Solved

After virus issues

Posted on 2013-05-24
11
326 Views
Last Modified: 2013-11-22
Howdy all.  I have a client workstation that had a nasty bug.  I was able to clean it and restore desktop etc., but every program pops up an error "Illegal operation attempted on a registry key marked for deletion".  On some of the shortcuts I've been able to make it work by giving the program "start as administrator".  The rest won't allow that option to be checked.  Office 2010 is one of them.  Anything else I can do to fix this?
Thanks,
jwhite
0
Comment
Question by:jwhite273
  • 3
  • 3
  • 2
  • +3
11 Comments
 
LVL 24

Expert Comment

by:aadih
ID: 39194518
What OS?   What bug?  What anti-virus program used to clean?  Some details are necessary?
0
 
LVL 17

Assisted Solution

by:upul007
upul007 earned 166 total points
ID: 39194532
If you did not clean the virus in safe mode, perhaps doing it that way will help clear the registry entries.
0
 
LVL 19

Expert Comment

by:helpfinder
ID: 39194538
Did you try to reinstall affected programs (e.g. MS Office)?

what if you try to log on as different user on that machine? Do you have problems to run apps as well?
0
 
LVL 14

Expert Comment

by:comfortjeanius
ID: 39194558
Try running SFC /SCANNOW and reboot the computer and see what happens.
0
 
LVL 26

Expert Comment

by:pony10us
ID: 39194562
This is often seen when using Combofix to clean a system and not rebooting when told.
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 

Author Comment

by:jwhite273
ID: 39195020
Ok, here's the rest of the info I should have included.
OS is Win 7 x64
Bug appears to be PCRestorePro
Working in safe mode I have been able to use Malwarebytes and Combofix.  Spybot S&D 2 would not launch.
Office 2010 has been uninstalled/reinstalled.
Able to get back in real mode, but as I stated above, some progs are throwing the error.  On those I can set run as admin, work, the rest don't.

Sorry for not including this in the first place.
0
 
LVL 26

Assisted Solution

by:pony10us
pony10us earned 167 total points
ID: 39195101
Let me preface by stating clearly that I am not a Combofix expert.

What I have been told is that when this happens after running Combofix it can sometimes be fixed by rebooting.  It may take a few reboots to resolve.  

Again, I want to stress that I am not a Combofix expert.
0
 
LVL 24

Accepted Solution

by:
aadih earned 167 total points
ID: 39195577
Can you run MBAM in normal windows?  If so, run it.

Also did you try to restore the system to an earlier date?  If you can, please do a system restore.
0
 

Author Comment

by:jwhite273
ID: 39195619
OK, ran Mbytes in real mode, found more crap and removed.  Finally got Spybot 2 running, again more stuff removed, ran Combofix in realm mode and that found more.  After aqll 3 and a quick run of mbar, we seem to be operating normally.  What confuses me is that when I clean a machine in safe mode, that's usually the end of it.  This is the first time I've had to rerun programs to get the proper results.  Thanks all.
0
 

Author Closing Comment

by:jwhite273
ID: 39195620
Thanks again all.
0
 
LVL 24

Expert Comment

by:aadih
ID: 39195625
You must always run the scanning program in normal mode first.  If that is not available or the program does not run, then it must be run in safe mode. But after the normal mode becomes available, it must be run from the noraml mode.

Great.  You got it working.  :-)
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

These are on the increase and getting more common these days. Users who use the Google search engine may complain of having their search redirected to unwanted sites, regardless of what browser is used. This happens when the system is infected with…
HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now