Vista Home Prem - Spyware - I can't get to My Computer to run any Apps

I'm trying to clean up a Vista laptop. It was infected with System Check. In the start menu, everything is missing except shutdown.

How do I clean it up?
LVL 25
Tony GiangrecoAsked:
Who is Participating?
☠ MASQ ☠Connect With a Mentor Commented:
See how you get on with this
Please read through completely before starting.
Post if you've any difficulties with he solution.

If you've already started on a repair and just need to get your icons back, start here
Tony GiangrecoAuthor Commented:
Ok, I've been following it. I ran MB, Rkill and Rogue Killer. Now all my icons show and it runs better.

I see two problems:

1. When I click Start, my list of programs are blank. If i click All Programs everything shows.
2. The System Check icon is still on the desktop and I verified the executable it points to is still in the c:\program Data folder. I thought MD would have removed it. I'm hesitant in deleteing it because it might start up again.
☠ MASQ ☠Commented:
Restart your computer, run RKill again, wait for the window to close and then run another Quick Scan with MBAM. Then reboot and see if the System Check icon persists.  If it does please post the MBAM log.
If there's malware running on your system and you can't kill it due to it restarting, then there's a heartbeat set up with another malware program.  Get Process Explorer from and suspend each process, then kill them.

Configure the displayed columns in Process Explorer to include company name.  This will generally show something dodgy for your malware.  You can also get Autoruns and Rootkit Revealer from there... autoruns will allow you to easily remove any automatically started programs from startup (however they're configured to start) and RKR will scan and remove rootkits from your system.

There are a few articles on Mark's Blog on the same site which explain how to remove this kind of stuff.
rpggamergirlConnect With a Mentor Commented:
Use TheKiller, followed by removal tools as suggested like Mbam, ComboFix, TDSSkiler etc.

Note that "TheKiller" is renamed as explorer.exe
Double click on it (If running Vista or Windows 7, right click on it and select "Run as an Administrator")
Press OK button after program finish
Do not restart your system after this step. You then run other tools like MalwareBytes, TDSSKiller or ComboFix.

NOTE: If malware blocks TheKiller from running please try to run it  again.

ComboFix by sUBs: 

STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply.
Do not mouse-click combofix's window while it is running. That may cause it to stall.

ComboFix tutorial:

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.