Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Regedit Was Disabled


  • Please log in to reply
4 replies to this topic

#1 keepoo

keepoo

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:16 AM

Posted 10 January 2006 - 01:28 AM

My computer had been infected by Brontok.C worm recently.. and i found out that it disable my regedit by saying "Registry editing has been disabled by your administrator" .. how can i enable it back? as i want to restore my Folder Option under Tools because the #@X! worm had also made it dissappear! help me..



keepoo

BC AdBot (Login to Remove)

 


#2 *Desdinova*

*Desdinova*

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Local time:01:16 PM

Posted 10 January 2006 - 03:24 AM

Hi keepo,


The restrictions (and who knows some infected items too, the worm is possibly still active) might be visible in a HJT logfile, so an expert can help you out with that
First read this topic and follow all instructions
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/
Then, post the logfile here, please
http://www.bleepingcomputer.com/forums/f/22/virus-trojan-spyware-and-malware-removal-logs/
and mention the problems you experience


Good luck :thumbsup:

#3 stidyup

stidyup

  • Members
  • 641 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:16 AM

Posted 10 January 2006 - 03:24 AM

Freeware Regedits Replacements

How to re-enable Regedit1

How to re-enable Regedit2

However if your still infected non of this is likely to work you need to do the following, submit a hijackthis log to the HJT Forum.

How to submit a hijackthis log

Download Hijackthis

Try running the following from safe mode (Getting to safe-mode) Sysclean you'll also need the virus template file from here lpt***.zip remember to extract the contents of the zip file into the same folder as Sysclean.com

or

DrWeb CureIT

or

KASFX which is powered by the Kaspersky AV engine, you will need internet access to update it. If you haven't got net access in safe mode, update it before you use it.

If your good with the command line also try Sophos Command Line scanner this command will scan all of your hdd's SAV32CLI.EXE -F -di -remove -dn -mbr -all -zip -p=avscanlog.txt and give you a log file to review afterwards.

Also try installing and running A2 Free and Ewido again run from safe mode.

I'd also run Spybot(Spybot Tutorial) and Adaware

If your using Win2K/XP run adaware/spybot from "safe mode with command prompt" If your using Win9x just run it from safe mode the command line options aren't needed..

At the C:\ prompt type the following:-

cd\
C:\progra~1\spybot~1\spybotsd.exe /autocheck /autofix
cd\
C:\progra~1\lavasoft\ad-awa~1\ad-aware.exe

#4 keepoo

keepoo
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:16 AM

Posted 16 January 2006 - 10:43 PM

Hi keepo,


The restrictions (and who knows some infected items too, the worm is possibly still active) might be visible in a HJT logfile, so an expert can help you out with that
First read this topic and follow all instructions
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/
Then, post the logfile here, please
http://www.bleepingcomputer.com/forums/f/22/virus-trojan-spyware-and-malware-removal-logs/
and mention the problems you experience


Good luck :thumbsup:




Hey...THANX...my problem solved at last!! I really appreciate your help...thanx again

#5 keepoo

keepoo
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:16 AM

Posted 16 January 2006 - 10:46 PM

Freeware Regedits Replacements

How to re-enable Regedit1

How to re-enable Regedit2

However if your still infected non of this is likely to work you need to do the following, submit a hijackthis log to the HJT Forum.

How to submit a hijackthis log

Download Hijackthis

Try running the following from safe mode (Getting to safe-mode) Sysclean you'll also need the virus template file from here lpt***.zip remember to extract the contents of the zip file into the same folder as Sysclean.com

or

DrWeb CureIT

or

KASFX which is powered by the Kaspersky AV engine, you will need internet access to update it. If you haven't got net access in safe mode, update it before you use it.

If your good with the command line also try Sophos Command Line scanner this command will scan all of your hdd's SAV32CLI.EXE -F -di -remove -dn -mbr -all -zip -p=avscanlog.txt and give you a log file to review afterwards.

Also try installing and running A2 Free and Ewido again run from safe mode.

I'd also run Spybot(Spybot Tutorial) and Adaware

If your using Win2K/XP run adaware/spybot from "safe mode with command prompt" If your using Win9x just run it from safe mode the command line options aren't needed..

At the C:\ prompt type the following:-

cd\
C:\progra~1\spybot~1\spybotsd.exe /autocheck /autofix
cd\
C:\progra~1\lavasoft\ad-awa~1\ad-aware.exe



Thanx man! Thanx for helping me... i finally get my my folder option back..actually the worm leaved someting before it gone....so i got rid of it and i learned a lot..thanx...see ya




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users