Jst two days i switched of my firewall and antivirus and the consequence is
i am in administrator login
i have to delete a bad registry key whick my malware bytes discovered
but its malware bytes and any software not able to delete it
i tried thru regedit.exe
i tried through command prompt using reg command . its also not able to do it (after closing explorer.exe)
i also don have space to repair BY windows XP cd
i also cant delete in any mode (safe mode , cmd mode )
i also cant delete on boot up by sftware
BUt i know its definitely 100 % malware Key
its in winlogon subkey . and another in HK Root ley
i have browsed through all net i havent get any idea
pls help
but don ask me to
reinstall os , search net etc please
I need to win against this
From the ip adress that my firewall bocket during bifferoverflow . the ip adress goes to russia
keys
====
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\… Helper Objects\{3a1d08a3-585e-42ba-bf27-5274d3f… (Trojan.Vundo.H)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\… NT\CurrentVersion\Winlogon\Notify\chjzix… (Trojan.Vundo.H)
HKEY_CLASSES_ROOT\CLSID\{3a1d08a3-585e… (Trojan.Vundo.H)
* 2 days ago
* – 6 days left to answer.
Additional Details
Also i checket permissions . its not allowing me to change . says "permission denied"
But the irritating part is i am in Admin login
What else shud i be to change permissions . OR the i think the malware changed my admin previledges by WINLOGON key
2 days ago
hai
i have used
hijac this , Spybot s&d , malware bytes , mcafe anti malware , and avg anti malware ( worst of all . din even detec it)
everything possible 🙁
my same previous quest was deleted as someone voted for no best answer
sorry for tht
Tagged with: additional details • administrator login • amp • anti malware • antivirus • bocket • command prompt • consequence • firewall • hk • hkey classes root • ip adress • machine software • microsoft helper • registry key • software microsoft • spybot • trojan vundo • windows xp • windows xp cd
Filed under: Windows Repair Software
I met this before, it must be done by unknown trojan, it always creates harmful registry item key.
If you cant find the matrix of trojan, you cant win against this.
So I will give you my advices as follow, if you wanna win against this, not reinstall OS.
1. Update your antivirus program or use special antitrojan tool.
2. Try a registry guarder to scan errors and restore it.
3. Try another spywarecease tool like this.
http://users7.nofeehost.com/walle321/spywarecease.asp
It isnt a good choice to edit registry manually unless you know your want exactly.
try running regedt32 I think it is only on vista. You may be able to download it from the web and use it to rid yourself of the bad keys. Good luck
Go to Start, Run, and type regedit and press Ok. Navigate to these keys, uses the tree view control on the left. When you find the key, right click it and press Delete.
Go here and follow these instructions. Maybe they’ll help…
http://virusexperts.blogspot.com/2008/10/trojanvundo-removal-tool.html
Also, maybe a registry cleaner will take care of it for you:
Advanced SystemCare Free: http://download.cnet.com/Advanced-SystemCare-Free/3000-2086_4-10407614.html
CCleaner: http://download.cnet.com/ccleaner/