Welcome to the Windows XP forum. If you have an error or a question make sure that you provide enough information to your fellow members in order to get a good answer, without information we cant answer you.
We try our best to keep this forum clean of illegal content. If you see any illegal activity use the "report" button you find in every post to report the specific post to the moderators.
![]() ![]() |
May 29 2008, 12:32 AM
Post
#1
|
|
|
Newbie Group: Members Posts: 15 Joined: 26-December 07 From: Orange, New South Wales Member No.: 168250 OS: XP Pro x86
|
PC Tools OnDemand issued an "VERY HIGH" alert during .Net framework 3.5 installation
for MSIEXEC.EXE. I Quarantined it. Internet Security won't let me restore it. Neither will System Resore. Now Windows Installer won't work. The service cannot be re-enabled, access denied. The service won't start up automatically. I've disabled DCOM. Any way of saving the Event Viewer Log also? I can place it here. This post has been edited by vaughancoveny: May 29 2008, 12:38 AM |
|
|
|
May 30 2008, 09:27 AM
Post
#2
|
|
|
K-Mart-ian Legend ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1155 Joined: 28-April 06 From: Buffalo, NY Member No.: 94953 OS: Server 2008 x64
|
You should probably turn DCOM back on. A lot of programs require that to be running.
|
|
|
|
May 31 2008, 04:13 AM
Post
#3
|
|
|
Newbie Group: Members Posts: 15 Joined: 26-December 07 From: Orange, New South Wales Member No.: 168250 OS: XP Pro x86
|
I did but it did not remedy the problem.
You may be getting confused with COM (ActiveX). Security programs often allow you to Disable DCOM, like DCOMobulator which phased out a few years ago, but there are other programs that do allow. Distributed COM, Distributed Transaction Coordinator and Task Scheduler all occupy, transmit and receive through port 135 and are dangerous. Unless you need prefetch functionality use Freebyte Task Scheduler instead or do things manually. |
|
|
|
Jun 2 2008, 08:16 AM
Post
#4
|
|
|
Jack of all trades, master of none ![]() ![]() ![]() Group: Members Posts: 346 Joined: 26-January 04 From: Bellefontaine, OH Member No.: 13177 OS: XP Pro x86
|
I'm not familiar with PC Tools OnDemand but I think you reacted to a false positive. You need to disable the PC Tools OnDemand and copy the missing msiexec.exe from %WinDir%\System32\dllcache. I admire your vigilence and care, but since you were in the process of installing an application from an assumed trusted source like Microsoft, you should have let it go and investigated the issue first. These apps are nice to help people out, but they are not 100% all the time. It probably picked up the installer as a false positive and now that you've Quarantined it, it isn't about to let it be restored.
Also, the installer service is normally stopped in Manual and only started when needed for an installation. |
|
|
|
Jun 2 2008, 12:18 PM
Post
#5
|
|
|
K-Mart-ian Legend ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1155 Joined: 28-April 06 From: Buffalo, NY Member No.: 94953 OS: Server 2008 x64
|
I'm not familiar with PC Tools OnDemand but I think you reacted to a false positive. You need to disable the PC Tools OnDemand and copy the missing msiexec.exe from %WinDir%\System32\dllcache. I admire your vigilence and care, but since you were in the process of installing an application from an assumed trusted source like Microsoft, you should have let it go and investigated the issue first. These apps are nice to help people out, but they are not 100% all the time. It probably picked up the installer as a false positive and now that you've Quarantined it, it isn't about to let it be restored. Also, the installer service is normally stopped in Manual and only started when needed for an installation. I have similar experiences with our corporate Anti-virus. It likes to detect my programming tools as 'trojans' and 'hack tools' and tries to erase them from my hard drive and our network drives. In my case, there doesn't seem to be an option to make it ignore those things... |
|
|
|
Jun 2 2008, 06:13 PM
Post
#6
|
|
|
MSFN SuperB ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 5750 Joined: 24-June 04 Member No.: 23344 OS: none
|
It's a false positive.
Remove it from the quarantined state and mark it as safe. |
|
|
|
Jun 2 2008, 06:22 PM
Post
#7
|
|
|
Time Lord Group: Super Moderator Posts: 2617 Joined: 27-January 04 From: The TARDIS Member No.: 13262 OS: XP Pro x86
|
As Jeremy mentioned it's a false positive. Unfortunately this is very common with PC Tools software (like SpywareDoctor).
You may also want to give Dial-a-fix a go. |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22nd November 2008 - 06:04 AM |