Network Connections not visble. Desktop theme hijacked to windows clasic

Discussion in 'Malware Help (A Specialist Will Reply)' started by AffectedUser, Oct 15, 2010.

  1. AffectedUser

    AffectedUser Private E-2

    Please help me. My laptop has turned into a brick on 13th Oct. It has been affected through the LAN Network as many other PC's on our network got simultaneously affected.

    The desktop theme has changed to 'Windows Classic'. Slowly all applications are getting affected and crashing. The Network Connections folder does not display ant network connections nor allows connection to the LAN or my home broadband. Copy and pasting of files is disabled. To copy the logs attached to this topic I have to use the 'CMD' prompt.

    Malwarebytes installs with errors but does not run due to vbalsgrid6.ocx. [Run-time error '372': Failed to load control 'vbalGrid' from vbalsgrid.ocx. Your version of vbalsgrid6.ocx may be outdated. Make sure you are using the version of the control that was provided with your application.]
    I have tried registering the vbalsgrid6.ocx provided by malwarebytes in the cmd prompt using regsvr32 but this does not help.

    Many Services are refusing to start on the pc including Workstation, RPC, Network Connections
     
    Last edited by a moderator: Oct 16, 2010
  2. AffectedUser

    AffectedUser Private E-2

    Logs Attached
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. AffectedUser

    AffectedUser Private E-2

    Thank you chaslang for responding.

    Even after installing Service Pack 6 for Visual Basic 6.0: Run-Time Redistribution Pack (vbrun60sp6.exe) I get the same error from Malwarebytes (Run-time error '372': Failed to load control 'vbalGrid' from vbalsgrid.ocx. Your version of vbalsgrid6.ocx may be outdated. Make sure you are using the version of the control that was provided with your application.)

    I have attached the Qoobox files as MGTools Logs.


    Additionally i am not able to use 'Search' in Windows.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay please run the below.


    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  6. AffectedUser

    AffectedUser Private E-2

    I have attached the TDSKiller Log. No threats were reported.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of your logs are showing any signs of malware. Did you actually run MGtools.exe? The log you attached was not created by MGtools. It appears to have been created by you. The log from MGtools is C:\MGlogs.zip and nothing else. It should not be named anything else. This is always the correct log.


    Try running the below to see if it helps with any of your permissions issues.

    Resetting Registry and File Permissions
     
  8. AffectedUser

    AffectedUser Private E-2

    I apologize chaslang, I mistook a combofix run for a MGTools session. Please find the correct logs attached.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No malware in those logs either.

    Did you follow the instructions for resetting permissions? If so, after a reboot, see if Malwarebytes will run.


    It is looking to me like whatever problems you are having are Windows related. You may need to install the drivers for your network card. Or perhaps you could try using System Restore to return to a restore point from before the problems began.
     
  10. AffectedUser

    AffectedUser Private E-2

    chaslang you're the man!!!!!

    Thanks a lot. I've reset the registry permissions as per your instructions and everything is back to normal.

    Since this was a pc linked to the network before all pc's connected to the network went down, does this mean that someone goofed up the server global policies for the network?

    I do not know how to thank you chaslang, but you are a genius.

    Thanks a gazillion.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Not sure what happened but something messed with policies/permissions.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds