Forum Home
Press F1
 
Thread ID: 93211 2008-09-08 02:29:00 Virus and/or Spyware corrupted windows... GR8Metal (14133) Press F1
Post ID Timestamp Content User
703400 2008-09-10 04:24:00 ..Well ... I removed the hard drive from the system and installed it into another PC as slave. Installed Avast AV, Trajan Remover, Malwarebytes, SuperAntispyware, SpywareTerminator. Updated all. Ran Avast - detected and removed a few trojan viruses. Ran all spyware utilities as listed above. Detected and removed up to 90 spyware objects total. Removed hard drive from PC. Installed back into original PC. Booted - still unable to boot into windows safe mode to run utilities again.... Any ideas? GR8Metal (14133)
703401 2008-09-10 04:29:00 So you boot into Windows normally, and there are no icons or task bar (eg, windows explorer is not running).

If that's the case, and ONLY if that's the case, try this. I've had it work twice this week so far, with spyware infected machines.

When booted to the desktop (or as close as you can get) open the task manager (Ctrl+alt+del). Click on file -> New Task.

In the run box, type in regedit

Navigate to:

HKLM/Software/Microsoft/Windows NT/Current Version/Image File Execution Options/explorer.exe


Remove the "Debugger" registry key. Exit regedit, reboot, and you should find that the system is back to normal (assuming there are no other registry entries that have been altered, or other viruses on the system, etc.)
wratterus (105)
703402 2008-09-10 04:32:00 That would include tracking cookies right?

My record so far is 1069. But that was an easy one, the most screwed up, hijacked thing I had only had a 100 odd. Nope - I had already manually gone into the temp files and deleted every thing while it was slaved, then once Nod did its thing - the drive booted, the first thing I did was run Ccleaner - there may have been a couple of cookies but less than ten. PS: the final count on the combined spyware was 1108.
That was between Termainator,Malwarebytes,Spybot,Spyware Doc and Combofix.


Now back to this problem ( 3rd PC this week with the same problem as you have described and its only Wednesday)

you may need to do a repair install - if you dont know how follow these instructions - This is meant to reinstall XP but leave all your programs/ data alone - works most of the time.

You will need your 25 digit product key for this.

Place XP CD in drive: Reboot or shutdown and start PC.

1.When the Press any key to boot from CD message is displayed on your screen, press a key to start your computer from the Windows XP CD.

2.Press ENTER when you see the message To setup Windows XP now, and then press ENTER displayed on the Welcome to Setup screen.

3.Do not choose the option to press R to use the Recovery Console.

4.In the Windows XP Licensing Agreement, press F8 to agree to the license agreement.

5.Make sure that your current installation of Windows XP is selected in the box, and then press R to repair Windows XP.

NOTE: if it doesn't locate your old OS STOP! As any further actions may result in wiping your data.

6.Follow the instructions on the screen to complete Setup.

Once the system has been repaired, you will need to rerun the malware scanners as there will still be traces of bugs in the system.
wainuitech (129)
703403 2008-09-10 04:43:00 Wratterus . . . . your a bloody legend! :punk It worked! Now I can continue to check for other bugs . . . . GR8Metal (14133)
703404 2008-09-10 04:46:00 No worries, good to hear. :thumbs: wratterus (105)
703405 2008-09-10 05:28:00 A big thanks to everyone else who helped out with this particular issue! :thanks :thumbs: GR8Metal (14133)
703406 2008-09-13 08:38:00 Hey I tried what you said Speedy Gonzales but no viruses, trojans, spyware found . Still the problem persists .

I asked my local computer technician at PB tech and he told me that several comps have come with the same problem .

He told me to make a new profile and copy all the data to that one . Sadly that did not work either .

Looks like I'll have to completely reformat .

Thanks anyway guys .
NewOrcOrder (14157)
703407 2008-09-13 09:50:00 NewOrcOrder - I don't normally suggest this here as sometimes this program can cause a few unforeseen problems - BUT since its on the verge of a reinstall any way - run Combofix (www.bleepingcomputer.com) wainuitech (129)
703408 2008-09-13 22:44:00 Hehe. Will this work in safe mode? Coz that's the only way I can run a program without getting the "no permissions" error. NewOrcOrder (14157)
1 2