PC_Antispyware 2010

Discussion in 'Malware Help (A Specialist Will Reply)' started by PoolBoy, Aug 24, 2009.

  1. PoolBoy

    PoolBoy Private E-2

    Hello,

    Operating system Win XP Pro / SP3

    I have been infected with this terrible program as well as others I am sure.

    It has hijacked the browser which now does re-directs on searches.

    Also RUNDLL Error Loading tapi.info

    I ran SuperAntiSpyware and it found some items and said it needed to reboot. Upon reboot the program would not run again saying I did not have access permission. I tried to uninstall/reinstall SAS but I get the following error message; "Windows Installer has insufficient privileges to modify SuperAntiSpyware.exe"

    Malwarebytes installed and updated itself but when running it only runs for a few seconds and then goes away. When trying to restart is says can not find path, program, etc.

    ComboFix runs but hangs afted getting to "deleting folders" (let run 1 hour)

    RootRepeal starts and says "Intializing, please wait..." and never progresses (let run 1 hour)

    All the above have been tried in "Safe Mode" with similar results.
     

    Attached Files:

  2. PoolBoy

    PoolBoy Private E-2

    Additional information;

    Can not go to System Restore to delete restore points. The System Restore tab is missing when right clicking on My Computer.

    When trying to go through the Windows Menu to System Restore the following message appears; "System Restore has been turned off by group policy"
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this:

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Now see if you can run the other scans....attach the logs that you can produce.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.
     
  4. PoolBoy

    PoolBoy Private E-2

    Trying to remove JS2E Runtime Environment via Add/Remove gave the following error message; Error applying transforms. Verify that the specified transform paths are valid.

    Reg-edit was successfully entered into registry.

    Avenger was successful.

    None of the other scans would run. Same results as before with the exception of Root Repeal. Came back after running it to a blue screen of death saying something to the effect of windows being stopped (the entire text was not visible on the display).

    I turned off the computer and turned back on. Started to come back up but to a white background with a blue triangle with an exclamation point, and a brief text message asking if i had changed my background and i think it said because my background has been changed to a web page or something like that.

    Then it came up to my background picture and just stopped. I rebooted into safe mode and it allowed me to click on my name (user) and then it went to a black screen that says safe mode in corner. Nothing else on screen. I am able to ctrl, alt, del and bring up task manager.

    I have rebooted and it just comes up to my desktop photo. There is nothing else. I am using task manager to open up programs and to run MGTools.

    Please help. This is worse than ever!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use task manager to start Avenger.exe.

    Once it opens...* -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    See if you can now boot normally.
     
  6. PoolBoy

    PoolBoy Private E-2

    Did not work.

    Avenger reported that it executed script and then it rebooted the computer.

    The computer came up to just my desktop background only (no icons) just as before.

    I ran again MGTools in case something has changed.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this while I check your logs.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  8. PoolBoy

    PoolBoy Private E-2

    It reported success but no change after re-boot.
     
    Last edited: Aug 31, 2009
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\Avenger.txt
    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. PoolBoy

    PoolBoy Private E-2

    Avenger ran successfully.

    ComboFix did not run after reboot.

    Desktop remains the same (no icons).
     

    Attached Files:

  11. PoolBoy

    PoolBoy Private E-2

    I have manually started ComboFix. It found a newer version and has updated itself. It is currently scanning. I will report back when it has completed.

    If is successfuly completes and creates a log file I will run MGTools again.

    Based on the previous attempts of running ComboFix I do not hold out much hope on a successful run.
     
  12. PoolBoy

    PoolBoy Private E-2

    ComboFix got to the same point in the past where it would hang or stop, "Deleting Folders". I left the room and heard the computer reboot. The computer came back up to the desktop photo only (no icons).

    I ran GetLogs.bat and the zip file is attached.

    There is no file C:\ComboFix.txt to attach so obviously ComboFix did not finish completely.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Open Task Manager and click File, New Task (Run...) and enter cmd into the box and click OK. This should open a command prompt window if it works properly. Copy and paste the below into the command prompt window. (You right click in the command prompt window to be able to select Paste).

    copy C:\WINDOWS\ServicePackFiles\i386\explorer.exe c:\windows\explorer.exe

    If the above command states the file was copied, now try to run explorer.exe and see if your Desktop appears.
     
  14. PoolBoy

    PoolBoy Private E-2

    That worked. The Desktop is back albeit now has a warning pasted over the background picture saying "danger! Your computer is infected ..........

    Immediately upon typing explorer.exe in the DOS window another DOS window openen up and ComboFix finished running and created a log.

    I then ran again MGTools again and created a new log file for that.
     

    Attached Files:

  15. PoolBoy

    PoolBoy Private E-2

    Ok so I crossed my fingers and did a reboot and my desktop was still there. I can also report that I am no longer recieving the RUNDLL ERROR: Tapi.nfo message anymore.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Much better...now use windows explorer to find and delete:
    c:\windows\system32\onhelp.htm

    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the Exe file and attach the new MGLogs.zip
     
  17. PoolBoy

    PoolBoy Private E-2

    That took awhile. Dam redirector would not let me get to the new MGTools page.
     

