Re: Unable to open regedit.exe or cmd.exe - conflicker?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Apr 15, 7:24 am, Al Falfa <anonym...@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote:
Sandiyan wrote:
On my home computer(XP sp3 with IE8), I am unable to start regedit.exe
or cmd.exe - when type these commands in start\run it doesn't bring the
app. Also, getting svchost error  - after connecting to isdn and in the
middle of surfing the internat. I can run services.msc and eventvwr.exe
though. I am assuming its a variant of conflicker? I run antivirus
product MS Onecare and am uptodate on updates and done a full scan using
onecare.
Searched on internet and some instructions to prevent virus requires you
modifying entries in regedit...if I cannot get regedit/cmd to work I am
in deeeeep trouble

Sandiyan,
 It may be enough to copy C:\WINDOWS\system32\cmd.exe to dmc.COM and
C:\WINDOWS\regedit.exe to editreg.COM in another folder. If not, then
get xp_emegencyutil.exe to create usable copies of REGEDIT, MSCONFIG
and Task Mgr fromhttp://www.dougknox.com/xp/utils/xp_emerutils.htm

 In editreg.COM or Copy_of_Regedit.com go to
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT
 \ CurrentVersion \ Image File Execution Options

 Look at any keys named cmd.exe, msconfig.exe, regedit.exe,
taskmgr.exe and delete any value name "Debugger".

Some viruses will recognize these commands you try to run, like
regedit, cmd, etc. and just not allow them to run based on their name
alone. They can also prevent you from going to sites that offer anti
virus programs, scans, etc. The virus knows about such important
programs and web sites because they were programmed to look for such
things and not let you do it.

Try making a copy of c:\windows\regedit.exe and call it c:\windows
\sandiyan.exe and see if you can run c:\windows\sandiyan.exe from
Start, Run. If that works, you have outsmarted the virus because it
doesn't know or care about sandiyan.exe, but you probably still have
the virus and now you must get rid of it.

Plus, in order to find a virus, malware, etc. the scanning program has
to know to look for it. That is what the definition/database files
are supposed to do. Not every scanning program is likely to know
about everything, so you might want to use a couple good ones. Maybe
you have a virus that your MS Onecare does not know about.

The Malwarebytes offering is popular here (and others) and is free,
but conficker is known to prevent you from going to anti virus sites
like that because it doesn't want you to be able to detect it. You
may have to boot in Safe Mode, or download it someplace else
temporarily... Many options.

Finally, be sure you keep up to date on the Microsoft updates,
especially the security ones.

Let us know what you find out.

.



Relevant Pages

  • Re: Virus: Downloader.Trojan
    ... Norton detected the virus as 230005.exe in Temporary Internet Files. ... commandline CD commands to navigate to the right location. ...
    (microsoft.public.security.virus)
  • Re: Virus: Downloader.Trojan
    ... >Norton detected the virus as 230005.exe in Temporary Internet Files. ... >commandline CD commands to navigate to the right location. ...
    (microsoft.public.security.virus)
  • Re: Save and Save As commands unavailable (dimmed)
    ... The disappearance of those commands often means either the presence of a virus, a damaged normal.dot file, or damaged registry entries. ... profile, if present, is affected. ...
    (microsoft.public.word.application.errors)
  • XP Pro noSP - Boots normal - Wont open applications
    ... Mouse or KB commands are followed by a few seconds of the ... it responds the same from the safe mode as it does ... virus of some sort since he allowed his Norton AV ... search skills are lacking. ...
    (microsoft.public.windowsxp.help_and_support)
  • Virus
    ... has diabled my Control panel, Regedit, Run, etc commands. ... It has also put a "Virus alert!" ...
    (microsoft.public.windowsxp.help_and_support)