stuck on welcome sreen after removing reg strings because of trojan #2

Tech-Archive recommends: Speed Up your PC by fixing your registry



Soz if it's a 2nd post, but I can post in other groups, but I don't see it
here yet!!

Hi all...(trojan Spy-Agent.bw !mem)

Ad-watch was blocking an entry to the registry (ntos.exe) So I updated
"multi av scanner" online, then ran in safe mode.
"Mcafee" reported the above trojan. Below is a link I found for removal

http://www.symantec.com/security_response/writeup.jsp?docid=2007-081617-4608-99&tabid=3

I complied with step 4

Navigate to and delete the following entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Network\"UID" = [COMPUTERNAME]_[UNIQUE_ID] ***I deleted
this***
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\"pathx" = [MALWARE_ORIGINAL_FILENAME] ***And
this "userinit"*** (I hope it meant that)
***Then it stated: (Restore the following registry entries to their original
values, if required:)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\"Userinit" = "%SYSTEM%\userinit.exe,
%System%\ntos.exe"

Which I didn't do, as I wasn't sure how to, and it did state IF required!

So on rebooting, the pc stays on the welcome screen, and in safe mode it
allows clicking administrator but goes back to welcome after a few seconds.

(Oops!!...Also I didn't back up the registry) So there you have it. Is there
a way to fix this, or do I have to bite the proverbial bullet and
RE-FORMAT!!

Nestlings on Runescape and daughter using a friends memory stick. If only I
knew which ones I could delight in the punishment to be doled out.

TIA


--


Regards
p.mc


.



Relevant Pages

  • Re: Explorer.exe infected
    ... an entry will show up for that entry. ... you may need to do this in Safe Mode. ... Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file ... > my registry, but the dialog to select 'OK' disappers just ...
    (microsoft.public.security.virus)
  • cant run the fixblast.exe
    ... Try to open the registry to delete the entry and the ... registry appears for a brief minute and disappears. ... access through safe mode but the entry is not in the ...
    (microsoft.public.windowsxp.security_admin)
  • RE: cant run the fixblast.exe
    ... Try the manual cleanup of the registry/file system using this link: ... Try to open the registry to delete the entry and the ... >access through safe mode but the entry is not in the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Registry Entry Removal
    ... Taskbar Repair Tool ... and/or try safe mode. ... but unistall did not remve the registry entry under ... How can I remove this registry ...
    (microsoft.public.windowsxp.general)
  • Re: Nearly 100% CPU Usage
    ... Paul Calcagno wrote: ... for the download) will this registry problem go away that might have been ... is that I ran the OneCare Live scanner in safe mode. ... Add-ons because trying to enable them one at a time when IE is open ...
    (microsoft.public.windowsxp.general)