Regedit and Task manager disabled by virus

S

Skorpioen

Hi,

My regedit and task manager has been disabled by a virus.

will the www.dougknox.com fix work.

what is worrying me is that the virus trojan still operates even when I
start in safe mode, and nothing has been able to detect or delete it yet...

please help
 
D

David H. Lipman

From: "Skorpioen" <[email protected]>

| Hi,

| My regedit and task manager has been disabled by a virus.

| will the www.dougknox.com fix work.

| what is worrying me is that the virus trojan still operates even when I
| start in safe mode, and nothing has been able to detect or delete it yet...

| please help

Either it is a virus or a trojan. There is no such thing as a "virus trojan". Chances
are that you have a trojan.

Two suggested programs to try to remove what's infected your PC...

Malwarebytes Anti-Malware
http://www.malwarebytes.org/mbam/program/mbam-setup.exe

SuperAntiSpyware
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE
 
M

Mick Murphy

Try these 2 Programs:

http://www.spybot.info/en/index.html

Spybot Search & Destroy 1.6 is a very good, FREE Anti-Spyware Program.
Download, install, update, and immunize your System with it.
Then SCAN with it.
Update it, and scan your System once a fortnight.

http://www.malwarebytes.org/mbam.php

Malwarebytes is as the name says, a Malware Remover!
For the Free version scroll down their page to either download from
Download.com, or Major Geeks.com

Download, install, and update.

Important re: Safe Mode
If you happen to find a problem that you can’t uninstall / delete, reboot
the computer, and go into Safe Mode.
To get into Safe mode, tap F8 right at Power On / Startup, and use UP arrow
key to get to Safe Mode from list of options, then hit ENTER.
RESCAN your computer with your Anti-Virus, Malwarebytes and Spybot S & D
while in Safe Mode.

If unable to install above Programs in Normal Mode:
Sometimes Trojans, Viruses, Malware, etc stop you installing and/or updating
Programs to remove them.
If that happens, reboot into Safe Mode with Networking (from F8 list of
Startup Options), and install, update and scan from there.
 
S

Skorpioen

Ok, Spybot cleared the Trojans, I can now access regedit and Task Manager,
and the pop ups have gone.
I also installed Windows Defender after the trojans had been removed.

But now I notice a large amount of traffic whenever I connect to the
internet, even if everything is idle. I have turned off automatic updates. I
have since installed Sygate Personal Firewall, and all I allow to connect is
Internet Explorer, scvhost and another IO process..... yet the downloads
still occur (I tested it and it reached 5MB with just one idle Internet
Explorer window open). Could this still be a trojan hidden somewhere?

I did turn on automatic updates briefly to allow Defender to update, that is
when I noticed the traffic starting - I then turned off automatic updates,
restarted the PC and reconnected, yet the traffic continues...

Please help
 
P

Paul

Skorpioen said:
Ok, Spybot cleared the Trojans, I can now access regedit and Task Manager,
and the pop ups have gone.
I also installed Windows Defender after the trojans had been removed.

But now I notice a large amount of traffic whenever I connect to the
internet, even if everything is idle. I have turned off automatic updates. I
have since installed Sygate Personal Firewall, and all I allow to connect is
Internet Explorer, scvhost and another IO process..... yet the downloads
still occur (I tested it and it reached 5MB with just one idle Internet
Explorer window open). Could this still be a trojan hidden somewhere?

I did turn on automatic updates briefly to allow Defender to update, that is
when I noticed the traffic starting - I then turned off automatic updates,
restarted the PC and reconnected, yet the traffic continues...

Please help

If you want to see where traffic is going, try Wireshark.

http://en.wikipedia.org/wiki/Wireshark

If you enable View:Name Resolution:Network Layer in that tool,
that will make it easier to read the trace.

If you use the Analyze:Expert Info option, that will give
you a different looking trace. Clicking on an entry in the
Expert Info, should take you to the same entry in the main window.

Note that some malware may interfere with the operation
of the program. But you might also get some indication of
that, if you attempted to reach anti-malware sites. Some
malware will try to prevent you from getting to those
sites, so you can download tools from them.

Paul
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top