PDA

View Full Version : zlob virus?



LA_MERC_th33_r00k
October 16th, 2007, 08:41 AM
I am cussing this one out for sure. It pops a "security message" window and has disabled the computers users to non-admin status. I cannot access control panel no matter how I try. It works in safe and normal modes. Scanners used to date:
Spybot
Adaware
AVG free
Scanned HDD on bench machine w/ Spyware Doctor and AVG full version.

Still there. Is there something I am missing or is time to start thinking wipe/reload. I really do not want to wipe and reload.

Is there a registry edit I can do?

T4rg3T....Onji......I need help.

rook

LA_MERC_Onji
October 16th, 2007, 08:47 AM
1. make sure when your scanning, to ALWAYS do it in safe mode
2. do a start-run-msconfig, goto the startup tab and uncheck everything except your virus software
3. do a start-run %temp% and delete everything out of there

if you cant get to the control panel, try doing a start-run-control
if that doesnt work you can try getting do a specific control panel applet vai the run box. for instance, for add/remove programs do: start-run-appwiz.cpl

LA_MERC_th33_r00k
October 16th, 2007, 09:20 AM
So I deleted the Temp files.

Will not let me access start-run-control and start-run-appwiz.cpl due to restrictions set on this computer. It tells me to see the administrator.

I keep trying to ell it if I do see the "administrator" I will kill him and permanently put him away in a safe spot.

LA_MERC_Spark
October 16th, 2007, 09:21 AM
meh... download TRK here

http://trinityhome.org/Home/index.php?wpid=93&front_id=12

use the iso file to create a boot disk. When it loads do not hit any keys. type this command in at the prompt:

virusscan -a avg

this will run avg which will automatically dl updates. The good part is this process is independent of windows so it is better than safe mode. There are also 3 other virus scan programs available. see the documentation for details

LA_MERC_T4rg3T
October 16th, 2007, 10:07 AM
Usually, these virii do not remove administrator access but they remove access to certain functions that will allow you to uninstall them. They basically change registry settings which limit your access..

Start off by changing this registry settings back to normal. I would suggest doing a restore to the date before you got the virus using XP's system restore.

If you can not restore, try manually reseting the registry keys.

http://www.pctools.com/guides/registry/detail/543/

http://www.pctools.com/guides/registry/detail/1041/

Will will then need to remove the virus and try to find out all what registry settings it makes changes to.

LA_MERC_T4rg3T
October 16th, 2007, 10:09 AM
These instructions might also be helpful.

http://www.symantec.com/security_response/writeup.jsp?docid=2005-120811-1051-99&tabid=3

LA_MERC_Nutria
October 16th, 2007, 10:31 AM
If I have any problems I use this safety.live.com

LA_MERC_th33_r00k
October 16th, 2007, 11:09 AM
I have 2 more machines coming in with the same issue. HAhahahahahaha. Pron lovin bastages.

42d3e78f26a4b20d412==