Windows setting keep resetting!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Barne, Mar 21, 2008.

  1. Barne

    Barne Private E-2

    Hello everyone!

    I've a bit of a problem and i have no idea what to try anymore. Someone asked me to look at this PC since Internet Explorer kept crashing on start up so he could not use it. I tried to just reinstall it at first but it gave me and error, and still does (something about the integrety of the nessesary files that can not be checked and to make sure the cryyptography service is running, and it is running when i check it in services.msc). So i went on and installed SpywareDocter 5, there was no spyware removal program on there yet and i heard that one was good. It showed quite a lot of threads and i removed them but off course some came back!

    So i went to check online, Internet Explorer did work again now but was REALLY slow. After a while i found that Spyware Docter's gaurd features actually slow it down a lot, so i decided to just get rid of the whole thing all together and just come over here for help and followed the guide.

    Now the big problem begins, i had to install Firefox via CD (also installed spyware docter via CD) since although IE now ran, it couldn't download. It keeps timing out. Well no wonder since the security settings are set to not allow downloads, when i change that it just resets it back! This is the same with every setting in IE and also in Windows itself, like for simple appearance settings. I change something and hit OK and it just ignores it and puts it back to what it was. Even when trying to change these settings with a program such as Tuneup Utilities, speaking of which thos settings don't apear to save neither.

    Anyway i followed the guide and now there don't appear to be any more threads but i still can't change any settings in Windows whichs is really annoying! If someone can help that would be very much appriciated since i have no more ideas... I've included some logs, but i can't seem to find ComboFix.txt.

    Thanks in advance!!!
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Barne and Welcome to Majorgeeks!

    Sadly you have no attachements from the read me* below attached to your post, so please see this guide on how to attach the logs HOW TO: Attach Items To Your Post


    Combofix log will be found in this location C:\combofix.txt instructions on running Combofix





    *Recap on the Read Me

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Barne

    Barne Private E-2

    Hello and thanks a lot for the welcome and the quick reply.

    Strange i though i uploaded the atachments, let me dot it again for now. And i can't find ComboFix log file anywhere, does this happen to be a hidden file? Since i can't view those since i can't change that option neither, keeps resetting too!

    Anyway here are the other two while i look at that readme, thank you so far!
     

    Attached Files:

  4. Barne

    Barne Private E-2

    Sorry for double posting but when i just went into safe mode to run ccleaner ComboFix ran it's last bit and generated a log file, it didn't do so in normal mode apperently! So here is also the log file of that one, while i still go through the readme for now. The next step i can't do by the way since i can't change any Windows settings, boy this is annoying!
     

    Attached Files:

  5. Barne

    Barne Private E-2

    Here are the newest logs after i went through the read me's again. The problem still remains.

    Sorry another post in here, is there an edit butten? I don't see it, sorry!

    EDIT: Oh now i do see it, does it go away after a certain amount of time or something?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Lokale service')
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)

    After clicking Fix, exit HJT.
    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also delete all files (almost 1000 of them) in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    D:\Documents and Settings\Daniel guta\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Barne

    Barne Private E-2

    Hello again!

    Thank you so much for helping me so far. However unfrtunatly the problem keeps persisting. I've included the logs that you asked for. Note that i again had to run ComboFix twice since the first time it wouldn't make a log file again, the second time i loaded safe mode and then it did (in safe mode however i can't change any settings neither it seems). So here are the new logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which problem exactly are you referring too?



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you receive a success message about adding the above patch to the registy! Tell me what happens.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! You logs will be clean if the above registry patch gets applied successfully, thus if you are still having problems, you need to be very specific on what they are. Problems with Windows rebooting are more frequently related issues within the Windows OS or they could be hardware related.
     
  9. Barne

    Barne Private E-2

    Hello again,

    Here is the newest log and i'll try to explain the problem in more detail now, sorry for not doing so in my previous post.

    The problem is that i can't cange Windows settings. It is like they are all locked down in the registry or something. For example, i can't change the view options of folders to show known extensions or hidden files. Once i hit OK in the options window it resets back to what it was. The same is happening for appearance settings, like the start menu does not show the 'internet' and 'e-mail' buttens and the top 6 most used programs under there, it's just white. They are disabled in the propperties for the start menu but enabling them and hitting ok (or aply ok) just resets it back and disables them again. And in Internet Explorer the settins are locked too, most annoyingly there are the security settings which are set so high that you can't do anything with it!

    The boot up problem was not that it didn't boot up. The PC works great, but the program ComboFix makes a log file after it's restarted, well here it only would do that if it got rebooted into safe mode, in normal mode nothing happened as if it just was never started in the first place.

    I hop this explanation is a bit clear.

    Thanks a milion for helping with cleaning, at least there can't be any more damage now. Just wish i knew what the problem was now and how to fix it, i never experienced something like this (well not this severe)!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems do not appear to be related to malware. It appears that you may have some registry corruption of other issues that are preventing access to certain registry keys. You may need to work these problems in the Software Forum. However, first I suggest you try a couple of things.

    1. See if you can apply my fix from message # 8 in safe boot mode
    2. See if the problems you decribe also appear in safe boot mode
    3. If the problems do also occur in safe boot mode, try using
      • the Administrator account in safe mode. Does it still happen while using the Administrator account?
      • try using different user accounts in normal mode. Do the problems occur on other user accounts?
    4. Create a new user account ( you may need to boot into safe boot mode and use the Administrator account to do this). Does the new user account show the same problems?
     
  11. Barne

    Barne Private E-2

    Hello!

    I'm very sorry for the late reply. I've been away for a few days so i haven't read your reply yet. However the problem kept persisting and it even occurst in safe mode under the administrator account and it makes it impossible to create a new account this way (well via the normal easy windows way anyway).

    The PC had problems for a while so i figure all the infections have damaged it in some way over time like corruption of the registry as you said. I've also noticed that a few files on the hard disc are corrupt to which makes many installed programs unusable. I just decided to format the thing, seemed like the easiest solution to fix everythingin 1 go.

    Thank you very much for your great help in removing the (many) mailware infections! It's been a nice learning experience for me!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds