No Control Panel (disabled by virus)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Knine10, Nov 26, 2007.

  1. Knine10

    Knine10 Private E-2

    Hello,

    I was infected by a virus and lost control panel...also I can't remove programs as I get a message saying "this operation has been cancelled due to restrictions in effect on this computer. please contact system administrator." I have followed the steps in the READ & RUN ME FIRST thread and would appreciate any further advice.

    Thanks
    Knine10
     

    Attached Files:

  2. Knine10

    Knine10 Private E-2

    logs 2
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03

    Reboot and install:
    Java Runtime 6

    Download this file to your desktop - Combofix.exe
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    When you return....please attach new logs for:
    ShowNew
    GetRUnKeys
    HJT ----> properly installed and renamed.
    ComboFix
     
  4. Knine10

    Knine10 Private E-2

    Yessss got control panel back :celebrate. Here are the logs you requested. Thanks for your help so far. :)
     

    Attached Files:

  5. Knine10

    Knine10 Private E-2

    here is the HJT log.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a couple of items to fix.

    Please uninstall thru add/remove programs:
    Viewpoint Media Player

    Then make sure these folders are gone:
    C:\Documents and Settings\Justin\Application Data\Viewpoint
    C:\Documents and Settings\All Users\Application Data\Viewpoint
    C:\Program Files\Viewpoint

    Next, re-run HJT and have it fix these items:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll G
    R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
    After clicking fix, exit HJT.

    Tell me how things are running.
     
  7. Knine10

    Knine10 Private E-2

    here is the HJT log... things are running better than before :)
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  9. Knine10

    Knine10 Private E-2

    Thanks a lot for all your help :clap. My computer is running very smoothly. :D
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds