Video Screencast Help
Search Video Help Close Back
to help

Virus Problem

Created: 10 Aug 2012 | Updated: 24 Oct 2012 | 7 comments
Sonday's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Hi Guys,

Some viruses are attacked on network & we cleaned that but the problem is virus disabled the task manager & regedit.

Comments 7 CommentsJump to latest comment

Ashish-Sharma's picture

Is your system infected? Symantec tools to help clear an infection

https://www-secure.symantec.com/connect/forums/your-system-infected-symantec-tools-help-clear-infection

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

0
Login to vote
  • Actions
Mithun Sanghavi's picture

Hello,

Try Unhookexec.inf, which may help, check this link below:

http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99

You could also perform the changes on the GPO, which may assist with the same. ( I would recommend you to create a case with Microsoft).

Secondly, There are many tools to fix this however the cause for this issue a Malware that is blocking all these. So make sure you update your SEP client with latest definitions and run full scan in safe mode.

OR scan using Symantec Power Eraser.

However you should also submit the suspicious files to symantec security response so that they can create defs. that will catch these threats. 

Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

Here's a good tool -

https://www-secure.symantec.com/connect/downloads/simple-utility-reset-folder-options-show-all-hidden-enable-registry-editing-enable-task-ma

NOTE: This tool is not provided neither supported by Symantec.

Hope that helps!!

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3

Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a

0
Login to vote
  • Actions
Swapnil khare's picture

What was the infection name which had occured ?

Check thread below there are many tools from Symantec which can be used to restore access to registry , taskmgr etc , however it truly depends on what kind of infection was it

 

You may like to try tools below on some Client machines first might help

https://www-secure.symantec.com/connect/forums/cannot-access-regedit-task-manager-and-msconfig

 

Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.

Swapnil

0
Login to vote
  • Actions
Greet9's picture

Hi Sonday,

Please download this file unhookexec.inf and run infected system.

http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99

SOLUTION
0
Login to vote
  • Actions
cus000's picture

You'll need to clear back the registry entries... are you managed to get the threat/virus name?

 

You may try ctrl-alt-del and use the function "run" .....from here try run your regedit...

0
Login to vote
  • Actions
Fabiano.Pessoa's picture

Good morning,

Use the tool Re-Enable 2.0
And to scan your PC, use the scan in safe mode, I am amazed how people do not warn about it.

hugs

Fabiano Pessoa

Systems Analyst - Forensic Expert

0
Login to vote
  • Actions