PDA

View Full Version : Cleansed computer has broken links to files



gnowgnow
2012-01-12, 05:02
I recently ran McAfee Stinger to cleanse FalseAlert and Trojan viruses in my computer. I then downloaded Spybot to ensure my machine is clean. Spybot removed several more files. However, when I ran some of my application sofeware, I discover I can't open many files. I get the message "Not possible to open XXXX.yy" Can someone please help me?

Zenobia
2012-01-12, 22:57
What type of files will not open?Is it .exe files?

Could you open Spybot,click Mode up top,select Advanced mode,(if a warning window comes up,please select "Yes"),then click Tools,View Reports,then click View Previous Reports.

The Spybot logfiles are dated(Checks.yymmdd-hhmm or Fixes.yymmdd-hhmm).Please select the Spybot Fixes logfile from the scan where the several more files were removed and doubleclick it.It should open in the Spybot window.Rightclick somewhere in that window,and select "Select All".Then rightclick again,select Copy,then Paste the logfile here in a reply.

gnowgnow
2012-01-13, 04:04
I recently ran McAfee Stinger to cleanse FalseAlert and Trojan viruses in my computer. I then downloaded Spybot to ensure my machine is clean. Spybot removed several more files. However, when I ran some of my application sofeware, I discover I can't open many files. I get the message "Not possible to open XXXX.yy" Can someone please help me?

I'm a newby and so unfamiliar with the format of responding, but I would like to thank you for addressing my problem.

The files that lost the link are not exe files. They are data files but I can't find those files in the locations I stored them.

Here is file Fixes log:


--- Report generated: 2012-01-08 20:25 ---

DoubleClick: Tracking cookie (Internet Explorer: Ken) (Cookie, fixed)


DoubleClick: Tracking cookie (Chrome: Chrome) (Cookie, fixed)


DoubleClick: Tracking cookie (Chrome: Chrome) (Cookie, fixed)


DoubleClick: Tracking cookie (Chrome: Chrome) (Cookie, fixed)



--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-01-26 TeaTimer.exe (1.6.4.26)
2012-01-08 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-01-26 advcheck.dll (1.6.2.15)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-12-29 Includes\AdwareC.sbi (*)
2010-08-12 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-11-29 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-10-04 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-09-26 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2011-12-07 Includes\Malware.sbi (*)
2012-01-03 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-12-27 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2011-02-24 Includes\Security.sbi (*)
2011-12-13 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-10-18 Includes\Spyware.sbi (*)
2011-10-18 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2011-09-27 Includes\Trojans.sbi (*)
2012-01-02 Includes\TrojansC-02.sbi (*)
2011-12-28 Includes\TrojansC-03.sbi (*)
2012-01-03 Includes\TrojansC-04.sbi (*)
2012-01-02 Includes\TrojansC-05.sbi (*)
2012-01-02 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Zenobia
2012-01-13, 08:46
You're welcome.Thank you for posting the logfile. :)
Just some tracking cookies were removed when you ran that particular scan with Spybot,so that would not have an affect on any of your data files.

If the data files are missing from the location you stored them,it's possible that another program might have removed them for a couple of reasons.For example,the files might have been removed due to a false positive,etc.

I see in some instructions for Stinger that it's possible to save the scan results to a logfile.Did you happen to save the Stinger scan results,by any chance?

gnowgnow
2012-01-13, 09:46
Unfortunately, I didn't save any information generated by Stinger.

Now, I find another application program that has an error message (shown below). The file in the message must be an integral part of the program as I went to the program folder and couldn't find the file.


Not possible to open thefile
File Transaction1134H016K

Zenobia
2012-01-13, 11:43
May I ask the name of the program that you were trying to open when you received the "Not possible to open the file File Transaction1134H016K" message?

Also,when you were running the previous application or applications,were you actually getting the "Not possible to open XXXX.yy" message,or did you put in XXXX.yy just for an example?
And may I ask the names of the programs you were running when you got that message?

gnowgnow
2012-01-13, 22:29
The message comes from a software for adjusting my hearing aid.

The XXX.yy file is an example. The files that I lost the links are Lotus 123, PowerPoint and Word.

Additionally, all the links in my Favorites have disappeared. My OS is Windows 7.

gnowgnow
2012-01-13, 22:33
One further point, those files I stored in McAfee Vault remained untouched. Unfortunately, I didn't place all the important files in that location.

Zenobia
2012-01-14, 07:35
This is a long shot,since even if the malware hid some of your files,your files still should open when running programs.But,it's better to err on the side of caution.
Please click this link,and follow the instructions to temporarily show hidden files in Windows 7:
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/#win7

The files that lost the link are not exe files. They are data files but I can't find those files in the locations I stored them.
Now please go to the location where you stored them,and let me know if they are visible there now.

gnowgnow
2012-01-15, 03:40
Will do it when I get home tomorrow. Thanks for being so patient

Zenobia
2012-01-16, 05:26
Okie-doke. :)

gnowgnow
2012-01-16, 08:41
You're a genius. I'm in awe! Using the link you gave me, I was able to see all the data files. The application program lost the links to these files but by double-clinking on these files I was able to load them into the application program such as PowerPoint or Word. Thanks a heap.

I also found a folder called Favorite which contains all my favorites but have disappeared from the screen under Favorites. Is there a quick way of restoring these favorites links.

Also, several people suggested I should install two programs: Hot Virtual Keyboard and Malwarebytes to protect my machine. What are your expert opinions on these programs?

glock907
2012-01-16, 09:45
spybot will not remove 12 spyware says i am not the administrator need help free to call Edit- Removed phone number for your own privacy, also we do not call members. ;)

glock907
2012-01-16, 09:47
goint to bed now please call with help about 12 noon central time
thank you:thanks:

spybotsandra
2012-01-16, 10:44
Hello,

Windows Vista/Windows 7 might tell you that you are not being allowed to operate at the administration level of your computer.
You can solve this problem as follows:
Right-click the Spybot - Search & Destroy entry in your start menu,
instead of just left-clicking to start it.
Then, choose Run as administrator/take ownership from the context menu.
You will find a screenshot of this problem (http://www.safer-networking.org/en/faq/42.html) in our FAQ.

Best regards
Sandra
Team Spybot

Zenobia
2012-01-17, 09:06
You're a genius. I'm in awe! Using the link you gave me, I was able to see all the data files. The application program lost the links to these files but by double-clinking on these files I was able to load them into the application program such as PowerPoint or Word. Thanks a heap.

I also found a folder called Favorite which contains all my favorites but have disappeared from the screen under Favorites. Is there a quick way of restoring these favorites links.

Also, several people suggested I should install two programs: Hot Virtual Keyboard and Malwarebytes to protect my machine. What are your expert opinions on these programs?

Good,I'm glad to hear that. :)
For your favorites,please try this:
Click your start button,and type cmd.Rightclick cmd,and select Run as Administrator.
Type,or copy and paste this line into the window:
cd %USERPROFILE%\Favorites
Then press enter.
Next,type attrib,and then press enter.
If your favorites are located in the right spot,you should see your bookmarks listed there,followed by .url It'll look something like this:
A C:\Users\gnowgnow\Favorites\Drivers & Downloads.url

Do your favorites all have sh listed in front of them,like this?
A SH C:\Users\gnowgnow\Favorites\Drivers & Downloads.url

I'm not familiar with Hot Virtual Keyboard but it looks pretty good.MalwareBytes is definately a good program to install,in my opinion. :)

gnowgnow
2012-01-18, 22:43
Good,I'm glad to hear that. :)
For your favorites,please try this:
Click your start button,and type cmd.Rightclick cmd,and select Run as Administrator.
Type,or copy and paste this line into the window:
cd %USERPROFILE%\Favorites
Then press enter.
Next,type attrib,and then press enter.
If your favorites are located in the right spot,you should see your bookmarks listed there,followed by .url It'll look something like this:
A C:\Users\gnowgnow\Favorites\Drivers & Downloads.url

Do your favorites all have sh listed in front of them,like this?
A SH C:\Users\gnowgnow\Favorites\Drivers & Downloads.url

I'm not familiar with Hot Virtual Keyboard but it looks pretty good.MalwareBytes is definately a good program to install,in my opinion. :)

Following your instructions, this is a segment displayed on the screen:

A H C:\Users\gnowgnow\Favorites\Trade Architures.url
A H C:\Users\gnowgnow\Favorites\USATODAY.url
A H C:\Users\gnowgnow\Favorites\Yahoo! Finance -.url

How do I move the files to Drivers & Downloads?

Zenobia
2012-01-19, 05:01
No need to move the files to Driver's & Downloads,the above was just an example of what the .url listed in cmd might look like. :)

Please click your start button,and type cmd.Rightclick cmd,and select Run as Administrator.
Type,or copy and paste this line into the window:
cd %USERPROFILE%\Favorites
Then press enter.
Next,please type in:
attrib -h
Then press enter.
You'll probably get a message in the cmd window that says: "Not resetting system file - C:\Users\gnowgnow\Favorites\desktop.ini"
No need to worry about that message.
Hopefully,that should remove the hidden attribute from your favorites.
Type exit in the cmd window,then open up Internet Explorer.Are your favorites visible now?

gnowgnow
2012-01-19, 08:23
No need to move the files to Driver's & Downloads,the above was just an example of what the .url listed in cmd might look like. :)

Please click your start button,and type cmd.Rightclick cmd,and select Run as Administrator.
Type,or copy and paste this line into the window:
cd %USERPROFILE%\Favorites
Then press enter.
Next,please type in:
attrib -h
Then press enter.
You'll probably get a message in the cmd window that says: "Not resetting system file - C:\Users\gnowgnow\Favorites\desktop.ini"
No need to worry about that message.
Hopefully,that should remove the hidden attribute from your favorites.
Type exit in the cmd window,then open up Internet Explorer.Are your favorites visible now?

Works like a charm. Got all my favorites back. Save me a lot of efforts to retype all the favorites. Really appreciate your help.

Could the file Transaction1134H016K be hidden? Anyway to check that, Guru?

Zenobia
2012-01-19, 10:54
Good,I'm glad to hear that.You're welcome. :)

No,I don't believe Transaction1134H016K being hidden would be the problem,since if it is,your program should still be able to open it.
If you've reversed showing hidden files,please go here to temporarily unhide them once again:
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/#win7
Please click your start button,then type,or copy and paste in Transaction1134H016K
If the file appears in your start menu,rightclick it and select Open file location.After the file location opens,could you highlight the text in the address bar above,then right click and select Copy.Please paste it here in your reply.

gnowgnow
2012-01-20, 03:14
Good,I'm glad to hear that.You're welcome. :)

No,I don't believe Transaction1134H016K being hidden would be the problem,since if it is,your program should still be able to open it.
If you've reversed showing hidden files,please go here to temporarily unhide them once again:
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/#win7
Please click your start button,then type,or copy and paste in Transaction1134H016K
If the file appears in your start menu,rightclick it and select Open file location.After the file location opens,could you highlight the text in the address bar above,then right click and select Copy.Please paste it here in your reply.

When I typed in the link, this is what I got:

Page Not Found / Error!
404 ERROR: Page Not Found!

The requested page http://www.bleepingcomputer.comwww.bleepingcomputer.com/tuto...-windows// could not be found on this server.

When I typed in the file Transactions1134H016K after opening the start button, I got the message: "Iten not found"


I think you may be correct that the file has been corrupted by the virus, and not just simply hidden.

Zenobia
2012-01-20, 09:28
That's possible,but I was also wondering if it was possible the file may have been moved to another location,and that might be the cause of the problems opening your program.

Try clicking on the link,it should take you right there.
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/#win7
You only need to do the above again if you went in and reversed showing hidden files after you did it before,though. :)

Now,click the start button and type,or copy and paste in the file
File Transaction1134H016K
If it doesn't show up,try clicking Search Everywhere.
If the file appears,rightclick it and select Open file location.After the file location opens,could you highlight the text in the address bar above,then right click and select Copy.Please paste it here in your reply.

gnowgnow
2012-01-21, 09:22
That's possible,but I was also wondering if it was possible the file may have been moved to another location,and that might be the cause of the problems opening your program.

Try clicking on the link,it should take you right there.
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/#win7
You only need to do the above again if you went in and reversed showing hidden files after you did it before,though. :)

Now,click the start button and type,or copy and paste in the file
File Transaction1134H016K
If it doesn't show up,try clicking Search Everywhere.
If the file appears,rightclick it and select Open file location.After the file location opens,could you highlight the text in the address bar above,then right click and select Copy.Please paste it here in your reply.

I clicked on the link and performed all the steps to unhide the file but didn't find it using the search function in Startup. Where do I find the Search Everywhere button?

Zenobia
2012-01-22, 07:46
Search Everywhere usually comes up on the start menu in Vista if the file being searched for isn't found.After looking around,I think Windows 7 users do not have that option in their start menu.Sorry about that. :)

Some programs have an option to repair them in add/remove programs.Does the software to adjust your hearing aid have that option in add/remove programs?
It could be worth a try,to see if you can get the program working again:
http://windows.microsoft.com/en-US/windows7/Uninstall-or-change-a-program

gnowgnow
2012-01-23, 08:24
Search Everywhere usually comes up on the start menu in Vista if the file being searched for isn't found.After looking around,I think Windows 7 users do not have that option in their start menu.Sorry about that. :)

Some programs have an option to repair them in add/remove programs.Does the software to adjust your hearing aid have that option in add/remove programs?
It could be worth a try,to see if you can get the program working again:
http://windows.microsoft.com/en-US/windows7/Uninstall-or-change-a-program

Already tried clicking in Uninstall Program to see if it has the repair feature, but it doesn't. May have to get the CD from my audiologist to reinstall the program, which I was hoping to avoid.

Zenobia
2012-01-24, 04:05
Already tried clicking in Uninstall Program to see if it has the repair feature, but it doesn't. May have to get the CD from my audiologist to reinstall the program, which I was hoping to avoid.
Yes,that would probably be the best bet,in my opinion. :)

Two more things,before I forget.
1.
Using the link you gave me, I was able to see all the data files. The application program lost the links to these files but by double-clinking on these files I was able to load them into the application program such as PowerPoint or Word. Thanks a heap.
If these files still have the hidden attribute,you won't be able to view them once you rehide the files on your computer.
If you've reversed showing hidden files,please go here to temporarily unhide them once again:
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/#win7
Could you return to where these files are located,rightclick them,then select Properties.Look under the General tab.Can you let me know if Hidden is checkmarked?Also,is the word Hidden and the checkbox next to it partially transparent?

2.Since removing the original infection,has everything been okay with your computer?There are no signs of the original infection remaining?(for example,your browser being redirected to unwanted sites,etc.?)

gnowgnow
2012-01-26, 22:46
Yes,that would probably be the best bet,in my opinion. :)

Two more things,before I forget.
1.
If these files still have the hidden attribute,you won't be able to view them once you rehide the files on your computer.
If you've reversed showing hidden files,please go here to temporarily unhide them once again:
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/#win7
Could you return to where these files are located,rightclick them,then select Properties.Look under the General tab.Can you let me know if Hidden is checkmarked?Also,is the word Hidden and the checkbox next to it partially transparent?

2.Since removing the original infection,has everything been okay with your computer?There are no signs of the original infection remaining?(for example,your browser being redirected to unwanted sites,etc.?)

Thanks for following up on this matter. I've turned the hide off the files.

An unrelated subject. In downloading Malwarebytes and Hot Virtual Keyboard, a program called Aro2011 was downloaded into my computer. It scanned my system and flagged me that over 1000 errors were found in my registry. To rectify these errors I've to purchase the upgraded version. With that many registry errors my system would be slowed to a crawl, but I didn't detect any slowdown. I've TuneUp installed and it didn't warn me or any system problems. Do you think Aro2011 is a scam?

Again, thanks for all your help.

Zenobia
2012-01-27, 06:51
Thanks for following up on this matter. I've turned the hide off the files. Good,glad to hear it was sorted. :bigthumb:

I'm not familiar with the Aro2011 program.From reading about the program online,I don't see it being mentioned as a scam or malware.
It does appear to be a registry cleaner,though.Please see here about those:
http://forums.spybot.info/showthread.php?t=30038
In my own opinion,it's probably not needed.
If you decide you'd like to uninstall it,click Start,type appwiz.cpl,doubleclick appwiz.cpl,and you should be able to uninstall it from add/remove programs.

Did you end up installing Malwarebytes and Hot Virtual Keyboard?When looking for Aro2011,I saw that there was a sponsored download link on one of the popular download sites,and some people accidentally ended up downloading Aro2011 by mistake,and didn't end up with the original program they intended to get. :)

gnowgnow
2012-01-28, 21:22
Good,glad to hear it was sorted. :bigthumb:

I'm not familiar with the Aro2011 program.From reading about the program online,I don't see it being mentioned as a scam or malware.
It does appear to be a registry cleaner,though.Please see here about those:
http://forums.spybot.info/showthread.php?t=30038
In my own opinion,it's probably not needed.
If you decide you'd like to uninstall it,click Start,type appwiz.cpl,doubleclick appwiz.cpl,and you should be able to uninstall it from add/remove programs.

Did you end up installing Malwarebytes and Hot Virtual Keyboard?When looking for Aro2011,I saw that there was a sponsored download link on one of the popular download sites,and some people accidentally ended up downloading Aro2011 by mistake,and didn't end up with the original program they intended to get. :)

Thanks for the link that provides excellent information on registry cleaning.

Thanks for explaining how the ARO2011 got installed in my computer. I thought a malware put it there.

I've installed both Malwarebytes and Hot Virtual Keboard, but not sure if the latter is doing any good. I'm still seeking information and may uninstall it.

Zenobia
2012-01-29, 07:05
Hot Virtual Keyboard is a program that basically improves on windows own on-screen keyboard,but it isn't an anti-malware program.
When it was recommended for you to install it,what were some of the reasons given for doing so?
I'm not familiar with hot virtual keyboard,but if it was recommended to help prevent anyone seeing what is being typed on your keyboard,then this article about using on-screen keyboards in general might be helpful. :)
http://ask-leo.com/will_using_an_on_screen_keyboard_stop_keyboard_loggers_and_hackers.html

gnowgnow
2012-01-30, 22:32
Hot Virtual Keyboard is a program that basically improves on windows own on-screen keyboard,but it isn't an anti-malware program.
When it was recommended for you to install it,what were some of the reasons given for doing so?
I'm not familiar with hot virtual keyboard,but if it was recommended to help prevent anyone seeing what is being typed on your keyboard,then this article about using on-screen keyboards in general might be helpful. :)
http://ask-leo.com/will_using_an_on_screen_keyboard_stop_keyboard_loggers_and_hackers.html

This is what the person recommending Hot Virtual Keyboard wrote:

"Keylogger is a software that performs the action of tracking (or logging) the keys struck on a keyboard, typically in a covert manner so that the person using the keyboard is unaware that their actions are being monitored.

Keylogger applications capture a user's sensitive information. User accounts and banking information have the most appeal to the cyber-criminal. They can discover your address, telephone number and more. Logging of keystrokes is usually ONLY ONE feature of this type of surveillance software. Some keyloggers have the ability to record VoIP (Voice over Internet) telephone calls, take pictures of the computer screen and even control the Webcam.".

Your link to the article on keylogger is very interesting and informative. Thanks. I think I'm going to uninstall Hot Virtual Keyboard.

Zenobia
2012-01-31, 05:57
You're welcome.
The person recommending Hot Virtual Keyboard does have a valid point,it could help prevent some keystroke logging(though not all),which does make the program useful,so whether to uninstall or not is up to you. :)

gnowgnow
2012-02-02, 02:33
You're welcome.
The person recommending Hot Virtual Keyboard does have a valid point,it could help prevent some keystroke logging(though not all),which does make the program useful,so whether to uninstall or not is up to you. :)


I value your opinion, so I'll continue evaluatiing the Hot Virtual Keyboard before deciding to keep it or uninstall it.

Zenobia
2012-02-02, 17:36
It's up to you.You could keep it as an extra safety precaution when using some sites if you wanted to,such as your banking site,if you use one,etc.But it would be troublesome to use all the time,nor should it be necessary,unless somebody suspected they might have a keylogger on their system.

Hope things are a bit better with your computer.
You did great. :)

gnowgnow
2012-02-17, 19:51
Yes,that would probably be the best bet,in my opinion. :)

Two more things,before I forget.
1.
If these files still have the hidden attribute,you won't be able to view them once you rehide the files on your computer.
If you've reversed showing hidden files,please go here to temporarily unhide them once again:
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/#win7
Could you return to where these files are located,rightclick them,then select Properties.Look under the General tab.Can you let me know if Hidden is checkmarked?Also,is the word Hidden and the checkbox next to it partially transparent?

2.Since removing the original infection,has everything been okay with your computer?There are no signs of the original infection remaining?(for example,your browser being redirected to unwanted sites,etc.?)

My audiologist had to consult with his IT person about the error message when I tried fine tuning my hearing aid with the software. This computer expert said I had to clean my hard disk. He said it shouldn't be hard to do if I had backed up my system with Windows 7 backup function. It simply would be reformating the hard disk and then restore all the application programs and data back onto the disk. I think he was oversimplying the procedure. Would you have time to step me through this process?

Zenobia
2012-02-17, 21:48
Unfortunately,no,not at the moment.I'll be working the next couple of days,which means I'll be unavailable for long amounts of time.
Also,I don't have Windows 7,I still use Windows Vista,so I've never actually reinstalled and restored backups with the Windows 7 operating system.

What I can do is show you some links from Microsoft that should help with the procedure. :)
http://windows.microsoft.com/en-CA/windows7/Installing-and-reinstalling-Windows-7
The "Using the Custom installation option and formatting the hard disk" section should cover the reformatting,if that is the best option for you.

And this is a page detailing how to restore files from a backup:
http://windows.microsoft.com/en-CA/windows7/Restore-files-from-a-backup

Please let me know how it goes. :)

gnowgnow
2012-02-20, 03:16
Unfortunately,no,not at the moment.I'll be working the next couple of days,which means I'll be unavailable for long amounts of time.
Also,I don't have Windows 7,I still use Windows Vista,so I've never actually reinstalled and restored backups with the Windows 7 operating system.

What I can do is show you some links from Microsoft that should help with the procedure. :)
http://windows.microsoft.com/en-CA/windows7/Installing-and-reinstalling-Windows-7
The "Using the Custom installation option and formatting the hard disk" section should cover the reformatting,if that is the best option for you.

And this is a page detailing how to restore files from a backup:
http://windows.microsoft.com/en-CA/windows7/Restore-files-from-a-backup

Please let me know how it goes. :)
Thanks for those links. Will let you know the outcome.

Zenobia
2012-02-20, 07:33
You're welcome.Hope everything goes well. :)

gnowgnow
2012-03-05, 08:29
Thanks for those links. Will let you know the outcome.

Reformatting the hard disk was easy enough. Popped in recover disk and typed format C at cmd. However, after restoring files on disk C, I still got the error message when I run the program. I think when I backed up C I must have also got the error file transferred. This is frustrating and I'm at a point where I think I need to bring my laptop to a professional for cleansing.

Zenobia
2012-03-06, 07:15
I can certainly understand your feeling frustrated.You've done a lot to get your computer in working order again,and most of it was not easy fixes.

and I'm at a point where I think I need to bring my laptop to a professional for cleansing.
Just to be on the safe side:Are you having any signs of the original infection?You shouldn`t,after formatting drive C:,unless some of it was accidently restored from backup.

If you are still getting the same error message,perhaps the backup you restored of the program was from a time when the program was already damaged.Would it be possible for you to ask your audiologist about the best way to proceed?I was thinking perhaps a fresh install of the program would be better than restoring from backup.Your audiologist,or your audiologist`s IT person would probably know if that is advisable,being familiar with the program.

How has your computer been overall?Has it been working well,other than the error message from the software to adjust your hearing aid? :)

gnowgnow
2012-03-07, 04:23
I can certainly understand your feeling frustrated.You've done a lot to get your computer in working order again,and most of it was not easy fixes.

Just to be on the safe side:Are you having any signs of the original infection?You shouldn`t,after formatting drive C:,unless some of it was accidently restored from backup.

If you are still getting the same error message,perhaps the backup you restored of the program was from a time when the program was already damaged.Would it be possible for you to ask your audiologist about the best way to proceed?I was thinking perhaps a fresh install of the program would be better than restoring from backup.Your audiologist,or your audiologist`s IT person would probably know if that is advisable,being familiar with the program.

How has your computer been overall?Has it been working well,other than the error message from the software to adjust your hearing aid? :)

My computer seems to be working fine. Thanks to you, all the application programs are working well.

I've uninstalled and reinstalled the hearing aid program three times now, and the error message still appears. Could the viruses that attacked my computer have damage that portion of my hard disk where the hearing aid program resides? Perhaps a remnant of the viruse is still in my machine, hidden from Spybot, Malwarebyte and Security Essentials. Not sure what to think.

gnowgnow
2012-03-07, 10:14
My computer seems to be working fine. Thanks to you, all the application programs are working well.

I've uninstalled and reinstalled the hearing aid program three times now, and the error message still appears. Could the viruses that attacked my computer have damage that portion of my hard disk where the hearing aid program resides? Perhaps a remnant of the viruse is still in my machine, hidden from Spybot, Malwarebyte and Security Essentials. Not sure what to think.

I think I know what is happening. After I unistalled the program, a data file is still left behind in my computer. I just realized this because after I reinstalled the program, I didn't need to reinput a set of personal data into the program. After I wiped clean my hard disk and restored all the files, that file that caused the malfunction of the program was placed back onto the hard disk.

Is there a way to wipe out all the pieces connected to this hearing aid program when I use the uninstall function in Windows 7?

Zenobia
2012-03-07, 20:30
Yes,if there are pieces of the program left behind after you uninstall,you could probably remove those manually after uninstalling the program.However,I suggest talking to your audiologist,to see what he thinks of that idea,first. :)

gnowgnow
2012-03-08, 05:25
Yes,if there are pieces of the program left behind after you uninstall,you could probably remove those manually after uninstalling the program.However,I suggest talking to your audiologist,to see what he thinks of that idea,first. :)

There lies the problem. Locating those file(s) causing the trouble. The program ran fine when I installed it in a friend's laptop, but I couldn't find the difference in the number of files/folder between those shown in my friend's machine and mine. All the file names are also the same. Very baffling!

Went to Best Buy to see if the experts there could recommend a software to completely uninstall the program. I was told that I need to reformat the hard disk. I told them I already done that and descrbed what I did. They said it sounded correct but suggested that I let their experts take a look for a $85 fee. Not sure I want to pay that until I exhausted all my attempts.

Zenobia
2012-03-09, 02:46
After you uninstall the program,you could look in Program Files,(probably located at C:\Program Files),and see if there was a folder left behind by the program.If so,delete it.
Then,show hidden files once again:
http://windows.microsoft.com/en-US/windows7/Show-hidden-files
Then go to Program Data(probably located at C:\ProgramData),and if a folder was left behind by the program,you can delete it.
I suggest leaving both folders in the recycle bin (if found) for a little while,in case they're needed later.
I still suggest talking to your audiologist first,just to be on the safe side. :)

gnowgnow
2012-03-10, 06:49
After you uninstall the program,you could look in Program Files,(probably located at C:\Program Files),and see if there was a folder left behind by the program.If so,delete it.
Then,show hidden files once again:
http://windows.microsoft.com/en-US/windows7/Show-hidden-files
Then go to Program Data(probably located at C:\ProgramData),and if a folder was left behind by the program,you can delete it.
I suggest leaving both folders in the recycle bin (if found) for a little while,in case they're needed later.
I still suggest talking to your audiologist first,just to be on the safe side. :)

Are you good or what!!! Following your set of instructions, I opened ProgramData and found a folder with the name of my hearing aid program but no files in it . I turned the unhide function on and, there it was, a file in the folder. I immediately deleted the file, reinstalled the program and started it. It asked for input of my personal data and then it ran without being blocked by the offending message. Thank you, thank you.

On another subject. Yesterday I received a malicious email, with Subject: Help, which tried to solicit money from me for a purported relative of mine in financial trouble while visiting a foreign country. Unfortunately I opened the email and it took over a minute of continuous hitting the delete button to remove the email. Then I had trouble closing my email box and took over two to three minutes of clicking on the "Sign Off" button to get it shut down. I rebooted my machine and it took a long time for it to come back on. I immediately ran MS Security Essentials, Malwarebytes and Spybot sequentially after each has finished checking my system. I encountered no problem updating MS Security Essentials and Malwarebytes before starting their scam functions. Updating Spybot took a little more time as initially I got the message that the server was down. After unloading and loading Spybot
several times, I got it to update. The first two software said my system was clean. Spybot flagged out four malwares which I immediately removed. However, my system was still running very slowly. I rebooted, but again it took longer than usual to come back on and the response was very slow. I ran McAfee Stinger from a thumb drive and it flagged out two very destructive viruses -- FalseAlert and TrojanC. These are the two viruses that started all my problems several weeks ago. After removing these two viruses, my system seems to be running smoothly.

This sequence of events is creating concerns in me and a sense of insecurity. Why didn't the three antivirus software that I initially used found the destructive viruses? FlaseAlert and Trojan have been around for awhile so their signatures should already been in the database of those software programs.

Zenobia
2012-03-10, 08:36
Good,glad your program is working. :)

The reasons the first three programs might not have picked up on what Stinger found vary.It could have been a false positive on Stinger's part,or perhaps Stinger did pick up on infections which the others missed.If it did detect and remove FakeAlert and a trojan,that's good.It's a good tool to check for the problems it's designed to remove,when things have gone pear-shaped.(You can see what viruses/malware it will search for by pressing the "List Viruses" button.)Just remember,it's not a replacement for full antivirus software,as is stated here on this page:
http://www.mcafee.com/us/downloads/free-tools/stinger.aspx

If you don't mind,I'd like to have a peek at what Spybot removed.Go into Spybot > Mode > Advanced mode > Tools > View Reports > View Previous reports.Look for the Checks.yymmdd-hhmm or Fixes.yymmdd-hhmm file from the scan you did yesterday.Doubleclick the file,and it should open up in the Spybot window.Rightclick somewhere in that window,and select "Select All".Then rightclick again,select Copy,then Paste the logfile here in a reply.

gnowgnow
2012-03-12, 04:48
Good,glad your program is working. :)

The reasons the first three programs might not have picked up on what Stinger found vary.It could have been a false positive on Stinger's part,or perhaps Stinger did pick up on infections which the others missed.If it did detect and remove FakeAlert and a trojan,that's good.It's a good tool to check for the problems it's designed to remove,when things have gone pear-shaped.(You can see what viruses/malware it will search for by pressing the "List Viruses" button.)Just remember,it's not a replacement for full antivirus software,as is stated here on this page:
http://www.mcafee.com/us/downloads/free-tools/stinger.aspx

If you don't mind,I'd like to have a peek at what Spybot removed.Go into Spybot > Mode > Advanced mode > Tools > View Reports > View Previous reports.Look for the Checks.yymmdd-hhmm or Fixes.yymmdd-hhmm file from the scan you did yesterday.Doubleclick the file,and it should open up in the Spybot window.Rightclick somewhere in that window,and select "Select All".Then rightclick again,select Copy,then Paste the logfile here in a reply.

I'm having problems with my WiFi. I'm sending this message on my iPad. Once get my WiFi up, I'll send the information.

Zenobia
2012-03-12, 05:06
Ok,thanks. :)

gnowgnow
2012-03-14, 07:40
Ok,thanks. :)

Here is the information:

--- Report generated: 2012-03-08 23:06 ---

DoubleClick: Tracking cookie (Internet Explorer: GnowGnow) (Cookie, fixed)


Right Media: Tracking cookie (Internet Explorer: GnowGnow) (Cookie, fixed)


Statcounter: Tracking cookie (Internet Explorer: GnowGnow) (Cookie, fixed)



--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2012-01-08 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2012-01-16 Includes\Adware.sbi (*)
2012-02-28 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-11-29 Includes\DialerC.sbi (*)
2012-01-31 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-10-04 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2012-01-24 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2012-01-10 Includes\Malware.sbi (*)
2012-03-06 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2012-02-28 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2011-02-24 Includes\Security.sbi (*)
2011-12-13 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2012-01-17 Includes\Spyware.sbi (*)
2012-02-28 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2011-09-27 Includes\Trojans.sbi (*)
2012-03-06 Includes\TrojansC-02.sbi (*)
2012-02-29 Includes\TrojansC-03.sbi (*)
2012-02-24 Includes\TrojansC-04.sbi (*)
2012-03-05 Includes\TrojansC-05.sbi (*)
2012-03-06 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Zenobia
2012-03-15, 03:30
Thanks for posting your report. :)
Those were tracking cookies which were removed.
Is everything working okay with your computer now?No problems?

gnowgnow
2012-03-15, 07:07
Ok,thanks. :)

Here's the information:

--- Report generated: 2012-03-08 23:06 ---

DoubleClick: Tracking cookie (Internet Explorer: gnowgnow) (Cookie, fixed)


Right Media: Tracking cookie (Internet Explorer: gnowgnow) (Cookie, fixed)


Statcounter: Tracking cookie (Internet Explorer: gnowgnow) (Cookie, fixed)



--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2012-01-08 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2012-01-16 Includes\Adware.sbi (*)
2012-02-28 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-11-29 Includes\DialerC.sbi (*)
2012-01-31 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-10-04 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2012-01-24 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2012-01-10 Includes\Malware.sbi (*)
2012-03-06 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2012-02-28 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2011-02-24 Includes\Security.sbi (*)
2011-12-13 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2012-01-17 Includes\Spyware.sbi (*)
2012-02-28 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2011-09-27 Includes\Trojans.sbi (*)
2012-03-06 Includes\TrojansC-02.sbi (*)
2012-02-29 Includes\TrojansC-03.sbi (*)
2012-02-24 Includes\TrojansC-04.sbi (*)
2012-03-05 Includes\TrojansC-05.sbi (*)
2012-03-06 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

gnowgnow
2012-03-15, 20:16
Thanks for posting your report. :)
Those were tracking cookies which were removed.
Is everything working okay with your computer now?No problems?

So far everything seems to be working fine, but I still feel uneasy that the cause of the slowdown wasn't detected by the antivirus programs installed on my computer.

I really want to thank you for your help.

Zenobia
2012-03-15, 23:47
You're welcome. :)

Did you open any attachments or anything when you opened the email?
http://ask-leo.com/can_just_opening_an_email_download_both_viruses_and_spyware.html


So far everything seems to be working fine, but I still feel uneasy that the cause of the slowdown wasn't detected by the antivirus programs installed on my computer.
There's a article here that covers why sometimes an antivirus or antimalware program will miss an infection,etc.:
http://ask-leo.com/why_dont_antimalware_tools_work_better.html

Also,Microsoft Security Essentials is an antivirus program,but Malwarebytes and Spybot are not,they fall more into the spyware detecting/removing category.I want to explain the difference,to avoid any confusion. :)

This article has some tips that may help to avoid being infected by using prevention:
http://forums.spybot.info/showthread.php?t=279

gnowgnow
2012-03-16, 07:36
You're welcome. :)

Did you open any attachments or anything when you opened the email?
http://ask-leo.com/can_just_opening_an_email_download_both_viruses_and_spyware.html


There's a article here that covers why sometimes an antivirus or antimalware program will miss an infection,etc.:
http://ask-leo.com/why_dont_antimalware_tools_work_better.html

Also,Microsoft Security Essentials is an antivirus program,but Malwarebytes and Spybot are not,they fall more into the spyware detecting/removing category.I want to explain the difference,to avoid any confusion. :)

This article has some tips that may help to avoid being infected by using prevention:
http://forums.spybot.info/showthread.php?t=279

No, I didn't open any attachments. After I opened the email and realized it was one of those scams, I quickly tried to close and delete it, but it just froze for a minute while I hit the delete button. After I deleted that email my system slowed down drastically.

Thanks for those very informative links. They're very helpful.

Zenobia
2012-03-16, 18:24
You're welcome. :)