Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Can't Access Taskmgr, Regedit, Safemode, Antivirus, etc.


  • Please log in to reply
3 replies to this topic

#1 chasing

chasing

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 03 April 2009 - 07:01 AM

Hey all,

I'm in desperate need of help.

About two days ago, I used my friend's flash disc in my laptop (IBM, OS: Win XP home edition). Upon inserting the USB device, my AV (Norton, 2004 version) immediately alerted me of a virus in the flash disc (unfortunately I didn't catch the name, but the file was jged.exe triggered by an autorun). A few minutes later, my computer rebooted by itself.

At first I thought nothing was wrong since everything was working fine. Then I tried to use the task manager to close a program and was surprised to find out that it was "disabled by the admin". I searched around the net for a fix for this, and found a solution through regedit. To my surprise, regedit is also disabled.

I checked the web and found out that viruses can do this. So I tried to access my Norton, but it won't open (nothing happens, not even an alert message). I tried to access an online scanner, but nothing happens as well (screen doesn't load). So I followed another advise from the net to enter in safe mode, but every time I try to, the screen goes blue saying Windows has encountered an error then switches back to booting normally.

Tinkering around, I also noticed that my firewall was turned off (even if I turned it on, restarting causes it to switch back to being off). I also have trouble unhiding folders (somehow, it reverts back to being hidden).

I managed to access the regedit using the gpedit.msc plus some other command I found on the net. I deleted the regkeys that enable/disable these functions, but somehow, after a few seconds, it returns. I also managed to find .exe files hidden in my computer using processexplorer, but everytime I restart, these randomly named .exe files just keep reappearing.

I download Superantispyware and malwarebytes. Both programs detected malwares and removed then, but after restart, the malwares are back.

Well, that's about it. I don't know what else to do.

Thanks in advance for any help. :thumbsup:

BC AdBot (Login to Remove)

 


#2 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:01 AM

Posted 06 April 2009 - 01:01 AM

Try this scan. If you can't get into Safe Mode run it in Normal Mode.

Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet.

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on drweb-cureit.exe to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the Virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All.
  • When complete, click Select All, then choose Cure > Move incurable.
    (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • Now put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and UNcheck "Heuristic analysis" under the "Scanning" tab, then click Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • When the scan is complete, a message will be displayed at the bottom indicating if any viruses were found.
  • Click "Yes to all" if asked to cure or move the file(s) and select "Move incurable".
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#3 velvetgal

velvetgal

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:01 AM

Posted 17 April 2009 - 03:05 AM

Hello everyone..I desperately need help..
so many thing happened weird with my pc.
The infected pc are not connected with internet, so I'm guessing it came from other people flashdisk/removable disk
Well,I have almost the same problem with chasing..However mine is more weird.. T_T
regedit and my task manager is disabled by the administrator..I already use tuneup software to go to the regedit and task manager to change the policy in it, but after I change it, it will restore itself.
I also already went to gpedit.msc 2 disable changing, using rrt tool to remove restriction not to be able to open regedit and task manager..
I use avg 8 to scan..but then again,the avg keep pooping a lot of warning saying that some of my .exe files is becoming infected..I can't run the .exe
Not only that, when my friend plug in the flaskdisk, the icon turn out 2 be a folder..usually it will appear as the hard disk icon
Yet,when I try to view hidden files using the folder option, it keeps coming back to "do not show hidden files".
For this problem, I already use unhookexec.inf to show back the hidden files and its not working.
So pleassee help me..2 of my pc office is infected..one of them can't even go into windows now..saying that no device is 2 be found even though everything is connected
Manny many thanks in advance :thumbsup:

#4 velvetgal

velvetgal

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:01 AM

Posted 17 April 2009 - 03:14 AM

Hello everyone..I desperately need help..
So many thing happened weird with my pc.
The infected pc are not connected with internet, so I'm guessing it came from other people flashdisk/removable disk
Well,I have almost the same problem with chasing..However mine is more weird.. T_T
regedit and my task manager is disabled by the administrator..I already use tuneup software to go to the regedit and task manager to change the policy in it, but after I change it, it will restore itself.
I also already went to gpedit.msc 2 disable changing, using rrt tool to remove restriction not to be able to open regedit and task manager..
I use avg 8 to scan..but then again,the avg keep pooping a lot of warning saying that some of my .exe files is becoming infected..I can't run the .exe
Not only that, when my friend plug in the flaskdisk, the icon turn out 2 be a folder..usually it will appear as the hard disk icon
Yet,when I try to view hidden files using the folder option, it keeps coming back to "do not show hidden files".
For this problem, I already use unhookexec.inf to show back the hidden files and its not working.
So pleassee help me..2 of my pc office is infected..one of them can't even go into windows now..saying that no device is 2 be found even though everything is connected
Btw, is there any other link to download DrWeb-Curelt? I can't download it from my mobile device

Manny many thanks in advance :thumbsup:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users