At this point most of your PC will be cleaned. But don't give up hope. You will need to Recopy "explorer.exe" back to your C:\WINDOWS directory again. And your Icons/Start menu will be back. http://liveterrain.com/windows-7/windows-7-wont-boot-after-install.php

Windows seems to work now (not tested with internet connection). No desktop, no explorer.exe, etc.I do have a windows 7 disk.Next Steps? Replace Explorer.exe? This will let you get to the Safe Mode menu.

Click OPEN (on the new task for explorer.exe) and it should run explorer.exe. AV-Comparitives is a good way to check your AV. Norton doesn't work.

It is possible to CTRL/ALT/Delete and start task manager etc. At this point, your desktop is blank, everyone and their grandmother has been Spam bombed and you cannot even get to a website to fix your pc.

I went into the details and excluded this file from being quarenteened so that Norton wouldn't remove it.After a reboot and my desktop is back! Again, I wish you well on getting this thing out of your life and please donate if you can. Usually you can get into Safe Mode. This is because your explorer.exe has been deleted/infected by the rootkit.

Look for any process labeled Suspicious.Mystic and kill it. (End process) Now, open the Windows Registry. First, it infects and deletes the program "explorer.exe" in the WINDOWS directory of your PC. (Typically, the beginning of the infection, causes your system to crash, and upon reboot, you have or do not. Just sit on that Yes/No or OK screen.

Kaspersky Online Scanner 7.0 may fail to start if another anti-virus program is already installed and running on your computer. VARIANTS (and other info) Variants are modified versions of rootkits/viruses intended to skip past signatures in Anti-Virus programs.

It will take a few minutes to go through your entire PC, depending on how much info you have. Once your system reboots, you will get various error messages. But not all its affects. Choose TOOLS, then Internet Options, Connections and then Click OFF the LAN checkboxes. (All check boxes should be OFF on this page).

Most likely, it is because rootkits change their names frequently and their signatures are difficult to detect. Please consider a donation (no matter how small), it will help me pay for/figure out other issues/problems with adware/viruses that slip by the big guns. Do...

during my vacation :/ I was away from computer for 5 mins and when I came back it had 7-8 windows security  dialogs requesting some kind of permission.

This will bring back your Icons and Start Button and task bar. (NOTE - the virus will have infected explorer.exe again and/or your system may have deleted explorer.exe again before you It is important that it is saved directly to your desktop**Please, never rename Combofix unless instructed.Close any open browsers.Close/disable all anti virus and anti malware programs so they do not interfere If it asks you to Reboot, DO NOT REBOOT IT JUST YET.

Another  (even easier) procedure which seems to work for a lot of users is to follow the step number 2 on the above guide. In fact, Symantic considers it a 'low risk'. during my vacation :/ I was away from computer for 5 mins and when I came back it had 7-8 windows security  dialogs requesting some kind of permission. It will say that it cannot find your homepage or whatever website you type in. (Typically, this is because it has tried a LAN attack).

I will give it a couple days or else I am getting a refund and it will be the first time I do this on Steam after a decade.Shame I really SafeGuard On Translate How-to Sections How to Windows 7: The Best Windows 7 Tips and Tricks for your Computer. Some of them tend to crash your system frequently. I have figured it out (it took me 9 hours of work) and successfully removed suspicious.mystic from multiple PC's.

Last edited by valcan_s; 23 May, 2014 @ 10:20am #8 Capt. This pattern/method should work with a number of rootkits/variants that are not covered by the big virus scan programs. Plug your flash drive into your infected PC and boot to SAFE Mode (this is done by pressing the F8 key while restarting the computer). It just removes the DLL's from the c:\WINDOWS directory.

There is no try. All trademarks are property of their respective owners in the US and other countries. After restart Norton found this "Suspicious.Mystic" and removed it. After that I just get a black screen in windows. I did not like so I restarted the computer.

It will look like a blank screen, with SAFE MODE in all 4 corners. However, it will not fully remove the virus or its effects. They almost always modify your registry.