My folder option missing & my regedit is disabled pliz help

Posted 9/29/2006 9:46 AM
#37013
User avatar

Blackmind Member

Date Joined Nov 2016
Total Posts: 1
my folder option missing & my regedit is disabled pliz help
whenever i try reedit, i get a message to say disabled by administrator but iam an administrator

what should i do?
Posted 1/10/2007 10:03 AM
#41674
User avatar

harinder Member

Date Joined Nov 2016
Total Posts: 1
try to fix your problem using mmc console in any version of windows[[blue] [/blue]
"Somebody" wrote:
Posted 3/25/2007 8:39 AM
#45063
User avatar

Antivirus123 Member

Date Joined Nov 2016
Total Posts: 2
Hi everyone facing problem of folder options , registry editing and task manager....


Some guys complained that vbs is not working, so i'm presenting here another solution.

Copy the following code,paste in any notepad and save as "EnableRegEdit.inf" . Right-click and install; your regedit will be enabled.(Be careful to copy the code exactly as presented here including everything.



[color=purple>Code]Italic to avoid any misunderstanding...[/color]

___________________________________________________________________________________

[Version]
Signature="$Chicago$"
Provider=Symantec


[DefaultInstall]
AddReg=UnhookRegKey


[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe ""%1"""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools,0x00000020,0


_________________________________________________________________________________

To enable Folder Options, copy following code,paste it in any notepad and save as "folderoptions.reg" file. Double click it and your folder options will be restored.

_________________________________________________________________________________

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoFolderOptions"=dword:0000000


[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions]
"NoBrowserOptions"=dword:00000000


__________________________________________________________________________________

To enable Task Manager, copy following code,paste it in any notepad and save as "EnableTaskManager.reg" file. Double click it and your folder options will be restored.

_________________________________________________________________________

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:0000000


__________________________________________________________________________________




Make sure you have a good AV software installed on your system.

I recommend AVG 7.5 Pro

Download Link

[url=sikeryali@yahoo.com]sikeryali@yahoo.com[/url]
Posted 4/1/2007 4:48 PM
#45409
User avatar

iSergiwa Member

Date Joined Nov 2016
Total Posts: 1
Hello,

In many cases, I was forced to do the hard work curing the computers that are infected because they were with no AV already installed on them at all, yes that's true, many people doesn't know whether their computers need an AV software or not, they don't even know what a computer virus is!

When someone of those ask me for help, I first do an offline scan & clean.

When I boot the computer, I usually be faced with the same thing every time; the virus made some system restrictions in order to make himself hidden, those restrictions are usually the following :

1 - Disable Ctrl+Alt+Del >> so the user can't see the virus and the other running applications!

2 - Disable Folder Options >> so the user can't set the option to show hidden files!

3 –Disable Regedit >> so the user can't see what is going on in system startup!

Unfortunately, AV Softwares have nothing to do with these restrictions and do nothing to re-enable them!

Until AV softwares come with such tool in their next versions, here, you'll find a tiny tool that does the work for KAV, it Re-Enable all what the virus had disabled, and brings every thing back. I designed this tool and published it FOR FREE for every one need to use it!

Download link:

http://www.softpedia.com/get/Security/Security-Related/RRT-Remove-Ristrictions-Tool.shtml

Screenshots:

User image

User image

Thanks
Issam Sergiwa
Sergiwa.com
Posted 4/20/2007 9:01 AM
#46207
User avatar

asaygo Advanced member

Date Joined Nov 2016
Total Posts: 42
Try and use this BullGuard Tech Guide on how to enable "Folder options": How to enable Folder options if it's hidden

To enable the registry tools visit this BullGuard Tech Guide: How to enable regedit
Posted 6/27/2007 8:10 AM
#49653
User avatar

Cybermitz Member

Date Joined Nov 2016
Total Posts: 1
You are infected by virus..scan your computer with AVG 7.5. This antivirus is free and you can download it in the net.

Steps in enabling registry editor:

After scanning, go to run dialog box. Type gpedit.msc then goto:
User Configuration -> Administrative Templates -> System
in right-side pane, set "Prevent access to Registry editing tools" to either Not Configured or Disabled.

Steps in enabling Folder Options:

type "regedit" in the run dialog box then find "NoFolderOptions" in HKEY_CURRENT_USER. If it exist, set the value of it to 0 or delete it.

Now, try to check in the Control Panel if the Folder Options icon is already there. If still not exist. Try this step:

Type gpedit.msc then goto:
User Configuration -> Administrative Templates -> Windows Component -> Windows Explorer
in right-side pane, set "Removes the Folder Options menu item from the Tools menu" to Disabled.

Then try to check it again in the Control Panel if the Folder Options icon is already there.
Posted 8/17/2007 1:42 PM
#52171
User avatar

thugonomic Member

Date Joined Nov 2016
Total Posts: 2
HI

I tried running the script thru notepad for enabling my registry but it gave me the below error

Cant Find the script engine "VBScript" for script "C:\...


Can u please guide me further
Posted 8/22/2007 5:18 PM
#52440
User avatar

Andrei M Advanced member

Date Joined Nov 2016
Total Posts: 356
Hi,


Let's see some logs you may have a virus.
Please go here and try to post the required logs.


Regards,
Andrei M
[blue]Microsoft Certified Professional[/blue]
BullGuard | support[at]bullguard[dot]com

---------
If more than 24hrs have passed since my last reply on your thread, send me a private message to remind me.
---------
Posted 10/5/2007 4:27 AM
#54588
User avatar

coldheart Member

Date Joined Nov 2016
Total Posts: 1
Thnx man .... u really r an angel


"Cybermitz" wrote:
You are infected by virus..scan your computer with AVG 7.5. This antivirus is free and you can download it in the net.

Steps in enabling registry editor:

After scanning, go to run dialog box. Type gpedit.msc then goto:
User Configuration -> Administrative Templates -> System
in right-side pane, set "Prevent access to Registry editing tools" to either Not Configured or Disabled.

Steps in enabling Folder Options:

type "regedit" in the run dialog box then find "NoFolderOptions" in HKEY_CURRENT_USER. If it exist, set the value of it to 0 or delete it.

Now, try to check in the Control Panel if the Folder Options icon is already there. If still not exist. Try this step:

Type gpedit.msc then goto:
User Configuration -> Administrative Templates -> Windows Component -> Windows Explorer
in right-side pane, set "Removes the Folder Options menu item from the Tools menu" to Disabled.

Then try to check it again in the Control Panel if the Folder Options icon is already there.
Posted 10/23/2007 12:07 AM
#55167
User avatar

makata Member

Date Joined Nov 2016
Total Posts: 1
:jumpin: hi there people who have problem with regedit (disable by the administrator) the main reason of disabling the regedit are virus, i encountered a staberry virus quoted "i'm still waiting for the straberry virus from baguio" i asked and try too many ways to retrieve my regedit but its only a waste of time, heres the practical solution that surely make you laugh, but proven effective. click star menu, click control panel then click user account pick a task create a new account. log off the current account and log on from your new account. the regedit are working properly in this new account you may now fix the problem or delete viruses using regedit.

to remove straberry virus click start menu run: copy and paste or manually locate the following regedit: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\currentVersion\winlogon, then delete the sentence say "im still waiting for your straberry from baguio. then delete the other one who have related phrases. thanks and more power.
Posted 1/28/2008 11:23 AM
#59215
User avatar

Cloudcatcher Member

Date Joined Nov 2016
Total Posts: 1
I followed the instructions from Cybermitz and after struggling for two days to fix my computer from the Brontok virus and get my folder options working in both my user account and in administrator, Cybermitz had me fixed in ten minutes. Thank you!

Be careful of Brontok washer and remove restrictions tools. They did not work for me.

Thank you Cybermitz. :smile:
Posted 2/5/2008 10:57 AM
#59480
User avatar

prijygeorge Member

Date Joined Nov 2016
Total Posts: 1
thanks a lot cybermitz.

this was the most effective reply.

guys who have the same prob do try this out. dont go for tools or remover or washer.



Posted 2/26/2008 7:57 AM
#60019
User avatar

arash_beterkun Member

Date Joined Nov 2016
Total Posts: 1
Mr.cybermitz , thx . it really worked .
and im agree with u . the AVG anti virus is the best . beacuse it really fast , keen and free . :hop:
Posted 6/10/2008 12:25 AM
#62718
User avatar

biosong Member

Date Joined Nov 2016
Total Posts: 1
i find Babar Jahangir's suggestion VERY HELPFULL

thanks.
Posted 11/9/2008 5:01 PM
#67906
User avatar

help80 Member

Date Joined Nov 2016
Total Posts: 1
my folder option missing i guess becsuse of nude ssg sex scandal virus that attackts the flashdrives..
i tried running the regedit but the prompt appears "Registry editing has been disabled by your administrator"...im the administrator, i cannot proceed, please help...
Posted 1/11/2009 7:47 PM
#71026
User avatar

Maj Member

Date Joined Nov 2016
Total Posts: 1
Ok i struggled getting this to work and i did it with the help from these guys and the spreadsheet [found on microsofts site] [ http://www.microsoft.com/downloads/details.aspx?FamilyID=7821c32f-da15-438d-8e48-45915cd2bc14&displaylang=en ] . i have windows vista home basic so i needed to do it differently. [gpedit doesnt excist on home basi or premuim]


*virus scan AVG before doing this [Delete those viruses]!!!*



so create a new user

log on

run > regedit

[toolbar] edit> find

type System!DisableRegistryTools [press enter]

look to your left [folders have expanded] click on the one that hasnt been expanded or is the last one

now delete System!DisableRegistryTools which should appear on your right

ok log back into the account suffering

u should now be able to get onto regedit [start >run [regedit]
:smilewinkgrin:
part 2

log back into the new account


run > regedit

[toolbar] edit> find

type NoFolderOptions


look to your left [folders have expanded] click on the one that hasnt been expanded or is the last one

now delete NoFolderOptions which should appear on your right

ok log back into the account suffering [not anymore]

start > control pannel

folder options should be there!!



well done your pc is fixed XD :yeah:

Michael Ball
Posted 1/12/2009 6:18 AM
#71050
User avatar

Zynd Member

Date Joined Nov 2016
Total Posts: 1
Hi Guys,

I've been struggling to remove this virus from PC. The virus disables my ability to view hidden folders and operating system files. I tried changing the options but still I'm not successful in changing it. Can you please help me.

I've tried modifying the registry for the folder option but still unsuccessful.

then tried using Hijackthis and here is the output. Can you please help me.

Logfile of HijackThis v1.99.1
Scan saved at 2:04:04 PM, on 1/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe
c:\oracle\product\10.2.0\db_1\bin\isqlplussvc.exe
c:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
c:\oracle\product\10.2.0\db_1\jdk\bin\java.exe
c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Elantech\ktp.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\BisonCam\BisonTrayIcon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Elitecore\Single Signon\SSCyberoam_7310.exe
C:\Program Files\QuickTime\qttask.exe
C:\Documents and Settings\EarlD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\UltraEdit\uedit32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\regedit.exe
C:\Documents and Settings\EarlD\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://sites.google.com/a/misnet.com.ph/sample-project-site/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://sites.google.com/a/misnet.com.ph/sample-project-site/Home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by MISNet, Inc.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [KTPWare] C:\Program Files\Elantech\ktp.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BisonTrayIcon] C:\WINDOWS\BisonCam\BisonTrayIcon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Single Signon] C:\Program Files\Elitecore\Single Signon\SSCyberoam_7310.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\EarlD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O14 - IERESET.INF: START_PAGE_URL=https://sites.google.com/a/misnet.com.ph/sample-project-site/Home
O15 - Trusted Zone: http://www.oracle.com
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://emersoncorporate.webex.com/client/T25L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = misnet.com.ph
O17 - HKLM\Software\..\Telephony: DomainName = misnet.com.ph
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = misnet.com.ph
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = misnet.com.ph
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = misnet.com.ph
O18 - Protocol: qrev - {9DE24BAC-FC3C-42C4-9FC4-76B3FAFDBD90} - C:\PROGRA~1\QUESTS~1\TOADFO~1\RNetPin.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: OracleDBConsoleorcl - Oracle Corporation - c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe
O23 - Service: OracleOraDb10g_home1iSQL*Plus - Oracle - c:\oracle\product\10.2.0\db_1\bin\isqlplussvc.exe
O23 - Service: OracleOraDb10g_home1TNSListener - Unknown owner - c:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
O23 - Service: OracleServiceORCL - Oracle Corporation - c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


Thanks
Posted 1/12/2009 6:22 AM
#71052
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
Hello Zynd :smile:


I´ll suggest you proceed as follows ->






Download this program: http://www.ctrlaltdel.dk/Fix_download.exe

and save it on the desktop. Then double click on it (Fix_download.exe).

You may have to allow the program to download files from the web!

The program download the necessary cleaning programs. Once the program
is downloaded, there will be a folder on your desktop named
Fix. – if the instructions not automatically opens, so
double-click "FIX_manual.htm" in Fix folder.

Please follow the instructions and copy the logs here, in this Topic.



Note : Fix_download.exe is detected by some antivirus programs as a "RiskTool" /infection; it is not a virus. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.







If necessary, temporarily disable your anti-virus, real-time protection before downloading





I´ll lock this (old) topic

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Wednesday, April 26, 2017, 2:13 AM (GMT +2)
There are a total of 61,193 posts in 13,463 threads.
In the last 3 days there were 0 new threads and 0 reply posts.

Who's online

This forum has 38,021 registered members. Please welcome our newest member, tonyjohn.
There are currently no users on-line.
[Error loading the WebPart 'cr' of type 'CultureRedirect']
We use cookies to ensure that we give you the best experience on our website. By continuing to browse, we are assuming that you have no objection in accepting cookies. You can change your cookie settings at any time.