Operating system problem

Page 1 of 3 123 LastLast

  1. Posts : 12
    32
       #1

    Operating system problem


    I have everything up on my desktop, but seemingly cannot open any programs that require to go online. When trying to open explorer, I get promted with
    "Choose the program you want to use to open this file". "Do you want to run or save this file" then it asks Do you want to run this software. I select run, then it reverts back to "Choose the program you want to use to open this file"
    also for example
    If I open "Action Centre" and select "troubleshooting" I get
    C:\windows\System32\rundll32.exe
    Application not found
    a lot of times I get
    C:\windows\System32\msdt.exe
    Application not found
    This all started after I was advised my computer is infected with a virus.
    I can't download any program that I want to use to fix the problem.
    I am using my 2nd old slow laptop to access this forum.
    Can any-one offer advise on what to do please
      My Computer


  2. Posts : 2,566
    Win 7 Pro x64 SP1 OS X Snow Leopard 10.6.7
       #2

    If you have access to another computer:

    1. Download Malwarebytes:
    Malwarebytes

    2. Uninstall your current anti-virus software and replace with MS Security Essentials:

    http://www.microsoft.com/security_essentials/

    Put the installation file onto a USB stick, or CD. If you don't have any of those, you may put it on Windows SkyDrive (if you have a Windows Live Messenger).
      My Computer


  3. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #3

    After you try DeanP's suggestions, you can also run SFC /scannow from the command prompt to test the integrity of the system files.
      My Computer

  4.    #4

    Sounds like you have a serious infection smart enough to block the very scans which can neutralize it.

    If the two course of action proposed above don't succeed, try one of the free Bootable AV CD's like Avira from this list: FREE Bootable AntiVirus Rescue CDs Download List The virus has no ability to block a bootable scan, nor can it hide in any running processes.

    This may give you enough functionality to run MSE and Malwarebytes, then check system files to see if any have been damaged: SFC /SCANNOW Command - System File Checker

    If problems remain, try booting the Win7 DVD Repair console or Repair CD to System Restore back until you get before the infection: System Restore
    System Repair Disc - Create

    Recovering functionality but having irreparable system files, try Repair Install

    If any symptoms of infection remain after repeated scans, you may need to wipe the HD of all infected code and reinstall following these tips: re-install windows 7
      My Computer


  5. Posts : 12
    32
    Thread Starter
       #5

    Can't run MS Security Essentials
    Malwarebytes picked up 18 infections
    I am now downloading rescue system program.
    Hopefully I can get some functionality back again.
      My Computer


  6. Posts : 12
    32
    Thread Starter
       #6

    I run the scan program and
    Windows Resource Protection did not find any integrity violations.
      My Computer


  7. Posts : 1,036
    Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
       #7

    So, are you able to open programs now? If not, continue with the boot rescue disc as asked by greg.
      My Computer


  8. Posts : 908
    Vista Home Premium x86 SP2
       #8

    Hello!

    Could you please post the MBAM log so that we can see what we are dealing with? Thanks!

    Richard
      My Computer


  9. Posts : 12
    32
    Thread Starter
       #9

    MBAM log


    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 2
    Registry Data Items Infected: 5
    Folders Infected: 0
    Files Infected: 11
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> No action taken.
    HKEY_CLASSES_ROOT\pezfile\shell\open\command\(default) (Rogue.MultipleAV) -> Value: (default) -> No action taken.
    Registry Data Items Infected:
    HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (pezfile) Good: (exefile) -> No action taken.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Bad: (93.188.162.135,93.188.160.15) Good: () -> No action taken.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{25B4EF13-F7A3-47A5-8B29-EE862150BE66}\NameServer (Trojan.DNSChanger) -> Bad: (93.188.162.135,93.188.160.15) Good: () -> No action taken.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{39A69A42-31A8-4256-BF7F-64607B3E4741}\NameServer (Trojan.DNSChanger) -> Bad: (93.188.162.135,93.188.160.15) Good: () -> No action taken.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{AD0C62B4-8EBF-4331-99D6-C4041B957D3D}\NameServer (Trojan.DNSChanger) -> Bad: (93.188.162.135,93.188.160.15) Good: () -> No action taken.
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    c:\Users\Keith\AppData\Roaming\microsoft\svchost.exe (Trojan.Agent.Gen) -> No action taken.
    c:\Users\Keith\AppData\Roaming\microsoft\Windows\shell.exe (Trojan.Agent.Gen) -> No action taken.
    c:\Users\Keith\AppData\Local\Temp\1187.7056201924984.exe (Trojan.Agent.Gen) -> No action taken.
    c:\Users\Keith\AppData\Roaming\microsoft\stor.cfg (Malware.Trace) -> No action taken.
    c:\Users\karnjanarat\Desktop\internet security suite.lnk (Rogue.Link) -> No action taken.
    c:\explorer.exe (Worm.AutoRun) -> No action taken.
    c:\Users\Keith\AppData\Local\Temp\svchost.exe (Trojan.Agent) -> No action taken.
    c:\Users\Keith\local settings\application data\opRSK (Malware.Trace) -> No action taken.
    c:\Users\karnjanarat\AppData\Roaming\microsoft\internet explorer\quick launch\internet security suite.lnk (Rogue.InternetSecuritySuite) -> No action taken.
    c:\Users\karnjanarat\AppData\Roaming\microsoft\Windows\start menu\internet security suite.lnk (Rogue.InternetSecuritySuite) -> No action taken.
    c:\Users\karnjanarat\AppData\Roaming\microsoft\Windows\start menu\Programs\internet security suite.lnk (Rogue.InternetSecuritySuite) -> No action taken.
      My Computer


  10. Posts : 1,036
    Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
       #10

    It shows 'No action taken'. Make sure you reboot after the scan when prompted.
    In case if You're still facing problems running exe files, which i doubt as you could run mbam, dload exeHelper- http://www.raktor.net/exeHelper/exeHelper.com
    Now download rkill and run it. Don't reboot after running it.
    http://download.bleepingcomputer.com/grinler/rkill.exe
    Try to run any antivirus like Avira, MSE etc.. whatever you like and also run MBAM again. Post back the logs and let us know.
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:50.
Find Us