Author Topic: WIN XP PROBLEMS RUNNIG REGEDIT  (Read 4385 times)

0 Members and 1 Guest are viewing this topic.

jann

  • Guest
WIN XP PROBLEMS RUNNIG REGEDIT
« on: October 04, 2004, 11:39:08 AM »
I CANNOT OPEN REGEDIT, OR RUN MSCONFIG FROM THE RUN COMMAND. I SUSPECT A VIRUS, BUT EVERY SCAN PROOF NEGATIVE.
PLEASE HELP.
VIRUSSES WERE FOUND BUT WAS DELETED.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:WIN XP PROBLEMS RUNNIG REGEDIT
« Reply #1 on: October 04, 2004, 12:48:17 PM »
Follow the instructions on the page in my signature, instead of a full system scan under windows do a boottime scan. Let us know if that solved it or not.

Or you can login as ADMINISTRATOR, and use the policy editer to restore the user/group rights to use regedit and remove the infection while logged in as administrator.

This is the same behaviour that is caused by some malware. This same malware disables av scanners, so it looks clean, but the system is not.
« Last Edit: October 06, 2004, 04:33:29 PM by Eddy »

r4v3n

  • Guest
Re:WIN XP PROBLEMS RUNNIG REGEDIT
« Reply #2 on: October 06, 2004, 02:27:01 PM »
Hello,

If you are not able to open regedit.exe, try renaming regedit.exe to regedit.bat and then open it.
In order to view and change the extensions, the "Hide extensions for known file types" options should be disabled in explorer.
Also, if you are unable to open taskmanager, try googling for Nirsoft's cprocess utility. This is better than taskmanager, since it gets a better handle over the processes than the taskmanager does. This tool will show you all the processes running and just kill the malicious one. You'll be able to identify the malicious easily.

Thanks

Raven

netplus

  • Guest
Re:WIN XP PROBLEMS RUNNIG REGEDIT
« Reply #3 on: October 30, 2004, 11:48:40 PM »
boot in safe mode.
run regedit and go to HKLM.Software/microsoft/windows/currentversion/run key and look for bsplayer
If it is there delete the entry.
Also look in the run once key

exit regedit search for bsplayer and delete from your harddrive.