<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Restoring Safeboot</title>
	<atom:link href="http://blog.didierstevens.com/2006/06/26/restoring-safeboot/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/</link>
	<description>(blog 'DidierStevens)</description>
	<pubDate>Fri, 21 Nov 2008 02:45:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: SPTD.sys - THE DAEMONS HOME</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-33332</link>
		<dc:creator>SPTD.sys - THE DAEMONS HOME</dc:creator>
		<pubDate>Sat, 16 Aug 2008 00:23:50 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-33332</guid>
		<description>[...] &#34;Show hidden files and folders&#34; from Windows Explorer. To restore safeboot, please visit: Restoring Safeboot Didier Stevens  Bonne [...]</description>
		<content:encoded><![CDATA[<p>[...] &quot;Show hidden files and folders&quot; from Windows Explorer. To restore safeboot, please visit: Restoring Safeboot Didier Stevens  Bonne [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-28931</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 30 Mar 2008 21:41:17 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-28931</guid>
		<description>I know, I put that free safeboot.reg file on the web:
http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/</description>
		<content:encoded><![CDATA[<p>I know, I put that free safeboot.reg file on the web:<br />
<a href="http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/" rel="nofollow">http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-28930</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Sun, 30 Mar 2008 21:29:55 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-28930</guid>
		<description>heck just go NOW and find a safeboot.reg key on the web, free download, and stash it in a new folder on the desktop.

Click it and then safeboot will be there when you reboot right after.</description>
		<content:encoded><![CDATA[<p>heck just go NOW and find a safeboot.reg key on the web, free download, and stash it in a new folder on the desktop.</p>
<p>Click it and then safeboot will be there when you reboot right after.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-11006</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Fri, 06 Jul 2007 13:30:19 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-11006</guid>
		<description>I know that Safeboot is a third party encryption system, but it is also the name of the registry key (Safeboot) that holds the Safe Mode data.

Safe Mode is the name of the special boot process.
Safeboot is the name of the registry key.</description>
		<content:encoded><![CDATA[<p>I know that Safeboot is a third party encryption system, but it is also the name of the registry key (Safeboot) that holds the Safe Mode data.</p>
<p>Safe Mode is the name of the special boot process.<br />
Safeboot is the name of the registry key.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aus_e</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-10980</link>
		<dc:creator>Aus_e</dc:creator>
		<pubDate>Fri, 06 Jul 2007 05:10:32 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-10980</guid>
		<description>Please don't confuse safemode booting with safeboot. safeboot is a third party encryption system, which runs before the OS boots- that's why they talk of using Barts PE and setting it up for safeboot. norton's will only bugger the drive, as it won't even be able to read it if it's encrypted.

BTW I'm stuck - I can't find the Bart's plugin on the Safeboot CDs. does anyone know where they are?</description>
		<content:encoded><![CDATA[<p>Please don&#8217;t confuse safemode booting with safeboot. safeboot is a third party encryption system, which runs before the OS boots- that&#8217;s why they talk of using Barts PE and setting it up for safeboot. norton&#8217;s will only bugger the drive, as it won&#8217;t even be able to read it if it&#8217;s encrypted.</p>
<p>BTW I&#8217;m stuck - I can&#8217;t find the Bart&#8217;s plugin on the Safeboot CDs. does anyone know where they are?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blue</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-5677</link>
		<dc:creator>Blue</dc:creator>
		<pubDate>Sat, 26 May 2007 05:29:10 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-5677</guid>
		<description>ok just to fix the wireless you can use this registry values
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc]
"UuidSequenceNumber"=dword:0cdae01e

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisuio]
"Start"=dword:00000003

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess]
"Start"=dword:00000002

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv]
"Start"=dword:00000002

[HKEY_CURRENT_USER\SessionInformation]
"ProgramCount"=dword:00000004

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio]
"Start"=dword:00000003

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]
"Start"=dword:00000002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]
"Start"=dword:00000002</description>
		<content:encoded><![CDATA[<p>ok just to fix the wireless you can use this registry values<br />
Windows Registry Editor Version 5.00</p>
<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc]<br />
&#8220;UuidSequenceNumber&#8221;=dword:0cdae01e</p>
<p>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisuio]<br />
&#8220;Start&#8221;=dword:00000003</p>
<p>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess]<br />
&#8220;Start&#8221;=dword:00000002</p>
<p>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv]<br />
&#8220;Start&#8221;=dword:00000002</p>
<p>[HKEY_CURRENT_USER\SessionInformation]<br />
&#8220;ProgramCount&#8221;=dword:00000004</p>
<p>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio]<br />
&#8220;Start&#8221;=dword:00000003</p>
<p>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]<br />
&#8220;Start&#8221;=dword:00000002</p>
<p>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]<br />
&#8220;Start&#8221;=dword:00000002</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mario Biassoni - MCT</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-678</link>
		<dc:creator>Mario Biassoni - MCT</dc:creator>
		<pubDate>Tue, 27 Feb 2007 17:42:12 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-678</guid>
		<description>Hi there,

found this helpful page only after removing the fX#@$ing Bagle as per AV vendors instructions.

As for many of you it took me 2-3 days after infection to realize I have been infected;
happened like it did for Didier Stevens.
I agree that AV vendors are rating this virus erroneously: this is a burdensome one to removal!

Have to higlight that google searches did not hit right most of times; especially regarding the
disbaling of NDIS driver and the messing up of Safe Mode (originally searched for specific BSOD related info).
After some "big time" (strange as I ONLY use web services in English language for obvious reasons);
I used Gmer and HijackThis which made the situation pretty clear.

One point that prevents a successful restore of the SafeBoot key is that removal procedures DO NOT
mention about Safe Mode issues and they DO recommend to wipe out System Restore existent data.
This dismisses cases 2 and 3.

My thanks to Didier for providing a fresh&#38;clean SP2 SafeBoot .reg file for that all the SYSTEM hives
I could load did not provide a fix (system blind reboots after 5 minutes of disk activity).

Bests to all,

/Mario</description>
		<content:encoded><![CDATA[<p>Hi there,</p>
<p>found this helpful page only after removing the fX#@$ing Bagle as per AV vendors instructions.</p>
<p>As for many of you it took me 2-3 days after infection to realize I have been infected;<br />
happened like it did for Didier Stevens.<br />
I agree that AV vendors are rating this virus erroneously: this is a burdensome one to removal!</p>
<p>Have to higlight that google searches did not hit right most of times; especially regarding the<br />
disbaling of NDIS driver and the messing up of Safe Mode (originally searched for specific BSOD related info).<br />
After some &#8220;big time&#8221; (strange as I ONLY use web services in English language for obvious reasons);<br />
I used Gmer and HijackThis which made the situation pretty clear.</p>
<p>One point that prevents a successful restore of the SafeBoot key is that removal procedures DO NOT<br />
mention about Safe Mode issues and they DO recommend to wipe out System Restore existent data.<br />
This dismisses cases 2 and 3.</p>
<p>My thanks to Didier for providing a fresh&amp;clean SP2 SafeBoot .reg file for that all the SYSTEM hives<br />
I could load did not provide a fix (system blind reboots after 5 minutes of disk activity).</p>
<p>Bests to all,</p>
<p>/Mario</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dimaug</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-615</link>
		<dc:creator>dimaug</dc:creator>
		<pubDate>Mon, 19 Feb 2007 22:44:50 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-615</guid>
		<description>Recovering from Bagle, which blows out Safemode, among other things.
This really isn't that hard to recover from. Here's how I did it:
First, I discovered I had a problem because AVG wouldn't work, wouldn't uninstall and wouldn't reinstall from a fresh install file. After a reboot (and a failed system restore and a safemode BSOD), I discovered my wireless stopped working and Wireless Zero config wouldn't start because of unstarted dependecy services (it turned our to be NDIS I/O). A Google search told me that it was probably Bagle and led me to get Blacklight. Blacklight found all the nasties and I chose to rename them. Reboot and voila, Bagle disabled! However, I still had three problems - 1) System restore failed every time 2) Still no wireless and 3) Could not boot into safemode.
Solution
Loaded System hive from C:\WINDOWS\system32\config. Exported HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot to a reg file. Opened regfile in notepad and did a replace for the name I chose when loading to "SYSTEM". (for instance, when I loaded the hive, I called it "repair". I then did a find and replace from "repair" to "SYSTEM" [note case sensitive!]). Imported regfile. Safemode fixed.
Uninstalled and reinstalled Wireless NIC. This reloaded the NDIS protocol (which I had tried to reinstall alone, but no dice). Reset TCP/IP settings (I don't use DHCP), reestablished connection with WAP (I don't broadcast, so I had to do this by hand). Wireless fixed.
Disabled System restore. This deleted all the restore points, many of which were hosed anyway. This bugger had been around for a few days before I noticed it. Re-enabled System restore and manually created a restore point immediately. System restore fixed.</description>
		<content:encoded><![CDATA[<p>Recovering from Bagle, which blows out Safemode, among other things.<br />
This really isn&#8217;t that hard to recover from. Here&#8217;s how I did it:<br />
First, I discovered I had a problem because AVG wouldn&#8217;t work, wouldn&#8217;t uninstall and wouldn&#8217;t reinstall from a fresh install file. After a reboot (and a failed system restore and a safemode BSOD), I discovered my wireless stopped working and Wireless Zero config wouldn&#8217;t start because of unstarted dependecy services (it turned our to be NDIS I/O). A Google search told me that it was probably Bagle and led me to get Blacklight. Blacklight found all the nasties and I chose to rename them. Reboot and voila, Bagle disabled! However, I still had three problems - 1) System restore failed every time 2) Still no wireless and 3) Could not boot into safemode.<br />
Solution<br />
Loaded System hive from C:\WINDOWS\system32\config. Exported HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot to a reg file. Opened regfile in notepad and did a replace for the name I chose when loading to &#8220;SYSTEM&#8221;. (for instance, when I loaded the hive, I called it &#8220;repair&#8221;. I then did a find and replace from &#8220;repair&#8221; to &#8220;SYSTEM&#8221; [note case sensitive!]). Imported regfile. Safemode fixed.<br />
Uninstalled and reinstalled Wireless NIC. This reloaded the NDIS protocol (which I had tried to reinstall alone, but no dice). Reset TCP/IP settings (I don&#8217;t use DHCP), reestablished connection with WAP (I don&#8217;t broadcast, so I had to do this by hand). Wireless fixed.<br />
Disabled System restore. This deleted all the restore points, many of which were hosed anyway. This bugger had been around for a few days before I noticed it. Re-enabled System restore and manually created a restore point immediately. System restore fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-607</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Mon, 19 Feb 2007 13:59:32 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-607</guid>
		<description>@Mirco

Read me new post: http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/</description>
		<content:encoded><![CDATA[<p>@Mirco</p>
<p>Read me new post: <a href="http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/" rel="nofollow">http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mirco</title>
		<link>http://blog.didierstevens.com/2006/06/26/restoring-safeboot/#comment-578</link>
		<dc:creator>Mirco</dc:creator>
		<pubDate>Sun, 18 Feb 2007 16:07:04 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/#comment-578</guid>
		<description>I don't have a backup of my registy and I don't understand this Bart PE stuff.  Could somebody be kind enough to post the and exported .reg for the entires in safeboot? After all settings for safeboot won't vary that much from one machine to another.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t have a backup of my registy and I don&#8217;t understand this Bart PE stuff.  Could somebody be kind enough to post the and exported .reg for the entires in safeboot? After all settings for safeboot won&#8217;t vary that much from one machine to another.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
