free hosting

  12. #12
    Pro Member Kratt is an unknown quantity at this point
    Join Date
    Nov 2004
    Posts
    323
    well did reformat. :|

  13. #13
    Jay Street iBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond reputeiBrightDev has a reputation beyond repute iBrightDev's Avatar
    Join Date
    Oct 2005
    Location
    Not sure, need a GPS.
    Posts
    7,127
    sounds like a virus i dealt with a couple months back on a clients computer. it had infected so much of the system files that no anti-virus could fully remove it, so, i went for the manual removal, and it had just corrupted to much. ended up having to format and re-load windows os. good luck
    Full-service digital agency based in Scottsdale, Arizona - iBright Development

Closed Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts