Virus Problem
Created: 10 Aug 2012 | Updated: 24 Oct 2012 | 7 comments
This issue has been solved. See solution.
Hi Guys,
Some viruses are attacked on network & we cleaned that but the problem is virus disabled the task manager & regedit.
Discussion Filed Under:
Comments 7 Comments • Jump to latest comment
Is your system infected? Symantec tools to help clear an infection
https://www-secure.symantec.com/connect/forums/your-system-infected-symantec-tools-help-clear-infection
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hello,
Try Unhookexec.inf, which may help, check this link below:
http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99
You could also perform the changes on the GPO, which may assist with the same. ( I would recommend you to create a case with Microsoft).
Secondly, There are many tools to fix this however the cause for this issue a Malware that is blocking all these. So make sure you update your SEP client with latest definitions and run full scan in safe mode.
OR scan using Symantec Power Eraser.
However you should also submit the suspicious files to symantec security response so that they can create defs. that will catch these threats.
Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.
Here's a good tool -
https://www-secure.symantec.com/connect/downloads/simple-utility-reset-folder-options-show-all-hidden-enable-registry-editing-enable-task-ma
NOTE: This tool is not provided neither supported by Symantec.
Hope that helps!!
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3
Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a
What was the infection name which had occured ?
Check thread below there are many tools from Symantec which can be used to restore access to registry , taskmgr etc , however it truly depends on what kind of infection was it
You may like to try tools below on some Client machines first might help
https://www-secure.symantec.com/connect/forums/cannot-access-regedit-task-manager-and-msconfig
Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.
Swapnil
Hi Sonday,
Please download this file unhookexec.inf and run infected system.
http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99
You'll need to clear back the registry entries... are you managed to get the threat/virus name?
You may try ctrl-alt-del and use the function "run" .....from here try run your regedit...
Download regalyzer:
http://www.safer-networking.org/dl/products/regaly...
Restore Task Manager:
http://ask-leo.com/why_is_my_task_manager_disabled...
SEP Knowledge Base
Endpoint SWAT
Good morning,
Use the tool Re-Enable 2.0
And to scan your PC, use the scan in safe mode, I am amazed how people do not warn about it.
hugs
Fabiano Pessoa
Systems Analyst - Forensic Expert
Would you like to reply?
Login or Register to post your comment.