Reply
Contributor
bghanson
Posts: 18
Registered: ‎01-22-2009

Group Policy, Regedit, & System Restor Disablede

I have your Norton 360 installed on my home system and need some help. I renewed my subscription and have updated a the software via the software itself. I also have SpyBot, AD-Aware, & Malwarebytes' Anti-Malware. Last week my wife click on a pop up saying we were infected with spy ware and in doing so installed “AntiMalware Doctor” I think I have manually removed the malware but I am still having some problems left behind by it in the register. It changed the register via Group Policies to disable running: Regitedit ( I have another one that works); Task manager; any of the Anti Virus/Spyware; (when I re-enable Task Manager it show them running but I see no window/display of them running); System Restore; & GPEdit. It has also stopped me from reinstalling any anti-Virus Software. It says they have all been disabled by Group polices by the Administrator. I am the Administrator of this computer and it is not assigned to a domain it is in the default Workgroup. I am running XP Pro Service Pack 3 I also seem to be re running part of itself that edits the register and changes the setting back to disable on reboot.
Volunteer
yogesh_mohan
Posts: 5,302
Registered: ‎07-29-2008

Re: Group Policy, Regedit, & System Restor Disablede

You can use the UnHookExec.inf file from Symantec to enable the registry editor:

http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99


After that, restart your computer to Safe Mode and run scan using any of the security programs in your computer.


Yogesh

Contributor
bghanson
Posts: 18
Registered: ‎01-22-2009

Re: Group Policy, Regedit, & System Restor Disablede

What ever this Malware is it also disabled Safe mode.  I found a Regeditor that allows me to edit it.  So now I need to know which bits to change to reinable System Restore & Safe Mode.  I was able to reinable Task Manager.

Bot Obliterator
Quads
Posts: 13,252
Registered: ‎07-21-2008

Re: Group Policy, Regedit, & System Restore Disabled

Hi

 

Yogesh is probably trying to work out what is happening, and will be with you once he has figured it out.

 

Quads

Volunteer
yogesh_mohan
Posts: 5,302
Registered: ‎07-29-2008

Re: Group Policy, Regedit, & System Restor Disablede

[ Edited ]

Hi bghanson,


I am not sure about re-enabling the Safe Mode, but you can try to reenable the System Restore using the registry editor. Here are the steps:

1. Navigate to the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore and verify that the key on right DisableSR has a value of 0.
2. If DisableSR is set to 1, change it to 0.
3. If the key is not there, then create one DWORD value with the name DisableSR and give it a value 0.


Do not know why Quads has assured you that I will come up with a solution, may be he got some kind of  6th sense about me. But, I have not limited anyone from posting here, anyone with a good solution can post in this thread and help bghanson.


Yogesh

floplot
Posts: 9,952
Topics: 200
Kudos: 1,892
Solutions: 354
Registered: ‎04-11-2009

Re: Group Policy, Regedit, & System Restor Disablede

Hello bghanson

 

Please do the registry fix only if you are comfortable in doing things in the registry and also please back up your registry before you make any changes.  This is just basic before you do any changes to the registry, not meant to say that Yogesh is giving you bad instructions.

Success always occurs in private and failure in full view.




Contributor
bghanson
Posts: 18
Registered: ‎01-22-2009

Re: Group Policy, Regedit, & System Restor Disablede

I have done that but I know the back up is infected with what ever the Malware is.  I tried the regedits he suggested and it did reinable the SR but when I click on it it says to restart the system before it will protect my system.  When I do that I am back in the same boat.  Would it work if i took a copy of a reg. from a similar machine and inported it into mine. (same hardware but some different apps.)  then ran SR and restored to a date prior to my infection?  Also do you know which reg bit might have been changed to diable Symantec 360 from running?  Mayby if I cna reinable that and run it it will clear the Malware off my system so my regedits will stay..

Bot Obliterator
Quads
Posts: 13,252
Registered: ‎07-21-2008

Re: Group Policy, Regedit, & System Restore Disabled

[ Edited ]

Probably still infected with the Malware that when trying to enable things, The Malware fights back by just setting things like System Restore back to the way it want's there that means SR is disabled again, (and other settings) Restore Points are gone, or corrupt.

 

Safe Mode:  One of 2 things, Safe Mode is blocked, and anything else it wants, OR  Safe Mode has been removed.

 

Things have not been done in the usual correct order for Malware.  Try changing the PC settings while the infection is active and all you end up dong is going around in circles. You change something, Malware changes back....................................

 

Quads

Super Phishing Phryer
Turbo
Posts: 577
Registered: ‎05-02-2009

Re: Group Policy, Regedit, & System Restor Disablede

[ Edited ]

bghanson,

 

As Quads said you wont be able to make any progress while the malware is running, rkill is a small app. that can stop the running malware processes so that maybe you could then run MBAM. You mentioned in your first post that the name of the rogue is Antimalware Doctor. You can get removal instructions and download rkill here:  BleepingComputer

Contributor
bghanson
Posts: 18
Registered: ‎01-22-2009

Re: Group Policy, Regedit, & System Restor Disablede

I havecome to the same conclusion.  where or can I get a copy of rkill. I will give that a try.  Any thought on inporting a regester from a similar hardware computer?