![]() |
IOBit Software
|
|
|
||||||
| Software Software such as operating systems like Windows XP, Windows Vista, Windows 7 etc., or specific programs. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I have a PC that has its task manager & registry editor disabled, I'm not quite sure what caused it, most probable reason is spyware but I have my PC well protected.
Anyhow, I can't seem to be able to unlock the task manager again. Whatever it is that caused this has also disabled registry editing. I've tried running scripts that re-open the registry but its quickly closed again, which led me to believe that something is running on the PC ensuring that the registry remains closed. Spyware and antivirus scans didn't work, so I tried using Hijack this to isolate the problem and finally found the culprit. It turned out to be a file masquerading as REGSVR running out of C:\windows. When I kill this process I can re-open the registry editor and from there open up the task manager. Now the problem is, this file keeps running every time I restart windows. I've tried every trick I can think off to stop it but I can't seem to get anything to work. Its not listed under msconfig's startup. Its not listed in the Registry editor under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run or any of the users. My attempts at deleting the file or corrupting it don't seem to be doing any good, everytime I restart the PC this malicious file reappears and runs itself, shutting down the registry and task manager. Its not being picked up by updated spyware or antivirus scans (different programs) and there is little left I haven't tried. Any ideas how to get rid of it ? |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Read and run first - Malware section
http://forums.majorgeeks.com/showthread.php?t=35407 |
|
#3
|
|||
|
|||
|
thats wierd, I remember replying some time earlier. Looks like my post didn't get posted. Anyways, I didn't exactly follow this list but I ran my own comparable set of diagnostics with several of the same applications and I couldn't find anything funny, ALL start up keys have no Regsvr.exe in them or anything else out of the ordinary. I've exhausted all the tests I can think off, perhaps you have some specific test in mind ?
|
|
#4
|
||||
|
||||
|
There was a system glitch on Sunday so posts that day got deleted ....so to carry on ...try this:
To reinstall the Microsoft Task Manager: NOTE: You must be logged on as Administrator or as a member of the Administrators group in order to perform this procedure. 1. Click Start , click Run , and then type the following command: %systemroot%\inf NOTE : There are no spaces at all in the preceding command line. 2. Click OK to open the INF folder. 3. Locate the file mstask.inf Right-click the file, and then click Install . This will reinstall the files that Search needs to proceed normally. You will be asked to place your windows XP cd rom in the drive. |
|
#5
|
||||
|
||||
|
Are we certain that a computer administrator hasn't applied group policies to restrict access to the task manager? This is the ONLY time I've seen the symptoms you describe.
Is this computer part of a domain? If so, it may have inherited this restriction from the domain controller. You'll have to talk to the network administrator if this is the case. Otherwise, it should be a policy defined on the local computer. Here's how we can check: 1. Hit windows key + r (or click Start --> Run) 2. Type 'gpedit.msc' (without the quotes) 3. Hit enter (or click 'OK') The group policy editor will now launch. I'm willing to bet that there is a setting in here (ie, "Restrict Access to Task Manager") that has been enabled. Even better, please see this link on how to enable/disable task manager
__________________
A+, Project+ Certified Network Engineering Grad 5 years Sys Admin exp. 11 years web dev exp. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
regsvr
regsvr.exe Added by the WEBMONEY-G TROJAN! . Would suggest a bitscan. |
|
#7
|
||||
|
||||
|
Boot in safe mode. Run regedit. Navigate to HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System and look for DisableTaskMgr in the right-hand pane. It's probably set to a value of 1, and it should be set to 0 (zero). Right click on it, choose the appropriate option to change the value to 0, and exit regedit and reboot.
hopperdave2000 |
|
#8
|
|||
|
|||
|
I had this problem a while back and tried all of the things suggested here and more with no luck. System restore was the only thing that fixed it for me after cleaning out the trojan.
|
|
#9
|
|||
|
|||
|
I'm the system administrator and I didn't disable the task manager.
Quote:
Booting in safe mode or killing regsvr.exe to open the registry works and indeed the task manager is disabled in the registry, after fixing it and rebooting, my changes are apparently undone. Regsvr.exe runs again on startup and I'm assuming it shuts down regedit and the task manager as well. I've ran several anti-(you name it) programs and they all came out blank. I suppose I'll try bitscan as well but I doubt it'll catch anything. Also, I had system restore disabled so I can't restore to anything prior to the problem (which has existed for quite some time anyways) |
|
#10
|
||||
|
||||
|
Try regedit in safe mode or try a 3rd party regedit. Several good free ones are available right here at majorgeeks...
hopperdave2000 ![]() |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Quote:
|
|
#12
|
|||
|
|||
|
Quote:
Looks like I might have to reinstall, which is a very drastic measure but I seem to have run out of options here |
|
#13
|
||||
|
||||
|
Ever run the bitscan?
|
|
#14
|
|||
|
|||
|
Quote:
|
|
#15
|
||||
|
||||
|
Now do the read and run first sticky in the malware section ....
![]() |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|