Task Manager has been disabled by your administrator - Techist - Tech Forum

Go Back   Techist - Tech Forum > Computer Software > Microsoft Windows and Software
Click Here to Login
Closed Thread
 
Thread Tools Display Modes
 
Old 07-14-2006, 12:24 AM   #1 (permalink)
Newb Techie
 
Join Date: Jun 2006
Posts: 8
Exclamation Task Manager has been disabled by your administrator

I keep gettting the error msg: Task Manager has been disabled by your administrator. : when I try to cntl alt delete...

I am the administrator and never disabled or changed any permissions on my Win XP Pro....so what gives and how do I fix it.

I did get rid of some trojans that were on here today...so any suggestions on what to do???
__________________

redtechie is offline  
Old 07-14-2006, 12:25 AM   #2 (permalink)
Banned
 
Join Date: May 2005
Posts: 7,915
Send a message via Yahoo to talldude123
Default

Post a HiJackThis log here.
__________________

talldude123 is offline  
Old 07-14-2006, 01:14 AM   #3 (permalink)
Newb Techie
 
Join Date: Jun 2006
Posts: 8
Default

umm...i still need help yall...
redtechie is offline  
Old 07-14-2006, 01:20 AM   #4 (permalink)
Banned
 
Join Date: May 2005
Posts: 7,915
Send a message via Yahoo to talldude123
Default

Well, you're probably infected. I can't see if you're infected until you download HiJackThis, run HiJackThis, and paste the log here.
talldude123 is offline  
Old 07-14-2006, 01:30 AM   #5 (permalink)
Newb Techie
 
Join Date: Jun 2006
Posts: 8
Default

Logfile of HijackThis v1.99.1
Scan saved at 12:29:41 AM, on 7/14/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\CYB2K.EXE
C:\Program Files\Common Files\AOL\1152227094\ee\AOLSoftware.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Plaxo\2.6.2.9\PlaxoHelper.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Documents and Settings\jason\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myspace.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {35faabbf-38ae-4d95-8b94-2bb3a7ff0a36} - C:\WINDOWS\system32\shlmfd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\CYB2K.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1152227094\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [64ef548c.exe] C:\WINDOWS\System32\64ef548c.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.6.2.9\PlaxoHelper.exe -a
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://jasonpfales.spaces.msn.com//P...d/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: shlmfd - C:\WINDOWS\SYSTEM32\shlmfd.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
redtechie is offline  
Old 07-14-2006, 01:48 AM   #6 (permalink)
Law
Wizard Techie
 
Law's Avatar
 
Join Date: Aug 2005
Location: the data closet
Posts: 4,200
Default

CYB2K.EXE<--------Cybersitter, it's a program that monitor your internet usage and prevent user from accessing porn website, this may be the software that disable the task manager so that you can't terminate it.

Type gpedit.msc in run, Go to User Configuration/Administrative Templates/System/Ctrl+Alt+Del

“Remove Task Manager” is the setting you want to not defined or disable if it’s enable you won’t be able to access it.

Go to /Start Menu and Taskbar/ nothing should be enable, everything should be set to not defined, there’s a couple of setting you want to check, anything with the word taskbar or disable that is relevant.
Law is offline  
Old 07-14-2006, 01:57 AM   #7 (permalink)
Law
Wizard Techie
 
Law's Avatar
 
Join Date: Aug 2005
Location: the data closet
Posts: 4,200
Default

I don't know what this file is but it looks suspicious.

O4 - HKLM\..\Run: [64ef548c.exe] C:\WINDOWS\System32\64ef548c.exe
Law is offline  
Old 07-14-2006, 01:58 AM   #8 (permalink)
Banned
 
Join Date: May 2005
Posts: 7,915
Send a message via Yahoo to talldude123
Default

Onto your HiJackThis log, fix these entries using HiJackThis:

C:\WINDOWS\CYB2K.EXE

O2 - BHO: (no name) - {35faabbf-38ae-4d95-8b94-2bb3a7ff0a36} - C:\WINDOWS\system32\shlmfd.dll

O4 - HKLM\..\Run: [64ef548c.exe] C:\WINDOWS\System32\64ef548c.exe

O20 - Winlogon Notify: shlmfd - C:\WINDOWS\SYSTEM32\shlmfd.dll


Another thing; you don't have Windows updated. This is a key thing to do in order to have programs running smoothly, without any bugs appearing in them
talldude123 is offline  
Old 07-14-2006, 02:11 AM   #9 (permalink)
Newb Techie
 
Join Date: Jun 2006
Posts: 8
Default

ok...i check all that and nothing is definded...i also did the hijackthis..and restarted...but still getting the error msg...oh..i don't have windows set to update at all...and i don't use IE either..i'm using firefox
redtechie is offline  
Old 07-14-2006, 02:30 AM   #10 (permalink)
Law
Wizard Techie
 
Law's Avatar
 
Join Date: Aug 2005
Location: the data closet
Posts: 4,200
Default

Go to start/run and copy and paste this in and press enter. You might need to restart.

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
__________________

Law is offline  
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off




Copyright 2002- Social Knowledge, LLC All Rights Reserved.

All times are GMT -5. The time now is 03:07 AM.


Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2017, vBulletin Solutions, Inc.