Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

RegSvr32 Error on startup please help [Closed]

RegSvr32

  • This topic is locked This topic is locked

#1
rockstar1

rockstar1

    New Member

  • Member
  • Pip
  • 4 posts

After removing the TeslaKrypt Virus when i boot my computer i get this error.

Capture.png


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there are probably some elements left

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 1

#3
rockstar1

rockstar1

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

Here you go

Attached Files


  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi you will need to attach the main FRST log please
  • 0

#5
rockstar1

rockstar1

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

Sorry about that lol got it confused here you go.

Attached Files

  • Attached File  FRST.txt   94.12KB   744 downloads

  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you let me know what problems remain after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
HKU\S-1-5-21-2954068360-2895956722-819088778-1000\...\Run: [Idpwsoft] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\NorthP\AppData\Local\Ixsmsoft\mzrfocnl.dll
2016-01-29 16:32 - 2016-01-29 20:08 - 00000000 ___HD C:\Id3Lfn01uMHjikvC
2016-01-29 16:32 - 2016-01-29 20:05 - 00086304 _____ C:\spyhunter.fix
2016-01-29 04:44 - 2016-01-30 03:34 - 00000000 ____D C:\Users\NorthP\AppData\Local\Ixsmsoft
2016-01-03 04:54 - 2016-01-30 01:32 - 00000000 __HDC C:\ProgramData\{CF8DBD9D-2EFD-44F7-8D23-93B5C27D06D7}
2016-01-30 03:33 - 2015-06-04 09:44 - 00000000 ___HD C:\Users\NorthP\AppData\Local\0haexzEvrlru
2016-01-30 03:33 - 2014-08-12 10:37 - 00000000 ___HD C:\Users\NorthP\AppData\Local\02gMIi2NGGFFA
2016-01-30 03:33 - 2013-09-03 10:05 - 00000000 ___HD C:\Users\NorthP\AppData\Local\3gfNVtPRgkCSz
2016-01-30 01:32 - 2015-12-16 17:45 - 00000000 __HDC C:\ProgramData\{61A19DCC-35CF-45F2-9B6E-078047DDC28D}
2016-01-30 01:32 - 2015-02-18 10:13 - 00000000 __HDC C:\ProgramData\{2149AC3A-6876-48A5-8ACC-4DDA07B383D2}
2016-01-30 01:32 - 2015-02-18 10:08 - 00000000 __HDC C:\ProgramData\{BD761B7D-CF85-4D9F-8742-F8457E267565}
2016-01-30 01:32 - 2015-02-18 10:08 - 00000000 __HDC C:\ProgramData\{4F1011FE-3478-4D2B-8F9F-7EA7C144DFC2}
2016-01-30 01:32 - 2015-01-22 21:40 - 00000000 __HDC C:\ProgramData\{D9FE1BCD-7CBB-4429-93E8-07869EFFE08A}
2016-01-30 01:32 - 2015-01-21 22:44 - 00000000 __HDC C:\ProgramData\{B895D3F6-931C-4B01-A8AC-DCDBBE28F2F9}
2016-01-30 01:32 - 2015-01-20 14:38 - 00000000 __HDC C:\ProgramData\{3342DAE4-E9C8-491C-8DD2-FA5D6CB18DA6}
2016-01-30 01:32 - 2015-01-10 16:57 - 00000000 __HDC C:\ProgramData\{B7072B15-6E80-42FF-A9AE-4E62AF2B2418}
2016-01-30 01:32 - 2015-01-10 16:57 - 00000000 __HDC C:\ProgramData\{30FA7941-4170-4C83-A9A8-FDF01C431704}
2016-01-30 01:32 - 2014-12-30 08:07 - 00000000 __HDC C:\ProgramData\{3006A797-CDFA-44FC-98EF-155579E2CDBF}
2016-01-30 01:32 - 2014-08-30 19:24 - 00000000 __HDC C:\ProgramData\{087E1953-389C-4129-84BB-41E86CBEDF56}
2016-01-30 01:32 - 2014-08-28 15:39 - 00000000 __HDC C:\ProgramData\{7FFC8429-59AA-4310-831D-BDA0FDF42089}
2016-01-30 01:32 - 2014-08-28 15:38 - 00000000 __HDC C:\ProgramData\{B219DF15-4D19-412B-8C2C-CA83D4B20892}
2016-01-30 01:32 - 2014-08-27 23:11 - 00000000 __HDC C:\ProgramData\{39752E59-CE7D-4919-9B7F-020F8C66116C}
2016-01-30 01:32 - 2014-08-01 16:09 - 00000000 __HDC C:\ProgramData\{0EB7C0FC-5BF4-474E-B5F9-A6E991727B3E}
2016-01-30 01:31 - 2015-01-24 01:53 - 00000000 ____D C:\ProgramData\Globalscape
2016-01-30 01:31 - 2015-01-22 04:11 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-01-29 21:04 - 2014-10-03 19:23 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
CustomCLSID: HKU\S-1-5-21-2954068360-2895956722-819088778-1000_Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32 -> C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\tsmf.dll => No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData:482EE99B1E21CE8C
AlternateDataStreams: C:\Users\All Users:482EE99B1E21CE8C
AlternateDataStreams: C:\ProgramData\Application Data:482EE99B1E21CE8C
AlternateDataStreams: C:\ProgramData\Microsoft:7xcZvmHdFBJnUZimSwk0gtDC96
AlternateDataStreams: C:\ProgramData\Microsoft:gVfN0FPTVfOjPSFjHqANlWH
AlternateDataStreams: C:\ProgramData\Microsoft:i2NGGFFAlczLYogETx7Q
AlternateDataStreams: C:\ProgramData\Microsoft:ne5y7L4fHVZEgKaOGugDRO
AlternateDataStreams: C:\ProgramData\Microsoft:PiFxbFf1UQbLYibTm
AlternateDataStreams: C:\ProgramData\Microsoft:SBI6rIn2edCogjBSEO
AlternateDataStreams: C:\ProgramData\Microsoft:sJhe70Itpv4JE0DaLZC90
AlternateDataStreams: C:\ProgramData\Microsoft:ZI8ZgrBvyMv5gGpVZ
AlternateDataStreams: C:\Users\NorthP\Local Settings:4UNsWCrCgjU6aVv5jyIBgAvdS9ciU1
AlternateDataStreams: C:\Users\NorthP\AppData\Local:4UNsWCrCgjU6aVv5jyIBgAvdS9ciU1
AlternateDataStreams: C:\Users\NorthP\AppData\Local\0haexzEvrlru:loYhfQkyhruyVgOS6jOoJV87Hft4
AlternateDataStreams: C:\Users\NorthP\AppData\Local\Application Data:4UNsWCrCgjU6aVv5jyIBgAvdS9ciU1
AlternateDataStreams: C:\Users\NorthP\AppData\Local\Temp:APgmbFsNHUkqmmBCKq8U
AlternateDataStreams: C:\Users\NorthP\AppData\Local\Temp:IkYXe9RayQEnEQVi6m
AlternateDataStreams: C:\Users\NorthP\AppData\Local\Temporary Internet Files:ojPTaTF40NGo5ITIFS75BWvL12
C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

  • 0

#7
rockstar1

rockstar1

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

The error went away now thanks will run the adw cleaner

Attached Files


  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Did you run adwcleaner ?
  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.


  • 0






Similar Topics


Also tagged with one or more of these keywords: RegSvr32

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP