Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Operating system problem

17 Dec 2010   #1

 
 
Operating system problem

I have everything up on my desktop, but seemingly cannot open any programs that require to go online. When trying to open explorer, I get promted with
"Choose the program you want to use to open this file". "Do you want to run or save this file" then it asks Do you want to run this software. I select run, then it reverts back to "Choose the program you want to use to open this file"
also for example
If I open "Action Centre" and select "troubleshooting" I get
C:\windows\System32\rundll32.exe
Application not found
a lot of times I get
C:\windows\System32\msdt.exe
Application not found
This all started after I was advised my computer is infected with a virus.
I can't download any program that I want to use to fix the problem.
I am using my 2nd old slow laptop to access this forum.
Can any-one offer advise on what to do please


My System SpecsSystem Spec
.

17 Dec 2010   #2

Win 7 Pro x64 SP1 OS X Snow Leopard 10.6.7
 
 

If you have access to another computer:

1. Download Malwarebytes:
Malwarebytes

2. Uninstall your current anti-virus software and replace with MS Security Essentials:

http://www.microsoft.com/security_essentials/

Put the installation file onto a USB stick, or CD. If you don't have any of those, you may put it on Windows SkyDrive (if you have a Windows Live Messenger).
My System SpecsSystem Spec
18 Dec 2010   #3

Microsoft Community Contributor Award Recipient

Windows 7 Ult. x64 Windows 8.1 x64
 
 

After you try DeanP's suggestions, you can also run SFC /scannow from the command prompt to test the integrity of the system files.
My System SpecsSystem Spec
.


18 Dec 2010   #4
Microsoft MVP

 

Sounds like you have a serious infection smart enough to block the very scans which can neutralize it.

If the two course of action proposed above don't succeed, try one of the free Bootable AV CD's like Avira from this list: FREE Bootable AntiVirus Rescue CDs Download List The virus has no ability to block a bootable scan, nor can it hide in any running processes.

This may give you enough functionality to run MSE and Malwarebytes, then check system files to see if any have been damaged: SFC /SCANNOW Command - System File Checker

If problems remain, try booting the Windows 7 DVD Repair console or Repair CD to System Restore back until you get before the infection: System Restore
System Repair Disc - Create

Recovering functionality but having irreparable system files, try Repair Install

If any symptoms of infection remain after repeated scans, you may need to wipe the HD of all infected code and reinstall following these tips: re-install windows 7
My System SpecsSystem Spec
18 Dec 2010   #5

 
 

Can't run MS Security Essentials
Malwarebytes picked up 18 infections
I am now downloading rescue system program.
Hopefully I can get some functionality back again.
My System SpecsSystem Spec
18 Dec 2010   #6

 
 

I run the scan program and
Windows Resource Protection did not find any integrity violations.
My System SpecsSystem Spec
18 Dec 2010   #7

Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
 
 

So, are you able to open programs now? If not, continue with the boot rescue disc as asked by greg.
My System SpecsSystem Spec
18 Dec 2010   #8

Vista Home Premium x86 SP2
 
 

Hello!

Could you please post the MBAM log so that we can see what we are dealing with? Thanks!

Richard
My System SpecsSystem Spec
18 Dec 2010   #9

 
 
MBAM log

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 11
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> No action taken.
HKEY_CLASSES_ROOT\pezfile\shell\open\command\(default) (Rogue.MultipleAV) -> Value: (default) -> No action taken.
Registry Data Items Infected:
HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (pezfile) Good: (exefile) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Bad: (93.188.162.135,93.188.160.15) Good: () -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{25B4EF13-F7A3-47A5-8B29-EE862150BE66}\NameServer (Trojan.DNSChanger) -> Bad: (93.188.162.135,93.188.160.15) Good: () -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{39A69A42-31A8-4256-BF7F-64607B3E4741}\NameServer (Trojan.DNSChanger) -> Bad: (93.188.162.135,93.188.160.15) Good: () -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{AD0C62B4-8EBF-4331-99D6-C4041B957D3D}\NameServer (Trojan.DNSChanger) -> Bad: (93.188.162.135,93.188.160.15) Good: () -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Keith\AppData\Roaming\microsoft\svchost.exe (Trojan.Agent.Gen) -> No action taken.
c:\Users\Keith\AppData\Roaming\microsoft\Windows\shell.exe (Trojan.Agent.Gen) -> No action taken.
c:\Users\Keith\AppData\Local\Temp\1187.7056201924984.exe (Trojan.Agent.Gen) -> No action taken.
c:\Users\Keith\AppData\Roaming\microsoft\stor.cfg (Malware.Trace) -> No action taken.
c:\Users\karnjanarat\Desktop\internet security suite.lnk (Rogue.Link) -> No action taken.
c:\explorer.exe (Worm.AutoRun) -> No action taken.
c:\Users\Keith\AppData\Local\Temp\svchost.exe (Trojan.Agent) -> No action taken.
c:\Users\Keith\local settings\application data\opRSK (Malware.Trace) -> No action taken.
c:\Users\karnjanarat\AppData\Roaming\microsoft\internet explorer\quick launch\internet security suite.lnk (Rogue.InternetSecuritySuite) -> No action taken.
c:\Users\karnjanarat\AppData\Roaming\microsoft\Windows\start menu\internet security suite.lnk (Rogue.InternetSecuritySuite) -> No action taken.
c:\Users\karnjanarat\AppData\Roaming\microsoft\Windows\start menu\Programs\internet security suite.lnk (Rogue.InternetSecuritySuite) -> No action taken.
My System SpecsSystem Spec
18 Dec 2010   #10

Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
 
 

It shows 'No action taken'. Make sure you reboot after the scan when prompted.
In case if You're still facing problems running exe files, which i doubt as you could run mbam, dload exeHelper- http://www.raktor.net/exeHelper/exeHelper.com
Now download rkill and run it. Don't reboot after running it.
http://download.bleepingcomputer.com/grinler/rkill.exe
Try to run any antivirus like Avira, MSE etc.. whatever you like and also run MBAM again. Post back the logs and let us know.
My System SpecsSystem Spec
Reply

 Operating system problem




Thread Tools



Similar help and support threads for2: Operating system problem
Thread Forum
Solved New operating system BSOD Help and Support
how can i get past the can not read Operating System Not Found Problem General Discussion
Solved Unknown Operating System Problem (See attatched image) General Discussion
Dell Inspiron 1564 "Operating System Not Found" Problem BSOD Help and Support
Missing operating system" error massage when system starts General Discussion
No operating system General Discussion
operating system not found in system recovery Backup and Restore

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 01:53 PM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33