Disappearing TaskManager, Regedit, MsConfig

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by topcatoz, Dec 27, 2004.

  1. topcatoz

    topcatoz Private E-2

    I have followed the 'Hijack This' prerequisites but cannot remove a VX2 when in safe mode. 'Kill2me' identified the VX2 but could not remove it, as it was loaded in memory (in safe mode). Any thoughts? I can post my HijackThis log file if requested.
     
  2. Turcoloco

    Turcoloco MajorGeek

    If you can open up MS Configuration Panel ( START > RUN > msconfig > OK), then check the 'Startup' tab to see if there are any entries in there referring to the malware and uncheck them before rebooting in 'Safe Mode' the next time around. ;)
     
  3. BBINDER

    BBINDER Private E-2

    I have this same problem but i cannot download hijack this or run it from a disk, i cannot get into regedit or msconfig. All anti-virus and firewall software has been disabled and when i do a search from my homepage. It shuts down it down and returns to my desktop, So far Nicrosoft has not been any help.
    Hopefully someone here can pull a rabbit out of there hat and help me fix this thing. :rolleyes:
     
  4. Turcoloco

    Turcoloco MajorGeek

    Guys, make sure you read each and every sticky in the 'Spyware Specific' section and follow the instructions in their entirity. If your account really had the Amin privileges you should be able to run msconfig or registry editors, check to make sure your accounts are in the admin group. If you need with that let me know but if all is failing and you are not able to take control of the system any means that you've tried then what can I say...reformat and re-install after all a system that is that far infected and compromised is not worth saving...IMO. :rolleyes:
    ...but to this date I have yet to see a system that was infected with spyware and yet I couldn't recover from....don't give up easily and give us more details on what you have done/tried....repost when you can.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are several types of trojans out there that cause these problems. For example see this.

    http://windowsxp.mvps.org/ToolsQuit.htm

    I have fixed quite a few problems like this our forum.

    As Turcoloco pointed out, you need to run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.
     
  6. topcatoz

    topcatoz Private E-2

    Followed the instructions posted on the forum and cleaned the computer. Still need to use the replacement Taskmanager, MSConfig & Regedit. Thanks for the info

    Topcatoz
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds