maxx63
Jun 11 2006, 01:09 AM
Upon running the Clean-Up fix as told to, I now have a system that has been completely taken over
by some one who has name themselves Owner-Operator......and I am denied complete access to open
a single program......I want to warn everybody on this site, it is my belief that these are the writers
of malware such as Spy-Sheriff and other false-fixes like Clean-up and if there is anybody who knows any
different, I sure would like to hear about it.
Harry83
Jun 11 2006, 05:05 AM
Maxx,
What "Clean-Up fix" did you run? Since you only have 1 post, then I find it unlikely anyone told you to do anything to your system. If you tried to do a fix by yourself then you may have made a mistake which resulted in system problems.
This site is full of dedicated volunteers who help salvage people's computers from the brink of unusability....out of sheer kindness I might add. This site has provided comfort and relief to countless frustrated PC users and your remarks about this site are unwarranted.
If you have a legitimite problem that is related to self-help material on this site then please describe what you did, provide a link to the info you used for the fix, and we will help you get your computer back to normal.
If you are on this forum with malicious intent, then please leave.
Regards,
Tej
Jun 11 2006, 07:20 AM
Hear Hear!!
I shall second harry 83!
This is a fantastic site!.. and dont let any say different!.. all thse sites SWI, Castle Cops , are really phenomenal!
maxx63
Jun 11 2006, 09:51 AM
I must say that I think you are sadly mistaken...........
I was attemtping to follow the the very steps that grinzley posted to do..........
I downloaded the Clean-up program from the link he had posted........
Then I had a complete melt down........I really think he IS Spy-Sheriff........
And he gets off on screwing people........for FREE!
Now if I am the one whos wrong, I appollogize in advance. All I know is that is my
experience........
buttoni
Jun 11 2006, 10:19 AM
If you followed self-help tutorial/pinned instructions, all links & references there are legitimate & safe. Tools & programs there are recommended on MANY pc help sites, not just this one. It is much more likely that something "piggy-backed" onto your system or infected you at about the same time and you unfortunately didn't get to Grinler's always helpful/insiteful steps for cleaning BEFORE the malware was able to set up shop as "Owner-Operator" of your system. Just out of curiosity, do you surf the net with a user account with Administrative or Limited rights?
Harry83
Jun 11 2006, 10:38 AM
QUOTE
I downloaded the Clean-up program from the link he had posted........
Then I had a complete melt down........I really think he IS Spy-Sheriff........
So what you're saying is you were following the self-help tutorial for Spy Sheriff and after fllowing those steps you no longer have administrator access to your computer? Please gives us specifics about the problem (so we can help you) instead of accusing BC of being responsible for your problems...
quietman7
Jun 11 2006, 10:39 AM
Hello maxx63
Sounds like something occurred to change things but it was not the result of performing any of the steps in the self-help tutorials.
Exactly what self-help link you were using and what clean up program did you download and run?
Also, Owner-Operator folders are automatically created when installing Win XP and can be found in Documents & Settings along with All Users, Default User, etc. You may never now they are there unless you go into that folder to look. How are you trying to log on?
graveangel
Jun 11 2006, 11:22 AM
Maxx63
A few short months ago,i had a laptop that was nothing more than on its way to the little laptop heaven. I decided, reluctantly, to try one of these help forums to see if i anything could come from it. After asking numerous questions before i did anything,the very pleasant volunteers here helped fix my problems. Now i have a laptop running like an Aston Martin and security that even Fort Knox would envy.
The point is, everyone on here is only here to help. If you are not sure of anything,then ask before you do anything. If you look only a few posts away,i posted a question about about an anti-malware product, not because i dont know what im doing but because i think its best to ask before trying anything regardless of computer knowledge.
Im sure whatever issues you have with your system, they can be resolved here. I now like to give any help and advice here that i can. It is through sites like Bleeping Computer that we can fight against malware and help each other with our PC problems. If you feel it best to take your PC to a so called specialist (and in my opinion, i know of alot that are not) and let them look for $100 an hour then that is up to you,but you wont learn or get the advice you get here.
Maxx, repost with your exact problem and what guide you followed and everyone here will help you sort it.
maxx63
Jun 11 2006, 11:24 AM
B........I surf with admin. status..........or did.......now I can't even acess any of MY files/programs...........
The only way I am able get on line now is by setting up another admin. name. But, there is still no access
to any files/programs.......
H.......I googled 'Spy-Sheriff'and BC comes up as having tutorials on its removal.........I was atempting
to follow Grinzleys advise, step by step, and when in safe mode, I ran the 'Clean-Up' program (downloaded
from the link he had provided) I am now experiencing and continue to experience a total system lock-out,
save for being able to access the Net, but can not, as I already stated, download any programs which
may be able to restore my system. I was able to go to 'Restore' to restore my system to an earlier
date, but that was blocked as well. You can read for yourself his tutorial on this site, but I have noticed
his procedure has changed from what was posted at the time I accessed it.
But, in a nut-shell, the steps were to start up in safemode, run the Clean-Up, then the Ewido....etc.....
I never made ti to ewido because the clean-up program not only cleaned-up, but cleaned my out of my
system! lol
Look, sorry for the crass remarks ealier, but how the hell do you expect me to feel.......?
Harry83
Jun 11 2006, 11:33 AM
So this is the tutorial you used?
How to Remove SpySheriff and AntiSpylab?It was posted on May 11th and I don't think it has changed since then.
Are you saying that after you downloaded and ran SmitFraudFix, this all happened?
maxx63
Jun 11 2006, 12:02 PM
I justed pulled the hard copy of the steps I followed..........They are dated May 3rd.
How to remove the Spysheriff..........
Step one: print out these instructions.......check
Step two: download and install 'Clean-Up' but do not run it yet........(here is where the link for the 'clean-up'
is provided)........check
Step three: download and install and update Ewido security suite (there is another link here for that)
launch Ewido, click to update, click start, after updates are installed, exit.........check
Step four: Reboot into safemode, open 'Clean-Up', put a check mark next to the following
Empty Recycle bin
Delete Cookies
Delete Prefetch Files
Scan local drives for temporary files
Cleanup! all users
click okay, Click the Cleanup! button.............check
Then, whalaa! You now have a complete lock-out of your system!
There are many more steps to follow but obviously, you don't need to worry about them because
you no longer have a system to worry about anyways.......check!
maxx63
Jun 11 2006, 12:11 PM
So, as of todays date, the insructions have completely changed from the date May 3rd.
Now you are told to download Smitfraud........this was never mentioned when I accessed the site
on the 3rd of May. So what does the Smit thing do? Make your system physically blow-up? (tongue-in-cheek)!
loveablekitty
Jun 11 2006, 01:36 PM
Maxx63 your attitude is APPALING tho I fully can understand you being poed I have to say these people on this site and this forum have the best knowledge and clear imformation about the world of cps...... and they are willing and ABLE to help and has offered too..... STOP being a child and get on ur knees as a men and ask for help!!!!! Graveangle and Harry83 has your best interest in mind...But should NOT waste there Time nor MINDS on some one who spitefull as you.. come on it easy just say ""help please"
Harry83
Jun 11 2006, 02:05 PM
QUOTE
this was never mentioned when I accessed the site
on the 3rd of May.
So you've had this problem for 39 days?? I find it hard to believe you printed out instructions on the 3rd because you had SpywareSheriff and then waited until just now to use the instructions...Either you sat on SpywareSheriff for somewhere around 39 days or you've had this current problem for about that long...hrrmm quite the logical conundrum...
So go to this link and tell me if this is the tool you used:
CleanUp!Also are you able to download and run a simple program like HJT? If so then I suggest posting a HijackThis log in the HJT Logs and Analysis Forum. Here is a link to that Forum:
HJT ForumPlease follow the preparation directions and try not to alter your system until you receive help from one of our HJT Team Members. The preparation directions are found at the following link:
Prep Guide for Posting HJT LogsPlease note: Do not try to fix any problems with HJT yourself. This is an advanced tool and requires expert analysis.If you still have SpySheriff on your computer then follow the removal instructions posted here:
SpywareSheriff RemovalBut I guess you won't be able to do that since you have no access to anything...
