PDA

View Full Version : registry problem



seagoon
18th January 2007, 12:58
I want to scan the registry of an xp home machine using cmd sfc/scannow but if I type either in the run box I get this is not a win32 application. I can access the registry via c:\windows\registry but cannot scan. Any ideas anyone. I have virus checked the machine with just about anything I could get my hands on and it now comes up clean but the regedit problem persists.

GlosRFC
18th January 2007, 13:42
Can't linger as I have to go out but it sounds like you have another executable version of registry on your HD - probably installed as part of a virus attack. Do a search for regedit and see what it comes up with. You should only have regedit.exe in your Windows directory, plus some help files in the Windows\Help directory, and probably a backup copy in your Windows\$NtServicePackUninstall$ directory. If you find any others (particularly registry.com) you'll need to quarantine these and see if it then works.

GlosRFC
18th January 2007, 18:15
Back now :)

Right, I've had a bit more time to think about this and I'm pretty convinced that you've got another version of regedit lurking on your PC somewhere, particularly as you say that you can run regedit normally.

Have you tried Start, Run, Regedit.exe? If that works normally, then you definitely have a file called regedit.com installed somewhere. The difficulty will be locating exactly where it's hidden. See if you can do the following?

Click Start, Run
Type cmd.exe and a Command Prompt window should open.

Now copy the next line using ctrl+c
dir /s /a "c:\regedit*.*" > c:\find.txt & start notepad c:\find.txt
Next, paste that line into the Command window by right-clicking and selecting the paste option - note that the normal Windows cut/paste shortcut keys won't work here! If you can't paste it, then type it into the Command window but take special note of all the punctuation and the directions of the / and \ keys.

Press the enter key and let it run. It should scan your entire hard disk for all regedit files, append the details of these files into a small text file called find.txt, and then open up Notepad so you can see the results. Depending on your HD size it may take a couple of minutes to run - you'll know when it's finished when the Notepad window opens up or, if it doesn't, when the prompt reappears in the Command window.

Check the contents of this file - as I said, you're probably looking for a file called regedit.com - if that's the case we can then consider how to remove it.

vegyjones
18th January 2007, 18:34
Not that I am nosey.

But where did you have to go ? :D

mathare
18th January 2007, 18:41
Not that I am nosey.

But where did you have to go ? :DHe went to ::hump your wife :yikes:

vegyjones
18th January 2007, 18:43
But he was only gone 4 hours? :doh

GlosRFC
18th January 2007, 19:31
If you must know, I had to go and get some bedding for Flash. I'll ask your permission next time!

John
18th January 2007, 20:02
Bedding for Flash?

Quoi? :doh

mathare
18th January 2007, 21:17
Bedding for Flash?

Quoi? :dohI assume this is the pet Flash, not Flash as in the animation software. Or the quarterback from the camp classic with Max Von Sydow and Peter Duncan and a load of nobodies.

GlosRFC
18th January 2007, 21:35
Your first guess is correct

John
18th January 2007, 22:06
Gee there's no stopping you. :D

vegyjones
18th January 2007, 22:42
I'll ask your permission next time!

I think that's wise! :D

GlosRFC
19th January 2007, 01:23
I assume this is the pet Flash, not Flash as in the animation software. Or the quarterback from the camp classic with Max Von Sydow and Peter Duncan and a load of nobodies.

Brian Blessed, Timothy Dalton, Topol and Richard O'Brien are nobody's?

Win2Win
19th January 2007, 10:08
Nice pic......go well with rice.....:yikes:

sparkyminer
19th January 2007, 10:23
Flash isn't purple.:yikes: :D

mathare
19th January 2007, 10:46
Brian Blessed, Timothy Dalton, Topol and Richard O'Brien are nobody's?Ok, OK. I'll give you Brian Blessed. A failed James Bond and the bloke off of Crystal Maze though? Seriously.

vegyjones
19th January 2007, 10:49
Richard O'Brien...a man of many talents,

and you refer to him as"the bloke off of Crystal Maze" :ermmm Disgraceful!

mathare
19th January 2007, 10:53
Richard O'Brien...a man of many talents,

and you refer to him as"the bloke off of Crystal Maze" :ermmm Disgraceful!Sorry, very disrespectful of me.

I did of course mean the slaphead bloke off of Crystal Maze, not the one who was a one hit wonder in the 80s

seagoon
19th January 2007, 20:55
nice piccie of flash. the big problem I'm having is not being able to type cmd or regedit in the run command window. I agree it must be a virus at the bottom of it. I also dicovered there was no system32 folder but when I try to make one it says it already exists. a file and folder search comes up blank.
Don't you just hate kids who remove virus protection so they can get at cracks.::swear ::swear ::swear

GlosRFC
19th January 2007, 23:59
If you type regedit.exe in the run command window does it work? Even though you can't run cmd, you should also be able to open a command prompt window by clicking on Start, Accessories. If that still doesn't work, you'll need to restart Windows in safe mode and enter the dos instructions manually.

You will also have a system32 folder but I suspect the attributes have been set to hidden so you can't see it displayed. And a file/folder search will come up blank which is why you need to run the dos command I highlighted above. Then you'll be able to tell where the unwanted regedit.com file is hidden - almost certainly in the hidden system32 folder.

seagoon
20th January 2007, 22:59
cannot type cmd or regedit in run box in xp normal or safe mode.. as you say the system 32 must be hidden so I will try to un hide it and see what happens. many thanks for your advice so far. it all helps when you feel you are just banging your head against the wall.:D

GlosRFC
20th January 2007, 23:11
Can you get to a dos prompt through Start, Programs, Accessories?

Also, you'll need to type regedit.EXE and not just regedit - if you do have the regedit.com file in your root path, it will take precedence so you must try it with the exe file extension.

You can also get to a dos prompt by rebooting your PC and pressing the F8 key and selecting the dos option from there.

seagoon
21st January 2007, 14:13
spot on glosrfc I am in and running the scan right now. ta VERY mucn:Helooo :Helooo :Helooo