PDA

View Full Version : Registry Oddities W98 (W98)



cridley
04-01-2002, 02:31 AM
Have had a strange occurance - perhaps someone else has had this happen and can provide some insight. I removed viruses (different ones) from three W98 machines, cleaned them up (critical patches, scandisk, defrag, etc), installed Norton AV 2002 and all goes well. Within 3 days it seems the registry chokes and reverts back to one prior to my removal of the viruses and install of NAV 2002. The users usually get the 'Error with registry - system will reboot' message. Of course, NAV ceases to function and will not reinstall (beginning to wonder is NAV does not have something to do with it). The registry entries for the virus(es) are returned, but the infected files are clean or deleted. And of course the mess from the critical patches...

When checking these machines after this happens, there is a huge gap in the registry backups - that is, there are backups from prior to my work on them and then one which is from the day of the problem, which is the restored one of the from prior to my work. This pretty much hoses trying to simply restore the registry to its corect state, since there is no correct backup copy. I do perform scanreg and several other checks when I am done with a machine to make sure all is well.

I have two questions -

One, is there an easy way to prevent this - i.e. deleting all prior existing registry backups to prevent such a mess and replacing them with copies of the current known good registry? To be lame about it, could one just run the scanreg from within System Tools and choose to back it up 5 times to overwrite the old reg cabs?

Two can anybody suggest a procedure for preserving the registry during this type of work?

Any suggestions are welcome.

I gotta say, working in OS/400 is a heck of a lot easier than Windows.

Thanks.

tnguy
04-01-2002, 04:12 AM
If I had a similiar situation with a machine infected by viruses (and I have), I would Fdisk the machine, then format, then reinstall everything. If the machines had viruses that you DID find, what else might have been affected, that you DID NOT find, and what files might have been modified by the intruders? I know this may seem like overkill, but it is the only sure way to make sure that you have a clean machine.

TNguy
Network Administrator
=-= N0, I am not the Computer Nazi, and NO you may not access the Control Panel =-=