Completed Procedures, Help Appreciated

Discussion in 'Malware Help (A Specialist Will Reply)' started by CompuTed, Dec 29, 2005.

  1. CompuTed

    CompuTed Private E-2

    Am new to Major Geeks. I have run all the recommended procedures according to instructions here and still have a problem that I have seen addressed here before. My task manager won't open ( I just get an error message saying that it has encountered a problem and has to close). Have also installed the registry keys from kellys-korner and that didn't help. Have attached the "hijack this log" here... http://forum.majorgeeks.com/showthread.php?p=708984#post708984

    Any help greatly appreciated. Thanks.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Maybe best to run another newer HJT log and attach in this thread to be upto date, your other thread is now locked to new posts as not to confuse any issues, as the guys in this forum have set procedures to follow.

    Cheers :)
     
  3. CompuTed

    CompuTed Private E-2

    Thanks for the advice here. I have run a new HJT log file and attached it.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's!

    You have not attached the logs from BitDefender and Panda as required by step 6 of the READ ME.

    Please look in c:\windows\system32 for taskmgr.exe and if found tell me the filesize and date.
     
  5. CompuTed

    CompuTed Private E-2

    The file C:Windows/System32/taskmgr.exe is 132 KB in size. It was created on August 23, 2001 and modified on August 4, 2004.

    The BitDefender and Panda logs are attached.

    Thanks Much!!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please give the exact word for word error message and number (if any) that you get when trying to run Task Manager. Also double check the folder again an tell me if you see any files with similar names to taskmgr.exe like in particular taskmgr.com.

    Make sure viewing of hidden and system files and extensions is enabled.

    Did you look in add/remove prorgams for eGroup and uninstall if found?

    Did you add the below Proxy Server line:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212

    Use HJT to fix the below lines:
    R3 - Default URLSearchHook is missing
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/117a2f29f43b44fe2d00/netzip/RdxIE601.cab
     
    Last edited: Dec 29, 2005
  7. CompuTed

    CompuTed Private E-2

    The exact error message I get is..." Window TaskManager has encountered a problem and needs to close. We are sorry for the inconvenience." There is no number showing. Of course, there is also the option to send an error report to Microsoft and view addsitional technical info.

    There is a file in the same folder called taskman.exe, but nothing else. I searched for other taskmgr.exe files on the computer and found several...under folders C:/I386, C:/Windows/ServicePackFiles, etc. Double clicking these DOES bring us taskmanager but double clicking the one under system32 does not. I recall yesterday that double clicking on some of these other files did not work, only brought up the error message as well. Don't know if that helps, but I will follow the rest of your instructions and psot answers shortly. Thanks.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the one from C:\Windows\ServicePackFiles to your c:\windows\system32 folder and overwrite the problem one.

    Then try pressing CTRL-SHIFT_ESC to see if Task Manager comes up.

    You did not comment on the other items in my previous message.
     
  9. CompuTed

    CompuTed Private E-2

    Also, I do not have the program eGroup installed nor did I ever to my knowledge.

    I did not add the Proxy Server line that you referenced under R1...

    The environment I have here is that this computer is part of a home network. There are two other machines in the house wired into the home network and two other laptops access through a wireless network.

    I will go ahead and run hijack and allow it to fix the items you spelled out.
     
  10. CompuTed

    CompuTed Private E-2

    Just saw your last message. Will go ahead and copy the service pack file and see if that works before running the hijack fix. Thanks.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Fix those lines anyway and add the below R1 line to the fix list (as long as you are sure it is not something you need. Like for C:\Program Files\Common Files\Symantec Shared\ccProxy.exe)
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212
     
  12. CompuTed

    CompuTed Private E-2

    I copied the service pack taskmgr file to the system32 and both CTRL-SHIFT-ESC and CTRL-ALT-DEL work fine. Thanks. Should I go ahead with the Hijack fixes you recommended?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! See msg # 11 below.
     
  14. CompuTed

    CompuTed Private E-2

    I went ahead and made 4 of the 5 hijackthis changes you recommended. On re-boot, I got an error message...error loading NvQTwk. Don't know what that is...Other than that, everyting seems to be working fine. Taskmanager continues to work fine as well.

    Thanks a million for your time and help. Wish there was a way to re-pay. Do you do this as a hobby?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  16. CompuTed

    CompuTed Private E-2

    The only file I didn't fix was
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212

    I will probably go ahead and fix it today with a back-up. I just don't have any idea what it might be for. Thanks again for all your generous help.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! HJT will back it up when you fix it with HJT.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds