1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: Microsoft Office 2000 Registration Wizard Problem

Discussion in 'All Other Software' started by Transformer Man, Aug 19, 2011.

Thread Status:
Not open for further replies.
Advertisement
  1. flavallee

    flavallee Frank Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    63,629
    If your computer is infested with malware and spyware and other problems, we have no way of knowing that at this time.

    Use the links that I provided in post #8 to download and install them.

    After that's done and the computer has been restarted, follow these instructions carefully:

    ----------------------------------------------------------

    Start Malwarebytes Anti-Malware.

    Click "Updates(tab) - Check for Updates".

    When the definition files have updated, click "OK".

    Click "Scanner(tab) - Perform quick scan - Scan".

    If infections or problems are found during the scan, the number of them will be highlighted in red.

    When the scan is finished, click "Show Results".

    Make sure that EVERYTHING is selected, then click "Remove Selected".

    If you're prompted to restart to finish the removal process, click "Yes".

    Start Malwarebytes Anti-Malware again.

    Click "Logs"(tab).

    Highlight the scan log entry, then click "Open".

    When the scan log appears in Notepad, copy-and-paste it here.

    ----------------------------------------------------------

    Start SUPERAntiSpyware.

    Click "Check for Updates".

    When the definition files have updated, click "Close".

    Select the Quick Scan option, then click "Scan your Computer".

    If infections or problems are found during the scan, a list will appear and the number of them will be highlighted in red.

    When the scan is finished and the scan summary window appears, click "Continue".

    Make sure that EVERYTHING in the list is selected, then click "Remove Threats".

    Click "OK - Finish".

    If you're prompted to restart to finish the removal process, do so.

    Start SUPERAntiSpyware again.

    Click "View Scan Logs".

    Highlight the scan log entry, then click "View Selected Log".

    When the scan log appears in Notepad, copy-and-paste it here.

    ----------------------------------------------------------
     
  2. Transformer Man

    Transformer Man Thread Starter

    Joined:
    Jan 6, 2008
    Messages:
    77
    Sorry to take so long, but have been busy. Here is the Malware log. I will get the other log up once I complete the scan.

    Malwarebytes' Anti-Malware 1.51.1.1800
    www.malwarebytes.org

    Database version: 7640

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 9.0.8112.16421

    9/2/2011 10:22:38 PM
    mbam-log-2011-09-02 (22-22-38).txt

    Scan type: Quick scan
    Objects scanned: 176167
    Time elapsed: 8 minute(s), 17 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 22
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 13
    Files Infected: 4

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    c:\programdata\secure solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\programdata\secure solutions\antispyware 2008 xp (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\programdata\secure solutions\antispyware 2008 xp\BASE (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\programdata\secure solutions\antispyware 2008 xp\DELETED (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\programdata\secure solutions\antispyware 2008 xp\LOG (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\programdata\secure solutions\antispyware 2008 xp\SAVED (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Files Infected:
    c:\Users\jandhoney\local settings\application data\windows server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
    c:\programdata\secure solutions\antispyware 2008 xp\LOG\20080807142858252.log (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\programdata\secure solutions\antispyware 2008 xp\LOG\20080807235601930.log (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
     
  3. Transformer Man

    Transformer Man Thread Starter

    Joined:
    Jan 6, 2008
    Messages:
    77
    Here is the Superantispyware logs:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 09/02/2011 at 10:47 PM

    Application Version : 5.0.1118

    Core Rules Database Version : 7644
    Trace Rules Database Version: 5456

    Scan type : Quick Scan
    Total Scan Time : 00:17:58

    Operating System Information
    Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
    UAC On - Limited User (Administrator User)

    Memory items scanned : 773
    Memory threats detected : 0
    Registry items scanned : 29243
    Registry threats detected : 10
    File items scanned : 7725
    File threats detected : 8

    Adware.MyWebSearch/FunWebProducts
    HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
    HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
    HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
    HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
    HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
    HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
    HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
    HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
    HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
    HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version

    Adware.Tracking Cookie
    C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
    C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@adinterax[2].txt
    C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@imrworldwide[2].txt
    C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@interclick[2].txt
    C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@invitemedia[1].txt
    C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\jandhoney@mywebsearch[2].txt
    C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
    C:\Users\JandHoney\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt

    Second Log:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 08/31/2011 at 11:40 PM

    Application Version : 5.0.1118

    Core Rules Database Version : 7624
    Trace Rules Database Version: 5436

    Scan type : Quick Scan
    Total Scan Time : 00:00:06

    Operating System Information
    Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
    UAC On - Limited User (Administrator User)

    Memory items scanned : 0
    Memory threats detected : 0
    Registry items scanned : 0
    Registry threats detected : 0
    File items scanned : 1
    File threats detected : 0
     
  4. Transformer Man

    Transformer Man Thread Starter

    Joined:
    Jan 6, 2008
    Messages:
    77
    I see on my start up menu on the bottom right side of the computer something called "Blocked start up programs."
    Is this where I should block Windows Defender and what is the best way to complete this. Thank you.
     
  5. flavallee

    flavallee Frank Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    63,629
    According to the MBAM and SAS scan logs, your computer had a MyWebSearch and rogue software infestation.

    I suggest you run a quick scan with them at least once a week (after you first update the definition files), then remove everything they find.

    Doing that will insure that you keep "nasties" out of your computer.

    --------------------------------------------------------

    Close all open windows first, then start HiJackThis and click "Do a system scan and save a log file".

    Save the new log that appears, then submit it here.

    -------------------------------------------------------
     
  6. Transformer Man

    Transformer Man Thread Starter

    Joined:
    Jan 6, 2008
    Messages:
    77
    I will do as recommended and report back, however, I still cannot use my Microsoft Office documents as the register box comes up. I am using them via OpenOffice.
     
  7. flavallee

    flavallee Frank Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    63,629
    I'm assisting you with doing maintenance in your computer, but I really don't know how to resolve the Microsoft 2000 registration wizard problem.

    --------------------------------------------------------
     
  8. Triple6

    Triple6 Rob Moderator

    Joined:
    Dec 26, 2002
    Messages:
    45,577
  9. flavallee

    flavallee Frank Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    63,629
    Triple6:

    Thanks for the assist. (y)

    -------------------------------------------------------
     
  10. Transformer Man

    Transformer Man Thread Starter

    Joined:
    Jan 6, 2008
    Messages:
    77
    I tried to run HiJackThis and cannot get it to run like the first time. Any suggestions?
     
  11. Transformer Man

    Transformer Man Thread Starter

    Joined:
    Jan 6, 2008
    Messages:
    77
    Thank you. I will try this and see how it works. Much appreciated.
     
  12. flavallee

    flavallee Frank Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    63,629
    Go to Control Panel - User Accounts, then turn off the User Account Control(UAC) feature, then apply the change, then restart the computer.

    HiJackThis should work okay now.

    -------------------------------------------------------
     
  13. Transformer Man

    Transformer Man Thread Starter

    Joined:
    Jan 6, 2008
    Messages:
    77
    Thanks, Flavallee, I have done the above and will re-start the computer later.
     
  14. Transformer Man

    Transformer Man Thread Starter

    Joined:
    Jan 6, 2008
    Messages:
    77
    Thank you. I will try this method and see if I can get Microsoft Office to work as in the past.
     
  15. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1013406