can't get rid of "DisableRegedit"

Discussion in 'Malware Help (A Specialist Will Reply)' started by sfairbanks, Apr 8, 2006.

  1. sfairbanks

    sfairbanks Private E-2

    Hi
    This is my first post and excuse me if I do something wrong. I ran the recommended procedures, but after trying to get rid of this rotten registry setting, it still comes back everytime I restart. I'm posting my Hijackthis log in hopes that I do it right the first time.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have not completed ALL the steps in the READ & RUN ME sticky thread.

    Settings like you are mentioning are often just configure by software that you are using to block various malware. Check your settings. Otherwise complete ALL steps in the READ & RUN ME and attach the logs like it requests.
     
  3. sfairbanks

    sfairbanks Private E-2

    I tried every step again, I believe this is what your looking for. Please let me know what I've missed, thanks for your help.

    Shelley
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You skipped part of step 0 in the read where it talks about emptying quarantine folders. You did not empty the below:

    C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine

    Panda only shows the above and some cookies for multiple user accounts. Bitdefender fixed what it found.

    Did someone actually install AdwareAlert is it just the trial version? This used to be considered a rogue tool and I'm not sure it is of much value to have on your PC wasting resources. If it is a trial version, you should definitely uninstall it.

    Who's PC is this? I see multiple user accounts!
    And who is the administrator and owner?

    Please run the below tool which run very quickly and attach the runkeys.txt log.

    Using GetRunKey
     
  5. sfairbanks

    sfairbanks Private E-2

    OK, I here are some answers and more questions;

    1. I removed the items in the Quarentine folder.
    2. I am the admin/owner (Shelley). This is a home notebook computer and the other users are my kids (Lance 13, Mallory 10) and my husband Pete whose never touched the PC. Lance is the most active user, he mostly downloads music and surfs the web.

    3. AdwareAlert... How do I uninstall it? It doesn't show up in Add/Remove Programs or my All Programs list.

    4. GetRunKey.bat... I ran it and everytime it tries to access/edit the registry I get the error msg "Registry Editing has been Disabled by your administrator".. I get the same message when I try to fix items in HijackThis.

    This is the hack that I've been using to get to the registry, at the Run prompt I type...

    "REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f"

    Thats the only way I've found to get to or edit any registry settings right now.

    So only after doing that I can deliver you with the GetRunKey.txt you asked for.

    Shelley

    Shelley
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do the below (use your hack first if necessary).

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot! After reboot, delete the below folder:
    C:\Program Files\AdwareAlert

    Now tell me if you are still having problems.
     
  7. sfairbanks

    sfairbanks Private E-2

    I ran these steps and I still get the problem. It seems like some startup program continues to set the DisableRegistryTools and DisableTaskManager keys to 1.

    If I reboot in Safe Mode, I don't have the problem. Any other ideas are appreciated.

    Shelley
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have this installed: http://www.authentium.com/products/curtains.htm

    Perhaps you need to check how it is configured. Maybe it is locking this setting.



    Let's get a Startup List with HijackThis.
    • Run HijackThis, click Open the Misc Tools section
    • Put a check in the List also minor sections (full) check box.
    • Now click the Generate StartupList Log button.
    • This will create a file named startuplist.txt in the same folder that HijackThis is installed into.
    • Also a notepad file will open with this startuplist in it.
    • Attach the startuplist.txt file to your next message.
    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  9. sfairbanks

    sfairbanks Private E-2

    Here you go...

    I believe http://www.authentuim.com/products/curtains.htm is part of the Cox Security Suite. These are what this PC is using for Firewall, AntiVirus, popup-blocking and Parental Controls. It came free with our DSL and I thought I would try it. Any suggestions on whether this a good choice or not? I could not find any settings that would be causing this problem.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know what it is! I was just wondering if something related to it could be causing this locking of of the registry. You said you have no problem in safe mode. Does this software run in safe mode? Are you logging into the same user account in safe mode?

    Maybe you should try uninstalling this software to see what happens. Right now your problems do not appear to be malware related.



    Below are a couple comments having nothing to do with your problems. They are just a heads up:

    You have old versions of the below two programs installed. Get the new versions from the given links:
    BitComet 0.59 ----> BitComet 0.64Mozilla Firefox (1.5) ----> Mozilla Firefox 1.5.0.2


    Also the below should be uninstalled since you already have the current 5.0 Update 6 installed.
    J2SE Runtime Environment 5.0 Update 3
     
    Last edited: Apr 14, 2006
  11. sfairbanks

    sfairbanks Private E-2

    Thanks for your help. I followed your suggestions and uninstalled the Cox Internet Secutiry Suite. Only after I shutdown the computer then restarted it did the problem finally go away. (just a restart didn't do the trick).

    I called Cox tech support and got little help, but we concluded that the problem arose when I set the parental controls. They seemed to recall a similar case, so you can let others know if this should come up again.

    Shelley
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I knew it had to be behind your problem! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds