When done, and back at the main screen of KillBox, select the option: Delete on Reboot Then, in the Full Path of File to Delete box, copy and paste this entry: I am not sure if microsoft already fixed this issue in latest releases of windows. Where u have to write username and password. Motherboard: Dell Inc. | | 0K83V0 Processor: Pentium(R) Dual-Core CPU E5400 @ 2.70GHz | CPU 1 | 2700/200mhz . ==== Disk Partitions ========================= .

C:\Windows\System32\fltMC.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. HKCR\Interface\{4634D64C-B361-4AF9-94BC-FB86A7B18EFF} (Trojan.FakeMS) -> Delete on reboot. Ask a Question See Latest Posts TechSpot is dedicated to computer enthusiasts and power users. C:\Windows\System32\SystemPropertiesHardware.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.

admin aah…cool will surely try to find a hack using them, though there exists a lot using them. Open the folder where the contents were unzipped and run mbar.exe Follow the instructions in the wizard to update and allow the program to scan your computer for threats. Click on "Sweep" and allow it to fully scan your system. 6. im trying it but also i got the same problem..it says disk is full..hmm tnx for the article!!!hope to see more from u,,keep me updated pls h4v0c- thanks for the account

Then :- Download CCLEANER (http://www.ccleaner.com/) then run the scan under the windows tab. then DEFRAG (http://helpdesk.its.uiowa.edu/windows/instructions/defrag.htm) your C:\ drive. Can you carry out the rest of the requests. Folders Detected: 0 (No malicious items detected) Files Detected: 105 C:\Windows\System32\SEARCHINDEXER.EXE (Trojan.FakeMS) -> Quarantined and deleted successfully. take note, it would have an icon of a hard drive. 7.

because you cant replace the file because windows is already write protected??? I know just from the sound of it, is quite impossible but please help. Jump to content FacebookTwitter Geeks to Go Forum Security Virus, Spyware, Malware Removal Welcome to Geeks to Go - Register now for FREE Geeks To Go is a helpful hub, where khan aqib i cant break admin password with Guest account.anybody can help me john Very cool.

It has done this 3 time(s). 02/01/2013 7:06:28 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly. Thanks!Logfile of HijackThis v1.97.7Scan saved at 4:32:05 PM, on 7/26/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Google\ggviewer67-66.exeC:\WINDOWS\System32\atiptaxx.exeC:\WINDOWS\LTSMMSG.exeC:\Program Files\Apoint2K\Apoint.exeC:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exeC:\Program Files\Fujitsu\Application Panel\QuickTouch.exeC:\Program Files\Fujitsu\BtnHnd\BtnHnd.exeC:\Program Files\EarthLink 5.0\ConMgr.exeC:\Program C:\Windows\System32\MuiUnattend.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. Post the contents of that log in your next reply please.[/list] Step 7 Once back in Windows, go to your Control Panel and click Display | Desktop | Customise Desktop

I am planning for a webpage but not getting a head start…. 🙁 XP USER I tried to do all what you gave me but the sethc.exe I replaced with cmd.exe If so..do they get deleted when I delete em frm the guest a/c? Double click on the file to extract it to it's own folder on the desktop. Flrman1, Jan 3, 2004 #6 Sponsor This thread has been Locked and is not open to further replies.

Click Yes at the request to reboot. admin Well I don't think it is possible unless your guest account has the required privilege. Last but not the least (IMPORTANT) Windows has two type of login screens: Where the accounts are listed with some pictures. Make sure the disk is not full or write-protected and that the file is not currently in use" pls help anyone deee If sys 32 in not wratable then what??????

P2 McShield;McAfee McShield;C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe [2010-10-22 181480] R0 mfehidk;McAfee Inc. Thanks2009-1-21 admin What message do you get exactly when you try to copy the file?? C:\Windows\System32\convert.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. Move the file.Open the FINDnFIX folder again and double-click on RESTORE.bat.

Is there a way to circumvent this access request or did they fix this windows bug? If you have privileges to change System32 to being writeable, you already have admin access so wtf is the point of this?.jon is absolutely correct,;the trick is clear and good but The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again

C:\Windows\System32\com\MigRegDB.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.

Mark it as an accepted solution!I am not a Comcast employee. C:\Windows\System32\ssText3d.scr (Trojan.FakeMS) -> Quarantined and deleted successfully. And a bit later another dialog will pop up saying “Startup repair cannot repair this computer automatically”. Click on the View tab and make sure that "Show hidden files and folders" is checked.

If it doesn't pop up on your comp, then may be your shortcut is turned off. Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. C:\Windows\System32\xcopy.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. uStart Page = hxxp://www.google.ca/ mWinlogon: Userinit = userinit.exe, BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO:

It has done this 26 time(s). 02/01/2013 7:13:00 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly. anarchist Ahoy! Hit ctrl+O. I am a paying customer just like you!

It has done this 34 time(s). 02/01/2013 7:13:42 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly. C:\Windows\System32\mfpmp.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. Concept: When u press, the SHIFT key >= 5 times, a file with the name "sethc.exe" is executed.  You can verify this in TASK manager (don't close the pop up window). C:\Windows\System32\eventvwr.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.

i've tried about 20 anti spyware etc programs, but none helped . Log in or Sign up Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Computer problem? Alan Nicely done 🙂 Fogal I need admin rights on windows 2008 server but im a guest acc, how do i by pass this, my cmd is disabled.Please. After i created a new admin, of course 🙂 Akshay i reli need smethng for my skul computer lab they have blocked evry thng evn system 32 cant be modified Ssgar

Physical Sector Size: 0 Drive: 1, DevicePointer: 0xfffffa8005e24060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8005e24b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8005e24060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa8005e02150, DeviceName: are you still having problems. Both running Win7.