HJT Log, Generic task manager problems

Status
Not open for further replies.
I can't open the task manager when not in safe mode. Sasser Worm removal came up with nothing, along with Spybot. In regular mode, windows says it's being used by another program. Anyways, I've run a HJT log, if anyone would like to review it, I'd greatly appreciate it:
 
I dont think your going to get any replies because your suppoes to post your hjt log as a attachment and rename it to a ****.txt
 
Hello and welcome to Techspot.

Go HERE and follow the instructions exactly.

Post a fresh HJT log as an attachment, after doing the above.

Regards Howard :wave: :wave:
 
Sorry about that, back to the HJT...

Also, I noticed that I have two folders called "Microsoft Office" and "microsoft frontpage"

Realizing that I have neither of these programs, I went into safemode and deleted both of them. However, when I rebooted the computer, the folder "microsoft frontpage" was back, and when I tried to delete it, Windows said it was being used by another program. There are no contents within this folder except a folder called, "version3.0" and within that, another empty folder "bin"
I figure this folder is causing most of my grief.
 
Boot into safe mode. See how HERE. http://www.bleepingcomputer.com/forums/tutorial61.html

Turn off system restore.(XP/ME only) See how HERE. http://www.bleepingcomputer.com/forums/tutorial56.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE. http://www.bleepingcomputer.com/forums/tutorial62.html

Go to add remove programmes in your control panel and uninstall anything to do with(if there).

winupdates

Close control panel.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

winupdates.exe
mt.exe
mx.exe
ms.exe

Close task manager.

Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)

O4 - HKLM\..\Run: [Windows Update] C:\mt.exe
O4 - HKLM\..\Run: [Adware Remover] C:\mx.exe
O4 - HKLM\..\Run: [Virus Removal Tool] C:\ms.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files(if there).

C:\mt.exe
C:\mx.exe
C:\ms.exe
C:\Program Files\winupdates\winupdates.exe /auto

Reboot into normal mode and turn system restore back on.

Get some antivirus and firewall protection, such as AVG free and Zonealarm.

You can get them HERE and HERE.

Regards Howard :)
 
Update

I did everything you told me and I've gotten my task manager back!
I ran HJT again in normal mode after the fix and the house call scans etc in case i missed anything.

however, the mysterious "microsoft frontpage" folder is still cropping back up even after i delete it in safemode.
 
Winupdates is still there. this is your main baddie.

Boot into safe mode. See how HERE. http://www.bleepingcomputer.com/forums/tutorial61.html

Turn off system restore.(XP/ME only) See how HERE. http://www.bleepingcomputer.com/forums/tutorial56.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE. http://www.bleepingcomputer.com/forums/tutorial62.html

Go to add remove programme an uninstall winupdates, if it`s there. Close control panel.

Open your task manager and end process for winupdates.exe Close task manager.

Run HJT and have it fix this entry, if it`s there.

O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto

close HJT.

Go into this drirectory and delete the bold folder and everything in it.

C:\Program Files\winupdates\winupdates.exe /auto

Reboot your computer and post a fresh HJT log.

Regards Howard :)
 
Status
Not open for further replies.
Back