Removing items from MSCONFIG after WMF exploit



OK, so, I’m busy killing off running processes and fire up MSConfig to try to keep them from coming back on the next boot. To launch msconfig go to start, run… type in msconfig and click ok. The startup tab is where we’re looking for programs running at startup (makes sense…) This is a bit easier and more straightforward than visiting the run entry in the registry. It does combine a few locations into one place.


That much said, one or two visits I made were in the registry currentversion/run key that msconfig gives a listing for. Anyway, here’s what I found THERE….

There was an entry called system which was set to c:windowswsystem32kernels64.exe and xp_system which is set to c:windowsinet20001winlogon.exe in addition winstall.exe was run from c:winstall.exe

I was able to get rid of kernels64.exe and winstall.exe (they had been killed from memory using task manager.) Winlogon was running (two copies, system process and user process, the user process was coming from the strange directory inet20001 which is not a legit windows directory.)

The process of disabling did take a couple boots and the registry fix to run Task Manager had to be run each time as I tried to “kill” off running processes.

Popularity: 1% [?]

PDF Creator    Send article as PDF   
Blog Traffic Exchange Related Posts Blog Traffic Exchange Related Websites
  • Review of Buying a Great Boat by Athur Edmunds When the author of a book is an ex naval architect, you're pretty much guaranteed that you're getting some first class knowledge when it comes to selecting the boat that is right for you. This book did not disappoint in any major way and is truly helpful for those buying......
  • How to Regain Momentum After Skipping Runs [/caption]If we're being honest, it's not always easy to keep a consistent running schedule. There are some obsessive-compulsive exercisers who would probably feel miserable if they missed a run, but for the rest of us, we occasionally trip up and find ourselves in need of some momentum. Anyone who's ever......
  • Don't Use Free Registry Cleaners! Whatever you do, don't use free registry cleaners software, read this honest report about free registry cleaners to find out the consequences of using free registry cleaners software! Free registry cleaning software will ruin your computer by deleting important registry entries that are essential to run your computer and these......

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site