Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Topics - dfreyer

Pages: [1]
1
Tweaking.com Support & Help / Errors Reported During "Repair" Actions
« on: April 15, 2016, 05:48:38 pm »
Below is a list of repair actions giving errors:

HKLM_Set_Owner
HKLM_Set_Permissions
HKU_Set_Owner
HKU_Set_Permissions
Repair_Network
Repair_WMI
Services_Set_Permissions

The below discussion follows the same sequence as the above listed repair sequence.

The bulk of the errors reported centered on Registry Key security, reporting "Access is Denied." The same was reported for value reset actions in the Repair Network routine. Additionally, a command (int 6to4 reset all) was not found causing another error. The next log file has a fairly large number of programmatic SYNTAX errors reported by the MOF Compiler. Lastly, the "Writing Security Info" to 25 services failed, reporting "Access is Denied."

After a lengthy examination of the log files, it can be concluded the account trying to access registry keys and files needs elevation, allowing access to all the necessary keys, services and files.

For convenience, attached are the affected Repair Windows log files, for your analysis, should you wish to view them.

2
This issue has been investigated, with professional action, by Shane, taken to determine its root cause. However, any user relying on Bitdefender may see this issue, and therefore should be aware that it is a false positive as Shane explained below.


Shane,

I have used your utilities for quite some time to keep my system in top shape.  So I am not angry over having to put up with the hassle of removing the Gen.Variant.Kazy.563984 Trojan from my system.  However, this Trojan has a reputation of not being easily discovered by most anti-virus and anti-malware applications, while doing quite a bit of damage to its host system. Recommend you verify, by your own means, the infestation within your own system; remove Advanced System Tweaker from your file server, preventing further downloads; and put a large banner notification on tweaking.com's Home page telling of the infestation, with a link to instructions for its removal from a Windows bases system, so your users can uninstall Advanced System Tweaker and remove Gen.Variant.Kazy.563984 from their systems.   

The Trojan is embedded in the Advanced System Tweaker's close_process.exe file, and hope you can effectively clean close_process.exe then release a new version of the Advanced System Tweaker soon thereafter.

Wishing you continued success, I remain

A Loyal User,

David

Pages: [1]