Code 1260 / Group Policy-Malware Won't Open

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Joey Jiggles, Apr 4, 2014.

  1. Joey Jiggles

    Joey Jiggles Corporal

    Hey guys,

    I couldn't get all of my programs to work that you need in your guidlines and something is preventing Malware to open (never happened before). I also noticed a new search engine that is doing a switch on me.

    HitmanPro freezes and gives me this error:

    "AutoSuggest Drop-Down iexplore.exe - Application Error

    The exception unknown software exceptiong (0xc0000006) occurred in the application at location 0x71e4c7a5

    Click OK to terminate the program"

    Please see attached everything I could do (which I had to go on another computer because the one with the problem would freeze every time I would try to attach).

    Thank you guys! Looking forward to hearing from you.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall:
    Java(TM) SE Runtime Environment 6 Update 1

    Now download and install:


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :files
    C:\ProgramData\syruteou.dat
    C:\ProgramData\xibppwmn.dat
    
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "xibppwmn"=-
    "syruteou"=-
    
    [HKEY_USERS\S-1-5-21-1231257082-2659704953-3122731967-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "xibppwmn"=-
    "syruteou"=-
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{031949b3-28b6-43a4-90e2-dde1cfe21390}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9230cb90-79de-4945-88a4-762244a25bc8}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{F41776FD-7840-4BE5-82F4-70E037721A72}]
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip


    Make sure to tell me how things are running.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  3. Joey Jiggles

    Joey Jiggles Corporal

    TimW!

    Thank you for your reply.

    Unfortunatley, the computer is still running the same way. Google Chrome just sits at 'Untitled Tab' no matter what address I put in the address bar and iexplorer takes a few minutes for any page to load. Also, Malwarebytes still can't be used or even uninstalled due to the policy warning. I can't even attach anything to this reply. I needed to save the logs to a flash drive and use another computer. This computer just freezes the window. So frustrating!!!

    See attached logs. I hope they help!!

    Thank you.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now see if you can find and delete:
    C:\ProgramData\xibppwmn.dat

    Reboot and run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).
    Then attach the below logs:

    * C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Joey Jiggles

    Joey Jiggles Corporal

    Sorry I took so long to reply. The registry step you asked me to do went successfully.

    The computer still is acting the same. Every time I have to try and use the "manage attachments" the window for "manage attachments" freezes and I have to restart Internet Explorer. Also, Google Chrome still will not work. It will open, but will not open any page, just sits there and keeps loading.

    Another issue with Internet Explorer is when I open a new tab it says "RLO Search Powered by Yahoo" and at the top the link for this search is "http://rsearch.shopathome.com/?user_id=%7bB557CCFB-3DD5-4D0F..."

    So now, I am on a laptop uploading this message.

    Looking forward to hearing from you. Thank you.

    **EDIT: I tried to upload my attachment of the MLogs.zip but it wouldn't let me. It kept saying I already did.
     
    Last edited: May 1, 2014
  6. Joey Jiggles

    Joey Jiggles Corporal

    Ok, maybe my memory was a little off and I didn't run MGlogs after I did what you said.. so here is the new one.. sorry.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use explorer to find and delete:
    C:\ProgramData\xibppwmn.dat

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Reboot and run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).
    Then attach the below logs:

    * C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. Joey Jiggles

    Joey Jiggles Corporal

    Tim,

    My parents really needed to use their computer so I just took it to a local shop. Apparently my hardware was dying. Thank you for all your help!!!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds