Question about Microsoft Windows XP Professional

1 Answer

Not able to restore my registry settings...

Recently my pc was aatacked by a virus named win32/NSAnti... due to this i was not able to open my local drives n aslo i was unable to see hidden files...while i hav solved the drive problem still i have problem with hidden files because this virus has changed my registry...

please help me to restore my registry setting....

Posted by on

  • mava Feb 23, 2008

    Win32/NSAnti

  • nandu1987 Mar 18, 2008

    for me also the same problem when after booting , reformating then also my laptop is not working but it is working in safe mode give me a solution plzz..

×

1 Answer

  • Level 3:

    An expert who has achieved level 3 by getting 1000 points

    All-Star:

    An expert that got 10 achievements.

    MVP:

    An expert that got 5 achievements.

    Genius:

    An expert who has answered 1,000 questions.

  • Master
  • 1,019 Answers

Hi,
try re-installing windows over the top of your existing operating system.
If you get a prompt during setup, stating that you already have files. tick leave intact. or similar.
this can sometimes remedy faults, as windows will only replace missing-deleted or corrupt files on the hard drive.
Your other option, is to obtain disk partioning software and setup a seperate partion on the drive, install the operating system here, so that you can access the first partion.
just out of curiosity, did you go to Tools/folder options/View and tick the show hidden files And Folders checkbox ?
Mike @ Compurepair.

Posted on Feb 22, 2008

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

Problem signature: Problem Event Name: APPCRASH


App Crash is often caused by issues in Windows Registry. To avoid entire system corruption it is recommended that you immediately fix App Crash.

- Scan for Virus and Restore Original Versions of Infected System Files.
- Exclude Concerning Application from DEP and Firewall Protection.
- Fix windows registry with Reginout.(Must)
- Repair App Configurations.
- Uninstall Recent Updates.

Oct 29, 2013 | Microsoft Computers & Internet

2 Answers

My pc was infected by virus from website, all my exe file was disable, they asking me to pay them to enable the lock code, what can I do to cure the virus...


download this and add allow it to add it to your registry restart pc and you will be able to open programs again

http://filext.com/WinXP_EXE_Fix.reg

Feb 25, 2011 | Computers & Internet

1 Answer

Torjan remove virus


Reboot your computer if you have a Mac. Do this by holding down the "Shift" key while the computer restarts itself.

Launch an antivirus program that you should have installed on your computer, such as Symantec's Norton or McAfee. Wait for the program's window to appear, then go to "Disk View." Highlight your computer, then select "Scan/Repair" so that the antivirus can detect the Trojan and trash it.

Exit the antivirus program on your Mac. Restart your computer again to ensure that the Trojan has been deleted. Empty the trash can on your computer once it is back up and running.

Disable the System Restore feature if you're a Windows user. Go to "Start" at the bottom of your screen, then right-click the "My Computer" icon to go to "Properties." Check "Turn off System Restore" under the System Restore tab in the "Properties" window, then select "Apply." Confirm that you want to disable System Restore by clicking "Yes" and "OK."

Update your virus definitions in your antivirus program. Open the program, or go to the website, to download the latest definitions so that you can receive the most recent alerts and keep your computer protected.
Scan your files to detect the Trojan file. Follow the instructions in your antivirus program to delete any suspicious files. You may want to write down the path and file name of the Trojan, which is usually found in the "C:\" hard drive. Then, edit your computer's backup registry by choosing "Start," then "Run." Type "regedit" in the window that appears and click "OK."

Search for the registry entry from which the Trojan derived, which may begin with "HKEY" followed by the file path. Delete the registry entry to ensure that the Trojan is removed. Exit the registry entry, and restart your computer so that the changes can take effect.
Hopefully, it may help to remove Trojan virus from your PC.

Dec 07, 2010 | Free of Virus Remove Fake Antivirus

2 Answers

Trojan Horses PSW.Generic7.APIQ, Win32, etc.


Hi,

Boot into safe mode and go to your control panel > add or remove problem and delete the virus as a program on your pc.

After that please restore your computer to an earlier time when it worked bettrt.
KInd Regards

Nov 09, 2009 | Microsoft Windows XP Home Edition

1 Answer

Problem with windows xp


Sometimes it happens in windows XP that you are not able to open drives on your hard disk. When you double click on the drives icons or right click on the drive>>explore in My computer ,the drive does not open.

This problem is generally caused by most of the viruses which infect windows XP system. They block or restrict your access to any of the drives.

But don’t worry this is not a big trouble it can be fixed easily.

Fix:

Normally when a virus infects a windows system which causes a drive opening problem, it automatically creates a file named autorun.inf in the root directory of each drive.

This autorun.inf file is a read only ,hidden and a system file and the folder option is also disabled by the virus. This is deliberately done by the virus in order to protect itself. autorun.inf initiates all the activities that the virus performs when you try to open any drive.



Very simple . virus create some bad registry if you want to solve this problem then delet this registry


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion­\Explorer\MountPoints2


delete all drive from here

May 11, 2009 | Microsoft Windows XP Professional

1 Answer

Hi, recently i had virus in my comp called win32.worm.autorun.MQ i restored my windows through restore after cleaning up when i click on my drive it gives me error saying "resycled\boot.com is not valid...


This is a solution i found at another site that i think could help you with your probem

Hi

If you still need help with this please do following:

Download and install TrendMicro HijackThis
* Once installed open HijackThis by clicking Start > Programs > HijackThis and click the button labeled
Do a system scan only

* Click the scan button in the lower left hand corner of the interface and HijackThis will quickly scan your system.
* Once the scan is complete the scan button will now read save log. Click this button to save the log file to your PC. Once you select where you would like to save the file it will open in your systems default text editor. Typically this application is Notepad. Post the log here.

The link:http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/306207-resycled-boot-com-not-valid-win32-application.html

Please let me know if you need more help with this problem

Jan 06, 2009 | Computers & Internet

2 Answers

Win32/NSAnti


can you please cite the specific file of the virus..

I can do remote access if you want for removal..

Thanks for using fixya..

Apr 02, 2008 | Computers & Internet

1 Answer

I have win32 virus in my pc...


The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Remove all the entries that the risk added to the hosts file.
Update the virus definitions.
Run a full system scan and delete all the files detected.
Delete any values added to the registry.

For specific details on each of these steps, read the following instructions.

1. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:
How to disable or enable Windows Me System Restore
How to turn off or turn on Windows XP System Restore

Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.

For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: Antivirus Tools Cannot Clean Infected Files in the _Restore Folder (Article ID: Q263455).


2. To remove all the entries that the risk added to the hosts file

Navigate to the following location:


Windows 95/98/Me:
%Windir%
Windows NT/2000/XP:
%Windir%\System32\drivers\etc

Notes:
The location of the hosts file may vary and some computers may not have this file. There may also be multiple copies of this file in different locations. If the file is not located in these folders, search your disk drives for the hosts file, and then complete the following steps for each instance found.
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).


Double-click the hosts file.
If necessary, deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries added by the risk. (See the Technical Details section for a complete list of entries.)
Close Notepad and save your changes when prompted.


3. To update the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to Virus Definitions (LiveUpdate).
Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to Virus Definitions (Intelligent Updater).

The latest Intelligent Updater virus definitions can be obtained here: Intelligent Updater virus definitions. For detailed instructions read the document: How to update virus definition files using the Intelligent Updater.


4. To scan for and delete the infected files
Start your Symantec antivirus program and make sure that it is configured to scan all the files.
For Norton AntiVirus consumer products: Read the document: How to configure Norton AntiVirus to scan all files.
For Symantec AntiVirus Enterprise products: Read the document: How to verify that a Symantec Corporate antivirus product is set to scan all files.
Run a full system scan.
If any files are detected, click Delete.

Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.

After the files are deleted, restart the computer in Normal mode and proceed with the next section.

Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:

Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.


5. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.

Click Start > Run.
Type regedit
Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.


Navigate to and delete the subkey:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RpcRemotes


Navigate to the subkey:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup


In the right pane, delete the value:

"Ph4nt0m" = "Ph4nt0m"


Navigate to the subkey:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv


In the right pane, reset the value to the original value if applicable:

"Start"


Navigate to the subkey:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess


In the right pane, reset the value to the original value if applicable:

"Start"


Exit the Registry Editor.



also u can use the link for free download of virus removal tool
http://www.bitdefender.com/site/Download/browseFreeRemovalTool/

Jan 22, 2008 | Computers & Internet

1 Answer

Win32.funlove virus in xpsp2


you need to turn off system restore first as it backs itself up and then run your anti virus again, prefferably in safe mode, restart the pc and turn system restore back on.

Nov 16, 2007 | Computers & Internet

Not finding what you are looking for?
Microsoft Windows XP Professional Logo

Related Topics:

74 people viewed this question

Ask a Question

Usually answered in minutes!

Top Microsoft Computers & Internet Experts

micky dee

Level 3 Expert

2644 Answers

Les Dickinson
Les Dickinson

Level 3 Expert

18381 Answers

Brian Sullivan
Brian Sullivan

Level 3 Expert

27725 Answers

Are you a Microsoft Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...