Task managr and regedit not open, several instnces of notepad.exe running

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rachitsaran1987, May 10, 2011.

  1. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi there,
    I am rather frustrated ...
    I have been using my computer without any spyware/AV for the last 1 year now ...
    Never been affected yet ...
    But now, I have been facing this rather strange problem.

    At first, it was the typical "Task manager has been disabled by your administrator: problem, which I solved by using some script that came up on googling my problem. But still, when I try to open the task manager, it opens very very slowly and is there for viewing for about 2-3 seconds after which it gets closed. Same is the problem with regedit too. Also, my system is running very slow. In the brief time that task manager would let me look at it, I saw atleast 7-8 notepad.exe processes running.

    PLEASE HELP ME OUT. I do not want to lose my data (as most of it is in C: itself).

    P.S. - I am not able to download Hijackthis from any site. Can this be the malware/TH/Virus acting up? Please do not redirect me to some other page for the solution as, believe me, I have gone through at least 10 sites where they had "similar" problems.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi,

    Thanks for the prompt reply.

    I followed all the steps you mentioned and here are the results:

    Step 2: I have only one spyware installed, namely Spyware Blaster.

    Step 3: Uninstalled Java 6 24 and installed Java 6 25. Also installed CCLEANER.

    HOWEVER, I COULD NOT RUN IT AS IT CLOSES AUTOMATICALLY WITHIN 2-3 SECONDS. SO, CCLEANER COULD NOT BE RUN.

    Step 4: I have 32 bit WinXP installed. Version 2002, SP2. Also, changed msconfig to normal startup mode.

    Step 5: Found just one on that list (ShopperReport). Uninstalled it. Problem still there.

    Step 6: Removed Daemon Tools Lite from the system.

    Step 7: Ran SuperAntiSpyware, MalwareBytes, ComboFix, RootRepeal in that particular order.

    HOWEVER, COULD NOT RUN MGTOOLS AS IT GAVE THE ERROR: “REGISTRY EDITING HAS BEEN DISABLED BY YOUR ADMINISTRATOR.” AND WOULD NOT PROCEED ANY FURTHER.

    The other 4 logs are attached in this message.

    P.S. – I cannot access my Task Manager or the Regedit anymore.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    While you wait for Kestrel, please do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Can you now run C:\MGTools?
     
  5. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi,

    I did as you said and made the fixME.reg on desktop.
    However, it did not run.

    Gave the error : "REGISTRY EDITING HAS BEEN DISABLED BY YOUR ADMINISTRATOR".

    Funny thing, though, it did not even let me press "OK" on that dialog box. The dialog box (The one containing the aforementioned error) closed within 2-3 seconds.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    keoeiv5cyseeyeai
    
    File::
    c:\windows\system32\doozi.exe
    
    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableTaskMgr"=-
    "DisableRegistryTools"=-
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableRegistryTools"=dword:00000000
    "DisableTaskMgr"=dword:00000000
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Can you now run C:\MGTools.exe?
     
    Last edited: May 11, 2011
  7. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi,

    I used that script to run ComboFix as you had asked.
    Here are the results:

    Attempt 1: About midway during the 15th or 16th stage, The computer hangs and shows up a BSOD.

    The computer restarts automatically after dumping physical memory or something (when the count reached 100).
    I tried to take a snap of the BSOD but my cellphone decided to run out of battery at that precise moment. FML.
    However, when it restarted it gave the "Windows recovered from a critical error" and below is the related information:

    Error Signature:
    BCCode : 1000008e BCP1 : C0000005 BCP2 : BF8062A7 BCP3 : A780BB64
    BCP4 : 00000000 OSVer : 5_1_2600 SP : 2_0 Product : 256_1

    The following files will be included in the report:
    C:\DOCUME~1\UserXP\LOCALS~1\Temp\WER5775.dir00\Mini051211-01.dmp
    C:\DOCUME~1\UserXP\LOCALS~1\Temp\WER5775.dir00\sysdata.xml


    Attempt 2: I ran the ComboFix with that script again. This time no BSOD. Ran smoothly and produced a log. Attached below is that same log.

    Still, I cannot run MGTools. It gives the same error as before. "Registry editing has been disabled by your administrator".
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's run it again and see if it works:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableTaskMgr"=-
    "DisableRegistryTools"=-
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableRegistryTools"=dword:00000000
    "DisableTaskMgr"=dword:00000000
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Let me know what happens and attach the new log. ;)
     
  9. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi,

    I ran the scan again with the same script.
    Here is the log.

    All the problems I mentioned earlier are still there including MGTools issue.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there, let's try and dig a bit deeper.

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    kfdfuamd
    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableTaskMgr"=-
    "DisableRegistryTools"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Run this and attach the results.

    Using ESET's Online Scanner
     
  11. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi,

    Sorry for replying a bit late.

    I am facing a problem. The link of TDSSKiller that you gave is not working. I tried to google the removal tool, and still any Kaspersky link would not open.
    Even the Kaspersky site wouldn't open.

    So, I googled for the exe file of this tool and found a Mediafire Link. I downloaded it and tried running it.

    On the first screen, the only option under “Objects to Scan” visible was “Services and Drivers”. The other option “Boot Sectors” was not appearing. So, I decided not to run this version (2.4.0.0).

    Then, I tried googling more for this tool and strangely at least 10 sites came up from where I could download it. Funnily, though, I could not download this tool from ANY ONE of those sites. It just won’t start the download and hang up.

    I think there is something fishy going on here.

    As this was the first step in your solution, I did not proceed further (to run Combofix or OTL).

    Looking forward to further assistance on this issue.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It worls for me, I wonder if malware is perhaps blocking it. Try again using a different browser, or use another computer to get what we need onto the sick computer. Downloading from other strange sites is certainly not advisable.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have a problem, try the below link instead:

    TDSSK
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nice one Chas.
     
  15. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi Guys,

    Thanks for the support.

    I did as directed and downloaded and ran TDDSKiller. IT did not produce any errors and the log is attached below.

    Next, I ran Combofix with you script. It also ran smoothly and the log it produced is below.

    Then, I ran OTL which ran error free also. The logs are below.

    Finally, I ran those Dos Commands you had written.
    The first two ran smoothly. Here is its result:

    -------------------------------------------------------------------

    Running scan with ShowNew.bat - (c) 07/01/2006 By Chaslang

    ************************** WARNING **************************
    If you see a popup saying that:

    SteelWerX WhoAmI application has stopped working

    do not click the Cancel button that first appears. Wait for
    the Close program button to appear and click it to continue
    ************************** WARNING **************************

    Scanning please Wait.
    ============= Finding copies of actxprxy.dll ============= Please be patient
    ============= Finding copies of atapi.sys ================ Please be patient
    ============= Finding copies of beep.sys ================= Please be patient
    ============= Finding copies of csrss.exe ================ Please be patient
    ============= Finding copies of ctfmon.exe =============== Please be patient
    ============= Finding copies of eventlog.dll ============= Please be patient
    ============= Finding copies of explorer.exe ============= Please be patient
    ============= Finding copies of kernel32.dll ============= Please be patient
    ============= Finding copies of lsass.exe ================ Please be patient
    ============= Finding copies of netlogon.dll ============= Please be patient
    ============= Finding copies of powrprof.dll ============= Please be patient
    ============= Finding copies of proquota.exe ============= Please be patient
    ============= Finding copies of regedit.exe ============== Please be patient
    ============= Finding copies of scecli.dll ============= Please be patient
    ============= Finding copies of services.exe ============= Please be patient
    ============= Finding copies of spoolsv.exe ============== Please be patient
    ============= Finding copies of svchost.exe ============== Please be patient
    ============= Finding copies of tcpip.sys ================ Please be patient
    ============= Finding copies of tcpip6.sys =============== Please be patient
    ============= Finding copies of termsrv.dll ============== Please be patient
    ============= Finding copies of userinit.exe ============= Please be patient
    ============= Finding copies of user32.dll =============== Please be patient
    ============= Finding copies of wininit.dll ============== Please be patient
    ============= Finding copies of winlogon.exe ============= Please be patient
    ============= Finding copies of ip6fw.sys ================ Please be patient
    ============= Finding copies of ndis.sys ================= Please be patient
    ============= Finding copies of ntfs.sys ================= Please be patient
    ============= Finding copies of ws2_32.dll ============== Please be patient

    Checking for .COM files to Delete. They will only print if deleted!
    The system cannot find the file specified.
    Listing COM, DLL, EXE, and SYS file in C:\WINDOWS
    Locating COM files in C:\WINDOWS\system32 - recursive
    Locating DLL files in C:\WINDOWS
    Locating DLL files in C:\WINDOWS\system32 - recursive
    Locating EXE files in C:\WINDOWS
    Locating EXE files in C:\WINDOWS\system32 - recursive
    Locating SYS files in C:\WINDOWS
    Locating SYS files in C:\WINDOWS\system32 - recursive
    adding: newfiles.txt (188 bytes security) (deflated 79%)
    adding: ffdata.txt (188 bytes security) (deflated 76%)
    adding: winfiles.txt (188 bytes security) (deflated 88%)


    -----------------------------------------------------------------

    However, the third command "GetRunKey" threw the same error "Registry Editing has been disabled by your administrator" atleast 10 times.

    Also, I tried running the ESET Online scanner but, strangely, this link also did not work. I am able surf other sites easily. But when it comes to opening AV sites, there's something bizarre happening. Kaspersky site was also not opening. Same is happening with eset. :banghead

    I am getting a BIT worried now. :(
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the Image textbox. Do not include the word Code

    Code:
    :otl
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
      :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    Run OTL again like you did in post # 10.

    Attach the logs.

    Now rename MGTools.exe to jumping.com and try and run it again.
     
  17. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi,

    I ran OTL with admin rights and the code snippet you gave.
    It worked fine and the log is attached below (named OTL-withcode.txt).

    Then I ran OTL normally and the logs are attached below too. I am not able to attach the extras.txt as it says that you have attached it before in the same page. I guess, that both the Extra.txt must be same.

    As suggested further, I changed the name of "MGTools" to "jumping.com".
    It again gave the same error "Registry editing has been disabled by your administrator".

    But, this time I cliked OK as many times as the dialog box popped up (maybe like 20-25 times).

    And, voila! It produced a log report. It is attached below with the name "MGlogs.zip"
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have some bad news I am afraid. :(

    The reason we are having a problem fixing this is apparent in the runkeys.txt log which is part of MGtools. Registry editing and also Task Manager will be constantly getting disabled which is due to the Sality infection you have. This can be seen by the below seen your system.ini file.

    [MCIDRV_VER]
    DEVICEMB=1689560948906


    For additional info, see W32/Sality.ai also see the below. There are many forms of Sality:

    Virus:Win32/Sality.R

    Virus:Win32/Sality.AT

    These types of infections frequently require a reinstall to properly removal all traces and to fix the damage it causes.

    You can try the below tools but I have never seen them work properly:

    http://free.avg.com/us-en/win32-sality

    http://support.kaspersky.com/viruses/solutions?qid=208279889
     
  19. rachitsaran1987

    rachitsaran1987 Private E-2

    Hi,

    Thanks for all the support.

    The antiviruses you suggested didn't work.
    I am kinda regretting not scanning that flash drive. :banghead
    I guess, I would have to re-install Win XP.

    Also, as you know my system isn't very high-end. And hence I refrain from using any AVs, as they slow the system down. Could you suggest me a good and effective AV / Malware Scanner?
     
    Last edited: May 16, 2011
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Sorry that I had to be the bearer of bad news, but no antivirus = sality infections amongst many other nasties. :( You have 2 GB RAM, I used to use AV with just 1 gig. If you continue to surf without antivirus after you reinstall windows, then you are only going to end up here again and sometimes people have been refused help if they STILL have no AV.
    I use avast personally, but you can further discuss this in the software forum and see what others opinions are. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds