Trouble with task manager and regedit

Discussion in 'Malware Help (A Specialist Will Reply)' started by samcoffeeman, Oct 20, 2005.

  1. samcoffeeman

    samcoffeeman Private E-2

    Hey I recently have been having problems with my poor computer. My task manager will not come up and when I try to get to the registry editor it opens up a command window and then I get a message with something that says "The NVDM CPU has encountered an illegal instruction. CS:054c IP:9c3f OP:0f 04 00 10 04 Chhose close to terminate the application." I just realized it is regedit.com and not the correct program, I did not delete that yet. But still the task manager confuses me. I did have a worm WORM_VB AS(Trend Micro), which should be cleared now. Also when I ran Spybot S&D I came across an error involving hijackers.sbi? It said to check the include errors log for details but I couldn't figure out what that meant(Where that log is). I am including my HJT log if you would please take a look and "Give me sight...beyond sight" like the great sword of omens I would greatly appreciate it.
    Samcoffeeman
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below. Make sure your follow ALL the steps and also make sure HJT is installed and run properly. You must not use msconfig to disable startups as you are doing. The procedures will mention this and tell you how to set it properly.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  3. samcoffeeman

    samcoffeeman Private E-2

    Yes you were right, I did not go into safe mode correctly, I reran all the spy programs, adaware spybot, microsoft antispyware, ccleaner. Nopthing came up major this time. Still had the problem wiht the hijackers.sbi thing on spybot. I restarted in normal mode and ran HJT. I sitll can't get my task manager to come up and the regedit.com is still there. I am guessing I should delete that regedit.com. I attached my HJT log, take a peek at it for me?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothings major in you HJT log! Just some minor things you can have HJT fix:

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - (no file) (HKCU)

    Then exit HJT.

    Use Windows Explorer to look in c:\windows\system32 and sort the folder by Type. Now looks for all the files that end with .com . They will be grouped as type MS-DOS Application.
    Tell me the names of the files you see and also give me their file sizes in bytes. Do not give me what shows in the Explorer window. Right click on each file and select Properties and then get the likes this:

    Size: 9.00 KB (9,216 bytes)

    Also get the Created and Modified Dates. Like this: Thursday, August 29, 2002, 7:00:00 AM

    Also do you see regedit.exe and taskmgr.exe in this folder (sort by names to more easily find).
     
  5. samcoffeeman

    samcoffeeman Private E-2

    Task manager has been revived!
    Looks like it is pretty obvious which files are the problem. I found taskmgr.exe but not regedit.exe, only reg.exe and regedt32.exe.That leaves the question what are the files from and is there any invisible damage?
    I am going to run a google search to see what I find.
    Here is the info you asked for:
    Name: SIZE: CREATED: MODIFIED:
    CHCP.COM 7680b 8/29/02 7am same
    cmd.com 2b 10/18/05 12;31;15a 10/19/05 4;51;32p
    COMMAND.COM 50620b 8/29/02 7am same
    DISKCOMP.COM 9216b 8/29/02 7a same
    DISKCOPY.COM 7168 " "
    EDIT.COM 69886b " "
    FORMAT.COM 25600 " "
    GRAFTABL.COM 26112 " "
    GRAPHICS.COM 19694 " "
    KB16.COM 14710 " "
    LOADFIX.COM 1131 " "
    MODE.COM 19456 " "
    MORE.COM 15872 " "
    netstat.com 2 10/18/05 12;31;14a 10/19/05 4;51;32p
    ping.com 2 " " " "
    regedit.com 2 " 12;31;15a " "
    taskkill.com 2 " " " "
    tasklist.com 2 " " " "
    tracert.com 2 " " " "
    TREE.COM 11264 8/29/02 7am 8/29/02 7 am
    WIN.COM 18432 " "
     
  6. samcoffeeman

    samcoffeeman Private E-2

    Sorry they all got squished together when I posted but it is all the lower case ones that were created around the same time that are the problem. They are all 2 bytes in size. All of the others(originals) created august 29 02 7am.
     
  7. samcoffeeman

    samcoffeeman Private E-2

    It looks like those files are remnants of the WORM_VB AS virus I had removed by TrendMicro. The virus drops those specific files in along with winupdates.exe which I found during my exploration. I am surprised the program did not delete them, I am guessing I should but wanted to consult you first.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you should delete them but you need to get proper copies of the EXE versions back if they are missing. And as you saw, the below are the ones that you need to make sure still exist and run;
    • CMD.EXE
    • NETSTAT.EXE
    • PING.EXE
    • REGEDIT.EXE
    • TASKKILL.EXE
    • TASKLIST.EXE
    • TRACERT.EXE
     
  9. samcoffeeman

    samcoffeeman Private E-2

    Thanks for all your help. Enerything seems to be working well. I never found regedit.exe but i think it is the same as reg.exe because hwen I run regedit the editor comes up now. I'm goin to google the hijackers.sbi thing I had with spybot too see what that is all about.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just do the following exactly as written:
    - uninstall Spybot
    - reboot your PC
    - look for the Spybot folder (the default is normally C:\Program Files\Spybot - Search & Destroy ) ad delete the Spybot - Search & Destroy folder.
    - Now reinstall Spybot, update, and do a new scan.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds