Jump to content

Welcome to MSFN Forum
Register now to gain access to all of our features. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more. This message will be removed once you have signed in.
Login to Account Create an Account



Photo

What to use instead of NTREGOPT?


  • Please log in to reply
5 replies to this topic

#1
bizzybody

bizzybody

    Advanced Member

  • Member
  • PipPipPip
  • 367 posts
  • Joined 08-May 05

It appears that some recent "security" update to Windows 7 was aimed squarely at blocking good old NTREGOPT from being able to access the Registry.

 

I disabled Avast and turned off UAC and ran ntregopt as Administrator, while logged in with an account with administrator rights. No go, it's still completely blocked.

 

Is there another utility, free of ads and nags for $ for a "pro" version that does the same thing as ntregopt, but hasn't been blocked by Microsoft and anti-virus/malware?




How to remove advertisement from MSFN

#2
dencorso

dencorso

    Iuvat plus qui nihil obstat

  • Supervisor
  • 5,804 posts
  • Joined 07-April 07
  • OS:98SE
  • Country: Country Flag

Donator

Try to run NTREGOPT as the "Trusted Installer", instead of as Administrator.



#3
bizzybody

bizzybody

    Advanced Member

  • Member
  • PipPipPip
  • 367 posts
  • Joined 08-May 05

Not working. I got the runassystem and runastoken and the SetACL and the batch file to change the CLSIDs just sits there doing nothing after displaying its first line.

http://vorck.com/windows/ntauth.html

Edit: removed the -silent options and now it's visibly doing things...

Edit2: Still going, repeatedly saying setacl finished successfully

Edit3: Oh F this. Been running that batch file for about 45 minutes.

 

I put the runas and set acl exes in the same folder as ntregopt. When I run this batch file from an elevated command prompt, it stops and starts trusted installer then flashes another window and quits.

net stop trustedinstaller
net start trustedinstaller
runassystem64.exe "runfromtoken64.exe trustedinstaller.exe ntregopt.exe"
@ECHO OFF
ECHO Processing CLSID permissions
REM SET SETACLX64=C:\windows\system32\setaclx64.exe
FOR /F "tokens=1,2,3,4,5 delims=\" %%A IN ('REG.EXE query HKLM\SOFTWARE\Classes\CLSID\') DO (
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E" -ot reg -actn setowner -ownr "n:S-1-5-32-544;s:y" -rec yes -silent
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E" -ot reg -actn ace -ace "n:S-1-5-32-544;p:full;s:y;i:so,sc;m:set;w:dacl" -rec yes -silent
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E" -ot reg -actn ace -ace "n:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464;p:full;s:y;i:so,sc;m:revoke;w:dacl" -rec yes -silent
)

FOR /F "tokens=1,2,3,4,5 delims=\" %%A IN ('REG.EXE query HKCR\CLSID\') DO (
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E" -ot reg -actn setowner -ownr "n:S-1-5-32-544;s:y" -rec yes -silent
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E" -ot reg -actn ace -ace "n:S-1-5-32-544;p:full;s:y;i:so,sc;m:set;w:dacl" -rec yes -silent
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E" -ot reg -actn ace -ace "n:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464;p:full;s:y;i:so,sc;m:revoke;w:dacl" -rec yes -silent
)

FOR /F "tokens=1,2,3,4,5,6 delims=\" %%A IN ('REG.EXE query HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\') DO (
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E\%%F" -ot reg -actn setowner -ownr "n:S-1-5-32-544;s:y" -rec yes -silent
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E\%%F" -ot reg -actn ace -ace "n:S-1-5-32-544;p:full;s:y;i:so,sc;m:set;w:dacl" -rec yes -silent
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E\%%F" -ot reg -actn ace -ace "n:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464;p:full;s:y;i:so,sc;m:revoke;w:dacl" -rec yes -silent
)

FOR /F "tokens=1,2,3,4,5,6 delims=\" %%A IN ('REG.EXE query HKCR\Wow6432Node\CLSID\') DO (
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E\%%F" -ot reg -actn setowner -ownr "n:S-1-5-32-544;s:y" -rec yes -silent
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E\%%F" -ot reg -actn ace -ace "n:S-1-5-32-544;p:full;s:y;i:so,sc;m:set;w:dacl" -rec yes -silent
    SETACLX64 -on "%%A\%%B\%%C\%%D\%%E\%%F" -ot reg -actn ace -ace "n:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464;p:full;s:y;i:so,sc;m:revoke;w:dacl" -rec yes -silent
)

ECHO Complete

Edited by bizzybody, 01 May 2015 - 03:05 AM.


#4
jaclaz

jaclaz

    The Finder

  • Developer
  • 15,345 posts
  • Joined 23-July 04
  • OS:none specified
  • Country: Country Flag

Wait a minute.
 
Try EXACTLY the example given by Joakim
http://reboot.pro/fi...d-runfromtoken/
 
 

On one of my systems I have this simpel batch on my desktop to get quick access to my special power cmd:
 

net start trustedinstaller
C:\windows\system32\runassystem_x64 "C:\windows\system32\runfromtoken_x64 trustedinstaller.exe 1 cmd"

 

 
jaclaz



#5
cannie

cannie

    Advanced Member

  • Member
  • PipPipPip
  • 464 posts
  • Joined 04-June 08
  • OS:Windows 7 x86
  • Country: Country Flag

I use since long ago the freeware "Wise Registry Cleanerfor the same purpose. You may try it. Maybe it would be enough for your needs.

 

HTH


Edited by cannie, 01 May 2015 - 03:51 PM.


#6
xpclient

xpclient

    XP was my idea. 3rd party apps make NT6 my idea.

  • Member
  • PipPipPip
  • 340 posts
  • Joined 30-July 05
  • OS:XP Pro x64
  • Country: Country Flag

Sad. Thankfully ERUNT still works!!


Edited by xpclient, Yesterday, 08:53 PM.

Impossible to run NT6 without third party fixes.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users