This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] regedit and task manager disabled by admin

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:53:51 AM, on 5/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\JG99\Desktop\drweb-cureit.exe
C:\DOCUME~1\JG99\LOCALS~1\Temp\RarSFX0\gurh58.exe
C:\DOCUME~1\JG99\LOCALS~1\Temp\RarSFX0\vmxeh.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\RunOnce: [Uninstall getPlus® for Adobe] "C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218812918015
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9868A64-81D5-45CD-A133-5E0006E0971D}: NameServer = 202.138.128.50,202.138.128.54
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

–
End of file - 4543 bytes

Result from DrWeb

sscviihost.exe;c:\windows\system32;Win32.HLLW.Autoruner.1075;Incurable.Moved.;
Due, in part, to the large numbers of HJT logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time, I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
  • Read the Information panel and then click Accept.
  • Allow the ActiveX download if necessary.
  • Both the anti-virus engine and database will need to be downloaded, which may take a little time.
  • Once this has been completed, select My Computer from the Scan section on the left hand side.
  • Put the kettle on!
  • Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
    Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
  • When the scan has completed, click View scan report at the bottom.
  • Click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Sec-Info.zip from here and save it to your Desktop. You will need to extract the file.

Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see a folder with a .vbs file in it. Double click Sec-info.vbs to run it and a text file called Sec-Info.txt should be created in the same folder - either that or you'll get an error message.
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Came across a tool called "restriction removal tool". Used it, and my task manager and regedit was enabled. What do you think about this tool? Do you think the virus that caused my task manager and regedit to be disabled has been removed by this tool? If the virus still exist, what more should i do? many thanks

Do you think the virus that caused my task manager and regedit to be disabled has been removed by this tool?

No, as it is a "restriction removal tool" and not a "virus/trojan/worm/non-specific malware removal tool".

If the virus still exist, what more should i do?

Personally i'd follow the instructions in my previous post, but i'm biased as I posted them.
KASPERSKY ONLINE SCANNER 7 REPORT Monday, June 1, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Monday, June 01, 2009 12:01:14 Records in database: 2290724 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ Scan statistics: Files scanned: 166063 Threat name: 2 Infected objects: 19 Suspicious objects: 0 Duration of the scan: 01:23:57 File name / Threat name / Threats count C:\Documents and Settings\All Users\Documents\autorun.inf Infected: Trojan.Win32.AutoRun.a 1 C:\Program Files\MYGAME\Special Force\data\area\area.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\clan\clan.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\data.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\effect\effect.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\Force\force.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\lobby\lobby.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\Menu\menu.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\save\save.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\scr\scr.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\screenshot\screenshot.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\Sound\sound.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\data\Weapon\weapon.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\GameGuard\GameGuard.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\img\img.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\option\option.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\redist\redist.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\Program Files\MYGAME\Special Force\Special Force.exe Infected: Trojan-Downloader.Win32.AutoIt.aa 1 C:\WINDOWS\system32\autorun.ini Infected: Trojan.Win32.AutoRun.a 1 The selected area was scanned.
Sec-Info.txt has no contents in it….

from uninstall_list.txt

Adobe Flash Player ActiveX
Adobe Reader 7.0
ATI - Software Uninstall Utility
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Display Driver
ATI Parental Control & Encoder
Audition [removed]
Bluesoleil2.7.0.13 VoIP Release 071227
CABAL Online (PH) 1.0
Catalyst Control Center - Branding
DEVIL MAY CRY 4
Garena
Half-Life
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Java™ 6 Update 13
Left 4 Dead
LiveUpdate 1.6 (Symantec Corporation)
Microsoft .NET Framework 2.0
Microsoft Visual C++ 2005 Redistributable
MYGAME Launcher(Remove Only)
NVIDIA Drivers
O2Jam_PH
Outspark Sharp Launcher
POD-Bot 2.5
Project Powder
Ran Online [removed]
Returnil Virtual System Personal Edition
Security Update for Windows XP (KB958644)
Sierra Utilities
SigmaTel Audio
Special Force(Remove only)
Windows XP Service Pack 3
WinRAR archiver
Can you tell me what anti-virus program you are currently using, and if you don't have one, how long it has been since you did.
i used AVG free edition before but has since removed it. It is because it cannot remove and/or prevent some viruses and others from infecting my pc… what can you recommend?
Both the following are free - only install one though:

avast! 4 Home Edition: Available here
AntiVir PersonalEdition Classic :Available here

How long ago did you remove your anti-virus program?
i removed it in the early part of this year, if my memory serves me right… based on the result of the kaspersky scan and others, was i able to remove the viruses, adwares and malwares in my pc??? is my pc ok now???

i removed it in the early part of this year, if my memory serves me right…

based on the result of the kaspersky scan and others, was i able to remove the viruses, adwares and malwares in my pc???

is my pc ok now???

Possibly. The problem that you have is that surfing without adequate security, an anti-virus program and a firewall, leaves your PC at the mercy of malware writers, and they don't have a lot of mercy! As the PC has been open to attack for some time, it is impossible to guarantee that the machine is clean of malicious files or legitimate files that have been patched. It could also have security settings that have been lowered to make reinfection more easy in the future.

If it was my machine I would back up any important files and then reformat and reinstall the Operating System to be on the safe side, and this is what I recommend you do.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI