This post has been edited by tolson09: 21 October 2009 - 12:39 AM
Windos Police Pro Cant access task manager or registry
#1
Posted 21 October 2009 - 12:36 AM
#2
Posted 21 October 2009 - 07:21 PM
My name is Sam and I will be helping you.
In order to see what's going on with your computer I will ask for you to post various logs from the tools that we will use to resolve your issue. Please also share with me any information about how your computer is reacting and behaving each step of the way as we work through this process.
We need to create an OTL Report
- Please download OTL from here
- Save it to your desktop.
- Double click on the icon on your desktop.
- Click the "Scan All Users" checkbox.
- Under the Custom Scan box paste this in
netsvcs
%systemdrive%\*.exe
%systemroot%\system32\drivers\*.sys
- Click the "Quick Scan" button.
- The scan should take just a few minutes.
- Please copy and paste both logs back here in your next reply.
=============
The next log will show us any hidden files that are present.
- Download RootRepeal from the following location and save it to your desktop.
- Direct Download (Recommended)
- Zip Mirrors (Recommended if you have a slower connection or if the Direct Download mirror is down)
- Rar Mirrors - Only if you know what a RAR is and can extract it.
- Direct Download (Recommended)
- Extract RootRepeal.exe from the archive (If you did not use the "Direct Download" mirror).
- Open
on your desktop. - Click the
tab. - Click the
button. - Check all seven boxes:

- Push Ok
- Check the box for your main system drive (Usually C:), and press Ok.
- Allow RootRepeal to run a scan of your system. This may take some time.
- Once the scan completes, push the
button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!
========================================================
#3
Posted 22 October 2009 - 10:34 AM
#4
Posted 22 October 2009 - 11:12 AM
#5
Posted 22 October 2009 - 02:26 PM
This post has been edited by tolson09: 22 October 2009 - 02:28 PM
#6
Posted 22 October 2009 - 06:42 PM
tolson09, on Oct 22 2009, 11:12 AM, said:
Without having seen any logs I can't tell what type of infection you may have so I can't answer that question.
Skipping past OTL then, try to run Rootrepeal and post that log for me.
Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3


--------------------------------------------------------------------
Double click on Combo-Fix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the C:\ComboFix.txt so we can continue cleaning the system.
If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!
========================================================
#7
Posted 22 October 2009 - 06:55 PM
#8
Posted 22 October 2009 - 07:02 PM
- Download Win32kDiag from any of the following locations and save it to your Desktop.
- Download Win32kDiag (Win32kDiag.exe) - #1
- Download Win32kDiag (Win32kDiag.exe) - #2
- Download Win32kDiag (Win32kDiag.exe) - #3
- Download Win32kDiag (Win32kDiag.exe) - #1
- Double-click Win32kDiag.exe to run Win32kDiag and let it finish.
- When it states "Finished! Press any key to exit...", press any key on your keyboard to close the program.
- Double-click on the Win32kDiag.txt file that is located on your Desktop and post the entire contents of that log as a reply to this topic.
If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!
========================================================
#9
Posted 22 October 2009 - 10:29 PM
running from: C:\documents and settings\travis olson\win32diag.txt
Log file C:\documents and settings\travis olson\win32diag.txt
Warning could not get backup privelages
Searching C:\Windows . . . .
I even downloaded the other 2 links, renamed them. Thanks, sorry so sporatic getting back to your posts, we are different timezones and I couldnt get away from work.
#10
Posted 23 October 2009 - 07:37 AM
- Download peek.bat from the download link below and save it to your Desktop.
- A black Command Prompt window will appear shortly: the program is running.
If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!
========================================================
#11
Posted 23 October 2009 - 08:59 AM
Volume in drive C has no label
Volume serial number is 600F-D56C
#12
Posted 24 October 2009 - 09:43 AM
Are you saving these files directly to your desktop to run them?
If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!
========================================================
#13
Posted 24 October 2009 - 09:47 AM
eventlog.dll
Let me know all locations it is found and the file size of each.
If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!
========================================================
#14
Posted 26 October 2009 - 12:10 AM
C:\I386, size 55kb
C:\Windows\System32
C:\Windows\ServicePackFiles\i386
Thanks
#15
Posted 26 October 2009 - 12:11 AM
C:\Windows\System32, 55kb
C:\Windows\ServicePackFiles\i386, 55kb

Help
This topic is locked

Back to top








