WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
Lets kick off these toolbars manually, if uninstalling does not do the job:

  • Please run OTL.exe again
  • Under the Custom Scans/Fixes box at the bottom, copy and paste in the following:

Code:

:files
@C:\ProgramData\Temp:DFC5A2B2
C:\Program Files (x86)\somototoolbar
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}
C:\Program Files (x86)\Ask.com
C:\Program Files (x86)\Yontoo Layers Runtime (Drop Down Deals)
C:\Users\Erik Abreu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire 5
C:\Windows\tasks\PC Optimizer Pro64 startups.job

:otl
[2011/11/06 02:22:54 | 000,000,000 | -H-D | M] (Somoto Toolbar) -- C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}
O2 - BHO: (Somoto Toolbar) - {652853ad-5592-4231-88c6-706613a52e61} - C:\Program Files (x86)\somototoolbar\vmntemplateX.dll ()
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Yontoo Layers (Drop Down Deals)) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo Layers Runtime (Drop Down Deals)\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (Somoto Toolbar) - {652853ad-5592-4231-88c6-706613a52e61} - C:\Program Files (x86)\somototoolbar\vmntemplateX.dll ()
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found

:commands
[reboot]

  • Then click the Run Fix button at the top (Not the Run Scan!).
  • Allow it to run. It may take some time and you may see some things happen to your desktop - this is normal.
  • If it asks to reboot the computer, allow it to reboot.
  • If the program freezes, and the computer fails to reboot - let me know.
  • Finally, post the contents of the log. (Located at C:\_OTL\Moved Files)


====================

You need to install the latest version of Java. Having the latest version is important to take advantage of fixes that have eliminated security vulnerabilities.
  • Go to Start > Control Panel
  • Double-click on Add or Remove Programs
  • Look for entries that say Java, Java RunTime Environment or J2SE.
  • Uninstall all of them that are not named Java (TM) 6 Update 29

After doing this, you can go to java.com, click on Free Java Download and proceed from there to install the latest version of Java (currently Version 6 Update 29).

After installing Java, go to Start > Control Panel > Java to open the Java Control Panel.
Under the General tab, Temporary Internet Files click Settings, then click Delete Files.
Select both options and click OK to delete the Java cache.

====================

How are things running now?

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyFIX LOG

more_horiz
========== FILES ==========
ADS C:\ProgramData\Temp:DFC5A2B2 deleted successfully.
C:\Program Files (x86)\somototoolbar\components folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\searchbar folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\options folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\weatherbutton\panels folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\weatherbutton\icons folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\weatherbutton folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\uwa folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\radio\images folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\radio\css folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\radio folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\panels\images folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\panels\default\css folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\panels\default folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\panels\css folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\panels folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib\debugbar folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin\lib folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\skin folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\data\weather folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\data\search folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\data\rss folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\data\dynamicElements folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\data folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets\net.vmn.www.MyStartFacebook\css folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets\net.vmn.www.MyStartFacebook folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\widgets folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\newtab\images folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\newtab folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\modules folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content\lib folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome\content folder moved successfully.
C:\Program Files (x86)\somototoolbar\chrome folder moved successfully.
C:\Program Files (x86)\somototoolbar folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\components folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\searchbar folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\options folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\weatherbutton\panels folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\weatherbutton\icons folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\weatherbutton folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\uwa folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\radio\images folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\radio\css folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\radio folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\panels\images folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\panels\default\css folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\panels\default folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\panels\css folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\panels folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib\debugbar folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin\lib folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\skin folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\data\weather folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\data\search folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\data\rss folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\data\dynamicElements folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\data folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets\net.vmn.www.MyStartFacebook\js folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets\net.vmn.www.MyStartFacebook\images folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets\net.vmn.www.MyStartFacebook\css folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets\net.vmn.www.MyStartFacebook folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\widgets folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\newtab\images folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\newtab folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\modules folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content\lib folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome\content folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\chrome folder moved successfully.
C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61} folder moved successfully.
C:\Program Files (x86)\Ask.com\Updater folder moved successfully.
C:\Program Files (x86)\Ask.com\assets\oobe folder moved successfully.
C:\Program Files (x86)\Ask.com\assets folder moved successfully.
C:\Program Files (x86)\Ask.com folder moved successfully.
Folder move failed. C:\Program Files (x86)\Yontoo Layers Runtime (Drop Down Deals) scheduled to be moved on reboot.
C:\Users\Erik Abreu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire 5 folder moved successfully.
C:\Windows\tasks\PC Optimizer Pro64 startups.job moved successfully.
========== OTL ==========
Folder C:\Users\Erik Abreu\AppData\Roaming\Mozilla\Firefox\Profiles\93jyix6r.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{652853ad-5592-4231-88c6-706613a52e61}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{652853ad-5592-4231-88c6-706613a52e61}\ deleted successfully.
File C:\Program Files (x86)\somototoolbar\vmntemplateX.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ deleted successfully.
C:\Program Files (x86)\Yontoo Layers Runtime (Drop Down Deals)\YontooIEClient.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{652853ad-5592-4231-88c6-706613a52e61} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{652853ad-5592-4231-88c6-706613a52e61}\ not found.
File C:\Program Files (x86)\somototoolbar\vmntemplateX.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
========== COMMANDS ==========

OTL by OldTimer - Version 3.2.31.0 log created on 12132011_133503

Files\Folders moved on Reboot...
C:\Program Files (x86)\Yontoo Layers Runtime (Drop Down Deals) folder moved successfully.

Registry entries deleted on Reboot...

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyUPDATE

more_horiz
I downloaded java.

My Computer is running smoothly but my desktop is still black.
My start menu only consists of computer internet explorer and uninstall programs meaning im missing.

Control Panel My Music My Pictures


I Want my pc to look like it was when i first bought it.

Also my start bar is at the top. How do i get it back at the bottom.

Basiclly it runs very fast but my programs wont show like they were before the virus threat.

Files Got Deleted

And I lost my start menu options.

Thank You For Your Time And Help so far.

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
  • Please download Unhide by Grinler from here and save it to your desktop.
  • Double click unhide.exe to run the tool.
  • It will take some time to go through all your files, so please be patient.


Hopefully after this tool runs, things look a bit better. If they don´t there is no other way to fix this than the hard way. Some files may have been deleted or configuration changed - so reinstall and reconfigure is the only option you have.

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyUPDATE

more_horiz
My Computer unhid some folders that were on my computer. It seems that most of my 3rd party programs were deleted.

My computer is running really well proformance wise. But Malware bytes tells me once in a while that it blocked a malicious process.

Also my taskbar is at the top. how do i get it at the bottom like regular computers.

And My menu still is still empty no control panel no my pics , my vids , etc.

Thank You Very Much So Far. Also I can change my desktop backround now.

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyESET

more_horiz
Also Remember Those EST Threats. Are They Gone?

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
The ESET threads are mostly dead bodies that were quarantined already. There were a couple of downloads from CNET that were suspicious. I have heard that CNET downloads are not to be trusted anymore.

You can move the taskbar by rightclicking it, making sure the option "Block Task Bar" is NOT selected and simply drag it down with your mouse.

I´m sitting currently at a WINXP computer, so I cant verify, but your programs menu is somewhere in your users folder.

What you can try is to create some new dummy user. WIN7 will build the programs folder for that user and copy that into your own programs folder. After doing this, delete the dummy user again.

It will be work to re-create your programs folder, but there is really no other good way. You can uninstall/reinstall software applications to get the programs folder back etc.

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyUPDATE

more_horiz
I moved my taskbar. thank you

I made the account and logged back on my admin acc and the pro. are still missing. Is there a way to do it manually.

Also Do you believe my computer is clean even though malware bytes blocks a malicious process.

explorer.exe

and if my computer is clean what are some better free anti virus anti malware software and firewalls that you can recommend.

thank you.

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
Is malwarebytes still reporting explorer.exe as malicious??

After you make a new account, you will have a new user folder - find the programs folder and copy the contents of the programs folder to your main account. If you cant find the folder I will look at home, I have a WIN7 x64 machine there.

When we close this case I will post my ALORTKYCC (Awesome List Of Recommendations To Keep Your Computer Clean)

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
i cant find it .

malware bytes isnt reporting anything anymore

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
OK, I looked it up, it is the folder

c:\users\USERNAME\appdata\roaming\microsoft\windows\start menu

find this folder for your user and for the new user you created. Copy what you find missing.

Hope this helps

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 Emptyupdate

more_horiz
i found the folder and copied to my user. it didnt do anything. do you think i should restart. or is they're another way.

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
Well - I´m not much of an expert in Windows 7. If you have all the folders, you should see the start menu correctly. Maybe a restart reloads it.

Otherwise I´d say, you have to go the hard way and add manually to your programs menu all the stuff you want.
Problems like this can often be googled. Find other persons that had the same problem and see how they solved it.

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 Emptythank you

more_horiz
okay then thank you so much for all your help. i believe my computer is clean.

can i get the reccom.

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
I ran a baf. program that automaticly restored my "Iron Cache" Which Then Restored My Icons. So The Problems Are All Fixed. Thank You For your time and help.
Sincerely ,
Erik

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
Allright! Here follows my ALORTKYCC (Awesome List Of Recommendations To Keep Your Computer Clean):

1) Keep your Windows up-to-date. Windows Autoupdate should be ON (see Start >> Control Panel >> Security Center). An alternative way (but more time-consuming) is to periodically visit http://windowsupdate.microsoft.com. Hackers are looking every day for new security holes. Microsoft keeps patching them. You cannot fall behind in this race, it will make your system vulnerable.

2) For your average daily computer activities, use a limited/standard user account, not an administrator account. If you use Vista/WIN7 do not disable User Account Control (UAC). You would be amazed to know how much malware can´t touch you if you deny it admin rights. Create a separate password-protected administrator account that you use for admin activities, like (un)installing software.

3) Use a good antivirus. There are various free ones, you cannot go wrong with either of the following three:
  • Panda Cloud Antivirus. If you want your antivirus to be light on resources, I recommend Panda. Install without the toolbar.
  • Ad-Aware Free Internet Security has received great reviews from leading security analysts.
  • Avast! is a very complete antivirus, with modules like mailscanner and webshield.

4) If your computer has 1GB system memory or more, you should install a third party firewall, to replace the weak Windows Firewall. I recommend:

Note: you should run only ONE antivirus and ONE firewall. Running multiples of either is bad, it will cause slowdowns and/or conflicts.

5) Miscellaneous advice:
  • Stay away from cracks and keygens (look here for the why). Get free software instead. Gizmo is an excellent source of freeware reviews.
  • Navigate safely. Google Chrome is the safest browser available. However, Mozilla Firefox can be made extremely safe with the NoScript addon. Internet Explorer (always use the last version) can be made a lot safer with Spywareblaster (manual here).
  • The WOT (Webs Of Trust) addon will help you to stay on reliable webpages.
  • WinPatrol alerts you when changes are made in vital system areas. Especially good on light systems not running a third party firewall.
  • Make sure you have ways to recuperate your operating system and vital other data if its gets frustrated by malware and/or other problems. A Windows setup CD and recent backups/disk images will be priceless, if you find yourself in an unexpected tight spot.

Finally: did we help you? Help us back!

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
thank you

descriptionI believe I Have a cryptor virus and i has taken over my computer help!!!!!! - Page 1 EmptyRe: I believe I Have a cryptor virus and i has taken over my computer help!!!!!!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum