TechSpot

Unable to open Regedit Msconfig anc Ctrl Alt Del.

By pauljt
Oct 27, 2007
  1. Please can someone help with this issue, I have attached my HJT Log.

    Thankyou
     

    Attached Files:

  2. Rik

    Rik Banned Posts: 3,814

    Your pc is definately infected, you need to follow the instructions below very carefully.

    You need to have a read of this - If your system is infected. Read this before deciding whether to CLEAN or REFORMAT.

    Then if you should wish to proceed with cleaning your system you need to go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT, Combofix, Panda Antirootkit, and AVG Antispyware logs as ATTACHMENTS into this thread, only after doing the above.


    This thread is for the use of pauljt only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. pauljt

    pauljt TS Rookie Topic Starter

    Results to previous thread

    Panda Antirootkit scan showed no problems

    Could not open Combofix error" C:\WINDOWS\system32\cmd.exe Another program is using this file"

    Have attached HJT and AVG
     
  4. Rik

    Rik Banned Posts: 3,814

    And the asked for combofix log?

    Hijackthis.exe hasnt been renamed as per the instructions either.



    This thread is for the use of pauljt only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. pauljt

    pauljt TS Rookie Topic Starter

    File name is changed to crusty.exe, and my PC wouldn't open combifix
     
  6. Rik

    Rik Banned Posts: 3,814

    Renaming is isnt much good without providing a new log with it renamed.

    What do you mean combofix wouldnt open exactly. You are using windows xp sp2 so it should work perfectly well. The combofix log is also the most important log of them all too.



    This thread is for the use of pauljt only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  7. pauljt

    pauljt TS Rookie Topic Starter

    When opening Combofix from desktop, I get an error message saying another program is using that file C:\WINDOWS\System32\cmd.exe

    I'm assuming its the same virus thats stopping me opening other ".exe" files such as regedit and msconfig
     
  8. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    We need to temporarily disable Spybot search & Destroy`s tea time, as it may interfere with any fix we are trying to run.

    Disable Spybot's TeaTimer. This is a two step process.
    First:
    - Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
    - Choose Exit Spybot S&D Resident
    Second:
    - Open Spybot S&D
    - Click Mode, check Advanced Mode
    - Go To Left Panel, Click Tools, then also in left panel, click Resident
    - If your firewall raises a question, say OK
    - Uncheck the box labeled Resident Tea-Timer and OK any prompts.
    - Use File, Exit to terminate Spybot
    - Reboot your machine for the changes to take effect.

    You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key(if you can).

    Click on the processes tab and end process for(if there).

    dllhost.exe

    Close task manager.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O2 - BHO: XBTB09580 Class - {213C7491-5A0D-4b99-8B6B-1498B14B398F} - (no file)

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: (no name) - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)

    O4 - HKLM\..\Run: [RegistrySmart] C:\Program Files\RegistrySmart\RegistrySmart.exe

    O4 - Global Startup: dllhost.exe

    O8 - Extra context menu item: &Search - ?p=ZU

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O20 - Winlogon Notify: vtstr - C:\WINDOWS\

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or folders(if there).

    C:\windows\system32\vtstr.dll
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe

    Reboot into normal mode and rehide your protected OS files.

    Post fresh HJT and Combofix logs.

    Regards Howard :wave: :wave:

    This thread is for the use of pauljt only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  9. pauljt

    pauljt TS Rookie Topic Starter

    Cont.

    Sorry for the delay have been away on holiday.

    Had to do a complete re-install of windows as comp crashed completly and couldn't open up even in safe mode.

    I managed to retrieve all my usual settings and programs and followed you instructions.

    Everything is working fine now, but have enclosed another HJ report incase there's something i've missed.

    Thank you for your time

    Paul
     
  10. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is clean.

    Sorry you had to reformat your system.

    Hope you had a good holiday.


    Regards Howard :)

    This thread is for the use of pauljt only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  11. pauljt

    pauljt TS Rookie Topic Starter

    Howard,

    Thats great news, thank you so much for all your help with this.

    Cheers

    Paul

    This thread is now closed: If you need this thread unlocking, please pm a moderator with a link to the thread.

    Only the original thread starter can do this. Anyone else, will be ignored.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...