This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Icons disappeared

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks. I don't know why I didn't look at this before. Attached is the Zipped file and here's the text file: ========================================= 2037-04-10 04:28:15 . 2011-10-05 03:39:54 1,024 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\000000c0.@.vir 2037-04-10 04:28:09 . 2011-10-05 03:39:54 1,024 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\000000cb.@.vir 2037-04-10 04:27:51 . 2011-10-05 03:39:54 1,536 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\000000cf.@.vir 2037-04-10 04:27:36 . 2011-10-05 03:39:54 1,024 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\800000c0.@.vir 2037-04-10 04:27:26 . 2011-10-05 03:39:54 1,024 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\800000cb.@.vir 2037-04-10 04:27:17 . 2011-10-05 03:39:54 1,024 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\800000cf.@.vir 2037-04-10 04:26:53 . 2011-10-05 03:39:54 1,024 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\80000000.@.vir 2011-10-21 18:20:00 . 2011-10-21 18:20:00 1,330 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-_{53A908D4-99C6-469B-BC13-F4189F260742}.reg.dat 2011-10-21 18:20:00 . 2011-10-21 18:20:00 576 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-$BLSTUN$.reg.dat 2011-10-21 18:19:36 . 2011-10-21 18:19:36 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TosReelTimeMonitor.reg.dat 2011-10-21 18:19:36 . 2011-10-21 18:19:36 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TosNC.reg.dat 2011-10-21 18:19:30 . 2011-10-21 18:19:30 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-SmartFaceVWatcher.reg.dat 2011-10-21 18:19:30 . 2011-10-21 18:19:30 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-Teco.reg.dat 2011-10-21 18:19:30 . 2011-10-21 18:19:30 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TosWaitSrv.reg.dat 2011-10-21 18:19:30 . 2011-10-21 18:19:30 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-00TCrdMain.reg.dat 2011-10-21 18:19:30 . 2011-10-21 18:19:30 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-SmoothView.reg.dat 2011-10-21 18:19:30 . 2011-10-21 18:19:30 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-HSON.reg.dat 2011-10-21 18:19:30 . 2011-10-21 18:19:30 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TPwrMain.reg.dat 2011-10-21 18:19:30 . 2011-10-21 18:19:30 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-SynTPEnh.reg.dat 2011-10-21 18:14:47 . 2011-10-21 18:14:47 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-(Default).reg.dat 2011-10-21 18:14:45 . 2011-10-21 18:14:45 92 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-Locked.reg.dat 2011-10-21 18:13:26 . 2011-10-21 18:13:26 137 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKU-Default-Run-MyOilHmiRCcG.exe.reg.dat 2011-10-21 18:13:24 . 2011-10-21 18:13:24 169 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKU-Default-Run-Apple Update.reg.dat 2011-10-21 18:13:00 . 2011-10-21 18:13:00 188 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKCU-Run-WindowsNotifierVerifier.reg.dat 2011-10-21 18:12:55 . 2011-10-21 18:12:55 171 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKCU-Run-Apple Update.reg.dat 2011-10-21 18:12:55 . 2011-10-21 18:12:55 199 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKCU-Run-VirtualStore Update.reg.dat 2011-10-21 18:12:48 . 2011-10-21 18:12:48 196 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-Toolbar-Locked.reg.dat 2011-10-21 18:12:42 . 2011-10-21 18:12:42 118 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-URLSearchHooks-{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}.reg.dat 2011-10-21 17:26:12 . 2011-10-21 17:26:12 10,985 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2011-10-21 17:18:22 . 2011-10-21 17:18:22 51 —-a-w- C:\Qoobox\Quarantine\catchme.log 2011-10-17 08:40:23 . 2011-10-21 02:55:03 1,536 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\00000001.@.vir 2011-10-05 18:18:46 . 2011-10-06 03:33:47 71,168 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\80000032.@.vir 2011-10-05 18:18:46 . 2011-10-06 03:33:47 41,472 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\80000064.@.vir 2011-10-05 18:18:45 . 2011-10-06 03:33:47 209,920 —-a-w- C:\Qoobox\Quarantine\C\Windows\assembly\tmp\U\00000002.@.vir 2011-09-29 13:42:44 . 2011-09-29 13:42:42 507,904 —-a-w- C:\Qoobox\Quarantine\C\ProgramData\MyOilHmiRCcG.exe.vir 2011-09-26 04:19:34 . 2011-09-26 04:19:34 40,387 —-a-w- C:\Qoobox\Quarantine\C\Windows\$BLSTUN$\apUninstall.exe.vir 2011-09-19 04:27:12 . 2011-09-19 04:27:12 264,192 —-a-w- C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\ShellWMP.dll.vir 2011-09-19 04:27:10 . 2011-09-19 04:27:10 89,600 —-a-w- C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.exe.vir 2011-09-19 04:27:10 . 2011-09-19 04:27:10 124,928 —-a-w- C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.dll.vir 2011-09-19 04:26:58 . 2011-09-19 04:26:57 97,792 —-a-w- C:\Qoobox\Quarantine\C\ProgramData\WindowsNotifierVerifier.dll.vir 2011-09-19 04:26:57 . 2011-09-19 04:26:57 124,928 —-a-w- C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\VirtualStore\VirtualStoreUpdate\VirtualStoreupdt32.dll.vir 2011-09-19 04:26:57 . 2011-09-19 04:26:57 89,600 —-a-w- C:\Qoobox\Quarantine\C\Users\Owner\AppData\Local\VirtualStore\VirtualStoreUpdate\VirtualStoreupdt32.exe.vir 2011-09-13 07:01:58 . 2011-09-13 07:01:58 242,176 —-a-w- C:\Qoobox\Quarantine\C\Windows\$BLSTUN$\lmatn.dll.vir 2011-09-13 07:01:40 . 2011-09-13 07:01:40 294,912 —-a-w- C:\Qoobox\Quarantine\C\Windows\$BLSTUN$\qgnnv.dll.vir 2011-06-01 14:58:52 . 2011-06-01 14:58:52 124,416 —-a-w- C:\Qoobox\Quarantine\C\Program Files (x86)\Minibar\FrOGgy.dll.vir 2011-05-26 07:44:06 . 2011-05-26 07:44:06 204,800 —-a-w- C:\Qoobox\Quarantine\C\Program Files (x86)\Minibar\MiNIbarbutton.dll.vir 2011-05-26 07:40:22 . 2011-05-26 07:40:22 338,432 —-a-w- C:\Qoobox\Quarantine\C\Program Files (x86)\Minibar\KaNGo.dll.vir 2011-03-14 03:20:39 . 2011-03-14 03:20:39 94,309 —-a-w- C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat.vir 2011-03-14 03:20:09 . 2011-01-20 19:44:05 351,232 —-a-w- C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir 2011-03-14 03:20:09 . 2009-11-19 06:12:03 4,846 —-a-w- C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico.vir 2011-03-14 03:20:09 . 2011-01-20 19:44:23 257,536 —-a-w- C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll.vir 2011-03-14 03:20:06 . 2010-08-19 23:37:42 228,016 —-a-w- C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe.vir 2010-09-10 18:17:31 . 2009-08-04 02:15:38 4,608 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\Thumbs.db.vir 2009-07-13 23:31:13 . 2009-07-14 01:39:46 53,760 —-a-w- C:\Qoobox\Quarantine\C\Windows\System32\consrv.dll.vir
Hi Jack P, Was that the entire Qoobox folder? We used 2 tools that should have copied the files back to their correct location if they existed. One of these tools will also make a backup of the entire folder, if present, that the shortcuts were moved to. Is it possible the owner of this computer attempted fixing it before asking your assistance?
Yes, that's all that was in the folder that you asked for. I'm assuming that you looked at all 3 zipped files. There is also a folder named: BackEnv Also there are several other files in the folder: Add-Remove Programs.txt and SnapShot@2011-10-21_18.03.07.dat The owner is a teenage girl who doesn't know anything about removing a virus.
Hi Jack P, Yes I checked all the folders and the quarantined list. No sign of the folder. snapshot is just the windows folder, add_remove programs.txt is the list of installed programs that you would see in add/remove programs. Do the desktop icons take you to the programs they should? If you open windows explorer by using the windows key and the E key at the same time are you able to locate any programs or folders? What brand and model is the computer? Did it come with a Windows7 disk or were the OS backup disk(s) created when the computer was purchased? This may come down to a reinstall of windows.
Hi Jack P, That's a lot of work. Hang on a bit and I'll post some info with some easier steps. We should be able to get most of them. I'm at work at the moment, soon as I get home I'll put something together for you. Thanks
Hi Jack P,

