Malware help...

ajnineinchnails

New member
Local time
7:06 PM
Messages
17
Im running Win7 professional edition and I believe I have some sort of malware though Avast, Malewarebytes, spybot search and distroy, and microsoft security essentials pic up nothing... the reason i know i have something is that regedit is running as a process and regedit 32 on occasion... any help finding out what I have?
 

My Computer

OS
win 7
Can you post what processes are running exactly so someone can determine if it is Malware and how to fix it?




BTW: I need maleware help regularly (he's called my husband and he wears me out :p)
 

My Computer

Computer Manufacturer/Model Number
Chosen by me - Built by someone else ;)
OS
Windows 7 x 32 bit
CPU
AMD Phenom II 810 Quad Core
Motherboard
Gigabyte GA-MA770T
Memory
Corsair 4GB (2x2GB)
Graphics Card(s)
ASUS GTS250 1GB DDR3
Sound Card
Realtek Audio
Monitor(s) Displays
BenQ
Screen Resolution
1220 x 900
Hard Drives
Western Digital 1TB, Caviar Green
PSU
650w
Case
Antec Sonata Elite Black/Silver
Keyboard
Logitech New Touch
Mouse
Belkin
I'm not sure what you mean by "running" regedit? You might try installing Regmon so that you can monitor registry activity. Also Filemon can be used for the same purpose with files.

EDIT: I misread your phraseology, but those two programs might still be of some use.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
Sorry, I just can't type for crap sometimes... But yeah regedit keeps showing up in the task manager then shutting off then restarting and... idk...
 

My Computer

OS
win 7
Have you tried using the Resource Manager in the Task Manager? If you checkmark regedit in the Process pane, it might give you a clue as to what is happening in the two panes below.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
Yeah, I looked at the resource manager and like i said it keeps stoping and starting... killing my processer.
 

My Computer

OS
win 7
I'm not speaking of whether it appears there or not, but whether it appears long enough for you to use the diagnostic panes? The goal is to determine exactly what is calling regedit into action.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
Then I would resort to the two programs that I mentioned in post #3. If you are unable to track the problem, then the only thing I can think of is a System Restore, assuming that this problem hasn't gone on too long, and you have a restore point that is conveniently dated to just prior to when it began.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
Huh? Is that .exe what is causing regedit to run?

I've done a little Googling on the .exe, but it's function isn't clear to me yet. You have several choices, searching your folders for scraps of the program left behind, searching the registry for orphan keys, Googling for an uninstall method, restoring to a point before you installed it, backup from a prior image and the list could probably go on, if I were to think long enough.

You might consider buying Acronis True Image 2010, if you tend to experiement a lot with unknown programs, because it has a Try And Decide feature that permits a temp install that can be totally reversed, if you don't want to keep the program, or merged into the system if you do.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
Yup, I installed a program called dexpose2 that's an expose clone for windows and I uninstalled it and then i started to have problems... apparently the guy put maleware in it or something because that's what was running regedit... i booted into safe mode and wiped the folder where the .exe file was and sure nuff, booted back up and no problems whatsoever... *sighs*
 

My Computer

OS
win 7
Yeah idk what maleware function it served but i do know that when installed it was a full fledged expose clone...
 

My Computer

OS
win 7
Back
Top