Can't Run Regedit

C

Chuck Humphrey

When I try to run regedit the screen pops up for a fraction of a
second and then blinks off.

I have run Norton anti-virus and none are detected.
I have done a "repair" install of Windows XP and also revisited the
Microsoft Windows update site.

Help!?
Chuck Humphrey
 
R

Rick \Nutcase\ Rogers

Hi Chuck,

Your Norton virus definitions are out of date. This is a virus, and older
definitions will not catch it. Run Norton's update, then restart in Safe
mode and do a full system scan.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP

Associate Expert - WindowsXP Expert Zone

Windows help - www.rickrogers.org
 
C

Chuck Humphrey

I update NAV frequently. A recent check with "live update" shows that
there is nothing new to update. I have run a full NAV and I still
have the problem.

Yikes?!

Hi Chuck,

Your Norton virus definitions are out of date. This is a virus, and older
definitions will not catch it. Run Norton's update, then restart in Safe
mode and do a full system scan.

Chuck Humphrey
 
R

Rick \Nutcase\ Rogers

Quite possibly it's (the bug has) disabled the active scanner as well.
Restart in Safe mode, see if that allows regedit or task manager to open.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP

Associate Expert - WindowsXP Expert Zone

Windows help - www.rickrogers.org
 
C

Chuck Humphrey

Quite possibly it's (the bug has) disabled the active scanner as well.
Restart in Safe mode, see if that allows regedit or task manager to open.

Thanks for your help. I can run "regedit" in the safe mode. Can you
point me to advice as to how to enable the "active scanner," whatever
that may be. (As you can see I am among the unwashed:))

I am receiving messages once or twice a day that NAV has spotted
several different viruses. One is: Object name: c:\warpigs.exe
Virus Name: Backdoor.Hacarmy.C. The other is: Object name: c:\s.exe
Virus Name: W32.Spybot.Worm.

I have previously gone to the NAV website and followed the advice
there on removing the Backdoor trojan. The W32.Spybot worm is new and
I will now look at the NAV site to see what it has to say about that
one.

I previously found this Symantec article http://tinyurl.com/3y95t
but have not tried to follow its instructions pending finding out if
the solution is simpler.


Chuck Humphrey
 
R

Rick \Nutcase\ Rogers

Hi Chuck,

Have you tried running a full system scan while in Safe mode?

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP

Associate Expert - WindowsXP Expert Zone

Windows help - www.rickrogers.org
 
C

Chuck Humphrey

Yes. I have run two. The first time NAV removed a virus. The second
time, which was two days ago, I ran the full scan on my main c: drive
as well as on my backup e: external hard drive. Norton reported no
viruses found.

Hi Chuck,

Have you tried running a full system scan while in Safe mode?

Chuck Humphrey
 
R

Rick \Nutcase\ Rogers

Hi Chuck,

In Safe mode, start/run regedit. Expand the branches by clicking the + signs
and export (click on the key in the left pane, click file/export) a copy of
these three keys to the desktop (or some other location where you can easily
find them):

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

Then restart normally. Open a reply to this post. Right-click the first key,
select "edit". It will open in notepad. Click edit/select all/edit/copy. Go
to the reply, click in the message text area, hit ctrl+v to paste the
contents. Repeat for the other two keys. Send it.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP

Associate Expert - WindowsXP Expert Zone

Windows help - www.rickrogers.org
 
C

Chuck Humphrey

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINNT\\System32\\ctfmon.exe"
"H/PC Connection Agent"="\"C:\\Program Files\\Microsoft
ActiveSync\\WCESCOMM.EXE\""
"RoboForm"="\"C:\\Program Files\\Siber Systems\\AI
RoboForm\\RoboTaskBarIcon.exe\""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gateway Ink Monitor"="\"C:\\Program Files\\Gateway\\Gateway Ink
Monitor\\GWInkMonitor.exe\""
"NeroCheck"="C:\\WINNT\\System32\\NeroCheck.exe"
"IgfxTray"="C:\\WINNT\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINNT\\System32\\hkcmd.exe"
"PivotSoftware"="\"C:\\Program Files\\WinPortrait\\wpctrl.exe\""
"PaperPort PTD"="C:\\Program Files\\ScanSoft\\PaperPort\\pptd40nt.exe"
"IndexSearch"="C:\\Program
Files\\ScanSoft\\PaperPort\\IndexSearch.exe"
"QBCD Autorun"="D:\\autorun.exe restart QB_SEQUENCE first"
"siService.exe"="\"C:\\Program Files\\Sunbelt
Software\\iHateSpam\\siService.exe\""
"eClean"="C:\\Program Files\\eClean2000\\EClean.exe"
"MacLicense"="\"C:\\Program Files\\Conversions Plus\\MacLic.exe\""
"mmtask"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH
Jukebox\\mmtask.exe"
"UMonit"="E:\\Program Files\\xp_0781_8888\\UMonit.exe"
"RoxioDragToDisc"="\"C:\\Program Files\\Roxio\\Easy Media Creator
7\\Drag to Disc\\DrgToDsc.exe\""
"ftpqueue"="\"C:\\Program Files\\WS_FTP Pro\\ftpqueue.exe\" -tray"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\"
-atboottime"
"SM1BG"="E:\\WINNT\\DRIVERS\\SM1\\SM1bg.exe"
@=""
"OnfolioStorage"="C:\\Program Files\\Onfolio\\onfserv.exe nosignal"
"Zone Labs Client"="\"C:\\Program Files\\Zone
Labs\\ZoneAlarm\\zlclient.exe\""
"Winsock2 driver"="ZONEALARM.EXE"
"nod32kui"="\"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
There is no "startupreg" sub folder in this key.
Chuck Humphrey
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top