IE Critical Trojan.Zlob-X.a

Discussion in 'Malware Help (A Specialist Will Reply)' started by maglib, Nov 30, 2007.

  1. maglib

    maglib Private First Class

    Thank you for running this forum. In 12 years this is the first time I had to actually ask for help. I have a new Vista Home pc which I am lost about all it's security features and did have a difficult time running many of the steps as although I am an administrator it appears many of the things couldn't load or fix correctly. I didn't find anything using Windows defender of malicious spyware removal or Spybot that I thought were useful. I use Mcafee and have a firewall and I think I got this on Wednesday when my son was searching Oprah Winfrey eye color on the web and he yelled that something started downloading and I stopped it, now I get

    "Critical System Warning" Your system is probably infected with the latest version of Trojan.Zlob-X.a Full system optimization will greatly increase your computers performance and prevent data loss. Click OK to download antispyware. software recomended.

    It used to take over my internet explorer searches and make the first outcomes to be some sex website or a site that starts downloading immediately which I just shut down.
    I did put the website on my IE Restrictes site list although I can't figure out now what the site was. It didn't do anything.
    I now after trying all these fixes get the following when I first open IE:
    Cannot find'::{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}'.Make sure the path or Internet address is correct. I close that and IE still opens although it almost appears that it opens a ghostly version that disappers with another version in front (I may never have noticed this before and it may just be normal). No longer does it go to the sex site.


    The AVG showed some cookies and then I have Hijack this which I don't understand so here I am.

    I appreciate any assistance. Thanks in advance.
     

    Attached Files:

    Last edited: Nov 30, 2007
  2. maglib

    maglib Private First Class

    here is a mglogs.zip I now realize I didn't run as administraror the first time.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please note that the READ & RUN ME does not ask you to attach a HijackThis log. The reason for this is the MGtools already gets one automatically and puts it into the MGlogs.zip file. This was explained on the download page.

    That being said, you still did not get MGtools to run properly.

    Did you also disable UAC as requested in the instructions? Please make sure UAC is disabled and then continue with the below.

    Run FixIEDef as shown below. This tool removes IE Defender and the associated Trojan.Downloader.Delf infection.
    1. Download FixIEDef.zip by ShadowPuterDude to the Desktop.
    2. Double-click FixIEDef.zip, this will create a folder named FixIEDef on your Desktop.
    3. Double-click of the FixIEDef folder.
    4. Locate FixIEDef.bat and double-click on it.
    5. FixIEDef will now run.
    6. Press any key to close the CMD Console when the script is finished.
    Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.


    Then go to the C:\MGtools folder and run the GetLogs.bat file by double clicking on it. Let me know if you get any error messages. If it runs properly a new C:\MGlogs.zip file will be created. Please attach it.

    Also tell me if there is any change to your Zlob problem? There should be if FixIEDef was run.
     
  4. maglib

    maglib Private First Class

    Much thanks for your quick response. Sorry for being lost and not getting it right. It was a lot to take in as I'm not experienced with Vista and had many an issue trying to download and save with administrator errors

    I did disable UAC by clicking on disable uac.reg and I got some reply about something with keys were added to the registry. I will try it again and also run what you said to and will post it shortly.

    Could it have anything to do with that I had to save the files to my username and then copied the file to the root or program files depending on the instructions. Although I'm the administrator it doesn't let me run to c:\, I had even tried fixing this and got very confused on security/admin issues.


    [
     
  5. maglib

    maglib Private First Class

    I did what you said when I ran the first thing during the scan it said Access is denied to C:\windows\System32\powervideo.dll

    I definitely did DisableUAC.reg so I'm not sure if that has any impact.

    Here is the new log too.

    I didn't get the Critical system error when I went into IE but it came back when I tried to upload the Getlogs.bat. I also didn't get the error message about the file being missing when I went into IE. You've already helped me out now I pray you can help me fix this once and for all.

