J
jasonwhat
I'll tell the whole embarrassing story in hopes someone can help, or to
help others with the same problem.
I got an attachement from a contact on yahoo claiming to be a picture.
Of course the file was not really a jpeg, but launched some sort of
virus, baby.exe on the computer. Once I clicked it I knew what I had
done. I deleted the attachment file and performed a scan with NAV,
which turned up nothing.
A bit later I noticed I was getting an error that the administrator had
disabled task manager. Then I tried regedit and got a similar error.
Of course, it is my comp and I'm the admin. I spent a few hours
searching and tried several resources, spybot search and destroy,
adaware, asquared, hijack this found a registry entry that was setting
the lockout value to 1 on task manager, but I was unable to fix it
through hijack this.
I ran another NAV scan and it detected a generic trojan, baby.exe which
I got rid of. However, the lockouts of taskmanager and regedit
continued. I used a-squared to view the processes running in
taskmanager and found REGSVR.EXE, which I killed. From here I ran the
UnHookExec from NAV that freed my registry (I tried it before and
nothing) and re-enabled task manager access through regedit.
Everything seemed to be running find, though except I was having
trouble getting System Restore enabled again.
I searched and found a REGSVR-009(bunch of numbers).exe file and
deleted that. However, on restart, I was locked out of task manager
again and had to repeat the same steps of using a-squared to kill
REGSVR.EXE and go through regedit to enable taskmanger.
Most googlesearches identify REGSVR.EXE as part of a worm, but I was
unable to find anything using various tools and scans. I also checked
my registry for the typical systems and didn't find any. I have no
idea what is causing this to run everytime I start the computer.
Any ideas how I can find what is causing REGSVR.EXE to run and lock me
out of taskmanager and regedit? Even though NAV and other say I'm
clean, something isn't right and it is probably doing more than just
locking me out of taskmanager. Is this maybe a new virus that most
anti-virus, malware, and anti-trojan programs can't find?
Any help is great, thank you.
help others with the same problem.
I got an attachement from a contact on yahoo claiming to be a picture.
Of course the file was not really a jpeg, but launched some sort of
virus, baby.exe on the computer. Once I clicked it I knew what I had
done. I deleted the attachment file and performed a scan with NAV,
which turned up nothing.
A bit later I noticed I was getting an error that the administrator had
disabled task manager. Then I tried regedit and got a similar error.
Of course, it is my comp and I'm the admin. I spent a few hours
searching and tried several resources, spybot search and destroy,
adaware, asquared, hijack this found a registry entry that was setting
the lockout value to 1 on task manager, but I was unable to fix it
through hijack this.
I ran another NAV scan and it detected a generic trojan, baby.exe which
I got rid of. However, the lockouts of taskmanager and regedit
continued. I used a-squared to view the processes running in
taskmanager and found REGSVR.EXE, which I killed. From here I ran the
UnHookExec from NAV that freed my registry (I tried it before and
nothing) and re-enabled task manager access through regedit.
Everything seemed to be running find, though except I was having
trouble getting System Restore enabled again.
I searched and found a REGSVR-009(bunch of numbers).exe file and
deleted that. However, on restart, I was locked out of task manager
again and had to repeat the same steps of using a-squared to kill
REGSVR.EXE and go through regedit to enable taskmanger.
Most googlesearches identify REGSVR.EXE as part of a worm, but I was
unable to find anything using various tools and scans. I also checked
my registry for the typical systems and didn't find any. I have no
idea what is causing this to run everytime I start the computer.
Any ideas how I can find what is causing REGSVR.EXE to run and lock me
out of taskmanager and regedit? Even though NAV and other say I'm
clean, something isn't right and it is probably doing more than just
locking me out of taskmanager. Is this maybe a new virus that most
anti-virus, malware, and anti-trojan programs can't find?
Any help is great, thank you.