Re: System Restore

From: Rick \ (rick_at_mvps.org)
Date: 11/07/04


Date: Sun, 7 Nov 2004 16:11:54 -0500

Hi,

Click start/run, type regedit and click ok. Export a copy of the following
keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

Right click each of the keys in turn, choose edit. Then copy/paste the
contents of each into a reply.

-- 
Best of Luck,
Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org
"Fishslayer" <Fishslayer@discussions.microsoft.com> wrote in message 
news:79509126-54F3-4BE7-AA44-816256910071@microsoft.com...
> I finally managed to get in as the Adminisitrator!!  I ran the Stinger,
> under the repair option, and rebooted my computer.  Nothing has really
> changed.  When I go into Outlook, my email program immediately attempts to
> send 55 emails.  I don't know what else to do to get rid of the virus.
> McAfee is of little help!!  I've tried Spybot, Ad-Aware SE and Kapersky 
> virus
> removal programs to identify and disable the virus...but none seem to 
> work.
> Any programs that you would recommend?  Thanks for your help, it is much
> appreciated!!
>
> "Fishslayer" wrote:
>
>> Thanks "Nutcase".  I downloaded the Stinger program, but it is under my
>> username, and not the Administrator.  When I try to get into safemode, I 
>> keep
>> getting a "Key Board Failure" which won't allow me to type in the 
>> password as
>> the Administrator.  I can get into Safe Mode...just not as the 
>> Administrator,
>> and the Stinger tool is not listed as one of the programs from which to
>> choose.  Any suggestions?  This is frustrating!!
>>
>> "Rick "Nutcase" Rogers" wrote:
>>
>> > Hi,
>> >
>> > If the restore points are infected, then going back is pointless. If 
>> > they
>> > are corrupted and System Restore fails, then there is no going back.
>> >
>> > Suggest instead you download stinger from 
>> > http://vil.nai.com/vil/stinger/
>> > and then restart in Safe mode. Logon as administrator, then run the 
>> > file
>> > where it won't be interfered with by the virus.
>> >
>> > How to start in Safe mode:
>> > http://www.rickrogers.org/fixes.htm#Safe%20mode
>> >
>> > -- 
>> > Best of Luck,
>> >
>> > Rick Rogers, aka "Nutcase" - Microsoft MVP
>> > http://mvp.support.microsoft.com/
>> > Associate Expert - WindowsXP Expert Zone
>> > www.microsoft.com/windowsxp/expertzone
>> > Windows help - www.rickrogers.org
>> >
>> > "Fishslayer" <Fishslayer@discussions.microsoft.com> wrote in message
>> > news:5ADB18F6-2135-4931-BEB0-606930AD5D2D@microsoft.com...
>> > >I can't go back in time with system restore due to a trojan/virus/worm 
>> > >that
>> > > has infected my computer.  McAfee can't seem to identify/remove the 
>> > > virus
>> > > and
>> > > I'd like to go back in time to a previous setting.  Help please. 
>> > > Thanks
>> >
>> >
>> > 


Relevant Pages

  • Re: System Restore
    ... I ran the Stinger, ... I don't know what else to do to get rid of the virus. ... > username, and not the Administrator. ... >> are corrupted and System Restore fails, then there is no going back. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Non admin users cant do things they need to do
    ... i added the keys below to the registry (as administrator) logged off, ... can set the time then they can fake out system event logs by changing ...
    (microsoft.public.windowsxp.embedded)
  • Re: Non admin users cant do things they need to do
    ... You mean they are along with the registry entires? ... i added the keys below to the registry (as administrator) logged off, ... can set the time then they can fake out system event logs by changing ...
    (microsoft.public.windowsxp.embedded)
  • Re: Behavior of Randex variant.
    ... rather than a virus. ... However, the very next boot up, same ... >>> I first saw the problem on a Dell Laptop running Win2000. ... >>> "regedlt.exe" keys, and it will boot up normally. ...
    (microsoft.public.security.virus)
  • Re: 0x80070005 / _Inventory: Installer returned 0x5 (5)
    ... Are you the Administrator? ... Access Denied is a hard one to determine where the keys are failing - ... Use an account that has administrative credentials to log on to the Windows XP ... Navigate to the following key in the registry: ...
    (microsoft.public.windowsupdate)