Are all of the files on your system encrypted?? You may have been infected with a ransomware virus...If so, try and open one of them and tell me what it says... Do you have any browser redirection? We need more information abut what's actually happening with your system...
quietman7
Jun 11 2006, 03:38 PM
QUOTE
I justed pulled the hard copy of the steps I followed..........They are dated May 3rd. How to remove the Spysheriff...So, as of todays date, the insructions have completely changed from the date May 3rd. Now you are told to download Smitfraud........this was never mentioned when I accessed the site
That's because the self-help topic with the smitfraudfix you are referring to was created by Grinler on May 11 2006. It does not include CleanUP and is actually titled "
How To Remove Spyware Sheriff And Antispylab" which targets
spywaresheriff.exe. Since you downloaded instructions a least a week before he posted this fix, it cannot be the same self-help guide that you used.
QUOTE
I googled 'Spy-Sheriff'and BC comes up as having tutorials on its removal.........I was atempting to follow Grinzleys advise, step by step...
It appears your google search led you to an older but different self-help tutorial titled "
How to remove the Spysheriff" which targets
SpySheriff.exe. This self-help guide was created by Grinler on Jun 22 2005 and does include downloading and using CleanUp.
Although the names are similar,
spywaresheriff.exe and
SpySheriff.exe are actually
two different infections and thus, they are dealth with differently. The "procedure" did not change. Nothing was added or removed. We we are talking about two different tutorials, each with its own set of instructions for two different infections.
You apparently used the incorrect tutorial for your problem as a result of your search and not asking anyone here if this was the appropriate fix for your malware problem.
QUOTE
So what does the Smit thing do? Make your system physically blow-up?
The smitfraudfix tool was created by a malware removal expert specifically for newer smitfraud infections. It only targets and removes bad files related to these infections. It is safe, works well and is recommended by the vast majority of experts at forums like this as the appropriate fix tool to use.
I understand your frustration but airing it here will not resolve your current problem. Please provide as much information as you can so that we may attempt to help you.
maxx63
Jun 11 2006, 04:36 PM
Harry..........
First let me say thanks for your interest.............
Secondly, when first atempting to rid the spy-sheriff, I did initially run the
Ewido suite. This apparently seemed to fix the problem. That was the delay in the 39 days.
But, now its back with a venegance.
This is what happens when ANY file or program is attempted to open. An error box says "the application has failed to start because the application configuration is incorrect." Then it goes on to say, "Reinstalling the
application may fix this problem."
And I am blocked out from installing or reinstalling anything.
Furthermore, when my system starts, the starting procedure has been altered. There is no task bar.
Or I should say the task bar is blank. To see the programs, I must hit the 'windows' key, but then trying
to access any programs only gets the same error message as before.
What further information can I provide?
Thanks for your help and interest in this........its much appreciated! m.
Harry83
Jun 12 2006, 01:06 AM
First off, I must say that
I am not entirely clear what your exact problem is...So suggesting any fixes comes with a bit of liability. Therefore, I am only here to give
ideas...please don't try anything until moderators, or others comment on the potential fixes.
All I know is that you apparently have no Admin priviliges, no access to any programs/files, no ability to uninstall/install programs, no system restore capability, and no taskbar on startup...
This does indeed sound like a pretty catastrophic failure...the cause of which cannot be determined clearly at this time.
You may want to try a
.exe file association fix. You probably have other file associations missing as well...For XP, these fixes are found at the following site:
File Extension FixesAlso, here is an article that describes your problem and some replies on suggested fixes:
Applications, Start Menu, and Settings inaccessibleYou may need to a do a repair install on your computer if nothing else works...there are directions for how to do that in the link I provided above.
Here is another website that seemingly describes your problem exactly...is it credible? Not sure...could be a goad to purchase because you have to shell out $ to see their solution...but nevertheless here is a link to it:
Might help if you want to spend $10 but it's a gamble...In order to regain access to your computer, with administrative priviliges you may want to reset security settings back to defaults. An artical on how to do this in Windows XP Professional is found at this link:
How to Reset Security SettingsSo that reminds me,
what operating system are you using?
I've spent quite a while researching this because I haven't encountered such a problem before...I really hope some of this helps you out. Please let me know of any status changes to your system.
Regards,
Tej
Jun 12 2006, 03:53 AM
just my 0.2c worth
Suggesting fixes comes with NO liability on the part of the helpers. As I understand, everybody who helps here does so voluntarily.. they give a lot of their time and effort to help those in trouble.. "toiling and not asking for any reward!!!"
I feel the "victims".. if you can call it that, should really be appreciative that there is someone at the other end of the line to be able to communicate with, else they would be on their own and left to their own devices to figure out their problems.
There is a wealth of info on these sites, and its upto them to use that however they please......so the choice is theirs!
as I said, just my opinion
cheers
maxx63
Jun 12 2006, 09:06 AM
Harry.........
I am using XP pro.......
I read the info at the.exe link.......this reminds me of one other problem.......
I cannot bring up the task manager by pressing control-alt-delete. (this is one thing you
need to do in their insttructions) so I'm not sure that I can try what that link suggests.
As for now, my system has no changes to report.
And as for as the article on Applications, Start Menu, and Settings inaccessible, I wish I had the
original disk which came with the system.......It was thrown out when I moved afew months ago.
Another stupid mistake on my part! I do have a call into HP to get another one because I did
register my system with them. Once I have one I would sacrifice all my data for a system restore
back ups or not.
I did read all the info you just supplied......I will wait to see what else comes up. Thanks.
quietman7
Jun 12 2006, 10:56 AM
What happens if you start in Safe Mode? Can you access programs/files, uninstall/install anything?
Harry83
Jun 12 2006, 12:30 PM
Yes you should definitely call HP to get new disks if you can...Definitely try rebooting into safe mode, as quietman suggested, and tell us if you are able to do anything from there...You do this by restarting your PC and tapping F8 until a menu comes up. Then select "Safe Mode" from the menu when it comes up after pressing F8...it will basically start your PC with the bare bones essentials...if all of your problems still exist in safe mode then we'll move on from there. I'm at work right now but when I get home I'll look into your Task Manager problem....
maxx63
Jun 12 2006, 01:23 PM
Harry,QM..........
I have tried the safe mode route.........
I am still blocked out from anything.........
No program access, no downloading ability. In fact, I tried every available safe mode option,
but to no avail............m.
quietman7
Jun 12 2006, 02:34 PM
Just to summarize.
• You don't have the original XP CD.
• You cannot log on to your system with your normal log on.
• The task bar is blank.
• You cannot download any programs.
• You cannot install/uninstall any programs.
• You cannot get into safe more, or if you do, you still have the same problems.
• You cannot access or run any programs installed on your system w/o getting an error message.
Double check this and try things like notepad and standalone programs that do not require installation to confirm.
• You cannot bring up the task manager by pressing control-alt-delete.
What happens if you use your mouse to right click an open area in the task bar? Does a context list open which would allow you to select task manager?
What happens if you go to Start > Run and copy/paste or type:
taskmgrDo you have access to another computer. If so, download this
VB Script, save to a usb stick or CD, transfer it to your computer and double-click to run. What happens?
maxx63
Jun 12 2006, 09:39 PM
QM7.........
I think you will find this interesting.............
I just read your posting and clicked on the VB Script link and my system would not go there.
It simply 'flashed' (for lack of a better term) for a split-second on my screen and that was it.
Now, I do have access to another computer at the office, I'm at home now, but if you give
me the URL for the VB I can still put it on my flash drive and try it. Although, after what just happened
I dought it will work.
As for your check list, I have been able to uninstall a couple a programs such as photoshop and bear-
share.....but thats about it.
When I right click on the open space on the task bar, a menue box does come up allowing me to select the
task mgr., but clicking on it does nothing.
I have tried with no success to open programs like notepad, paint,address book.
The address book? Why the hell can I go on-line and not access my address book?
And there is no 'start' button, its gone too.
Thanks, by the way for your help............
Any other suggestions? m.
medab1
Jun 12 2006, 09:59 PM
QUOTE(maxx63 @ Jun 12 2006, 10:39 PM)

QM7.........
I think you will find this interesting.............
I just read your posting and clicked on the VB Script link and my system would not go there.
It simply 'flashed' (for lack of a better term) for a split-second on my screen and that was it.
Now, I do have access to another computer at the office, I'm at home now, but if you give
me the URL for the VB I can still put it on my flash drive and try it. Although, after what just happened
I dought it will work.
As for your check list, I have been able to uninstall a couple a programs such as photoshop and bear-
share.....but thats about it.
When I right click on the open space on the task bar, a menue box does come up allowing me to select the
task mgr., but clicking on it does nothing.
I have tried with no success to open programs like notepad, paint,address book.
The address book? Why the hell can I go on-line and not access my address book?
And there is no 'start' button, its gone too.
Thanks, by the way for your help............
Any other suggestions? m.
Here is a suggestion that may or may not help.
Since you have xp,if you can get on the computer,try running sfc /scannow.
Click Start & Run & type in sfc /scannow & click OK.
There is a space between the c and the /.
This is the System File Checker.
Google it if you are unfamilar with it.
It runs & fixes Windows files.
It may prompt you for the xp CD.
Or not.
If prompted for the CD & you don't have one you can't fix anything with it.
My Emachine has a backup of all needed files so I don't need an xp CD.
I have recovery CDs that contain the needed files too.
I have never been asked to insert one.
Good luck.
Harry83
Jun 12 2006, 10:26 PM
So literally the only thing you can do on your computer is turn it on and access the internet?
Try doing the .exe association fix that I mentioned earlier without the task manager method. If you can download them, and extract them from the .zip files then you might be able to get somewhere. Just double click the reg files and, say "yes" when prompted to allow it to merge with the registry. Then click around on some programs like notepad and see if anything will open up...
Here is the link to the VB Script...use your other computer to download this script and then transfer it onto your problem PC...
http://www.kellys-korner-xp.com/regs_edits...ktop_fixall.vbs
maxx63
Jun 12 2006, 10:31 PM
Harry.....
I will not be able to try this until tomorrow..........
See you then.......and thanks...........m.
Harry83
Jun 13 2006, 12:10 PM
There is another thing I want you to do, which was suggested by one of BC's most knowledgable members:
Download the following .bat file and when it asks if you want to open it or save it, specify save it. It may say run as well, let it run the program after it downloads it.
http://www.bleepingcomputer.com/files/bats/winlog.batIt should open a notepad when its done. Please paste the contents of that notepad as a reply to this topic.
Please do this at your next available opportunity, in addition to feedback about the other recommendations we have given you. Please keep us as updated as possible.
quietman7
Jun 13 2006, 12:33 PM
Download winlog.bat from the other computer you have access to along with the VBS script and place them on your usb stick. When you transfer both to your computer, you can place them in the root of C:\
If your able to run the batch file, a log will be created in C:\winlog.ext
You said you could not open notepad so you may have to try to open the .txt file with WordPad or a similar tool (i.e. editpad) if you have one.
Harry83 maybe we can get something to work here.
maxx63
Jun 13 2006, 05:51 PM
H83,QM...........
I just was not able to find the page for the first link for the .vbs (does that stand for vacation bible school?)
Anyways.......I was able to download the one for the .bat, saved it to my flashdrive.
Now what? I am still at work now with access to the other system if there is anything else to try while here.
( if you get this message in time) Also the system at work is Windows ME, if that make sany differance.
quietman7
Jun 13 2006, 06:53 PM
If you double-click on the link that Harry provided for the .vbs script you should get a direct download of xp_taskbar_desktop_fixall.vbs file to save to your usb stick. It does not lead to a site.
Save that file to your flashdrive and when you get home transfer it and winlog.bat to your computer. Follow the directions we provided for running each of these tools. Basically that will be to double-click on the .vbs file to run the script and double-click on the .bat file to create a log.
While you are at work also
download and save Hijackthis 1.99.1 from both of these locations:
merijn/filescastlecops.comOne is an .exe file and one is a .zip file. This way they will be available for us to attempt to use.
maxx63
Jun 13 2006, 07:22 PM
QM7..........
When I click on Harry's link, it simply flashes for a split second and thats it.
Is that what its supposed to do? Also, when I tried to open the .bat or winlog file,
it does the same thing.I can seem to get them to open or anything. What am I doing wrong?
I have not yet been able to download the HJT and castlecops yet but will shortly.
quietman7
Jun 13 2006, 07:46 PM
Try right-clicking on each link and choose Save link as (All files). Then just save it to a location where you can find the files after downloading.
maxx63
Jun 13 2006, 07:59 PM
QM7..........
Okay, right clicking on both of those links did give me the chance to save them to my flash drive on MY system. I've yet to download those other files but will be doing that now..........m.
maxx63
Jun 14 2006, 01:41 AM
H83, QM7...........
Okay here is the latest...........
I was able to run the HJT program.........scan.....whatever..........
Anyways, It gave me a long list of procedural stuff, but I don't know how to get this stuff to you guys.............what now......? m.
rowal5555
Jun 14 2006, 01:48 AM
Hi maxx. Have been following your saga with interest
Go here and follow the steps very carefully.
Good luck:
http://www.bleepingcomputer.com/tutorials/tutorial94.html
Harry83
Jun 14 2006, 02:55 AM
QUOTE
I was able to run the HJT program.........scan.....whatever..........
Anyways, It gave me a long list of procedural stuff, but I don't know how to get this stuff to you guys.............what now......? m

This might finally help us!
Post the HijackThis log in the HJT Logs and Analysis Forum. Here is a link to that Forum:
HJT ForumPlease follow the preparation directions and try not to alter your system until you receive help from one of our HJT Team Members. The preparation directions are found at the following link:
Prep Guide for Posting HJT LogsPlease note: Do not try to fix any problems with HJT yourself. This is an advanced tool and requires expert analysis.I'm assuming you probably won't be able to do most of the preparation steps...don't worry about it, just get that log posted in the HJT forum! Also, provide us a link to that thread so we can take a glance at it...
Furthermore,
give us feedback about the previous steps we asked you to take.To summarize:Run the VBS script Quietman asked you to do.
Run the winlog.bat file I asked you to run and post that log in this forum, by copying and pasting.
Post your HJT log in the HJT Forum and give us a link to the thread.
maxx63
Jun 14 2006, 08:27 AM
H83.........
I haven't been able to do anything with the VBS or.bat files yet.
I may not get the time to spend on the other 'assignments' until this evening,
the boss is coming into the ofice today.........As with any boss, things are 'different'
when their around. lol.
Glad to here we might be making some progress here, THANKS..................m.
quietman7
Jun 14 2006, 08:44 AM
QUOTE
I haven't been able to do anything with the VBS or.bat files yet.
You havn't had time or they don't work?
Its important to provide a hijackthis log as soon as you can now that we know it will run on your system. With the problems your having I would not be surprised if at some point you go to use it and the program will not work.
I want to make sure you have the instructions readily available for creating and posting a log so please print out the following.
When first running Hijackthis, you should see the "Welcome to Hijackthis,..." >
New Users quickstart.
1. Under "
What would you like to do?" choose the option to "
Do a system scan and save a log file".
2. HijackThis will analyze your system and
automatically open a notepad text file containing the HijackThis results when the scan is done.
3. Click on "
File" (top left hand menu) > Click on "
save as" > another window will open with a box that says save in: Hijackthis >> Click on "
Yes".
4. When you save the scan results, they will be saved with the default log filename
hijackthis.log in the same folder as Hijackthis.
5. Use
Ctrl-A to "
Select All",
Ctrl-C to copy it, and
Ctrl-V to paste the log into your post in the HijackThis forum.
6. Start a new topic, give it a relevant title and post the log along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own.
Please include the top portion of the HijackThis log that lists version information.
7. Close the program when done. A Hijackthis security expert will analyze your log and reply with instructions advising you what to fix.
Dennis H
Jun 14 2006, 08:47 AM
maxx, I am sorry you are having computer problems, but I must admit reading this thread is like reading a good book. A real page turner.
It looks as though the Bleeping Computer team is zeroing in on the monster that is haunting your computer.
Is there anyway for you to get rid of the boss so the saga can continue ?
Take Care,
Dennis
Papakid
Jun 14 2006, 11:06 AM
QUOTE
4. When you save the scan results, they will be saved to the default log filename hijackthis.log in C:\Program Files\Hijackthis\ folder.
Hi maxx,
I'm afraid the above file path mentioned will be incorrect unless you've saved HijackThis
_sfx.exe to your flash drive and installed it. You've been linked to three different downloads of HijackThis and the set-up for each one is different. Check the exact file name for what you have downloaded. You appear to have confirmed downloading after being linked to
HijackThis.exe and
HijackThis.zip.
Sorry for the confusion--to avoid any more, I suggest that you download HijackThis
_sfx.exe and follow the setup instructions on the page that
rowal5555 linked you to:
http://www.bleepingcomputer.com/tutorials/tutorial94.htmlThat will be the easiest way to go and HJT will be set up in Program Files. The other HijackThis's will work, but the log will be saved in whatever folder
HijackThis.exe is in.
Also if you aren't able to get Notepad to work then you won't be able to produce a log in the first place. You
might be able to reinstall Notepad, so while you are still at work I suggtest downloading it as well.
http://www.spywareinfo.com/~merijn/winfiles.html#notepadDownload Notepad.exe for XP and save it to your flash drive. When you get on your computer, try the other actions that have already been recommended in this thread. If you then can't get Notepad to open the HJT log, right click and
Copy Notepad.exe from the flash drive and then
Paste it into
both of the following folders:
C:\WINDOWS
C:\WINDOWS\System32Reboot and then see if you can open Notepad.
As already mentioned, let us know if you have any problems getting a log posted and link us back to it here when you do.
quietman7
Jun 14 2006, 11:18 AM
Yep, Papakid is correct. Line 4 in those instructions was for the setup.exe version which automatically installs in that directory. I just edited that out so others reading the thread will not get confused since those instructions were meant for the zipped version.
Harry83
Jun 14 2006, 11:46 AM
QUOTE
H83, QM7...........
Okay here is the latest...........
I was able to run the HJT program.........scan.....whatever..........
Anyways, It gave me a long list of procedural stuff, but I don't know how to get this stuff to you guys.............what now......? m.
Hrrrmm I was under the impression this meant he was already able to run HJT and produce a log but just didn't know how to post it...If he can't produce the log in notepad maybe there is a way for him to maximize the HJT window and take a series (however many it takes to get the whole log) of snapshots for us to look at? I know, it sounds a little crazy haha...HJT may actually be able to produce a log, but he might just not be able to open it...if that's the case he could save it to a thumb drive, bring it to work, and then submit it.
Harry83
Jun 14 2006, 01:18 PM
well actually screen shots wouldn't work either if he has nowhere to paste to...nevermind on that idea
quietman7
Jun 14 2006, 01:25 PM
That was my impression as well when maxx wrote:
QUOTE
I was able to run the HJT program.........scan.....whatever..........
Anyways, It gave me a long list of procedural stuff, but I don't know how to get this stuff to you guys
I suspect he saw the results of the scan but did not understand them. I was surprised that hijackthis even worked since maxx said he could not install or run programs. That's why I had him download the zipped version instead of the HJTsetup since I figured he'd have a problem installing it and suggested an alternative notepad like tool. It's trial and error here since some things will work but most won't.
Harry83
Jun 14 2006, 01:32 PM
What would happen if HJT couldn't actually create the log file when it was supposed to? Would he receive some sort of error? If he ran HJT, according to the way it's supposed to be setup, it should have created the text file automatically...now just because notepad isn't working and he can't open the file, doesn't necessarily mean the file wasn't created right? If that's the case he could simply transfer the file to a usable computer and post it...which would be awesome...
maxx63
Jun 14 2006, 06:31 PM
H83,QM7...........
Okay, I am stuck..............
Using my system at the office,I was able to create a word doc. with a digital image of the HJT log........
How do I get that word doc. on this site? Email? Or is there a way to create a link or download it to this site?
I am still learning how this site works everyday.........and I'm not sure how to do this.................m.
Grinler
Jun 14 2006, 07:14 PM
How about the output of the winlog.bat file?
maxx63
Jun 14 2006, 08:45 PM
G.......
By the .bat file, are you referring to the winlog?
If so, it will not open.
Is it imporant to look at the HJT scan?
If so , how do I get that to you?.........m.
Grinler
Jun 14 2006, 09:17 PM
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.