Quote Originally Posted by Pureghetto View Post
I also think it's virus / spyware. Your test is interesting and this is my result: I renamed hijackthis.exe to regedit.exe and it also behaved the same way. Currently my pc is on safe mode and I am running a virus scan on it (also regedit / taskmgr works fine on safe mode).

Computers in this network have been compromised too many times. A month or so ago my brother had virus problems that I was not able to clean up until several runs in safe mode. Recently he had this odd issue where he couldn't surf the net which was fixed rather quickly, and now my pc gets hit.

I r scared panda.
I know, brother bear. If it's killing a program called (but not necessarily) regedit.exe in normal mode, I'd bet that it's a virus. The virus doesn't get started in Safe Mode, so that's why it doesn't affect regedit or taskmgr there.

Download Process Explorer for Windows v11.0 from Microsoft's website. Run it, and select the Image Path column (from View... Select Columns).

What I think you should do is start killing processes, one by one, and running regedit. The process that killing allows regedit to run is the guilty party. Start by killing everything outside of C:\WINDOWS. Even if you're sure the process isn't a virus, kill it anyway.

Any process that immediately restarts after you kill it is also a prime suspect. Make a note of that process name and path. Let me know how you get on.