Setareh Posted June 3, 2006 Report Share Posted June 3, 2006 hi everyone ,in start/RUN... when i type regedit or msconfig & press the button run they don't run or sometimes they show up for a few seconds which u can't do anything .i can't run regedit.exe from C:\WINDOWS and can't run regedt32 from C:\WINDOWS\system32 .but when i'm in safemode all of them open .i downloaded HJK , but it doesn't open too . Please Help Me ,Setareh Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 3, 2006 Report Share Posted June 3, 2006 You don't say what operating system you are running.. I will assume it is XP, do you have any anti virus programs installed??Download Ewido from ]hereI suggest you boot into safe mode with networking see here for instructions and then run an Ewido scan and online Panda scanEwido Trojan ScannerInstall, and update the NEW free version of Ewido trojan scanner:When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.From the main ewido screen, click on update in the left menu, then click the Start update button.After the update finishes (the status bar at the bottom will display "Update successful")Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.If ewido finds anything, it will pop up a notification. Select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.Please go to Panda Active ScanOnce you are on the Panda site click the Scan your PC button - A new window will open...click the Check Now button - Enter your Country - Enter your State/Province - Enter your e-mail address and click send - Select either Home User or Company - Click the big Scan Now button - If it wants to install an ActiveX component allow it - It will start downloading the files it requires for the scan (Note: It may take a couple of minutes) - When download is complete, click on Local Disks to start the scan- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Boot back to normal mode and see if you can run hijackthis, Post the contents of the Panda scan report, the Ewido log and a HijackThis Log. Quote Link to comment Share on other sites More sharing options...
jason.b.c Posted June 3, 2006 Report Share Posted June 3, 2006 C:\WINDOWS\system32 .Well lets see, He's definately not running anything below Win 2000 thats for sure.. ;) Now have you used msconfig and regedit before.??Because i was going to say, Win 2000 dosen't have msconfig in it by default, You have to download it.. ;) Quote Link to comment Share on other sites More sharing options...
Setareh Posted June 3, 2006 Author Report Share Posted June 3, 2006 i have windows XP sp1.i had runned msconfig & regedit before Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 3, 2006 Report Share Posted June 3, 2006 Now have you used msconfig and regedit before.??Msconfig and Regedit work quite well on the W98 boxes that I have had!!Setareh, can you follow my instructions in my previous post and then get back to me please. Quote Link to comment Share on other sites More sharing options...
cozofdeath Posted June 3, 2006 Report Share Posted June 3, 2006 Yeah follow nellies instructions, because it sounds like something is keeping you from looking at your startup files. If you can access regedit and msconfig in safe mode, you should check out your startup files. Quote Link to comment Share on other sites More sharing options...
jason.b.c Posted June 4, 2006 Report Share Posted June 4, 2006 Msconfig and Regedit work quite well on the W98 boxes that I have had!!Oh i know they work, All i was saying was that system32 isn't a part of Win 9x that i've ever heard of.And that you'll usually only find that in Win 2000 or newer. ;) Quote Link to comment Share on other sites More sharing options...
Setareh Posted June 5, 2006 Author Report Share Posted June 5, 2006 hi . nelliei could run HJT from safemode then i did that and i got a log & send it to hijackthis site and it showed me which files are nasty . then i fixed them . but my problem didn't solvethen i did what u said , i scanned my computer with ewido & panda , & i got their reportsthen i scanned my pc with HJT again . now i can run regedit , msconfig & ...thank you so much for ur advice .i couldn't attach this then i copied it : ( HiJackThis )Logfile of HijackThis v1.98.2Scan saved at 01:05:34 ?.?, on 2006/06/06Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeD:\Program Files\ewido anti-malware\ewidoctrl.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\WINDOWS\System32\nvsvc32.exeD:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exeC:\WINDOWS\System32\svchost.exeD:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXEC:\WINDOWS\Explorer.EXED:\Program Files\Panda Software\Panda Antivirus Platinum\apvxdwin.exeC:\WINDOWS\System32\RUNDLL32.EXEC:\WINDOWS\System32\rundll32.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Google\Google Talk\googletalk.exeD:\Program Files\Yahoo!\Messenger\ymsgr_tray.exeD:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exeD:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exeD:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exeD:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exeD:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exeD:\Program Files\Panda Software\Panda Antivirus Platinum\IFACE.EXEC:\HJT\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR3 - URLSearchHook: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - D:\Program Files\Yahoo!\Common\YIeTagBm.dllO2 - BHO: Encarta Web Companion Helper Object - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLLO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLLO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=061206 serial=DR12CRS-9092362-GCK lang=ENO4 - HKLM\..\Run: [sCANINICIO] "D:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"O4 - HKLM\..\Run: [APVXDWIN] "D:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /sO4 - HKLM\..\Run: [Corel Reminder] "D:\Program Files\Corel\Graphics10\Register\NAVBrowser.exe" /r /i "D:\Program Files\Corel\Graphics10\Register\NavLoad.ini"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Program Files\D-Tools\daemon.exe" -lang 1033O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,SO4 - HKLM\..\Run: [NT Logging Service] syslog32.exeO4 - HKLM\..\Run: [Microsoft System Checkup] libsys32.exeO4 - HKLM\..\RunServices: [Microsoft System Checkup] libsys32.exeO4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quietO4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostartO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [RealPlayer] "D:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBootO4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: hp psc 1000 series.lnk = ?O4 - Global Startup: hpoddt01.exe.lnk = ?O8 - Extra context menu item: &Yahoo! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Program Files\Yahoo!\Common/ycdict.htmO8 - Extra context menu item: Yahoo! &Maps - file:///D:\Program Files\Yahoo!\Common/ycmap.htmO8 - Extra context menu item: Yahoo! &SMS - file:///D:\Program Files\Yahoo!\Common/ycsms.htmO9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLLO9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLLO9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htmO9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htmO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabScan_report_20060605.txt.txtPanda.txt Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 5, 2006 Report Share Posted June 5, 2006 jason.b.c... I see what you mean, point taken!! Setareh, your log tells me you have some major problems..but first of all... stay away from those automated hijackthis sites, they are dangerous. Do you know what you fixed????? As a matter of interest I ran my clean log through one of those sites and it flagged up a perfectly legitimate program as a trojan. You are using an out of date version of hijackthis, can you delete the copy that you have and replace it with v1.99.1 from one of the mirrors listed here and then post a fresh log. I suggest you stay off the internet as much as possible until we get you cleaned uphttp://forums.windowsforum.org/index.php?showtopic=17544 Quote Link to comment Share on other sites More sharing options...
jason.b.c Posted June 5, 2006 Report Share Posted June 5, 2006 jason.b.c... I see what you mean, point taken!!"K" :D , I was just kinda worried that maybe you thought i was trying to be rude. ;) It's funny how other windows systems are built so differantly.. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.