Disabled internet, no volume, windows classic theme

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fe1ix, Feb 9, 2011.

  1. Fe1ix

    Fe1ix Private E-2

    So after getting back from work today I restarted my desktop (which was working perfectly fine up until this point), and when it booted into windows 7 the theme was in windows classic. Furthermore I cannot:
    connect to the internet
    have sound
    run Symantec Endpoint Protection
    Uninstall programs
    Create/Use system restore points.

    I have ran everything suggested in the malware removal guide to no avail, it's tricky. Only things I have used it for in the past week or so are reddit, matlab,league of legends, skype and porn (my girlfriend is in Thailand)

    Worst case scenario I can just format and reinstall, I do that about every year anyways to keep a clean OS, and I haven't reformatted this since it was built in Nov 09
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put ComboFix directly on your desktop!! It needs to be run from there.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Windows\1cUWTTc4e
    C:\Windows\1euCH41Y2
    C:\Windows\1fQKO
    C:\Windows\1Vi1Y22E
    C:\Windows\2Qvsv
    C:\Windows\3tvJyeq
    C:\Windows\4IWYB
    C:\Windows\5hJOk1N
    C:\Windows\5pmmsMdNFo
    C:\Windows\74eKv
    C:\Windows\7msMUWiACu
    C:\Windows\7TtKhaDt2e
    C:\Windows\8nngEoL
    C:\Windows\8UHe2P
    C:\Windows\8xuuEFl
    C:\Windows\a1PWcH
    C:\Windows\ABrHyOQF
    C:\Windows\AHDL41
    C:\Windows\bMgNPtp6
    C:\Windows\bnGVMejdQS
    C:\Windows\csaYl7Vra4
    C:\Windows\CVkCg6GGje
    C:\Windows\dTU6n3qcO
    C:\Windows\dVgu63
    C:\Windows\dWmqNQboc
    C:\Windows\eDFchX7Gu
    C:\Windows\eVOOvF
    C:\Windows\FtuUKI7tLO
    C:\Windows\GcCSso
    C:\Windows\GDfBH3qm
    C:\Windows\GJX5lU7
    C:\Windows\Gniqh2
    C:\Windows\gUu2n5
    C:\Windows\hkwRCVmf3P
    C:\Windows\Hvo7kUU
    C:\Windows\hwvfAj
    C:\Windows\Iul4M
    C:\Windows\k1atV
    C:\Windows\l2X358N
    C:\Windows\lnE1ok7SVo
    C:\Windows\mrq5K4P
    C:\Windows\Mv8FNpV2hK
    C:\Windows\mYDaRfcd
    C:\Windows\nJtf64j
    C:\Windows\NxQK1
    C:\Windows\oemKQGlTS
    C:\Windows\oHjigD3tfi
    C:\Windows\OmW4hGUmrl
    C:\Windows\pA8P1O
    C:\Windows\pyxFWS2S
    C:\Windows\qRgYu374
    C:\Windows\r7WdPkmtN
    C:\Windows\RCLHfsoVKo
    C:\Windows\Sg8JQhcb
    C:\Windows\sGVbix
    C:\Windows\SL4Gxd
    C:\Windows\SnAF2h
    C:\Windows\sXQAwehfl
    C:\Windows\tfHvVM
    C:\Windows\tNbbFn
    C:\Windows\TOx3x5Y
    C:\Windows\uhbYm
    C:\Windows\VfboROYGFY
    C:\Windows\VQjKpNoC
    C:\Windows\VQJPHi
    C:\Windows\W2CS2
    C:\Windows\wkxxch3S
    C:\Windows\WtQPnivy6
    C:\Windows\WXtYjgGvWB
    C:\Windows\XJ5lf4C
    C:\Windows\Y4uGYpB
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  3. Fe1ix

    Fe1ix Private E-2

    I have enough free time tonight so I think I am going to go ahead and just format and reinstall. I have very little on the drive that the OS is installed on, and I think it will take less time to reformat and recustomize.

    Sorry to waste your time, but thanks for the help!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. Hope it goes well. ;)
     
  5. Fe1ix

    Fe1ix Private E-2

    Unless somehow my system just corrupted itself this badly, this thing is quite tricky. The setup for windows doesn't detect the drive that contains the corrupted OS. Luckily I run a raid, so I accessed that and am securely erasing it completely. At a combined 1.5 TB, this will take awhile.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's why we often try to fix and rid you of the malware since doing a reinstall can sometimes create more problems than doing the malware removal. ;)
     
  7. Fe1ix

    Fe1ix Private E-2

    Usually its quicker for me to just format and reinstall, since I keep no important data on the hard drives that my OS is installed on for that reason. Never before have I had malware that prevents a windows 7 install from detecting the hard drive. Oh well, I'll keep killing time while it slowly rewrites every bit.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good luck, if you run into problems, do post in the software forum. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds