1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Disabled regedit and Task Manager, Pc incredibly slow, Popups at increasing

Discussion in 'Malware and Virus Removal Archive' started by Tank, 2008/08/05.

  1. 2008/08/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Good. Suggests maybe the reg file just isn't quite right, but no matter. Can you do this manually? In the registry editor, navigate to and select the following key in the left pane using the + signs.

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults

    In the right pane, you will see entries with each of the following names.

    http
    https
    ftp
    file
    @ivt
    shell


    Verify first that each one is of the Type REG_DWORD
    If not, stop and post back, else continue.
    Double click each entry and change the value accordingly by typing only the number and clicking OK.

    http = 3
    https = 3
    ftp = 3
    file = 3
    @ivt = 1
    shell = 0

    Now navigate to the following key and repeat.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults

    The values of 1 of those keys might already have those settings, which is OK. They both need to have the same.

    Restart when done and see if you can download.
     
  2. 2008/08/11
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    Hello Geri,

    There is no Internet Settings key in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion

    However there is the full path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults

    And the key values in Protocol Defaults are the ones you indicate.

    Thanks,
    tank
     

  3. to hide this advert.

  4. 2008/08/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please scan again with HijackThis and post the log.
     
  5. 2008/08/11
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    Here it is, and sorry I've been calling you Geri.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:18:36 PM, on 8/11/2008
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINNT2\System32\smss.exe
    C:\WINNT2\system32\winlogon.exe
    C:\WINNT2\system32\services.exe
    C:\WINNT2\system32\lsass.exe
    C:\WINNT2\system32\svchost.exe
    C:\WINNT2\system32\spoolsv.exe
    C:\WINNT2\system32\cisvc.exe
    C:\WINNT2\system32\svchost.exe
    C:\WINNT2\System32\WBEM\WinMgmt.exe
    C:\WINNT2\system32\svchost.exe
    C:\WINNT2\Explorer.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINNT2\regedit.exe
    C:\Documents and Settings\Tank\Desktop\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT2\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT2\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT2\web\related.htm
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
    O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
    O16 - DPF: {43F25BA2-C4AB-4327-924C-1ED6AF4A6BA1} - https://www.mywebcalls.com/activePhone.ocx
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1216476783584
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT2\System32\dmadmin.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: PsExec (PSEXESVC) - Sysinternals - C:\WINNT2\PSEXESVC.EXE

    --
    End of file - 2830 bytes
     
  6. 2008/08/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    No problem RE: name calling :D

    Go back to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
    Right click the CurrentVersion key and select Permissions
    If you get a message about insufficient permissions and the permissions window does not open after clicking OK, repeat and it should open.
    Once in the Permissions dialog, click Advanced
    Select the Owner tab
    Make sure Administrators is selected (click to select) in the list, check the box to Replace owner on subcontainers and objects then click Apply
    Now click OK
    Back on the Permissions dialog, verify that System and Administrators are in the list. If either is missing, add them as follows.

    Click Add
    Type System then click Check Names (adjust for Administrators if needed)
    The window should populate with System or yourcomputername\Administrators
    Click OK
    On the Permissions dialog, with System (or Administrators) selected, the lower pane should have the Full Control box checked in the Allow column.

    Once you have completed the above, click OK to exit the Permissions dialog.
    Press F5 or click View>Refresh on the menu.

    Let me know if you now see the Internet Settings subkey.
     
  7. 2008/08/11
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    When I right-click on the key I get the menu:

    Collapse
    New
    Find...
    Delete
    Rename
    Copy Key Name

    No "Permissions" option

    I bellieve I'm logged in as Administrator as, when I installed win2k, I was asked for a User Name and password for the Administrator account and that's what appears in the login window every time I start windows.
     
  8. 2008/08/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hmmm, Export and Permissions should fall between Rename and Copy Key Name.

    Close the registry editor
    Click Start>Run and type regedt32 then hit Enter
    The registry editor should open
    See if you have the Permissions option
     
  9. 2008/08/12
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    Yep! Regedt32 does give the option. Should I carry through the procedure in Regedt32?
     
  10. 2008/08/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yes. There should be an Internet Settings subkey, and I'm hoping it's just a permissions problem, rather than missing keys. ;)
     
  11. 2008/08/12
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    When I click "Apply" I get a popup:

    Security Unable to set new Owner on HKEY_CURRENT_USER.
    Access is Denied
     
  12. 2008/08/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Make sure you first click on the CurrentVersion key to select it, then right click on it and select Permissions
     
  13. 2008/08/12
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    Right-clicking does not produce a menu. I had to click on "Security" from the toolbar with the HKEY_CURRENT_USER window active and then I got a menu with "Permissions" as an option. from then on I proceeded as instructed and okayed the popup. I went on, and now I get "Internet Settings" showing but no "ZoneMap" in Internet Settings.
     
  14. 2008/08/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Well, the particulars of navigation are a bit different in 2000 than XP. Sorry. Great job on working through it though! This is progress!! :)
    An odd quirk when applying permissions to include subcontainers and objects is that each time you do it, it only goes one tier deep. You will often get a message that the permissions could not be applied to the key or some subkeys, and the 1 tier thing is what that message is referring to. What you have to do now is repeat the procedure for ownership, making sure to check the box to include subcontainers. You can either continue working from the CurrentVersion key (recommended) or move to the Internet Settings key and repeat as necessary until you no longer get the message when applying the ownership. If continuing from the CurrentVersion key, you could be there considerably longer than if you move to the Internet Settings key. I have no way of knowing how many subkeys are affected by the permissions problem.
     
  15. 2008/08/12
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    Ok. I went through the procedure in CurrentVersion and got no popup but ZoneMap did not appear. I was going through the procedure in Internet Settings when I noticed that in the Permissions window I see Administrator and System but in the Owner window there's Administrator and Tank which is apparently another account? Should I add Tank to the Permissions window? or should I just select Administrator and proceed?
     
  16. 2008/08/12
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    Tank is actually the User Name I entered when asked for the Adminitrator account User Name during install of win2k.
     
  17. 2008/08/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Is there not Administrators? Since you are logged onto Tank, if no Administrators then yes, add Tank with Full Control.

    Administrators represents a user group, which both the Administrator and the Tank account would belong to.
     
  18. 2008/08/12
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    Owner window shows Administrators, Tank (No System).
    Permissions window shows Administrators, System (No Tank)

    Add Tank(my current login) to Permissions?

    by the way there was no Tank anywhere in the CurrentVersion Permissions or Owner windows.
     
  19. 2008/08/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Administrators, on owner.
    Both Administrators and System on Permissions
     
  20. 2008/08/12
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    "Administrators" already appears on both windows. I went through procedure in "Internet Settings" but ZoneMap did not show up.
     
  21. 2008/08/12
    Tank

    Tank Inactive Thread Starter

    Joined:
    2008/08/04
    Messages:
    50
    Likes Received:
    0
    Also, over here in Brazil its 3:58AM and I'm getting a bit groggy. So thanks for the help, I'll continue tomorrow.
    Thanks again,
    Tank
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.