Jump to content

Cant logon to WindowsXP, deleted some registry keys


guptavis
 Share

Recommended Posts

HEllo people,

I use Malwarebytes Antimalware regularly and havent had an infection found in about a year.

Yesterday i scanned after about a month and i saw 12 infections !

MBAM said it could not clean a few infections:


Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 2
Internet Explorer Unknown

9/11/2010 11:19:49 PM
mbam-log-2010-09-11 (23-19-49).txt

Scan type: Quick Scan
Objects scanned: 94917
Time elapsed: 2 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mp3_audio_codec (Spyware.Zbot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: c:\windows\system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> Delete on reboot.

Files Infected:
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\user.ds.lll (Stolen.data) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sdra64.exe (Spyware.Zbot) -> Delete on reboot.

So i thought of manually removing the infected Registry keys. (Something i've done many times before)

While I was at

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

I saw a key named 'Special Accounts', it looked fishy to my paranoid eyes. Had some 'strange' values in it, None corresponding to my Username (Administrator) or Guest. 3 were somewhat random letters with a ~, and one was ' search assistant'. Looked like malware remains of some kind, so, i deleted them all.

After that i rebooted, the welcome screen showed up (usually straightaway shows me desktop since there is just one user 'Administrator') with the only user 'Administrator'. When i click it, it shows 'loading your personal settings' for a second. Then it reads 'saving your settings' and stays at the logon screen. Repeated it for 10 times. Restarted and repeated. Shut Down and repeated. Always same result.

Then i tried the 'Last Know good configuration' in statup options. Still same result.

Tried 'Safe Mode' starts loading then breaks at 'unable to load NTFS.dll'

'Safe mode with networking' same logon screen and same one second login and return to logon screen.

I dont know how to login. Can someone please help. Is there a way to remotely add the keys back to my registry. Or some way to correct this problem?

Thanks and Regards

Link to comment
Share on other sites

Do you have the Windows disk? It's going to be very difficult if you haven't.

Assuming you do have a disk, load it, shut down and reboot. (Ensure that CD is first boot device.) Somewhere in the choices that come up on screen from the disk is a Repair install or "R". Select that and follow the instructions.

Note: the advice above is from memory of several years ago and may be missing some detail.

When you are up and running again, please, please make a backup or disk image so that the don't have the same problems again.

Link to comment
Share on other sites

As a matter of urgency, you also need to update your MalwareBytes to the latest version of the program (1.46) from your current 1.44 and also to the latest definitions database (4603) rather than the 3510 shown in your log.

Link to comment
Share on other sites

Do you have the Windows disk? It's going to be very difficult if you haven't.

Assuming you do have a disk, load it, shut down and reboot. (Ensure that CD is first boot device.) Somewhere in the choices that come up on screen from the disk is a Repair install or "R". Select that and follow the instructions.

Note: the advice above is from memory of several years ago and may be missing some detail.

When you are up and running again, please, please make a backup or disk image so that the don't have the same problems again.

Thanks for the reply. I remember having seen a repair option too, some years ago.

Finally found my Win XP CD and booted with it. It started fine and gave me this screen (attached at the end as attachment)

It did show a message of ' Detecting previous windows Installations ' before coming to this screen.

I guess it somehow did not detect my windows XP. Could be because i had installed Windows7 on another hard disk from the same MBR.

____________________________________________

On bootup it shows. 243kx8p.jpg

Default choice being WIndows7. So i guess ill have to remove the Windows 7 Bootloader for the XP setup CD to recogniseand repair my windows install. Any advice on How i can do that ?

On putting the CD (and restarting a couple times to try different options.) It did wipe out Grub from the MBR.

Earlier it used to be GRUB->Windows7 loader-> choose WinXP.

Now its Windows7 loader-> choose WinXP

And don't use an Administrator account for general web browsing. Use a Limited account as they will not allow the installation of new programs or alterations to the system.

I know this is recommended but it becomes annoying to use one account for browsing and another for other work. Im too lazy to switch back and forth. Though i think the infection could be off a cd. Might do this now,

As a matter of urgency, you also need to update your MalwareBytes to the latest version of the program (1.46) from your current 1.44 and also to the latest definitions database (4603) rather than the 3510 shown in your log.

Thanks,

Will do this once i can get in to the system.

post-18261-090827700 1284630518_thumb.jp

Link to comment
Share on other sites

There have been a whole load of trojans & worms getting through even highly regarded security suites such as ESET in recent weeks. They appear to have come through security flaws in Java & similar add-ons. One of the best ways to ensure all your add-ons & similar utilities are kept up-to-date is to use Secunia PSI weekly (Secunia Scanner). I neglected it over the last months and paid the price by having an insecure Java consol. Fortunately the infections were fairly easy to remove.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy