Add new comment

"Downadup" = "Conficker" and reg3dit

Worm infected my PC 01/17/2009

I monitor & kill trojan.exe added to C: temp folder with
1. Process Explorer v11.32, replaces TaskMgr and no permissions needed.
http://technet.microsoft.com/en-us/sysinternals/default.aspx

I fix disabled regedit, taskmgr, tweakUI with no-permissions editor
"reg3dit" at http://sysd.org/stas/node/18

As of late 2/8/9, reg3dit is no longer able to correct
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
i.e., the editor runs but changes don't last.
Keys of form "DisableRegistryTools"=dword:00000001

Suggestions?

By the way, MS Windows Update trashed my PC, so I had to backlevel some weeks
with Acronis TrueImage.

Microsoft Windows Defender and latest Microsoft Malicious Software Removal Tool
are worthless.

Anonymous (not verified) » February 9, 2009 » 14:41

Reply

*
*
The content of this field is kept private and will not be shown publicly.


*

  • Allowed HTML tags: <a> <i> <b> <u> <img> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <pre> <hr>
  • Lines and paragraphs break automatically.
  • Textual smileys will be replaced with graphical ones.