OS - Windows 7 Enterprise 64 bit
So it was late in the day on July 31st when she came to me. It's beginning behavior was exactly what I would have expect it had taken over the .exe files so you could not run any executables on the system. So I took in her PC pulled the drive and started a Malwarebytes scan before leaving for the day.
The next day when I arrived and checked Malwarebytes It had only found 1 item which I removed. Now here is where it starts to go a bit off the track. When I booted her system back up with the returned drive and logged in I got the message that windows was not genuine and that I had to activate it online. This I could not do because I had no internet connection, could not display device manager, and had no listing for network adapters. So I ran the things I do to repair the OS chkdsk /r, sfc /scannow, ect. to no avail. So I was getting ready to do an In place upgrade repair, when it failed saying it could not get the disk information, some research there led me to the fact that the virtual disk service was not running which led me to discover the the plug and play service had been deleted. Unbeknownst to me multiple services had been deleted or set to be deleted on that initial shut down. By comparing the services on that system with another Win 7 system I was able to export and import the registry entries back onto the infected system which brought it back to life, none of the files associated with the services had been removed. Then I was able to get rid of any residuals left behind. Here is a list of the services that were deleted.
Plug and Play
Base Filtering Engine
Internet Connection Sharing
Network List Service
Peer Name Resolution Protocol
PnP-X IP Bus Enumerator
QualityWindows Audio Video Experience
Remote Desktop Configuration
SPP Notification Service
System Event Notification Service
UPnP Device Host
Windows Color System
Windows Connect Now Config Registrar
Windows Font Cashe Service
WinHTTP Web Proxy Auto Discovery Service
Hopefully this will help someone else should they run into the same issues. And I hope this was the correct place for this post.
Edited by bedlin88, 02 August 2012 - 07:51 AM.