<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: The Undeletable SafeBoot Key</title>
	<atom:link href="http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-41541</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Thu, 20 Jan 2011 20:59:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-41541</guid>
		<description><![CDATA[@Ross If you restored your deleted SafeBoot keys with my .reg file, then why not delete them again yourself (with regedit), then run my program to create an undeletable SafeBoot key, and then restore them with my .reg file?
This way, they&#039;ll be protected.]]></description>
		<content:encoded><![CDATA[<p>@Ross If you restored your deleted SafeBoot keys with my .reg file, then why not delete them again yourself (with regedit), then run my program to create an undeletable SafeBoot key, and then restore them with my .reg file?<br />
This way, they&#8217;ll be protected.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-41540</link>
		<dc:creator><![CDATA[Ross]]></dc:creator>
		<pubDate>Thu, 20 Jan 2011 20:50:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-41540</guid>
		<description><![CDATA[Hi there, I think i will wait for your update! There&#039;s so many boxes in there and I dont really have a clue what I&#039;m doing :) Thankfully the REG changes have held, so it looks like I am rid of whatever did it in the first place. Fingers crossed .... thanks very much for this, my safeboot has been broken for a long time and I didnt know why, though I knew there had been virus activity.]]></description>
		<content:encoded><![CDATA[<p>Hi there, I think i will wait for your update! There&#8217;s so many boxes in there and I dont really have a clue what I&#8217;m doing <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Thankfully the REG changes have held, so it looks like I am rid of whatever did it in the first place. Fingers crossed &#8230;. thanks very much for this, my safeboot has been broken for a long time and I didnt know why, though I knew there had been virus activity.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-41537</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Thu, 20 Jan 2011 09:03:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-41537</guid>
		<description><![CDATA[@Ross I plan to update my tool to change the permissions of the existing key too. But meanwhile, you can use regedit, find the SafeBoot key, right-click permissions, select advanced and change the permissions for system and administrators.]]></description>
		<content:encoded><![CDATA[<p>@Ross I plan to update my tool to change the permissions of the existing key too. But meanwhile, you can use regedit, find the SafeBoot key, right-click permissions, select advanced and change the permissions for system and administrators.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-41534</link>
		<dc:creator><![CDATA[Ross]]></dc:creator>
		<pubDate>Thu, 20 Jan 2011 00:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-41534</guid>
		<description><![CDATA[Hi there - can you provide a link or some further information on how to change the permissions manually? I indeed had my keys deleted by a virus, I dont know how long its been like that. Thankfuly your other program (the .REG zip file) has restored them, but I would also like the added protection of knowing they cannot be changed again - if possible please :D Many thanks]]></description>
		<content:encoded><![CDATA[<p>Hi there &#8211; can you provide a link or some further information on how to change the permissions manually? I indeed had my keys deleted by a virus, I dont know how long its been like that. Thankfuly your other program (the .REG zip file) has restored them, but I would also like the added protection of knowing they cannot be changed again &#8211; if possible please <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  Many thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-40209</link>
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Fri, 08 Oct 2010 18:03:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-40209</guid>
		<description><![CDATA[Had a problem where SafeBoot registry keys were modified by malware.... I found and deleted the bad keys and I could see the original or &quot;normal&quot; SafeBoot keys in the backups of the ControlSet section, but I still could not log in in Safe Mode, if I tried to search for the SafeBoot key using the Regedit Find option none would be found.... Ended up merging one of the REG files you provided and solved the issue and Safe Mode is working again. Until now I cannot understand why I would see/find the regkeys by &quot;hand&quot; amd the Find option could not....

John.]]></description>
		<content:encoded><![CDATA[<p>Had a problem where SafeBoot registry keys were modified by malware&#8230;. I found and deleted the bad keys and I could see the original or &#8220;normal&#8221; SafeBoot keys in the backups of the ControlSet section, but I still could not log in in Safe Mode, if I tried to search for the SafeBoot key using the Regedit Find option none would be found&#8230;. Ended up merging one of the REG files you provided and solved the issue and Safe Mode is working again. Until now I cannot understand why I would see/find the regkeys by &#8220;hand&#8221; amd the Find option could not&#8230;.</p>
<p>John.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-40087</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 27 Sep 2010 19:14:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-40087</guid>
		<description><![CDATA[@tkocsir Take a look at the source code, it&#039;s rather simple. All the .reg files I&#039;ve are in the ZIP file.]]></description>
		<content:encoded><![CDATA[<p>@tkocsir Take a look at the source code, it&#8217;s rather simple. All the .reg files I&#8217;ve are in the ZIP file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tkocsir</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-40079</link>
		<dc:creator><![CDATA[tkocsir]]></dc:creator>
		<pubDate>Mon, 27 Sep 2010 14:36:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-40079</guid>
		<description><![CDATA[Hi!
I found this blog in these days and I think it is very helpful! But I need more info about what your program exactly does, because I want to do the same in an AutoIT script (with setacl.exe).

And another question: do you have .reg files for restoring safeboot for Vista and Windows 7?

Thank you for your work
Thomas]]></description>
		<content:encoded><![CDATA[<p>Hi!<br />
I found this blog in these days and I think it is very helpful! But I need more info about what your program exactly does, because I want to do the same in an AutoIT script (with setacl.exe).</p>
<p>And another question: do you have .reg files for restoring safeboot for Vista and Windows 7?</p>
<p>Thank you for your work<br />
Thomas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-39745</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Fri, 03 Sep 2010 09:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-39745</guid>
		<description><![CDATA[@Peter Just like it is shown in the screenshot: I add an ACE to deny Administrator and System accounts the right to delete the key.]]></description>
		<content:encoded><![CDATA[<p>@Peter Just like it is shown in the screenshot: I add an ACE to deny Administrator and System accounts the right to delete the key.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-39732</link>
		<dc:creator><![CDATA[Peter]]></dc:creator>
		<pubDate>Thu, 02 Sep 2010 06:16:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-39732</guid>
		<description><![CDATA[Can you please show more detail on what has been included in your special permissions for the administrator and system? 

I had a problem booting in Safemode after being infected with Antivirus 2010, and managed to sort it by deleting the existing Safeboot .REG (I tried to delete the whole folder and got an error saying not possible, and though the reg file was deleted it was immediately repopulated) and then ran the appropriate .REG exe provided on this site (many thanks for this!). After successfully booting in Safemode to run Malwarebytes (which detected and deleted certain REG files and .EXEs) I was asked to restart my computer... however after rebooting into normal Windows the problem remained, and when I went to restart back into Safemode the malware was obviously back up to its old tricks because I could no longer boot in Safemode!

I have just begun to repeat the process for a second time, but wondered if you could advise what permission levels to set to avoid this problem being repeated.

Hope that makes sense,

Many thanks for your help.]]></description>
		<content:encoded><![CDATA[<p>Can you please show more detail on what has been included in your special permissions for the administrator and system? </p>
<p>I had a problem booting in Safemode after being infected with Antivirus 2010, and managed to sort it by deleting the existing Safeboot .REG (I tried to delete the whole folder and got an error saying not possible, and though the reg file was deleted it was immediately repopulated) and then ran the appropriate .REG exe provided on this site (many thanks for this!). After successfully booting in Safemode to run Malwarebytes (which detected and deleted certain REG files and .EXEs) I was asked to restart my computer&#8230; however after rebooting into normal Windows the problem remained, and when I went to restart back into Safemode the malware was obviously back up to its old tricks because I could no longer boot in Safemode!</p>
<p>I have just begun to repeat the process for a second time, but wondered if you could advise what permission levels to set to avoid this problem being repeated.</p>
<p>Hope that makes sense,</p>
<p>Many thanks for your help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: İnatçı virüslerden kurtulun! &#124; Çaylak Bilişimci</title>
		<link>http://blog.didierstevens.com/2010/01/01/the-undeletable-safeboot-key/#comment-38641</link>
		<dc:creator><![CDATA[İnatçı virüslerden kurtulun! &#124; Çaylak Bilişimci]]></dc:creator>
		<pubDate>Mon, 24 May 2010 19:08:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1908#comment-38641</guid>
		<description><![CDATA[[...] UndeletableSafeBootKey  Güvenli modun farklı bir [...]]]></description>
		<content:encoded><![CDATA[<p>[...] UndeletableSafeBootKey  Güvenli modun farklı bir [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

