Weird Windows problem

by Volker Weber

I have come across a problem with my Windows 2000 Server that I cannot get a grip on. Here is what is happening: The HKEY_LOCAL_MACHINE\SOFTWARE key cannot be opened. In Regedit the little plus sign in front of "Software" goes away. A reboot cures the problem and after a few days the key becomes unavailable again. I have absolutely no clue of what is going on.

Any ideas?

Comments

Perhaps there's an app on the machine that opens the key using win32 apis, and leaves it open? A reboot would fix that until the app (or service, or whatever) starts running again.

There are several Outlook-spread worms that exhibit this behavior, IIRC.

Nathan T. Freeman, 2004-06-13 07:18

Bob, how would I find out?

Nathan, highly unlikely. There is no Outlook on the machine, but it is patched every day and the virus scanner is happy. Can you point me to a specific worm?

How did you get rid of Outlook? As far as I know you can only disable access to it (from the desktop, there might still be other ways to access it), but you can't easily remove it. Any hints that don't require major surgery are welcome.

Outlook is part of Microsoft Office. There is no Office installed on the server.

Oops, sorry, overlooked the "Server". I thought you were talking of "normal" Windows 2000, where Outlook Express comes with the IE, if you like it or not.

Outlook Express and Outlook share nothing but the name.

Internet Explorer is installed on the server. As is Outlook Express. However there is no account configured in Outlook Express so it is not operational. Additionally you can delete imn.exe (from its original name "Internet Mail & News").

Hi Volker,
eventuallt this: http://www.blunck.info/dp.html tool might come in handy to find out what is running when the content of software dissappears.
;-) stw

How to find out.... yes, that's the issue I guess. If you can access the key "for a while" after rebooting, perhaps you can try this:
reboot, immediately open Regedit and access the key
See if any running processes display errors because they can't access the key

If you boot into safe mode, does it still happen? Safe mode with networking? Have you checked your startup folder recently?

I can get into the key for days. And then suddenly I can no longer. I notice this when the virus scanner wants to read its login information from the registry in order to authenticate against the download server.

So, I have to wait for this to happen and then I can try and find out what is blocking access. I was thinking about using some of the tools from SysInternals.

The behaviour is actually not new. The machine developed it months ago but I never cared enough to cure it.

it's hard to solve such sorts of problems - even more if they just tend to happen from time to time.

my bet is some sort of spyware/malware.

virusscanner is happy here, too - all the day. today i manually cleaned up the system - using a combination of adaware, hijackthis and spybot search & destroy. the result was shocking.

i bought norton antivirus 2004 because i had positive experiences with prior versions plus the 2004 release now comes with integrated malware/spyware detection.

my mind changed and i will nomore buy any update extension nor any new version of NAV. it's just too unsatisfying in it's results.

i had some irc bot virus/spyware combination on my system for nearly 2 weeks and it didn't get catched by NAV. kaspersky trial found and removed it on the first tryout.

The Swen.A virus is known to block access to the registry and if I recall correctly also exhibits some of the other symptoms alluded to here.

http://chris-linfoot.net/plinks/CWLT-5RJDJA

Post a comment











Shall I remember this for you?




Use your full name and a working email address. Unless you want your comment to be removed. No kidding.



Recent comments

Ben Poole on Google Gears beta for Safari at 22:20
Alexander Kluge on How to save half a gig of disk space in a couple of seconds at 21:44
Volker Weber on How to save half a gig of disk space in a couple of seconds at 21:24
Martin Christian Kautz on How to save half a gig of disk space in a couple of seconds at 21:20
Claurice Jackson on How to save half a gig of disk space in a couple of seconds at 20:41
Andy Brunner on How to save half a gig of disk space in a couple of seconds at 19:56
Norlailawati Zain on What's the Notes market share really like? at 19:26
Richard Kaufmann on Department of Homeland Security launches Electronic System for Travel Authorization at 18:35
Lennard Timm on Password not appropriate at 14:37
Adalbert Duda on Password not appropriate at 14:03
Roger Schwarz on Synchronizing iPhone with ... Lotus Notes at 13:57
Ben Rose on Put a Porsche in your driveway at 13:31
Ben Rose on Put a Porsche in your driveway at 13:22
Ben Rose on Zones at 13:10
Nick Daisley on Put a Porsche in your driveway at 13:03
Ben Rose on Put a Porsche in your driveway at 12:50
Karsten Lehmann on Tweet of the day at 12:31
Andreas Gruen on Department of Homeland Security launches Electronic System for Travel Authorization at 12:26
Johannes Matzke on Put a Porsche in your driveway at 09:50
Jan-Piet Mens on Department of Homeland Security launches Electronic System for Travel Authorization at 08:30
Henrik Heigl on Put a Porsche in your driveway at 08:16
Simon Phipps on Department of Homeland Security launches Electronic System for Travel Authorization at 03:33
Colin Williams on Tweet of the day at 02:23
Volker Weber on Tweet of the day at 01:28
Konstantin Klein on Ich verstehe es auch nicht at 01:21

Ceci n'est pas un blog

vowe.net is a personal website published by Volker Weber a.k.a. vowe. I am an author, consultant and systems architect based in Darmstadt, Germany.

rss Click here to subscribe

Hello

About me
Contact
Publications
Certificates
Frequently asked questions

Twitter Updates

More >

Poll

Can you bring a camera phone to work?

Getting poll results. Please wait...

Local time is 22:28

visitors.gif
190 visitors online

News

Other sources of news, imported into my own format to make them more accessible:

Heise Online
Schlagzeilen
Weather

Archives

As most of my articles roll off the front page rather quickly, I am making an archive of previous posts available here. You can also use the handy search box at the top of the page if you are looking for something particular.

Last 30 days
More archives

Got the T-shirt?

Got the T-shirt?
Are you buying from the US?

Systems Architecture

This site runs on an Apache web server on top of the Linux operating system. The content is managed with MovableType which is implemented in Perl. Last but not least the HTML code your browser sees is put together with PHP.

© 1992-2008 Volker Weber.
All Rights Reserved.

Impressum