Task Manager enabled, but not opening

Hi.
I spent about 30 minutes researching this, but everything so far turned out to be a bust for my case here.

A friend's computer running Vista 32bit had a seemingly minor infection (some fake antivirus program). Using HiJackThis, SilentRunners and Spybot, I removed the infection. I tried installing AVG Antivirus Free, but the installation failed, both for version 2011 and version 9, so I installed Clam Win which installed, updated and scanned normally. The AVG installers failing could be a sign of another problem, but my main concern is that Task Manager won't open. There is no error message - just a short rattling of the hard drive as it opens the file, then nothing.

I tried CTRL-SHIFT-ESC, CTRL-ALT-DELETE, right-click on Taskbar and select Task Manager, double-click Taskgmr.exe from system32 folder and even double-clicking a version of Taskmgr.exe downloaded from a forum that supposedly helped others. I also could not rename or overwrite Taskmgr.exe with the downloaded copy, but that could be a Windows safety precaution.

I found all the recommendations for the usual suspects in the Registry, e.g. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System (the folder System did not exist).
For a list of them, try here: http://forums.orumph.com/viewtopic.php?f=6&t=11 - I did not download and use the file in that post but made the changes manually.
FYI, I had to run Command Prompt as Administrator for the registry changes to stick, still nothing, even after a restart.

The only three things I have not tried are System Restore (it would likely bring back the virus), sfc /scannow (didn't have time today nor the disc handy) or re-install. I would like to avoid either of those if I can, unless my friend can find the Vista CD in which case I'd try sfc.

I tried Process Explorer and searched for "taskmgr" in the hopes that some background task was still running and blocking it, but no such luck.

I also did not have the time to run Spybot in Safe Mode as I usually do when I take a computer with me to the office, but I let it run automatically on Windows restart.

So the question is: If a supposedly clean copy of Taskmgr.exe cannot even run from a different folder, what else could possibly block it?

Any other thoughts?

FYI, being that this is not my computer and that I do not have easy physical access to it, I cannot attach any logs for now, but maybe in a few days if I see any ideas that look promising. I have been working in Tech Support (especially virus removal) for over 5 years, so I'm no beginner, so hit me with whatever you think might work :-)

Thanks!
 

My Computer

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics Card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Keyboard
    Dell USB
    Mouse
    Dell USB 4 button optical
    Other Info
    DSL provided by ATT
Thanks for the answer.

As I mentioned, I have not tried SFC, but I am aware of it. It will likely not be able to replace any damaged files without the CD, and I don't know if Acer delivers Vista CDs with their computers, and the owners are a fairly old couple who may not have kept it, so I'd like to keep that as last resort (after I find a copy of Vista somewhere...).

Anyway, I also mentioned that a downloaded copy of Taskmgr.exe did not run, either, so it seems logical to assume that the file Taskmgr.exe is not the issue. Does anyone know what other files the Task Manager uses that could be damaged?

I also mentioned that I have used Process Explorer. Yes, it's good, but it's not a real replacement - the way I see it, if Task Manager is disabled, and I can't find the reason for it in the Registry, then what else could be damaged?
So I am trying to find out where else this issue could be taking place - other Registry locations, other possibly broken files ... etc.
 

My Computer

The only safe solutions are
SFC
System Restore
Repair Install -DVD is required

In lieu of that Process Explorer is still your best bet.
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics Card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Keyboard
    Dell USB
    Mouse
    Dell USB 4 button optical
    Other Info
    DSL provided by ATT
Alright, so I'll be asking them to try and find their Vista discs - unless anyone else can give me another idea of where to check.

Thanks for your answers.
 

My Computer

You do not need a DVD for an SFC.

We have one very talented member who can, sometimes, manually fix what SFC cannot. If you give us the log, when he comes online, perhaps he can help.

CBS Log
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics Card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Keyboard
    Dell USB
    Mouse
    Dell USB 4 button optical
    Other Info
    DSL provided by ATT
Hello!

I have a few things to say :)

Firstly, Clam Win is absolutely dire! It does not have real time protection, I think, but any way, it is absolutely the worst anti-virus around. Having Clam Win installed == unprotected computer. Please uninstall it, and install this excellent anti-virus program (free) by Microsoft, Microsoft Security Essentials: http://www.microsoft.com/security_essentials/

Secondly, my next thought would be that a virus is still there, and is actively closing the taskmanager process as soon as it starts. This is the classic signs of a rootkit, one of the worst and hardest to remove forms of a rootkit. We need to get a well trained professional in to scout this one out, as they can hide from anti-virus software, and from Windows itself. We need to call in assistance!

While you are at it, it is far quicker for me to analyse a CBS.log rather than a parsing of one. Although a parsed CBS log creates a marginally shorter log, and is fine if no errors/unimportant error is detected, if a proper error is detected, I need an MD5 scan, a lot of time, and a parsed log, or a short amount of easy time, and a full log. Since you are remoting in, we may as well grab the whole log now. It takes basically no extra work to upload, and may stop me making another trip to fetch more logs. :)

Do you mind following these instructions, after running SFC?

Please navigate to C:\Windows\Logs\CBS and copy CBS.log to your Desktop. Right click on it > Send to > Compressed (zipped) folder. Please now upload this new, small file instead, and possibly save us all work and time in the long run.

Thanks!

Richard
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS 420
    CPU
    Intel Core 2 Quad Q9300 2.50GHz
    Motherboard
    Stock Dell 0TP406
    Memory
    4 gb (DDR2 800) 400MHz
    Graphics Card(s)
    ATI Radeon HD 3870 (512 MBytes)
    Sound Card
    Onboard
    Monitor(s) Displays
    1 x Dell 2007FP and 1 x (old) Sonic flat screen
    Screen Resolution
    1600 x 1200 and 1280 x 1204
    Hard Drives
    1 x 640Gb (SATA 300)
    Western Digital: WDC WD6400AAKS-75A7B0

    1 x 1Tb (SATA 600)
    Western Digital: Caviar Black, SATA 6GB/S, 64Mb cache, 8ms
    Western Digital: WDC WD1002FAEX-00Z3A0 ATA Device
    PSU
    Stock PSU - 375W
    Case
    Dell XPS 420
    Cooling
    Stock Fan
    Keyboard
    Dell Bluetooth
    Mouse
    Advent Optical ADE-WG01 (colour change light up)
    Internet Speed
    120 kb/s
    Other Info
    ASUS USB 3.0 5Gbps/SATA 6Gbps - PCI-Express Combo Controller Card (U3S6)
OK, I'll try to get a log. I'll be out of town for a week, but I'll try to get one after I'm back.

I am somewhat surprised, though, but someone actually praising a Microsoft product, especially when it comes to antivirus...

Is the free version of Avast any better?

AVG Free versions 9 and 2011 failed to install, so I didn't have many options...
 

My Computer

Back
Top