TechSpot

Ctrl + alt + delete problems.

By MatthewN
Aug 6, 2003
  1. Whenever I use the ctrl alt delete shortcut, the task manager will come up, then disappear within a second. It will leave it's icon in the task bar in the bottom right of my computer, and whenever I move my mouse near it is disappears.

    If it is being caused by a virus then Norton can't detect it.

    I'm using Windows XP home edition if it matters.
     
  2. Rick

    Rick TechSpot Staff Posts: 4,573   +65

    Try booting into safe mode and see if you have the same problem.
     
  3. Nodsu

    Nodsu TS Rookie Posts: 5,837   +6

    Some viruses/worms are known to do this in order to avoid detection. It may as well be that Norton has already been disabled too.
     
  4. MatthewN

    MatthewN TS Rookie Topic Starter

    When I restarted in safe mode ctrl alt delete worked. Now I just have to find out what it is I've got here.
     
  5. MatthewN

    MatthewN TS Rookie Topic Starter

    Okay, turned out I had w32.spybot.worm

    I managed to get delete all of it, and I'm pretty sure I deleted the value from the registry, but it still seems to be active somehow because ctrl alt delete and all the other things won't work outside of safe mode. I've deleted all the files, and nothing is picking up anything.
     
  6. poertner_1274

    poertner_1274 secroF laicepS topShceT Posts: 4,172

    Well those pesky virii usually clone themselves and change names. Try to use adaware and see if that can't get rid of it.
     
  7. StormBringer

    StormBringer TS Rookie Posts: 2,244

  8. MatthewN

    MatthewN TS Rookie Topic Starter

    I fixed it. Anyways, I had just updated my AV less then a week ago.

    Turned out I had a whole different strain then most of the ones I've seen explanations for. There was another viral type thing that I had to delete that Norton and every other AV I tried wasn't even picking up at all. For most people the msconfig32.exe seemed to be the only thing disabling their stuff, but it was a whole different virus file that was disabling mine. Finding it was a major pain.
     
  9. StormBringer

    StormBringer TS Rookie Posts: 2,244

    Try using Heuristic scan option in your AV software, Norton and some others have it as an option, there is a learning curve to using it if you aren't familiar with some of the files that send up flags, such as macros. Heuristic scan is really the best because it doesn't just look for "known virus types" it also looks for files that have characteristics of a virus or something and can flag it as a possible virus. This is where the curve comes in. In order to properly use this option you have to be somewhat familiar with what is on your disks.
     
  10. JackJohnson

    JackJohnson TS Rookie

    Hey

    Hey MatthewN
    How exactly did u get rid of it. i have that exact problem and i have spybot search adn destroy for spyware, adware for more spy ware and norton. It is not finding anything. Can u please post the details of how u did this

    Thanks

    Jack
     
  11. poertner_1274

    poertner_1274 secroF laicepS topShceT Posts: 4,172

    I have replied to your other post, but you need to run both programs in Safe Mode and make sure that they are both up to date before running them.
     
  12. helpplease

    helpplease TS Rookie


    Hey can you help... i have no idea what safe mode is... can you tell me how to get there? My CTRL+ALT+DEL doesn't work either, it won't open :(
     
  13. poertner_1274

    poertner_1274 secroF laicepS topShceT Posts: 4,172

    First of all, have a good read here and follow the directions exactly. Then take a look here on how to attach your hijack this log as an attachment.

    That should take care of everything.

    BTW
    :wave:Welcome to TechSpot:wave:
     
  14. helpplease

    helpplease TS Rookie

    ok the hijackthis i have no ide what to do, what to pick and clean =/ i used my adaware and found this : Win32.P2P-Worm.Alcan.a
    :(
    sorry for bieng a pain
     
  15. IronDuke

    IronDuke TS Rookie Posts: 856

    Just re-read the instructions in the post and then follow them to the letter.
     
  16. JackJohnson

    JackJohnson TS Rookie

    IT was a virus, i had to go into safe mode adn look in windows/ system 32. I had a file name called etwr, that was a text pad entry, it will say "keylogger started - a certain date" take that date and look for a application created on that date, once u find it, u can delete it if ur in safe mode. The etwr thing kept track of everything that u typed.
     
  17. AshleyBrown

    AshleyBrown TS Rookie

    I am having hte same problems, now if I restart in safe mode...when I go back to regular mode will the ctrl+alt+delete come back up? because the window doesnt even popup for me at all...and I am getting reallly annoyed, I just reconfigured my computer and I dont facny having to do it again. ;_; please help
     
  18. Fukurou

    Fukurou TS Rookie Posts: 51

    Tried agian and agian

    I did that long and painfull method above but it hasnt worked at all. If someone pehaps could help me, I have my most recent log file Via HJT, perhaps someone could help as to pick out the bad file?
     
  19. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Go and have your computer scanned HERE.

    Then go and follow the instructions in this thread HERE.

    Then see. How to post your Hijackthis log-file as an ATTACHMENT.

    Open a new thread in the security and the web forum and post your HJT log, only after doing the above.

    Regards Howard :wave: :wave:
     
  20. Tedster

    Tedster Techspot old timer..... Posts: 6,000   +15

    it is very foolish to post your email address on a public forum. I guess you like spam.
     
  21. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Good point Tedster.

    Fukurou. You should edit your post above and remove your e-mail address asap.

    Regards Howard :)
     
  22. Fukurou

    Fukurou TS Rookie Posts: 51

    Fixed it so it's gone, thanks for that little warning, However, it's still shown in the Quote above which I dont think that I can change.
     
  23. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Sorry about that mate. It`s now gone.

    Regards Howard :)
     
  24. Fukurou

    Fukurou TS Rookie Posts: 51

    Not what I thought

    This program running in the background, much like what the other discribed is diffrent somhow. When I start my computer, I can press ctrl alt delete before the Worm has time to run it's script, and there I see in System Tasks (Project 1) shortly after that go away, in Processes I see (b.exe) the website for house call gave me the registry keys to fix then I run house call to delete the Infected files, For anyone else who is able to see this, Check this thead http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BND&VSect=T and for a list of other types to that nature http://www.sysinfo.org/startuplist.php?filter=&letter=B

    PS.
    House Call wont go past "Idle"
     
  25. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Follow the rest of the instructions. then, open a new thread in the security and the web forum and post a HJT log as instructed.

    Regards Howard :)
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...