Windows cannot find taskmgr.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by FiddyGeeky, Jul 4, 2007.

  1. FiddyGeeky

    FiddyGeeky Private E-2

    Hi i am new here... Whenever i start my windows I had an error message that says:

    "Windows cannot find 'C:\DOCUME~1\NURFIT~1\taskmgr.exe'.Make sure you typed the name correctly,and then try again. To search for a file, click the Start button,and then click Search." Just like in the attachment...

    Sometimes when i insert in my thumbdrive, it can autoplay. But if i double-click on the Removable Disk icon, i will get an error message that say "Windows cannot find 'Boot.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search."

    I know i've seen a forum with these same problems in http://forums.majorgeeks.com/showthread.php?t=122668&page=2So i just start a new thread since i am not allow to post reply...

    So I would be grateful if anybody outhere or maybe the same person by the name Chaslang who had helped in the forum above could help me.. Thanks.
     

    Attached Files:

  2. FiddyGeeky

    FiddyGeeky Private E-2

    I have read and followed the READ & RUN ME FIRST. Malware Removal Guide Thread.

    I have also already scan AVG Antispyware, BitDefender and PandaActiveScan as followed in the READ & RUN ME FIRST.
    I have attached the BitDefender Log and PandaActiveScan log.
     

    Attached Files:

  3. FiddyGeeky

    FiddyGeeky Private E-2

    These are my GetRunKey,ShowNew and HijackThis log files.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now reboot in normal mode
    Now run Ccleaner
    Now locate the below folder and delete it if found:
    C:\Program Files\True Sword 4

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. HJT


    Make sure you tell me how things are working now!
     
  5. FiddyGeeky

    FiddyGeeky Private E-2

    Thank you very much Chaslang for replying :)...

    I had already done what you have asked me to do... I had deleted C:\Program Files\True Sword 4...

    It works!!! :dancer No more error message pop up...

    But I just post the GetRunKey and HJT log files as you had suggested...
     

    Attached Files:

    Last edited by a moderator: Jul 5, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. FiddyGeeky

    FiddyGeeky Private E-2

    One more thing everything when i insert in my thumbdrive, i face this problem... My thumbdrive can autoplay but if i double-click on the Removable Disk icon from My Computer, i will get an error message that say

    "Windows cannot find 'Boot.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search."

    I scan my thumbdrive and i found out that my thumbdrive is infected with a Win32 worm... I am unable to clean it...

    I am using NOD32 anti-virus program...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Editing AUTORUN.INF on all drives if infected
    1. Right-click Start then click Search
    2. In the Named input box, type:
      AUTORUN.INF
    3. In the Look In drop-down list, select My Computer
    4. Once located, select the file then open with Notepad. Check if it contains the following strings:
      • shellexecute=Boot.exe
      • shell\Open\command=Boot.exe e
    5. If those lines are found, delete the two lines with boot.exe on it.
    6. Make sure you check ALL drives (thumb drive too) and do the same on all drives.
    7. Save the edited file and then reboot.
     
  9. FiddyGeeky

    FiddyGeeky Private E-2

    I am able to locate AUTORUN.INF but I CAN'T open it with Notepad... If i open a copy of it, i can find the following strings:

    shellexecute=Boot.exe
    shell\Open\command=Boot.exe e
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can open it with notepad but you just have to set it to all files type or from the instructions I gave you, you may have to choose what application to open it with. However whatever you are opening it with, just delete those lines and save it back as a text file.
     
  11. FiddyGeeky

    FiddyGeeky Private E-2

    Ok thanks to you once again chaslang... It works!!! No more error mesage... :celebrate
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Make sure you have completed everything I gave you in message # 6.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds