View Single Post

  #12  
Old 08-23-2007, 04:32 AM
oddjob Offline
Registered User
 
Join Date: Nov 2006
Posts: 225
Hi Alpoes

There is at least one piece of malware now in the wild that has been programmed by its authors to disable Task Manager (amongst other things).

***********************

Make sure you have exposed all Hidden Files & Folders.

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and close My Computer.

***********************

If you can get online OK then run each of the following fixing utilities in turn. Try your Task Manager after using each one to see if you can ID which tool fixes it.....

1. Superantispyware > http://www.superantispyware.com/

2. AVG Anti Spyware > http://free.grisoft.com/doc/5390/us/frt/0?prd=asf

3. TrojanHunter > http://www.misec.net/

4. ComboFix (either location will do) >
http://download.bleepingcomputer.com...a/ComboFix.exe
http://www.techsupportforum.com/sect...s/ComboFix.exe

Double click combofix.exe & follow the prompts.
Note >> Do not mouseclick combofix's window while it's running. That may cause it to stall.


Have these run full scans on your entire systems on their default settings.

Let them fix whatever they find.

***********************

If you are offered the chance to save scan log reports from these tools please do so. We may want to see them.

***********************

Rehide your Hidden Files & Folders by carrying out the reverse operation to that described at the start of this post & reboot to normal mode.

***********************

If the TM still is inoperative do this ....

Please download VundoFix.exe to your desktop from here …..

http://www.atribune.org/ccount/click.php?id=4

1. Double-click VundoFix.exe to run it.
2. When VundoFix re-opens, click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. You will receive a prompt asking if you want to remove the files, click "YES".
5. Once you click yes, your desktop will go blank as it starts removing Vundo.
6. When completed, it will prompt that it will reboot your computer, click "OK".

7. Please post the contents of C:\vundofix.txt and a HijackThis* log.

If vundofix cannot delete a file, it will try to delete it during a reboot, after the reboot vundofix will open again, you must run vundofix again, from Step2 above.

You must keep running vundofix until it does delete the file. I've read reports of a stubborn vundo file taking 5 or 6 scans & reboots before it is deleted.


*Get self extracting HijackThis from here ....

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the hijackthis_sfx.exe file and it will self-extract into its own folder ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the menu click on "Do a system scan and save a logfile".


When done please let us know how you got on.


OJ
__________________
“The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards - and even then I have my doubts.”
Eugene H. Spafford
Reply With Quote