republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » [XP Pro] No Alt+Ctrl+Del, Task manager?
Search Topic:
Uniqs:
3284
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Heads up on new SpywareSheriff variant »
« Security Software Updates - 26 Sept 2005  
AuthorAll Replies


bigyeah
Premium
join:2004-06-25
clubs:
[XP Pro] No Alt+Ctrl+Del, Task manager?

For some reason my Alt+Ctrl+del function does not bring up task manager. Also limewire opens and reopens itself. I fixed the limewire problem by simply uninstalling it, but i still cannot open up task manager. Any solutions?


cocothebean
You Are My Nightmare
Premium
join:2002-11-16
Carson City, NV
Did you do a system restore as far back as you can?


heels_fan
1.20.09 The start of Socialism
Premium
join:2003-02-07
Columbia, TN
reply to bigyeah
can you go to start->run and type in "taskmgr" (without the quotes). Does task manger come up?


jaa
Premium,MVM
join:2000-06-13
·Optimum Online
·Vonage

reply to bigyeah
I've seen situations where malware blocks taskmanager from coming up. You might try to cleanup the system (see the security forum for guide and tools) and see if the problem resolves itself.
--
NOTHING justifies terrorism. We don't negotiate with terrorists. Those that support terrorists are terrorists.

Fox13

join:2005-06-23
Brampton, ON


1 edit
reply to bigyeah
Try Ctrl + Shift + Esc It's another way in.

I have also seen situations where spyware blocks the Task Manager. I'd run the big 3 on your pc once if you haven't already.

1. Microsoft Anti-Spyware Beta
2. Adaware SE
3. Spybot S&D 1.4

Edit: Don't forget to check startup under msconfig.


heels_fan
1.20.09 The start of Socialism
Premium
join:2003-02-07
Columbia, TN
reply to bigyeah
also, if it is spyware, it may not let msconfig come up either.


bigyeah
Premium
join:2004-06-25
clubs:

reply to heels_fan
said by heels_fan See Profile :

can you go to start->run and type in "taskmgr" (without the quotes). Does task manger come up?
Nope, doesn't work. "Another program is currently using this file."


heels_fan
1.20.09 The start of Socialism
Premium
join:2003-02-07
Columbia, TN
go to start->run->msconfig
and see if that comes up.

you can also go start->run-> regedit and see if the registry editor comes up.


Kramer
Premium,Mod
join:2000-08-03
Richmond, VA
clubs:
reply to bigyeah
Moving this thread to Security. Please click the link that says "Attention: All "HijackThis Log" Threads Will Be Locked Unless you Follow These Steps First"


bigyeah
Premium
join:2004-06-25
clubs:

reply to bigyeah
I cannot complete the steps because i cannot boot into safe mode. I can get up to where i choose which user i want (administrator, "my name") and then it reboots when i choose it. Automatically restart if there is a system failure is unchecked also.

I am pretty sure i could never boot into safe mode, it always did this since i reformatted, i just never had to use it so i didn't bother fixing it, finally it coming back to haunt me. Any suggestions

And yes i cannot open regedit, i have to use Registrar Lite to access the registry.


Kayrac
Premium
join:2001-09-29
Rochester, NH
»Security »I think my computer is infected or hijacked. What should I do?
do that as much as possible


bigyeah
Premium
join:2004-06-25
clubs:


1 edit
reply to bigyeah
I removed the virus with Killbox. Task Manager opens now, but regedit does not. However, if i type "regedit.exe" it works, but "regedit" does not.

Another problem i am still experiencing is not being able to boot into safe mode. I can get all the way up to where it asks if i want to revert to system restore, or continue in safe mode. I click yes and it reboots my system. This is from the Administrator User and "My" user.

I have used following programs to remove the virus, or virus's

Pc-Cillin online scan
Pc-Cillin level 6 deep scan
Ewido Security Suite
Spybot S&D
Ad-Aware
Hijack This
CCleaner

My Hijack this log is as follows

Logfile of HijackThis v1.99.1
Scan saved at 7:44:15 PM, on 9/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\PROGRA~1\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\Trend Micro\Internet Security 2005\PcCtlCom.exe
C:\PROGRA~1\Trend Micro\Internet Security 2005\Tmntsrv.exe
C:\PROGRA~1\Trend Micro\Internet Security 2005\tmproxy.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunes.exe
C:\Documents and Settings\All Users\Documents\Kev's Important Stuff\Install Files\Kev's Pen Drive\Spyware Removal\Hijack This\HIJACKTHIS V1.99.1.EXE

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Total Uninstall] "C:\Program Files\Total Uninstall 3\Tu.exe"
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - »housecall60.trendmicro.com/house···an60.cab
O16 - DPF: {0DD4ADBE-E91D-48CC-9A04-87EA1674E385} (PerfTesAXDemo Control) - »gamer.ubicom.com/benchmarks/Perf···ug23.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - »go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - »update.microsoft.com/windowsupda···61018125
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\Trend Micro\Internet Security 2005\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\Trend Micro\Internet Security 2005\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\Trend Micro\Internet Security 2005\tmproxy.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe


DevilFrank

join:2003-07-13
·T-Com

Did you see the "Setup-Wizard"?
»securityresponse.symantec.com/av···a.b.html
--
Regards from Germany. Please excuse my stumbling English


bigyeah
Premium
join:2004-06-25
clubs:

said by DevilFrank See Profile :

Did you see the "Setup-Wizard"?
»securityresponse.symantec.com/av···a.b.html
I need to be able to run in safe mode to delete the virus it says, and for some reason i cannot.

B
Premium,MVM
join:2000-10-28


Sigh. Why not just reinstall everything from scratch (repeatedly) until the system works as it's supposed to? You've just cleaned up known malware but things are still screwy...

-- B
--
In a realm outside causality and function


DevilFrank

join:2003-07-13
·T-Com

reply to bigyeah
Did you use the system configuration utility or the F8-key during the boot process?

I haven´t hear that the F8 during the boot process not start the safe-modus...
--
Regards from Germany. Please excuse my stumbling English


foxsteve
Premium
join:2001-12-28
Campbell, CA
reply to bigyeah
You can start your system from NTFS DOS disk/floppy and clean it.


bigyeah
Premium
join:2004-06-25
clubs:


1 edit
reply to DevilFrank
said by DevilFrank See Profile :

Did you use the system configuration utility or the F8-key during the boot process?

I haven´t hear that the F8 during the boot process not start the safe-modus...
I can get into the safe mode menu all the way up to where it asks me if i want to continue in safe mode or revert to system restore.

This safe mode issue of mine i am pretty sure has been on going, i want to fix this problem first then move on to cleaning my pc thoroughly.
Forums » Up and Running » Security » SecurityHeads up on new SpywareSheriff variant »
« Security Software Updates - 26 Sept 2005  


Friday, 04-Dec 15:01:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [119] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [99] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [78] FCC Ponders Moving From PSTN To IP Voice
· [74] Sprint Defuses GPS Privacy Media Bomb
· [70] Baltimore To Ban Lazy Cable Installs
· [64] Broadband Killed The Game Console
Most people now reading
· False positive in Avast! or is it real? [Security]
· [WotLK] Doing away w/ conquest? [World of Warcraft]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· Equal speeds ruling [Canadian Broadband]
· Windows 7 boot manager editing questions [Microsoft Help]
· Linux is terrorist - according to MS... [All Things Unix]
· Sprint to interface with Google Voice [VOIP Tech Chat]
· Google takes aim at browser redirection [Security]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]
· Long ethernet runs [Wireless Service Providers]