 B Premium,MVM join:2000-10-28
| reply to siggyx Re: Help
Well, technically, I think the rules are broken ONLY after the first HJT log appears! So we should be safe.
Swordfish, the only potential problem with logging in as local administrator is that you'd be giving any resident trojans more privileges.
If, however, your domain user (the regularly logged in user who was infected) is ALREADY a local administrator of the machine (as is frequently the case), then it won't matter much.
It would probably be best if you took this machine off the network until you clean it up.
-- B -- In a realm outside causality and function |
|
  Swordfish II Watching A Dream Premium join:2002-05-12 Cloud 9 | ok, I ran adaware in safe mode but none of that stuff came up. Gonna do the virus scans and hijack this scans -- I'm not going there to die. I'm going there to see if i really am alive. |
|
 B Premium,MVM join:2000-10-28
| While you're still in Safe Mode, try going to a command prompt (you can use Explorer but I don't trust it) and navigating to the directories indicated in your first screen shot -- see if those files are still there.
-- B -- In a realm outside causality and function |
|