View Single Post
Old 2009-09-02, 12:39   Link #4
SaintessHeart
NYAAAAHAAANNNNN~
 
 
Join Date: Nov 2007
Age: 35
Quote:
Originally Posted by kakakka View Post
It doesn't go to Safe Mode

Here's the result from HiJackThis

Spoiler for hijackthis:


These entries always show up in Malwarebyte scans

Spoiler for mbam-log:
OT : Funny, your computer runs BOTH HP and Compaq's custom programs. Rule of the thumb : never install or run anything packaged under the computer's brand name, they are usually useless and full of bugs. Just install the drivers they give you.

You mean it hangs when you try to go into safemode?

Had the same problem recently, need to try a few times for me. Anyway I bolded the potential malware on hijackthis already, the red on being the most suspicious.

Regedit seems to be disabled, one of the first few signs of something wrong. Only the dumbest of system administrators managing a network would disable regedit IMO, because it doesn't help to slow infection of malware, only helps to deter port intrusions.

1. Uninstall Google toolbar and Superantispyware. For the latter product, DELETE anything it quarantined. Don't restart your computer yet if it does prompt.

2. Download and run CCleaner. Clean up your registry AND temp files, then go disable system restore. Now you can restart.

3. Backup your Registry if you can access regedit, and quarantine the backup in an antivirus. Delete the stuff I bolded on hijackthis. Before you do that, rename hijackthis.exe with something random like "uguuuguu123456.exe" and set the file as read-only. Post the new hijackthis log here if you can, and if possible, the safemode one too.

EDIT :

I am not sure if this works, but try if you want, since your computer is pretty much either a test subject or a gone case.

Open notepad and copypasta this in :

Quote:
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System]

[-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\DisableRegistryTools]
Save it as "Repair.reg" by selecting the file type to save as All Files, and putting in the filename.

This too :

Quote:
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System]

[-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\DisableTaskMgr]
Save this as "repair2.reg" under same methods.

Run both the .reg files and replace the registry values, then go back to step 3 before my edit to post a new hijackthis log.

P.S If they don't work modify the files with these

Spoiler for just in case:


I haven't been building .reg files for a bloody long time, close to half a decade.
__________________

When three puppygirls named after pastries are on top of each other, it is called Eclair a'la menthe et Biscotti aux fraises avec beaucoup de Ricotta sur le dessus.
Most of all, you have to be disciplined and you have to save, even if you hate our current financial system. Because if you don't save, then you're guaranteed to end up with nothing.

Last edited by SaintessHeart; 2009-09-02 at 13:09.
SaintessHeart is offline   Reply With Quote