Windows7 No Firewall Access No Internet & MORE

Discussion in 'Malware Help (A Specialist Will Reply)' started by Superlost6, Feb 22, 2013.

  1. Superlost6

    Superlost6 Specialist

    Good Day,
    I have a good friends desktop here trying to fix, It's Dell Optiplex GX w/ Windows7 Home.....

    When I got it there was no internet connection allowed & No Firewall access (see images attached)....

    1.) I did services.msc and security center was disabled. I enabled it and it sill gives me the same error "Cant access settings"....

    2.) At this time I wanted to see how bad the PC was infected and if the virus program had any logs.. I could not get norton to run as it wanted to "Update" first & with no internet connection it would stop and turn off.. I then downloaded Microsoft Essentials virus program...

    3.) Before running the Virus scan I did a malwarebytes scan & fixed issues found. It found 175 items in less then 4 min.. (see log)

    4.) At this point I knew it was a bad sign so I did the entire Major Geeks malware scan program....

    5. mgtools did the scan yet "Failed" to create mglogs.txt file and said repot this in next post... rolleyes

    6.) HitmanPro failed to run as it needed a internet connection.. :cry

    7.) Microsoft Malicious Software removal found "No Infections"

    8.) SUPERAntiSpyware found "No Issues"

    9.) tdsskiller Found "No Issues"

    10.) roguekiller did list an item after scan (see log)

    11.) Advanced SystemCare found some common issues and fixed (see log)

    12.) Combofix scan ran successfully (see log)

    13.) Since mglogs fail to create, I did a hijack this scan (see log)

    14.) I did see a program installed on the unit "My Clean PC" I hav not talked to the guy yet I know he's a cheap sob and thought lead me to be leave he did not pay for this so I felt it was a little suspicious so I did a deep uninstall.. For the record..

    After all the scans Sill no internet connection and fire wall & security center changes are "Denied access" so to speak.. :confused

    See all logs below, I might need to do a 2nd post as it's more then 5 attachments.....

    I will be here all night accepting any help. Thank you for your kind assistance in this mess!

    Superlost6 rolleyes
     

    Attached Files:

  2. Superlost6

    Superlost6 Specialist

    Additional Attachments....
     

    Attached Files:

  3. Superlost6

    Superlost6 Specialist

    I just ran a Farbar Service Scanner scan.. (see log)
    :banghead
     

    Attached Files:

    • FSS.txt
      File size:
      3.6 KB
      Views:
      2
  4. Superlost6

    Superlost6 Specialist

    I was able to run mgtools a few times, on this last run it made the (mglog zip)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.
    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. Superlost6

    Superlost6 Specialist

    Thanks chaslang,
    Happy ;) to report that I am typing this from the infected PC.. All seems ok, I love the Windows repair tool... As per your request below is the log..

    Thanks for all the help.. going to double check somew things to make sure alls working. I'll check back to see if you find issues in log
    THANK YOU
    Superlost6
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log has not been updated properly. You need to run MSconfig and put your PC intro normal startup mode. Then you need to temporarily shutdown protection software and run run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log again:
    • C:\MGlogs.zip


    Make sure that you wait for GetLogs.bat to finish running before posting the log. It will tell you when it is finished.
     
  8. Superlost6

    Superlost6 Specialist

    Sorry I feel asleep last night, (as per your advice) ;)


    Thank you, I did the start-up change and re-ran.. Here is the log.

    I did ask my friend about "My Clean PC" as I thought, he did not buy it. He thought it was windows offering to clean his PC.. rolleyes

    So I assume this is were it all startred, I hope the log looks good as he's comming here in 1hr after Church to get his PC.. :eek

    If there is things still needing attention mabe I can go to his house and repair.. I look forward to your responce. Once more THANK YOU
    superlost6
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per the logs you attached, you are still using MSconfig to control startups. You are in selective startup mode. Many things are disable including Microsoft Security Essentials and Advanced System Care.
     
  10. Superlost6

    Superlost6 Specialist

    Hmmmm.... That's strange.

    I think somethings not correctly running in mgtools.. I changed the settings as you requested begot the scan..

    As for now, the PC was picked up by my friend.. Seems to be running ok..

    I told him if any issues bring it back..

    Thanks for all your assistance
    Superlost6
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No, it was correct and it was a new log. Perhaps you had not rebooted after changing MSconfig and the changes did not take affect yet.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds