Unsolved
This post is more than 5 years old
2 Intern
•
2.2K Posts
0
3914
June 14th, 2008 23:00
Scotty Asking For Permissions
After MBAM found and cleaned up C:\WINDOWS\SYSTEM32\DRIVERS\rndismpp.sys I have started to get Winpatrol Alerts as to whether to allow a change in a couple of entries to the registry.
The first is labeled as a .REG file and the system asks to change regedit.exe %1 to regedit.exe %1*
Th other is labeled as a .SCR file and the change is from %1 /s to %1%* At the top of the second entry it says "NAME" and under that "Company Name".
I have no idea what any of of this means or if a HJT log would be required for further analysis. I do remember that MBAM made some reference to root kit as per the above file. Thanks for any help. As careful as I try to be I guess stuff still sneaks in.
0 events found


joe53
2 Intern
•
5.8K Posts
•
17.3K Points
0
June 15th, 2008 02:00
It wouldn't surprise me that WinPatrol alerts you to registry changes after MBAM deletes a nasty. Can you give the exact text of the WinPatrol alert?
The .SCR file extension can refer to a script, or to a screensaver- did you change your screensaver lately?
However, if MBAM had detected/removed that rndismpp.sys on my PC, I would probably run a HJT logfile by the experts, just to be sure I was clean.
dalem29
2 Intern
•
2.2K Posts
0
June 15th, 2008 11:00
Hi Joe:
It just basically asks if it is OK to make the change...doesn't explain what the change would amount to. I'll go ahead and post a log and see if there is anything else in there.
dalem29
2 Intern
•
2.2K Posts
0
August 7th, 2008 17:00
joe53
2 Intern
•
5.8K Posts
•
17.3K Points
0
August 7th, 2008 20:00
I imagine you must have floated this thread to the top at some point.
To remove it, click on it to open it. Then click on "Thread Options" at the top, and select "Un-Float this Thread".