You can restore the defaults for the Start Menu and Administrative Tools as follows:

Windows 7: Restore Default Shortcuts in Start Menu All Programs

The Adminstrative Tools and Default games are under Related Tutorials in the above link.



Also ….

To manually recreate "All Programs" entries, follow these steps…

  • Download App Paths
  • Double click on AppPaths.exe to run the program.
  • Keep the program open.

In this example I'll recreate an entry for Avast antivirus program.
  • Go Start>All Programs.
  • Right click on Avast entry, click "Properties".

[external image: Posted Image]
NOTE. Make sure, you right click on Avast program, NOT on Avast folder.

  • You'll see this window:

[external image: Posted Image]

Due to the damage caused by the infection, you'll find "Target" box empty.

  • Go back to AppPaths window and find Avast entry.
  • Right click on Avast line, click "Edit".
  • A pop-up window will open:

[external image: Posted Image]

  • Highlight everything in "Path" box, right click on it, click "Copy"
  • Go back to Avast "Properties" window, right click inside "Target" box, click "Paste".
  • IMPORTANT! Add quotation marks at the beginning of the path and at the end
  • Click OK and you're done.

[external image: Posted Image]

In case, program's link shows as (empty):

[external image: Posted Image]

  • Open Windows Explorer, navigate to Avast folder in Program Files
  • Right click on Avast ".exe" file, click "Create shortcut":

[external image: Posted Image]

  • Copy that shortcut, go back to Start menu.
  • Right click on avast!Free Antivirus, click "Paste".
  • You'll see Avast shortcut recreated replacing (empty) entry.

Alternatively….
…you paste that shortcut in:
(XP) - C:\Documents and Settings\All Users\Start Menu\Programs\Avast
(Vista/7) - C:\Program Data\Start Menu\Programs\Avast


Post back when you are done and we'll clean up the tools.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI