Help - Search - Members - Calendar
Full Version: regedit (no access?)
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
xALPHA MALEx
How can I fix this problem! I don't know all the computer language so be detailed with me. I can't seem to get into me regedit. Some how it was renamed. Can you please help.
ALPHA MALE :
Mosaic1
Regedit is a place only for experts and others who are being guided by experts. You should not go in there unless you know what you are doing.


What exactly happens when you try to open regedit. And how are you trying to open it?


Post a hijackthis log please. Download and then extract Hijackthis.exe to a new folder. Do not run it from the zip the desktop or a temp folder.

Here's a link:
http://www.merijn.org/files/hijackthis.zip

Do not remove anything using HijackThis. Save the log and then copy and paste the contents into your next reply here in this same topic. It lists many types of entries. Some are good, and others need to be removed. We will help you sort it out.
xALPHA MALEx
Well I was worried that sobebody hijacked my regedit and sure enough when I tried to access it I it said it had been disabled by my administrator. My computer works fine I just watn to see if something else is going on.
xALPHA MALEx thumbsup.gif
Mosaic1
That restriction can be placed for several reasons. Is this a work computer?


May I see a hijackthis log please?
xALPHA MALEx
Let me know if this is it.

Logfile of HijackThis v1.99.1
xALPHA MALEx
DID YOU GET THAT?
Mosaic1
When the log opens, copy and paste the contents into your next reply.
xALPHA MALEx
Logfile of HijackThis v1.99.1
Mosaic1
Youhave a very nasty worm. It is spread through ICQ and File sharing networks. I see you run Limewire. I stronlgy suggest you uninstall LimeWire.

Read more:
http://securityresponse.symantec.com/avcen...aggle.e@mm.html

I'll be back later with more.
Mosaic1
I am not leaving you in a lurch. But I have to do some chores and errands. I also have to study that link and work out a removal for you. As you see, there is a lot to be considered.
xALPHA MALEx
Thank you very much. Do I need to stay online for a while or will you be back at a certain time?
xALPHA MALEx
Mosaic1
There is going to be more. But as a start do this:




Download this zip:
http://www.dougknox.com/xp/fileassoc/xp_regfile.zip

Extract the reg file it contains to your desktop. It's name is:
xp_regfile.reg

We'll use it shortly.



Sign off the internet.

Run hijckthis and fix these items,

F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.win
F1 - win.ini: run=C:\WINDOWS\system32\mouse_configurator.win

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


Delete these files:
C:\WINDOWS\system32\winmgd.win
C:\WINDOWS\system32\mouse_configurator.win

----------------------

Double click on xp_regfile.reg and say yes to the prompt.

Restart the computer.


Go here and have your computer scanned for viruses:

http://www.pandasoftware.com/activescan/


It will not fix anything, but it will generate a log. Please do that and then post that Oandascan log into your next reply here.


Run hijackthis and post the new log too.


I'll be back in an hour or two. I can't be sure. But I stayed around long enough to get you started. There will be more.

This one has been around for a while. Is your Anti Virus up to date? If not, update it after you finish everything else and run a full system scan, Let me know what it finds.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.