Advertisement

There's no such thing as a stupid question, but they're the easiest to answer.
Login
Search

Advertisement

All Other Software All Other Software
Search Search
Search for:
Tech Support Guy > > >

Solved: Microsoft Office 2000 Registration Wizard Problem


(!)

flavallee's Avatar
flavallee   (Frank) flavallee is offline flavallee is a Trusted Advisor with special permissions. flavallee has a Profile Picture
Computer Specs
Trusted Advisor with 58,438 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
29-Aug-2011, 03:26 PM #16
If your computer is infested with malware and spyware and other problems, we have no way of knowing that at this time.

Use the links that I provided in post #8 to download and install them.

After that's done and the computer has been restarted, follow these instructions carefully:

----------------------------------------------------------

Start Malwarebytes Anti-Malware.

Click "Updates(tab) - Check for Updates".

When the definition files have updated, click "OK".

Click "Scanner(tab) - Perform quick scan - Scan".

If infections or problems are found during the scan, the number of them will be highlighted in red.

When the scan is finished, click "Show Results".

Make sure that EVERYTHING is selected, then click "Remove Selected".

If you're prompted to restart to finish the removal process, click "Yes".

Start Malwarebytes Anti-Malware again.

Click "Logs"(tab).

Highlight the scan log entry, then click "Open".

When the scan log appears in Notepad, copy-and-paste it here.

----------------------------------------------------------

Start SUPERAntiSpyware.

Click "Check for Updates".

When the definition files have updated, click "Close".

Select the Quick Scan option, then click "Scan your Computer".

If infections or problems are found during the scan, a list will appear and the number of them will be highlighted in red.

When the scan is finished and the scan summary window appears, click "Continue".

Make sure that EVERYTHING in the list is selected, then click "Remove Threats".

Click "OK - Finish".

If you're prompted to restart to finish the removal process, do so.

Start SUPERAntiSpyware again.

Click "View Scan Logs".

Highlight the scan log entry, then click "View Selected Log".

When the scan log appears in Notepad, copy-and-paste it here.

----------------------------------------------------------
Transformer Man's Avatar
Transformer Man Transformer Man is offline
Computer Specs
Member with 59 posts.
THREAD STARTER
 
Join Date: Jan 2008
Experience: Intermediate
02-Sep-2011, 10:27 PM #17
Sorry to take so long, but have been busy. Here is the Malware log. I will get the other log up once I complete the scan.

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7640

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

9/2/2011 10:22:38 PM
mbam-log-2011-09-02 (22-22-38).txt

Scan type: Quick scan
Objects scanned: 176167
Time elapsed: 8 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 22
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 13
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B1 8EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2556 0540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC2 01FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF0 5104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\programdata\secure solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\programdata\secure solutions\antispyware 2008 xp (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\programdata\secure solutions\antispyware 2008 xp\BASE (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\programdata\secure solutions\antispyware 2008 xp\DELETED (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\programdata\secure solutions\antispyware 2008 xp\LOG (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\programdata\secure solutions\antispyware 2008 xp\SAVED (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
c:\Users\jandhoney\local settings\application data\windows server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
c:\programdata\secure solutions\antispyware 2008 xp\LOG\20080807142858252.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\programdata\secure solutions\antispyware 2008 xp\LOG\20080807235601930.log (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Transformer Man's Avatar
Transformer Man Transformer Man is offline
Computer Specs
Member with 59 posts.
THREAD STARTER
 
Join Date: Jan 2008
Experience: Intermediate
02-Sep-2011, 10:59 PM #18
Here is the Superantispyware logs:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/02/2011 at 10:47 PM

Application Version : 5.0.1118

Core Rules Database Version : 7644
Trace Rules Database Version: 5456

Scan type : Quick Scan
Total Scan Time : 00:17:58

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User (Administrator User)

Memory items scanned : 773
Memory threats detected : 0
Registry items scanned : 29243
Registry threats detected : 10
File items scanned : 7725
File threats detected : 8

Adware.MyWebSearch/FunWebProducts
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version

Adware.Tracking Cookie
C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@a1.i nterclick[2].txt
C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@adin terax[2].txt
C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@imrw orldwide[2].txt
C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@inte rclick[2].txt
C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@invi temedia[1].txt
C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@mywe bsearch[2].txt
C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@upda tes.liquiddigitalmedia[2].txt
C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@www. windowsmedia[2].txt

Second Log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/31/2011 at 11:40 PM

Application Version : 5.0.1118

Core Rules Database Version : 7624
Trace Rules Database Version: 5436

Scan type : Quick Scan
Total Scan Time : 00:00:06

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User (Administrator User)

Memory items scanned : 0
Memory threats detected : 0
Registry items scanned : 0
Registry threats detected : 0
File items scanned : 1
File threats detected : 0
Transformer Man's Avatar
Transformer Man Transformer Man is offline
Computer Specs
Member with 59 posts.
THREAD STARTER
 
Join Date: Jan 2008
Experience: Intermediate
02-Sep-2011, 11:04 PM #19
I see on my start up menu on the bottom right side of the computer something called "Blocked start up programs."
Is this where I should block Windows Defender and what is the best way to complete this. Thank you.
flavallee's Avatar
flavallee   (Frank) flavallee is offline flavallee is a Trusted Advisor with special permissions. flavallee has a Profile Picture
Computer Specs
Trusted Advisor with 58,438 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
03-Sep-2011, 08:06 AM #20
According to the MBAM and SAS scan logs, your computer had a MyWebSearch and rogue software infestation.

I suggest you run a quick scan with them at least once a week (after you first update the definition files), then remove everything they find.

Doing that will insure that you keep "nasties" out of your computer.

--------------------------------------------------------

Close all open windows first, then start HiJackThis and click "Do a system scan and save a log file".

Save the new log that appears, then submit it here.

-------------------------------------------------------
Transformer Man's Avatar
Transformer Man Transformer Man is offline
Computer Specs
Member with 59 posts.
THREAD STARTER
 
Join Date: Jan 2008
Experience: Intermediate
03-Sep-2011, 09:32 AM #21
I will do as recommended and report back, however, I still cannot use my Microsoft Office documents as the register box comes up. I am using them via OpenOffice.
flavallee's Avatar
flavallee   (Frank) flavallee is offline flavallee is a Trusted Advisor with special permissions. flavallee has a Profile Picture
Computer Specs
Trusted Advisor with 58,438 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
03-Sep-2011, 09:35 AM #22
I'm assisting you with doing maintenance in your computer, but I really don't know how to resolve the Microsoft 2000 registration wizard problem.

--------------------------------------------------------
Triple6's Avatar
Triple6   (Rob) Triple6 is offline
Computer Specs
Moderator with 43,225 posts.
 
Join Date: Dec 2002
Location: Canada
Experience: Advanced
03-Sep-2011, 10:50 AM #23
You may want to open an Office program by right clicking on any Office program and choosing "Run as Administrator", going through the wizard once, then opening an Office program normally.

Or try this fix: http://support.microsoft.com/kb/884202

Or this one: http://support.microsoft.com/kb/818798
__________________
Microsoft MVP - Windows Desktop Experience
flavallee's Avatar
flavallee   (Frank) flavallee is offline flavallee is a Trusted Advisor with special permissions. flavallee has a Profile Picture
Computer Specs
Trusted Advisor with 58,438 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
03-Sep-2011, 10:53 AM #24
Triple6:

Thanks for the assist.

-------------------------------------------------------
Transformer Man's Avatar
Transformer Man Transformer Man is offline
Computer Specs
Member with 59 posts.
THREAD STARTER
 
Join Date: Jan 2008
Experience: Intermediate
03-Sep-2011, 10:03 PM #25
I tried to run HiJackThis and cannot get it to run like the first time. Any suggestions?
Transformer Man's Avatar
Transformer Man Transformer Man is offline
Computer Specs
Member with 59 posts.
THREAD STARTER
 
Join Date: Jan 2008
Experience: Intermediate
03-Sep-2011, 10:07 PM #26
Thank you. I will try this and see how it works. Much appreciated.
flavallee's Avatar
flavallee   (Frank) flavallee is offline flavallee is a Trusted Advisor with special permissions. flavallee has a Profile Picture
Computer Specs
Trusted Advisor with 58,438 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
04-Sep-2011, 09:19 AM #27
Quote:
Originally Posted by Transformer Man View Post
I tried to run HiJackThis and cannot get it to run like the first time. Any suggestions?
Go to Control Panel - User Accounts, then turn off the User Account Control(UAC) feature, then apply the change, then restart the computer.

HiJackThis should work okay now.

-------------------------------------------------------
Transformer Man's Avatar
Transformer Man Transformer Man is offline
Computer Specs
Member with 59 posts.
THREAD STARTER
 
Join Date: Jan 2008
Experience: Intermediate
04-Sep-2011, 09:08 PM #28
Thanks, Flavallee, I have done the above and will re-start the computer later.
Transformer Man's Avatar
Transformer Man Transformer Man is offline
Computer Specs
Member with 59 posts.
THREAD STARTER
 
Join Date: Jan 2008
Experience: Intermediate
04-Sep-2011, 09:09 PM #29
Thank you. I will try this method and see if I can get Microsoft Office to work as in the past.
As Seen On

BBC, Reader's Digest, PC Magazine, Today Show, Money Magazine
WELCOME TO TECH SUPPORT GUY!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.


Tags
2000, microsoft, office, premium, wizard

(clock)
THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


WELCOME
You Are Using: Server ID
Trusted Website Back to the Top ↑