Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

email infected by Torpig?


  • Please log in to reply

#16
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts

Hi, Karolion.
 
Apologies for the delay.
 
You have Desktop synchronized with OneDrive, that's why with any change on Desktop you get a warning. You have to select "Got it". 
 

1. Delete account with Registry Editor

  • Copy the contents of the code below to Notepad (To open Notepad, type Notepad in the Search area and select it when the specific item appears).
  • Make sure to leave an empty line at the end of the script.
Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4005300964-2302935580-1863167367-1019]

  • Name the file as fix.reg
  • Change the Save as Type to All Files and Save it on the desktop.
  • Once saved, double click on the fix.reg file and merge it into the Registry.
  • Restart. 

 

2. FRST fix

Please do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Please select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
    start::
    closeprocesses:
    createrestorepoint:
    DriverUpdate (HKLM\...\{70A3DB76-E1F1-4D1C-B791-824F1C63238A}) (Version: 5.8.19 - Slimware Utilities Holdings, Inc.) Hidden <==== ATTENTION
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
    SearchScopes: HKU\S-1-5-21-4005300964-2302935580-1863167367-1001 -> DefaultScope {10ABE9E3-13DA-46DD-B4E9-AA1779861B5A} URL = 
    SearchScopes: HKU\S-1-5-21-4005300964-2302935580-1863167367-1001 -> {10ABE9E3-13DA-46DD-B4E9-AA1779861B5A} URL = 
    FirewallRules: [{E281517D-A7B0-4B35-98C2-15EDAB153D75}] => (Allow) C:\Users\19192\AppData\Local\Temp\HelpDesk\u8\HelpDesk\RPCHelpDeskServiceUAC.exe => No File
    FirewallRules: [{868BB4AB-5C17-4ED0-A373-2D0A60535557}] => (Allow) C:\Users\19192\AppData\Local\Temp\HelpDesk\u8\HelpDesk\RPCHelpDeskServiceUAC.exe => No File
    FirewallRules: [{C7F4D455-330B-4ACC-BC29-DF1ACFF695FE}] => (Allow) C:\Users\19192\AppData\Local\Temp\ShowMyPC\-ShowMyPC3606\SMPCSetup.exe => No File
    FirewallRules: [{5806E64E-1B06-4E0B-B9C2-B4EF9AFB8809}] => (Allow) C:\Users\19192\AppData\Local\Temp\ShowMyPC\-ShowMyPC3606\tvnserver.exe => No File
    HKLM-x32\...\Run: [tvncontrol] => "C:\Program Files (x86)\ShowMyPCService\tvnserver.exe" -controlservice -slave (No File)
    Task: {0701D042-9791-4309-AC67-196ABEC83A9E} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
    Task: {24F4E6C9-ACF2-48C9-969B-5A4D116A5E3D} - \Lenovo\ImController\TimeBasedEvents\fce8b35d-f625-4d1c-924d-c555a774b87c -> No File <==== ATTENTION
    Task: {79185E2D-6052-4A95-9D94-E7BE95E4EE15} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe (No File)
    Task: {8CCDCD9E-AE81-4FE0-8458-861B71078265} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
    Task: {9FD42CCE-79DC-4BD4-850F-D1327A7FC731} - \Lenovo\ImController\TimeBasedEvents\5162f36a-538c-448c-adde-aa0d542ef045 -> No File <==== ATTENTION
    Task: {B2C9009F-58CB-4892-B36E-CA623FA3E35A} - \Lenovo\ImController\TimeBasedEvents\91917b8d-c346-4ebd-b347-373688af688b -> No File <==== ATTENTION
    Task: {DA622FAA-9F58-4D2A-BF99-030204ACD04C} - \Lenovo\ImController\TimeBasedEvents\4698dca5-e53b-4db6-a01f-2fcfe4af3754 -> No File <==== ATTENTION
    Task: {F15C1A7A-F903-4445-90BE-34AC99FBA265} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
    Task: {FD00D536-B53A-4FBC-852A-5E01E1347A32} - \Lenovo\ImController\TimeBasedEvents\8cca9d46-7384-4f46-8e72-8b54f6bbc9f4 -> No File <==== ATTENTION
    CHR Notifications: Default -> hxxps://19216801.me
    CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=E210US714G0&p={searchTerms}
    CHR DefaultSearchKeyword: Default -> mcafee
    CHR DefaultSuggestURL: Default -> hxxps://us.search.yahoo.com/sugg/gossip/gossip-us-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
    S2 GamingServices; C:\Program Files\WindowsApps\Microsoft.GamingServices_2.57.20005.0_x64__8wekyb3d8bbwe\GamingServices.exe [X]
    S2 GamingServicesNet; C:\Program Files\WindowsApps\Microsoft.GamingServices_2.57.20005.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe [X]
    S2 HelpDeskService; C:\Users\19192\AppData\Local\Temp\HelpDesk\u8\HelpDesk\RPCHelpDeskServiceUAC.exe [X] <==== ATTENTION
    S2 ImControllerService; %SystemRoot%\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [X]
    2021-11-09 17:48 - 2021-11-09 17:48 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001
    2021-11-09 17:38 - 2021-11-09 17:38 - 000000000 ____D C:\Users\19192\AppData\Local\GoToAssist Remote Support Customer
    2021-11-09 17:17 - 2021-11-09 17:17 - 002745776 _____ C:\Users\19192\Downloads\ShowMyPC3606.exe
    2021-11-09 16:48 - 2021-11-09 17:56 - 000000000 ____D C:\ProgramData\HelpDeskHost
    2021-11-09 16:48 - 2021-11-09 16:48 - 000368560 _____ () C:\Users\19192\Downloads\HelpDesk_495711758.exe
    2021-11-09 16:48 - 2021-11-09 16:48 - 000003124 _____ C:\Windows\system32\Tasks\KillHelpDeskService
    2021-11-09 16:48 - 2021-11-09 16:48 - 000000000 ____D C:\ProgramData\RemotePC
    2021-11-09 16:48 - 2021-11-09 16:48 - 000000000 ____D C:\Program Files (x86)\RemotePC
    2021-11-09 17:21 - 2021-11-09 17:21 - 000000128 _____ C:\Users\19192\AppData\Local\PUTTY.RND
    Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}
    emptytemp:
    end::
  • Please right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Please post the log in your next reply.

  • 0

Advertisements


#17
karolion

karolion

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts

Sorry I could not reply yesterday evening.  I received a dialogue box after I did the FRST64 fix which reads as follows... https://www.dropbox....guebox.png?dl=0

 

Since you didn't instruct me to click OK to restart I haven't done that yet.

Attached Files


  • 0

#18
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts

Yes, please let the computer restart. :)


  • 0

#19
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts

After the restart:
 
1. Uninstall DriverUpdate
 
Try to uninstall it once again and let me know about the result.
 

2. ESET Online Scanner

Download ESET Online Scanner and save it to your desktop.

  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

  • 0

#20
karolion

karolion

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts

This time I was able to uninstall DriverUpdate.  There were no threats detected in the ESET scan. 

 

I then got a prompt to select whether or not I wanted a free ESET Smart Security Premium trial.  When I opted to do so a window prompted me to save the program to the desktop which I did.  I checked the box to delete application data on closing and clicked continue.  Another dialogue box appeared asking if I wanted to enter an email address to have scan results sent to my mailbox.  I entered my email address.  I know the scan results can be accessed after the scan has completed but I thought it could be helpful in case there were future problems.  I figured you trust this program and that it would be okay to provide my email address to ESET.


  • 0

#21
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts

Hi, Karolion.
 
You probably chose to download free Eset Smart Security Premium trial. After some days of free trial you will be getting prompts to buy the product. It is something you may consider, but it's not necessary, since you are running Windows 10 with its built-in antivirus.

 

Can I see the log please?

 

It is located here: C:\Users\username\AppData\Local\Temp\log.txt

 
Let's see fresh FRST logs now. I will let you know if Eset was installed and what to do in case you don't want that.

  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please copy and paste the content of these two logs in your next reply.

  • 0

#22
karolion

karolion

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts

I can't locate the scan.  I was able to show hidden files and this is what I saw... https://www.dropbox....search.png?dl=0

I couldn't find the file you specified.  I had ESET email me a copy of the report.  I'll copy and paste it here but it doesn't look like the other reports that have appeared in the notepad.

 

Scan report
2021-11-18 12:13:42
 
Files scanned: 576060
Detected files: 0
Cleaned files: 0
Total scan time: 01:00:14

Scan status: Finished

 

I did another scan and have attached the text file it prompted me to save.  I got the same message as the first time, "Success!  Scan completed.  We didn't detect any viruses or other infections."

Attached Files


  • 0

#23
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts
Very good!!

Let’s see the fresh FRST logs now.
  • 0

#24
karolion

karolion

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts

I have attached them.

Attached Files


  • 0

#25
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts

Hi!
 
Let's do some tidiness now.
 
1. FRST fix

Please do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Please select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
CreateRestorePoint:
CloseProcesses:
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14527.20276 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14527.20276 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E616003B-1FCD-492F-904C-741D360C791D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {01B10BEE-CEC8-4B67-9D40-0F1B616CB656} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22654872 2021-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {045E4C8F-E096-4C5F-AA86-8441F3475142} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138600 2021-11-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {7498719E-9F93-47F6-A09C-F1DB7CE9EA56} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\19192\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [19989464 2021-11-18] (ESET, spol. s r.o. -> ESET)
Task: {7B853215-31F4-482F-AD03-3F4AEB9487D3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138600 2021-11-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {B66638EA-88E1-4C44-8194-313C7CD8EC7A} - \KillHelpDeskService -> No File <==== ATTENTION
Task: {C9837A75-6F35-4D2B-A87A-A3FED7D06F8F} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\19192\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [19989464 2021-11-18] (ESET, spol. s r.o. -> ESET)
Task: {E56B4006-2F6A-4E46-8852-CEA43C985289} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22654872 2021-11-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12034464 2021-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {73F46A70-9630-4059-B911-C5423206F6AD} - System32\Tasks\Lenovo\UDC\Lenovo UDC Monitor => C:\Windows\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe [201584 2021-07-21] (Lenovo -> Lenovo Group Ltd.)
Task: {D0FAFD93-351B-47CD-9DC5-09079FFB2273} - System32\Tasks\Lenovo\UDC\Lenovo UDC Idle Monitor => C:\windows\system32\drivers\Lenovo\udc\Service\UDCUserAgent.exe [443248 2021-07-21] (Lenovo -> Lenovo Group Ltd.)
2021-11-18 11:54 - 2021-11-19 01:22 - 000003858 _____ C:\Windows\system32\Tasks\EOSv3 Scheduler onLogOn
2021-11-18 11:54 - 2021-11-19 01:22 - 000003416 _____ C:\Windows\system32\Tasks\EOSv3 Scheduler onTime
2021-11-18 10:25 - 2021-11-18 10:25 - 000000000 ____D C:\Users\19192\AppData\Local\ESET
2021-11-15 13:45 - 2021-04-14 04:50 - 000000000 ____D C:\Users\19192\AppData\Local\Lenovo
2021-11-15 13:45 - 2021-03-10 06:51 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo
2021-11-15 13:45 - 2021-03-10 06:51 - 000000000 ____D C:\Windows\Lenovo
2021-11-15 13:45 - 2021-03-10 06:51 - 000000000 ____D C:\ProgramData\Lenovo
2021-11-13 13:04 - 2021-03-10 07:03 - 000000000 ____D C:\Program Files (x86)\Lenovo
2021-11-12 17:28 - 2021-03-10 06:52 - 000000000 ____D C:\Program Files\Microsoft Office
C:\Program Files\Common Files\Microsoft Shared\ClickToRun
EmptyTemp: 
End::
  • Please right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Please post the log in your next reply.

 

2. Uninstall programs

  • Press the Windows Key + R.
  • Type appwiz.cpl in the Run box and click OK.
  • The Add/Remove Programs list will open. Locate the following programs in the list:
Office 16 Click-to-Run Extensibility Component 
Office 16 Click-to-Run Licensing Component 
Office 16 Click-to-Run Localization Component 
  • Select the above programs, one by one, and click Uninstall.
  • Restart the computer.

 

3. Feedback
 
How is the computer running now? Any remaining issues/questions/concerns? 
 
 
In your next reply please post:

  • The fixlog.txt
  • If everything went fine with uninstalling the programs
  • Your feedback

  • 0

Advertisements


#26
karolion

karolion

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts

Everything went fine uninstalling the programs on your list.  The computer seems to be working fine.  I tried to sign in to Microsoft Office, which is what I was trying to do when I called what I thought was Microsoft for help and spoke to "Sam", and received this message... https://www.dropbox....ftstop.png?dl=0

 

Do I have to create an Outlook email account to use the Office subscription I purchased with the laptop?  I get the same message when I enter either my Yahoo or Gmail address to attempt to sign in to Microsoft Office. 

Attached Files


  • 0

#27
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts

Karolion,
 
I have to apologize here. I'm sorry. Reading your logs I missed that you have installed Microsoft 365 - en-us and I completely forgot your initial issue with Office. I saw everything else about Office in your logs and thought they were remnants. The latest fix and the programs I asked you to uninstall were about Office. Although the programs are not necessary to run Office I would like you to follow these steps to restore the items we sent to Quarantine with the FRST fix. 
 