    Much thanks.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    GetLogs.bat is not running properly. I'm not sure if Windows Vista is causing you a problem or if it is something else like McAfee or another program interfering. We need to get those logs to continue. Let's try something different.

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the below command follow by the enter key and tell me what happens.

    GetRunKey

    If the command prompt window is still open. You can just type exit to close it or click the X to close the window.

    Also look in your C:\Windows\System32 folder for the powervideo.dll file and tell me if you see it. This is part of the IEDefender malware we are trying to remove.
     
  7. maglib

    maglib Private First Class

    I didn't know if you needed this from the run of IEdef. I notice on the bottom something about chinese p2p???
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No we don't need this. It is just what changes have gone into the FixIEDef program. Did you see my other message? We were posting at the same time.
     
  9. maglib

    maglib Private First Class

    When I run getrunkey it says is not recognized as an internal or external command operable program or batch file.

    Yes PowerVideo.dll is there. should I delete it in dos?


     
  10. maglib

    maglib Private First Class

    I also just got back the message when i opened IE about "Cannot find '::{2559 ....
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I left something out. Before running GetRunKey enter the below command at the command prompt.

    cd C:\MGtools

    Now what happens?

    Yes see if it allows you to delete it. If not, try renaming it to PowerVideo.BAD
     
  12. maglib

    maglib Private First Class

    it's working but has pause with "adding: runkeys.txt (160 bytes security) <deflated 80%>"
     
  13. maglib

    maglib Private First Class

    It's still paused but here is the notepad file it created. I still haven't gotten the chance to try and delete or rename that file.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does a notepad window open with the runkeys.txt log in it? It should right after the above message you saw prints.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah! Okay it ran properly. Not sure why it is not running when GetLogs.bat is used.

    Now run ShowNew from the command prompt. This should give you a log named newfiles.txt

    Note: The runkeys.txt and newfiles.txt logs should automatically be added to the C:\MGlogs.zip file as the scans complete.
     
  16. maglib

    maglib Private First Class

    We posted at the same time, did you see the log?
     
  17. maglib

    maglib Private First Class

    Do I stop this run or just shut the window as I can't type in it.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have notepad with runkeys.txt showing, close it. And then from the same command prompt window where you ran GetRunKey (and after doing the cd C:\MGtools) enter the ShowNew command
     
  19. maglib

    maglib Private First Class

    Here it is.
     

    Attached Files:

  20. maglib

    maglib Private First Class

    When I tried to delete or rename powervideo.dll I got:
    "The process cannot access the file because it's being used by another process.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good! Still don't know why the do not run from GetLogs.bat.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Video On-line - {BD907325-42B2-4077-BA63-F636B627C998} - C:\Windows\System32\PowerVideo.dll
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now delete all files in the below folder. Windows will block deletion of a couple from the current date.
    C:\Users\Maggs\AppData\Local\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger. Hopefully it runs properly this time.

    Make sure you tell me how things are working now!

    I'll be back tomorrow .........well that is later today. Got to sleep now. ;)
     
  22. maglib

    maglib Private First Class

    Thanks I've been up for 25 hours and the kids will be up in about 3 hours. I appreciate all the help and I hope I can get through this by tomorrow. Good Night.
     
  23. maglib

    maglib Private First Class

    The avenger is only for XP and 2000 and I'm on vista. Any other solution?

    Thanks I hope you got some sleep.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! It was late. ;)

    Make sure that ComboFix.exe that you downloaded while running the READ ME is on you Desktop. This is necessary for the below steps to work. But DO NOT run it.

    Print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFScript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have the below icons on your Desktop (double click the thumbnail to expand it)
    CFScript.jpg
    • Now refer to the above image and use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.
     
    Last edited: Dec 4, 2007
  25. maglib

    maglib Private First Class

    1A. Part of my vista issue and not being able to run appears to be issues with administrator options. i have to be able to right click and choose run as administrator or many file in the root don't work correctly. When i download files that are supposed to save to anything other than users/maggs I need to save them in my profile and then move them to C:\ manually as they won't save in download mode.

    1.There is no file on my computer called CFScript.jpg.

    2. Since i was so sleepy last night I tried to redo some of the things (I think I couldn't run the one as I was doing it in windows vs. running it in the cmd as administrator mode) and am attaching new logs.

    2.I did try to drag ComboFix-do.txt over ComboFixe.exe and got a blue screen that said "out of memory Freeware implementation of REG.Exe has stopped working."

    In the other screen it said "Were you trying to run CFScript? The name, CFScript appears to be incorrectly spelt." Note spelt vs. spelled

    3.I was able to deletePowerVideo.dll

    4. when I tried to delete temp these 2 didn't delete:
    sqlite_k4ezxH1CIlaTVPa
    (first character was a squiggly which I can't find on keyboard) then it was DFCA26.tmp

    5. I'm still getting cannot fine '::{2559AlF4-2lD7-llDr-BMF-00...... (I can't read my own handwriting)


    Thanks again. I got only 2.5 hours of sleep. I see you've been extremely busy today and it appears many people have same issue. I guess this stuff runs in spurts and is meant to mess with holiday spirits?
     
  26. maglib

    maglib Private First Class

    here's the mglogs.zip too
     

    Attached Files:

  27. maglib

    maglib Private First Class

    first time logs didn't attach. Here is runkeys.txt, newfiles.txt and procdll.txt (I was able to run GetLogs.bat in dos mode as administrator option only)
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean. You already attached the MGlogs.zip file in message # 27. You don't need to attach these logs as they are in MGlogs.zip.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not supposed to have this file on your PC. The instructions did not say that.

    I forgot to change the ComboFix-do.txt to CFScript.txt. See the previous procedure which I just edited to make it correct. However since you have been able to delete the PowerVideo.dll file we don't need to re-run the fix now.


    Exactly when are you getting this and make sure you give me the exact word for word message. Do not abbreviate? And whereever you are getting it, does it happen ever time? Does it also happen in safe boot mode?
     
  30. maglib

    maglib Private First Class

    I don't get the error if I use IE from my desktop but, if I run IE from my Windows Menu then I get the following message in an Windows Internet Explorer box (it has a red circle with a white x in it):

    Cannot find '::{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}'.Make sure the path or Internet address is correct. OK

    I hit the close box and not OK. IE then opens normally. I'm worried to hit OK.

    I don't see anything else wrong at this point. Is there something wrong with the IE option through windows start?

    Aside from that I was trying to understand hijackthis log and wanted to confirm if it was safe to delete the following:
    O1 - Hosts: ::1 localhost

    O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    010 - ALL OF THESE:
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

    O13 - Gopher Prefix:


    Additional questions: What do I neet to do to restore my secure status? should I delete all those files I downloaded?

    Any other clean up I should do?

    Yours appreciatively,
    maglib
     
  31. maglib

    maglib Private First Class

    I also just found out that I can't turn windows security Center Service on. When I try to turn on now, I get the same red circle with white x "the security center service can't be started."
     
  32. maglib

    maglib Private First Class

    Another issue when I shutdown and turned the pc back on it went into the default non-password everyone else sign on and there is an internet explorer error message (yellow triangle with black exclamation point):
    "The Recycle Bin on C:\ is corrupted. Do you want to empty the Recycle Bin for this drive? Yes/No".

    I decided to go to another pc and haven't answered it.
     
  33. maglib

    maglib Private First Class

    Cannot find '::{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}'.Make sure the path or Internet address is correct. OK

    I hit the close box and not OK. IE then opens normally. I'm worried to hit OK.

    I still get this even in safe mode when I go through the start/IE menu but not when I go through the desktop IE. I have reset my IE with no change.

    Other issues from last 2 still exist too like not being able to get Security Center to work.

    Thanks.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not appear to be due to malware. You may want to check in the Software Forum for ideas.

    Those items from your HJT log are normal and some you may need. The below are probably not needed:

    O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000


    For Security Center, try uninstall Spybot and see what happens.
     
  35. maglib

    maglib Private First Class

    I uninstalled both spybot and AVG and rebooted with no luck. The icon disappeared on the taskbar.

    I ran services.msc and double clicked on Security Center and got the message that :

    "Configuration Manager: The specified device instance handle does not correspond to a present device."


    Then the Log On (I changed this in a prior run which had previously selected this account with stars for password) is now Local System account and the Allow service to interact with desktop is not checked.

    The general tab i switched from Automatic (delayed start) to automatic and attempted to start and got the error message:
    Windows could not start the Security Center service on Local Computer.
    Error 1079:The account specified for this service is different from the account specified for other services running in the same process.


    Vista is way too confusing and I have no clue what the above means. Do you?


    On other notes, to get rid of the IE message I cheated and just deleted the old one off the start menu and pinned the desktop shortcut IE to the start menu and now no more problem. No clue why but, I guess it won't matter.


    Thanks. Do you take contributions via paypal?
     
  36. maglib

    maglib Private First Class

    I got the security center to work but, I'm not 100% sure how. I ran Services.msc and started switching some of the things to start and then it ran. If I've got it right, it was either User Profile Service or Windows Installer and if I look at it after reboot User Profile Service is started although Windows Installer is not. It was not Remote Registry nor SecurityCenter that I'm positive of as I tried after doing both of those. Any one else having this problem I would suggest having them start some of these functions although maybe changing Log On for both RemoteRegistry and SecurityCenter to NT AUTHORITY\LocalService and deleting the passowords also helped? I'm not sure.

    At this point my Services.msc looks like this (I'm also attaching a copy I hope):

    RemoteRegistry is automatic and its Log On is Local Service (I deleted both passwords and they automatically were filled in).

    SecurityCenter still says when I double click it the following error:
    "Configuration Manager: The specified device instance handle does not correspond to a present device."
    it looks like: automatic and started with Log On set to Local Service and same password delete that was auto filled in.


    Any idea if this is good or not or what the SecurityCenter error means?
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do the below two Procedures

    Procedure 1
    1. Click the Start, Run and enter eventvwr.msc in the box and click OK.
    2. Accept the UAC prompt
    3. Expand Windows Logs and click on System
    4. On the right-hand side, click "Filter current log..."
    5. Select "Warning," "Critical," and "Error" and hit OK
    6. Find the event(s) from the Service Control Manager that relates to the
      Security Center Service and select it
    7. Hit the "Copy" button on the right hand side
    8. Reply to this message and paste the entire event into your response
    Procedure 2

    1. Click the Start and select All Programs:Accessories
    2. Right-click Command Prompt and select "Run as administrator..."
    3. In the command prompt, type sc qc wscsvc
    4. Click the little "C:\_" icon in the upper left corner
    5. Select Edit:Mark...
    6. Click-drag the cursor over all the output from the sc command to select it
    7. Right-click anywhere in the selection
    8. In your reply to this post, paste the output so we can see what it says.
    The above information may give a little more information on what is going on.
     
  38. maglib

    maglib Private First Class

    There are 1000's of messages relating to servicing and many other things as well, looks like this pc has had issues since before I even received it. Is there an easier way to send you the details or am I giving too much. This is only 2 of thousands of warning, error and critical messages. I pray this is normal......

    Here is a recent ones under servicing:
    Log Name: System
    Source: Microsoft-Windows-Servicing
    Date: 11/29/2007 9:05:43 AM
    Event ID: 4376
    Task Category: None
    Level: Warning
    Keywords: Classic
    User: MAGGSVISTAPC\Maggs
    Computer: homeoffice-pc
    Description:
    Servicing has required reboot to complete the operation of setting package KB941649_1(Update) into Install Requested(Install Requested) state
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Servicing" Guid="{bd12f3b8-fc40-4a61-a307-b7a013a069c1}" EventSourceName="Microsoft-Windows-Servicing" />
    <EventID Qualifiers="32768">4376</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2007-11-29T14:05:43.000Z" />
    <EventRecordID>21340</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>homeoffice-pc</Computer>
    <Security UserID="S-1-5-21-3888322268-3302397270-4173792592-1000" />
    </System>
    <UserData>
    <CbsPackageChangeState xmlns="http://manifests.microsoft.com/win/2004/08/windows/setup_provider">
    <PackageIdentifier>KB941649_1</PackageIdentifier>
    <ReleaseType>Update</ReleaseType>
    <PackageState>Install Requested</PackageState>
    <PackageAssembly>Package_1_for_KB941649~31bf3856ad364e35~x86~~6.0.2.1</PackageAssembly>
    <Operation>Installed</Operation>
    <OperationCompleted>True</OperationCompleted>
    <ErrorCode>0x0</ErrorCode>
    <RebootOption>True</RebootOption>
    <MissingElements>
    </MissingElements>
    </CbsPackageChangeState>
    </UserData>
    </Event>


    Here is one under Service Control Manager eventlog Provider:
    Log Name: System
    Source: Service Control Manager
    Date: 12/3/2007 10:42:23 PM
    Event ID: 7000
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: MaggsVistaPC
    Description:
    The Security Center service failed to start due to the following error:
    The account specified for this service is different from the account specified for other services running in the same process.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Service Control Manager" Guid="{555908D1-A6D7-4695-8E1E-26931D2012F4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2007-12-04T03:42:23.000Z" />
    <EventRecordID>23423</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>MaggsVistaPC</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="param1">Security Center</Data>
    <Data Name="param2">%%1079</Data>
    </EventData>
    </Event>
     
    Last edited by a moderator: Dec 5, 2007
  39. maglib

    maglib Private First Class

    Microsoft Windows [Version 6.0.6000]
    Copyright (c) 2006 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>sc qc wscsvc
    [SC] QueryServiceConfig SUCCESS

    SERVICE_NAME: wscsvc
    TYPE : 20 WIN32_SHARE_PROCESS
    START_TYPE : 2 AUTO_START
    ERROR_CONTROL : 1 NORMAL
    BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    LOAD_ORDER_GROUP :
    TAG : 0
    DISPLAY_NAME : Security Center
    DEPENDENCIES : RpcSs
    : winmgmt
    SERVICE_START_NAME : NT AUTHORITY\LocalService

    C:\Windows\system32>
     
    Last edited by a moderator: Dec 5, 2007
  40. maglib

    maglib Private First Class

    Here is the log attached I think.

    Sadly it was too big to attach. Here is just Error for Service Control Manager and Servicing with no details:
     

    Attached Files:

    Last edited by a moderator: Dec 5, 2007
  41. maglib

    maglib Private First Class

    I also found the following in control panel/System and Maintenance/Problem Reports and Solutions/View Problem History (looks like Combofix has some issues in compatability but, I can't figure out how to copy this report nor print it other than screen shots to onenote and saving. It's shortcut is Windows\System32\wercon.exe


    I just learned how to zip a file so I attached it and the error report.
    Sorry about being somewhat clueless.
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well this is a somewhat typical problem on Vista that seems to be occurring more and more frequently. If you are still having problems we may have to play around with services.msc and for the Security Center Service on the Log On tab to change the account specified to NT AUTHORITY\LocalService and delete the passwords. I have used this a few times and sometimes it works and sometimes it does not. It works more reliably under Windows XP than in Vista.


    Similare procedures have been used in the past for other services like Remote Registry. An example of that can be found here:

    http://windowsxp.mvps.org/remotereg.htm
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds