Re: REGEDIT Disappears

From: Rick \ (rick_at_mvps.org)
Date: 10/02/04


Date: Sat, 2 Oct 2004 07:25:37 -0400

The virus is masking itself from Norton's, this is not uncommon. I would
recommend at this point that you download stinger from
http://vil.nai.com/vil/stinger/ and then reboot into safe mode to run it
(running it in normal mode will not be effective, you need to have the
system bypass the startup group that is loading the virus). Also disable
System Restore to purge the restore points that will have a copy of the
virus before restarting normally.

-- 
Best of Luck,
Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org
<anonymous@discussions.microsoft.com> wrote in message 
news:17d801c4a7ca$1da48490$a301280a@phx.gbl...
> Hi Sharon,
>
> Thanks for your suggestion of renaming regedit. I did
> that and it did the trick. It's my understanding from
> other responses that I've received concerning the
> disappearing regedit screen that worms and viruses most
> likely caused this problem in the 1st place. But I am
> confused because I have Norton live updates running and I
> scan 3 times a week and Norton rarely says its caught a
> virus. So I am not sure where to go and how to follow up.
> But at least for now, my original problem has been
> resolved. Thanks.
>>-----Original Message-----
>>On Fri, 1 Oct 2004 05:59:18 -0700, Alan Kauf-Stern wrote:
>>
>>> I had an earlier posting (9/28) concerning immediate
>>> logoff when logging onto to a user account on my Sony
>>> Windows XP Home Edition desktop. I was finally able to
>>> get to the Recovery Console as per suggestions and was
>>> able to copy the System32\userinit.exe to
> wsaupdater.exe,
>>> again per suggested instructions. Logons to the
> accounts
>>> is now possible - Great, but, there is always a but.
> In
>>> order to complete the instructions, I need to use
> REGEDIT
>>> to update the HKEY_LOCAL_MACHINE. Ok, there is the
>>> background. Now my problem is that when I invoke
> REGEDIT,
>>> the REGEDIT window appears, but it immediately
> disappears
>>> before I can do anything!!!!!! What's wrong? How can I
>>> stop this so that I can utilize REGEDIT? Thanks in
>>> advance. Alan
>>
>>It's not uncommon for malware to block the running of
> MSCONFIG, Task
>>Manager and the Registry Editor -thus making the removal
> of the intrusion
>>more difficult. If the system tools are blocked by name,
> renaming their
>>executables is a workaround. Example: Rename regedit.exe
> to regedit.com
>>
>>Or you can run the tool created by MVP Doug Knox that
> creates a "backup
>>set" of those three programs for you:
>>http://www.dougknox.com/xp/utils/xp_emerutils.htm
>>
>>-- 
>>Sharon F
>>MS-MVP ~ Windows XP Shell/User
>>.
>> 


Relevant Pages

  • Re: "Registry editing has been disabled by your admin"
    ... See www.dougknox.com, Win XP Utilities, Windows XP Security Console. ... > When trying to open regedit I receive the message: ... > This I'm fairly sure is the result of having foolishly acquired a virus ... > Pc Cillin has quarantined the infected files. ...
    (microsoft.public.windowsxp.general)
  • Re: I have the svchost.exe Virus
    ... > windows version of svchost by arent. ... Trace the virus with the online ... that very symptom with regedit. ...
    (microsoft.public.security.virus)
  • Re: regedit window stays open for a short time
    ... 2- Turned off system restore. ... No virus found. ... 6- Normal cold boot - Regedit closes by itself. ... program window are also copied to the Windows Clipboard, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Problems with XP Taskmanager and more....
    ... This behavior can be caused by a virus. ... Emergency Msconfig, Regedit, Task Manager ... 2004 Windows MVP "Winny" Award ...
    (microsoft.public.windowsxp.basics)
  • Re: Problems with XP Taskmanager and more....
    ... This behavior can be caused by a virus. ... Emergency Msconfig, Regedit, Task Manager ... 2004 Windows MVP "Winny" Award ...
    (microsoft.public.windowsxp.general)

Loading