Page 15 of 16 FirstFirst ... 5111213141516 LastLast
Results 141 to 150 of 156

Thread: Please help get rid of smitfraud remnants

  1. #141
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    Ok. That's the correct version. I can't remember, did you finally find the dllcache folder?

  2. #142
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    I have to say that because smitfraudfix does fix temporarily I have doubts. But your other symptoms are too odd. They don't match. So I really think you may be better served if you remove Service Pack2 and then use your install CD, if it is a regular install CD, and not a restore CD to do a windows Repair install, be sure your Anti Virus and Firewalls are in good working order
    and then get the windows updates you'll need to reapply.


    BUT Before you do that, uninstall Internet Explorer 7. If you attempt a repair install while Internet Explorer 7 is present, it may cause your system to become extremely unstable. Do not attempt a Repair install until IE 7 has been successfully uninstalled and you have restarted after doing so.


    Further Help for Repair install here:

    http://www.michaelstevenstech.com/XPrepairinstall.htm
    Last edited by Mosaic1; 2007-01-24 at 14:47.

  3. #143
    Member
    Join Date
    Dec 2006
    Posts
    81

    Default

    can't u think of anything else?

    thx

  4. #144
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    I'm sorry. I have read your logs. They show no restrictions. And they should. IF you took the regmon logs for rundll32.exe when display properties was broken, they should have shown something. But no. However, snitfraudfix fixed something. And that's a mystery.

    Plus, not being abke to register themeui.dll occasionally and havig a white list in Display Properties\desktop

    That doesn't follow. A restriction dims that out. I believe you disabled Active Desktop using a vbs you downloaded. That also fixed this for a short time. But it came back.

    We have gone in circles.

    A repair install is not a format. Your personal files will still be there when you finish. It is a bit of work, but I can't see much hope in keeping this up.

  5. #145
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    WE can fool around and remove some registry keys & values which will restore themselves clean without the previous information. In the event of some kind of registry corruption, that would be a last ditch effort.

    I am too tired today to go in and do that. If you want to wait another day, we can do that.


    Are you able to open dispaly properties at this point?

  6. #146
    Member
    Join Date
    Dec 2006
    Posts
    81

    Question

    Yes I want to try.

    Since we did a tweak one of the times, I have always been able to register themeui.dll successfully.

    I can open display properties but I cannot change wallpaper or theme. It's kind of strange that smitfraud.fix is able to sort this out until the next reboot.

    Thx

    Mills

  7. #147
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    I am not sure this is helpful. A repair install is really the best thing. I am not going to be able to continue this much longer, and neither should you.


    Download and install subinacl from:
    http://download.microsoft.com/downlo...7/subinacl.msi

    Install it. It will auto install to this location:

    C:\Program Files\Windows Resource Kits\Tools

    Next. Download and save the zip attachment.

    Extract the file it contains to this folder:
    C:\Program Files\Windows Resource Kits\Tools



    So now you'll have
    C:\Program Files\Windows Resource Kits\Tools\reset.cmd


    Double click on reset.cmd to run it. The command window will open and there will be a lot of activity. This is a labor intense operation. Be offline and go for coffee while it runs. Let it do its job of resetting default permissions. It will take a while. Then restart the computer.

    See if anything has improved. If not, run Smitfraudfix and restart again.

    What's the situation now?

  8. #148
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    Millslord,

    Did you try it and if so, any results?

    Mo

  9. #149
    Member
    Join Date
    Dec 2006
    Posts
    81

    Default

    Dear Mosaic,

    The same crap as always.

    Thx

    Mills

  10. #150
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    I think we have to say enough then. Either live with it and whatever other damage may have been done, or uninstall IE7 and restart the system.

    Do your repair install.


    BTW if you uninstall Service Pack 2 & IE 7 does this problem persist?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •