1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Annoying pop ups

Discussion in 'Malware and Virus Removal Archive' started by jamon08, 2007/09/08.

  1. 2007/10/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Changing at this point could be a problem for sure. Lets leave it as is for now.

    It looks like there are quite a number of missing directories as well. Not surprizing really ...... they aren't default directories for the Default account that was loaded when the new user was created, but instead would be default directories for a successfully created new account. It may take me some time to sort out just what needs done, so don't expect anything right away. I still want to load the last ntuser.dat file to see what kinds of differences there are between it and the one I sent too.

    While logged onto the fulas account, open regedit and right click HKEY_CURRENT_USER after clicking once to select it, then select Permissions. Is the name Fulas listed? If you select it in the list, is it marked Full Control in the lower pane? Click the Advanced button. On the Permissions tab, where Fulas is listed in the Permissions entries, does it say 'This key and subkeys' in the 'Apply To' column?
     
  2. 2007/10/02
    jamon08

    jamon08 Inactive Thread Starter

    Joined:
    2007/09/08
    Messages:
    85
    Likes Received:
    0
    No

    Jae
     

  3. to hide this advert.

  4. 2007/10/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    What exactly is listed there? And what permissions are applied to each entry?
     
  5. 2007/10/02
    jamon08

    jamon08 Inactive Thread Starter

    Joined:
    2007/09/08
    Messages:
    85
    Likes Received:
    0
    adminisrators(marino\adminisrators) - Full Control and Read
    creator owner - special permissions
    sytem - Full Control and Read
    user (marino\user) - read
     
  6. 2007/10/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    And just to be quite sure, this is while logged on to Fulas? And is the marino account a separate active account? Does the Fulas account still have admin privledges?

    Edit - just realized, marino is the name of your computer. Correct?
     
  7. 2007/10/02
    jamon08

    jamon08 Inactive Thread Starter

    Joined:
    2007/09/08
    Messages:
    85
    Likes Received:
    0
    yup

    It was listed seperatly as above in the privilages frame, not that I have seen that account any where else

    No it didn't so I have given it administrators privilages and this is the new frame

    administrators(marino\administrators) - full control and read
    dad(marino\dad) - full control and read
    restricted - read
    system - full control and read

    I also noticed that whilst fulas account it has administrators rights it has Xp settings and when its limited it reverts back to classic
     
  8. 2007/10/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    OK, we need to get the user Fulas some permissions for it's own user hive. Logon to Fulas and open regedit. Select HKEY_CURRENT_USER then right click and select Permissions. Click Advanced. Select the Owner tab. The current owner should be 'Administrators (marino\Administrators)'. There should also be listed below, the option to change owner to 'Administrators (marino\Administrators)' and 'Fulas (marino\Fulas)'. If the current owner is not known, select the 'Administrators (marino\Administrators)', check the box to replace owner on subcontainers and objects, click Apply then OK. Otherwise, just click OK to close the Advanced Security Settings window.

    Now, back on the Permissions window, click Add. Type Fulas in the 'Enter object names to select' area, then click Check Names. marino\Fulas should appear in the window. Click OK. Back on the Permissions window again, click Fulas (marino\Fulas) to select it, then check the box below to Allow Full Control. Click Apply and OK.

    Exit the registry editor.

    Highlight and copy the contents of the quote box below to a blank notepad. Save it to Local Disk C: as;

    Filename: md.bat
    Save as type: All Files (*.*)

    Reboot to safe mode and logon to the Admin account. Double click C:\md.bat to run it. It will open and close relatively quickly. If prompted to make any directories, or copy any files or directories, answer yes. Reboot back to normal and logon to Fulas again. See how things are and let me know.
     
  9. 2007/10/02
    jamon08

    jamon08 Inactive Thread Starter

    Joined:
    2007/09/08
    Messages:
    85
    Likes Received:
    0
    yup marino is the name of the computer

    everything looks ok, have changed a few setting in both admin and limited and they seem to be saved. Have got internet.
    there was an error when I went to dial up on fulas though " Norton tried to start internet worm protection but was unsuccessful. "

    then once connected got a "norton has encountered an internal program error uninstall and then reinstall norton antivirus "

    everthing else looks cool
     
  10. 2007/10/03
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    That's encouraging!

    I'm not at all surprized about the Norton error. Notice in the md.bat there were user specific symantec files copied? Figured it was worth a shot ;) Try a re-install. You may also need to re-install a few other apps for them to work on that account too, like Flash Player, ArcSoft, PowerDVD, Microsoft Office. Not sure, so you'll just have to check them.

    Ultimately, you will at some point seriously consider a fresh install of Windows. There's obviously some corruption somewhere, whether in the file system permissions or registry permissions, or both. Corruption enough to prevent creating a new user profile.

    Sounds as though we have gone about as far as we can now, which appears may be enough, once AV and such are repaired and working properly on the kids account. Give me an update after today's use, then again after a few days or week or two. ;)

    If I'm not mistaken, your malware problems have been resolved too. May want to check with Geri again and see if he wants or needs anything else, or has further recommendations.
     
  11. 2007/10/03
    jamon08

    jamon08 Inactive Thread Starter

    Joined:
    2007/09/08
    Messages:
    85
    Likes Received:
    0
    Norton has decided to work wthout errors, so I'm going to leave it alone.

    Do I need a disk to do this ? cause I downloaded it off internet.

    I do this with recovery disks aye ? but I should be prepared to lose all saved programmes and data ? is there any way I can save Norton somehow ?


    Today is sweet ! update ya in a couple of weeks, thanx man !!

    How do I get hold of Geri ?

    What does noahdfear mean ?;)
     
  12. 2007/10/03
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yippee! :)
    So long as you have the setup file and the license key, you're good to go.
    Recovery discs, yes. Yes, you will lose everything, and the computer will be in the state in which it came from the factory. Norton setup file (mentioned above) and license key can be saved to external media for re-installing at any time.
    That's awesome! Better than I had hoped for. You're most welcome too. I'm happy I could help. :)

    I'd like to say thank you as well, for your patience and trust. :cool:
    Just post a message to him right in this topic. He's still following along and will respond.
    dfear is for my first and last name; noah is a name I wanted to give my boy, and a play on words as well.

    'no fear' 'noah fear' 'noahdfear'

    :p
     
  13. 2007/10/04
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Jae

    Good work Dave, Thanks.
    You saved yet another person....that must be like about 357,000 now :D

    OK Jae
    You can delete any tools I had you download, if there is any left after Dave got done with you.

    Please look at this link for some preventive recommendations, It could keep you from ending up back here to the Spyware and Virus Removal Forms.
    http://www.windowsbbs.com/showthread.php?t=67958
    and I'm sure you don't want to be back here saying hi to us ;) :rolleyes:

    Surf Safely
    Geri
     
  14. 2007/10/06
    jamon08

    jamon08 Inactive Thread Starter

    Joined:
    2007/09/08
    Messages:
    85
    Likes Received:
    0
    Sweet !!
    You guyz keep up the good work !!
    Yup, I'll will try not to end up in that forum again.
    Once again, many thanx
    Jae ;)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.