Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS)
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 15th, 2005, 05:31 PM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Question RegDefend doesn't defend me at all

I've downloaded RegDefend 1300, installed it and run it. I know it is running because Process Guard tells me it has allowed it to start. But when I try RegTest,Test 1, every single modification is successful: RD is not defending at all my registry.
Please explain what has happened - is RD on strike?
By the way: I run win2k, have PG, Outpost,Nod32 and TDS3 installed:
.

Last edited by rat : May 15th, 2005 at 05:59 PM.
  #2  
Old May 15th, 2005, 07:23 PM
richrf richrf is offline
Very Frequent Poster
 
Join Date: Dec 2003
Posts: 1,907
Default Re: RegDefend doesn't defend me at all

Hi,

Just to make sure the install was sucessful, does your PG Protection indicate that REgDefend has the Install Driver/Services options. This is needed while RegDefend is installing. If not, you might want to try to uninstall and re-install with PG in learning mode and the Drivers/Services unchecked so that RegDefend can install all of the stuff it needs. That is what I normally do.

Rich
  #3  
Old May 15th, 2005, 09:14 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,806
Default Re: RegDefend doesn't defend me at all

Try Changing something in your startup, or if you run IE, change your home page. You will know if Regdefend is working.

Pete
  #4  
Old May 16th, 2005, 05:07 AM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Angry Re: RegDefend doesn't defend me at all

Hi Rich, yes I have given RegDefend the privilege to install drivers/services.
Hi Pete, no I am using Opera 8 and Firefox 1.04. Anyway I changed somrthing in Startup - no sign of life from RD.
  #5  
Old May 16th, 2005, 06:03 AM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: RegDefend doesn't defend me at all

Try uninstalling, rebooting then reinstalling RegDefend. Make sure your ANTIVIRUS, ANTISPYWARE, ANTIADWARE applications are all closed before installing it again.
  #6  
Old May 16th, 2005, 03:42 PM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Default Re: RegDefend doesn't defend me at all

HI Jason, I've uninstalled RegDefend, rebooted, closed Outpost,TDS3,Nod32,Ewido,Spybot, Adaware and Spywareblaster, reinstalled RegDefend and run RegTest: same results as before.
  #7  
Old May 16th, 2005, 04:04 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: RegDefend doesn't defend me at all

Quote:
Originally Posted by rat
HI Jason, I've uninstalled RegDefend, rebooted, closed Outpost,TDS3,Nod32,Ewido,Spybot, Adaware and Spywareblaster, reinstalled RegDefend and run RegTest: same results as before.
Hi rat,

Try using TopToBottom for Windows 2000 and Windows XP to see if the RegDefend driver (regdefend.sys) is being loaded.

Nick
Attached Images
 
  #8  
Old May 16th, 2005, 06:01 PM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Unhappy Re: RegDefend doesn't defend me at all

Hi Nick, thank you for your suggestion.I've downloaded TopToBottom and
I can't in fact see the RegDefend driver.... What should I do ? I'm a little out of my depht...
(I am not sure I shall be able to browse again to the Forum in the next hours because my phone line is in very bad state: ADSL is gone and the 56 kb modem hops
along at about 6 kb/s....)
Rat
  #9  
Old May 16th, 2005, 06:57 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: RegDefend doesn't defend me at all

Hi rat,

Sorry about your phone lines. Try installing RD in Safe Mode (tap the F8 key a few times before the OS starts to load). That will minimize the chance of collisions with other apps during the install process. Reboot normally after the install completes.

Nick
  #10  
Old May 16th, 2005, 08:22 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: RegDefend doesn't defend me at all

When properly installed, the RD driver should have a registry key like the one below. The Start value should be 2 (for automatic startup).

Nick
Attached Images
 
  #11  
Old May 17th, 2005, 03:26 PM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Default Re: RegDefend doesn't defend me at all

Hi Nick, nothing doing. I've installed RegDefend in Safe Mode, no anti-spyware/virus /malware applications running (even Task Manager said so), rebooted and run the test :same results. To be quite sure that the RD file had not become corrupted I re-downloaded it - still the same results. And no RD driver in the registry.
Maybe Jason has a cure?
Attached Images
 
  #12  
Old May 17th, 2005, 06:05 PM
BlueZannetti BlueZannetti is offline
Administrator
 
Join Date: Oct 2003
Posts: 6,589
Default Re: RegDefend doesn't defend me at all

Quote:
Originally Posted by rat
HI Jason, I've uninstalled RegDefend, rebooted, closed Outpost,TDS3,Nod32,Ewido,Spybot, Adaware and Spywareblaster, reinstalled RegDefend and run RegTest: same results as before.
rat,

While you've closed out many of your programs, there's no mention of either putting PG into learning mode or disabling protection (not shutting down the GUI - disabling protection) in the mix of things tried.

There's really not a lot of information to go on, but it sure sounds like a configuration issue (either application or system/OS level) or a conflict during install that we're not seeing at this point.

I assume no tweaking with permission levels, policies, etc., has been performed on this machine. Correct?

Blue
  #13  
Old May 17th, 2005, 09:24 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: RegDefend doesn't defend me at all

Hi rat,

As Blue suggests, it does look like some other app/setting/policy/permission is blocking the RD driver/service creation. Since this also happens in Safe Mode, I would first suspect system policies and permissions. One way to test your permissions is to try manually creating a driver/service key called regdefend with regedit. If you do not have permission, W2K will tell you. So will PG unless you disable it or give regedit.exe permission to install drivers.

Nick
Attached Images
 
  #14  
Old May 17th, 2005, 10:03 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: RegDefend doesn't defend me at all

FWIW, I played around a bit with deleting the driver registry key, and found that if I delete the key and reboot, RD re-creates the key at startup. If I delete the driver registry key and also delete the RD GUI autostart key, the driver key will remain absent when I reboot. However, when I then start RD manually, the driver key is restored. So RD will attempt to reinstall the driver key when required.

Nick
  #15  
Old May 18th, 2005, 04:41 AM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Default Re: RegDefend doesn't defend me at all

Hi Blue, hi Nick - yes, if I do not give regedit.exe permission to install drivers/services PG wont let me create a regdefend key. But if I give the permission (or if I disable PG) I have no difficulty at alli in creating it.
I'm very grateful for your support - but....will the patient die?
(a sad) Rat
Attached Images
 
  #16  
Old May 18th, 2005, 01:54 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: RegDefend doesn't defend me at all

Hi rat,

I installed RD on a W2K system just so I could export the driver registry key. Rename the attached rd_2kdriver.reg.txt to rd_2kdriver.reg. Double-click it to merge it into the registry. I'm not 100% sure that the key is transportable from one W2K system to another, but it is worth a try. Anyway, let's see if the key sticks and the driver stays installed.

Nick
Attached Files
File Type: txt rd_2kdriver.reg.txt (2.7 KB, 12 views)
  #17  
Old May 18th, 2005, 03:31 PM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Default Re: RegDefend doesn't defend me at all

Hi Nick, Hooray! The key did stick and the driver appears in the registry: everything seems OK to me. I'm trying to attach a screnshot of the registry
but this godforsaken modem+this miserable phone line keep disappearing during upload. Anyway, I'll try now to install and shall come back as soon as possible.
Thanks!
Rat
Edited: impossible to upload.
  #18  
Old May 18th, 2005, 04:28 PM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Default Re: RegDefend doesn't defend me at all

Hi Nick, I rejoiced too soon.. RegTest failed as before. What I cannot understand is that the regdefend key is in the registry (I think this time the screenshot got attached) and the program is installed and starts - but does nothing...
Attached Images
 

Last edited by puff-m-d : May 18th, 2005 at 04:54 PM. Reason: To resize attachment to fit screen...
  #19  
Old May 18th, 2005, 04:47 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re: RegDefend doesn't defend me at all

Hi Rat, Have you checked that the default groups are all enabled in "Main"? There should be two instances of RegDefend.exe running in Task manager.

Also check the following - Open "System Information" and make sure that you have this entry under "Software environment" - "System drivers"

regdefend regdefend \??\c:\program files\regdefend\regdefend.sys Kernel Driver Yes Auto Running OK Normal No Yes

HTH Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #20  
Old May 18th, 2005, 07:24 PM
Bowserman's Avatar
Bowserman Bowserman is offline
Infrequent Poster
 
Join Date: Apr 2003
Location: South Australia
Posts: 510
Default Re: RegDefend doesn't defend me at all

Also, just in case you did by accident.....check that you haven't added regtest.exe to the APO list (Application Permission Override) for any of the groups .


Regards,
Jade.
  #21  
Old May 19th, 2005, 05:42 PM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Default Re: RegDefend doesn't defend me at all

Hi Pilli, to sum up the situation:when I install RegDefend (in safe mode, no other defensive applications running) no RD key appears inthe registry. If I merge the key Nick sent me, it appears in the registry.
In System Information "Drivers": no RegDefend driver; in System Information,"auto-execute programs":
(Program): RegDefend
(Command): "c:\∞\regdefend\regdefend.exe" -minimize
No instance at all of RegDefend running in Task Manager.
Finally, you wrote:"Hi Rat, Have you checked that the default groups are all enabled in "Main"?". Excuse my stupidity, but I haven't understood what you mean by that.

Hi, Bowserman: no, I haven't added anything to the APO of the groups (By the way, I am unable to see any APO. Where should I look?).
Regards
Rat
  #22  
Old May 19th, 2005, 08:26 PM
BlueZannetti BlueZannetti is offline
Administrator
 
Join Date: Oct 2003
Posts: 6,589
Default Re: RegDefend doesn't defend me at all

rat,

This is a real puzzler.

About the only thing I can think of is a fundamental configuration problem related to machine localization - I noticed that the registry editor title bar is in Italian. Crossed signals due to language expectations? Wouldn't think this is a problem, but I can't think of any other options at the moment which would be benign.

Comments? I know, a shot in the dark.

Blue
  #23  
Old May 20th, 2005, 04:41 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re: RegDefend doesn't defend me at all

Quote:
Finally, you wrote:"Hi Rat, Have you checked that the default groups are all enabled in "Main"?". Excuse my stupidity, but I haven't understood what you mean by that.
Not stupid The unasked ones are the stupid ones. In RD's Main tab you should see the groups listed, the default ones are:
Autostarts,
Extra protection
Internet Explorer protection.
To the left you should see an "on / Off" tick box. Thes should be enabled if they are not already as if X RD is effectively disabled.

Please uninstall then reinstall RegDefend in normal mode as an Administrator with all your running security programs disabled. If this does not work there must be a deeper problem which is alluding us at the moment.

Attached shows how you can see that the drive is installed properly

HTH Pilli
Attached Thumbnails
Click image for larger version

Name:	RD_driver.jpg
Views:	143
Size:	80.5 KB
ID:	157815  

__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net

Last edited by Pilli : May 20th, 2005 at 04:56 AM.
  #24  
Old May 20th, 2005, 05:02 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re: RegDefend doesn't defend me at all

Here is how Main should look with the default groups enabled:
Attached Images
 
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #25  
Old May 20th, 2005, 11:20 AM
rat rat is offline
Infrequent Poster
 
Join Date: Apr 2003
Posts: 19
Default Re: RegDefend doesn't defend me at all

Pilli, this issue is becoming ....well I don't know how to define it. I did what you told me to do: uninstalled and reinstalled RD, only to discover that the downloaded setup file had become corrupted.
Ok, I download it again, I install it and two things happen in sequence:
1) RD suddenly awakens and blocks a program which is trying to modify the registry (I have verified that it is not a false alarm),
2) RD tells me that my trial period is ended and stops working...
Only 5 of the 14 trial days have elapsed, but what should I do ? Could I receive an 8-day-key to verify if RD really works on my system (and buy it, of course)?
Regards
Rat
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS) « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:25 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums