Home > Windows 7 > HELP! TROJAN VIRKEL! Cannot Run Msconfig Or Regedit!

HELP! TROJAN VIRKEL! Cannot Run Msconfig Or Regedit!

Contents

Ask a question and give support. No, create an account now. Navigate to the following location: * Windows 95/98/Me: %Windir% * Windows NT/2000/XP: %Windir%\System32\drivers\etc Notes: * The location of the hosts file may vary and some computers may not have this file. Flag Permalink This was helpful (0) Collapse - Get that file from by R.

Very Puzzled.But thanks again. I then noticed that NAV was inactive (no icon present) and that the Microsoft security icon was flashing for my attention. Logfile of HijackThis v1.99.1 Scan saved at 7:21:08 p.m., on 11/09/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe All my restore dates are gone except after the fact.

Msconfig Missing Windows 7

DisableRegistryTools value is set under HKEY_CURRENT+USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\ & Explorer b. To remove all the entries that the risk added to the hosts file 1. I have posted this to the forums where I got the information to compile. Staff Online Now etaf Moderator Advertisement Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Home Forums Forums Quick Links Search Forums Recent

Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. If the file is not located in these folders, search your disk drives for the hosts file, and then complete the following steps for each instance found. * %Windir% is a I am currently reviewing your log. If you are getting the symptoms described in this post...try the PANDA scanner.

Advertisements do not imply our endorsement of that product or service. Msconfig Disabled I do a full scan each start-up 2) Norton Anti-Virus, with definitions updated as of Thursday, Dec 30, 2004, system is scanned weekly 3) Fully updated XP patches through Microsoft Automatic Steve Jan 15, 2005 #5 lordx TS Rookie Posts: 33 Back up your sensitive data. http://www.techspot.com/community/topics/nasty-trojan-disables-regedit-msconfig-antivirus-firewall-task-manager-etc.18950/ Logfile of HijackThis v1.99.1 Scan saved at 1:07:46 p.m., on 3/09/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe

Click OK. 13. Click Start > Control Panel. 2. But alas, the automatic update service would get disabled as soon as I started it, couldn't get to MSCONFIG, or REGEDIT or TASK MANAGER. Any suggestions?

Msconfig Disabled

cannot run msconfig or regedit! Sorry, there was a problem flagging this post. Msconfig Missing Windows 7 helpmeverkler, Jun 9, 2007 #3 Cheeseball81 Moderator Joined: Mar 3, 2004 Messages: 84,310 Have you tried a System Restore Cheeseball81, Jun 9, 2007 #4 helpmeverkler Thread Starter Joined: Jun 8, Can't Open Msconfig Windows 10 text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]HKLM\Software\Classes\*\shellex\ContextMenuHandlers\AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" -> {HKLM...CLSID} = "AVG7 Shell Extension Class" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG

Ends the following processes, which may be related to other threats or security-related programs: * msconfig.exe * kav.exe * kavsvc.exe * mcvsshld.exe * mcagent.exe * mcvsrte.exe * mcshield.exe * mcvsftsn.exe * Any advice is appreciated. To edit the Win.ini file If you are running Windows 95/98/Me, follow these steps: 1. All submitted content is subject to our Terms of Use. Msconfig Windows 7 Download

For instructions refer to the document: How to make a backup of the Windows registry. 1. and install it. Join over 733,556 other people just like you! Perform a forensic analysis and restore the computers using trusted media. * Train employees not to open attachments unless they are expecting them.

goto end of line and type ;c:\WINDOWS\pchealth\helpctr\binariesassuming ur windows is in c drive.now try!!!Happy xping Flag Permalink This was helpful (1) Collapse - IT WORKED!!! I was also able to access the registry and remove the DisallowRun keys that locked me out of the registry without their reappearance. HELP!

I put a call in to my ISP to let them know I had this Trojan and to ask if they could monitor my account for any untoward activity.

Jump to content FacebookTwitter Geeks to Go Forum Security Virus, Spyware, Malware Removal Welcome to Geeks to Go - Register now for FREE Geeks To Go is a helpful hub, where If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer. By default, this is C:\Documents and Settings\[CURRENT USER] (Windows NT/2000/XP). 4. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000). 2.

helpmeverkler, Jun 14, 2007 #8 Cheeseball81 Moderator Joined: Mar 3, 2004 Messages: 84,310 Did you ever rename HijackThis and try to run it Cheeseball81, Jun 14, 2007 #9 Sponsor How to remove Begin2Search / Coolwebsearch Jan 16, 2005 #7 jcmit TS Rookie Nasty Indeed!! I will appreciate very much =)Logfile of HijackThis v1.99.1Scan saved at 2:30:34 AM, on 2/14/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0011)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\ibmpmsvc.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\S24EvMon.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Changes the hosts file in C:\WINDOWS\system32\drivers\etc to block major AV sites and online virus scans.

So what might have changed? It's a bit rough, but it's a start. This is how I kill my time: Painting with Light 02-05-2007, 09:47 PM #3 src2206 TSF Enthusiast Join Date: Apr 2006 Location: Kolkata, India Posts: 2,096 OS: The update will start and a progress bar will show the updates being installed.

For instructions, read the document, How to start the computer in Safe Mode. Adds the following lines to the hosts file to prevent access to various security-related Web sites: 127.0.0.1 avp.com 127.0.0.1 www.avp.com 127.0.0.1 ca.com 127.0.0.1 dispatch.mcafee.com 127.0.0.1 download.mcafee.com 127.0.0.1 f-secure.com 127.0.0.1 fastclick.net 127.0.0.1 Creates the following shortcut to itself so that it executes every time Windows starts: %UserProfile%\Start Menu\Programs\Startup\csrss.lnk Note: %UserProfile% is a variable that refers to the current user's profile folder. If there's anything that you do not understand, kindly ask your questions before proceeding.

I removed some registry keys and the main virus file and the two .com files, the virus is definately gone but it left behind some problems. Register now to gain access to all of our features, it's FREE and only takes one minute. If any files are detected, click Delete. 4. The worm also lowers security settings and blocks access to several Web sites.

Do not install if you are using the 64 bit version of windows. *NOTE* Cleanup deletes EVERYTHING out of temporary folders and does not make backups. I hope u all could solve my problem. Loading...