Chat
Micro Mart Forum
Home       Members    Calendar    Who's On
Welcome Guest ( Login | Register )
        



Registry locked on users with Admin... Expand / Collapse
Author
Message
Posted 18/11/2008 22:25:24


286

286286286286286

Group: Forum Members
Last Login: Today @ 22:38:02
Posts: 436, Visits: 897
PC has 4 users, Mum, Dad, kid1, kid2. Mum & Dad are Admins but can't Run or access programs.

I created a new Admin account for me and installed my favourites.
Comodo, Spywareblaster, Avast, Spybot, Malwarebytes.
Ran them and cleaned loads of cack.
Updated to SP3.
Installed Windows Defender.
Ran CCleaner.
Ran Glary Registry Repair.

Spybot can't immunize the Admins' Internet Explorer files.
The other Admin's get an error message about not being able to execute Rundll32.exe.

I've searched this and amn't getting anywhere!!

Over 10 hours wasted so far!!!

Media PC 3700 64 @ 2.5GHz XP Home HD3850
Kitchen PC XP3000 @ 2.3GHz XP Reduced Media Ti4200
Advent laptop AMD64 3000 XP Home STOLEN!!
Dell laptop 1.66GHz CoreDuo Mandriva 2009 STOLEN!!
Mac Mini 1.66GHz CoreDuo OS10.4
'Drawer PC' E2140 @ 2.75GHz Ubuntu 7.10
24" iMac 2.4GHz Core2Duo OS10.5
Asus Eee 900 Xandros KDE 3.4

Support the Open Rights Group
Post #321732
Posted 18/11/2008 23:10:14


Pentium

PentiumPentiumPentiumPentiumPentium

Group: Moderators
Last Login: Today @ 22:34:53
Posts: 8,994, Visits: 25,943
sounds like you need some malware specific cleaning, not the generalised stuff , prolly vundofix or running HJT and posting at icrontic or another specialist site like castlecops

SPIKE09
REMEMBER IT'S JUST A RIDE (BILL HICKS THE GREATEST)
rig 1 Spike Athlon 64 X2 3800,1 gig pc3200 (dc) ,radeon X1900XT rig 2Angus Ogg Athlon  2200,ASUS A7V8X-X,1GB2 PC2700,RADEON 9600XT
rig3 The Dagda Acer aspire 1353 xv, AthlonXP-M 2400, 512 Mb PC2700 .Rig 4 Q6600,ASROCK DUALQUAD thingy,2GB GEIL DDR540 X1600pro rig 5 TVTWINs- IntelE6400,2Gb DDR667,Nvidia6600 silent.rig6.AMD 64 3700 1Gb pc3200 rig7.Smokey Q6600,2GB pc5400,x800gto, asrock quad-dualthingummy| E6420,4GB ram and Q6600 currently homeless TOP 1,000 in the world in F@H
F@H BETA TESTER- team MM FOLD it does every body good join team 46590 2ND Mug. Hmm you know who you are.
 

Post #321747
Posted 19/11/2008 08:22:41
386

386386386386386

Group: Forum Members
Last Login: Today @ 20:25:59
Posts: 586, Visits: 1,439
You sound like you need a bit more 'grunt' in your efforts. Try HiJackThis! . As the blurb says, 'it is not for the average user' and gets deep into what processes/dll's etc are active on your machine. I don't hold out much hope however as it sounds like someone has been browsing/delving where they didn't ought-to in Admin mode.

Anyway, find out what you can and then repost in the AV forum.
Post #321767
« Prev Topic | Next Topic »


Reading This Topic Expand / Collapse
Active Users: 0 (0 guests, 0 members, 0 anonymous members)
No members currently viewing this topic.
Forum Moderators: TheEditor, CaptainCAD, admin, Sarah of the Dead

Permissions Expand / Collapse

All times are GMT, Time now is 10:50pm

Powered by InstantForum.NET v4.1.4 © 2009
Execution: 0.094. 10 queries. Compression Disabled.