Removing items from MSCONFIG after WMF exploit



OK, so, I’m busy killing off running processes and fire up MSConfig to try to keep them from coming back on the next boot. To launch msconfig go to start, run… type in msconfig and click ok. The startup tab is where we’re looking for programs running at startup (makes sense…) This is a bit easier and more straightforward than visiting the run entry in the registry. It does combine a few locations into one place.


That much said, one or two visits I made were in the registry currentversion/run key that msconfig gives a listing for. Anyway, here’s what I found THERE….

There was an entry called system which was set to c:windowswsystem32kernels64.exe and xp_system which is set to c:windowsinet20001winlogon.exe in addition winstall.exe was run from c:winstall.exe

I was able to get rid of kernels64.exe and winstall.exe (they had been killed from memory using task manager.) Winlogon was running (two copies, system process and user process, the user process was coming from the strange directory inet20001 which is not a legit windows directory.)

The process of disabling did take a couple boots and the registry fix to run Task Manager had to be run each time as I tried to “kill” off running processes.

Related Posts

Blog Traffic Exchange Related Posts
  • Disinfecting a PC... part 1 This is the first in a several part series documenting the cleaning of an infected PC. The only real noteworthy item is that it was a dial-up only connection and was rather infested for that. (On par with some of the broadband connected pc's I've seen. It's also an interesting......
  • Task Manager Suspicious Processes after WMF exploit After getting into Task Manager I saw a number of suspicious processes. There were a lot of things running as my user that I didn't recognize. kernels64.exe, vxgame6.exe, vxgame4.exe, mm4.exe, vxh8jkdq2.exe, netsh.exe, cmd.exe, winstall.exe, vxgamet4.exe, vxgame2.exe covers most of the list of suspect entries. netsh and cmd are both legit......
  • How to Remove Total PC Defender | Total PC Defender Removal Guide Total PC Defender is a rogue antivirus application that installs via malware and trojans. The software then runs each time the system boots and will run a fake scan that is designed to scare the user. This scan will find security problems, numerous viruses and they will further claim that......
Blog Traffic Exchange Related Websites
  • Treadmill Vs Outdoor Running [/caption] Running outside feels great when you have the breeze cooling you down and the amazing scenery, but what if you just want to listen to music and go for a more organized run? Are there really any differences between running outside and running indoors on a treadmill? The answer......
  • Cleaner For Registry Errors The operating system of the computer has the registry at its core. Over time, the user will install and remove programs, always changing the registry contents. The registry can develop errors as it collects redundant and outdated files over time and it is necessary to fix them. If left alone,......
  • How to Eat and Run - Right Now [/caption] When you're going out on your own for a run that will last 45 minutes or more, there's a good chance that you'll need to be prepared - inside and out. And being prepared on the inside means that you'll need the energy and nutrients in your system to......
en.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site