trojan.Dropper virus won't let me edit the registry of msconfig files

Status
Not open for further replies.

coreydjones

Beta member
Messages
5
Pick up this virus recently and was able to get some info on how to remove it but still have a problem that I'm looking for help on. The virus has disabled my regedit and msconfig files so that when I run them they briefly come up but then disappear so you cannot edit them. Does anyone know how to remove the virus that is keeping me from editing these files? Thanks in advance.
 
Follow these instructions carefully

Download ALL 10 programs and update if needed.

Ad Aware SE Personal Free

Ad-aware Messenger Service Plugin

Ad-Aware VX2 Cleaner Plugin

Spybot Search and Destroy Free

Windows Defender 2 Beta

HijackThis

Ewido

CCleaner

Cleanup!

Follow these steps

Delete the prefetch folder C:\WINDOWS\Prefetch, this folder will come back on next reboot.

Delete all cookies and temporary internet files in the control panel, Internet Options.

Go to Start, run, type msconfig, go to startup, disable everything except your antivirus, Firewall, click apply, don¡¦t reboot yet.

Download Msconfig Cleanup below

Msconfig Cleanup

Run Msconfig Cleanup after you unchecked the items you were told to uncheck and recheck, click "Select All", then click "Clean up Selected", then click "Quit". Make sure your antivirus and firewall are not checked.

Now run each Spyware program 1 by 1. Running all 3 at the same time will slow most systems down.

When each program has finished scanning, remove everything.

Now go to the recycle bin and delete everything that is in it.

Then run CCleaner „² make sure you run the Cleaner section of Windows and Applications and then the Registry Cleaner. Make a backup if you wish while running the Registry Cleaner when it asks you.

When finished with the scans, reboot, and go into Safe Mode and run these scans again, remove everything they find, and then reboot back into Windows in normal mode.

Then run HiJackthis!

Save the log, copy and paste the log on www.techist.com
Do not attach the log, copy and paste always. This will make things go much faster.
 
Re:

Try this...

[!] The deletion of files below refer strictly to files with the .com file extension. Do not delete any of the following files which have the .exe file extension [!]

1. Open windows explorer, then go to C:\WINDOWS\system32\ where C:\ is your Windows XP partition.

2. Go to Tools > Folder Options... > View Tab and ensure that you've unchecked 'Show hidden files and folders', 'Hide extensions for known file types' and 'Hide protected operating system files'.

3. Still at the directory C:\WINDOWS\system32\ locate and delete the following files if they exist:


cmd.com , regedt32.com , taskmgr.com

4. Browse to the directory C:\WINDOWS\pchealth\helpctr\binaries, then locate and delete the following file if it exists:

msconfig.com

4. Then in explorer, go to the directory C:\WINDOWS\ and delete the following file if it exists:

regedit.com

5. Now try and execute regedit and msconfig using Run and see if it works.
 
Problem solved

Got the problem solved by running Ad-Aware in safemode. Did not find any of these files on my hard drive. Thanks anyway.
 
That allowed me to get into the msconfig and the regedit files. I also had to run the virus scan nummerous times to find and delete the virus infected files. Actually I am still finding some of the files but now at least I can get into the msconfig and the regedit files.
 
No I did not perform all the thing you had listed. I have been working with a Symantec technian to get this resolved and the only thing I noticed was that he was doing nothing to resolve the issue with accessing my msconfig and regedit files. I seemed to have gotten rid of the virus alerts by just running the norton antivirus in safe mode.
 
that dont me nothing. Just because norton hasnt found anything doesnt mean there aint nothing there
 
I have not had any problems since I ran the antivirus and the ad aware in safe mode. At least not yet. If I still have a virus I hav enot seen the affects of it yet.
 
Status
Not open for further replies.
Back
Top Bottom