Re: Run-Msconfig and Run-Regedit

From: Malke (malke_at_nospoonnotreally.com)
Date: 11/26/04


Date: Thu, 25 Nov 2004 17:35:42 -0800

Bowdrie wrote:

> I have been attempting remove a virus W32.Spybot.Worm from my Windows
> XP in
> accord with the Symantec removal instructions. During the removal
> process I need to use Start-Run-msconfig (to restart in Safe Mode) and
> later, also Start-Run-regedit (in order to open the Registry Editor
> and delete values the
> virus may have created). In both cases the desired window opens but
> immediately goes away. I thought my wireless network connection may
> have
> something to do with it, and disabled it, but the situation continues.
> Any ideas how to make these windows stay open so I can work in them?
> Thank You.

You need to clean the computer first. Disconnect the infected computer
from the Internet and any lan. From a different, known-clean computer
(that was not on the same network as the infected computers) with a cd
burner, get Sysclean. You will download it, burn it to cd-r, and take
it to the infected computer.

TrendMicro's Sysclean is an extensive antivirus tool which has the
advantage of not needing to be installed. It requires two parts - the
scanning engine and the virus pattern files.

1. Create a new folder on your Desktop or the C: drive named something
useful like "Sysclean".
2. Go here and download the two parts of the program to that folder:

http://www.trendmicro.com/download/dcs.asp - Sysclean
http://www.trendmicro.com/download/pattern.asp - virus pattern files

The pattern files will be zipped - extract them with your unzipper (like
WinZip) or if you have XP, you can just open the folder. You need to
put the extracted files in the Sysclean folder you made.

3. Restart your computer in Safe Mode. Get into Safe Mode by repeatedly
tapping the F8 key as the computer is starting up to get to the proper
menu.
4. Go to the Sysclean folder you made and double-click on sysclean.com.
Start the scan. After the scan is finished, look at the log. You may
need to make a note of where any viruses were found if they were not
able to be removed so you can manually delete them.

After running Sysclean, install a full-featured antivirus such as EZ-AV
from http://www.my-etrust.com/microsoft. Before you connect to the
Internet to update its virus definitions, make sure you have a firewall
in place. Update the av and do a full system scan with it in Safe Mode.

Malke

-- 
MS-MVP Windows User/Shell
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"


Relevant Pages

  • Re: Problem with IE and programs
    ... > Can not reach system restore either, as it is blank as well. ... TrendMicro's Sysclean is an extensive antivirus tool which has the ... scanning engine and the virus pattern files. ... Go here and download the two parts of the program to that folder: ...
    (microsoft.public.windowsxp.general)
  • Re: Virus found
    ... TrendMicro's Sysclean is an extensive antivirus tool which has the ... scanning engine and the virus pattern files. ... Create a new folder on your Desktop or the C: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: x box dill incompatible
    ... I DOWNLOADED BATA VIRUS SCAN FROM MICROSOLT ... THE COMPUTER RAN LIKE A RACE HORSE BUT THE TAX ... If you do not have av installed, first run Sysclean (after deleting ... Create a new folder on your Desktop or the C: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: virus problem
    ... > prompts me to this virus but cannot delete it. ... *not* contained only in System Restore points. ... Mode with TrendMicro's Sysclean: ... Create a new folder on your Desktop or the C: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Trojan.Tooso.B Patch
    ... Since the Symantec article says that this virus disables av software, ... TrendMicro's Sysclean is an extensive antivirus tool which has the ... scanning engine and the virus pattern files. ... Create a new folder on your Desktop or the C: ...
    (microsoft.public.security.virus)