Winlogin.exe Error

Discussion in 'Malware Help (A Specialist Will Reply)' started by dgmgcg, Aug 4, 2006.

  1. dgmgcg

    dgmgcg Private E-2

    I keep receiving a winlogin.exe error. It's a blue screen that informs me that my computer has been shut down. I have run all sorts of antivirus scans but cannot seem to find anything. Help, please?

    I've attached the HJT log file.

    Michelle
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. dgmgcg

    dgmgcg Private E-2

    Thanks for your quick reply. I am currently working through the steps in Read and run me first. I do have a question, though.

    Step one says to remove any spyware through control panel -> add/remove programs. I did find a MyWay Search Assistant thing, however it will not let me remove it. You know the nifty little button that says remove on EVERY other program listed? It doesn't exist there. All it says is "Used - Rarely".. and nothing more. I cannot figure out how to get rid of it and wasn't sure if I should proceed to step two without it..

    Help? :confused:

    Michelle
     
  4. dgmgcg

    dgmgcg Private E-2

    Alright, I am back and I've worked through the Read Me First stuff as much as possible. I did skip the system restore step, because the instructions stressed that you do that ONLY after you're clean. I could never get clean, I think, and I was afraid to do that. Let me know if I should..

    Here are the results I got. (I will also attach log files)

    GetRunKey would never work for me. It would open, the black little box, and then just disappear. The newfiles one worked and I have the log, but no matter what I tried GetRunkey would not.

    In safe mode I ran Ccleaner, and it found a zillion things and said it deleted em all.

    I then ran Microsoft malicious Software and it found nothing.

    I ran Spybot Search and Destroy and it found 17 or so items, but it could not remove a "BearShare" regkey or something of the sort. It said it was still in use and asked to run SSD upon reboot.

    I then ran Windows Defender, which found a whole bunch of stuff as well. One of those was Virtumonde.C. It said it deleted all the infected files.

    I ran Bitdefender, found lots of things, said it cleaned 'em all.

    I ran Panda, and it found a lot of things too, but I couldn't figure out how to get it to clean anything without paying so I just saved the log.

    I rebooted into normal mode and SSD automatically popped up before anything loaded. If possible, it found more the second time than the first?! It said it cleaned it all.

    I then installed HJT as per instructions, renamed it, and ran it. I'll attach the log file.

    After all of this, I checked in control panel add/remove programs just to see if that MyWay Search Assistant was still there. It is.

    Ahhhhhhhh!

    At any rate, thanks for taking the time to read all of this and I'll attach the logs.

    Michelle
     

    Attached Files:

  5. dgmgcg

    dgmgcg Private E-2

    Other two files. Also, I forgot to explain why there are two bdscan files. I ran the scanner once and the computer completely froze up and went wonky, so I had to restart it. I managed to save the report from the first time before everything went blue, so I attached both.

    Also, I'm not sure if this is normal but I thought I'd describe it just in case.. While in Safe Mode, it would begin with the taskbar shown and everything looked 'normal' only big and safe modeish. An error message of some sort would pop up and disappear so quickly that I couldn't read it, and then the screen would go black. It said Microsoft Safe Mode at the top and bottom, but there was no taskbar or Start button. I had to alt+ctrl+del to open the taskmanager, and use the file - run option from that to run any of these files.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Choose the download from below that is appropriate for your Windows Version and run it:

    For Windows XP Pro: download and run XPproFix
    For Windows XP Home: download and run XPHomeFix
    For Windows 2000: download and run: W2KFix

    Then try running GetRunKey again ALSO MAKE SURE you extracted ALL the files from the ZIP file, otherwise you will get a blank log.

    Don't worry about MyWay, we will get rid of it later.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of gbeabwcb.dll once and then click the kill button. After you have killed all of the gbeabwcb.dll under winlogon click ok. (If you do not find the dll, just continue on.)



    Next double click on explorer.exe and again click once on each instance of gbeabwcb.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.shareware.us/srchasst.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O20 - Winlogon Notify: gbeabwcb - C:\WINDOWS\SYSTEM32\gbeabwcb.dll
    O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll (file missing)


    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\kfiyldri.exe
    C:\WINDOWS\SYSTEM32\pqgcsnvg.exe
    C:\WINDOWS\SYSTEM32\xuxuvfme.exe
    C:\WINDOWS\SYSTEM32\gbeabwcb.dll
    C:\WINDOWS\SYSTEM32\klkkj.ini2
    C:\WINDOWS\Temp\1.tmp

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\David & Michelle\Local Settings\Temp\

    Now attach a new HJT log and tell me how the steps went.

    Also download the newest version (just updated) of ShowNew and attach a new log from ShowNew.

    Make sure you tell me how things are working now!
     
    Last edited: Aug 8, 2006
  7. dgmgcg

    dgmgcg Private E-2

    Thanks so much for all of your help. Here are my results.

    In order of your instructions, I downloaded the fix for my version of windows and GetRunKey still will not work. It doesn't create ANY log at all. A blank black screen pops up, then disappears in a second.

    I downloaded the two other programs, Process Explorer and Killbox. Rebooted in normal mode, disconnected the cables, and closed everything. Then I opened Process Explorer, and I couldn't find the gbeabwcb.dll under winlogon OR explorer, so I went on as you instructed.

    I ran HJT and found all the lines you indicated. I checked them and clicked fix.

    I did the fixme.reg file as you instructed also.

    I ran Pocket Killbox, deleted all of the files you listed, and rebooted. I came back and deleted all of the files in the Local Settings\Temp folder. I will attach my new HJT log and my new ShowNew file to this post.

    Everything seems to be working fine but I really didn't notice much to indicate the presence of these things anyway. I think I've probably had a lot of them a while, it's only been recently that the blue screen of death has made it's appearance.

    A semi-random question: We have a wireless network in our home. I don't know if this matters but it's a Linksys Wireless G broadband router, and a linksys wireless g network card in the laptop. Can these things cross infect ? Should I start this whole process over on the laptop, even though I've never gotten a blue screen on it?

    At any rate, here you go! Again, thanks so much for your help.

    Michelle
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you extracted ALL files from the ZIP file? Where did you extract it too? Tell me what files you see in the folder with GetRunKey.bat

    Typically you will not spread infections accross the network unless you are file sharing on the PCs. It never hurts to check though!

    Okay you're clean but we have a couple things to do!

    First have HJT fix the below left over which has been removed:
    O20 - Winlogon Notify: gbeabwcb - gbeabwcb.dll (file missing)


    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below software using Add/Remove programs:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03
    Notifier
    Viewpoint Media Player

    Now, if you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. dgmgcg

    dgmgcg Private E-2

    Well, I'd say that was easy but...:eek: That'd be a lie. I really appreciate your patience and time, though.

    Alright, I did all that you said in the last post. Except: I couldn't find "Viewpoint" in the add/remove programs list. Should it be there? Also, that stupid MyWay thing is there. And on a random note that maybe you could just help me with :) There's a "Sims Livin Large" thing in there, and when I click remove nothing happens. How do I make these stubborn things go away? :(

    About the getrunkey thing. Okay so I decided to go from scratch. I deleted it all off of my computer, then redownloaded the zip file. I clicked "Extract All" and it extracted them to C:\Software Removal Tools\GetRunKey folder. Inside (Now, keep in mind, this is all AFTER I extracted. The zip file is still somewhere else. I am NOT looking inside the zip file, I promise.) are the files: GetRunKey.bat which is 41kb and grep.exe 78.5 kb. I clicked it and again the dos prompt thing pops up, it's black, no words at all pop up and then it just disappears.

    I think that's it. I will probably try to work through the Read Me on the laptop just to be sure, before classes start again. I never want to see that lovely blue screen again, much less in the middle of a lecture!

    Michelle
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will get to these later! First I want to figure out why GetRunKey will not run.

    Click Start, Run and enter cmd in the box and click OK. This will open a command prompt windows. In this window enter the below commands.

    cd "C:\Software Removal Tools\GetRunKey"
    getrunkey

    What happens? Tell me if you are seeing any error messages and tell me exactly what they say. I have a feeling that your registry editor (regedit.exe) is corrupted or missing.

    If the above still gives an error or yields a basically blank log, in that command prompt window enter regedit and hit enter. What happens?

    Now try installing this Your Uninstaller! 2006 and use it to uninstall some of the items you are having problems uninstalling. Tell me the results.
     
  11. dgmgcg

    dgmgcg Private E-2

    Okay I did the cmd stuff and here's what happened.

    I went to the GetRunKey directory and then typed in getrunkey, and it hesitated for a second as though it would process and then a really weird message came up. It came up right underneath the line I had just typed and it looked as though half the sentence was missing.

    It said..
    & was unexpected at this time.

    ?

    I typed regedit and the registry editor popped up.

    I haven't tried that uninstaller yet, just heading out, but I'll do it a bit later and let you know the results.

    Michelle
     
  12. dgmgcg

    dgmgcg Private E-2

    The uninstaller worked perfectly.

    Michelle
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using the below attached version of GetRunKey2.zip. The file to run is GetRunKey2.bat

    Extract it into the same folder as the previous version.
    Run it from the command prompt just like last time. Tell me what happens.
     

    Attached Files:

  14. dgmgcg

    dgmgcg Private E-2

    Same EXACT thing! :(

    M
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay from the command prompt while in the folder where you have put GetRunKey, type grep -V and hit enter.

    Do you see the below text?
     
  16. dgmgcg

    dgmgcg Private E-2

    Yes, I seen exactly the thing you quoted.

    M
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay download the attach new version and overwrite the previous version with it.

    Extract the GetRunKey2.bat file to overwrite the previous batch file too.

    After it runs, close the runkeys.txt notepad window that opens. Then look for this file C:\GRKdebug.txt
    Upload this file here as an attachment.


    Note: your system appears to be free from malware but it is troublesome that GetRunKey will not produce an output on your system. You are in effect helping me troubleshoot the reason. This has run thus far on a few hundred PCs without incident (other than when the XPproFix was needed or if all files were not extracted).
     
  18. dgmgcg

    dgmgcg Private E-2

    Okay, I tried AGAIN. I didn't see a file attached to your last post, so I assumed you meant a new version on the site? At any rate, I went and downloaded it again and overwrote all the old stuff. Then I extracted getrunkey2 and overwrote the old one. I went into the dos prompt thing and did it from there, and the same thing happened. A weird message that seems chopped off...

    & was unexpected at this time.

    Then I did a search for any of the files there should have been but there are none.

    I'm glad my system seems all better, but what does it mean that the getrunkey wont work? Is it something wrong with my pc?

    At any rate I'm very glad to help. (Am I?)

    =)

    Michelle
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that Michelle! I was in a rush (I was late for a meeting) and I forgot to actually attach the new version. I'm attaching it now to this message. Please use it and then upload that GRKdebug.txt file I requested.

    Yes you are helping. The only real way we can make sure our programs always run properly is to test them on as many PCs as possible. I have run this on so many PCs that it is hard to imagine why it is not running. The only thing I can think of is some kind of conflict with a file or process name with somethings on your PC. The log from Shownew reveals that GetRunKey is getting pretty far into the program because I can see all the temp files created while GetRunKey is collecting data. The trouble is that it never completes. I'm trying to narrow in on exactly where it is dying before that message prints on your screen. So this new version will not fix that problem (not yet) but the GRKdebug file should give me a feeling for where it gets too.

    Thanks for helping debug this. I cannot debug it anywhere else since it runs on every PC and every Windows OS I have tried.
     

    Attached Files:

  20. dgmgcg

    dgmgcg Private E-2

    Alright, I did as you requested. In the prompt it looked the same with the same unusual error message. I did find, however, the GRKdebug file you want and am attaching it now!

    Michelle
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay thanks! That's a start! Now repeat with this attachment and then again upload the GRKdebug.txt file.

    Again I still expect the same error message because I'm not fixing anything yet. I'm just trying to locate the exact point where it is failing. It does not make any sense right now based on what the last GRKdebug.txt file indicated.
     

    Attached Files:

  22. dgmgcg

    dgmgcg Private E-2

    Here ya go!

    I must say, you seem like a genius to me. This is all like speaking Greek! Do you work in this field?

    Michelle
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why thank you! ;) I don't really work in this field but I do use PCs for work. I'm a Research & Development Engineer.


    Okay let's give this new attachment a try.

    This time in addition to C:\GRKdebug.txt also locate the below file and attach it too:

    C:\xtemp100.txt
     

    Attached Files:

    Last edited: Aug 8, 2006
  24. dgmgcg

    dgmgcg Private E-2

    All done.

    I got a different error message this time.

    It said:
    LOOKING FOR C:\DOCUME~1\DAVID
    The system cannot find the path specified.
    & was unexpected at this time.

    Also, I couldn't find xtemp100! I did find an xtemp98 so I attached it in case.

    I think it's great what you do here, helping people and all.

    Michelle
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From the command prompt window enter the below command and tell me what you get:

    echo %TEMP%


    Also run this new version of GetRunKey2.bat and attach the GRKdebug.txt log and the xtemp100.txt log (if it is found).
     

    Attached Files:

    Last edited: Aug 30, 2006
  26. dgmgcg

    dgmgcg Private E-2

    Okay, here's the error message:

    The filename, directory name, or volume label syntax is incorrect. The System cannot find the path specified.

    The new runkey worked. I think? I'm attaching two files. There were NO xtemp files at all..

    Michelle
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! This reveals the problem! Something in your Windows XP environment is not setup properly. It should have shown something like:

    C:\DOCUME~1\username\LOCALS~1\Temp

    where username is user user login account name. The real full path is
    C:\Documents and Settings\username\Local Settings\Temp

    We need to figure out how to get this setup properly.

    What is your user account name?
     
  28. dgmgcg

    dgmgcg Private E-2

    David & Michelle is the only one on the 'puter, as far as I know!

    M
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To Fix the TEMP Environment variable

    1. Right-click My Computer and select Properties.
    2. Select the Advanced tab.
    3. Click the Environment Variables button.
    4. In the User variables for usernamearea, If the TEMP variable exists, select TEMP (by clicking on it) and click the Edit button and change it to C:\Documents and Settings\username\Local Settings\Temp
    5. If the TEMP variable does not exist, click New and set the below
      • Variable name: TEMP
      • Variable value: C:\Documents and Settings\username\Local Settings\Temp
    6. Then click OK.
    7. Then click OK again to close the Environment Variable window
    8. Then click OK to close the System Properties window
    9. Now Reboot your PC for the change to take effect.
    After reboot, try running the original GetRunKey.bat program and tell me what happens!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    from the command prompt if you enter the below, what do you get:

    echo %username%
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you tell me the exact output with any spaces or punctuation....etc.
     
  32. dgmgcg

    dgmgcg Private E-2

    It says:

    'David' is not recognized as an internal or external command, operable program or batch file.
    'Michelle' is not recognized as an internal or external command, operable program or batch file.

    Working on the other stuff at this moment.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I deleted that other info right now since we really need to know the full user account name first.

    Sounds like your environment variable are all messed up!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From a command prompt enter the below:

    set > c:\env.txt


    Then locate the c:\env.txt file and upload it here as an attachment!

    I think the user account name is why you got the strange message with & was unexpected at this time
    You have an & in your user account name and it is not really valid to have this. When the system got to the & in your account name it barfed!
     
  35. dgmgcg

    dgmgcg Private E-2

    Sorry for getting ahead of myself! Here ya go..
     

    Attached Files:

    • env.txt
      File size:
      1.1 KB
      Views:
      1
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to change this:

    TEMP=C:\Documents and Settings\username\Local Settings\Temp

    to

    TEMP=C:\Documents and Settings\David & Michelle\Local Settings\Temp
     
  37. dgmgcg

    dgmgcg Private E-2

    You meant in the same place as you had mentioned. Right click my computer, etc etc?

    I did that there and ran the set thing again, I'll post the log. Dunno if thats necessary or useful or not but if it is that'll save a whole post! :)

    How do I take the & out of our username? Would that make things easier?

    Michelle
     

    Attached Files:

    • env.txt
      File size:
      1.1 KB
      Views:
      1
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well user accounts can have their names changed via Control Panel ---> User Accounts . But I'm not 100% sure of the impact on anything else you have setup with your account when the name changes. It is really rather stupid of Windows to allow the character in there to begin with because of problems like we are seeing here where GetRunKey would fail and so would even echoing your %username% and %TEMP% environment variables. All this just due to the &. If you put "" around the echo it will probably work OK!

    Try echo "%username%"
    The only problem is that now the quotes are also echoed. So you will probably see

    "David & Michelle"
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just checked! Changing the user account name will only change the loging ID and will not resolve the environment problems! They will still show with the & in them and nothing will change as far as that goes. I'm not sure there is a fix for this. I can make a change to GetRunKey.bat to bypass this potential illegal user name problems that cause a problem due to the TEMP environment variable that I was looking at to detect possible malware; however, I would expect that this could represent problems in more places than just my simple batch file scanner.

    You need to fix the TEMP environment variable. In your last attachment you showed

    TEMP=TEMP=C:\Documents and Settings\David & Michelle\Local Settings\Temp

    The extra TEMP= must be removed.
     
    Last edited: Aug 8, 2006
  40. dgmgcg

    dgmgcg Private E-2

    This sounds so ominous! What do I do?

    I think I fixed the problem, and I regenerated the text file so you can have a look.

    Did you still want me to try to run the original getrunkey to see if it works now?

    Michelle
     

    Attached Files:

    • env.txt
      File size:
      1.1 KB
      Views:
      1
  41. dgmgcg

    dgmgcg Private E-2

    Oh, I forgot to mention....

    I did the echo thing with "s and it turned out exactly as you said. "David & Michelle"

    I have a random question. On my laptop everytime you start in normal mode the system configuration utility pops up and says it's running in selective or diagnostic mode and some other stuff (it's like a warning message). I click okay then the utility itself pops up. It says it's running on Selective Startup with Process System.ini, win.ini, load system services, load startup items, and Use Modified Boot.ini checked. I would have never changed this and I don't even know how to open it (or is it msconfig?.. anyway..) I'm sure it's been like this for weeks but I'd never had anyone to ask about it!! :)

    M
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have not had any problems up to now, I would not worry about it. But just be aware of a potential problem. If you even see that strange message again with the & in it, it should ring a bell as to what the problem is.

    Yes you have it correct now.

    No! It will not run with that type of username. It will always die at that point. As of yet, I cannot find any work around for a non-valid user name. At least not when used at a command prompt or in an batch file using the Windows environment variables.

    For now I would just say we are done. Your malware was fixed (quite awhile ago) but wanted to make sure there was no malware causing a problem that made GetRunKeys fail. Now we know the reason and I thank you for the help in debugging this.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I expected but we cannot use the quotes in my GetRunKey program because your file paths and environment variables do not have quotes in them and thus what I'm looking for would never be found even though the program would run to completion.

    Yes it is MSconfig. Just select Normal Startup in the System Config Utility window. Then reboot and see if everything it okay.
     
  44. dgmgcg

    dgmgcg Private E-2

    You're welcome, although I'm not sure I did very much.

    Thanks for helping with the buggies on the machine. I haven't had that lovely blue screen in days, so I guess all is well.

    I'm sure I'll be back in a few days. I'm going to run through the Read Me on my laptop just in case, and post the logs just so someone can give them a once over and make sure I'm not missing anything important!

    I switched it over to normal startup and everything seems okay. So I guess this is a wrap!

    Again, thanks a bunch for everything.

    (Oh, and to reaffirm the obvious - we each have a separate username on the notebook, and so GetRunKey worked perfectly the first try on it.)

    Michelle
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you did! You helped me understand where the problem was! We found out that it was not malware or a bug in GetRunKey, but rather an unfortunate choice of user name that Windows also unfortunately allowed you to use.

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds