Re: Help, possible virus disabled taskmanager and regedit on server.
- From: "Merv Porter [SBS-MVP]" <mwport@xxxxxxxxxxxxxxxxxxx>
- Date: Thu, 18 Dec 2008 08:28:27 -0500
The following may get you past the disabled Task Manager (you may need to
create the DisableTaskMgr key) and Regedit isuues, but your systems have
been compromised. Best practice is generally to do a wipe and restore from
backup.
TUTORIAL: Task Manager, Regedit, etc won't open (Part 1)
http://www.ozzu.com/windows-tutorials/tutorial-task-manager-regedit-etc-won-open-part-t44857.html
-----------------------------------------
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\
System]
Value Name: DisableTaskMgr
Data Type: REG_DWORD (DWORD Value)
Value Data: (0 = default, 1 = disable Task Manager)
If the value is set to 1 Task Manager will be disabled. By returning it to
it's default value of 0 it can be re-enabled (although doesn't "fix" the
root cause, i.e. trojan removal). If regedit is also not working, you can
make a copy of regedit.exe and rename the copy regedit.com and at a run
command prompt you can type in regedit.com instead of plain old regedit and
it should work.
-----------------------------------------
--
Merv Porter [SBS-MVP]
============================
"David" <david@xxxxxxxxxx> wrote in message
news:aMq2l.27034$Iz4.3007@xxxxxxxxxxxxxxxx
Hi All
Fairly new to SBS 2003.I have my server set up to download latest MS
patches automatically. I run AVG virus scanner, ISA2004 is running.
Trouble is I think a virus has got in from somewhere. It has disabled task
mananger and regedit on the server and has done the same for all clients.
( I can't re-enable task manager using gpedit.msc either).
Virus scans of hard disks dont pick anything up. Everything is running
fairlly normally apart from this. Any help that doesn't involve a
reinstall appreciated or its going to be a sleepless Christmass!)
Cheers, David (UK)
.
- Follow-Ups:
- Re: Help, possible virus disabled taskmanager and regedit on server.
- From: David
- Re: Help, possible virus disabled taskmanager and regedit on server.
- From: Jim Behning SBS MVP
- Re: Help, possible virus disabled taskmanager and regedit on server.
- References:
- Prev by Date: RE: Email Issue
- Next by Date: Re: OT: all systems on network slow for last week or so
- Previous by thread: Re: Help, possible virus disabled taskmanager and regedit on server.
- Next by thread: Re: Help, possible virus disabled taskmanager and regedit on server.
- Index(es):
Relevant Pages
|