hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Xp Probs
h4x0re
damit, does anyone here know how to enable the taskmanager?


it says it was disabled by the administrator but not me :S:S


any help please?


thanks in advance
tweakz20
http://www.windowsnetworking.com/kbase/Win...sXPHomePro.html
G-O-O-G-L-E
why's this in exploit research and discussion anyway?
h4x0re
it doesnt seem just to be tm. my regedit is disabled also. any help or clue? thanks
buzzons
yea you got a virus thats stoping u opening them

buz
h4x0re
QUOTE (buzzons @ May 17 2004, 09:29 PM)
yea you got a virus thats stoping u opening them

buz

dam, i just was thinkin some shit like that. well would u have any idea of wich one that effects u in this way? or a patch to prevenet? thanks
tweakz20
try this maybe... see if it will merge
CODE

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000
"DisableRegistryTools"=dword:00000000



and here's a link to a different program to edit your registry:
http://www.winguides.com/tweak/?isplugin
(it is trial ware, sorry, don't know any free ones.)
h4x0re
good lookin, adware removed the registry entry and my av did the job so im aight now.


h4x0re
(filtered), i reastarted now im really (filtered). i cant open anything i just get a missing error

i found lsass.exe in my c:\windows\fonts folder but i deleted it. can anyone please help me to remove?


im stilled (filtered) even though its not running
SkitZZ
what av are you running and did you update it ?

found this link on google might help you
http://www.mvps.org/sramesh2k/ToolsQuit.htm

and try this google search for more info wink.gif
http://www.google.com/search?hl=en&lr=&ie=...nnot+open+virus


SkitZZ
tweakz20
http://www.governmentsecurity.org/forum/in...&st=0&#entry734

check those places for suspecious programs/reg entries
h4x0re
i really dont know whats going on. im really fuxed. all my programs wont open gives a error saying they cant be found but thats bs
F34R
had a trojan disable my taskmgr before as well... its a massive pain in the ass... only fix was to create a new user account and do a virus scan.
krackatoa
Rebuild it from scratch
h4x0re
good thoughts, but i have to backup before i format sad.gif hey ole well, i removed the vir anyway and can only open my programs from dos ?!?! if i click on the exe it gives missing error


sad.gifsad.gif
ComSec
just to be safe...try this to check your system files...have your XP on hand if prompted.....if some of your files are corrupt this will replace them from the original disc.....then re-boot

from the run box type

sfc /scannow


but it sounds like you might have an infection virii or trojan

h4x0re
thanks ComSec, and to all who helped me

hopefully this thing will be removed soon


thanks again



h4x0re
CloudyOne
I actually got that before.

I do believe it was cause by one of those "ebacteria" you get off of emule.

it actually redirects your svchost.exe files to open using one that it creates itself, which then would normally call upon the real svchost.exe. Now if that file is to be deleted, i would then be unable to open any .exe files without dragging it to my dos prompt. So i put the file back (luckily it was in my recycle bin).

After you get the file put back into place, you should have no problems opening programs, however you still would have the virus on your computer.

It sucks because you can't do a sys restore, or regedit. OR delete the file. I put the file back so that i could open my cd burning programs without it erroring so that i could make backups of my files.

Then you would inevitable have to reformat.

After i reformatted was when i diagnosed what file it was that caused it.

I reformatted and promptly got all my security tools up. I zipped and then encrypted (using SecureIT) the exe files in the windows dir and the system32 dir, and i made a backup of my registry.

I then went through all the files in my emule folder, since those were the only files in question in my mind.

Coupled with Trojan Guarder Gold, Spysweeper, Hex Workshop, and Fearless Binded File Detector, i was able to narrow which files actually had "extra" data in them. Ironic enough, all of them were supposed key generators. So, being that my computer was still in good health, i made a restore point (not like it would help). I then opened the files until i found which one it was. I can't remember which one it was now but when i found it it did the same thing as before, and i compared the differences between my zipped backup of my windows exe's and was able to find the difference.

Now the smart thing i could have done here, was get one of those programs that password protect directories on your comp, so it would error when the file tries to copy/create itself there.

I also guess i could have created another user on the comp with limited access, so i could see what depenedcy files it springs, without it able to change any critical files due to limited access. But i guess i know now for next time.
Killaloop
I got one of the blaster variants back that days.
It caused all that stuff (no regedit, firewall closed, AV closed, tm closed, diskdrive didn't work....more of this).
if nothing works out install windows on another drive and start a complete viri ,trojan and spyware scan on your other windows installation.
if everything seems fine try a repai installation on this windows installation.
was the only way to rescue that windows installation back that days
manu
Time to switch LINUX..

Manu biggrin.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.