Error 1406 on Microsoft Office Professional

Page 1 of 2 12 LastLast

  1. Posts : 5
    Windows 7 Ultimate x64
       #1

    Error 1406 on Microsoft Office Professional


    I have had Microsoft Office Professional 2010 installed on my home computer for a couple of years and a few days ago it refused to open any Office files saying something about the registry and that I had to fix Office using programs in the control menu. This didn't work so I tried uninstalling office and reinstalling it but I get the following error message:

    Error 1406. Setup cannot write the value to the registry key \Software\Classes\Interface\{9149345A-5191-11CF-8700-00AA0060263B}\TypeLib. Verify that you have sufficient permissions to access the registry or contact Microsoft Product Support Services (PSS) for assistance. For information about how to contact PSS, see C:\Users\Maja\AppData\Local\Temp\Setup000012d8\PSS10R.CHM.

    I have full administrator permission and controls on my computer. I have uninstalled any useless programs that have recently been installed including a norton web checking side program but it hasn't made any difference.
      My Computer


  2. Posts : 10,200
    MS Windows 7 Ultimate SP1 64-bit
       #2

    mtopping,
    Welcome to SevenForums.

    First and foremost:
    Run Windows Defender Offline.
    WINDOWS DEFENDER OFFLINE IS NOT Windows Defender.

    Once again MS has made an ununderstandable naming of a program.

    Click on the WDO (Windows Defender Offline) link in my signature.
    Put WDO onto a usb stick. boot from the stick. WDO will automatically run a quick scan. After the quick scan, you run a full scan of all of your drives.

    Besides the excellent explanation at the MS link, we also have a tutorial on using WDO, and you , you lucky dog, get my write-up. Be sure to post back the .log files when finished.

    HOW TO USE WINDOWS DEFENDER OFFLINE ON A USB STICK
    Windows Defender Offline
    · is a free standalone, bootable malware and virus remover from Microsoft.
    · performs an offline scan of an infected PC to remove viruses, rootkits and other advanced malware.

    Download Windows Defender Offline (about 764 kB)

    You will have the choice of downloading the 32bit version (x86) or the 64 bit version (x64).
    The link will help you determine whether you are running a 32 bit version or 64 bit version of Windows

    NOTE!! You can download and prepare a 32 bit version using a 64 bit version of Windows
    NOTE!! You can download and prepare a 64 bit version using a 32bit version of Windows.

    You run the 32 bit version on a 32 bit version of Windows.
    You run the 64 bit version on a 64 bit version of Windows.

    The 32 bit download file name is: mssstool32.exe
    The 64 bit download file name is: mssstool64.exe

    For the curious, this program was originally name Microsoft Standalone System Sweeper.


    INSTALLATION:
    You will need an Internet Connection.
    Insert 512 mB (Microsoft’s 256 mB is no longer accurate) or larger USB stick into a usb port.
    Run the downloaded program--mssstool64.exe or mssstool32.exe
    NEXT button
    Choose the option On a USB flash drive that is not password protected
    NEXT button
    NEXT button
    .
    The install program will format the usb stick using the NTFS format.
    The install program will download about 210 mB.
    The install program will name the USB stick WDO_Media32 or WDO_Media64
    The WDO_Media32 usb stick will have used space of 255 mB (268,140,544 bytes)
    The WDO_Media64 usb stick will have used space of 282 mB (296,165,376 bytes)
    You can expect the number of mB to increase as more malware appears.

    UPDATE Windows Defender Offline USB stick:
    · reinsert the usb stick
    · run the installation program, mssstool64.exe or mssstool32.exe, again.
    · the update will download about 66 mB (mssstool32.exe) and 68 mB (mssstool64.exe).

    Since the malware database is sometimes updated several times in a day, always update before running.

    PERFORM AN OFFLINE SCAN
    Bootup your computer from the USB stick
    Windows Defender Offline will automatically perform a quick scan.
    After the quick scan finishes, Choose Full Scan
    Select all of your drives

    The initial, full scan can easily take several hours, but
    Remember, your computer is being very thoroughly checked for all types of malware.


    RESULTS OF THE SCAN
    The results will be in 4 log files in:
    \Windows\Microsoft Antimalware\Support
      My Computer


  3. Posts : 25
    Windows 7 Ultimate x64 Service Pack 1 and ASUS ExpressGate
       #3

    I am assuming that this program can also be run not only from a USB flash stick drive, but also from a built-in (or otherwise) SD Card slot as well?
      My Computer


  4. Posts : 5
    Windows 7 Ultimate x64
    Thread Starter
       #4

    Scan done, here are the log files:


    **********Cache stats************
    No. Of buckets -> 12800
    Each Bucket has max capacity of -> 1 entries
    number of Entries is 0
    Number of invalid entries is 0
    Number of Inserts issued is 0
    Number of replaces issued is 0
    Number of Insert failures is 0
    Number of lookups is 0
    Number of misses is 0
    Number of false fast lookups is 0
    Number of invalidations is 0
    Number of maintenance invalidations is 0
    Current File Size is 311296
    Journal ID = 0
    Trusted image state = 0 USN = 0

    2012-05-10T01:27:27.515Z Version: Product 4.0.1526.0 Service 4.0.1526.0 Engine 0.0.0.0 AS 0.0.0.0 AV 0.0.0.0
    2012-05-10T01:27:43.656Z Version: Product 4.0.1526.0 Service 4.0.1526.0 Engine 1.1.8304.0 AS 1.125.1464.0 AV 1.125.1464.0
    2012-05-10T04:09:58.843Z DETECTION Adware:JS/Pornpop file:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038->(GZip)
    2012-05-10T04:09:58.843Z DETECTION Adware:Win32/OpenCandy file:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe->(inno#000155)
    2012-05-10T04:09:58.843Z DETECTION Adware:Win32/OpenCandy file:\Users\Maja\Downloads\Programs\IZArc4.1.exe->(inno#000155)
    2012-05-10T04:09:58.843Z DETECTION Adware:Win32/OpenCandy file:F:\Programs\IZArc4.1.exe->(inno#000155)
    2012-05-10T04:09:58.859Z DETECTION Adware:JS/Advantage file:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
    2012-05-10T04:09:58.859Z DETECTION Adware:Win32/Advantage file:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
    2012-05-10T04:09:58.859Z DETECTION HackTool:Win32/Keygen file:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip->Windows Loader/Windows Loader.exe

    --------------------------------------------------------------------------------
    2012-05-10T01:27:27.468Z Trace session started - MpWppTracing-05092012-172727-00000003-ffffffff.bin
    2012-05-10T01:27:27.468Z Service is asked to be reenabled.
    2012-05-10T01:27:27.468Z Task(-EnableService) launched**********Cache stats************
    No. Of buckets -> 12800
    Each Bucket has max capacity of -> 1 entries
    number of Entries is 0
    Number of invalid entries is 0
    Number of Inserts issued is 0
    Number of replaces issued is 0
    Number of Insert failures is 0
    Number of lookups is 0
    Number of misses is 0
    Number of false fast lookups is 0
    Number of invalidations is 0
    Number of maintenance invalidations is 0
    Current File Size is 311296
    Journal ID = 0
    Trusted image state = 0 USN = 0

    2012-05-10T01:27:27.500Z Loading engine...
    2012-05-10T01:27:27.500Z loaded!
    2012-05-10T01:27:27.500Z NisUpdate from SignatureDropLocation returns S_OK
    2012-05-10T01:27:27.500Z NisUpdate from SignatureDefaultLocation returns S_OK
    2012-05-10T01:27:27.500Z Cache Disabled: 0
    2012-05-10T01:27:27.515Z Verifying license file...
    2012-05-10T01:27:27.515Z verified!
    2012-05-10T01:27:27.515Z Product supports installmode: 0
    Product Version: 4.0.1526.0
    Service Version: 4.0.1526.0
    Engine Version: 0.0.0.0
    AS Signature Version: 0.0.0.0
    AV Signature Version: 0.0.0.0
    ************************************************************
    2012-05-10T01:27:39.531Z Verifying engine and signature files (source: 0) ...
    2012-05-10T01:27:39.828Z verified!
    2012-05-10T01:27:43.609Z Initializing SQM in engine...
    2012-05-10T01:27:43.609Z SQM initialized in the engine successfully
    Signature updated on ‎05‎-‎09‎-‎2012 17:27:43
    Product Version: 4.0.1526.0
    Service Version: 4.0.1526.0
    Engine Version: 1.1.8304.0
    AS Signature Version: 1.125.1464.0
    AV Signature Version: 1.125.1464.0
    ************************************************************
    2012-05-10T04:09:29.515Z Task(SpyNetService -RestrictPrivileges -AccessKey 52B79C0F-2854-7A08-6CD4-0DFD6E664A06) launched
    2012-05-10T04:09:58.843Z DETECTIONEVENT Adware:JS/Pornpop containerfile:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038;file:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038->(GZip);
    2012-05-10T04:09:58.843Z DETECTION_ADD Adware:JS/Pornpop containerfile:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038
    2012-05-10T04:09:58.843Z DETECTION_ADD Adware:JS/Pornpop file:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038->(GZip)
    2012-05-10T04:09:58.843Z DETECTIONEVENT Adware:Win32/OpenCandy containerfile:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe;containerfile:\Users\Maja\Downloads\Programs\IZArc4.1.exe;containerfile:F:\Programs\IZArc4.1.exe;file:C:\Document s and Settings\Maja\My Documents\Downloads\IZArc4.1.exe->(inno#000155);file:\Users\Maja\Downloads\Programs\IZArc4.1.exe->(inno#000155);file:F:\Programs\IZArc4.1.exe->(inno#000155);
    2012-05-10T04:09:58.843Z DETECTION_ADD Adware:Win32/OpenCandy containerfile:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe
    2012-05-10T04:09:58.843Z DETECTION_ADD Adware:Win32/OpenCandy containerfile:\Users\Maja\Downloads\Programs\IZArc4.1.exe
    2012-05-10T04:09:58.843Z DETECTION_ADD Adware:Win32/OpenCandy containerfile:F:\Programs\IZArc4.1.exe
    2012-05-10T04:09:58.843Z DETECTION_ADD Adware:Win32/OpenCandy file:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe->(inno#000155)
    2012-05-10T04:09:58.843Z DETECTION_ADD Adware:Win32/OpenCandy file:\Users\Maja\Downloads\Programs\IZArc4.1.exe->(inno#000155)
    2012-05-10T04:09:58.843Z DETECTION_ADD Adware:Win32/OpenCandy file:F:\Programs\IZArc4.1.exe->(inno#000155)
    2012-05-10T04:09:58.859Z DETECTIONEVENT Adware:JS/Advantage containerfile:C:\Program Files\AdVantage\ffext.mod;file:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js;
    2012-05-10T04:09:58.859Z DETECTION_ADD Adware:JS/Advantage containerfile:C:\Program Files\AdVantage\ffext.mod
    2012-05-10T04:09:58.859Z DETECTION_ADD Adware:JS/Advantage file:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
    2012-05-10T04:09:58.859Z DETECTIONEVENT Adware:Win32/Advantage containerfile:C:\Program Files\AdVantage\ffext.mod;file:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll;
    2012-05-10T04:09:58.859Z DETECTION_ADD Adware:Win32/Advantage containerfile:C:\Program Files\AdVantage\ffext.mod
    2012-05-10T04:09:58.859Z DETECTION_ADD Adware:Win32/Advantage file:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
    2012-05-10T04:09:58.859Z DETECTIONEVENT HackTool:Win32/Keygen containerfile:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip;file:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip->Windows Loader/Windows Loader.exe;
    2012-05-10T04:09:58.859Z DETECTION_ADD HackTool:Win32/Keygen containerfile:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip
    2012-05-10T04:09:58.859Z DETECTION_ADD HackTool:Win32/Keygen file:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip->Windows Loader/Windows Loader.exe
    Begin Full Scan
    Scan ID:{0588F45D-BE7C-4E8A-9525-01C2082CC1D7}
    Scan Source:2
    Start Time:‎05‎-‎09‎-‎2012 17:34:52
    End Time:‎05‎-‎09‎-‎2012 20:09:58
    Result Count:5
    Threat Name:Adware:JS/Pornpop
    ID:153970
    Severity:2
    Number of Resources:2
    Resource Schema:file
    Resource Path:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038->(GZip)
    Extended Info:5865989931585
    Resource Schema:containerfile
    Resource Path:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038
    Extended Info:0
    Threat Name:Adware:Win32/OpenCandy
    ID:159633
    Severity:1
    Number of Resources:6
    Resource Schema:file
    Resource Path:F:\Programs\IZArc4.1.exe->(inno#000155)
    Extended Info:188534088470235
    Resource Schema:file
    Resource Path:\Users\Maja\Downloads\Programs\IZArc4.1.exe->(inno#000155)
    Extended Info:188534088470235
    Resource Schema:file
    Resource Path:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe->(inno#000155)
    Extended Info:188534088470235
    Resource Schema:containerfile
    Resource Path:F:\Programs\IZArc4.1.exe
    Extended Info:0
    Resource Schema:containerfile
    Resource Path:\Users\Maja\Downloads\Programs\IZArc4.1.exe
    Extended Info:0
    Resource Schema:containerfile
    Resource Path:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe
    Extended Info:0
    Threat Name:Adware:JS/Advantage
    ID:156261
    Severity:2
    Number of Resources:2
    Resource Schema:file
    Resource Path:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
    Extended Info:15568244960619
    Resource Schema:containerfile
    Resource Path:C:\Program Files\AdVantage\ffext.mod
    Extended Info:0
    Threat Name:Adware:Win32/Advantage
    ID:18086
    Severity:2
    Number of Resources:2
    Resource Schema:file
    Resource Path:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
    Extended Info:77481240935276
    Resource Schema:containerfile
    Resource Path:C:\Program Files\AdVantage\ffext.mod
    Extended Info:0
    Threat Name:HackTool:Win32/Keygen
    ID:2147593794
    Severity:2
    Number of Resources:2
    Resource Schema:file
    Resource Path:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip->Windows Loader/Windows Loader.exe
    Extended Info:24633941045526
    Resource Schema:containerfile
    Resource Path:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip
    Extended Info:0
    End Scan
    ************************************************************

    2012-05-10T06:38:56.062Z Task(SpyNetService -RestrictPrivileges -AccessKey 0328A637-2AA9-F858-8CF1-07ACB5105B0D) launched
    Begin Resource Scan
    Scan ID:{96A0E676-066E-4B4C-A8C5-BA87712817C9}
    Scan Source:6
    Start Time:‎05‎-‎09‎-‎2012 22:38:41
    End Time:‎05‎-‎09‎-‎2012 22:39:25
    Explicit resource to scan
    Resource Schema:containerfile
    Resource Path:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038
    Explicit resource to scan
    Resource Schema:containerfile
    Resource Path:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe
    Explicit resource to scan
    Resource Schema:containerfile
    Resource Path:C:\Program Files\AdVantage\ffext.mod
    Explicit resource to scan
    Resource Schema:containerfile
    Resource Path:\Users\Maja\Downloads\Programs\IZArc4.1.exe
    Explicit resource to scan
    Resource Schema:containerfile
    Resource Path:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip
    Explicit resource to scan
    Resource Schema:containerfile
    Resource Path:F:\Programs\IZArc4.1.exe
    Explicit resource to scan
    Resource Schema:file
    Resource Path:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038->(GZip)
    Explicit resource to scan
    Resource Schema:file
    Resource Path:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe->(inno#000155)
    Explicit resource to scan
    Resource Schema:file
    Resource Path:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
    Explicit resource to scan
    Resource Schema:file
    Resource Path:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
    Explicit resource to scan
    Resource Schema:file
    Resource Path:\Users\Maja\Downloads\Programs\IZArc4.1.exe->(inno#000155)
    Explicit resource to scan
    Resource Schema:file
    Resource Path:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip->Windows Loader/Windows Loader.exe
    Explicit resource to scan
    Resource Schema:file
    Resource Path:F:\Programs\IZArc4.1.exe->(inno#000155)
    Result Count:5
    Threat Name:Adware:JS/Pornpop
    ID:153970
    Severity:2
    Number of Resources:2
    Resource Schema:file
    Resource Path:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038->(GZip)
    Extended Info:5865989931585
    Resource Schema:containerfile
    Resource Path:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038
    Extended Info:0
    Threat Name:Adware:Win32/OpenCandy
    ID:159633
    Severity:1
    Number of Resources:6
    Resource Schema:file
    Resource Path:F:\Programs\IZArc4.1.exe->(inno#000155)
    Extended Info:188534088470235
    Resource Schema:file
    Resource Path:\Users\Maja\Downloads\Programs\IZArc4.1.exe->(inno#000155)
    Extended Info:188534088470235
    Resource Schema:file
    Resource Path:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe->(inno#000155)
    Extended Info:188534088470235
    Resource Schema:containerfile
    Resource Path:F:\Programs\IZArc4.1.exe
    Extended Info:0
    Resource Schema:containerfile
    Resource Path:\Users\Maja\Downloads\Programs\IZArc4.1.exe
    Extended Info:0
    Resource Schema:containerfile
    Resource Path:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe
    Extended Info:0
    Threat Name:Adware:JS/Advantage
    ID:156261
    Severity:2
    Number of Resources:2
    Resource Schema:file
    Resource Path:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
    Extended Info:15568244960619
    Resource Schema:containerfile
    Resource Path:C:\Program Files\AdVantage\ffext.mod
    Extended Info:0
    Threat Name:Adware:Win32/Advantage
    ID:18086
    Severity:2
    Number of Resources:2
    Resource Schema:file
    Resource Path:C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
    Extended Info:77481240935276
    Resource Schema:containerfile
    Resource Path:C:\Program Files\AdVantage\ffext.mod
    Extended Info:0
    Threat Name:HackTool:Win32/Keygen
    ID:2147593794
    Severity:2
    Number of Resources:2
    Resource Schema:file
    Resource Path:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip->Windows Loader/Windows Loader.exe
    Extended Info:24633941045526
    Resource Schema:containerfile
    Resource Path:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip
    Extended Info:0
    End Scan
    ************************************************************

    Beginning threat actions
    Start time:‎05‎-‎09‎-‎2012 22:39:26
    Threat Name:Adware:JS/Pornpop
    Threat ID:153970
    Action:remove
    Threat Name:Adware:Win32/OpenCandy
    Threat ID:159633
    Action:remove
    Threat Name:Adware:JS/Advantage
    Threat ID:156261
    Action:remove
    Threat Name:Adware:Win32/Advantage
    Threat ID:18086
    Action:remove
    Threat Name:HackTool:Win32/Keygen
    Threat ID:2147593794
    Action:remove
    File to act on SHA1:6DBE312ADC97CC0F5DCFB527449893EA5169B0B6
    !ERROR
    Action clean/remove failed on file:\\?\F:\Programs\IZArc4.1.exe->(inno#000155)
    Error code:1630
    !ERROR
    Resource action complete:Removal
    Schema:file
    Path:\\?\F:\Programs\IZArc4.1.exe->(inno#000155)
    Threat ID:159633
    Resource refcount:1
    Result:1630
    File to act on SHA1:2B1680820BDBE1903647B64C690D1C381B778344
    File cleaned/removed successfully
    File Name:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip->Windows Loader/Windows Loader.exe
    Resource action complete:Removal
    Schema:file
    Path:\\?\D:\Users\Maja\Downloads\Programs\Windows Loader v1.9.3.zip->Windows Loader/Windows Loader.exe
    Threat ID:2147593794
    Resource refcount:1
    Result:0
    File to act on SHA1:6DBE312ADC97CC0F5DCFB527449893EA5169B0B6
    !ERROR
    Action clean/remove failed on file:\\?\D:\Users\Maja\Downloads\Programs\IZArc4.1.exe->(inno#000155)
    Error code:1630
    !ERROR
    Resource action complete:Removal
    Schema:file
    Path:\\?\D:\Users\Maja\Downloads\Programs\IZArc4.1.exe->(inno#000155)
    Threat ID:159633
    Resource refcount:1
    Result:1630
    File to act on SHA1:23062BB72A27D283F2CE57EFD35C16EAC2575461
    !ERROR
    Action clean/remove failed on file:\\?\C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
    Error code:1630
    !ERROR
    Resource action complete:Removal
    Schema:file
    Path:\\?\C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
    Threat ID:156261
    Resource refcount:1
    Result:1630
    File to act on SHA1:23062BB72A27D283F2CE57EFD35C16EAC2575461
    !ERROR
    Action clean/remove failed on file:\\?\C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
    Error code:1630
    !ERROR
    Resource action complete:Removal
    Schema:file
    Path:\\?\C:\Program Files\AdVantage\ffext.mod->{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
    Threat ID:18086
    Resource refcount:1
    Result:1630
    File to act on SHA1:6DBE312ADC97CC0F5DCFB527449893EA5169B0B6
    !ERROR
    Action clean/remove failed on file:\\?\C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe->(inno#000155)
    Error code:1630
    !ERROR
    Resource action complete:Removal
    Schema:file
    Path:\\?\C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe->(inno#000155)
    Threat ID:159633
    Resource refcount:1
    Result:1630
    File to act on SHA1:E2698352BE874F511DC2C4ACE0BEE85C78D579F8
    File cleaned/removed successfully
    File Name:C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038->(GZip)
    Resource action complete:Removal
    Schema:file
    Path:\\?\C:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000038->(GZip)
    Threat ID:153970
    Resource refcount:1
    Result:0
    Resource action complete:Quarantine
    Schema:containerfile
    Path:\\?\F:\Programs\IZArc4.1.exe
    Threat ID:159633
    Resource refcount:1
    Result:0
    File to act on SHA1:6DBE312ADC97CC0F5DCFB527449893EA5169B0B6
    File cleaned/removed successfully
    File Name:F:\Programs\IZArc4.1.exe
    Resource action complete:Removal
    Schema:containerfile
    Path:\\?\F:\Programs\IZArc4.1.exe
    Threat ID:159633
    Resource refcount:1
    Result:0
    Resource action complete:Quarantine
    Schema:containerfile
    Path:\\?\D:\Users\Maja\Downloads\Programs\IZArc4.1.exe
    Threat ID:159633
    Resource refcount:1
    Result:0
    File to act on SHA1:6DBE312ADC97CC0F5DCFB527449893EA5169B0B6
    File cleaned/removed successfully
    File Name:\Users\Maja\Downloads\Programs\IZArc4.1.exe
    Resource action complete:Removal
    Schema:containerfile
    Path:\\?\D:\Users\Maja\Downloads\Programs\IZArc4.1.exe
    Threat ID:159633
    Resource refcount:1
    Result:0
    Resource action complete:Quarantine
    Schema:containerfile
    Path:\\?\C:\Program Files\AdVantage\ffext.mod
    Threat ID:156261
    Resource refcount:2
    Result:0
    Resource action complete:Removal
    Schema:containerfile
    Path:\\?\C:\Program Files\AdVantage\ffext.mod
    Threat ID:156261
    Resource refcount:2
    Result:0
    Resource action complete:Quarantine
    Schema:containerfile
    Path:\\?\C:\Program Files\AdVantage\ffext.mod
    Threat ID:18086
    Resource refcount:2
    Result:0
    File to act on SHA1:23062BB72A27D283F2CE57EFD35C16EAC2575461
    File cleaned/removed successfully
    File Name:C:\Program Files\AdVantage\ffext.mod
    Resource action complete:Removal
    Schema:containerfile
    Path:\\?\C:\Program Files\AdVantage\ffext.mod
    Threat ID:18086
    Resource refcount:2
    Result:0
    Resource action complete:Quarantine
    Schema:containerfile
    Path:\\?\C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe
    Threat ID:159633
    Resource refcount:1
    Result:0
    File to act on SHA1:6DBE312ADC97CC0F5DCFB527449893EA5169B0B6
    File cleaned/removed successfully
    File Name:C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe
    Resource action complete:Removal
    Schema:containerfile
    Path:\\?\C:\Documents and Settings\Maja\My Documents\Downloads\IZArc4.1.exe
    Threat ID:159633
    Resource refcount:1
    Result:0
    Finished threat ID:2147593794
    Threat result:0
    Threat status flags:0
    Finished threat ID:18086
    Threat result:0
    Threat status flags:0
    Finished threat ID:156261
    Threat result:0
    Threat status flags:0
    Finished threat ID:159633
    Threat result:0
    Threat status flags:0
    Finished threat ID:153970
    Threat result:0
    Threat status flags:0
    Finished threat actions
    End time:‎05‎-‎09‎-‎2012 22:39:37
    Result:0


    ERRORS_ONLY=0
    MAX_SIZE=5120
    APPEND=1
    MAX_LINE_SIZE=256
    -------------------------------------------------
    START 2012/05/09 17:27:27:265 TID:856 PID:824

    INFO 2012/05/09 17:27:27:265 TID:856 PID:824
    Binary architecture is amd64

    INFO 2012/05/09 17:27:27:281 TID:856 PID:824
    UtilIsFileExists(D:\Windows\SysWOW64\ntdll.dll) returned 0x00000000

    INFO 2012/05/09 17:27:27:281 TID:856 PID:824
    CheckProcessorArchitecture returned 0x00000000

    INFO 2012/05/09 17:27:27:281 TID:856 PID:824
    Setting target OS key: "D:\Windows"

    INFO 2012/05/09 17:27:27:281 TID:856 PID:824
    SetRecoveryEnvironmentKey returned 0x00000000

    INFO 2012/05/09 17:27:27:281 TID:856 PID:824
    Searching for signatures. Default signature path: ""

    INFO 2012/05/09 17:27:27:281 TID:856 PID:824
    Searching for signatures at root of drives...

    WARNING 2012/05/09 17:27:27:281 TID:856 PID:824
    Missing definitions file in 'C:\mpam-fex64.exe'

    WARNING 2012/05/09 17:27:27:281 TID:856 PID:824
    Missing definitions file in 'D:\mpam-fex64.exe'

    WARNING 2012/05/09 17:27:27:281 TID:856 PID:824
    Missing definitions file in 'E:\mpam-fex64.exe'

    WARNING 2012/05/09 17:27:27:281 TID:856 PID:824
    Missing definitions file in 'F:\mpam-fex64.exe'

    WARNING 2012/05/09 17:27:27:296 TID:856 PID:824
    Missing definitions file in 'G:\mpam-fex64.exe'

    WARNING 2012/05/09 17:27:27:296 TID:856 PID:824
    Missing definitions file in 'H:\mpam-fex64.exe'

    INFO 2012/05/09 17:27:27:296 TID:856 PID:824
    Found definitions file in 'I:\mpam-fex64.exe'

    INFO 2012/05/09 17:27:27:296 TID:856 PID:824
    Using signature path: "I:\mpam-fex64.exe"

    INFO 2012/05/09 17:27:27:296 TID:856 PID:824
    SearchForSignatures returned 0x00000000

    INFO 2012/05/09 17:27:27:296 TID:856 PID:824
    Initializing offline environment and service...

    INFO 2012/05/09 17:27:43:671 TID:856 PID:824
    Launching user interface...

    INFO 2012/05/09 17:27:43:671 TID:856 PID:824
    Launched UI, waiting...

    INFO 2012/05/09 22:40:36:468 TID:856 PID:824
    Wait finished (UI signaled)

    INFO 2012/05/09 22:40:36:468 TID:856 PID:824
    RunCallisto returned 0x00000000

    INFO 2012/05/09 22:40:38:468 TID:856 PID:824
    Offline scan completed with 0x00000000

    FINISH 2012/05/09 22:40:38:468 TID:828 PID:824
      My Computer


  5. Posts : 10,200
    MS Windows 7 Ultimate SP1 64-bit
       #5

    mtopping,
    now that the malware is gone, any problems remain?
      My Computer


  6. Posts : 5
    Windows 7 Ultimate x64
    Thread Starter
       #6

    Yes, since I have reinstalled Microsoft office, when I open word or excel it asks me if I want to activate online. I click yes, and the activation wizard starts to connect then I get the following message:

    An unspecified error has occurred. Your request cannot be processed at this time. Please try again later. ( 0x8007000D )
      My Computer


  7. Posts : 10,200
    MS Windows 7 Ultimate SP1 64-bit
       #7

    OK.

    That's a MS office validation and not Win 7 Validation.

    I don't have any notes on how to rid yourself of this one, but
    I'm sure if you google it and set site:msdn.com;technet.com that you will get a good answer.
      My Computer


  8. Posts : 5
    Windows 7 Ultimate x64
    Thread Starter
       #8

    Thanks for your help anyway, karlsnooks. At least I got rid of some malware!
      My Computer


  9. Posts : 10,200
    MS Windows 7 Ultimate SP1 64-bit
       #9

    mtopping,

    Download and run this program. Post results.
    http://go.microsoft.com/fwlink/?linkid=52012

    i'm asking some others to look at results.
      My Computer


  10. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #10

    Unfortunately, MGADiag is useless for Office 2010 - it only sees Office XP to 2007 installs.
    However, there is an inbuilt office validation tool somewhere..... <rummage>
    Ah -
    cscript.exe "C:\Program Files (x86)\microsoft Office\Office14\ospp.vbs"
    will bring up the options list.

    I have no experience in reading these - but I'd be happy to give it a go.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 16:42.
Find Us