Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 42

Thread: Browser Redirect in IE and Mozilla

  1. #21
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    I'm sorry. Posted instructions for cleaning system restore of XP. Please find the right steps below.

    Let's reset system restore
    Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

    A To disable the System Restore feature:

    1. Click on the Start button.
    2. Hover over the Computer option, right click on it and then click Properties.
    3. On the left hand side, click Advanced Settings.
    4. If asked to permit the action, click on Allow.
    5. Click on the System Protection tab.
    6. Uncheck any checkboxes listed for your hard drives.
    7. Press OK.


    B. Reboot.

    C Turn ON System Restore.
    Follow the steps like you did when disabling system restore but on step 6. check any checkboxes listed for your hard drives.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  2. #22
    Junior Member
    Join Date
    Nov 2008
    Posts
    25

    Default Unable to un-check C:

    I am unable to uncheck the C:\ Drive from the list.

  3. #23
    Junior Member
    Join Date
    Nov 2008
    Posts
    25

    Default Oops

    Sorry, accidently submitted.

    It says that it's a "Group Policy" (On the Administrator)

    Thanks,
    devious

  4. #24
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    Download ERUNT
    Save it to your desktop. Run and install this program.

    In the box that opens ONLY choose
    System registry.

    Then click OK.

    Click save and then go to File > Exit.
    This is so the registry can be restored to this point if we need it. It may take a minute. Just let it go until it's done.

    Go to registery edit (type regedit in RUN and press enter)
    - Navigate to the following key
    HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\SystemRestore
    - Delate following keys if found:

    DisableConfig
    DisableSR


    Reboot if needed and see if you can change the system restore settings after that.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #25
    Junior Member
    Join Date
    Nov 2008
    Posts
    25

    Default Didnt work....

    I downloaded it, backed it up and then deleted the two registries.


    Didnt work... Now I am getting a "Searching..." Message. (See Attachment)


    I am going to restore the reg, just to make sure it doesnt cause any damage.


    Anything else I can try?

    Thanks,
    devious

  6. #26
    Junior Member
    Join Date
    Nov 2008
    Posts
    25

    Default Uhoh

    Restoring the reg. backup didnt do anything! The searching message is still there...

    What do I do?

    Thanks
    -devious

  7. #27
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    It shows same message in my system too for some time before showing any details. Did you wait any moment after you had opened system protection tab?


    Creating & executing batch file
    -------------------------------

    Open notepad and then copy and paste the bolded lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop. (If you are still unsure on how to do this there is a little tutorial with pictures here)
    @echo off
    regedit /e c:\keyExport.txt "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\SystemRestore"
    notepad c:\keyExport.txt

    Double-click on fixes.bat file to execute it.


    Post back contents of c:\keyExport.txt (should open up in Notepad window).
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  8. #28
    Junior Member
    Join Date
    Nov 2008
    Posts
    25

    Default

    Yep, I waited probley 2-3 minutes.


    Heres the content of the log:

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\SystemRestore]



    Thanks
    devious

  9. #29
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    How did you attempt to restore ERUNT backup?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  10. #30
    Junior Member
    Join Date
    Nov 2008
    Posts
    25

    Default

    By navigating to: C:\WINDOWS\ERDNT\30-11-2008

    And then clicking ERDNT in that folder.


    It game me like 8 error messages.


    -Thanks
    Devious

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •