Welcome to SecurityForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Disabled registry from new trojan

 
   Security Forums (Home) -> General Discussions RSS
Next:  Trojan horse Generic10.BHES  
Author Message
Mike S.

External


Since: Jul 24, 2008
Posts: 1



(Msg. 1) Posted: Thu Jul 24, 2008 4:25 am
Post subject: Disabled registry from new trojan
Archived from groups: alt>comp>anti-virus (more info?)

I recently had my computer infected with four trojans due to them
being new and undetected by the majority of anti-virus programs. So I
submitted them to AVG who confirmed they were trojans and updated
their virus definitions. This removed the four trojans from my
computer. However, I still have problems that need to be fixed. One of
which is a disabled registry.

Here's what needs fixing (from my HijackThis log):

F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files
\System\svchost.exe"

O2 - BHO: (no name) - {5277E001-1190-3001-0699-ca3230262a11} - C:
\Program Files\Common Files\System\wship_help.acm (file missing)

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System,
DisableRegedit=1

O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System,
DisableRegedit=1


Some people have suggested using SDFfix. Is there any reason why I
can't just use HijackThis to fix them? SDFix seems more complicated
and unnecessary. Or does what I use to fix those problems depend on my
computer and whether it's up-to-date and backed up, etc.?

I just want to use the safest, most reliable method to fix this
problem.

 >> Stay informed about: Disabled registry from new trojan 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1748



(Msg. 2) Posted: Thu Jul 24, 2008 4:14 pm
Post subject: Re: Disabled registry from new trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Mike S."

| I recently had my computer infected with four trojans due to them
| being new and undetected by the majority of anti-virus programs. So I
| submitted them to AVG who confirmed they were trojans and updated
| their virus definitions. This removed the four trojans from my
| computer. However, I still have problems that need to be fixed. One of
| which is a disabled registry.

| Here's what needs fixing (from my HijackThis log):

< snip >


| Some people have suggested using SDFfix. Is there any reason why I
| can't just use HijackThis to fix them? SDFix seems more complicated
| and unnecessary. Or does what I use to fix those problems depend on my
| computer and whether it's up-to-date and backed up, etc.?

| I just want to use the safest, most reliable method to fix this
| problem.


Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/ds/28400/28470/Multi_AV.exe

http://www.pctipp.ch/downloads/dl/35905.asp

English:
http://www.raymond.cc/blog/archives/2008/01/09/scan-your-computer-with...ltiple-

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp

 >> Stay informed about: Disabled registry from new trojan 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Virus: Firewall and antivirus, trojan scanners, .. disable.. - For any reason, Zone Alarm didn't rename a .PIF file attached to a message. Confusing it with a .TIF, and quite sure the work was correctly done by the firewall, I confidently clicked on the attachment and within the following microsecond I realized my....

Trojan Stuck in registry, System Restore Unavailble - Hiho, I have a Trojan. Packed. 9 and other spyware trapped in my WinXP registry and I can't get it out. It is intefering with my IE as well as all my other online programs (AOL, gaming, etc). Norton and SpyDoctor do nothing. Will a registry cleaner solv...

New Trojan? - Not sure what's up with my machine, but the spousal unit was on Ebay the other night and may have picked up something. I've noticed since then, when I've used Hotmail as well as our bank's website, the on-screen chars. and the typing lags behind...

trojan.svc.a - my avg anti virus resident sheild has come up with constant warnings 'backdoor trojan svc.a detectected' I can find no inf on this one-i ran avg it said it detected and healed but i went away for a while came back then it said same message. What is this....

PUP.exe Trojan? - I have been having some odd problems lately with my PC which seem to indicate a Trojan in onboard. On startup I get a 'new' .exe appearing in my C:\windows\system32 directory ervery time. It always has a different name (tblfiltu.exe, ssecd.exe,..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]