PDA

View Full Version : Virus issues: c:\windows\system32:regedt.exe infected


Digiegg
08-29-2007, 08:49 PM
My computer's been effected with 2 viruses. Just a Trojan thank god.
Now it's effected my regedt.exe. There's no way to neutralize it except to delete this file, but isn't this one of the main files that is needed to run windows? I'm afraid if I delete this, I won't be able to run windows again. Help me out?

grantmoore3d
08-29-2007, 09:17 PM
This is an important tool, but not something required to run windows. Regedit.exe basically is a tool used to edit the registry. The registry is where windows keeps a lot of important details needed to run.

My advice, back up your data and get your computer formatted right away. Just deleting that won't really do anything to solve your problem, it's like sweeping dirt under the rug instead of cleaning it up.

minkey
08-30-2007, 03:36 AM
My advice, back up your data and get your computer formatted right away. Just deleting that won't really do anything to solve your problem, it's like sweeping dirt under the rug instead of cleaning it up.


couldn't agre more. backup what you can *test fo rinfection as much as you can on the files being backed up and do a format. (when running windows to do the format don't do a quick format)

Cheers.

lots
08-30-2007, 03:44 AM
My computer's been effected with 2 viruses. Just a Trojan thank god.
Now it's effected my regedt.exe. There's no way to neutralize it except to delete this file, but isn't this one of the main files that is needed to run windows? I'm afraid if I delete this, I won't be able to run windows again. Help me out?

The file that ships with windows is called regedit, not regedt. So is this a typeo? If not, it should be safe to delete...

minkey
08-30-2007, 04:04 AM
The file that ships with windows is called regedit, not regedt. So is this a typeo? If not, it should be safe to delete...

well this is true if you dont have MS 95/98/2000. If you have XP or above then LOTS is correct and you should be able to use your program with out a problem to remove this.

I still recommend you to backup and format still for the sake of saftey.

but in the mean while here is a little more information about the RegEdt.exe:

REGEDT.EXE may use 35 or more path and file names, here are the most common:


1 :%CACHE%\CONTENT.IE5\????????\APPWRAP[1].EXE
2 :%CACHE%\CONTENT.IE5\????????\TIMESSQUARE[1].EXE
3 :%CACHE%\CONTENT.IE5\????????\WATCH_FREE_PORN[1].EXE
4 :%commonfiles%\frjdhfrn\dpcpnlbl\ABELFLFR.EXE
5 :%DOCUMENTS%\MY RECEIVED FILES\WAREZP2P_DLC.EXE
6 :%PROGRAMFILES%\BLOCK CHECKER\BLOCK CHECKER.EXE
7 :%PROGRAMFILES%\SPAMPAL\ZLIB.DLL
8 :%PROGRAMFILES%\WINUPDATES\WINUPDATES.EXE
9 :%TEMP%\YOUR_D~1.PIF
10:%WINDIR%\DOWNLOADED PROGRAM FILES\GDNUS2089.EXE
11:%WINDIR%\DOWNLOADED PROGRAM FILES\MM83.OCX
12:%WINDIR%\DOWNLOADED PROGRAM FILES\POPCAPLOADER.DLL
13:%WINDIR%\ELITEUNSTALL.EXE
14:%WINDIR%\EMQ2W.SYS
15:%WINDIR%\ICONT.EXE
you can always try and manually remove it as well......

anyways good luck.

Cheers.

salmonmoose
08-30-2007, 04:18 AM
If backing up and reformatting is less than straight forwards, you should be able to delete the suspicious files - and make sure you are free of problems. When you're done you can put your Windows disc back in and tell it to fix itself, it'll go and find all the bits that are missing and replace them. You may have to give Windows your serial number again.

CGTalk Moderation
08-30-2007, 04:18 AM
This thread has been automatically closed as it remained inactive for 12 months. If you wish to continue the discussion, please create a new thread in the appropriate forum.