Cannot open regedit, task manager, among others....

Status
Not open for further replies.
Just an update while reading the steps...I am talking to my friend, and an error popped up!

rundll32.exe has encountered a problem...

continuing reading the steps...

I have downloaded all of the necessary programs, I am going to go through all of this and post everything ASAP. I may have to post some of this tomorrow, I have to get some rest tonight I have a long day tomorrow...I really appreciate all of this help and I will bump this up tomorrow with all of the various logs, checks, spyware logs and everything posted. Thank you so much!

I am currently at home on a different PC. This morning I could not access the internet on the damaged PC and the internet icon, ofcourse, was changed into a Windows 95-esque icon all big and pixelated, just as all the other non-working programs look.

I ran all the necessary spyware programs and deleted EVERYTHING. The computer seems to be falling apart, programs are slowly but surely falling victim to this crappy icon appearance and lack of opening ability.

Windows Media player has also fallen victim.

I am considering a reformatting...I would like to hear any other alternatives first from the experts! Thanks so much for the help thus far!
 
If you cannot post the requested log files, a reformat is probably the best way to proceed.

Regards Howard :)

This thread is for the use of The Lost Chord only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
I am going to go ahead with it...but I have a question:

When trying to re-install windows XP over the currently working one (well, not so much working one)...I couldnt get past a part where it now says Could not find CD-Rom drive...some gibberish about an SCSI drive or something, it is a blue screen and it pops up and says press F3 to cancel. This comes up everytimg I boot up unless I quickly switch to my CURRENT setup instead of the setp process option of the unfinished installation (repair installation so to speak).

If I reformat, I assume it will also do away with this temperary repair installation that seems to WANT to complete but cannot? Also, I am considering bringing an external hardrive over and saving my music to it. Any dangers involved? Considering how nothing works and it seems highly damaged, could it affect an external HD in any way by plugging it in via USB?

Thanks so much!
 
You could try a Windows Repair as per this thread HERE.

If that doesn`t help, then a reformat and reinstall is probably the way to go.

I don`t think you should have any problems backing up your music to an external hard drive.

What ever you do, I don`t recommend trying to reinstall Windows over itself as the system is probably still infected with whatever has buggered up your OS in the first place.

You will need to go into your bios and set your boot priority to cd-rom/hdd.

I`m sorry I wasn`t able to clean your system.

Regards Howard :(

This thread is for the use of The Lost Chord only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Its fine, I recieved alot of help here and am glad!

Do you have a thread on reformatting process...or should I have an expert perform it? I have a computer guy who comes here, but he costs an arm and a leg when fixing things I dont understand...I have never re-formatted before, so...

Thanks again!
 
Wow!!

I did not follow your instructions on a reformatting, but rather was immediately intrigued by this Symantec Dell Restore option I had.

Now, because the computer seems to be in tip top, brand new shape after I preformed this QUICK and simple 10 minute "Restore" by hitting ctrl and F11 at boot up and just hitting Restore system, I am scared it is too good to be true.

Is it? The system has gotten rid of anything bad it seems and has just bombarded me with all the junk it did when I FIRST booted it up...but it is perfect! Everything is running great!

Is it possible, though, that anything nasty is still on here??? It says it cleaned everything, and brings the PC back to when I first booted it up basically...it gave me all the classic prompts and package junk all over again, and I couldn't be more happy to see them haha!!

Well, let me know if I should be concerned because I am overwhlemed with joy as it stands...

Thank you!!
 
Hijackthis Log Check after Restore

Hi! I have recieved great help here and my system is working great. I would like to see if anyone here can help me get rid of some junk on my HijackThis log.

I am running 37 processes and would like to cut it down, and get rid of anything unneccesary. I would also like to make sure there are no current running viruses or anything after the restore has taken place.

here is my recent log:

View attachment 15532

Thanks so much for the help here, this forum is fantastic!
 
That`s good news. However, just to make sure, please post a fresh HJT log.

Regards Howard :)

This thread is for the use of The Lost Chord only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Threads merged.

You`ve manage to get your system reinfected. You`re also running an outdated version of HJT from the wrong location and have not renamed it as per the instructions.

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

If after reading the above, you wish to clean your system, do the following.

Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT, AVG Antispyware and Combofix logs as attachments into this thread, only after doing the above.

Also, let me know the results of the AVG Antirootkit scan.

Regards Howard :)

This thread is for the use of The Lost Chord only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
You`re not running any antivirus or firewall software. This is a huge security risk and is probably the reason your system is infected.

Download and install one of the free antivirus programmes and one of the free firewall programmes below.

AVG free or Avast antivirus programmes.

Zonealarm or Kerio free firewall programmes.

Install whichever firewall you chose, followed by whichever antivirus programme you chose. Run the antivirus updates and do a full system scan from safe mode. Delete whatever the antivirus programme finds.

All items in your AVG Antispyware log say "No Action Taken". That`s because you didn`t tell AVG Antispyware to quarantine the results. See HERE for instructions.

You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

Click start/run and type services.msc into the run box and press the enter key.

When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

Windows System Helper

Close the services window.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

WindowsHelp.exe

Close task manager.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O23 - Service: Windows System Helper - Unknown owner - C:\WINDOWS\system32\WindowsHelp.exe

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\WINDOWS\system32\WindowsHelp.exe

Reboot into normal mode and rehide your protected OS files.

Post a fresh HJT log as well as another AVG Antispyware log.

Regards Howard :)

This thread is for the use of The Lost Chord only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Thanks!

Now, here are the new logs: I have a Windows Firewall program installed, but no anti-virus. I have always had trouble with anti-virus and have found it to just slow down my computer significantly and to not be of much help. I will install anti-virus if necessary to fix this problem though!

View attachment 15576

View attachment 15577

View attachment 15578

How am I looking?

Also, I have noticed I am running multiple processes of the same name, i.e. svchost.exe specifically. Is this necessary? I never noticed so many duplicates before!

I have downloaded AVG anti virus, I got impulsive and really want this computer to be protected from now on.. It is installed, I am going to run a virus scan now (I did the online scan and it found nothing) should I post a new log after the virus scan?
 
Your HJT log is now clean.

Delete all files in AVG Antispyware quarantine.

Turn off system restore.(XP/ME only) See how HERE.

Now, turn system restore back on. This will have deleted all your old restore points and any nasties that are in them. It will also have created a new, clean restore point.

The windows firewall is absolute rubbish and won`t protect your system properly. Also, running without an antivirus programme is foolish to say the least. How do you think you got infected in the first place?

I strongly suggest you install antivirus and firewall software as below.

AVG free or Avast antivirus programmes.

Zonealarm or Kerio free firewall programmes.

If you have any further virus/spyware problems, please post in this thread.

Regards Howard :)

This thread is for the use of The Lost Chord only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Status
Not open for further replies.
Back