PDA

View Full Version : regedit (WXP-Pro)



phillipfabbe
02-23-2006, 10:42 AM
i am hoping i get someone who knows what there doing, i recently had a bad virus/trojan, what ever it was reaked havoc on my system, now i can't get into my registry fron the run command. I type in regedit and for a few short seconds a dos window pops up them dissappears. i have tried other ways of getting into my registry oinly to find out that it says it's been disabled by the admin, well the admin. is me, and i didn't disable it. when i ran across this virus/trojan, when it finished scanning my drive, it found roughly 4785 files that this gaggle viruys infected and or attached itself to a butt load of files, i still think it's in here somewhere, but i can find anymore trace of this anywhere, or at least this is what norton says.

well , anyway, i am going nuts trying to get into this, can someone help me.

motoflop
02-28-2006, 09:54 AM
You have still active some virus or spyware which forces regedit to close. Try to make copy of regedit.exe and rename the copy for example to "foobar.exe". The virus is propably monitoring if you try to start "regedit" and kills the program rightaway, but it won't hopefully recognize foobar.exe. The virus might have also set registry policies to prevent regedit to run. If they are set, you have to either reset them or you can edit your foobar copy of regedit with hex editor. You have to locate unicode string "DisableRegistryTools". It is near offset 0x0D00. When you locate it, change one letter, for example first "D" to "X". Now when you run foobar.exe, it checks if it finds "XisableRegistryTools" and as it cannot find it, it allows you to edit registry.

phillipfabbe
02-28-2006, 01:16 PM
after alot of cussing and hair pulling and wiping my eyes, i can get into my regedit through a dos window, can you tell me how i can set this back so that i can go back to the run line and type regedit the normal way.

motoflop
03-02-2006, 12:01 PM
I suggest you get HijackThis utility (search it from web) and post generated log file to winguides virus/spyware forums. Hopefully some wise gurus can then help you.