India Broadband Forum


Tool for locking registry entires and thereby spies

This is a discussion on Tool for locking registry entires and thereby spies within the Computer Security forums, part of the Computer technology category; Do you know any tool for locking the registry? Tune up utilities offer this function.The problem is that it is ...

Go Back   India Broadband Forum > Computers > Computer technology > Computer Security

India Broadband Forum


                      

Reply

 

LinkBack Thread Tools Display Modes
Old 03-13-09, 07:40 PM   #1
meetdilip
Guest
 
Posts: n/a
Default Tool for locking registry entires and thereby spies

Do you know any tool for locking the registry?

Tune up utilities offer this function.The problem is that it is not reliable. It automatically unlocks after some time. As you might has noticed from my previous posts, my computer was infected with koolynoody, a downloader. I used ccleaner and spybot. Both failed. Now i used CA Yahoo antispy. It detected KoolyNoody and i manually deleted all entries in registry that were not fixed. Now today again i found it in my registry. I took registry back up and stored it.

Also i found 2 explorer.exe in task manager. Is it possible? Please take a look at the images.

Also please tell me how to prevent koolynoody to make the registry entry again.

Please feel free to contact me.

regards

Dilip
Attached Images
File Type: jpg 2 explorer.JPG (134.0 KB, 13 views)
  Reply With Quote
Old 03-13-09, 08:21 PM   #2
kirankumargb
Guest
 
Posts: n/a
Default

i used to use system mechanic... it was giving a good protection for my registry ... it would block even when we ourselves are installing any software, i had to unlock it first then install software.......
  Reply With Quote
Old 03-13-09, 08:40 PM   #3
Platinum Member
 
StarK's Avatar
 
Join Date: Mar 2008
Location: Nayi Dilli
Posts: 1,392
Rep Power: 4
StarK will become famous soon enoughStarK will become famous soon enough
Send a message via MSN to StarK
Default

as long as the malware will remain on ur system u will get those registry entries back. the right way to do it would be first to scan ur system with a good antivirus (try avira) http://www.free-av.com/en/download/index.html and get rid of any copies of the malware on ur hdd, then clean the registry.

but if u still feel too vulnerable then to prevent such malicious modifications u should use a HIPS(host based intrusion prevention system). You can find this feature in comodo firewall (free to use).Free Firewall Antivirus Software Download by Comodo

every modification by any any software on ur computer would first need authentication from you. u can also set it to learn so it does not bother you for legit sw. its also a great firewall, though i discontinued using it since i don't feel like i need so much security now that i use avira and sygate firewall ... tho u might find it usefull.

tc.

PS: the registry is a crucial part of the windows os so 'locking' it up will probably result in a non functional pc :P

Last edited by StarK; 03-13-09 at 08:42 PM. Reason: Automerged Doublepost
StarK is offline   Reply With Quote
Old 03-13-09, 08:42 PM   #4
Platinum Member
 
Join Date: Aug 2007
Location: Chennai
Posts: 4,246
Rep Power: 12
essbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of light
Default

Remove KoolyNoody Hijacker - Hijacker Removal Instructions.
Spybot or AD-adaware also recommended.

Try FireFOX browser. Seems to affect IE only.>
Para two;
Two explorer.exe . But usage is NIL . How ? wait.
similarly you get multiple entries for svchost.exe.

http://www.anvir.com/ .
Download (free)application
Gives details of all programs at start up etc.
[quote]
Hmm, www.koolynoody.net isn't loading right now.

The computers that run www.koolynoody.net are having some trouble. Usually this is just a temporary problem, so you might want to try again in a few minutes.
Quote:
Sponsored Resource

Want more detail? See which nameservers are failing.
Nameserver trace for www.koolynoody.net:

* Looking for who is responsible for root zone and followed l.root-servers.net.
* Looking for who is responsible for net and followed f.gtld-servers.net.
* Looking for who is responsible for koolynoody.net and followed ns.johnruffo.com.

Nameservers for www.koolynoody.net:

* ns.johnruffo.com returned (SERVFAIL)
* ns2.johnruffo.com returned (SERVFAIL)
essbebe is offline   Reply With Quote
Old 03-13-09, 08:45 PM   #5
Platinum Member
 
StarK's Avatar
 
Join Date: Mar 2008
Location: Nayi Dilli
Posts: 1,392
Rep Power: 4
StarK will become famous soon enoughStarK will become famous soon enough
Send a message via MSN to StarK
Default

and i see a lot of unnecessary processes running in ur task manager... get rid of them. specially the second explorer.exe!? one of them is probably malware.

get process explorer and find out from where the processes are running and whether they are legit or not..
StarK is offline   Reply With Quote
Old 03-13-09, 09:12 PM   #6
Platinum Member
 
Join Date: Aug 2007
Location: Chennai
Posts: 4,246
Rep Power: 12
essbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of lightessbebe is a glorious beacon of light
Default

@moderator:
IB.net server problem often this evening.
Trying annexure fifth time. here.
Unable to edit previous post and add annexure. there.
Attached Images
File Type: jpg anvir processes.jpg (37.6 KB, 7 views)
essbebe is offline   Reply With Quote
Old 03-26-09, 12:32 PM   #7
Bronze Member
 
Join Date: Sep 2008
Location: Cochin/Bangalore
Age: 26
Posts: 164
Rep Power: 2
SledgeHammer is on a distinguished road
Default

Well I don't think that it's a good idea to completely lock the registry since apps usually write to the registry during the operating time.
SledgeHammer is offline   Reply With Quote
Old 03-26-09, 09:46 PM   #8
Bronze Member
 
Jaganathsamal's Avatar
 
Join Date: Dec 2008
Age: 17
Posts: 170
Rep Power: 1
Jaganathsamal is on a distinguished road
Default

Clean up ur system using any good software.
Open the registry editor and deny write permissions to evey user account on ur system. You can also disable your registry editing using group policy editor (gpedit.msc)

Free online scan & remove viruses/malwares e.t.c , visit http://housecall.trendmicro.com/
Jaganathsamal is offline   Reply With Quote
Reply

Tags
entires, locking, registry, spies, tool

Thread Tools
Display Modes

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Virus in registry, pls help meetdilip Computer Security 26 04-26-09 01:02 AM
Yuuguu : an IM tool that also functions as a Remote Desktop tool panchabhut News from the Tech and IT World 2 04-04-09 10:51 PM
need registry cleaner software? anni Software News, Previews and Reviews 15 02-14-09 12:24 AM
Which Registry Cleaner is good? Rameshjeee Software News, Previews and Reviews 8 09-21-08 05:58 PM
microsft registry checker works on its own!! ridam Computer hardware and software tips and tricks 1 06-08-08 04:04 PM


All times are GMT +5.5. The time now is 05:22 PM.


India Broadband Forum