Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > HijackThis Log Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Closed Thread
 
Thread Tools
Old 04-12-2008, 08:35 AM   #1 (permalink)
Registered User
 
Join Date: Apr 2008
Posts: 1
OS: winxp sp2


safeboot minimal key error and rootkey trojan

Ok first time user here.
I've got some kind of rootkey virus/trojan that blocks all anti-virus program loading and scans (as well as loading various microsoft programs, intellimouse, msworks, etc.). It also prevents safemode entry attempts. This virus somehow got past my installed Outpost AV.

Multiple online virus scans tried: panda, trend housecall, bitdefender, and kapersky and 3 days later still stuck as these scans either froze or did not discover any malware other than adware ??

As some online articles suggested, I ran safebootkeyrepair and it got me into safe mode once but at that time all the virus software I tried performing either gave an "invalid win32 appl." error or stated "unable to install in safe mode" msg. Before leaving the one time I was in safe mode, I performed regedit32 and removed all mdelk, srosa, wintems hldrrr keys as suggested by online webhelp forums.(there were about 6 keys ).
Unfortunately most seem to have all reappeared at the next re-boot.

Subsequently as well, every new safe mode attempt just brings me back to a reboot and safebootkeyrepair.exe gives the following error message in the log.txt :

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
plus at end
Error: Key: system\currentcontrolset\control\safeboot\minimal does not exist!
this is one cagey trojan.

any help appreciated: the online virus scans that supposedly avoid the virus blocking either freeze up at around 3-5 minutes or discover nothing (curious becuz the bad programs keep appearing in a search). Complicating matters, by not being able to go into safe mode. this keeps me from running anti virus specific .exe 's from avg, pavark etc. which are suggested to be run in safe mode. I also tried microsoft's malicious software tool which also froze?? (sigh)

I've removed all AV software and only have Spybot sd installed currently which was not on your suggested removal list??

Meanwhile, I'm trying all the online scans again starting with panda (each take about 7-8 hours so I'll have plenty of free time awaiting your advice (smile))

addendum; I forgot to mention that this virus/trojan constantly tries to install something called "microsoft photo info" which i have to cancell a few dozen times anytime i try to use windows explorer or other software

Last edited by ziggyff : 04-12-2008 at 08:52 AM. Reason: addendum
ziggyff is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 04-17-2008, 05:40 AM   #2 (permalink)
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: Rhode Island, USA
Posts: 3,252
OS: XP Home SP3, XP MCE SP3, XP Pro SP3


Re: safeboot minimal key error and rootkey trojan

Hello and welcome to TSF.

Sorry for the delayed response. If you have not received help elsewhere and still need help please follow the instructions in IMPORTANT - Read This Before Posting A Log and post the two text files, main.txt and extra.txt produced by the Deckard's System Scanner, as it has been a while since you posted.
__________________
My services are free. However, you can donate to TSF to help keep it running and prospering.
ASAP

amateur is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 07:28 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82