WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionDifferent computer... Same thumbdrive... EmptyDifferent computer... Same thumbdrive...

more_horiz
I had a thumbdrive that was infected and it got two of my machines.

Symptoms are...
File menu is gone.
Can't add/remove.
Can't install Access 2k7 which I need for work.

Any help is greatly appriciated... THANKS A TON!

Here is the hjt log from my second machine.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:32 PM, on 12/4/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\cohrence.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Parallels\Parallels Tools\toolsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Parallels\Parallels Tools\ParallelsToolsCenter.exe
C:\Program Files\Parallels\Parallels Tools\SIA\sharedintapp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Ilium Software\ListPro\ListProAlarms.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.apple.com/startpage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [Parallels Tools] C:\Program Files\Parallels\Parallels Tools\ParallelsToolsCenter.exe
O4 - HKLM\..\Run: [SharedInternetApplication] "C:\Program Files\Parallels\Parallels Tools\SIA\sharedintapp.exe" /start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpyHunter Security Suite] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe"
O4 - Startup: ListProAlarms.lnk = C:\Program Files\Ilium Software\ListPro\ListProAlarms.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.runaware.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1216674843292
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Parallels Coherence Service (cohrence) - Parallels Software International, Inc. - C:\Program Files\Parallels\Parallels Tools\cohrence.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Parallels Tools Utility Service (toolsrv) - Parallels Software International, Inc. - C:\Program Files\Parallels\Parallels Tools\toolsrv.exe

--
End of file - 5622 bytes

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Hello again SKIN.
Plug in ALL flash drives you have and we'll clean them.


  • Download combofix from here, use the top links - combofix.exe
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    Different computer... Same thumbdrive... Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will this next prompt that asks if you want to continue the malware scan, select yes

    Different computer... Same thumbdrive... Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
ComboFix 08-12-04.04 - Administrator 2008-12-04 22:59:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.211 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-11-05 to 2008-12-05 )))))))))))))))))))))))))))))))
.

2008-11-25 10:20 . 2008-11-25 10:20 d-------- c:\program files\Enigma Software Group
2008-11-18 17:29 . 2005-11-10 20:26 61,551 --a------ c:\windows\system32\CNWILMNT.DLL
2008-11-17 16:56 . 2008-11-18 09:41 d-------- c:\documents and settings\Administrator\Application Data\GetRightToGo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 03:25 --------- d-----w c:\program files\Symantec AntiVirus
2008-11-18 22:31 --------- d-----w c:\program files\Canon
2008-10-14 17:04 --------- d-----w c:\documents and settings\Administrator\Application Data\U3
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Parallels Tools"="c:\program files\Parallels\Parallels Tools\ParallelsToolsCenter.exe" [2008-06-09 1064960]
"SharedInternetApplication"="c:\program files\Parallels\Parallels Tools\SIA\sharedintapp.exe" [2008-06-09 77824]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 53408]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-03-17 124656]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-09-10 864256]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ListProAlarms.lnk - c:\program files\Ilium Software\ListPro\ListProAlarms.exe [2008-09-05 102400]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 PrlNP;PrlNP;c:\windows\system32\DRIVERS\prlfs.sys [2008-07-21 138368]
R2 cohrence;Parallels Coherence Service;"c:\program files\Parallels\Parallels Tools\cohrence.exe" [2008-07-21 53346]
R2 prl_paravirt_32;Parallels Paravirtualization Driver;\??\c:\windows\system32\drivers\prl_paravirt_32.sys [2008-07-21 14957]
R2 PrlTime;Parallels Time Synchronization Driver;\??\c:\windows\system32\drivers\PrlTime.sys [2008-07-21 2550]
R2 toolsrv;Parallels Tools Utility Service;c:\program files\Parallels\Parallels Tools\toolsrv.exe [2008-07-21 90112]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-11-05 99376]
R3 PCITG;PCITG;c:\windows\system32\drivers\pcitg.sys [2008-07-21 15232]
R3 prleth;Parallels Network Adapter;c:\windows\system32\DRIVERS\prleth.sys [2008-07-21 6112]
R3 PrlMouse;Parallels Mouse Synchronization Tool;c:\windows\system32\DRIVERS\PrlMouse.sys [2008-07-21 5341]
R3 PrlVideo;PrlVideo;c:\windows\system32\DRIVERS\PrlVideo.sys [2008-07-21 16384]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\DRIVERS\NtApm.sys [2008-07-21 9344]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2006-03-17 115952]

*Newly Created Service* - PROCEXP90
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 23:02:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(512)
c:\windows\System32\prlnp.dll
.
Completion time: 2008-12-04 23:03:20
ComboFix-quarantined-files.txt 2008-12-05 04:03:14

Pre-Run: 24,973,938,688 bytes free
Post-Run: 25,006,313,472 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

81 --- E O F --- 2008-12-05 03:08:06

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz

  • Now open a new notepad file.
  • Input this into the notepad file:

    Windows Registry Editor Version 5.00

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSimpleNetIDList"=-


  • Save this as fix.reg, save it to your desktop.
  • Double click fix.reg to run it.
  • Select yes to the registry merge prompt.


Looks good, what problems remain?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Still can not get to add/remove programs.

Still have this windows icon instead of an actual file menu...

Different computer... Same thumbdrive... Picture%208

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Bump?

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Hello.
Sorry for the delay, missed your post. Try this.


  • Now open a new notepad file.
  • Input this into the notepad file:

    Windows Registry Editor Version 5.00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoFileMenu"=-


  • Save this as fix.reg, save it to your desktop.
  • Double click fix.reg to run it.
  • Select yes to the registry merge prompt.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Still no file menu and still can not get into add/remove programs.

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Okay, lets see what this says.

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar



  • Now open a new notepad file.
  • Input this into the notepad file:

    regedit /e peek1.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar"
    type peek1.txt >> look.txt
    del peek1.txt
    start notepad look.txt


  • Save this as look.bat, save it to your desktop.
  • Double click look.bat to run it.
  • Copy and paste the report back here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
"LinksFolderName"="Links"
"Locked"=dword:00000001
"ShowDiscussionButton"="Yes"
"SaveLinksOrder"=hex:01,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Explorer]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{01E04581-4EEE-11D0-BFE9-00AA005B4383}"=hex:81,45,e0,01,ee,4e,d0,11,bf,e9,00,\
aa,00,5b,43,83,10,00,00,00,00,00,00,00,01,e0,32,f4,01,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{01E04581-4EEE-11D0-BFE9-00AA005B4383}"=hex:81,45,e0,01,ee,4e,d0,11,bf,e9,00,\
aa,00,5b,43,83,10,00,00,00,00,00,00,00,01,e0,32,f4,01,00,00,00
"{0E5CBF21-D15F-11D0-8301-00AA005B4383}"=hex:21,bf,5c,0e,5f,d1,d0,11,83,01,00,\
aa,00,5b,43,83,22,00,1c,00,08,00,00,00,06,00,00,00,01,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,4c,00,00,00,01,14,02,00,00,00,00,00,c0,00,00,00,00,\
00,00,46,81,00,00,00,10,00,00,00,e0,e1,cd,63,7e,eb,c8,01,30,bb,bc,95,76,eb,\
c8,01,50,7c,50,65,7e,eb,c8,01,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,61,01,14,00,1f,50,e0,4f,d0,20,ea,3a,69,10,a2,d8,\
08,00,2b,30,30,9d,19,00,2f,43,3a,5c,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,5c,00,31,00,00,00,00,00,f5,38,14,b1,10,00,44,4f,43,55,4d,\
45,7e,31,00,00,44,00,03,00,04,00,ef,be,f5,38,c2,86,f5,38,86,a9,14,00,00,00,\
44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,73,00,20,00,61,00,6e,00,64,\
00,20,00,53,00,65,00,74,00,74,00,69,00,6e,00,67,00,73,00,00,00,18,00,4a,00,\
31,00,00,00,00,00,f5,38,16,b1,10,00,41,44,4d,49,4e,49,7e,31,00,00,32,00,03,\
00,04,00,ef,be,f5,38,14,b1,f5,38,86,a9,14,00,00,00,41,00,64,00,6d,00,69,00,\
6e,00,69,00,73,00,74,00,72,00,61,00,74,00,6f,00,72,00,00,00,18,00,56,00,31,\
00,00,00,00,00,f5,38,28,b1,11,00,46,41,56,4f,52,49,7e,31,00,00,3e,00,03,00,\
04,00,ef,be,f5,38,15,b1,f5,38,28,b1,14,00,28,00,46,00,61,00,76,00,6f,00,72,\
00,69,00,74,00,65,00,73,00,00,00,40,73,68,65,6c,6c,33,32,2e,64,6c,6c,2c,2d,\
31,32,36,39,33,00,18,00,36,00,31,00,00,00,00,00,f5,38,24,b1,10,00,4c,69,6e,\
6b,73,00,22,00,03,00,04,00,ef,be,f5,38,23,b1,f5,38,24,b1,14,00,00,00,4c,00,\
69,00,6e,00,6b,00,73,00,00,00,14,00,00,00,60,00,00,00,03,00,00,a0,58,00,00,\
00,00,00,00,00,74,6f,64,64,70,65,61,72,63,65,38,31,64,36,00,00,50,7f,60,97,\
a3,b7,95,49,b7,c7,70,4b,88,c6,da,20,01,42,53,b7,69,57,dd,11,b9,93,00,1c,42,\
1f,e3,d9,50,7f,60,97,a3,b7,95,49,b7,c7,70,4b,88,c6,da,20,01,42,53,b7,69,57,\
dd,11,b9,93,00,1c,42,1f,e3,d9,00,00,00,00
"ITBarLayout"=hex:11,00,00,00,4c,00,00,00,00,00,00,00,34,00,00,00,1f,00,00,00,\
56,00,00,00,01,00,00,00,20,07,00,00,a0,0f,00,00,05,00,00,00,62,05,00,00,26,\
00,00,00,02,00,00,00,21,07,00,00,a0,0f,00,00,04,00,00,00,21,01,00,00,a0,0f,\
00,00,03,00,00,00,20,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"ITBar7Layout"=hex:13,00,00,00,00,00,00,00,00,00,00,00,30,00,00,00,10,00,00,00,\
15,00,00,00,01,00,00,00,00,07,00,00,5e,01,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Okay.
New plan.

I just learned you can mess the toolbars up. LMBO or ROFL

Right click at the grey area at the top, and select "Unlock toolbars"
Then you can drag them around abit and mess them up, yours has been messed.
Once unlocked, you should be able to drag stuff around and see what happens.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
I tried to right click and nothing comes up. I still can not get to add/remove programs either. Running appwiz.cpl brings up the hour glass for a brief second and then nothing happens after that.

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Hold tight, having a colleague look at this.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Hello.
I need to know what happens when you do this:
Start > Run
type in:
control.exe

Do you get the control panel?

Right click the Start button and select Properties > then look at the Start Menu tab, make sure your theme isn't set to classic start menu, then press "Customize" on the normal Start Menu option > this opens another window, press the "Advanced" tab > under control panel, select "Display as a link" or "Display as a menu"

Press okay and close down the options, do you have your menus back now?

Press Start > Run again.
type in:
regedit

This opens the registry editor, follow this key path, and check if the key in bold below exists
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

If not, a repair install or format maybe the only option.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
I did an regsvr32 appwiz.cpl and got my add/remove back. I will try what you said and see what happens. I still dont have my file menu, otherwise everything is fine.

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Belahzur wrote:
Hello.
I need to know what happens when you do this:
Start > Run
type in:
control.exe

Do you get the control panel?


Yes

Belahzur wrote:

Right click the Start button and select Properties > then look at the Start Menu tab, make sure your theme isn't set to classic start menu, then press "Customize" on the normal Start Menu option > this opens another window, press the "Advanced" tab > under control panel, select "Display as a link" or "Display as a menu"

Press okay and close down the options, do you have your menus back now?


I did that... Still do not have file menus.

Belahzur wrote:

Press Start > Run again.
type in:
regedit

This opens the registry editor, follow this key path, and check if the key in bold below exists
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall


Yes that key is present.

Belahzur wrote:

If not, a repair install or format maybe the only option.


Well after I did all of this what do you think? Is a reinstall my only option? The only problem now
is the file menus are gone.

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Repair install and re-install are two different things.
We can try a repair before formatting.

Do you have your XP disc?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Belahzur wrote:
Repair install and re-install are two different things.
We can try a repair before formatting.

Do you have your XP disc?


Yes I do have it.

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Okay.
Put the disc in and reboot your machine.
Allow it to boot from disc and when the blue screen appears, select R for repair.

Read here:
http://www.michaelstevenstech.com/XPrepairinstall.htm

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Different computer... Same thumbdrive... DXwU4
Different computer... Same thumbdrive... VvYDg

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.

............................................................................................

Please be a GeekPolice fan on Facebook!

Different computer... Same thumbdrive... Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionDifferent computer... Same thumbdrive... EmptyRe: Different computer... Same thumbdrive...

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum