07-16-2009 06:46 PM
Ok, ran RRT in safe and normal mode. Access to "regedit" is still blocked.
However, I was able to run "HiJackThis." Log is attached.
07-16-2009 07:07 PM
Hi
We are slowly getting there you still have other infections. I will weed out the bad ones in the hijackthis log now we can get that to run.
Plus still the rootkit, that's a different fish.
Quads
07-16-2009 07:30 PM
Ok, I have left the first bad one out as i am not sure yet if that will cause a login loop with userinit.exe
So Now start Hijackthis again and tick, check these entries only
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install (not need on startup)
O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\HP_ADM~1.MET\LOCALS~1\Temp\notepad.exe
O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\u0h72og.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\u0h72og.exe (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Pol
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
And click "Fix Checked"
The PC may need to be restarted.
Quads
07-17-2009 02:55 AM - edited 07-17-2009 03:22 AM
I will slowly keep breaking this down, and freeing it up.
You comment earlir on
"and restarted in normal Windows XP mode. Security Configuration appeared stating Windows was in Diagnostic or Selective Start up Mode. It asks me to choose Normal Windows startup and start Windows normally to stop the warning, "
Could be to do with
O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\HP_ADM~1.MET\LOCALS~1\Temp\notepad.exe
Which is a Rogue / Fake
Quads
07-17-2009 03:30 AM
07-17-2009 03:34 AM
Just click, "Do System Scan only"
Then when it finishes scanning like before to get the log you will see little tick boxes, Please only tick the entries I stated in the previous post with the list of entries to tick and fix checked.
Quads
07-17-2009 03:47 AM
I don't see this entry:
"O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\HP_ADM~1.MET\LOCALS~1\Temp\notepad.exe
Instead, it says,
"O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\HP_ADM~1.MET\LOCALS~1\Temp\mdm.exe"
Do I still check it?
07-17-2009 03:59 AM
Ok will have to think on that, why it changed.
Did you see the entry for disabled registry??
Just do the others
Quads
07-17-2009 04:06 AM
Jormungandr wrote:I don't see this entry:
"O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\HP_ADM~1.MET\LOCALS~1\Temp\notepad.exe
"
Instead, it says,
"O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\HP_ADM~1.MET\LOCALS~1\Temp\mdm.exe"
Do I still check it?
In answer to that question.
Yes remove it, It belongs to a Trojan Downloader
Quads
07-17-2009 04:13 AM
Yes, the DisableRegedit=1 entry is there.
So, check/tick all the ones you listed except for:
"O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\HP_ADM~1.MET\LOCALS~1\Temp\mdm.exe" ?
