Help needed with a acrer aspire all in one Z3801 with malware problems

Page 2 of 3 FirstFirst 123 LastLast

  1. Posts : 20,583
    Win-7-Pro64bit 7-H-Prem-64bit
       #11

    Hi,
    Click Start and type in the search box
    windows update
    Click on the suggestion or the enter key
    On the top left of the windows you'll see View update history that will show you successful and failed updates.

    Pictures are good too :)
    Just turn off the flash on the camera first.
      My Computer


  2. Posts : 27
    32bit win7 pro
    Thread Starter
       #12

    torchwood said:
    In that case can you run the following
    Malwarebytes free (uncheck trial, in dashboard settings check rootkit detection)
    Then ESET on-line, you will have to dissable your current AV.
    Report any findings

    Roy
    Re your question Roy, I had a laptop lent to me, this was what I ment, the malware infected machine is the acer all in one etc, just noticed Malwarbytes has stopped opening on the infected machine, think there is not much hope fixing the Acer what without being able to use the internet or use the DVD drive plus other mounting issues
      My Computer


  3. Posts : 27
    32bit win7 pro
    Thread Starter
       #13

    ThrashZone said:
    Hi,
    Click Start and type in the search box
    windows update
    Click on the suggestion or the enter key
    On the top left of the windows you'll see View update history that will show you successful and failed updates.

    Pictures are good too :)
    Just turn off the flash on the camera first.
    Re your question, what do you want to know?, I opened update history and I notice a lot of failed updates mostly from the beginning of the year, apart from that I am not sure what you need to know?,
      My Computer


  4. Posts : 20,583
    Win-7-Pro64bit 7-H-Prem-64bit
       #14

    Hi,
    A list of the failing to install updates would be nice
    If too many to list just reset the update system

    Try using this to reset the update system it's very good,
    Use Option 2 on the list after right clicking it and select run as administrator
    https://gallery.technet.microsoft.co...Agent-d824badc

    Download it to your downloads folder
    Right click it and select Extract all to the downloads folder.
    Then right click ResetWUEng and select run as administrator
    Follow the rest of the prompts
    Press any key to continue
    Type 2 for that Option on the list and the Enter key to reset update services..
    Press y for Yes and then the Enter key I believe twice
    After it has completed
    Type 15 for that option and the Enter key to restart the machine.
    Should say will restart in 60 seconds save your work.... press any key to continue.
    After restart go to windows updates and manually check for updates shouldn't take a few minutes.
    Help needed with a acrer aspire all in one Z3801 with malware problems-reset-win-updates-eng.jpg
      My Computer


  5. Posts : 27
    32bit win7 pro
    Thread Starter
       #15

    ThrashZone said:
    Hi,
    A list of the failing to install updates would be nice
    If too many to list just reset the update system

    Try using this to reset the update system it's very good,
    Use Option 2 on the list after right clicking it and select run as administrator
    https://gallery.technet.microsoft.co...Agent-d824badc

    Download it to your downloads folder
    Right click it and select Extract all to the downloads folder.
    Then right click ResetWUEng and select run as administrator
    Follow the rest of the prompts
    Press any key to continue
    Type 2 for that Option on the list and the Enter key to reset update services..
    Press y for Yes and then the Enter key I believe twice
    After it has completed
    Type 15 for that option and the Enter key to restart the machine.
    Should say will restart in 60 seconds save your work.... press any key to continue.
    After restart go to windows updates and manually check for updates shouldn't take a few minutes.
    Help needed with a acrer aspire all in one Z3801 with malware problems-reset-win-updates-eng.jpg
    OK, update from 1 week ago,
    I Have now moved this Acer Aspire Z3801 pc to my friends home and i am now able to get onto the internet using his internet connection, (BT hub)
    Before i couldn't get the wifi to work through BT-WiFi-Fon of which i have been using for some time at my place, OK i did as you suggested and downloaded and ran as administrator the windows reset update agent tool, i ran as per your instructions option 2 from the list and it ran/finished, completed successfully, it then asked to press any key to continue/finish which i did, it brought it back to the main menu, but!,as per your instructions press y for yes?? but its here i am not following you, where can i put y for yes? its just the 1 to 16 options list that appears after option 2 runs and finishes, then next you say Enter key I twice, that's a capital i!, thinking maybe to try option 15 ''download diagnostics'' i typed 15 and it opened a new options list 1 to 5 ''Download and run diagnostics for your system'', 1 on the list is for win7, 2, 3 ,4 and 5 are for 8, 8-1, and 10 etc etc, anyway i pressed option 1 and it opened up a scan, of which it ended with another box saying it had found two issues and it had fixed them, but i now notice it appears this copy of windows7 is not a legal copy, so will have to sort that problem out as well. ok, will do the restart and post back what i find re manually checking for updates, fingers crossed,
      My Computer


  6. Posts : 27
    32bit win7 pro
    Thread Starter
       #16

    update history and updates are all reset and showing as if a new instal!, what next? click update? what about this unlicensed copy of win7?
    i have a new win7 disc set disc set here and just tried to put the licence number in but it does not accept it?
      My Computer


  7. Posts : 20,583
    Win-7-Pro64bit 7-H-Prem-64bit
       #17

    Hi,
    Can't help with activation besides use phone activation options.
    You can post this report just simply copy and paste the results
    http://go.microsoft.com/fwlink/?LinkID=52012
      My Computer


  8. Posts : 27
    32bit win7 pro
    Thread Starter
       #18

    ThrashZone said:
    Hi,
    Can't help with activation besides use phone activation options.
    You can post this report just simply copy and paste the results
    http://go.microsoft.com/fwlink/?LinkID=52012
    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-X92GV-V7DCV-P4K27
    Windows Product Key Hash: aU2z1/fnhnLHmhBm699qYZT2E6s=
    Windows Product ID: 00426-OEM-8992662-00400
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.001
    ID: {C4F2230C-BACC-4B29-8170-E195C34FC171}(1)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Ultimate
    Architecture: 0x00000000
    Build lab: 7601.win7sp1_gdr.150525-0603
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7600.16385], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{C4F2230C-BACC-4B29-8170-E195C34FC171}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-P4K27</PKey><PID>00426-OEM-8992662-00400</PID><PIDType>2</PIDType><SID>S-1-5-21-3069225087-1665415207-3981302129</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Aspire Z3801</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>P01-A2</Version><SMBIOSVersion major="2" minor="7"/><Date>20110707000000.000000+000</Date></BIOS><HWID>02FF3407018400FE</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Input Error: Can not find script file "C:\Windows\system32\slmgr.vbs".

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x80072EE7
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 9:3:2016 19:13
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: LAAAAAEAAQABAAEAAAABAAAAAgABAAEAeqggVVy2useUEbK9Sq+K+8ClLnM=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
    ACPI Table Name OEMID Value OEMTableID Value
    APIC ACRSYS ACRPRDCT
    FACP ACRSYS ACRPRDCT
    HPET ACRSYS ACRPRDCT
    MCFG ACRSYS ACRPRDCT
    SSDT AMICPU PROC
    SLIC ACRSYS ACRPRDCT
    ASF! INTEL HCG
      My Computer


  9. Posts : 7,107
    W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
       #19

    Hi Marc,

    The install is classified as counterfiet.

    You have the Dell factory W7 Ultimate default key on your Acer computer.
    The exploit used to circumvent activation has failed and MS has picked it up.
    File Scan Data-->
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7600.16385], Hr = 0x800b0100

    You need to use the code on the OEM sticker, and it will also tell you which version,(shipped with Home premium)

    Having stated its counterfiet in your case it can be caused by incorrect OS media, did you use Dell re-installation discs?
    the report is also incomplete
    Licensing Data-->
    Input Error: Can not find script file "C:\Windows\system32\slmgr.vbs".
    run the following
    regsvr32 vbscript.dll

    i would also like to see the results from this run the following command from a command Prompt window.

    reg query HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32

    finally did you realise your running 32bit

    Roy
    Last edited by torchwood; 10 Sep 2016 at 07:16.
      My Computer


  10. Posts : 27
    32bit win7 pro
    Thread Starter
       #20

    hi Roy, ok this machine/pc i bought a few years ago as back up machine and at the time it switched on and operated just fine and apart from a pop up after booting saying windows was not genuine and click to make genuine i just stored it away until it was needed, i had no part in altering or modifying it so just dont know its pre history, when my tower type pc gave up i started using this acer aspire (all in one) of which has operated faultlessly until only a few months ago, i have a windows 7 box set i bought back in 2010 that is a 2 discs win7 32 and 64bit box set so if what you say its a mismatch of different programmes would it be best to do a clean instal? or do you think we can rectify what i have got installed?, ok in the mean time i will carry on with your last suggestion ''regsvr32 vbscript.dll and post the outcome, thanks,
      My Computer


 
Page 2 of 3 FirstFirst 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 03:15.
Find Us