Forum Home
Press F1
 
Thread ID: 122804 2012-01-13 22:49:00 registry infected? hoanikai (13138) Press F1
Post ID Timestamp Content User
1253938 2012-01-13 22:49:00 Good day folks,

After a good run, my pc has suffered a virus raid.
I run eset NOD32 and it picked up the threat strght away.
However this morning I can't open firefox.exe ad a number of others.
It appears that the registry values that associate with file name extension are corrupted.

any clues?
i run windows xp pro
hoanikai (13138)
1253939 2012-01-13 23:01:00 Scan it with malwarebytes update it first. Then do a full scan. I would also run trojan remover. (http://www.simplysup.com) Update then click on scan. Then reset everything under the utils menu Speedy Gonzales (78)
1253940 2012-01-13 23:06:00 thanks speedy, however when malwarebytes downloaded, i cant open and run the exe file...don't have malwarebytes onboard.
any ideas
hoanikai (13138)
1253941 2012-01-13 23:16:00 try downloading again, but rename it to something else before downloading, see if that works bevy121 (117)
1253942 2012-01-13 23:36:00 If the File associations have been changed/ damaged, go HERE (www.dougknox.com) Download the appropriate file for the association you want, merge it into the reg and it should fix it. ( try the exe)

Had a customer a few weeks back, he managed to get some malware and it totally screwed all exe files, ran the exe fix, and all was well.
wainuitech (129)
1253943 2012-01-13 23:37:00 Go to the BleepingComputer site
www.bleepingcomputer.com
Halfway down that page, you'll see a reference to Rkill, download and run that first (DONT reboot) then download and run MalwareBytes.
What's happening is that you are still infected, and that infection is running processes that is actively stopping you downloading/running anything to fix it, Rkill should stop that process.
feersumendjinn (64)
1253944 2012-01-14 00:17:00 thanks so far...
have managed to get malwarebtes onboard..scanning now
hoanikai (13138)
1253945 2012-01-14 00:30:00 If after scanning with all known good malware checkers, and I'd do a Hijackthis too - it's still screwed up, do a Windows Repair install. pctek (84)
1253946 2012-01-14 01:13:00 malwarebytes scan completed...3 threats found and quarantined.
can open .exe & .com again
got super anti spyware scanning now
will post more later..
thanks everyone
hoanikai (13138)
1253947 2012-01-14 23:53:00 hello folks,

have just managed to get back online

a few more threats found on super anti spyware scan
then did a crap cleaner workover registry included
seems like everything is running well again.
the rkill did the trick.

thanks for everyones help.

Question:
I am running eset NOD32 in conjunction with a windows firewall,
should i add a purely malware protection program that is running continually in the same way as the eset?

Please get back to me if you can help.
Perhaps I should make this a new post
hoanikai (13138)
1 2