Click to See Complete Forum and Search --> : System restore issues
trippinstu
May 25th, 2008, 09:04 PM
Alright, I'm pretty sure I have a virus from an email or something on my other computer. For the past week I have been fighting the thing. Everything I tried didn't work so I tried to do a system restore today. Whenever I try to open any program on the desktop I get a message asking what program I want to use to open it. And the same with the system restore. I tried every program on the list and it wouldn't work with any of them...
Anyone know of any way I could get to it?
Thanks,
-Stu
futuretech
May 26th, 2008, 01:12 AM
This usually points to a corrupt registry key
HKEY_Classes_Root/EXEFILE/Shell/Open/Command
What is the default value?
What it should be is
"%1" %*
If it is not then you would need to change it to be so.
As always before editing the registry backup the key first.
Ferrit
May 26th, 2008, 11:19 AM
Alot of the time when a system is infected, it also infects the system restore files .
So restoreing may not work. It may just re infect you.
What virus was it you had?
What windows?
trippinstu
May 26th, 2008, 12:43 PM
Maybe I should inform you guys that I'm not the greatest with computers, anything to do with the registry and I'm lost. I have XP SP2. And it probably can't get any worse... after all I can only open a few folders, and I can't open any programs.
CCT
May 26th, 2008, 01:19 PM
Try this: http://bertk.mvps.org/
Restore to at least 2 weeks back.
trippinstu
May 26th, 2008, 01:56 PM
I tried both ways on the website and either way it pops up with a box that asks what program I want to use to run it. No matter what program I click it won't do anything, it just closes the box.
CCT
May 26th, 2008, 01:58 PM
You tried the Safe Mode method ?
You also tried the start, run, %systemroot%\system32\restore\rstrui.exe method in Safe Mode?
trippinstu
May 26th, 2008, 02:02 PM
Yeah, and it still tells me the same exact thing
CCT
May 26th, 2008, 02:14 PM
If you have IMPORTANT stuff on there can you drag and drop it onto a CD succesfully?
NooNoo
May 26th, 2008, 02:19 PM
What antivirus do you have?
trippinstu
May 26th, 2008, 02:22 PM
nope, I tried that earlier because I have a LOT of music on here, otherwise I would just clear everything and start over. Other than all my music I only have a few games, but I can easily install those back on in about an hour. I tried to reinstall AVG so I could find the virus or whatever was causing this mess, but it wouldn't work for me. So, anyone know of any other ways to get to restore? It probably can't get any worse than this... unless it self destructs, although that would make a pretty good story...
trippinstu
May 26th, 2008, 02:23 PM
AVG, but it got disabled somehow and when I try to open it asks the whole what program I want to use to open it bull...
trippinstu
May 26th, 2008, 02:55 PM
ok, stupid question here, how do I do the backslash (/) ... except backwards? I feel stupid now because I just noticed I was putting in the wrong symbol... or whatever the thing is
NooNoo
May 26th, 2008, 02:59 PM
yes \ is leftward leaning
try this (http://www.dougknox.com/xp/file_assoc.htm) not quite automatic, but it can be done one stage at a time.
If Doug's tip to get regedit.exe going doesn't work, the try booting to safe mode and rename regedit.exe to regedit.com
trippinstu
May 26th, 2008, 03:08 PM
THANK YOU SOOOOOOO MUCH!!!
It actually didn't take very long and it was kinda simple.
Thanks Again,
-Stu
NooNoo
May 26th, 2008, 03:09 PM
Anytime :)
NooNoo
May 26th, 2008, 03:10 PM
Oh and go get Avast from Avast.com - the home version is free.
trippinstu
May 26th, 2008, 03:10 PM
Ok, I can finally use my programs, but AVG won't update? It says connection with update server has failed. Is this just an AVG error or could it be caused by the virus?
NooNoo
May 26th, 2008, 03:10 PM
Could be either, see my post above.
trippinstu
May 26th, 2008, 03:12 PM
alright, I'll try avast
CCT
May 26th, 2008, 03:24 PM
If you have AVG 7.5 it won't update because it isn't supported anymore.
You need AVG 8.0 .
futuretech
May 26th, 2008, 11:20 PM
http://www.symantec.com/security_response/writeup.jsp?docid=2001-072013-2927-99
the above link is to a symantec tool that removes the sircam.worm and included in the tool is the resetting of the key i mentioned in my earlier response.