CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Win XP Computer "Hosed Up"!

 
Post new topic   Reply to topic       All -> FavForums -> Windows NT/2000/2003/XP [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
oneof4

Corporal
Corporal


Joined: Sep 15, 2004
Posts: 71
Location: USA

PostPosted: Thu Jan 24, 2008 2:53 am    Post subject: Win XP Computer "Hosed Up"!
Reply with quote

I'm not sure if this is the right forum for this or not, but here goes...

A friend asked if I could look at this Gateway Celeron machine (circa ~ 2004), which means it does not have SP2 installed yet.

Things I've experienced so far:

Unable to open "My Computer", Windows Explorer, or Control Panal. This prevents me from installing Anti-virus, or spyware programs from my flash drive, or uninstalling possible problem programs.
Booted into Safe-Mode (Explorer came up ok), and attempted to install AVG & Ad-Aware, but niether would install in safe-mode. Unusual thing while in safe-mode was every 2 min. or so, the message window that you normally get at the very beginning telling you that you are using Windows Safe-Mode, etc, etc. kept popping up.
I am awaiting word from my friend whether or not they have the OS restore disks, in the meantime does anyone have a suggestion?

Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Thu Jan 24, 2008 3:34 am    Post subject:
Reply with quote

Hi oneof4,
This will enable the MSI in safemode so you can attempt to install some programs. Not all programs use the MSI, so it might not work.

Copy all the green text in the code box that follows to Notepad:

Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\MSIServer]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\MSIServer]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\MSIServer]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\MSIServer]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\BITS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\WUAUSERV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\BITS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\WUAUSERV]
@="Service"


Click on the Format menu in Notepad and uncheck Word Wrap. Then, save the file to your desktop in a file called safemode.txt. Next, right click on the file and change the file's extension from txt to reg. Click anywhere on your desktop. The file should now be named safemode.reg. Right click on the file and choose Merge from the context menu. You will get a warning, permit the merge, and then you will get a merged message.

My feelings are that if this computer does not have SP2 installed, it is probably badly infected. You might consider the Malware Removal and Prevention

procedure. This procedure has been designed to enable you to partially or even fully rid your

computer of viruses, trojans, adware, and spyware. Be sure to carefully follow the directions in order to

achieve the best results. If you have any questions about any of the steps, then please post a new topic

in the appropriate forum. There are links to them along the way. If you still need help when you finish,

please read
these directions


for posting a topic in the
HijackThis forum
and a trained 1st responder or security expert will assist you.

Back to top
View users profile Send private message
oneof4

Corporal
Corporal


Joined: Sep 15, 2004
Posts: 71
Location: USA

PostPosted: Fri Jan 25, 2008 2:42 am    Post subject:
Reply with quote

Thanks for the suggestion. I tried it, but I was given a message that the file was not a valid Win32 application. I ok'd the message just in case, but nothing changed when trying to install AVG or Ad-Aware, and the safe-mode warning message continued to pop up every minute or so.

Any other suggestions?

Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Fri Jan 25, 2008 3:04 am    Post subject:
Reply with quote

You did change the file extension and do the merge from normal mode, and then boot into safemode, correct?

I think your options are somewhat limited if you can't install scanning programs. I am guessing that the puter does not have any?

What are the particulars of the system? OS, installed software, hardware?

You could try an online scan http://www.pandasecurity.com/homeusers/solutions/activescan/
or perhaps a different file manager if Explorer won't cooperate http://www.gpsoft.com.au/ (free 30 day trial)

I'll see if I can get any other ideas.

Back to top
View users profile Send private message
oneof4

Corporal
Corporal


Joined: Sep 15, 2004
Posts: 71
Location: USA

PostPosted: Sat Jan 26, 2008 5:15 am    Post subject:
Reply with quote

No, I didn't try to merge it in "Normal" Windows, but after this evenings session with it I may not need to. While in safe mode last night, I dropped the installation program for AVG onto the desktop, tonight I was able to actually install it while in "Normal" Windows. The scan revealed 161 Trojan viruses!! All were healed or deleted according to the scan result. I also installed Ad-Aware, but evidently I got a bad download or something cause it's giving me some errors when I try to run it, so I installed an older version of SpySweeper and am scanning as I type this reply. I just finished downloading the latest version of AVG Anti-Spyware and will install/run it as soon as SS completes.
I haven't connected to the internet as of yet, and don't plan to till I complete these initial scans, and get SP2 installed. I will then update the two AVG scanning programs, re-scan the system, and then go through the rest of the Malware Removal and Prevention list.

Does this procedure make sense?

Back to top
View users profile Send private message
johnlgalt

Special Response Team
Premium Member

Joined: Feb 27, 2007
Posts: 1419

Premium SRT

PostPosted: Sat Jan 26, 2008 5:51 am    Post subject:
Reply with quote

sort of - better would be to not install the program, but rather have a version that will run off removable media - such as a CDR / UFD - and run that- especially CDR - less chance that the scanner gets infected....


_________________
<img src="http://www.castlecops.com/zx/johnlgalt/johnlgalt%20sig.png">

<img src="http://www.castlecops.com/zx/johnlgalt/John%20L.%20Galt%20%20CPU-Z.png">
Back to top
View users profile Send private message Visit posters website Yahoo Messenger MSN Messenger
oneof4

Corporal
Corporal


Joined: Sep 15, 2004
Posts: 71
Location: USA

PostPosted: Sun Jan 27, 2008 4:24 am    Post subject:
Reply with quote

johnlgalt wrote:
sort of - better would be to not install the program, but rather have a version that will run off removable media - such as a CDR / UFD - and run that- especially CDR - less chance that the scanner gets infected....


Thanks for the suggestion, but I've already installed AVG and so far have "apparently" eliminated all but "Look2Me". It keeps returning each time I reboot the system. Is there an easy removal procedure for it?

Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Sun Jan 27, 2008 4:55 pm    Post subject:
Reply with quote

I know you said that you are planning to do the MRP anyway, but since we are not qualified or allowed to really assist with malware removal in this forum I recommend that you do that now. They have access to more powerful tools that should only be used with expert supervision.

Malware Removal and Prevention procedure. This procedure has been designed to enable you to partially or even fully rid your computer of viruses, trojans, adware, and spyware. Be sure to carefully follow the directions in order to achieve the best results.

If you have any questions about any of the steps, then please post a new topic in the appropriate forum. There are links to them along the way. If you still need help when you finish, please read
these directions
for posting a topic in the HijackThis forum and a trained 1st responder or security expert will assist you.


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
oneof4

Corporal
Corporal


Joined: Sep 15, 2004
Posts: 71
Location: USA

PostPosted: Sun Jan 27, 2008 6:04 pm    Post subject:
Reply with quote

Thank you mrsugg, I will do as you suggest.

Back to top
View users profile Send private message
a_cup

Special Response Team
Premium Member

Joined: Mar 15, 2005
Posts: 2435

Premium SRT

PostPosted: Mon Mar 03, 2008 5:43 pm    Post subject:
Reply with quote

FYI...."The Look2Me Removal Tool has been integrated into Ad-Aware 2007. Make sure to upgrade to Ad-Aware 2007 in order to use this tool."

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Windows NT/2000/2003/XP All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer