ComputerForum.com ComputerForum.com  
TigerDirect
 
Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Display Modes
Old 03-29-2008, 03:38 PM   #1 (permalink)
Bronze Member
 
Hey it's me's Avatar
 
Join Date: Jan 2008
Location: NY, NY
Posts: 93
Default Can't open HJT or REGEDIT!

OK, I'm not sure what I've done but, I'm working on my IBM T40 thinkpad and all of the sudden I can't open regedit and everytime I try and download and install HJT I get the same issue. Avast tells me I have about 4 different types of trojans that begin with Win32:. I was able to download and I'm runnig S&D but, I'm concerned about the others I mentioned just now. THAT is the 1st time I've ever encountered this issue regarding my registry. I've deleteled some things from it recently, but they were sfotware files I wanted completely removed. I also found a folder called Vauead and I deleted it. Ididn;t find anything like it in my add remove control panel so I simply deleted it from the programs file.

I'm scared. this is my father's computer on loan. I'm trying to see the Dell I've had windows updates problems with and you guys are helping me fix so I can buy myself my own portable computer which I need for work. I have to return this to him in perfect shape. I've installed some things I use on it for now. But I'm not sure why that would be a problem. ANyway

PLEASE HELP clean this computer for me.
thank you in advance for your incredible FREE HELP! I can't tell you how grateful I am for this community!!

IBM Thinkpad T40
windows XP PRo
159 GHZ
Pent M
512 ram
Hey it's me is offline   Reply With Quote


Old 03-29-2008, 03:42 PM   #2 (permalink)
Bronze Member
 
Hey it's me's Avatar
 
Join Date: Jan 2008
Location: NY, NY
Posts: 93
Default

BTW, this is the message I get when I try and install HJT or open the regedit:

Windows cannot find 'C:\Program Files\Trend Micro\Hijack This\HijackThis.exe'. Make sure you tped the name correctly, and then try again. To search for a file, click start button, and then click search.
and....
Windows cannot find 'regedit'. Make sure you tped the name correctly, and then try again. To search for a file, click start button, and then click search.


VERY disconcerting indeed! would you not agree?
Hey it's me is offline   Reply With Quote
Old 03-29-2008, 04:29 PM   #3 (permalink)
Diamond Member
 
g25racer's Avatar
 
Join Date: Feb 2008
Posts: 3,583
Default

Your def infected. Try doing a system restore to an earlier point.
__________________
CPU - AMD Athlon 64x2 5200+ @ 2.6ghz
Ram - 2GB Stock clock
HD - 320gb seagate & Samsung 750gb 32mb cache
GPU - XFX 8600GT XXX Zalman @ 680 or 700mhz
PSU - Ultra X-finity 600watt
OS - Vista Home Premium(32) & XP Pro and Vista
Audio - JVC 460watts
Control - Logitech G25 Wheel & Logitech Rumblepad 2
Games - GTR2 and LFS
-- Race Sim's for Life --
g25racer is offline   Reply With Quote
Old 03-29-2008, 07:28 PM   #4 (permalink)
Diamond Member
 
GameMaster's Avatar
 
Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,846
Default

OK let's try to run your HijackThis.
Rename it.
Go to the HijackThis. Rename the Trend Micro folder as...Racer, rename your HijackThsi folder as Game and rename Hijackthis.exe as master.exe ( in Properties ).
Then run the program and post the scan results.
__________________
dznutz:
Quote:
a firewall is like a gate. it keeps the bad people out and the dog in but it's not fool proof. but lets say you download and run an infected program. that will be like letting in a "friend." if it's infected you run that program you can get malware. that's like a friend raping your family and stealing your money.
GameMaster is offline   Reply With Quote
Old 04-07-2008, 04:11 AM   #5 (permalink)
Bronze Member
 
Hey it's me's Avatar
 
Join Date: Jan 2008
Location: NY, NY
Posts: 93
Default

Hi Game master, as always your directions are ace! here's the HJT log after I changed the names as you told me to. sorry it took so long for me to get back to you. this computer still can't open regedit. my week last week was insane, I will be back on again to see your repsonse Monday 4/7/08.
Thanks again, can;t fathom what I did to make my registry not accessable.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:16:39 PM, on 4/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Mozilla Firefox 3 Beta 4\firefox.exe
C:\Program Files\racer\Game\master.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/mini...ansporter.cab?
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1154110343740
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1158602166459
O16 - DPF: {9FE1C75D-439C-4D76-9FFB-18E592DE51E6} - https://na4.salesforce.com/setup/out...s2/install.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 7561 bytes
Hey it's me is offline   Reply With Quote


Old 04-07-2008, 09:25 AM   #6 (permalink)
Diamond Member
 
GameMaster's Avatar
 
Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,846
Default

Hmm...your problems (and HijackThis renaming help ) show presence of Trojans. However I can't find any in your log!

Please open your HijackThis and choose Do a system scan only.
Check this entry:

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

Now click Fix checked.

Reboot your computer.
Is it any better ( I doubt it )?

Download Deckard's System Scanner (DSS) to your Desktop. You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<- this one will be minimized.
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your reply.
__________________
dznutz:
Quote:
a firewall is like a gate. it keeps the bad people out and the dog in but it's not fool proof. but lets say you download and run an infected program. that will be like letting in a "friend." if it's infected you run that program you can get malware. that's like a friend raping your family and stealing your money.
GameMaster is offline   Reply With Quote
Old 04-07-2008, 11:24 PM   #7 (permalink)
Bronze Member
 
Hey it's me's Avatar
 
Join Date: Jan 2008
Location: NY, NY
Posts: 93
Default

Hi Game master you can find

main.txt here:

http://www.savefile.com/files/1490369


extra.txt here:

http://www.savefile.com/files/1490369


ok, GM, is it possible I perhaps did something stupid and erased my registry?? is that possible?



NOW I'm scared!
Hey it's me is offline   Reply With Quote
Old 04-07-2008, 11:59 PM   #8 (permalink)
Platinum Member
 
Join Date: Jul 2006
Posts: 804
Default

Are you using an administrator account on the computer?
soccerdude is offline   Reply With Quote
Old 04-08-2008, 12:18 AM   #9 (permalink)
Bronze Member
 
Hey it's me's Avatar
 
Join Date: Jan 2008
Location: NY, NY
Posts: 93
Default

uhm? what do you mean?
Hey it's me is offline   Reply With Quote
Old 04-08-2008, 12:50 AM   #10 (permalink)
Diamond Member
 
Verve's Avatar
 
Join Date: Sep 2005
Location: Tampa Bay, Florida
Age: 18
Posts: 2,486
Default

not that I'm a big expert or anything, but wouldn't an antivirus boot scan be helpful?
__________________
Formerly Starwarsman
HP DV6885 Special Edition
Core2Duo T8100 @ 2.1 GHz
3GB DDR2 Ram
250GB SATA HDD
Geforce 8400m GS
Vista Home Premium SP1

The Masterplan
Verve is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Win Explorer Shortcuts Open In Same Window KlumpDud Operating Systems 9 11-11-2006 03:55 AM
cannot open file once downloaded PLEASE HELP speedaccordinly General Software 8 11-09-2006 06:00 AM
Some files open slow (related to networking) loginn Operating Systems 12 10-31-2006 05:07 AM
Windows Cannot Open This File...... mattizzle General Software 2 10-19-2006 09:03 PM
SPY Ware and not being able to open a window CCsoultions Computer Security 2 04-05-2005 03:06 PM


All times are GMT +1. The time now is 01:49 PM.


Powered by: vBulletin Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.
Copyright © 2002-2007 Computer Forum and Web Design Forum