Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Windows Update (6300-NGSRP-TMR521A-SMG-542P4-3180). Virus

130 views
Skip to first unread message

Usman

unread,
Nov 6, 2007, 9:31:01 AM11/6/07
to
QUESTIONS OR COMMENTS
Message: The Message is belaow that accour at login time.

Windows Update (6300-NGSRP-TMR521A-SMG-542P4-3180). Check System Settings.
May be your system not full patch. System Still Safe. www.microsoft.com
Patch Code: AS3-CTRKEA-SR

This is a virus. This virus is also change the Language of folder option.
My Computer -> Tool -> Folder Option -> View

Then the all setting language is changed.

Plz send me the solution of this problem at given email address

usman...@yahoo.com

PA Bear

unread,
Nov 6, 2007, 12:26:51 PM11/6/07
to
Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315

Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/page2.html#Removing_Malware

When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware with
assistance from an expert. **Post your log to
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for expert
analysis, not here.**

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA) computer repair shop.
--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE, OE, Security, Shell/User)
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.org/

fwznssr

unread,
Nov 16, 2007, 4:42:01 AM11/16/07
to
if you get this exact error on boot up:

windows update : (6300-ngsrp-tmr 521a-smg-542ph-3180) check system settings
or upgrade system , maybe ur system not full patch , patch code as3-ctrkea-sr

Please use this step:

1. Turn off system restore by right-clicking on ‘My Computer’-> properties
-> system restore and tick ‘turn off system restore on all drives’. Click
apply and click ok.
2. Copy the script below to a notepad and save it as repair.inf:

[Version]

Signature="$Chicago$"

Provider=Babenya Galak

[DefaultInstall]

AddReg=UnhookRegKey

DelReg=del

[UnhookRegKey]

HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""

HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0,
"Explorer.exe"

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder,
Bitmap,0, "C:\WINDOWS\SYSTEM32\SHELL32.DLL,4"

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder,
Text,0, "@shell32.dll,-30498"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ClassicViewState, text,0, "@shell32.dll,-30506"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ControlPanelInMyComputer, text,0, "@shell32.dll,-30497"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\DesktopProcess, text,0, "@shell32.dll,-30507"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\DisableThumbCache, text,0, "@shell32.dll,-30517"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\FolderSizeTip, text,0, "@shell32.dll,-30514"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\FriendlyTree, text,0, "@shell32.dll,-30511"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden,
Bitmap,0, "%SystemRoot%\system32\SHELL32.dll,4"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden,
text,0, "@shell32.dll,-30499"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, text,0, "@shell32.dll,-30499"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN, text,0, "@shell32.dll,-30501"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue,0x00010001,1

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, DefaultValue,0x00010001,2

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, text,0,"@shell32.dll,-30503"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, type,0, "CheckBox"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\NetCrawler, text,0, "@shell32.dll,-30509"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\PersistBrowsers, text,0, "@shell32.dll,-30513"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowCompColor, text,0, "@shell32.dll,-30512"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowFullPath, text,0, "@shell32.dll,-30504"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowFullPathAddress, text,0, "@shell32.dll,-30505"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowInfoTip, text,0, "@shell32.dll,-30502"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SimpleSharing, text,0, "@shell32.dll,-30518"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, text,0, "@shell32.dll,-30508"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Thickets,
Bitmap ,0, "C:\WINDOWS\system32\SHELL32.DLL,4"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Thickets\AUTO, text,0, "Show and manage the pair as a single file"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Thickets\NOHIDE, text,0, "Show both parts but manage as a single file"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Thickets\NONE, text,0, "Show both parts and manage them individually"

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\WebViewBarricade, text,0, "@shell32.dll,-30510"

[del]

HKCU,
Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistriTools

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableCMD

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableTaskMgr

HKCU,
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions

HKCU, Software\Microsoft\Windows\CurrentVersion\Run, Intelprc

HKCU, Software\Microsoft\Windows\CurrentVersion\Run, Network

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SystemWindows

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system,
legalnoticecaption

HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system,legalnoticetext

3. Right click on repair.inf and click install.
4. Reboot your PC and see if the message comes back.
5. If it does, try to use the file again in safe mode. (Some complex
anti-virus software will block changes to registry)

Happy hunting!

fwznssr

chetan

unread,
Nov 26, 2007, 3:25:01 AM11/26/07
to

Plz also send me the solution of this problem at given email address.

Umer

unread,
Nov 27, 2007, 2:07:01 AM11/27/07
to
Try cleaning with AVG/NOD32 first. The apply the given below method of
repair.inf to restore Reg keys to original.

Umer...@hotmail.com

asim

unread,
Nov 28, 2007, 1:16:02 PM11/28/07
to
usman plz if u have solution of this problem plz email me.my email is
asimrafi...@gmail.com.thanxs.

hassan

unread,
Nov 30, 2007, 8:55:00 AM11/30/07
to
boss am also facing the same problem. do you ve the solution for it
if yes plz send me at hassan....@gmail.com
would be greateful

Nihit

unread,
Dec 17, 2007, 2:18:01 AM12/17/07
to
Hey even i m facing the same problem...

Actually what is this and from where we can get the patch??

Please Microsoft help us out...

aiyappa

unread,
Jan 5, 2008, 12:21:01 PM1/5/08
to
dear usman.
tis is aiyappa.am facing with the same problem that u have mentioned
here.If u have got some solutions for tis please let me kno.it will be very
kind of u if u help me out of tis.
thanking you
waiting for ur reply.
mail me on aiya...@gmail.com
regads
aiyappa

Oj

unread,
Feb 27, 2008, 4:04:01 AM2/27/08
to
hi this Omaid...
kindly mail me the solution of this problem if u hav recvd it..... at this
mail address
umai...@yahoo.com

khanna@discussions.microsoft.com Kumar khanna

unread,
May 1, 2008, 2:59:00 PM5/1/08
to
hai, I am kumar khanna,

I am unhappy with this OS.

Its too slow.

if some one can help me then do send me an email in kumar...@gmail.com

thanks,
KK

jun xiong@discussions.microsoft.com xu jun xiong

unread,
May 3, 2008, 10:05:00 AM5/3/08
to
dont understand what this mean. "Then the all setting language is changed"

jen

unread,
May 3, 2008, 10:02:46 PM5/3/08
to

"xu jun xiong" <xu jun xi...@discussions.microsoft.com> wrote in message
news:499840C5-F86A-4D88...@microsoft.com...

"Usman" wrote:
>> QUESTIONS OR COMMENTS
>> Message: The Message is belaow that accour at login time.
>> Windows Update (6300-NGSRP-TMR521A-SMG-542P4-3180). Check System
>> Settings.
>> May be your system not full patch. System Still Safe.
>> www.microsoft.com
>> Patch Code: AS3-CTRKEA-SR
>> This is a virus. This virus is also change the Language of folder
>> option.
>> My Computer -> Tool -> Folder Option -> View
>> Then the all setting language is changed.
> dont understand what this mean. "Then the all setting language is
> changed"


And I don't guess you ever will, since it was posted on *Tues, Nov 6
2007 9:31 am*.

-jen


AHMAD@discussions.microsoft.com TANVIR AHMAD

unread,
May 9, 2008, 4:49:01 AM5/9/08
to

javaid

unread,
May 22, 2008, 8:16:01 PM5/22/08
to
How to copy the script to a notepad and lateron to click it? Plz elaborate.

Code: AS3-CTRKEA-SR@discussions.microsoft.com Patch Code: AS3-CTRKEA-SR

unread,
Jul 6, 2008, 1:52:00 PM7/6/08
to

"Usman" wrote:

Hi.
i'm A.RAHMAN from INDIA. I'm working as an AutoCad operator in a
construction company. please sent me any solution or any antivirus for this
(Patch Code: AS3-CTRKEA-SR) patch code virus. Thankyou & this is my E-Mail Id
tajamul...@yahoo.com Thankyou once again.

CODE:AS3-CTRKEA-SR@discussions.microsoft.com PATCH CODE:AS3-CTRKEA-SR

unread,
Aug 4, 2008, 9:53:01 AM8/4/08
to
Windows Update

JK

unread,
Jan 31, 2010, 4:40:01 AM1/31/10
to
If anyone got the solution for this problem, please let me know the solution..
email id: egale...@gmail.com

Hank Arnold

unread,
Jan 31, 2010, 5:57:21 AM1/31/10
to
On 1/31/2010 4:40 AM, JK wrote:
> If anyone got the solution for this problem, please let me know the solution..
> email id: egale...@gmail.com

Exactly what is the problem???

--

Regards,
Hank Arnold
Microsoft MVP
Windows Server - Directory Services
http://it.toolbox.com/blogs/personal-pc-assistant/

VanguardLH

unread,
Jan 31, 2010, 7:46:44 AM1/31/10
to
JK wrote:

> If anyone got the solution for this problem,

And "this" problem is WHAT?

> please let me know the solution..

No problem mentioned. No solution needed.

> email id: egale...@gmail.com

If you have the time to post here when asking for help, you have the time to
return here to check for replies.

You sure that the message isn't from some malware, especially if it contains
crappy English typical of Chinese authors? When was the last time you
scanned your host for malware and by using multiple anti-malware products?


--- Posting Hints ---

ALWAYS REVIEW your message before submitting it. You want someone OTHER
than yourself to understand your post. Also remember that no one here is
looking over your shoulder to see at what you are pointing. If you don't
well explain your situation by providing the details that you already know,
don't expect others to know what is your situation. Explain YOUR computing
environment and just what actions you take to reproduce the problem.

Often you get just one chance per potential respondent to elicit a reply
from them. If they skip your post because you gave them nothing to go on
(no details, no versions, no OS, no context) then they will usually move on
to the next post and never return to yours.

What is Usenet:
http://en.wikipedia.org/wiki/Usenet
http://en.wikipedia.org/wiki/Newsgroups
http://www.masonicinfo.com/newsgroups.htm
http://www.mcfedries.com/Ramblings/usenet-primer.asp

When using a webnews-for-dummies interface, like Microsoft's Communities or
Google Groups or a forum-to-Usenet proxy, those are gateways to Usenet.
Despite the appearance of a forum, you are participating in a newsgroup (aka
Usenet).

How to post to newsgroups:
http://66.39.69.143/goodpost.htm
http://support.microsoft.com/kb/555375
http://users.tpg.com.au/bzyhjr/liszt.html
http://www.mugsy.org/asa_faq/getting_along/usenet.shtml

Regarding error or status messages:
- Do NOT omit the message.
- Do NOT describe the message.
- Do NOT summarize the message.
- Do NOT paraphrase the message.
- Do NOT truncate the message.
- Do show the ENTIRE message (but munge or star out personal info,
like your username in an e-mail address but not the domain).

nmand...@gmail.com

unread,
Sep 20, 2013, 4:13:20 PM9/20/13
to
did not work
0 new messages