Problems with registry

Discussion in 'Malware Help (A Specialist Will Reply)' started by devolic, Apr 5, 2006.

  1. devolic

    devolic Private E-2

    Hello and what a teriffic site.

    I went to install a game that I just bought and low and behold, this is what I received.

    16 bit ms-dos subsystem
    c:\windows\system32\regedit.com
    The NTVDM CPU has encountered and illegal instruction.
    CS:054d IP:0102 OP:ff ff 83 3e 51 Choose ‘Close’ to terminate the application


    I actually had to manually close out the program as it locked.
    I also notice that some of my favorites are screwy at times w/ different characters.

    I have followed all 6 steps in the order as mentioned.
    Everything except the 2 scanners passed.

    However, I could not run panda in safe mode.
    I had access to it, but the scanner was off the screen by 90%.
    I tried to resize and couldn't get anywhere.
    That was the first with this 21" monitor.

    Appreciate,
    Doug
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to uninstall Viewpoint Manager as indicated in step 0 of the READ & RUN ME.

    Also look in C:\windows\system32 and tell me all the files you see that end with a .com extension. Sorting the folder view by type will make that easier. Tell me all filenames and the filesizes. DO NOT do anything other than telling me what you find. However, you can delete regedit.com if found since it is not valid. Only regedit.exe is valid.
     
  3. devolic

    devolic Private E-2

    Here you go sir.

    Ya, I guess I missed that one
    I had a few Viewpoint things in there.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below four files:
    tracert.com 1KB
    tasklist.com 1KB
    ping.com 1KB
    cmd.com 1KB

    Tell me which Win Xp OS you have. Is it Home, Media, or XP Pro?
    Now check if the below files exist and what their file sizes are. (Just check for them! These are valid files!)
    cmd.exe
    ping.exe
    tasklist.exe
    tracert.exe

    Exit ALL browers and delete the below:
    C:\Documents and Settings\Doug\Local Settings\Temp <--- delete all files and subfolders in this Temp folder.
    C:\Documents and Settings\Raff\Local Settings\Temporary Internet Files\Content.IE5\M013TCBN\sp2-adtegrity-728[1].swf


    Question: Did you install the below:
    O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll

    Also do you know what the below service is for:
    O23 - Service: WPEServ - Unknown owner - C:\Program Files\Common Files\WPE\wpeserv.exe



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {B2B9F4C9-C584-F56F-421D-B2F284CD689F} - blank (file missing)
    O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - blank (file missing)
    O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - blank (file missing)
    O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - blank (file missing)
    After clicking Fix, exit HJT.

    How are things working now?
     
    Last edited: Apr 6, 2006
  5. devolic

    devolic Private E-2

    I have XP Home.
    I did not have tasklist.exe on my system
    At one point I did have Trellian, but not anymore.

    I also ran wpeserv.exe through google and didn't find out much. So I'm not to sure what that's about

    When I type regedit it does indeed go through now, but like every 5 mins or so I get a minimized window for like a second.

    It could be with all the stuff running when I go to use HJT.
    I usually don't run that much stuff at start-up so maybe I'm just not used to seing it.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not part of Home!

    It is still in your log! Thus it still seems to be installed.

    That is why I asked you what it is. Locate it and right click on it and see if you can get any Properties and Version info.

    I don't know wha you mean. Are you saying regedit minimizes every 5 minutes?

    I don't follow what you are trying to tell me.
     
  7. devolic

    devolic Private E-2

    regedit it self is not what is minimizing.
    Something appears minimized on the taskbar for a brief moment, not sure what it is though. I usually don't run that much stuff at start-up so it may be one of them. I haven't turned them off since running HJT. So I was just saying that maybe one of those programs can be causing it, and I'm just not use to seeing it, that's all
     
  8. devolic

    devolic Private E-2

    I went to HJT and it did not give any info on wpeserv
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's not how you get Properties and Version information. HijackThis has nothing to do with this.

    Locate C:\Program Files\Common Files\WPE\wpeserv.exe using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  10. devolic

    devolic Private E-2

    Copyright 2003
    File Version 1.0.0.1
    Internal Name WPEServ
    Product Name WPEServ Module
    Product Version 1.0


    That's all I could get
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never complete the steps from the Read Me properly!!!!
    Your Ad-Aware Version has not been used for more than a year! Please uninstall your outdated Ad-Aware 6 and download, install, and update the proper version from the link given in the READ & RUN ME!

    Use the below online file scanner to check out the C:\Program Files\Common Files\WPE\wpeserv.exe file!

    http://virusscan.jotti.org/

    Let me know what it finds.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
    O2 - BHO: (no name) - {B2B9F4C9-C584-F56F-421D-B2F284CD689F} - blank (file missing)
    O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - blank (file missing)
    O3 - Toolbar: ToolbarBrowser - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
    O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - blank (file missing)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - blank (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\TRELLIAN <-- the whole folder
    C:\Program Files\Instant Buzz <-- the whole folder

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Apr 7, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds