View Single Post
Old 11-16-2008, 06:19 AM   #41 (permalink)
Ried
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,923
OS: WinXP and Vista


Re: Programs Restricted/no desktop/Virtumonde

Hi bajanknight,

From the Admin acct, ensure resident AV and any protective programs are disabled.

Open notepad and copy/paste the text in the code box below into it:

Quote:

Fcopy::
c:\windows\SYSTEM32\DLLCACHE\userinit.exe | c:\windows\SYSTEM32\userinit.exe

Driver::
Otx83
TTUQNRGA

Registry::

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Otx83.sys]

Save this as "CFScript.txt", and as Type: All Files (*.*)
in the same location as ComboFix.exe





Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt. Please post that log for review.


Will Safe Mode load up under Steph acct?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here