First do this please:

 

Do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Please select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
Folder: C:\FRST\Quarantine
End::
  • Please right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Please post the log in your next reply.

 

Now...

 

At the beginning of this thread you said the following, and as I understand, you have the same difficulties now. 

 

I paid for a year subscription to Microsoft 365 to be included with the computer for a discounted price.  Since I first received the computer I have not been able to sign into Microsoft on it, though I can sign in to Microsoft in my browser.  Yesterday was the first time I needed to use Microsoft 365 to create a word document.  I got a message saying the 180 day sign up period had expired and I'd have to purchase a new subscription, but it hasn't been 180 days since I got the computer.

 

I would like you to tell me:

 

1. What happens when you try to open Word?

 

2. What do you mean you can sign in to Microsoft in the browser?

 

3. When did you buy the computer?


  • 0

#28
karolion

karolion

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts

I was trying to open Office and the sign in prompt would ask for my phone number, email or Skype.  I had used my phone number to attempt sign in because I wasn't sure which email account was associated with Microsoft or if both accounts were.  This is an image of the error I was receiving when trying to sign in with my phone number... https://www.dropbox....ftstop.png?dl=0

 

Since my last response I decided to change the phone number to my email account and was able to sign in to Office on the web.  When I choose to create a new Word document (or Excel, PowerPoint, etc.) in Office on the web it opens a blank document in a new browser tab.  I saved a test document and was able to access it from OneDrive.  I also had the option to save a copy to the hard drive.  Sorry for the lengthy explanation but I wanted to give you a detailed account.

 

If you don't mind I do have two more questions.  When I choose the Word app in the Start menu I get this error message... https://www.dropbox....derror.png?dl=0

 

Should I delete the shortcut?  There are similar shortcuts for Excel, PowerPoint, Publisher and OneNote which give the same error message with a prompt to delete the shortcut for the corresponding program *.exe file when selected.  The icons for these shortcuts look like a tiny sheet of paper with the top right corner folded down.

 

This dialogue box also appeared before I tried to sign in to Microsoft Office... https://www.dropbox....eerror.png?dl=0

I don't know what this text document is but I thought I'd confirm with you that I should click on "Got it".

 

Now the answer to your second question is since I got the computer I was having difficulty signing in to Microsoft on the computer using the phone number and I would have a notification to fix the error with my Microsoft account which looks like this... https://www.dropbox....ctprob.png?dl=0

It seems with Windows 10 that Microsoft wants me signed in when I am working on the laptop regardless of whether I'm working on a Microsoft Office document or not, perhaps because they assume everyone has an Outlook email account they should be signed into in order to access the most recent emails.  It wants me to use a pin number to sign in now, I suppose for security purposes.  That's just a guess on my part.

 

To answer your last question I checked my email and I believe the date I received the computer was 14 April, 2021.  I ordered it on 9 April.

Attached Files


  • 0

#29
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts

Kalolion,

 

Thanks about the information given.

 

When we started the procedure to clean your computer, I asked you to make sure that you changed all your passwords. Did you do that? 

 

If you didn't do that, please do it now.

 

After that:

 

 

1. Restore Quarantine 

 

Please do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Please select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
RestoreQuarantine: C:\FRST\Quarantine\C\Program Files\Microsoft Office
RestoreQuarantine: C:\FRST\Quarantine\C\Windows\System32\Tasks\Microsoft
End::
  • Please right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Please post the log in your next reply.

 

2. Open Office programs and check

 

Should I delete the shortcut?  There are similar shortcuts for Excel, PowerPoint, Publisher and OneNote which give the same error message with a prompt to delete the shortcut for the corresponding program *.exe file when selected.  The icons for these shortcuts look like a tiny sheet of paper with the top right corner folded down.

 

Yes, you can delete the shortcuts. Try to open the programs like this: 

 

Click on the Start icon and then scroll until you find Word, for example, click on it and let me know what happens. 

 

 

3. Microsoft 365 Subscription

 

You said at the beginning of this topic that you got a message that your 180 days subscription ended. If you bought the computer in April, then 7 months passed since then, so the 180 days subscription ended. If that is the case, you will not be able to have access to the Office apps.

 


  • 0

#30
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 3,240 posts

As for this:

 

 

This dialogue box also appeared before I tried to sign in to Microsoft Office... https://www.dropbox....eerror.png?dl=0

 
I don't know what this text document is but I thought I'd confirm with you that I should click on "Got it".
 
Yes, click Got it. 

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP