I'm experiencing a similar problem and I ran (as crunchie suggested) Malwarebytes' Anti-Malware which discovered 12 items my previous anti-spyware (STOPzilla, I can't believe I paid for it as I usually never buy this kind of thing) didn't find. STOPzilla has stopped working after I booted up today and my original problems (not being able to access my Control Panel or perform a Windows Update) are still problems that it never fixed anyways. I'm posting my Malwarebytes' Anti-Malware results here now:

--------------------------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.21
Database version: 971
Windows 6.0.6000

12:36:40 PM 7/20/2008
mbam-log-7-20-2008 (12-36-40).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 144515
Time elapsed: 52 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 9
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\ekvgsnw.bltm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ekvgsnw.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\vac.video (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7fcab5d2-b5f4-407f-b920-a41a13f29488} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b9fb244b-358c-4c6f-a063-bd66e8d3427a} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{ca71ec92-1809-4352-8671-451fce3d607b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{ae0635a6-2b7d-46bd-ac4b-7c5192d04a0f} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\newmediacodec.videosupport (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mediaeldoradocodec (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MediaEldoradoCodec (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\MediaEldoradoCodec\install.ico (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\MediaEldoradoCodec\Uninstall.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
---------------------------------------------------------

Please help me as the guys at STOPzilla (even though I paid for their product, which won't even run anymore) aren't helping!

Thanks,
DrGAKMAN

Dani AI

Generated

Quick, focused troubleshooting you can do now (moves from safe diagnostics to fixes). These steps assume a recent anti‑malware sweep already ran but the UI items still won’t open — they’re designed to tell whether the problem is a policy/association issue, a damaged Explorer/shell, or an active/resident component.

Try these checks first

  • Disconnect from the network to reduce reinfection risk, then boot to Safe Mode (F8). If Control Panel / Computer work in Safe Mode the problem is likely a shell extension, policy, or resident malware.
  • Test opening Control Panel and Computer directly: press Windows+R and run control; then run:
    explorer.exe shell:MyComputerFolder

    If those work but shortcuts don’t, it’s an association/shortcut/shell-extension issue.

Targeted repairs (do these only after exporting any registry keys and backing up important files)

  • Open an elevated command prompt and run:
    sfc /scannow

    This repairs missing/corrupted system files.

  • Check registry policies (run regedit). Look under:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

    If values like NoControlPanel or related entries exist, export the key, then remove or set them to 0.

  • Re-register the shell (optional, if you suspect shell DLLs are broken):
    regsvr32 /i shell32.dll
  • Use Autoruns (Sysinternals) to disable unknown shell extensions, and run on‑demand scanners (another AV and a rootkit scanner) from Safe Mode with Networking.

If nothing fixes it

  • Create a temporary admin to see if the profile is damaged:
    net user tempadmin P@ssw0rd /add
    net localgroup administrators tempadmin /add

    Log into that account — if the UI is fine, recreate the user profile and copy data.

Next post: include which AV/firewall you had installed and exactly what happens when you try Windows Update or open Control Panel (errors/messages). Also post an Autoruns or HijackThis log as suggested and answer ’s AV/firewall questions so helpers can tailor the fix. If repair attempts fail, back up data and consider System Restore or a repair install.

Recommended Answers

All 2 Replies

What anti-virus program are you using? What firewall?
What happens when you try to get to Windows Update? What happens when you try to open the Control Panel?

Hi,

First of all, could you post a Hijack This log as this will reveal all the processes linked to the problem. Make sure that you close all other instances of any program before you run it.
Again, did you run a full system scan with a good, trusted anti-virus software like AVG? If it does find any viruses, it will quarantine them, or attempt to heal them. After running the scan, get SDfix from here. Just run the program, and it should re-enable all disabled components.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.