Hya Reillytj , welcome to PCHF.
When in safemode , see if you can start explorer and apps like this:
task manager/file/new task (run)/explorer.exe
task manager/file/new task (run)/hijackthis.exe
task manager/file/new task (run)/ect
If not , then do the fix in normal mode.
Please download
Process Explorer by Systernals from
HERE.
Also download
KillBox by Option^Explicit from
HERE.
And download the Hoster from
here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original Hosts file.
Then boot up in
SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.
Unzip
Process Explorer and double click on
procexp.exe
In the top section of the Process Exlporer screen double click on
winlogon.exe to bring up the winlogon.exe properties screen. Click on the
Threads tab at the top.
Once you see this screen click on each instance of
reg.dll once and then click the
kill button.
After you have killed all of the
reg.dll's under winlogon click
OK.
Next In the top section of the Process Exlporer screen again , double click on
explorer.exe and again click once on each instance of
reg.dll then click the
kill button.
Once you have done that click
OK again.
Next run
HijackThis and place a check beside each of the following:
Now click
fix checked and close HijackThis.
Please copy the text in the quote below, and paste it into a blank notepad window.
Save it as
vundo.reg and in the "save as" type box choose "all files".
Once you have saved it double click it and allow it to merge with the registry.
Code:
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}]
[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1]
Double click on
Killbox.exe and then check the
delete on reboot button.
Enter the following filepath and filename into the Full path of file to delete box:
C:\WINDOWS\reg.dll
Click the
red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)
After your computer has rebooted run Hijackthis again and attach the new Hijackthis to a post , log instead of copying it to a post please.
Also do you know that Cisco Systems VPN Client is running on youre pc?