registry question PLEASE

Discussion in 'Malware Help (A Specialist Will Reply)' started by bbolin06, Jul 22, 2006.

  1. bbolin06

    bbolin06 Private First Class

    I just installed my 80 gb hard drive and reinstalled xp pro now I get this message when I get on line.I keep getting a scan critical system errors message. It tells me to go to regdoc32.com or registyrcleanergold.com or regdoc.com or correctreg.com and download a registry repair and run it.These messages pop up one after another. But it wants me to pay to download it. Is there a way I can fix this with out having to fork out money?????? Signed broke As always thanks in advance

    win xp pro
    128 mbs of memory
    80 gb hard drive
    pent. 3
    Toshiba dvd-rom sd-c2402
    External Benq cdrw
    ATI RAGE MOBILITY-P video card
    dell inspiron 5000 laptop
     
    Last edited by a moderator: Jul 22, 2006
  2. matt.chugg

    matt.chugg MajorGeek

    You have some form of spyware on your system.

    Welcome to MajorGeeks :)

    -- Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
    Last edited by a moderator: Jul 22, 2006
  3. bbolin06

    bbolin06 Private First Class

    I did all the steps and still keeps doig it. Here is my Highjack this log. Thank you for your help
     

    Attached Files:

    Last edited by a moderator: Jul 23, 2006
  4. matt.chugg

    matt.chugg MajorGeek

    Please post all the logs requested.


    Why is that a word document? Post the logs as they are produced either as a .txt file or .log file. Word documents can contain macros and viruses, since you are allready infected with something I am not going to open that document.
     
  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    You really do need to follow the steps closely as HJT while good is not the fix all application many think it is, which is why we have you run this one last, you need to run through the guide as posted above by Matt again and install the requested software and run the online scans ( Panda and Bitdefender ) which we also request logs from.

    HiJackThis also needs to be run from Normal mode to give us a full picture of whats installed, your log is from Safe mode.


    As your not fully upto date with XP Service Pack 2, it seems as if you may have messenger service running which some spyware uses to try and infect your PC by poping up alert boxes that resemble ligitimate system alerts, just double check that the messenger service is disabled, to do this a few routes are available, ( messenger service is not your instant messenging software as in Yahoo or MSN but a tool used by network admins to issue alerts but sadly was exploited by spammers and malware groups to infect your PC, this service was disabled once SP2 was installed )

    1. Download and run Shoot the Messenger a nice small app from Steve gibson.

    2. The manual way....
    Click Start > Settings > Control Panel > Administrative Tools > Services > scroll down to Messenger and highlight > Right Click and choose Properties > click Stop > then under the Startup Type dropdown menu pick Disable > OK


    But you really need to update to SP2 and install any new updates from MS, you should also install some malware protection in Antivirus, Firewall and Antispyware apps before going online , this guide will help in that area How to Protect yourself from malware! ( the majority of the applications in that guide are free as I dont have any paid for security software on my PC as they do the job fine in keeping me malware free )
     
    Last edited: Jul 23, 2006
  6. bbolin06

    bbolin06 Private First Class

    Here is the log that hjt made

    Edit: deleted inline log
     
    Last edited by a moderator: Jul 23, 2006
  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Please do run through the steps as outlined by Matt in this post http://forum.majorgeeks.com/showpost.php?p=819227&postcount=2

    I know the guide may look long and tedious, but its designed to help remove the malware from your PC, if its not followed fully its hard for us to help you remove the pests.

    Your Hijack this log is still from Safe Mode, we do need it from Normal Mode and not attached in the way described, hijack this automatically creates a TXT file that you can attach to your post as described in the guide.

    but also run the steps to disable Messenger I mentioned in this post http://forum.majorgeeks.com/showpost.php?p=819481&postcount=5
     
  8. bbolin06

    bbolin06 Private First Class

    I did all the steps last night and it is still doing it. I also turned off the messanger this morning and it stopped it from popping up but did that delete the problem or just cover it
     
  9. matt.chugg

    matt.chugg MajorGeek

    I Need these logs before we can continue.
     
  10. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    It will have removed the popups ( by disabling the messenger service ), completly as that route for malware is now closed, but did you click any of them? plus as your running an older version of XP in SP1 you may have more malware installed, so as Matt said above we do need to see your logs and per the guide.

    Sorry to keep harping on about following the guide but all we wish to achieve is you to have a clean PC and a malware free surfing experience :)

    You last HJT log was still incomplete ( their were no indications Microsoft Defender or the Panda and Bitdefender scans were run ), are you running it from safe mode? or are you using msconfig or another startup manager to disable startups.. if so stop using them as we need to see a full list of whats running.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds