Tech Problem Aggregator

Regedit, Task Manager closes immediately

Q: Regedit, Task Manager closes immediately

Regedit, Task Manager close immediately!
I've run Spy-Bot, AdAware, Norton 2004. Some forum questions are similar, but items they were asked to get fixed in their HijackThis logs are not listed in my logs.
(Someone in my house did recently click on an IM Message with a fake message, which then started propagating malicious fake away messages for my family member. I'm not sure if the Norton virus scan took complete care of the IM problem or not.)(I also installed Service Pack 2 a couple of weeks ago for my XP computer.)

Please Help!

Here is the HijackThis log:
Logfile of HijackThis v1.98.2
Scan saved at 12:14:49 PM, on 9/8/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\qggo.exe
C:\WINDOWS\system32\MSTFX.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VSdotNET\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\iwhr.exe
C:\Program Files\My Daily Horoscope\MyDailyHoroscope.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CashBack\bin\cashback.exe
C:\Program Files\NAVISearch\bin\nls.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\WINDOWS\System32\dllhost.exe
C:\unzipped\hijackthis\HijackThis.exe
C:\WINDOWS\SYSTEM32\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.metacrawler.com/info.metac.toolbar/dog/forms/search.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.metacrawler.com/info.metac.toolbar/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3DAB6C2E-9B65-249E-8776-6D557CDD2216} - C:\WINDOWS\system32\ovkmyt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\system32\nvms.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\system32\mscb.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ebtschg] C:\WINDOWS\System32\fyhnfom.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [szeqkxrpk] C:\WINDOWS\qggo.exe
O4 - HKLM\..\Run: [Microsoft Autofix Service] MSTFX.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [knvdy] C:\WINDOWS\iwhr.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\RunOnce: [Register C:\WINDOWS\system32\msbe.dll] "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\msbe.dll",DllRegisterServer
O4 - HKLM\..\RunOnce: [Register C:\WINDOWS\system32\nvms.dll] "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\nvms.dll",DllRegisterServer
O4 - HKLM\..\RunOnce: [Register C:\WINDOWS\system32\mscb.dll] "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mscb.dll",DllRegisterServer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MyDailyHoroscope] C:\PROGRA~1\MYDAIL~1\MYDAIL~1.EXE
O4 - HKCU\..\RunOnce: [Microsoft Autofix Service] MSTFX.EXE
O4 - Startup: Microsoft Office Shortcut Bar.Lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Metacrawler Cursor Search - C:\Documents and Settings\All Users\Application Data\Infospace\MetacrawlerToolbar\contextsearch.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: Yahoo! Canasta - http://download.games.yahoo.com/games/clients/y/yt1_x.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...71b0834b3328:522a1c137ec85ca995271ab95b94951b
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {43B70AAD-23F4-4FD8-ADD9-441D8592EEB8} (Snapfish Fix Photo Control) - http://www.snapfish.com/SnapfishImageEditor.cab
O16 - DPF: {5763F8E8-0DD7-4A0F-ADB0-9F64C8F2C349} (Pixami/Snapfish Upload UI Control) - http://www.snapfish.com/SnapfishUploader.cab
O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} (MaxisSuperstarTeleX Control) - http://thesims.ea.com/teleport/superstar/MaxisSuperstarTeleX.cab
O16 - DPF: {666DDE35-E955-11D0-A707-000000521958} - http://69.56.176.227/webplugin.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50038/QDow_AS2.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://cam.hi-ke.de:8080/activex/AxisCamControl.ocx
O16 - DPF: {A44B714B-EE0F-453E-9300-A69B321FEF6C} (MaxisSimsFamilyTeleX Control) - http://thesims.ea.com/teleport/families/MaxisSimsFamilyTeleX.cab
O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://autos.msn.com/components/ocx/autopricer/autopricer.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/budicon.cab
O16 - DPF: {EE2589EB-7FC8-44DB-A892-573F2C4B41E0} - http://pdf.forbes.com/forbesnews/triggernews/ForbesDownloaderSigned.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by2fd.bay2.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
Thanks for any help you can provide!!

A: Regedit, Task Manager closes immediately

Task Manager, MSCONFIG, or REGEDIT disappears while opening

3 more replies
Answer Match 108.78%

Im running Win XP Home and just started to encounter this problem. I just finished ad-aware/spybot/cswshredder/defragging/antivirus and any other little tricks of the trade i have picked up.....

Seems that when i try to open Task Manager it will only stay open for around two seconds, then just closes automatically....

Any help would be great ty.
 

A:Task Manager Closes Immediately

11 more replies
Answer Match 107.1%

This is about my cousin's computer. His task manager and regedit don't function correctly. Each closes immediately after they're opened. Here's the Hijack log. If you see anything, please help.Logfile of HijackThis v1.99.1Scan saved at 2:56:53 AM, on 1/3/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0011)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeC:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Trend Micro\Antivirus\Tmntsrv.exeC:\Program Files\Trend Micro\Antivirus\tmproxy.exeC:\WINDOWS\System32\wltrysvc.exeC:\WINDOWS\System32\bcmwltry.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\hkcmd.exeC:\Program Files\Java\jre1.5.0_08\bin\jusched.exeC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Intel\P... Read more

A:Task Manager And Regedit Close Immediately

Hi LorialoUpload this file ->C:\WINDOWS\system32\Volume.exe to VirusTotal and post results here, please

6 more replies
Answer Match 105%

I can't get either of them to work

I've run spybot and ad-aware and they've come up clean, but my task manager still closes right after I open it. Can someone help please?

Here is the log from HijackThis:

Logfile of HijackThis v1.98.0
Scan saved at 2:05:19 PM, on 7/28/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\microsoft\crypto\iroffer\spool.exe
C:\WINDOWS\System32\svchosting.exe
C:\WINDOWS\System32\wuam.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\exploirez.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\SYSCFG16.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\leon lai\Desktop\New Folder\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h... Read more

A:Task manager and Regedit closes automatically

16 more replies
Answer Match 105%

I am having the exact same problem and have been trying to fix it for the past two days..still no luck. Can anyone help me?

Logfile of HijackThis v1.98.2
Scan saved at 9:35:43 PM, on 10/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\QTIMER.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\TMobile\PwpUpdtr.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\Creative\SBLive\Diagno... Read more

A:Task manager and Regedit closes automatically

6 more replies
Answer Match 105%

please find the hijack this log below

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:06:27 PM, on 5/28/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\avupdate.exe
C:\WINDOWS&#... Read more

A:regedit task manager closes automaticaly

Hello jangoindian, Welcome to Bleeping Computer.
My name is fireman4it and I will be helping you with your Malware problem.

Please take note of some guidelines for this fix:
Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
In the upper right hand corner of the topic you will see a button called Watch Topic.I suggest you click it and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

Finally, please reply using the ADD REPLY button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.1.Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
Vista/Windows 7 users right-click and select Run As Administrator.If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give i... Read more

7 more replies
Answer Match 103.74%

MY REGISTRY EDITOR, TASK MANAGER AND MSCONFIG OPENS BUT QUICKLY CLOSES... I COPIED A LOG OF HIJACK THIS... I HOPE SOMEONE CAN HELP ME.. THANKS...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:39:28 PM, on 11/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\SCVHOST.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE
C:\WINDOWS\System32\SCVHOST.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.upians.com.ph/
F2 - REG:system.ini: Shell=Explorer.exe SCVHOST.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 -... Read more

More replies
Answer Match 103.74%

At my wits end here. Initially figured that I had TDSS or a TDL4 variant, ran TDSSkiller which detected and removed it, then combofix, on reboot am still infected. Ran malwarebytes, superantispyware, the microsoft malicious software removal tool as well to no avail. Ran a MBR checker and determined that the MBR was infected, so I used an XP cd, booted into the recovery console, wrote a new mbr, immediately booted into safe mode and ran combofix again; still infected when xp loaded up. I couldn't attach a DDS log as it keeps closing, so I have attached a hijack this log instead.

Other behavior I've noticed:

*Malware creates a random .exe file in either \WINDOWS, or \Documents and Settings with a gold & red colored shield icon, with a random filename such as 'svcproxyutil.exe' or 'xmlcheckapp'
*Creates files starting from FY1.tmp all the way up to FY7.tmp
*On delete of the suspicious randomly named .exe the file is immediately re-created by explorer.exe or services.exe (I checked this using the old sysinternals filemon tool)
*Process Explorer is also closed immediately when opened unless I rename the .exe, in which case it will run.

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-09-14 11:43:54
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-5 ST3500418AS rev.CC66
Running: 8wm4uq6b.exe; Driver: C:\DOCUME~1\te\LOCALS~1\Temp\kxldapob.sys
---- Kerne... Read more

A:regedit, command prompt, task manager close immediately on open

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything. We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. To help Bleeping Computer better assist you please perform the following steps:*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/418940 <<< CLICK THIS LINK If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.*************************************************** If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lo... Read more

2 more replies
Answer Match 102.9%

CMD, Regedit, services.msc, task manager closes straight after opening them.

I even logged in safe mode and still closes straight after I opened them. Heres my log.

Logfile of HijackThis v1.99.1
Scan saved at 11:24:31 AM, on 8/26/2008
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe
C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe
C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\iPod\bin\iPodService.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Buzz\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1... Read more

More replies
Answer Match 93.24%

I know this has been addressed in previous posts but none of the solutions I found worked for me.

Upon starting my computer, opening regedit isn't possible. I get an error message saying: "Regedit is disabled by administer." To fix this, I run (every time I turn on my netbook) the following statement: REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

This allows me to open Regedit, but it immediately closes again.

I have started working in Sierra Leone and know my computer has many viruses on it. Still, none of my anti-virus software (I use AVG Free 9.0 and PandaSecurity ActiveScan 2.0) has solved this problem.

Below please find my HJT log. Any and all help would be greatly appreciated.

Thanks,

Daniel

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 6:18:45 PM, on 1/13/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Fi... Read more

More replies
Answer Match 92.4%

It all started when I tried to change the name of the person to which the computer was originally registered to mine. Seemed easy until I tried to run regedit. Screen flashes on and then closes in seconds. From all I read- it could be a virus. I have McAfee installed. Did not detect anything. Ran adaware and spybot- which took care of some files but problem persists. Have tried to install Hijackthis but anytime I type this word in google I am returned to desktop screen immediately. Can't install it. Now what????
 

A:regedit screen opens and then closes immediately

10 more replies
Answer Match 92.4%

I have Windows XP Pro, and when i try to open up regedit or msconfig, they immediately close. THe reason i have been trying to get into regedit is to completely delete my old corporate edition of Norton antivirus in order to install the New norton cd i just bought.

i have seen in other posts that it is necessary to post the hijackthis log, so here it is....

if you could please guide me in how to remove this virus, i would greatly appreciate it. thank you

Logfile of HijackThis v1.97.7
Scan saved at 12:30:06 PM, on 9/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\WINDOWS\System32\rmctrl.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\taskswitch.exe
C:\WINDOWS\System32\pctspk.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\XMGDGPUN.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Creative\TaskBar\CTLTray.exe
C:\Program Files\Creative\TaskBar\CTLTask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System... Read more

A:REGEDIT and MSCONFIG closes immediately upon opening

16 more replies
Answer Match 77.28%

I have a PC that, when I log in, doesn't show any desktop icons. Hitting Ctrl-Alt-Del doesn't bring up the task manager. If I right-click on the desktop, no menu appears. Also, instead of the list of users appearing after boot-up, it's the single box that prompts for username and password. If any of the other users of the machine log in, their background picture shows up briefly, but then they are immediately loged out.I can start up in safe mode (and when I do the list of users, including Administrator, is there), but when I log in I still don't get desktop icons. Hitting Ctrl-Alt-Del (in Safe mode) brings up a task manager window with no top section. There's no title bar (which would normally say "Windows Task Manager" and have the minimize, maximize, and close buttons on it). There are also no tabs (normally would have Applications, Process, Performance, and Networking). Also, at the bottom it has the three buttons: End Task, Switch To, and New Task..., but nothing below that (i.e. no process count, CPU usage, or Commit Charge). Using the New Task... and browsing, I was able to run DSS, which runs a version of HijackThis (I couldn't find a direct copy of HijackThis to run). So I am attaching the log from that run.I tried to run explorer and found that in the C:\WINDOWS directory, the explorer.exe file was missing. I have since taken the hard drive out and put it as a second drive in my main PC (the one I'm sending this from). I transfered the log file from t... Read more

A:I Can't Log In (no Icons, No Task Manager), Others Logged Out Immediately

Hello meakerb,Welcome to Bleeping Computer You're in really bad shape here. I need a file uploaded so I know how to proceed, please.Please navigate to the following file:C:\DOCUME~1\Max\LOCALS~1\Temp\setwebinfo.dllPlease do the same for : C:\DOCUME~1\Owen\LOCALS~1\Temp\monwebdb.dllAnd: C:\Program Files\pgtpflf\engenact.dllPlease go to VirusTotal and submit the file for a scan and post the results in your next reply.Thanks,tea

6 more replies
Answer Match 76.86%

I've just installed windows 8 and I've noticed that I have a problem with task manager, which opens normally but when I click "more details" it closes after a 1-2 seconds. Could anyone help me with that?

More replies
Answer Match 76.86%

hi guys i found out that my task manager could not open today so i download the rrt tool to enable it, it has been enabled but it closes by itself when openedneed help here. thanks.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:16:03 PM, on 1/29/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16574)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\Program Files\Common Files\Symantec Shared\ccProxy.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Norton Internet Security\ISSVC.exec:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exec:\Program Files\Common Files\Symantec Shared\SNDSrvc.exec:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\Explorer.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\WINDO... Read more

A:Task Manager Closes By Itself In Less Than A Second

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. Please download ComboFix and save it to your desktop.Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.Double click combofix.exe and follow the prompts.When it's done running it will produce a log for you. Please post that log in your next reply.Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

2 more replies
Answer Match 76.86%

ever since i installed a program called sandboxie my computer has been a bit slower but more important my windows task manager closes automatically

i uninstalled sandboxie and it still does it

can anyone help?

A:task manager closes

The inability to open or close the task manager, perform system restore, or use other Windows functions properly can be the result of Malware...I would suggest a few scans starting with this one...Download the free one and follow the instructions for it's usage...http://www.malwarebytes.org/

3 more replies
Answer Match 76.44%

I don't know how this happened, but I can no longer use the three programs listed above. Anybody have a solution????
 

A:Can't use regedit, task manager, or cmd. Help!!

here is a screen shot of what happens when I try to run regedit and cmd. I don't even get a response from ctrl+alt+delete( task manager )
 

2 more replies
Answer Match 76.02%

My computer was recently infected with one of the fake FBI alert virus, which I thought I had successfully removed. However, my task manager is still having problems. Immediately after opening, it will close.

Hijackthis Log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:18:02 PM, on 1/16/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\mobsync.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Radica\Stylin' Studio\SS_MW.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrmon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
c:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program... Read more

A:Task Manager Closes Upon Starting

Download Farbar Recovery Scan Tool on a clean PC (if possible) and save to a flash drive (memory stick). Use which ever of the folllowing is applicable to your system. (32 or 64 bit)

Download http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ <--- 64 bit version Save to USB flash drive

Download http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ <--- 32 bit version Save to USB Flash drive

Plug the flashdrive into the infected PC.

Enter System Recovery Options I give two methods, use whichever is convenient for you.

To enter System Recovery Options from the Advanced Boot Options:

Restart the computer.
As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
Use the arrow keys to select the Repair your computer menu item.
Select Your Country as the keyboard language settings, and then click Next.
Select the operating system you want to repair, and then click Next.
Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:

Insert the installation disc.
Restart your computer.
If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
Click Repair your computer.
Select Your Country as the keyboard language settings, and then click Next.
Select the operating system you want to repair, and then click Next.
Select your user account and click N... Read more

3 more replies
Answer Match 76.02%

I'm having a problem with my computer right now. every time I try to open windows task manager or regedit, it closes immediately. my computer also seemed to have slowed down a bit. Any help would be appreciated.

Here is the log of Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:57:10 PM, on 4/28/2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\USB 2.0 PC CAMERA\Camera Snap.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\user\My Documents\sir files2\Antivirus stuff\HiJackThi... Read more

A:Task Manager Instantly Closes

12 more replies
Answer Match 76.02%

I'm not really sure what kind of problem is this. every time I try to open windows task manager or regedit, it closes immediately. My computer also seemed to have slowed downed when this happened. Any help is appreciated.

here is the log of Hijcackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:57:10 PM, on 4/28/2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\USB 2.0 PC CAMERA\Camera Snap.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\user\My Documents\sir files2\Antivirus stuff\Hi... Read more

A:Task Manager closes automaticaly

As this issue is already being addressed elsewhere, I will now close this thread.

Please note:
NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help

NOTE: We are aware that users sometimes seek help from several Forums at the same time. Unfortunately, this can cause confusion and actually wastes time and resources - yours, ours and other Volunteers across the community.

Thank you.

We no longer use HijackThis as our initial analysis tool.

We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

1 more replies
Answer Match 76.02%

I am using Windows Vista.
And I think I downloaded a file that was infected but my antivirus Eset didn't detect it. And I tried using all these virus scans, SUPERANTISPYWARE, An Eset full scan, and Housecall from Trend Micro. Nothing was picked up. I've googled my problem and found nothing but some help with hijackthis logs and stuff. Please help me with this problem.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:14:44 AM, on 9/5/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\WINDOWS\RtHDVCpl.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Razer\Habu\razerhid.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Documents and Settings\All Users\Application Data\scvhost.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\Program Files\Trill... Read more

More replies
Answer Match 76.02%

Hello
I'm having some trouble with Task Manager & Disk Defragmentation, both of which close immediately upon opening. CPU usage icons appear in the bottom right, though disappear when selected. I have run Ad-aware, Search & Destroy, Norton, AVG & most anything else I could think to. Listed below is my Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 9:30:27 PM, on 03/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\WINNT\system32\IEXPLORE.EXE
C:\Program Files\AVG\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\MsgSys.EXE
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\SBHookSvc.exe
C:\WINNT\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://start.sh... Read more

A:Task Manager closes automatically

bump
 

1 more replies
Answer Match 76.02%

I'm having a problem with my computer right now. every time I try to open windows task manager or regedit, it closes immediately. my computer also seemed to have slowed down a bit. Any help would be appreciated.I've attached the log file of hijackthis here:

A:Task Manager Instantly Closes

Hi,Platform: Windows XP SP2 (WinNT 5.01.2600)you are running SP2, you really need to update to SP3, SP2 is no longer supported, we will take care of this once your computer is cleanPlease do the following:Open HiJackThisClick on Do a system scan onlyCheck the boxes next to ONLY the entries listed below (if still present):O4 - HKLM\..\Run: [Microsoft Firewall 2.9] C:\DOCUME~1\user\LOCALS~1\Temp\MSFW.exeO4 - HKCU\..\Run: [Microsoft Firewall 2.9] C:\DOCUME~1\user\LOCALS~1\Temp\MSFW.exeO4 - HKCU\..\Run: [Fmjqjv] C:\Documents and Settings\user\Application Data\Fmjqjv.exeO4 - HKCU\..\Run: [{00831268-F9C4-4268-6859-0DE0A84C49DD}] "C:\Documents and Settings\user\Application Data\Ewcia\paqu.exe"O4 - HKCU\..\Run: [Microsoft Security Essentials] C:\Documents and Settings\user\Application Data\explorateur\explorateur.exeO23 - Service: BCL easyPDF SDK Loader (ai7m5fmis4mqn) - Unknown owner - C:\WINDOWS\system32\louhyt.exe (file missing)O23 - Service: BeTwin Terminal Services (aoypd6oayuyu) - Unknown owner - C:\Documents and Settings\LocalService\Application Data\Microsoft\duridou.exe (file missing)O23 - Service: Network Connectivity Service (lo6moirc7diuot) - Unknown owner - C:\WINDOWS\system32\nafuwoul.exe (file missing)O23 - Service: ASF Agent (yj5y8iul9f)... Read more

2 more replies
Answer Match 76.02%

Task Manager, MSCONFIG, and REGEDIT are disabled. I have tried fixing this with information found in other threads, and it just isn't working. Ad-aware, SpybotS&D, and AVG all find nothing. Trend Micro House Call finds nothing.
here is my logfile.

Logfile of HijackThis v1.97.7
Scan saved at 3:52:04 AM, on 2/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SYSTEM32\winsock2.2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\MOTORHEAD\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.variablepro.com/iq/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Emile = 1337
F0 - system.ini: Shell=explorer.exe winsock2.2.exe
F2 - REG:system.ini: Shell=explorer.exe winsock2.2.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_12_0.dll
O2 ... Read more

A:[Resolved] Task Manager closes

6 more replies
Answer Match 75.6%

i have problem with my task manager.when i open my computer suddenly the error popup saying that "There is no disk in the drive. Please insert a disk into drive\Device\Harddisk3\DR6.when i click cancel the popup still keep coming. i also cant open the task manager. it says that the task manager has been disable by the administrator.i hv tried to click STart>run>regedit.... it also says the task manager has been disable by the administrator.will someone please help me with the problem. i appreciate it very much. thank you. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 12:23:06 PM, on 9/17/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.exeC:\WINDOWS\system32\RVHOST.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\CyberLink\PowerDVD ... Read more

A:Cannot Open Task Manager And Regedit.

can someone help me with this thing please...

3 more replies
Answer Match 75.6%

I seem to have a virus disabling my task manager and registry editor. I have run spybot and malwarebyte's anti-malware. The list each one finds includes mentions of task manager and regedit. When I fix the problems, I'm able to open the two programs for about 5-10 seconds. The virus then seems to reapply itself.

Here is my log for malwarebytes:

Malwarebytes' Anti-Malware 1.41
Database version: 2825
Windows 5.1.2600 Service Pack 3

10/26/2009 3:26:45 PM
mbam-log-2009-10-26 (15-26-45).txt

Scan type: Full Scan (C:\|)
Objects scanned: 209821
Time elapsed: 1 hour(s), 14 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Inf... Read more

A:Task manager and regedit disabled

Hello, I am moving this from XP to the Am I Infected forum. Please Rerun MBAM (MalwareBytes) like this:Open MBAM in normal mode and click Update tab, select Check for Updates,when doneclick Scanner tab,select Quick scan and scan (normal mode).After scan click Remove Selected, Post new scan log and Reboot into normal mode.Next run ATF and SAS:Note.. SAS doesn't open the registry hives for other user accounts on the system, so scans should be done from each user account.Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".From your regular user account..Download Attribune's ATF Cleaner and then SUPERAntiSpyware , Free Home Version. Save both to desktop ..DO NOT run yet.Open SUPER from icon and install and Update itUnder Scanner Options make sure the following are checked (leave all others unchecked):Close browsers before scanning.Scan for tracking cookies.Terminate memory threats before quarantining.Click the "Close" button to leave the control center screen and exit the program. DO NOT run yet.Now reboot into Safe Mode: How to enter safe mode(XP)Using the F8 MethodRestart your computer. When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu. Select the... Read more

7 more replies
Answer Match 75.6%

Like the title says my regedit and task managers are both locked. I can't access either. Also my C: drive's hard disk space is being eaten by something. Here's the Hijack This log:

Logfile of HijackThis v1.99.0
Scan saved at 12:19:18 PM, on 11/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\program files\support.com\client\bin\tgcmd.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\QuickTime\q... Read more

A:Task Manager and Regedit locked

8 more replies
Answer Match 75.6%

i believe it was a virus that is doing all this because my PC were all find back then till i downloaded a patch for an online game

IMPORTANT INFO:1.Window XP Service Pack 2
2.Task Manager and Regedit disabled
3.I cant access to any official antivirus website
(except for websites like download.com)
4.Task manager and Regedit are not manually disabled


ok this is what happened...

I start to realised that my pc was infected when i tried to end a task using task manager and i got this error stating that "task manager has been disabled by your administrator" . first i thought it was just a technical error so i start to go through some guide to enable my task manager as it was . Then i found this guide that by running Regedit i could enable my task manager back as it was , but then i also realised that my Regedit was also disabled . Since this computer belong to me and no one is touching it because i'm a single guy who live alone , so i guess it should be a virus .

A:Task Manager and Regedit disabled

Hello and welcome to TSF.

We want all our members to perform the steps outlined in the link given below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

1 more replies
Answer Match 75.6%

Although regularly scheduled virus check with Norton 360, I suspect there might be some virus in my PC. I started notice something wrong yesterday as I could not run ctrl-alt-del to access Task Manager and run regedit. I soon also noticed my Norton360 has been deactivated and could not be activated manually. So I contacted Norton for support. Followed their instructions I removed Norton 360 with the intention to reinstall the software. That?s when I found out I could not even complete the Norton360 installation. The only suggestion I got from the technical supports at Norton is format my PC, which I really hope to avoid.
I have since run online scans using Trend Micro Sysclean and Panda ActiveScan, both tools report nothing suspicious.
I have found HijackThisLog has helped the other member fix a very similar problem back in 2004, I?m attaching my log. Please can anyone provide any help or guidance to get me back to being able to run these programs. Many Thanks.

---------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:09:28, on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\... Read more

More replies
Answer Match 75.6%

I tried to use Task Manager only to be greeted by the message "Task Manager has been disabled by your administrator", and the pc then shuts down and reboots, which is strange as I am the administrator. Googled some solutions, one of which was to change a value in the registry. Start > run > regedit produces the same result, only the message is "Regedit has been ............" followed by the shut down and reboot.

Tried to perform a system restore, and as soon as you click on "Restore to an earlier date" the pc shut down and rebooted.

Hopefully someone can give me some guidance on this as I don't know if this is a result of malware/virus or what.

Thanks in advance

A:Task Manager & Regedit Disabled

Possibly solved the problem.

It is/was Newfolder.exe apparently, and had also got onto my usb sticks.

I think I have managed to get rid of it.

1 more replies
Answer Match 75.6%

ALGUEM ME AJUDA, MEU REGEDIT N?O ABRE E NEM O GERENCIADOR DE TAREFAS, AGRADE?O DESDE J?ComboFix 10-01-13.07 - Administrador 13/01/2010 20:18:57.1.1 - x86Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.766.406 [GMT -2:00]Executando de: c:\documents and settings\Administrador\Desktop\Downloads\ComboFix.exe.((((((((((((((((((((((((((((((((((((( Outras Exclus?es ))))))))))))))))))))))))))))))))))))))))))))))))))).c:\arquivos de programas\driverc:\arquivos de programas\driver\Modem Driver\Uninst.isuc:\documents and settings\Administrador\Menu Iniciar\Programas\Inicializar\??????.lnkc:\windows\Alcmtr.exec:\windows\system32\com.runc:\windows\system32\dp1.fnec:\windows\system32\eAPI.fnec:\windows\system32\internet.fnec:\windows\system32\krnln.fnrc:\windows\system32\og.dllc:\windows\system32\og.edtc:\windows\system32\RegEx.fnrc:\windows\system32\shell.fnec:\windows\system32\spec.fnec:\windows\system32\ul.dllc:\windows\system32\XP-B517DF2B.EXE.(((((((((((((((( Arquivos/Ficheiros criados de 2009-12-13 to 2010-01-13 )))))))))))))))))))))))))))).2010-01-13 22:13 . 2010-01-13 22:13 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!2010... Read more

A:Regedit and Task manager do not work

Hello. I think that this is Portuguese. Saying Regedit and Task manager do not work.I moved your Topic to the HijackThis Logs and Virus/Trojan/Spyware/Malware Removal section of the Security foum. This where it need to be.

1 more replies
Answer Match 75.6%

Hey all! I am new here, found this site searching my problem in google. Hoping you can help me. My task manager won't open and REGEDIT/CMD are "currently being used by another program". If you need any more info, please respond and I will be happy to give it. I am in dire need of help because I am not able to install a program for my guitar and that program is vital to me recording some tracks that my band mates across the state need.

Thanks in advance!

A:Task Manager, Cmd And Regedit Used By Another Program

Assuming this is an XP Pc try the repair methods in this link.Task Manager Has Been Disabled, How to Fix It?If you need to use method 4,be sure to back up the registry first.How to Back up Registry:Go to Start ? Run and type: regeditClick OK.On the left side, click to highlight My Computer at the top.Go up to File ? Export Make sure in that window there is a tick next to "All" under Export Branch.Leave the "Save As Type" as "Registration Files".Under "Filename" put RegBackup.Choose to save it to C:\Click save and then go to File ? Exit.Or you can download and use ERUNT a free tool.Take a complete registry backup using ERUNT

5 more replies
Answer Match 75.6%

Task Manager, regedit, msconfig just flash on my screen (Windows XP). NAV caught backdoor.sdbot two weeks ago and I thought removed it. Adaware finds nothing. Any help would be greatly appreciated.
 

A:Task Manager/regedit problems

16 more replies
Answer Match 75.6%

Operating System: WinXP Home

When I attempt to start regedit, I get the following error:

"Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

Found another problem where I could no longer access any AntiVirus websites. I purchased Norton and McAfee install CDs, but have had no luck installing. I still can't access most of the antivirus sites.

Found variants of beagle virus on machine and removed using Stinger command line tool. I am still unable to install any Anti-Virus software. The Norton installation ends with a "Write error. Probably disk is full" message, even though I have 30GB free space. The McAfee 10.0 install just ends abruptly about 5 seconds after it starts.

I ran through the normal spyware removal tools and have included my HijackThis log below. Any help would be greatly appreciated. I have a feeling that the antivirus software installs fail b/c I don't have access to the registry.

-Todd



Logfile of HijackThis v1.99.1
Scan saved at 10:38:57 PM, on 2/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Sys... Read more

A:Can't open task manager or regedit

Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted.

Please read this post completely before begining the fix. If there's anything that you do not understand, kindly ask your questions before proceeding. Please ensure that there aren't any any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.


* * * * * *


Let's do this first..




Download and unzip - bfu.zip
Run the program and click the Web button located on the top right corner

Copy/Paste this url into the address bar of the Download script window:

http://metallica.geekstogo.com/alcanshorty.bfu


Checkmark the following boxes:Use settings specified in script for the above option
Show log after script ends
Execute the script by clicking the Execute button.

When it finishes running, click the Save button for a copy of the log
Post the log created by the script when you have completed the fix


If you have any questions about the use of BFU please click here


* * * * * * ADDITIONAL DOWNLOADS * * * * * * * * * * * * * *


Download Hoster.exe
Close ALL browser & Run Hoster.exe immeaditelyClick "Make Hosts Writable?" in the upper right corner (If available).
Click Restore Original Hosts and then click OK.
Click the X to exit the program & re-open your brow... Read more

1 more replies
Answer Match 75.6%

Hey,

Well, on my Laptop I have got Windows XP Tablet PC Edition 2005 SP2 installed. I have got Zone Alarm Internet Security Suite and Adaware installed. Adaware found 282 infections, deleted all. Zone alarm found no viruses. The regedit and task manager are disabled. I am on the administrator account.

This is my Hijackthis log :-
Code:
Logfile of HijackThis v1.99.1
Scan saved at 17:33:08, on 01/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
C:\WINDOWS\SYSTEM32\WISPTIS.EXE
C:\WINDOWS\System32\tabbtnu.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Transmeta\Crusoe Persistent Translation Service\pttsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RVHOST.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Prog... Read more

A:Windows XP - Regedit and Task Manager....

YesYes, Try the free tool called Remove Restrictions Tool (RRT) at the link below.

http://www.raymond.cc/blog/archives...regedit-and-folder-options-disabled-by-virus/

Tufenuf
 

3 more replies
Answer Match 75.6%

I know this thread has been dealt with before, but going through the archive, I ended up a bit more confused than anything lol .... I believe I have a Trojan (keylog/briss) or so says McAfee online scan. I've run Norton and Ad-aware to no avail, run registry mechanic, run spybot, all with no effect on this virus. a lot of spyware and virus possibilities were wiped, but my issue still remains.... I'm going to close IE now to run Hijack to give you an idea of my system, and repost in a minute....

Thank you... Michael
 

A:Locked out from Task Manager, regedit, etc....

16 more replies
Answer Match 75.6%

i m not able to run my antivirus and a lot of programs.... and even my task manager and regedit is disabled can anyone plz help i'll attach my hjt log
 

A:task manager, regedit disabled......etc plz help

someone plz help me
 

1 more replies
Answer Match 75.6%

I downloaded the microsoft update so my restarting problem is fixed. Only thing left is the task manager ect. Here is the Hijackthis log.

Logfile of HijackThis v1.96.0
Scan saved at 3:31:38 PM, on 8/11/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\LEXBCES.EXE
C:\windows\system32\spoolsv.exe
C:\windows\system32\LEXPPS.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\windows\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Object Desktop\WindowBlinds\wbload.exe
C:\windows\Explorer.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\windows\System32\lxamsp32.exe
C:\windows\System32\PRMVUECOCC.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Nick\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.search-explorer.net/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.search-explorer.net/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.search-explorer.net/search_page.php
R0 - HKCU\Software\Microsoft\Internet E... Read more

A:Task Manager, Regedit ect. Problems

6 more replies
Answer Match 75.6%

Same problem as some other threads. Task manager and regedit open for half a second and close. &#304;'ve installed hijack in safe mode and took this log below. can you help me sort this out? thousand thanks in advance.

Logfile of HijackThis v1.97.7
Scan saved at 20:00:46, on 24/08/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\WISPTIS.EXE
C:\WINDOWS\System32\tabbtnu.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Documents and Settings\Ferran\Desktop\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ukproxy:80
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {78104A01-8E71-4F30-9A36-3793799615B4} - C:\Program Files\Microsoft\Rights Management Add-on\mime_filter.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} ... Read more

A:Help please. Task Manager, regedit not working

Use System Restore to roll your computer back to a date to before when your computer worked right. Before the error(s) started occurring.

To start System Restore, click Start, point to Programs, point to Accessories, point to System Tools, and then click System Restore. Or, in the Help and Support main screen, click Use System Restore under Fix a problem.

You may need to remove; restart your computer; re-install some programs after this. Backup your sensitive data first.
 

2 more replies
Answer Match 75.6%

I tried the directions that were posted for a different user regarding this virus. However, for some reason it didn't work for my machine.
Here is the Log for my machine, maybe someone can help me get rid of this evil.
Logfile of HijackThis v1.99.0
Scan saved at 9:48:27 AM, on 2/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WINLOGONPC.EXE
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\CW4\cw4.exe
C:\WI... Read more

More replies
Answer Match 75.6%

when i try to open the task manager and the regedit it comes up but then it goes away what can i do to fix the problem. Need help.

A:task manager regedit msconfig

Welcome to TSF Father!

Well, first off you need to give us a little more info than that. Please tell me exactly what happened. Second, as for the task manager, you can get a better one from here and maybe even use it to troubleshoot your problem:

http://technet.microsoft.com/en-us/s.../bb896653.aspx

Christian Dude

3 more replies
Answer Match 75.6%

Hey all, I'm currently having problems with some programs, mainly Task Manager. Whenever I try to CAD to it, or Run it, it only flashes on the screen and then closes. The same happens for Regedit.exe.

I have scanned my system for everything with Spybot, Spyware Doctor, Ad Aware, Norton, and just recently HijackThis. I know I have a lot of junk running (it's an old machine and half the things I don't know about). Here is the log file. Help me clean this thing up!
Logfile of HijackThis v1.98.2
Scan saved at 6:10:26 PM, on 8/15/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS2\System32\smss.exe
C:\WINDOWS2\system32\winlogon.exe
C:\WINDOWS2\system32\services.exe
C:\WINDOWS2\system32\lsass.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\System32\svchost.exe
C:\WINDOWS2\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS2\System32\nvsvc32.exe
C:\WINDOWS2\wanmpsvc.exe
C:\WINDOWS2\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS2\SYSTEM32\USRmlnkA.exe
C:\WINDOWS2\System32\wgzjdd.exe
C:\WINDOWS2\System32\RUNDLL32.EXE
C:\WINDOWS2\System32\MSCONFIG32.EXE
C:\WINDOWS2\SYSTEM32\USRshutA.exe
C:\Program Files\U.S. Robotics\ControlCenter\Reminder.exe
C:\WINDOWS2\SYSTEM32\USRmlnkA.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\... Read more

A:Problems with Task Manager, Regedit, others

6 more replies
Answer Match 75.6%

hi guys! I am new here but I already need your help, please. First of all, sorry my terrible english... it is because i am form Brazil... I am a begginer in computers and I saw that many of you had the same problem I have: I havea notebook with win xp and my task manager, regedit, nav, etc... don't stay open... I tried to follow the instructions on the other posts but I got lost. Using the Hijackthis I got this:

StartupList report, 13/8/2004, 19:44:13
StartupList version: 1.52
Started from : C:\Documents and

Settings\Administrador\Desktop\HijackThis.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================

Running processes:

C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\Explorer.EXE
C:\Documents and Settings\Administrador\Desktop\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Administrador\Menu

Iniciar\Programas\Inicializar]
Webshots.lnk = C:\Arquivos de

programas\Webshots\WebshotsTray.exe

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Menu

Iniciar\Programas\Inicializar]
Microsoft Office.lnk = C:\Arquivos de programas\Microsoft

Office\Office10\OSA.EXE

-------------------------... Read more

A:[Solved] help: no task manager, regedit, etc

11 more replies
Answer Match 75.6%

As per above, my task bar manager isn't working. Whenever I click Ctrl Alt Del, I get the grey box saying Task manager has been disabled by your administrator.

So browsed the web to get some answer for why it's not working and I found out that it may be caused by some viruses. Even my regedit doesn't work.

Ok, now, whenever I click paste, I get this: Biet tin gi chua, vao day coi di http://nhattruongquang.0catch.com

What the crap is that?

However, my log of Hijack This:

Logfile of HijackThis v1.98.2
Scan saved at 7:00:24 PM, on 6/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\RVHOST.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\System32\spoo... Read more

A:Regedit and Task Manager not Working

I just realise I wasn't using the latest HijackThis. Anyway, this is my new log.

Latest update is that I my regedit is enabled but I still get the Task Manager disabled box.

Logfile of HijackThis v1.99.1
Scan saved at 1:55:26 PM, on 6/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.... Read more

2 more replies
Answer Match 75.6%

Good day.

I noticed that my Task Manager and Regedit is disabled by the "administrator". So I decided to scan my PC using Malwarebytes. It detected a 2 Trojan.Downloader which is winrmey.exe stored in D:\WINDOWS\Temp folder and winnlptpo.exe also stored in the Temp folder of the Local Settings folder in the Documents and Settings folder and a Hijack.Taskmanager and a Hijack.Regedit log. I fixed it, then I can use my task manager now. But then, when I restarted my PC, I can't open my task manager and registry editor again. And when I scanned it with Malwarebytes, it detected another Trojan.Downloader with a seemingly random filename (By the way, I googled winrmey.exe and there were no results).

So I decided to download HouseCall from TrendMicro and scanned it. It detected 79 threats (78 PE_SALITY EN-1, and a Trojan), fixed and then restarted my PC. But then, the same happened. I can't still open my Task Manager.

Anyway, there isn't any other manifestations of the malware that infected my PC aside from blocking the Task Manager and Registry Editor. Anyway, everytime I start my PC, the time and date always revert to March 8, 2006 12:00AM due to a BIOS Checksum Error.

Root Repeal Log

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2006/03/08 00:16
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
-------------------
Name: dum... Read more

A:Can't open Task Manager and Regedit

Hi,I'm sorry I have bad news for you:You have contracted sality.Sality is a family of file infecting viruses that spread by infecting exe and scr files. The virus also includes an autorun worm component that allows it to spread to any removable or discoverable drive. In addition, Sality includes a downloader trojan component that installs additional malware via the Web...About Sality VirusWin32/Sality FamilyIf the computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before coThere is no guarantee the infection can be completely removed. In many cases the infected files cannot be deleted and anti-malware scanners cannot disinfect them properly. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best... Read more

4 more replies
Answer Match 75.6%

Hello, As I couldnot access task manager and the programs did not start properly on my laptop (XP Home Edition Service Pack 3), I decided to format it but after I had transferred my files to another laptop via lan, this recenty formatted working one (Windows Vista Home Premium Service Pack 2) started to behave like the previous one. I cannot access task manager, also the programs run slow. What should I do now? I have downloaded Combofix, Hijack this, mbam, spybot and SuperAntiSpyware desperately, in the hope that one of them will solve the problem but nothing changed after I scanned both of the computers with them. (I also get a blue screen while I try to scan the computer with XP via combofix) Thank you in advance for the answers which may help me to get rid of this problem.

A:I cannot access task manager and regedit

QUOTEHello, As I couldnot access task manager and the programs did not start properly on my laptop (XP Home Edition Service Pack 3), I decided to format it but after I had transferred my files to another laptop via lan, this recenty formatted working one (Windows Vista Home Premium Service Pack 2) started to behave like the previous one. I cannot access task manager, also the programs run slow. What should I do now? I have downloaded Combofix, Hijack this, mbam, spybot and SuperAntiSpyware desperately, in the hope that one of them will solve the problem but nothing changed after I scanned both of the computers with them. (I also get a blue screen while I try to scan the computer with XP via combofix) Thank you in advance for the answers which may help me to get rid of this problem.Hello again, As I had no replies for my previous post and my problem still exists, I went on searching forum looking for how to enable my task manager and I have succeed using one of the programs from the recommended sites here. But the my blue screen problem BAD_POOL_HEADER (on XP) and slow working (XP & Vista) continued, then I searched for viruses on both of them and I have these logs. for xp;Malwarebytes' Anti-Malware 1.45www.malwarebytes.orgDatabase version: 3948Windows 5.1.2600 Service Pack 3Internet Explorer 8.0.6001.187024/3/2010 8:56:34 AMmbam-log-2010-04-03 (08-56-34).txtScan type: Quick scanObjects scanned: 67415Time elapsed: 48 minute(s), 14 second(s)Memory Processes Infected: 0M... Read more

3 more replies
Answer Match 75.6%

Original post

http://www.techsupportforum.com/f100...ed-428542.html

i believe it was a virus that is doing all this because my PC were all find back then till i downloaded a patch for an online game

IMPORTANT INFO:1.Window XP Service Pack 2
2.Task Manager and Regedit disabled
3.I cant access to any official antivirus website
(except for websites like download.com)
4.Task manager and Regedit are not manually disabled


ok this is what happened...

I start to realised that my pc was infected when i tried to end a task using task manager and i got this error stating that "task manager has been disabled by your administrator" . first i thought it was just a technical error so i start to go through some guide to enable my task manager as it was . Then i found this guide that by running Regedit i could enable my task manager back as it was , but then i also realised that my Regedit was also disabled . Since this computer belong to me and no one is touching it because i'm a single guy who live alone , so i guess it should be a virus .

im quite lost.. i dont know what to do.. even though i go through the tutorials .. sorry im a newbie xD

the dds seems to be not responding and the only thing i got was the logs..
i think this should be it

GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-11-05 14:26:20
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\user\LOCALS~1\Temp\kxtdapob.sys


---- Services - GMER 1.0.15 ... Read more

A:Task Manager and Regedit disabled

Hello -

Let's see if we can get some logs from this tool.
Download RSIT by random/random and save it to your desktop.
Double click RSIT.exe to start the tool and click Continue at the disclaimer.
When the scan completes it will open a log named log.txt maximized, and a log named info.txt minimized.
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of log.txt here.
Please attach info.txt to your post.
To attach a file to a new post, simplyClick the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
copy and paste the following into the "Upload File from your Computer" box:C:\rsit\info.txt

Click Upload.



---------------------------------------------------------------------------------------------

19 more replies
Answer Match 75.6%

Another Big Problem Mr.TSG.
Now when i press crtl + alt + del , it says Task manager has been disabled by your administrator.
Plz Help this time also..

My HJT Log is attached

Please also tell how dangerous it is to hold on with windows with such a problem ?

Thanks as always
 

A:Task Manager and Regedit Disabled !!

please help
 

2 more replies
Answer Match 75.6%

Hi I have a pentium(R) 4 cpu 2.66GHZ, 1GB Ram, XP, SP2.

I cannot seem to start CMD, or Regedit. I get a popup 'Another program is currently using it'

Also, I cannot launch task manager when I right click on my mouse from the task bar.

I tried doing a system restore to 3 weeks ago and I still have the same problem.

Also , it appears that my PC is running very slow, sometimes it freezes, sometimes it take a long time to reboot,

I have NOD32 and I ran a spybot and ran a fix and repair. Still have the same problems.

Can you please help ? Thank you.

A:Cannot start CMD, Regedit, task manager

hi, post in security forum, its a virus - very likely.
if you press ALT + CTRL + DEL - you will likely get a message that " TASK MANAGER DISABLED BY SYS ADMIN " - there is a way to reenable by downloading a task manager file that re-enables it, editing registry.
without the task manager
get
get http://technet.microsoft.com/en-us/s.../bb896645.aspx
instead of task manager for now, it's much better - no install, stand alone. it will help, prob.
to fix some problems automatically.
download & dblclick the files (.reg)
http://www.kellys-korner-xp.com/xp_tweaks.htm

i strongly suggest the security threads 1st.
eliot

1 more replies
Answer Match 75.6%

I have the following issue with my Dell Computer that is running Windows XP Pro. I'd appreciate it if anyone can help resolve it.

The Task Manager is disabled and the Regedit (registry editor) is also disabled (if I run "regedit" it displays a message "Registry Editing has been disabled by your System Administrator". After searching the web for related issues, I found that this was due to the DisableTaskMgr and DisableRegistryTools registry key entries [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]. Using some tools, I was able to delete these registry entires and it resolved the issue. However, within a few seconds these registry entries re-appear and the issue persists.

I have searched several web sites for similar issues and have tried a lot of different things but am unable to resolve the issue. I have re-installed the OS from scratch with latest Service Packs, checked to make sure there are no viruses or spyware, checked the security policy settings (gpedit.msc), etc. None of this helps. The registry entires keep re-appearing each time I delete them. I am using Administrator account to log on.

 

A:Task Manager and Regedit disabled

Hi,

Your issue will be best helped by having you post in our Malware Removal forum

I would say you are being reinfected, there is some malware that causes the exact issues you are having so let's have you do this:'

http://forums.techguy.org/54-malware-removal-hijackthis-logs/

To download Hijackthis:

go to HERE and download 'Hijack This!' self installer. Save it to the desktop or other suitable place. DO NOT just press run from the website Double click on the file and it will install to C:\program files\hijackthis and create an entry in the start menu.
Click on the entry in start menu to run HijackThis
Click the "Scan" button, when the scan is finished the scan button will become "Save Log" click that and save the log.
Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.
It will possibly show issues deserving our attention, but most of what it lists will be harmless or even required,
so do NOT fix anything yet.
Someone here will be happy to help you analyze the results.

This thread will no longer be needed so I am Closing it, please do as advised, it is for your benefit.
 

1 more replies
Answer Match 75.6%

Can somebody please help me, I can't access my Task Manager, Regedit and some other stuff and everythings is so slow. Here are the logs. Thanks!

Logfile of random's system information tool 1.04 (written by random/random)
Run by Edsel at 2008-12-03 20:39:12
Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (9%) free of 26 GB
Total RAM: 511 MB (9% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:39:42 PM, on 12/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe... Read more

A:Cannot access Task Manager, regedit, etc.

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a description of your problem, along with any steps you may have performed so far.Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results, click no to the Optional_ScanFollow the instructions that pop up for posting the results.Close the program window, and delete the program from your desktop.Please note: You may have to disable ... Read more

2 more replies
Answer Match 75.6%

I am working on the second computer in as many days that is exhibiting the following symptoms:
1. On bootup, I receive an error - generic host process for win32 services has encountered a problem and needs to close
2. I can't run regedit, cmd, or task manager. When I try, Explorer closes down, then restarts
3. The following registry entry was in HKLM\SOFTWARE\Microsoft\Windows\Current Version\Run: UserFaultCheck with a value of %systemroot%\system32\dumprep 0 -u
4. Can't run housecall from Trend Micro - tried to run but it failed when attempting to install updates (used java version, html version failed also although I can't remember why)
5. Occasionally when booting up, Explorer does not load.

The above symptoms are the same in Safe Mode.

It strikes me as quite interesting that I've encountered 2 of these in the past 2 days, making me believe there may have been a bad update or there's some virus/malware causing the problem. I ran hijackthis and looked through the log file, but didn't see anything I thought was suspicious. I'll post it just the same.

Both computers were running Windows XP Home Edition, SP3. I can get to symantec.com and trendmicro.com, but not mcafee.com. Could conficker be involved?

I appreciate any help anyone can provide.

Here's my hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:37:25 PM, on 4/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.1... Read more

More replies
Answer Match 75.6%

I've opened an unknown .exe file that i received and My OS is windows Xp .

When i clicked that .exe file . ( its known as activation.exe )
Error message comes up that says : Already activated !
Then i clicked on run.bat which doesnt work somehow too, i thought it must be activated to run it .

Came up clean on virustotal ?

Then i tried to Ctrl alt delete to find the problem but failed as task manager is disabled by my admin .
I googled how other way to enable it and used regedit , also denied access .

Im in a loss and i found this place so yeah I am not sure what to post and i Dont know what to do . It is not even my computer .
I rebooted once and my computer has reasonably slowed down by abit too . I wonder if it is all coming from the same problem.. Probably a virus .
Need to know what to do next . Thanks

Oh, i also deleted the original file of the activation.exe

A:Cannot execute regedit , task manager

Please download Malwarebytes Anti-Malware (v1.41) and save it to your desktop.alternate download link 1alternate download link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.Make sure you are connected to the Internet.Double-click on mbam-setup.exe to install the application.When the installation begins, follow the prompts and do not make any changes to default settings.When installation has finished, make sure you leave both of these checked:Update Malwarebytes' Anti-MalwareLaunch Malwarebytes' Anti-MalwareThen click Finish.MBAM will automatically start and you will be asked to update the program before performing a scan.If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.On the Scanner tab:Make sure the "Perform Quick Scan" option is selected.Then click on the Scan button.If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button. The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.When the scan is finished, a message box will... Read more

1 more replies
Answer Match 75.6%

Well, I know this is caused by malware, unfortunately. I've gotten rid of the malware itself, but I have no idea how to re enable the Task Manager or regedit. Each says "Disabled by administrator", but I'm the only account on the computer, and it's an admin account.

What should I do?

I'm on Win7 Pro x64

Thanks

A:Task Manager and Regedit Disabled

I'd stab at a guess and say you haven't got rid of all the malware.

Did you carry out a scan in Safe Mode? If not, it would be advisable to do so.

Malwarebytes is a great tool to use in these cases.

You might want to check these tutorials:

Regedit - Enable or Disable - Vista Forums

Task Manager - Enable or Disable - Vista Forums

9 more replies
Answer Match 75.6%

My task manager won't open, and neither does regedit, i removed Trojan.Dropper/Sys-NV with the Free SuperAntiSpyware and it deleted C:\WINDOWS\SYSTEM32\MSPGW.EXE, but the task manager and regedit still dont work:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:28:14, on 9.8.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AnVir Task Manager Pro\AnVir.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus... Read more

More replies
Answer Match 75.6%

Today out of the blue I got hit with a ton of spyware and viruses. I managed to clean up most of them using PC Tools software, but I still cannot get Task Manager, CMD or Regedit to function. When I try to run them, I am returned with "Another program is currently using this file". Here is my Hijack this log, since I know you'll need it:Logfile of HijackThis v1.97.7Scan saved at 3:37:31 PM, on 11/12/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0011)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exec:\program files\common files\logitech\lvmvfm\LVPrcSrv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\RunDLL32.exeC:\WINDOWS\system32\taskswitch.exeC:\Program Files\Microsoft IntelliPoint\ipoint.exeC:\Program Files\Microsoft Hardware\Keyboard\type32.exeC:\Program Files\Skype\Phone\Skype.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files... Read more

A:Task Manager, Cmd, And Regedit Will Not Start

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. Download KillBox and unzip it to your desktop.Open Killbox and select the Delete on reboot option.Copy and paste the following file to the field labeled "Full path of file to delete"C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exePress the Delete button (the button that looks like a red circle with a white X in it).A first dialog box will ask if you want to delete the file on reboot, press the YES button.A second dialog box will ask you if you want to REBOOT now. Press the YES button.Your computer will reboot.Please post a new hijackthis log.

2 more replies
Answer Match 75.6%

pls help me.
my regedit and task manager are not working.
when i try to open regedit it says "registry editing has been disabled by administrator".
and the when i right click the task bar the task manager option is grey and not working.
i am using windows 7 home premium 64 bit(this version of windows does not have gpedit).
my antivirus software is bitdefender internet security 64 bit.
pls resolve my problem soon

THANKS in advance.
 

A:regedit, task manager not working..

Sounds like malware, I would post in the malware removal forum.
 

2 more replies
Answer Match 75.6%

Once,i came back from a vacation , and when i turned on my PC ,plugged in my new SanDisk Cruzer 16GB ....Every file was infected.Just 1 second.I got enough time to get a HiJackThis log which i included in the post.Well,scanned PC with ESET NOD32 , restarted and everythings ok.But there are leftovers....This.Used UnHookExec.inf , regedit is back.But task manager isn't.Can anybody help?
 

A:Regedit + Task Manager problem...

Also I have been rooting through HKEY_CURRENT_USER and found a folder called "don't load"...It has 3 entries :
1.(Default) REG_SZ (Value Not Set)
2.NCPA.CPL REG_SZ No
3.ODBCCP32.CPL REG_SZ No
so,is it bad?
 

2 more replies
Answer Match 75.6%

Looks like my computer decided to bring in the new year with a bang. Im running windows xp SP2 with 2gb ram, 160 gb, 2*7600gt in SLI, GA-M57SLI-S4 mobo. A friend of mine borrowed my pen drive and returned it with some files on it.

Ever since I pluggedit in and removed it, my task manager cannot be accessd and i get the error msg, "Task manager has been disabled by your administrator". I have 'Speed Fan' & 'Ram Cleaner' running in the background and they both show CPU utilization as 100%.

I tried to use Registry Mechanic 7 to fix the registry, but Registry Mechanic closes by itself without sovling any problems. I ran AVG anti virus and Anti spyware and Zone Alarm's built in anti-spyware check, but no threats were found. I CCleaner to clean out my registry, and also tired System Mechanic 7 but the same problem persists.
i went to Start>run and typed this in.
"REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f"

the first time i did it, i got an error saying that the program was currently in use by another application. when i tried it again, a black dos window flashed before me for a second.

Regedit is not opening. No error msg is displayed. When I tried using the group policy editor, the 'Remove Task Manager' option was set to 'not configured'. If i double click any registry backup file, it opens in notepad.

Now if i try to open task manage... Read more

A:100% CPU usuage+no task manager & regedit

Typing the REG command from Start > Run will cause a command window to appear briefly, so that is normal.

The DisableTaskMgr key may be located in another part of the registry. Download Autoruns: http://www.microsoft.com/technet/sysinternals/Utilities/AutoRuns.mspx which should show what is disabling TaskManager. If regedit and your Control Panel are also being disabled there you should see that too.
 

3 more replies
Answer Match 75.6%

I have run both Spybot and Adaware and both have fixed multiple problems but for some reason I can never get my task manager to open up and for a while I couldn't delete a program called win-dh from my add/remove programs list. Every time I clicked delte it would reappear. Also when I run all of these programs in safe mode it keeps deleting them but the programs keep recreating registry entries and starting all over again. SO yeah any and all help would be appreciated. Everytime I try to run HJT it closes automatically and it does the same to my Task Manager and Regedit I am getting extremly frustrated.

PS. this is not my computer I am fixing it for a family at my church.
 

A:Cant get Task manager or Regedit to open

Click here to download HJTsetup.exe: http://www.thespykiller.co.uk/files/HJTSetup.exe
Save HJTsetup.exe to your desktop.

Double click on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
Put a check by Create a desktop icon then click Next again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click Finish and it will launch Hijack This.
Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
Click Save to save the log file and then the log will open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
 

2 more replies
Answer Match 75.6%

Well, somehow Task Manager and registry editor got disabled and I can't get it working. Even with gpedit.msc I open it once, than I can't open another. Same with registry editor. Please help me out.
------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 9:03:50 AM, on 9/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\laxtp.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winpirvo.exe
C:\WINDOWS\system32\mmc.exe
C:\Program Files\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1... Read more

More replies
Answer Match 75.6%

I cannot access the task manager or regedit
i have just reformated my pc as it had the xp 2008 antivirus on.
Have tried taskmanager v.2 opens then closes
any help on this would be greatly appreciated.

have included hijackthis log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:45:40, on 10/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\winwqov.exe
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\wineobsrj.exe
C:\Program Files\Ou... Read more

A:Task Manager and regedit not working

This is not the full HijackThis log. Please go to the following URL, read and follow the malware cleaning instructions, including instructions for attaching the logs rather than pasting them:

New malware cleaning instructions from TechSpot:

http://www.techspot.com/vb/post645589-1.html
 

58 more replies
Answer Match 75.6%

Logfile of HijackThis v1.99.1Scan saved at 7:21:04 AM, on 2/28/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Trend Micro\Tmas\Tmas.exeC:\Program Files\Microsoft AntiSpyware\gcasDtServ.exeC:\Program Files\Microsoft AntiSpyware\gcasServ.exeC:\Documents and Settings\Master\Desktop\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missingO4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exeO4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security ... Read more

A:Pop Ups And Task Manager/regedit Hijack Help Me, Please

I have tried everything, none of my spyware removal devices detect anything but I still have annoying pop-ups and I can't get into my task manager or regedit.

When the problems started my Microsoft Anti spyware, Trend micro spyware, and Spy-bot did detect and remove Surf Side Kick.

I don't know anything about computers so any help would be appreciated, I had shut down all my spyware devices while doing some audio recording the other night and I think I picked up whatever problem this is while searching for some free (legally free) drum loops and ended up on some warez sites.

4 more replies
Answer Match 75.6%

I lost my task manager and regedit at the same time. I have tried all of the tricks and they come back for a while, then they are gone again...any sugestions?

Here's tonights hijack this log:
Logfile of HijackThis v1.99.0
Scan saved at 9:59:11 PM, on 1/8/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
C:\WINDOWS\System32\Fast.exe
C:\WINDOWS\System32\mqsvc.exe
C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\Explorer.EXE
c:\WINDOWS\Fonts\lsass.exe
C:\WINDOWS\System32\taskswitch.exe
C:\WINDOWS\System32\NILaunch.exe
C:\WINDOWS\System32\khooker.exe
C:\Program Files\Trend Micro\Internet Security\pccguide.exe
C:\Program Files\Trend Micro\Internet Security\PCClient.exe
C:\PROGRA~1\Hardware\Mouse\Amoumain.exe
C:\PROGRA~1\Hardware\Keyboard\Ikeymain.exe
C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\EarthLink TotalAccess\Spyware Blocker\SpywareBlocker.exe
C:\Program Files... Read more

A:Solved: task manager and regedit gone

16 more replies
Answer Match 75.6%

Hi, yea everytime i go to open the task manager and regedit it just keeps closing... ive ran an online AV (trend micro housecall), and 2 spybot scanners (S. Search and Destroy, Ad-Aware) and i couldnt find anything... so i downloaded HJT... but cant figure out what is causing the problem... ive seen a few posts with the same situation but their files were different... heres the HJT log

Logfile of HijackThis v1.96.0
Scan saved at 8:30:24 PM, on 8/30/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\System32\MSCONFIG35.EXE
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\Executive Software\DiskeeperServer\DKService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinAce\WinAce.exe
C:\Docum... Read more

A:My Task Manager, REGEDIT keeps closing...

7 more replies
Answer Match 75.6%

I can't get regedit or task manager to work, when I try
I get message they are disabled by administrator. I didn't disable them. Also I have Trend Micro antivirus
and it want update or scan. I can't go to trendmicro.com
My computer is using Windows XP Pro.
 

A:Regedit and task manager disabled by adm.

I solved the problem by uninstalling TrenMicro Anti Virus and reinstalling. The trick was not to activated
it until after it completed installation. Then I updated,
activated and scanned. That got rid of the virus. Then
I fixed regedit with a fix I found on the web , the I
fixed task manager with another fix from the web.
 

1 more replies
Answer Match 75.6%

HI I HAVE A HUUGE PROBLEM...WHICH MAY LOOK SMALL FOR SOME OF YOU

whenever I open up REGEDIT it stays on for one second and *poof* it closes right away same goes with the task manager

I hope you guys could give me a solution as soon as possible

THANKS!
KNIXXED:grinthumb
 

A:Regedit And Task Manager Problem

Sounds like you've got a virus.
 

13 more replies
Answer Match 75.6%

Hi:

My task manager has been disabled as well as regedit. I also keep getting a CThelper.exe pop up that says I have no disk in the drive.

As I found on another post, I downloaded RSIT. Here are the results from the log.txt file. The info.txt is attached.

Thanks for your help, John

=========================

Logfile of random's system information tool 1.05 (written by random/random)
Run by John at 2008-12-28 07:55:15
Microsoft Windows XP Professional Service Pack 2
System drive C: has 76 GB (51%) free of 148 GB
Total RAM: 2046 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:22 AM, on 12/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel... Read more

A:Task Manager / Regedit Disabled

Hi:

My task manager has been disabled as well as regedit. I also keep getting a CThelper.exe pop up that says I have no disk in the drive.

As requested, I've provided the information needed below and in the attachments.

Thanks for your help, John

DDS (Version 1.1.0) - NTFSx86
Run by John at 21:29:43.09 on Tue 12/30/2008
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1470 [GMT -6:00]

AV: McAfee VirusScan *On-access scanning disabled* (Outdated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files... Read more

11 more replies
Answer Match 75.6%

I am using windows Xp, service pack 2.

Yesterday, my computer begins to run quite slow sometimes and I cannot open the task manager to check what is slowing my system down. I was able to open it the last time I use it. It shows "task manager has been disabled by your administrator" when I press Ctrl+Alt+Delete. I also cannot open my regedit.

I had also google it and find quite some solution. I try most of it and the task manager just shows up for a mili seconds and close again. After I restart it, it shows back again "task manager has been disabled by your administrator".

Another problem:
This problem I had it a long time ago. This would show up every time I open my computer, is there anyway to prevent it from opening every time I start up windows?:

Windows Script Host
Script: C:\Documents and Settings\Xp\Start Menu\Programs\Startup\Recycled.vbs
Line: 2
Char: 1
Error: The system cannot find the file specified
Code: 80070002
Source: (null)

----------------------------------------------------

This is my Hijack This log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:59:12 AM, on 9/7/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDO... Read more

More replies
Answer Match 75.6%

After recently installing and un-installing Lime Wire my task manager stopped working, as did my regedit. I removed all Lime Wire files and my tak manager started to work. About a day later it stopped again. I have run.. PestPatrol, Adaware, Spybot, Super Anti Spyware(normal and safe mode), Spywaredoctor, Dr web-cureit and bitdefender, as well as RRT and nothing has worked. I am still task managerless and after a few attempts at downloading HJT, I've finally managed to do it, so here is my log... Logfile of HijackThis v1.99.1Scan saved at 12:20:52 PM, on 6/3/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\AOL\ACS\AOLAcsd.exeC:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exec:\program files\mcafee.com\agent\mcdetect.exec:\PROGRA~1\mcafee.com\agent\mctskshd.exeC:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\wanmpsvc.exeC:\WINDOWS\system32\fxssvc.exeC:\WINDOWS\E... Read more

A:Non-working Task Manager Or Regedit

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Jena054 My name is Richie and i'll be helping you to fix your problems.Please make sure all hidden files are showing:* Click 'Start'.* Open 'My Computer'.* Select the 'Tools' menu and click 'Folder Options'.* Select the 'View' tab.* Under the 'Hidden files and folders' heading select 'Show hidden files and folders'.* Uncheck the 'Hide file extensions for known types' option.* Uncheck the 'Hide protected operating system files (recommended)' option.* Click Yes to confirm.* Click OK.-----------------------------------Go here:http://virusscan.jotti.org/ Using the 'Browse' button,browse to:C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exeThen press the 'Submit' button.Wait while the file is scanned.Post the results into your next reply please.If Jotti's too busy,try here:Go here:http://www.virustotal.com/en/virustotalf.htmlUsing the 'Browse' button,browse to:C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exeThen click on 'Send'.Post the results into your next reply please.Also post a new Hijackthis log.

15 more replies
Answer Match 75.6%

My computer has something installed on it that prevents the user from being able to run CMD, regedit and also prevents CTRL+ALT+DELETE. I have seen other topics on this issue but the cause seems to be different for each one.I have already installed SPYBOT and ran it. Problem still exists. While troubleshooting, I found that on bootup we can open up task manager if I am quick enough. The task running is called "setup" and it is attached to a process 'svchost'. If I end this process or task then cmd, regedit, ctrl+alt+delete works fine.Here is the hijackthis log.Logfile of Trend Micro HijackThis v2.0.0 (BETA)Scan saved at 9:30:10 AM, on 7/5/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\brsvc01a.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\brss01a.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svcho... Read more

A:Another Program Using Cmd, Task Manager, Regedit?

Hello,It's important you follow the next steps in the right order without missing any step.;* Download Brute Force Uninstaller.Unzip it to a folder of it?s own (c:\BFU).Read here how to unzip/extract properly:http://metallica.geekstogo.com/xpcompressedexplanation.htmlStart the Brute Force Uninstaller by doubleclicking BFU.exeNext to the 'scriptfile to execute'-window you'll see a little icon as shown in next picture: When you click that icon, a little window will open that says: 'Please enter the full URL to the sript you want to execute'In the field, copy and paste next URL:http://metallica.geekstogo.com/alcanshorty.bfuClick Ok. Then click execute in Brute Force Uninstaller.Extra note:If nothing happens after pressing the Execute button, this means that the script didn't download. In that case, download the script ( alcanshorty.bfu ) manually from above url ( rightclick on it and choose 'save as' and save it in your BFU-folder). Then start BFU.exe again and click the browse button next to the 'scriptfile to execute'-windowBrowse to the script you downloaded and Click Ok and Execute in Brute Force Uninstaller.Wait for the complete script execution box to popup and press OK.Press exit to terminate the BFU program Then, * Download Combofix to your desktop.Doubleclick combofix.exeFollow the prompts.Don't click on the window while the fix is running, because that will cause your system to hang.When finished and after reboot (in case it asks to reboot), combofix will open aga... Read more

4 more replies
Answer Match 75.6%

I have not been able to use Task Manager / regedit / cmd.The problem is on my home desktop.I have followed all the steps in the Preparation Guide, but was unable to get step 5 to work. Housecall started but fell over. At this stage I went straight to step 6 successfully.After quiet a few reboots & visits to safe mode I still have no joy with using Task Manager / regedit / cmd. (all work ok in safe mode, just not normal mode)Please can someone help?Thanks in advance.Logfile of HijackThis v1.99.1Scan saved at 11:00:41 PM, on 7/05/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\CA\eTrust Antivirus\InoRpc.exeC:\Program Files\CA\eTrust Antivirus\InoRT.exeC:\Program Files\CA\eTrust Antivirus\InoTask.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Photodex\ProShowGold\ScsiAccess.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:&#... Read more

A:Cannot Open Task Manager Regedit Cmd

Hello,* Download Brute Force Uninstaller.Unzip it to a folder of it?s own (c:\BFU).Read here how to unzip/extract properly:http://metallica.geekstogo.com/xpcompressedexplanation.htmlStart the Brute Force Uninstaller by doubleclicking BFU.exeNext to the 'scriptfile to execute'-window you'll see a little icon as shown in next picture: When you click that icon, a little window will open that says: 'Please enter the full URL to the sript you want to execute'In the field, copy and paste next URL:http://metallica.geekstogo.com/alcanshorty.bfuClick Ok. Then click execute in Brute Force Uninstaller.Extra note:If nothing happens after pressing the Execute button, this means that the script didn't download. In that case, download the script ( alcanshorty.bfu ) manually from above url ( rightclick on it and choose 'save as' and save it in your BFU-folder). Then start BFU.exe again and click the browse button next to the 'scriptfile to execute'-windowBrowse to the script you downloaded and Click Ok and Execute in Brute Force Uninstaller.Wait for the complete script execution box to popup and press OK.Press exit to terminate the BFU program.Please download, install, and update AVG Anti-SpywareLoad AVG Anti-Spyware and then click the Update tab at the top. Under Manual Update click Start update.After the update finishes (the status bar at the bottom will display "Update successful")
Then click on the Scanner tab at the top. Click the "Settings" tab and then change... Read more

7 more replies
Answer Match 75.6%

my system says cannot find taskmanger or regedit whenever i wnat to access them.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:48:40 AM, on 3/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\wmplayer.exe
C:\WIN... Read more

More replies
Answer Match 75.6%

ok.. i have a problem with regedit and task manager...yesterday i donwloaded a progrem whcih caused the task manager and regedit to be disabled by the administrator but how can that be if i am the administrator??

here is a hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49, on 2009-02-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\winvnc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ROCCAT\Kone Mouse\KoneHID.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ROCCAT\Kone Mouse\osd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\UPORAB~1\LOCALS~1\Temp\kvxxc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.ex... Read more

A:Task manager and regedit won't open

7 more replies
Answer Match 75.6%

i can't open regedit, msconfig, and task manager.can anyone help me?, please.here is my HJT scan log:Logfile of HijackThis v1.99.1Scan saved at 1:28:18 AM, on 4/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0011)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\LEXPPS.EXEC:\WINDOWS\Explorer.EXEC:\WINDOWS\ehome\ehtray.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\WINDOWS\system32\nvraidservice.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\MSNShell\BIN\MSNShell.exeC:\Program Files\MSN Messenger\MsnMsgr.ExeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\WINDOWS\eHome\ehRecvr.exeC:\WINDOWS\eHome\ehSched.exeC:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exeC:\WINDOWS\system32�... Read more

A:I Can't Use Regedit, Msconfig,task Manager

Hello

I would like to take a look at this log for you and will get back to you as soon as I can.

Thank You.

5 more replies
Answer Match 75.6%

My computer is really weird, a week now...gone so slow, CTRL+ALT+DEL is not working,

I already tried some simple advices on how to enable the task manager, then it works,

but after few mins. the task manager and also the regedit (from run) doesnt appear when hit

CTRL+ALT+DEL

This is my log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:11:39 PM, on 7/17/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RVHOST.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RVHOST.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\W... Read more

A:task manager + regedit has been disabled

16 more replies
Answer Match 75.6%

I have the same problem as most people on this board concerning task manager and regedit. These commands would pop-up for a second then disappear. Unfortunately, I am not very good with tech terms however this board seems to be very helpful to newbies and experienced users alike. I have attached my hijackthis log with this post. Please help me fix my problem. Thanks.

Logfile of HijackThis v1.96.0
Scan saved at 4:40:44 AM, on 8/12/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Winamp\Winampa.exe
C:\WINNT\system32\WUAUMQR.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.supret.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\... Read more

A:Problems with task manager, regedit

Scan with HijackThis, put a checkmark at and "Fix checked" the following entries.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.supret.com/
O4 - HKLM\..\Run: [Winsock2 driver] WUAUMQR.EXE

Restart your computer in Safe mode and delete C:\WINNT\system32\WUAUMQR.EXE file.
 

3 more replies
Answer Match 75.6%

Hi, Im SuperSonic. I couldnt find much time to type everything in again, so I pasted what I typed in Yahoo Answers some time ago. Heres the story from the beginning:-

Yesterday, I took a pen drive from my friend and inserted it in the comp. When I tried to open the pen drive folder, a message came up "Windows cant find the file Axxx.vbs"(xxx was a number) At the same time Symantec AntiVirus popped up, saying it had quarantined 4 files(3 Axxx.vbs and 1 AQxxx.vbs and some registry entries). Then I took the pen drive out and started minding my other work. Then I realized that Task Manager and Regedit were disabled. Then I found that Symantec Antivirus was no longer running. I tried to run it but it won't start(or maybe closing instantly).

Then I installed Spybot S&D, but it started for a few seconds, was normal, then quit instantly. Same happened to ESET. Then I tried to boot into Safe Mode, but it kept rebooting while displaying a list of .sys files that were being run.

In the process I lost a lot of important files. When restarting, the computer said my user profile was corrupted and created a temp profile. I thought it was a permanent profile, so I Cut-Pasted everything from my original profile to the new profile. Today when I started up, the temp profile was gone, and with it, all the things I'd copied.

So, the main problem now is that Firewall,Regedit and Task Manager keep getting disabled, and antivirus stuff refuse to run. Any help would be ap... Read more

A:Regedit/task manager disabled (+HJT log)

13 more replies
Answer Match 75.18%

Logfile of HijackThis v1.96.0
Scan saved at 7:14:11 AM, on 8/6/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\WUAUMQR.EXE
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 ... Read more

A:[Resolved] task manager closes right when it starts

Scan with HijackThis, put a checkmark at and "Fix checked" the following entries.

O4 - HKLM\..\Run: [Winsock2 driver] WUAUMQR.EXE
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/28051e716ae2b5893018/netzip/RdxIE2.cab
O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C} (NSUpdateLiteCtrl Class) - http://204.177.92.201/quickdl/action/NSupd9x.cab

Restart your computer and delete

C:\WINDOWS\System32\WUAUMQR.EXE file.
 

3 more replies
Answer Match 75.18%

Hi this problem strated last week each time I press alt+ctrl+delete the windows task manager suddenly appears and then suddenly disapears.I have some programs in the background runing that slow down my computer and I can't turn them off. What should I do?
 

A:Windows Task Manager closes suddenly

Hi Pav...
Man that sounds like possible virus activity. If you don't have a scanner you know better =) .... get your scanner updated with the latest and reboot into SAFE mode. Do a thorough scan.
If the problem persists let me know and I'll dig a little further.
 

1 more replies
Answer Match 75.18%

Hey,

Earlier today, I closed my Opera browser, then tried several times to get it to reopen, but for some reason it wouldn't. When I opened up Task Manager to see what was up, then I realized...it was only staying on the Processes list for one or two seconds before disappearing!

So I went to Firefox (which for some reason was working) and installed Google Chrome. That was successful, but the first time I tried opening it, it had the same issues Opera was having...stayed on the Processes list for one/two seconds, then disappeared.

I could find NO threads similar to mine anywhere...could you help please?

Computer Info:

System: Microsoft Windows XP
Professional
Version 2002
Service Pack 3
Computer: Intel(R) Pentium(R) 5 CPU
2.80 GHz
2.79 GHz, 2.50 GB of RAM
Physical Address Extension

A:Task Manager automatically closes down browsers

UPDATE: I've tried System Restore, AdAware, SuperAntiSpyware, MalwareBytes' Anti-Malware...and NOTHING seems to be working...

2 more replies
Answer Match 75.18%

Hi All
Hope every one is enjoying the holidays.
Often when I close IE, the screen closes right away but it still runs in the background somewhere, and it eats up 40% of my ram. when it gets real annoying, I sometimes choose end task in the task manager. I dont know if thats a good idea or not. does anyone have a solution?
thank you in advance
Zevy

I Have Windows xp service pack 2, IE7, 1mb RAM, pentium processor

A:IE closes screen but still runs in task manager

Hello and welcome to TSF

Please do this:


Produce a list of IE add ons
Click Here to download StartUplist. Save it to your desktop.
Extract the files.
You should now have StartupList.exe double click on it.
Wait until it is complete.
Right click on Browser Helper Objects (BHO), click on Save Node and all sub nodes as.. then when the save box appears type in BHO.txt and click Save.
Now right click on ActiveX Objects, click on Save Node and all sub nodes as.. then when the save box appears type in ActiveX Objects.txt and click Save.
Then right click on Internet Explore toolbar, click on Save Node and all sub nodes as.. then when the save box appears type in IE toolbars.txt and click Save.
Last one, right click on Internet Explore buttons/tools, click on Save Node and all sub nodes as.. then when the save box appears type in IE buttons.txt and click Save.

Open up the folder where Startuplist.exe is stored and locate thes files, please post them in your next reply:BHO.txt
ActiveX Objects.txt
IE toolbars.txt
IE buttons.txt

8 more replies
Answer Match 75.18%

Any help would be much appreciated
I can't right click because task manager closes automatically and the system just runs slow and there are serious problems on this computer
this site is great are there places you can make donations?

Logfile of HijackThis v1.99.0
Scan saved at 4:34:47 PM, on 1/21/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS\zjpqknfn.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\BSPLAYER.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\America Onlin... Read more

A:Many problems Task Manager closes automatically

Hi and welcome. Please don't duplicate post. Security forums are very very busy and you need to have a bit of patience.

Your log is pretty messy, so only the gurus will tackle it

http://forums.techguy.org/showthread.php?t=321982
 

1 more replies
Answer Match 75.18%

ok, after some searching I have determined that I have a virus/worm/trojan that causes the task manager and reg editor to close immediatly after I open it. I have managed to open the task manager by changing the name is the taskmgr.exe file, but it still cannot be open by ctrl+alt+delete. Here is my HijackThis log file and if anyone who has more experience with the logs could let me know what they think the problem is that owuld be much apprecited. oh, and i have ran Norton AV in safe mode and the problem was not found.

Logfile of HijackThis v1.99.0
Scan saved at 4:26:49 PM, on 2/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\WINLOGONPC.EXE
C:\Program ... Read more

A:Solved: Task Manager and Regeedit closes!

8 more replies
Answer Match 75.18%

I'll cut to the point. I got a virus from a file I downloaded from Kazaa Lite. AVG Anti-Virus Resident Shield did not stop the virus from infecting my system, which upset me a great deal. So, enough chatter. Let's get to diagnosing and resolving.
Symptoms

- Task manager and registry editor close immediately (less than one second) after they are opened
- Task manager and registry editor both open just fine in Safe Mode
- Task manager works fine when I copy taskmgr.exe to taskmgr.com and run the .com file. Same goes for regedit.exe and the regedit.com clone
- Experiencing the following problems as reported on the Symantec Security Response report on W32.Spybot.Worm:

Creates and shares a folder on the KaZaA file-sharing network, by adding the following registry value:

"dir0"="012345:<configurable path>"

to the registry key:

HKEY_CURRENT_USER\SOFTWARE\KAZAA\LocalContent

Copies itself to the configured path as filenames designed to trick other users into downloading and executing the worm.
Click to expand...

Methods Proven Ineffective to Resolve Problem

- Found and deleted all files created in the aforementioned generated Kazaa share folder, with the help of AVG Anti-Virus
- Deleted generated Kazaa share folder (C:\WINNT\system32\shellext)
- Ran partial scans on suspected directories using Trend Micro Housecall
- Ran full scan using Panda Software ActiveScan. NOTE: This scan did detect and remove a virus, but did not resolve the prob... Read more

A:[Windows 2000] Task Manager and Registry Editor close immediately

7 more replies
Answer Match 74.76%

Yesterday, my computer begins to run quite slow sometimes and I cannot open the task manager to check what is slowing my system down. I was able to open it the last time I use it. It shows "task manager has been disabled by your administrator" when I press Ctrl+Alt+Delete. I also cannot open my regedit.

I had also google it and find quite some solution. I try most of it and the task manager just shows up for a mili seconds and close again. After I restart it, it shows back again "task manager has been disabled by your administrator".

Another problem:
This problem I had it a long time ago. This would show up every time I open my computer, is there anyway to prevent it from opening every time I start up windows?:

Windows Script Host
Script: C:\Documents and Settings\Xp\Start Menu\Programs\Startup\Recycled.vbs
Line: 2
Char: 1
Error: The system cannot find the file specified
Code: 80070002
Source: (null)

----------------------------------------------------

This is my Hijack This log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:59:12 AM, on 9/7/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C: ... Read more

A:Task manager and Regedit cannot open: With Hijackthis log

Hello and welcome to Bleeping Computer.My name is km2357 and I will be helping you to remove any infection(s) that you may have.I will be giving you a series of instructions that need to be followed in the order in which I give them to you.If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.Please do not start another thread or topic, I will assist you at this thread until we solve your problems.Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.Sorry for the delay in replying, the forum is very busy. If you still need help, please do the following:Step # 1 Download and run DDSDownload DDS and save it to your desktop from here or here or hereDisable any script blocker, and then double click dds.scr to run the tool. When done, DDS will open two (2) logs: DDS.txt Attach.txtSave both reports to your desktop. Post them back to your topic.Step # 2: Download and Run GmerPlease download gmer.zip from Gmer and save it to your desktop.***Please close any open programs ***Double-click gmer.exe. The program will begin to run.**Caution**These types of scans can produce false positives. Do NOT take any action on any "<--- ROOTKIT" entries unless advised by a trained Security AnalystIf possible rootkit activity is found, you will be asked if you would like to perform a full scan. Cli... Read more

3 more replies
Answer Match 74.76%

Well, I officially got a bad one...

I work on computers everyday, and know alot about removal, and I am quite shocked that I was not able to do anything with this...

Here are the symptoms:

No Task Manager - I ran a small line that re-enables it, but in about 5 seconds it is disabled again

No regedit - I ran another command, it brings it back for 5 seconds as well, then it is disabled.

Cannot view hidden files - I put a tick in for "Show hidden files and folders" I can see them for 5 seconds, then nothing.

So, I ran alot of scans (I will name them) and none of them worked, I was going to do them all in safe mode now... but now whenever I try to reboot into safe mode, i get a STOP: ox00000007b error (never happened before)

It is a trojan downloader for sure... in netstat, I can see a bunch of connections randomly appear, then my anti virus goes nuts, and Heals those files, but after about 10 minutes it does it over again...

My computer now has a bunch of weird connections to my router... never saw that before (about 8 connections to it)

Sadly, I clicked on one link, a popup came, a windows installer window, and thats what caused this all, I clicked cancel on the MSI window, but it didnt help...

So far I ran:

HJT (no suspicious entries thru my eyes)
Adaware 2007
Spybot 1.6
SUPER Anti-spyware
Trojan Hunter
Malware Bytes
AVG (but it caused my computer to crash about 150k files in)
And ComboFix

Nothing has changed the status... ... Read more

A:No Task Manager/Regedit/Hidden files

Well, I solved my own problem...

Since nobody here could help me, hopefully this will help someone else...

I downloaded AntiVir and scanned... and it got rid of the virus... along with half of my applications...

I got the W32/Sality.AA virus from a website, it automatically installed, I plan on taking any action I can against the site.

But I lost alot of my executables, including my old anti-virus...

System Restore wouldnt work either... but if these symptoms are happening to you after typical scans, you probably have the Sality.AA virus.

1 more replies
Answer Match 74.76%

I know, I've seen lots of posts of people whose task managers won't stay open....but Mine seems to be different. I am using Windows XP, and have just done Virus scans as well as scanning with Adaware.
any help would be much appreciated.

Logfile of HijackThis v1.99.0
Scan saved at 10:23:48 AM, on 12/17/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
C:\WINDOWS\System32\MMTASK7.EXE
C:\Program Files\Windows ControlAd\WinCtlAd.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Windows ControlAd\WinCtlAdAlt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\Documents and Settings\Jeremy Kis\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local ... Read more

A:Task manager and regedit won't stay open

7 more replies
Answer Match 74.76%

I have scanned my computer for viruses with Norton and it shows nothing. Task manager won't come up no matter what I push and when I go to regedit, it says this fle is in use. Thanks for any help!
Here is my HJT log
Logfile of HijackThis v1.99.1
Scan saved at 11:54:59 AM, on 3/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.ex... Read more

A:Regedit and task manager not working (HJT included)

I've had some experience in this, but I just joined this forum, so if you wish, you can hold off on deleting the HijackThis log entries until you get confirmation from a long-standing member here, but here are my suggestions:

Background:

1. Run online scan: Trend Housecall
Delete all if finds, and if it can't delete something, post here.

2. Scan with adaware SE. http://www.lavasoftusa.com/software/adaware/ Quoted directions:

"Scanning with Ad-Aware Se

Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan.

Close ALL windows except Ad-Aware SE.

Click on the"world" icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.

Once the update is finished click on the "Gear" icon (second from the left at the top of the window) to access the preferences/settings window.

In the "General" window make sure the following are selected in green:

? Automatically save log-file

? Automatically quarantine objects prior to removal

? Safe Mode (always request confirmation)
Under Definitions:

? Prompt to udate outdated definitions - set the number of days
Click on the "Scanning" button on the left and select in green :

Under Driver, Folders & Files:

? Scan Within Archives
Under Select drives & folders to scan:

? choose all hard drives
Under Memory & Registry: al... Read more

1 more replies
Answer Match 74.76%

Hi there.
I cannot access neither to my task manager, nor regedit and nor to msconfig. Its says that another program is using this file. However I run process explorere software from http://www.sysinternals.com/Utilitie...sExplorer.html and still could not find a program which uses them. even i could not find these processes.

Any help would be very much appreciated

Respect
Taleh
 

A:task manager, regedit and msconfig is not working

closed duplicate
http://forums.techguy.org/windows-nt-2000-xp/453995-no-task-mangaer.html
 

1 more replies
Answer Match 74.76%

I'm having a problem with the Task Manager and Regedit. The applications appear for a couple of seconds and disappear. I've read a couple of forums about this topic. I'm guessing it is a virus and I have ran different virus checkers, adware and spybot and detected nothing. I made a copy of TaskMgr.exe and renamed it differently but I don't know what I'm supposed to do with that. I used HT and this is what I got. I don't understand what it means so if anyone can help me, I'd appreciate it.
Logfile of HijackThis v1.98.0
Scan saved at 2:12:03 PM, on 7/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\qttask.exe
C:\WINDOWS\System32\KQXCMZKQ.EXE
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\lexpps.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Avant Browser\iexplore.exe
C:\Documents and Settings\Annabelle\Local Settings\Temp\HijackThis.exe
C:\Documents and Settings\Annabelle\Desktop\TASK2.exe

R1 - HKLM\S... Read more

A:[Solved] Task Manager, Regedit disappears

6 more replies