Can't open any programs except photoshop not even OTL - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

Can't open any programs except photoshop not even OTL

#166 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 22 April 2012 - 08:33 PM

when I tried to start application virtualizaion it was on manual and it said windows could not start the application virtualization service agent service on local computer. error 1053: the service did not respond to the start of control request in a timely fashion

#167 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 22 April 2012 - 08:43 PM

interesting I tried net start bfe again and I got this message

the base filtering engine service is starting.
the base filtering engine service could not be started
a systerm arror has occured
system error 5 occured
access is denied

#168 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 22 April 2012 - 08:49 PM

i got into regedit but saw no + sign

#169 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 22 April 2012 - 08:54 PM

okay i got it to say the requested service has already been started more help is available by typing net helpmsg 2182

#170 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 22 April 2012 - 10:49 PM

Is it possible to reformat without a cd?

#171 RKinner

  • Group: Expert
  • Posts: 10,636
  • Joined: 19-April 05

Posted 22 April 2012 - 11:12 PM

Reformatting without a CD is only possible if this is something like a Dell where they have a hidden partition. You can of course try a System Restore to the oldest time you have.


IF you are now able to get into regedit we are making progress.

If you find
HKEY_LOCAL_MACHINE

there should be a + in the front which you can press and then you will see several entries below it which should include System which should also have a +. If there is no + then there should be a - which will close it up if you click on it and change it to a +.

Were you able to uninstall

Microsoft Application Virtualization ?

Can you try OTL again?

#172 RKinner

  • Group: Expert
  • Posts: 10,636
  • Joined: 19-April 05

Posted 22 April 2012 - 11:29 PM

Just saw that you got BFE started.

I'm thinking this is probably a zeroaccess infection which is sort of hard to cure without combofix or aswMBR but we can try. Let's first check the partitions:

Do the following:
Open a command prompt (elevated if you still have UAC turned on (right click and Run As Admin)
type diskmgmt.msc
Click "OK"

Disk Management will open.

Click and hold the right side of the Disk Management Window and drag it to the right until you can see all the columns.

Take a screen Shot of the Disk Management Window and attach the screen shot to your reply.
http://graphicssoft....nscreenshot.htm Save the file as a .jpg or the forum won't allow it.

From the same Command Prompt:
cd  \

dir  /a  /s  consrv.dll


(It will search your PC for the file consrv.dll
Does it find it? Where?)

dir  /a  \windows\assembly\tmp\U


(Does it find anything?)

#173 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 22 April 2012 - 11:49 PM

heres the screenshot

Attached thumbnail(s)

  • Attached Image: sdfsdf.jpg


#174 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 22 April 2012 - 11:51 PM

it says volume in drive c has no label volume serial number is 7073-a108 the second one said file not found

#175 RKinner

  • Group: Expert
  • Posts: 10,636
  • Joined: 19-April 05

Posted 23 April 2012 - 12:13 AM

See if you can delete the folder C:\Windows\system64

This is part of your ZeroAccess infection.
Were you able to uninstall

Microsoft Application Virtualization ?

Can you try OTL again?

If it still doesn't work, right click on it and select Properties (Have you tried UNBLOCK?) then Security then Click on Administrators and look in the bottom. Is the Full Control checked under Allow?

If not you need to take ownership of the file http://technet.micro...y/cc753659.aspx and edit ti so that it has Full Control checked under Allow. Then try to run it.

#176 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 23 April 2012 - 12:20 AM

o yes i did unsinstall the visualization thing and system 64 is locked

#177 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 23 April 2012 - 12:22 AM

o nvm i didn't get rid of it

#178 RKinner

  • Group: Expert
  • Posts: 10,636
  • Joined: 19-April 05

Posted 23 April 2012 - 12:22 AM

Can you take ownership of system64?

I'm going to have to go to bed now. Got to catch the early ferry tomorrow. Maliprop should be around for a while.

#179 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 23 April 2012 - 12:25 AM

says i need admin how do I contact maliprop?

#180 neataznyam

  • Group: Member
  • Posts: 150
  • Joined: 21-March 12

Posted 23 April 2012 - 12:27 AM

k system 64 deleted

Share this topic:


  • 15 Pages +
  • « First
  • 10
  • 11
  • 12
  • 13
  • 14
  • Last »