Question

No safe mode, disabled regedit, disabled task manager, gpedit does not have entries needed to fix

Asked by: skitterling

have a dell latitude d810 with XP sp3.  seem to have a virus which has disabled regedit and task manager.  can't boot into safe mode - get a blue screen stop error 0x0000007B which says may have a virus.  when I go to gpedit.msc to re-enable regedit and task manager, under user config:administrative templates:there is only windows components.  it does not show system options.

ran malwarebytes anti-malware - found Backdoor.Bot, quarantined and deleted successfully

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-03-19 at 10:58:59ID24246711
Tags

safe mode

,

regedit

,

task manager

,

gpedit

,

virus

Topic

Anti-Virus

Participating Experts
4
Points
0
Comments
25

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. regedit vs gpedit
    I recently came across a new (to me anyway) command called group policy in a windows xp tips page (http://tipsdr.com). It appears that this can only be run from Windows XP Professional and seems to be a very powerful editing tool - probably more user friendly than regedit as ...
  2. gpedit.msc
    I have been reading that XP only allows 20% of my bandwidth by default. I also read that this is bs. However, I cannot open gpedit to find out. Start->Run->gpedit.msc doesnt work. I also read it can be located in windows->system32, but I couldnt find gpedit. Where is...
  3. gpedit & user access & domains.
    hi ...ok Setup= server 2003, exchange 2003, clients XP pro(40 no) all users need rights to do what they like on there machine (ie install printers, install software), yes i know, i have good users and we only clamp down on naughty people. I setup each XP Pro's "local u...
  4. GPedit.msc settings backup/restore
    As i am maintaining almost all pc's and laptops in my family, and am using the GPedit.msc console to change a whole lot of settings. The thing is, i'm getting a bit tired of going thru the whole list of settings on every pc. Is there a way to backup/restore of export/import ...
  5. gpedit and cmd disabled
    I have a XP pro sp2 PC which has CMD, regedit, and gpedit disabled. That is to say, when I try to start them I get a message sayign that they have been disabled by the system adminstrator. The PC is standalone, bought new so has not been on a domain as far as the user can sa...
  6. Disabled taskmgr, regedit, IE, spybotsd, malware
    Have an XP Pro SP3 with malware. It has disabled taskmgr, regedit, IE, spybotsd at least. Malwarebytes removed four items (trojans and downloaders). GPedit will run, but changes to Ctrl-alt-del; and disable regedit will not stick. Common tricks to run Reg delete as a vbs ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: epochassetPosted on 2009-03-19 at 11:04:34ID: 23932308

Did you try booting with last-known good config option on the bootup F8 menu?

 

by: skitterlingPosted on 2009-03-19 at 11:06:06ID: 23932321

Yes.  It did not make a difference.

 

by: epochassetPosted on 2009-03-19 at 11:08:41ID: 23932355

Try resetting local group policy to defaults.  This procedure should work, http://escapelogic.com/main/node/2.

 

by: DetoxicatedPosted on 2009-03-19 at 11:22:26ID: 23932488

First of all, check the filtering options in Group Policy - Administrative Templates (Right Click - View - Filtering - Make sure that nothing is filtered).

If this is not the case, do the following:
1. Right click Administrative Templates under User Configuration
2. Choose Add/Remove Templates
3. Click the button that says "Add"
4. If the window does not already take you there, browse to %windir%\inf\ (ie. c:\windows\inf\)
5. Choose the system.adm template
6. Click the button that says "Close"

 

by: epochassetPosted on 2009-03-19 at 11:25:50ID: 23932521

Also another solution to resetting group policy is to simply delete the %Systemroot%\System32\GroupPolicy folder and reboot.  See http://www.experts-exchange.com/Security/Operating_Systems_Security/Windows/Q_21988937.html.

 

by: skitterlingPosted on 2009-03-19 at 11:29:05ID: 23932541

tried resetting group policy to default - made no difference.  I'll try to delete the folder.  I'll also check filtering options in group policy to see if that's set.

 

by: skitterlingPosted on 2009-03-19 at 11:39:26ID: 23932636

okay, enabled system.adm and made sure regedit setting were okay.  rebooted.  still no joy - everything's still disabled.

 

by: skitterlingPosted on 2009-03-19 at 11:40:38ID: 23932651

epochasset - there is no grouppolicy folder to delete in that location.

 

by: DezzyMelbPosted on 2009-03-19 at 13:09:40ID: 23933564

Try making a backup of the profile that is affected by logging in as another user (You may need to reboot) and renaming that users profile folder located in %Systemroot%\documents and settings\. By doing this the next time you log onto the computer you computer will start a fresh profile. All you need to do from there is copy your fav's documents desktop and any other items you have in your old profile to the new one.

Be sure to virus scan your old profile items prior to copying them back to the new one.

One example would be if you normally logged in as skitterling with luck there will be a folder in %systemroot%\documents and settings called skitterling all you need to do is log in as an admin and rename this folder to skitterling.old. With any luck When you next log in as skitterling your profile and settings will be set back to default. all you need to do then is copy your desktop fav's and documents from the skitterling.old folder to the new skitterling folder.

 

by: DezzyMelbPosted on 2009-03-19 at 13:10:59ID: 23933577

Don't forget you will need to setup any mail clients and other specialised software IE MSN and outlook.

 

by: skitterlingPosted on 2009-03-19 at 13:13:01ID: 23933608

thanks DezzyMelb, but this problem is present on all profiles on this laptop.

 

by: DezzyMelbPosted on 2009-03-19 at 13:19:21ID: 23933697

Have your attempted to delete the Default or all users profiles?

 

by: skitterlingPosted on 2009-03-19 at 13:22:25ID: 23933735

DezzyMelb, I have to admit, I don't see what profiles have to do with most likely having a boot sector virus.  Can you explain?

 

by: DezzyMelbPosted on 2009-03-19 at 13:35:25ID: 23933879

I was under the assumption that because you could access the computer you have already repaired the Boot sector issue and was attempting to restore access to your registry and group policy to remove the windows side of the virus?

Is this not the case?

 

by: skitterlingPosted on 2009-03-19 at 13:47:34ID: 23934018

Not the case.  I can't seem to get rid of the virus.  I can access the computer as normal except in Safe Mode.  While in XP however, regedit and task manager are disabled and I have not been able to get them re-enabled.  Without those tools, I have not been able to find the virus to get rid of it.

 

by: skitterlingPosted on 2009-03-19 at 13:54:16ID: 23934105

hey all, I'm going offline, I'll be back at this at 8:30am EST.  I will gladly try any suggestions I find when I get back.  Thanks in advance!

 

by: DetoxicatedPosted on 2009-03-19 at 15:17:56ID: 23934866

You can use Panda Active Scan to detect what kind of "malicious software" you are dealing with: http://www.activescan.com. It is one of the best free tools out there so if I were you I would try a complete system scan.

 

by: skitterlingPosted on 2009-03-20 at 05:21:29ID: 23938616

back online!

Thanks Detoxicated, I'll try that now.

 

by: skitterlingPosted on 2009-03-20 at 06:39:51ID: 23939173

Panda Active Scan won't update and, therefore, won't scan.  Sigh...

Any other suggestions, anyone?

 

by: DetoxicatedPosted on 2009-03-20 at 07:02:51ID: 23939347

What do you mean by "won't update"? Do you get an error message? I have just run a full system scan in my machine and worked perfectly...

If you want to "cure" your machine, the first thing that you need to do is use the best antivirus software out there.

I would definitely recommend Panda Active Scan since it's free (at least for viruses, worms and Trojans) and has minimum installation needs.

 

by: skitterlingPosted on 2009-03-20 at 08:16:32ID: 23940145

No error message.  I downloaded and installed the piece Active Scan wants you to, then it goes to the screen that says it is updating, but nothing updated or happened for over an hour.

 

by: epochassetPosted on 2009-03-20 at 09:33:33ID: 23941059

Download a program called security task manager here, http://www.neuber.com/taskmanager/index.html.  When running it your looking for anything with very high ratings, meaning they are suspect as being malicious.  Look for anything in the high ratings that is not something you would expect to be installed.  If anything sticks out see if its corresponding file is present on the filesystem.  With most viruses you wont be able to find the file as its being hidden, but you can kill it from within security task manager then try and rename the file via a command prompt.  Once killing everything try running virus scanner updates, etc again, and if you are able to rename (to keep from loading) anything malicious you may be able to boot without the affective issue.

 

by: epochassetPosted on 2009-03-20 at 09:38:50ID: 23941118

For example, not more than a week ago I had a workstation which after a few minutes post bootup it would stop wanting to load any new programs.  Security task manager showed a DLL running in System32 which I could not find (was running in kernel mode).  I was able to kill it with security task manager and then rename the dll from a prompt (if you cant see the file it doesnt mean you cant do stuff to it from a prompt).  After rebooting it did not load again, and the workstation hasn't had an issue since.

 

by: warturtlePosted on 2009-03-21 at 13:18:19ID: 23948676

Hmmm.. I have read all the comments and would suggest you to download ComboFix and save it with a different name like CoF.exe or something different from the actual filename. Then disable your antivirus and firewall and run it. Do not use mouse or keyboard while its running though. The virus that you might have in your system might prevent the installation of antiviruses if it can recognise the name, so best to rename all scanners and use.

Secondly, download SuperAntiSpyware, update it and do a scan. Don't forget to change the name after downloading though.

Thirdly, you can send us a HijackThis log after doing the scans, that will help us see what is still left on your system.

Hope it helps.

 

by: skitterlingPosted on 2009-03-24 at 09:56:05ID: 23970517

well, nothing worked - ended up reformatting the drive and re-installing OS and programs.  thank you, back up policy!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...