Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cannot load RegEdit, MSCONFIG, Taks Manager

Status
Not open for further replies.

Mike Lewis

Programmer
Jan 10, 2003
17,505
Scotland
I am using XP Pro SP1 on an IBM Thinkpad.

I've suddenly found that I can no longer load RegEdit or MSCONFIG. When I try, the program appears on the screen for about one second, and then disappears. The same thing happens when I hit Ctrl-Alt-Del to bring up the Task Manager.

This may be coincidence, but I have also recently become infected with two viruses: W32/Nachi-B and W32/Bobax-C. I have successfully removed these viruses (as far as I know), and I have seen nothing to suggest that these particular viruses cause the problem I have described. But I thought it would be relevant to mention it.

As far as I can see, all my other applications and utilities are working OK. Also, I am able to bring up REGEDIT and MSCONFIG if I boot to safe mode.

Hope someone can point me in the right direction.

Mike


Mike Lewis
Edinburgh, Scotland

My Visual Foxpro web site: My Crystal Reports web site:
 
What are Good Virus/Spyware?Update/Firewall Practices?
faq779-5240
 
Thanks for both those replies. You've confirmed what I was rapidly discovering for myself - the machine in question has definitely been clobbered by a virus. I'm now seeing other types of virus-like behaviour, including random attemtps to dial up my Internet connection and navigate to sites I've never heard of.

My existing AV program (Sophos) doesn't recognise this virus. I'll either try installing another one, or wait for my next monthly update. I'll also install ZoneAlarms.

Interestingly, in eight years of using Windows 95 and 98, I was never knowingly infected by a virus. Within three weeks of using XP, I've been hit at least three times. (Fortunately, the XP machine isn't my main system.)

Mike


Mike Lewis
Edinburgh, Scotland

My Visual Foxpro web site: My Crystal Reports web site:
 
I'd be a bit concerned if my virus scanner was only updated monthly, is this correct? I recommend checking for updates every time you go online.

Virus Scanners are not equipped to catch Trojans or Worms, they are mainly interested in Viruses, as the name implies.

Often they include detection for the more common type of Worms or Trojans, but the detections of these other pests is better handled by an appropriate type of scanner.

This may explain why some virus scanners catch what others miss.

 
linney,

I'd be a bit concerned if my virus scanner was only updated monthly, is this correct? I recommend checking for updates every time you go online.


You're right of course. The vendor sends out a CD every month, but they do encourage you to download daily updates as well. It's just that this is my first virus attack for nearly a decade, and I never needed to worry about it before. It's what's known as complacency.

The problem I've now got is that I dare not connect the infected machine to the Internet. Whenever I dial up, I see a lot of modem activity -- data being sent and received, even though the system is not apparently doing anything.

The AV vendor requires you to connect to their web site (to download updates) from the same machine that is being updated, so I'm in a kind of Catch-22 situation. The machine is fine as long as I don't connect to the Internet.

I also tried installing ZoneAlarms, but the virus wouldn't let it run (just as it wouldn't let me run RegEdit, etc).

I guess I'll have to sweat it out until I get the next AV CD. If that doesn't solve the problem, I'll have to swallow hard and think about re-installing XP.

Mike


Mike Lewis
Edinburgh, Scotland

My Visual Foxpro web site: My Crystal Reports web site:
 
Hi Mike,
You could enable the Built in XP Internet Connection Firewall.
This should stop anything connecting in to your PC. You can then download the latest updates or one of the on-line scanners that is in the FAQ linney suggested.

Greg Palmer
Free Software for Adminstrators
 
Greg,

That sounds like a good idea. I hadn't realised that XP has a built-in firewall. If it succeeds in stopping the modem activity, I'll check out all the other resources that folk here have suggested.

Mike


Mike Lewis
Edinburgh, Scotland

My Visual Foxpro web site: My Crystal Reports web site:
 
You might try going to the following link. It takes you to the page where you can download the latest sophos ide (identity) files. That should update your current installation with the latest info.

They should go into the "program files\sophos sweep for nt" folder (I think)


There are versions of the ide files zipped as a bundles for SAV May,Jun,July. Just pick the one that matches your last installation.

HTH
Norman
 
Norman,

Thanks for your reply. Pehaps you can help me on this point.

I had previously visited the page you suggested to download the IDE files, but something confused me. The page clearly states that you must download the corect IDEs for the platform you are using (Windows NT/2000/XP vs 95/98). But it only gives a link to one set of downloads.

I assumed that means that the site detects which version of Windows you are running and serves you the IDE file for that version. Does that sound right to you?

If so, I can't do the download because it is my XP machine that is infected, and I can't use it to access the Internet. My other system is Win 98, but, if I've understood this right, I can't use that to download the XP files.

If that's not correct, how do I tell it which files to download? As I said before, there is only one set of IDEs on the page.

I realise you might not know the answer to that question. I might just go ahead and do the download anyway.

Mike


Mike Lewis
Edinburgh, Scotland

My Visual Foxpro web site: My Crystal Reports web site:
 
Hi Mike,
You only need to know what version of Sophos you are using. When going to you are presented with a table, this table allows you to select the correct download for your version. It also gives you a link just above the table to show you how to discover your version.

Greg Palmer
Free Software for Adminstrators
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top