Re: Safe editing of the registry--need very explicit guidance

From: Kent W. England [MVP] (kwe_at_mvps.org)
Date: 06/22/04


Date: Mon, 21 Jun 2004 19:35:33 -0700

1940 LaSalle wrote:

> I may have a virus that hides a couple of IE 6 options,
> and I may have to edit the registry to get rid of it.
> (This is the Java JJblack Trojan virus, as best I can
> figure out.)
>
> What do I do to ensure that this exercise doesn't become
> another horror story? I'm not even sure how I go about
> backing up the registry, which I'm told is a "must do"
> step.

If you are going to change or delete a key, then export that key to a
.reg file so that you can restore it later. In addition, make a system
restore point so that if you delete a key that prevents Windows from
working properly (but still it boots) you can use your restore point as
a brute force alternative to importing your saved registry keys.

You should also run NTbackup and make a system state backup that will
save your registry hives inside the Windows folder. Then if XP doesn't
boot at all, you can use Recovery Console to copy those backup hives
over the damaged hive(s). If you don't do this, you can still
laboriously extract your last restore point from the SVI folder, but it
is a real PITA.

-- 
Kent W. England, Microsoft MVP for Windows Security


Relevant Pages

  • Re: Networking, registry and more problems!
    ... "Windows cannot display the Properties of this connection. ... use System Restore to restore Windows to an earlier time ... The Magnuson-Moss Warranty Act ... "One of the files containing the system's Registry data had to be ...
    (microsoft.public.windowsxp.general)
  • >>>> RESTORE REGISTRY <<<<
    ... Restore Registry Windows 98 ... Manually Restore Xp Registry ... Restore Registry From Backup ...
    (de.comp.os.unix.shell)
  • Re: Im an idiot with a recovery console
    ... There is no Registry modification thing in Recovery console but if you ... Windows XP but no Microsoft programs are working with the afore ... use the generic restore system in XP thats all turned off but I know ... I started an XP installation i have on a seperate ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: LSA Shell (Export Version) Message: "LSA Shell encountered a problem Windows is shutting do
    ... System Restore back to a time prior to when this began. ... It is possible that the registry ACL for the key Lsa may not be set to the ... > I'm told that it's a known problem with Windows XP. ... > same error message and my computer shuts down and restarts. ...
    (microsoft.public.windowsxp.accessibility)
  • Re: lost details
    ... Registry Backup and Restore for Windows NT/2000/2003/XP ...
    (microsoft.public.windowsxp.general)

Quantcast