    Attached Files:

  18. PoolBoy

    PoolBoy Private E-2

    So with the little success that was made today I decided to start back at square one and see what would run and what would not.

    SuperAntiSpyware - Can not install. Getting 1321 error where I do not have permission to modify superantispyware.exe

    Malwarebytes - Installed and ran successfully

    ComboFix - Ran successfully

    Root Repeal - Starts and says "Initializing, please wait..." at the 1/2 hour mark windows said virtual memory getting low, at the 1 hour mark - nothing. Windows task manager reported program not running. Root Repeal ended by me.

    MGTools - Successful
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this and see if that finishes it.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  20. PoolBoy

    PoolBoy Private E-2

    RegEdit reported success.

    How things are running;

    About 30% of my desk top icons are wrong or different. Several are generic Microsoft; Norton, SAS, Desktop Manager (BlackBerry), Quick Time, HP, Virtual Earth.

    All icons now have their text in a blue rectangle window verses being over the desk top photo.

    All Adobe Acrobat icons are now a small logo on a white back ground when before they were just a large logo.

    All Microsoft Office programs are missing from any menu including those that were anchored in my windows start menu (MS Office Pro 2003).

    Microsoft Word always has the following error now upon opening and closing; MICROSOFT VISUAL BASIC-The macros in this project are disabled. See on line help ......

    I tried to Detect and Repair MS Word, including restore start menu items. It asked for the install disk saying it needed a file. I put the install disk in and then it says it can not find MAINSP3.MSP which is the service pack 3 file I believe. When I go to Microsoft and try to download/install MAINSP3.MSP is says it is already installed. So I have no way to fix or repair Office.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may need to right click each icon / properties / find target. If it does not take you to the exe file, then you will need to delete it, go to the program exe file and right click and send to desktop.

    First lets do this:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FCopy::
    C:\WINDOWS\ServicePackFiles\i386\explorer.exe|C:\WINDOWS\SYSTEM32\explorer.exe
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now go to C:\MGTools\analyse.exe and double click it. Attach the log if it runs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  22. PoolBoy

    PoolBoy Private E-2

    Dragged the created CFscript.txt across to ComboFix. ComboFix ran and updated itself and restarted. After scan or item #50 ComboFix did nothing. After 35 minutes I closed it and rebooted the computer.

    Analyse.exe - Windows can not access the specified device, path, or file. You may not have the appropriate permissions to run the item.

    GetLogs.bat - Zip file attached

    -----------------------------------------

    **New Symptom**Automatic Windows updates can not install. It appears that there is something affecting Windows Installer. It can not find the appropriate install file.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. Any additional issues you are having need to be addressed in the software forums.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  24. PoolBoy

    PoolBoy Private E-2

    So all of the problems with SAS, ComboFix, RootRepeal not running/installing are not a result of Malware and can not be corrected?

    The Windows Installer not being able to install programs as a result of this attack will be addressed in this other forum?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member



    Try the below:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your root folder (C:\Junction.zip)
    • Unzip it and put junction.exe in the root folder (C:\junction.exe)
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >C:\log.txt
    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes).
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.
     
    Last edited: Sep 19, 2009
  26. PoolBoy

    PoolBoy Private E-2

    The Win32kDiag ran and created a log.

    Junction was not successful. The DOS window briefly flashes. I confirmed that Junction.exe is in c:\ and not in c:\Junction
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Win32kDiag fixed a bunch of issues with permissions in the Windows folders. Let's try the below with Junction to see if we can locate issues out side of the Windows folders. Make sure that you follow these steps exactly and redownload Junctions.


    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your Desktop this time.
    • Unzip it and save junction.exe to your Desktop
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
    cmd /c C:\Documents and Settings\JEFF\Desktop\junction -s c:\ >C:\log.txt

    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes).
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.
    Now do the below no matter what happens with the above!

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the log from Junction if it ran.
    • C:\MGlogs.zip
     
  28. PoolBoy

    PoolBoy Private E-2

    Junction result same as before, the DOS window briefly flashes.

    New MGLogs.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's try it in another folder where we can fix permissions. First run C:\win32kdiag.exe -f -r
    like you did back in msg # 25.

    No let's try the below with Junction in the Windows folder to see to see if it will run.



    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your C:\Windows this time.
    • Unzip it and save junction.exe to your C:\Windows
    • Now click Start => Run and enter cmd into the box and click OK. This will open a command prompt window.
    • Now Copy and paste the following command into the run box and click OK. I say copy and paste because you must get the space correct.
    C:\Windows\junction -s c:\ >C:\log.txt

    • A license agreement from SysInternals should appear if junction runs.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes).
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.
    Now do the below no matter what happens with the above!

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the log from Junction if it ran
    • C:\MGlogs.zip
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmmm!!! I just looked at you last MGlogs.zip file and I see why Junction is not running. You did not put the Junction.exe file on your Desktop. You the Junction.zip file on your Desktop but you extracted Junction.exe into a folder named Junction on your Desktop which is why the command will not work and also it is why my last message will fail if you attempt to follow those instructions. You are not doing what I asked you to do. You need to put the Junction.exe file where requested.
     
    Last edited: Sep 25, 2009
  31. PoolBoy

    PoolBoy Private E-2

    First I ran C:\win32kdiag.exe -f -r

    Ok I believe Junction is saved in the right place now (when unzipped it automatically creates the \Junction folder).

    Same result, DOS windows flashes


    Then I put Junction in the C:\Windows folder. This time the license agreement window also opened up. I clicked on agree and both windows closed.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably because you are using the lousy built in ZIP function of Windows. It was not in a folder to begin with so it should not be put in a folder when extracted. You may want to check your Windows Options. I never used the Windows ZIP function since the day I installed XP. I always use WinZip which is 1000x better.

    You mean the original command prompt Window close too?
     
  33. PoolBoy

    PoolBoy Private E-2

    Yes, the command prompt window closed as well after agreeing to license.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now that Junction.exe is in the Windows folder, run the C:\win32kdiag.exe -f -r
    command one more time and attach this log so we can see if it detects any permissions issues with Junction.
     
  35. PoolBoy

    PoolBoy Private E-2

    Ran as requested

    I can not attach the log file it says already attached
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Need the log. ;)
     
  37. PoolBoy

    PoolBoy Private E-2

    Had to put it into a zip file
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and save Inherit to your Windows folder.

    Then from your Windows Explorer window, drag junction.exe ontop of inherit.exe.

    Now also drag C:\MGtools\analyse.exe on top of inherit.exe

    Did you get an OK for each file?

    Now see if the junction will run.

    Also run C:\MGtools\GetLogs.bat and and then attach the new C:\MGlogs.zip file after it finishes.
     
  39. PoolBoy

    PoolBoy Private E-2

    I had to also put Inherit into c:\MGTools in order to drag analyse.exe onto Inherit.exe

    Both responded with OK

    Junction still just flashes the command window
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'm not sure why Junction will not run but Inherit did fix analyse.exe which now ran and produce a log in the MGlogs.zip file.

    What problems do you still see? Can you run SUPERAntiSpyware now? If not, put inherit.exe into the C:\Program Files\SUPERAntiSpyware folder and then drag the
    SUPERAntiSpyware.exe file ontop of inherit and then see if you can run SUPERAntiSpyware. You can do this for any program that does not appear to run.
     
  41. PoolBoy

    PoolBoy Private E-2

    SAS would not run getting the same error message ever since the attack over a month ago. "Windows can not access the specified device, path, or file. You may not have the appropriate permissions to run the item."

    Copied Inherit.exe into the SAS folder and draged SAS.exe and now SAS is running and doing a scan. 205 items found so far (203 adware and 2 Rouge.WindowsPolicePro)

    It looks like I will have to do this with ComboFix, RootRepeal, etc.

    About 30% of my desk top icons are wrong or different. Several are generic Microsoft; Norton, SAS, Desktop Manager (BlackBerry), Quick Time, HP, Virtual Earth.

    All icons now have their text in a blue rectangle window verses being over the desk top photo.

    All Adobe Acrobat icons are now a small logo on a white back ground when before they were just a large logo.

    All Microsoft Office programs are missing from any menu including those that were anchored in my windows start menu (MS Office Pro 2003).

    Microsoft Word always has the following error now upon opening and closing; MICROSOFT VISUAL BASIC-The macros in this project are disabled. See on line help ......

    I tried to Detect and Repair MS Word, including restore start menu items. It asked for the install disk saying it needed a file. I put the install disk in and then it says it can not find MAINSP3.MSP which is the service pack 3 file I believe. When I go to Microsoft and try to download/install MAINSP3.MSP is says it is already installed. So I have no way to fix or repair Office.


    I am thinking that after this Malware attack that I most likely need to re-install the operating system and all of my software. Or better yet get a new computer with Windows 7 next month.
     
  42. PoolBoy

    PoolBoy Private E-2

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would like to see all of these logs.

    I'm still wondering why you cannout run junction.exe.

    Please download the current version of MGtools and this time save it to your C:\Windows folder (yes this is not normally where we want it but this is a test). Then locate the C:\Windows\MGtools.exe file and double click on it to run it. When it finishes, attach the new C:\MGlogs.zip file.

    Do the Desktop shortcuts work? i.e., are they associated with the correct programs. Blue shading on Desktop icons while not normal, is typically a settings issue. First thing I would try is right clicking on the Desktop and selet Arrange Icons By, then make sure to uncheck Lock Web Items on Desktop.

    This may be a faster solution since you may have too much damage to reliably recover from and you may have many outstanding permissions issues which is why various programs are having problems running or running properly.

    By the way Windows Installer issues related to MS Office have long been problematic. Sometimes it is triggered by malware attacks but many times it is not due to malware. This would be something better worked in the Software Forum but did you try dragging outlook onto inherit?

    That's up to you. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds