1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Windows Installer During BOOT!

Discussion in 'Windows XP' started by EL CONJUNTO, 2010/01/27.

  1. 2010/01/27
    EL CONJUNTO

    EL CONJUNTO Well-Known Member Thread Starter

    Joined:
    2005/02/21
    Messages:
    135
    Likes Received:
    2
    I found a Win XP Pro machine where during boot, right after the blue Welcome screen and just before the desktop appears, the Windows Installer appears. It stays on for about 20 seconds whether or not you hit cancel and then everything continues as normal with seemingly no problems. Is there any way to determine just what its trying to install or simply a way to just remove it? Its puzzling and annoying but I don't want to open up a can of worms and could just as well tell the owner to ignore it. Anyone with some ideas?
     
  2. 2010/01/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116

  3. to hide this advert.

  4. 2010/01/28
    EL CONJUNTO

    EL CONJUNTO Well-Known Member Thread Starter

    Joined:
    2005/02/21
    Messages:
    135
    Likes Received:
    2
  5. 2010/01/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I can't read the file.
    You didn't follow instructions.
    You simply renamed autoruns.arn to autoruns.txt
    It won't work.
    Please re-read instructions.

    and look at the image, I posted.
     
  6. 2010/01/28
    EL CONJUNTO

    EL CONJUNTO Well-Known Member Thread Starter

    Joined:
    2005/02/21
    Messages:
    135
    Likes Received:
    2
    I have limited access to the machine...please PM me. THX
     
  7. 2010/01/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Simply try again tomorrow, when you're at the computer.
     
  8. 2010/01/29
    EL CONJUNTO

    EL CONJUNTO Well-Known Member Thread Starter

    Joined:
    2005/02/21
    Messages:
    135
    Likes Received:
    2
  9. 2010/01/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I can't say for sure, without running some scans, but I suspect, you may have some infection.

    Read this post, then post the requested log(s) in the Malware and Virus Removal forum.
     
  10. 2010/01/29
    EL CONJUNTO

    EL CONJUNTO Well-Known Member Thread Starter

    Joined:
    2005/02/21
    Messages:
    135
    Likes Received:
    2
    The computer was infected prior to me cleaning it. I don't know if this is a residual part of the virus as I came in late to the game. ...But it WAS infected.
     
  11. 2010/01/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    According to what I saw in Autoruns, you still ARE.
     
  12. 2010/01/29
    EL CONJUNTO

    EL CONJUNTO Well-Known Member Thread Starter

    Joined:
    2005/02/21
    Messages:
    135
    Likes Received:
    2
    I downloaded DDS and will try to get the logs sometime Sunday. I'll post them as soon as I can.
     
  13. 2010/01/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very well, but don't post them here. Create new topic in Malware Forum.
     
  14. 2010/01/29
    EL CONJUNTO

    EL CONJUNTO Well-Known Member Thread Starter

    Joined:
    2005/02/21
    Messages:
    135
    Likes Received:
    2
    Will do..............Thanks!
     
  15. 2010/01/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Sure thing :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.