Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Nasty, Nasty Variant of Antivirus Soft


  • Please log in to reply
No replies to this topic

#1 mhmallory

mhmallory

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:35 PM

Posted 02 February 2010 - 11:32 PM

I' m working on removing a nasty, nasty strain of Antivirus Soft. This strain is a little different infections I have seen. It has the following traits -

1). Programs cannot be installed from any source.

2). If I attempt to run Malware Bytes from a pen drive, I get an error of - Unable to write Registry ( running as administrator).

3). If I add a user from command prompt, with net user, and add that user ID to the Administrator group with net localgroup command, this new user ID cannot write to registry.

4). I' am denied access to "Administrative Tools", "Local Security Policy".

5). Cannot write registry from safe mode.

6). I attempted to use latest version of Combofix, but it cannot install because it cannot access registry.

It appears that Antivirus Soft has changed read/write permission on the registry. I can run an existing installed copy of Malware Bytes with definitions that are 30 days or so old, no virus is detected. Right now, I'm making a image copy of the infected computer with Acronis to a network drive.

What should I try next? Should I manually attempt to edit the registry keys and remove affected keys?

TIA
mhmallory

My mistake - This is a XP SP2 Desktop :thumbsup:

Edited by mhmallory, 03 February 2010 - 12:22 AM.


BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users