Around 12:30 today the following things happened:
1. My sound stopped working. There did not seem to be any reason why. Thought maybe it was a hardware error, so I restarted.
2. After the restart I noticed that not only did my sound not come back, but now my network connection icon in the task tray had an X through it like it is not connecting.
3. Getting suspicious, I attempt to update Microsoft Security Essentials. It won't update.
4. For some reason I decide to go into the Control Panel and see if I can see any weird hardware problems there. I immediately notice that I cannot click/open many things. I cannot click any of the options under System and Security, such as Find and Fix Problems, as well as others.
5. I open the event viewer. There are over 3,000 errors for "Distributed COM" which say:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{89115307-8248-448F-ADA0-F3F3718A9B2A}
and APPID
Unavailable
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.6. I open Firefox and I get a strange prompt. My browser is set to go the firefox google page, but it gives me a 303 error and says the site has moved with a link to a page(I should say this only SOMETIMES happens. Not every single time). BUT even though my network is supposedly disabled I can go to other sites. I seem to have full internet access.
7. I assume a virus, although I cannot at all think of where it would come from.
8. I boot into safe mode with networking.
9. I notice that not only does my network still have a red X, now my volume icon has a red X, and I have 2 notices in the security center. One says that Microsoft Security Essentials is not active, and the other says that Windows Defender is not active. Microsoft Security Essentials IS active, but is not monitoring and I can't make it monitor. Still can't update it's definitions. When I try and click the Turn On Windows Defender notice, it opens a folder to my system32 directory.
10. I do the following in Safe Mode:
10.a. Run and update Malwarebytes successfully. Finds no threats.
10.b. Run and update Spybot successfully. No threats.
10.c. Run and update ClamWin successfully. ClamWin finds one infection of kui.exe which is a Worm.Palevo-609. I remove all instances of it.
11. Reboot into normal mode. All of the problems are still there. Network disabled icon, sound not working but not a disabled icon, Security Essentials says it is not active. Windows Defender says it is not active. I also cannot run Windows Update. Tells me the service needs to be restarted (I checked the service and it is running).
12. Run RKill and shows 4 problems, but they seem to be false positives. Will post log on request.
13. Run Housecall. Finds nothing.
14. Run ESET Online Scanner. Finds nothing.
15. Post on bleepingcomputer for the first time.

Help
This topic is locked

Back to top














