PDA

View Full Version : Task Manager has been disable by administrator



lotsaproblemguy
26-08-2006, 11:59 AM
As you can read the topic when ever I try to open up by task manager it show that message " task manager has been disable by administrator" I have my account lock with a password only I have access to my account and my account is the administrator side.. I don't know if I did anything wrong to disable my task manager can someone help me reactive it again? O and there are files that are transparent.. I asked my friend what are they and he said they are system file they usually are hidden so u won't accidnetly delete em.. so I was wondering how do I make them hidden again? I'm afraid I might accidently delete one of em

Speedy Gonzales
26-08-2006, 12:06 PM
Get hijackthis (http://www.merijn.org/files/hijackthis.zip) from here (http://www.merijn.org/)

Unzip this run it and scan, and post the log here, or here (http://www.hijackthis.de/en) tick the nasty entries in hijackthis, and tick fix checked.

It maybe better if u do this in safe mode, and then run hijackthis.

lotsaproblemguy
26-08-2006, 12:14 PM
why safe mode? and I forgot how to do safe mode isn't safe mode when all ur start up program doesn't appear when u restart?

lotsaproblemguy
26-08-2006, 12:20 PM
Alrite I scan and fixed 1 unessescary and 2 posibly nasty the other 2 left are from a game call tricksteronline so I won't worry about it here is the new log

Logfile of HijackThis v1.99.1
Scan saved at 7:16:39 PM, on 8/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Fr0sTen\Desktop\hijackthis\HijackThis.exe

O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [PrevxHome] C:\Program Files\Prevx Home\SAGUI.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37240.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.tricksteronline.com/control/KALogoutComponent.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\Prevx Home\PXAgent.exe" -f (file missing)
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Speedy Gonzales
26-08-2006, 12:31 PM
why safe mode? and I forgot how to do safe mode isn't safe mode when all ur start up program doesn't appear when u restart?

You press F8 as soon as u reboot. No it loads what it needs to get into XP.

The desktop etc still loads. And doesnt run programs that usually run in normal XP.

The log looks ok now. Is task manager working now?

lotsaproblemguy
26-08-2006, 12:40 PM
I haven't reboot yet .. I haven't have a virus / spyware scan in a millions years now IM just trying to update my virus and spyware scanner tahn make scans How about the system file problem how can I fix that

Speedy Gonzales
26-08-2006, 01:20 PM
Well reboot then. If you ticked some nasty entries in hijackthis.

lotsaproblemguy
26-08-2006, 02:13 PM
well i rebooted... i click f8 throught out the shut down and start up.. I unno if it got in safe mode or not... so.. but the thing still not working =[ i still can't use task manager

Speedy Gonzales
26-08-2006, 02:22 PM
Try one of the methods here (http://windowsxp.mvps.org/Taskmanager_error.htm)

lotsaproblemguy
26-08-2006, 03:11 PM
O thx so much I fix my task manager I think I have accidently deleted some register or something? I have other problem.. I don't have a turn off button only a log out.. and I can't find my start > Run > cmd... My run and my turn off comp button just disapear today!!

http://img90.imageshack.us/img90/5681/blehgz0.png < pic

Speedy Gonzales
26-08-2006, 03:23 PM
Go here

Run Command Missing

Right click the Start button and select Properties, then Customize. Scroll down and put the check mark in the Show Run entry.

If you're using the new Start panel, its on the Advanced tab.

Or check your settings here: Start/Run/Regedit

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\Explorer

Value Name: NoRun
Data Type: REG_DWORD (DWORD Value)
Value Data: (0 = disabled, 1 = enabled)

Pancake
26-08-2006, 03:39 PM
Give this a go.....

Copy and paste all this from within the box into Notebook then go to FILE and SAVE AS. "All Files" must be selected in the "Save as Type" box. In that box type Fix.reg and save it to your Desktop.Double click to merge it to the registry



REGEDIT 4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer]
"NoClose"=dword:0000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer]
"NoLogOff"=dword:0000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer]
"NoRun"=dword:0000000


Reboot.....................

Thomas01
26-08-2006, 05:14 PM
O thx so much I fix my task manager I think I have accidently deleted some register or something? I have other problem.. I don't have a turn off button only a log out.. and I can't find my start > Run > cmd... My run and my turn off comp button just disapear today!!

http://img90.imageshack.us/img90/5681/blehgz0.png < pic

To me it looks as though you are continually getting into trouble. It may be your computer set up but I suggest your methods of operation are at fault. Your English is poor and spelling atrocious so I wonder if English is not your first language - that can be a problem if you have to cope with instructions in a foreign language (been there - done that!).
I remember 60 years ago being told by our teachers that especially Latin helped our logical thought processes, a help for any future efforts.
As a teacher myself for 20 odd years I always tried to get my students to follow the rules closely - and things we disliked doing should always be done to the best of our ability. For me, for instance when a design engineer I hated filling in the Bills of Materials at the end of the day. So I put lots of effort into producing the best Bills of Materials in the office.
For you I suggest using your spell checker and watch your English - keep it simple.
Thinking logically will always be a help when using computers.
Best of luck with your problems.
Tom

lotsaproblemguy
04-09-2006, 09:20 AM
Give this a go.....

Copy and paste all this from within the box into Notebook then go to FILE and SAVE AS. "All Files" must be selected in the "Save as Type" box. In that box type Fix.reg and save it to your Desktop.Double click to merge it to the registry



Reboot.....................

rawr I just notice I don't have notepad MY COMP IS SOOOO MESS UP =[[ rawr Mayb I need to reformat it or something