Command Prompt (cmd) and Regedit.exe restarts or crashes Explorer.exe Automatically and Google.com randomly redirects to other websites.
1. Rename your regedit.exe located in c:\windows to a file like pctech.exe then double click and open your registry.
2. Browse to the following location. HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
3. Copy the path of the key like in this example the viral file is called: dfxu.igg
4. Click start then go to run and paste the path and click ok.
5. You should see the file listed there. If not you may have to turn on hidden files.
6. With this information we then used a tool called Avenger.exe or Hijackthis to delete the file on reboot.
Hijackthis screen shot:
Open hijackthis run system scan then click config (bottom right)
Choose the tab misc Tools on top.
Choose delete a file on reboot
Click open
It will tell you that this file will be deleted on next reboot. Click Yes or ok and your system will reboot.
This took care of it, now command prompt and regedit edit open fine.