Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

Skip to comments.

Help Vanity: Fixing damage from Virus (can't access Regedit)
geronl

Posted on 12/23/2011 11:13:55 AM PST by GeronL

I have kind of done this before. I have been working to delete a virus all morning on this borrowed computer. I think I have succeeded in the main.

The problem is the virus did cause some problems. Some exe files will not execute. It is probably a registry value that has been changed.

This is a BORROWED computer. I was using it when it apparently got infected. So I have a duty to fix this.

It an an EEPC netbook running Windows XP.

So the registry value at exe in the command line should be what?

SO how do I get access to the registry since Regedit an exe file?


TOPICS: Chit/Chat; Computers/Internet
KEYWORDS: computerhelp; computerproblem; regedit; techhelp; virus
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 101-114 next last
To: GeronL

Assuming you have rebooted —

Depending on the virus, it my have destroyed part of the original .exe files.

If so, you might try a system restore from a time previous to your getting the virus.

Otherwise, you may have to re-install those programs.


21 posted on 12/23/2011 11:37:23 AM PST by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: GeronL

Can you open Malware Bytes in safe mode? If you can - and find someting - run it a few more times. Could be tentacles...


22 posted on 12/23/2011 11:38:30 AM PST by GOPJ (Better is a dinner of herbs where love is, Than a fatted calf with hatred - Proverbs 15)
[ Post Reply | Private Reply | To 2 | View Replies]

To: TomGuy

If you don’t hear back from me in an hour, I goofed up big time. oops. heh.


23 posted on 12/23/2011 11:47:50 AM PST by GeronL (The Right to Life came before the Right to Pursue Happiness)
[ Post Reply | Private Reply | To 21 | View Replies]

To: cynwoody; smokingfrog

I downloaded something called “regeditfix” and it seems to have fixed that particular problem. Now to run Malwarebytes!


24 posted on 12/23/2011 11:53:09 AM PST by GeronL (The Right to Life came before the Right to Pursue Happiness)
[ Post Reply | Private Reply | To 20 | View Replies]

To: GeronL

http://www.dougknox.com/xp/file_assoc.htm

Try this, or go to the root dougknox.com


25 posted on 12/23/2011 11:58:49 AM PST by FastCoyote (I am intolerant of the intolerable.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: GOPJ

There must be more parts to the virus than I thought. It was preventing Malware bytes from running and slowing everything down.

It was called ping.exe in the Task Manager.


26 posted on 12/23/2011 12:04:59 PM PST by GeronL (The Right to Life came before the Right to Pursue Happiness)
[ Post Reply | Private Reply | To 22 | View Replies]

To: FastCoyote

Drop rkill to your computer. Run it. It will stop all processes.

Download a temp version of Kaspersky.

Run kaspersky. That should get rid of it. Malwarebytes will coat some bucks.

If the puter is borrowed you are not going to want to spend money on it.


27 posted on 12/23/2011 12:08:13 PM PST by EQAndyBuzz (Control the media, you control its citizens.)
[ Post Reply | Private Reply | To 25 | View Replies]

To: GeronL

Try CCleaner:

http://www.piriform.com/ccleaner/download


28 posted on 12/23/2011 12:16:44 PM PST by Red Badger (Every child should have a meadow to play in..............)
[ Post Reply | Private Reply | To 1 | View Replies]

To: GeronL

AVAST (Free) has a boot time scanner, it worked for me on a nasty little virus which, wouldn’t let me access command prompt, took all my desktop icons, etc. this was on a Win7 machine. Assuming you can download it, give it a shot.

Hope this helps.


29 posted on 12/23/2011 12:17:04 PM PST by ConservativeChris
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeChris

BTW regular scan DID NOT catch virus, only “boot time scan” worked.


30 posted on 12/23/2011 12:19:24 PM PST by ConservativeChris
[ Post Reply | Private Reply | To 29 | View Replies]

To: time4good; GeronL
If you have access to the internet, google ‘bleepingcomputer.com combofix download’ and download Combofix.exe. Ignore the hype on it itself being a virus. THE best one-shot program I’ve used countless times on my own and client computers to find and slit the throat of nasty viruses. Put it on a memory stick, boot into Safe Mode (safe with networking if it works) and from the command prompt run it.

It will take about 20 minutes. Ignore the parts about antivirus installed or running in Recovery Console mode.

Has worked for me 99.8% of the time. (Can’t remember the .02% instance)


time4good,
Thanks for the info.

I used instructions from bleeping computer to remove 'Antivir Solution Pro' - the only time I have been virused; saved having to wipe disk and start from scratch.

Since I was using FireFox not IE as a browser, I was able to access the internet and download the necessary tools. It was one nasty virus that infected the registry and prevented me from running registry restore.
31 posted on 12/23/2011 12:19:25 PM PST by algernonpj (He who pays the piper . . .)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Red Badger; ConservativeChris; GOPJ

Seems to have worked good ‘nuff.

I wonder if there isn’t a couple of monitoring and logging files left from the virus though.

Guess I can run Malware Bytes again to make sure.


32 posted on 12/23/2011 12:25:41 PM PST by GeronL (The Right to Life came before the Right to Pursue Happiness)
[ Post Reply | Private Reply | To 28 | View Replies]

To: GeronL

You can mess with it by finding ping.exe, and replacing it with an empty file named ping.exe. Mark it read-only.


33 posted on 12/23/2011 12:26:00 PM PST by tacticalogic ("Oh, bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: GeronL

When you do CCleaner’s Registry Cleaner, you need to run it TWICE.

Once to initially clean it, then again to see if it missed anything the first time. It sometimes does...............


34 posted on 12/23/2011 12:28:56 PM PST by Red Badger (Every child should have a meadow to play in..............)
[ Post Reply | Private Reply | To 32 | View Replies]

To: tacticalogic

There is also a system file named ping.exe thats been here since March 2008.

The problem one is apparently a temporary file created by ANOTHER program. dang.


35 posted on 12/23/2011 12:51:47 PM PST by GeronL (The Right to Life came before the Right to Pursue Happiness)
[ Post Reply | Private Reply | To 33 | View Replies]

To: GeronL
The problem one is apparently a temporary file created by ANOTHER program. dang.

That's why you want to leave an empty file in it's place, and make it read only.

Once you do that, whatever is launching it will still find the file where it's expecting it, but it won't run. If whatever is creating tries to create a new one, it will fail because there's already a file there by that name. Making it read-only prevents it from being overwritten by the other program. It may start throwing an error that will tell you what the name of the program that tried to create it is.

36 posted on 12/23/2011 1:12:39 PM PST by tacticalogic ("Oh, bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: GeronL

Someone else already stated this - but SYSTEM RESTORE

This will change the registry keys back to where they were before you got the virus.

I got bombarded one day after posting on a blog where the virus corrupted everything. I had a terrible time getting into any system files. I was even unable to do a system restore from my desktop. I had to run it in safe mode and killed the little bugger instantly and restored everything back to an earlier time. It’s my best friend!


37 posted on 12/23/2011 1:16:01 PM PST by jcsjcm (This country was built on exceptionalism and individualism. In God we Trust - Laus Deo)
[ Post Reply | Private Reply | To 1 | View Replies]

To: GeronL
Someone needs to post that “Macs don't get viruses”; just to keep the thread interesting.
38 posted on 12/23/2011 1:18:06 PM PST by HereInTheHeartland (I love how the FR spellchecker doesn't recognize the word "Obama")
[ Post Reply | Private Reply | To 1 | View Replies]

To: tacticalogic; jcsjcm

Thanks guys


39 posted on 12/23/2011 1:27:07 PM PST by GeronL (The Right to Life came before the Right to Pursue Happiness)
[ Post Reply | Private Reply | To 36 | View Replies]

To: tacticalogic

The actual name of the file is PING.EXE-31216D26.pf and it is located in the Wondows “Prefetch” folder. I am not sure what file is creating it, but I guess we should see.


40 posted on 12/23/2011 2:22:28 PM PST by GeronL (The Right to Life came before the Right to Pursue Happiness)
[ Post Reply | Private Reply | To 36 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 101-114 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson