1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

corrupt O/S settings?

Discussion in 'Malware and Virus Removal Archive' started by charlie_c, 2004/10/10.

Thread Status:
Not open for further replies.
  1. 2004/10/10
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    I think I may have operating system problems. May have downloaded a virus - but updated NAV didn't find any. Programs have been running slow, many programs are not responding and sometimes crash. My "disk clean-up" doesn’t work. I have to delete temp files manually. (My resousces are low - need a HD clean-up.) I had a previous problem where my "system restore" left most of my programs missing. Had to call tech support. They undid my restore and restored settings from my XP O/S CD. Had to run: "start/run/CMD" "“ then "C:>" in dos prompt ran "sfc_/scannow" - w/ CD inserted.
    Do these steps look right? My level is probably intermediate.

    Thanks,
    C.
     
    Last edited: 2004/10/10
  2. 2004/10/10
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    My first suggestion would be to run an online virus scan with RAV. Copy and paste the report here.
     

  3. to hide this advert.

  4. 2004/10/10
    Paul

    Paul Inactive

    Joined:
    2002/01/29
    Messages:
    1,293
    Likes Received:
    1
    Make sure you are running updated anti spyware programmes such as Ad-aware and Spybot. Links available in my sig. Spyware probably isn't the main cause of your problems, but may be contributing to it?
     
    Paul,
    #3
  5. 2004/10/11
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Thanks - but I ran Spybot only last week. Took everything listed out.
     
  6. 2004/10/11
    BillyBob Lifetime Subscription

    BillyBob Inactive

    Joined:
    2002/01/07
    Messages:
    6,048
    Likes Received:
    0
    A LOT can happen is a week. I have had times when I ran it every day and it found something. And the more you are online the more of a chance of something invading the machine.

    Do you execute the " IMMUNIZE " part of Spybot ?

    BillyBob
     
  7. 2004/10/11
    BillyBob Lifetime Subscription

    BillyBob Inactive

    Joined:
    2002/01/07
    Messages:
    6,048
    Likes Received:
    0
    PS.

    Also WATCH your E-Mail.

    And make sure you have any and all E-Mail Preview panes turned OFF.

    BB
     
  8. 2004/10/11
    Johanna

    Johanna Inactive Alumni

    Joined:
    2003/03/08
    Messages:
    2,402
    Likes Received:
    2
    I saw an underscrore in your SFC command that doesn't belong there.
    Johanna

    SFC
    Start > Run > cmd
    sfc /scannow
    and have your XP CD

    sfc - system file checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

    If you want to see what was replaced, right click My Computer > manage, expand event viewer > system.

    System File Checker (sfc)
    Scans and verifies the versions of all protected system files after you restart your computer.
     
  9. 2004/10/12
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    I leave email on the server.
    I do download newsgroup messages, though.
    What about that, besides being careful what you open?
     
  10. 2004/10/12
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Thanks - that was a mark to me meaning to leave a space. I misread my scribble. :rolleyes:
     
  11. 2004/10/13
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Scan started at 10/12/2004 5:05:12 PM

    Scanning memory...
    Scanning boot sectors...
    Scanning files...
    C:\install.htm - HTML/DialogArg.B* -> Infected
    C:\Documents and Settings\Charles\Local Settings\Temporary Internet Files\Content.IE5\SOJVSPO0\inetdl[1].exe - Adware:InetDelivery.A.dam#2 -> Infected

    Scanned
    ============================
    Objects: 113642
    Directories: 3889
    Archives: 6585
    Size(Kb): 516850
    Infected files: 2

    Found
    ============================
    Viruses found: 2
    Suspicious files: 0
    Disinfected files: 0
    Mail files: 206

    -------------------------------------------------------------------
    Sorry took a while to find the time. I do see 2 viruses. It doesn't say when I got them and what they are. I ran NAV last Sat. - didn't find any viruses.
    This scan doesn't offer a fix. Should I run NAV again?
     
  12. 2004/10/13
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    These are your infected files.
    C:\install.htm - HTML/DialogArg.B* -> Infected
    C:\Documents and Settings\Charles\Local Settings\Temporary Internet Files\Content.IE5\SOJVSPO0\inetdl[1].exe - Adware:InetDelivery.A.dam#2 -> Infected

    Go to start>run and type msconfig, hit enter. On the boot.ini tab, check the box next to /safeboot and OK. Yes to restart. This will restart your computer in safe mode. Logon to you user account.

    Now in safe mode, you will need to show hidden files and folders, as well as system files.

    Delete the install.htm file in C:
    Open C:\Temp if present, select all and delete.
    Open C:\Windows\Temp, select all and delete.
    Open C:\Documents and settings\username\Local Settings\temp, select all and delete. Do this for all usernames.
    Open C:\Windows\Prefetch, select all and delete.
    Open My Computer, right click Local disk C: and choose properties, then disk cleanup. Check all boxes except compress old files and OK.
    Uncheck the /safeboot box in msconfig and ok to reboot.

    Install, immediately update and run Ad-aware in full scan mode. delete everything it finds. Reboot and let us know if things are working better.
     
  13. 2004/10/13
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Is "spybot - search and destroy" as good? I have this already.
     
  14. 2004/10/13
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Just as good, but each finds things the other doesn't. Use together for better cleaning results. Many on this board do so already, including myself.
     
  15. 2004/10/15
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    OK - I tried these steps - but have questions. On normal logon - account options are "myname" and "guest ". I believe I set up "myname" as administrater account. But in safemode logon - choices are "myname" and "administrator ". Now which do I chose? I logged on using "myname ". I followed all steps in safe mode and ran the disk cleanup. It hung up on "scanning compress old files ". It never moved in 4 hours. A h.p. technician had me check all options in the disk cleanup, in a previous warrenty service call. I'm off the warrenty now.
    I guess I am to put the check back in the box for "hide protected o/s files & folders" before leaving safe mode?
    When rebooting - a dialog box stated that I was in "diagnostic or selective start up mode" and prompted me to "chose normal start up mode on the gereral tab to start windows normally..." Do I want this. It says it will open all devices and drivers on start up. I did anyway.
    Lastly - I ran "spybot ". Just ran it 2 days ago - and 13 items were back. Should I immunize? Now I have nothing blocked - but have 505 items available to block. Will this effect opening my excite homepage - and other pages that I use - since it was listed in the scan.

    OK - you can see that I am still in a delima. What to do next?
    Thanks for hanging in there with me.
     
  16. 2004/10/15
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Correct
    Hence the reason I said to check all EXCEPT compress old files.
    Completely your choice.
    Just click OK. Normal prompt after using the sytem configuration utility, which was done when checking/unchecking the /safeboot box.
    And what about Ad-aware??
    If you are visiting sites that leave behind junk for Spybot to catch and remove, then it's doing it's job properly. I don't believe that immunizing will block you from those sites, but may help to avoid picking up unwanted objects while visiting them. Yes, you should use the immunize feature, and also install SpywareBlaster from the link below on that page. Easy enough to undo if it causes you problems.
    If you are visiting undesireable sites (note I said 'if'), and the delima is that Spybot keeps finding baddies to remove because of it, even after doing the above mentioned immunizations, it's not really a delima. Either stop visiting them or continue to use cleaners to remove the junk they leave behind. That's what the programs were designed for.

    Are you still having the same problems you noted in your first post?
     
  17. 2004/10/15
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    corrupt O/S settings? reply to noahdfear

    Couldn't get reply to work in original thread.

     
  18. 2004/10/19
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi Charlie,

    No idea why you are having trouble replying. :confused:

    Go to start, then run
    and copy/paste the following command, then hit enter.

    cleanmgr /sageset:1

    Check all boxes except compress old files and click OK. Then open run again and copy/paste the following command, then hit enter.

    cleanmgr /sagerun:1

    Definately install, update and scan with Ad-aware, in full scan mode, deleteing all it finds, regardless of whether or not the above disk cleanup instructions above work.
     
  19. 2004/10/20
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Bad news: The "cleanmgr" commands failed to resolve the "clean disk" prolem. I repeated the steps twice - and each time the scan opened (and locked) with "scanning old compressed files ".

    Good news: I ran the Ad-Aware - found and deleted 277 critical objects. Things seem to be running quicker and smoother now.

    BTW - I checked "Start-up" items and unchecked at least 20 that didn't need to be checked. Do you know what absolutly has to be checked?

    The "clean disk" fix seems to be the difficult one. Scan w/ XP OS CD? Walk me through the steps, please.

    Thanks, eternally.
     
  20. 2004/10/21
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    The 'compress old files' piece can take what seems like just this side of forever to scan for and then to fix. The good news is that after it's run a few times (I do mine about once a week) it gets lots faster. The good news is that you don't lose much if you don't allow it to be fixed as several on here suggest. I'd say just let it run and if that means overnight, so be it. Mine cleanup scan now completes in about 3 minutes and the cleaning takes even less. The first couple of runs may have taken hours - no idea since I been here before and just started the sacn and went to work then when I got home, started the clean and went fishing.

    Black Viper has the best site on the internet for explaining all the start up items and the effects of allowing or not allowing them to run. Well worth a look.

    The "clean disk" fix seems to be the difficult one. Scan w/ XP OS CD? Walk me through the steps, please

    If this is the disk cleanup then we should have covered that. If not, I'm not sure what you mean.
     
  21. 2004/10/21
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    The Black Viper site recommendation and tweaking the services is a good one, and will help to free up resources, but different I believe from what you were referring to as 'startup' items, if I'm understanding you correctly. Were you referring to entries on the startup tab in msconfig? Because of the number of startup entries, along with your reporting the removal of 277 critical objects with Ad-aware, I recommend you recheck everything on the startup tab and exit without restart. Download HijackThis.exe from here. Save it to a permanent folder (I create a new folder in C:\ named HJT). Reboot and open HijackThis, then click scan, then save log. Once it is saved it will open in notepad. Select all from the edit button, copy and paste the results here. Don't fix anything with it yet!

    PS. You mentioned in PM an MS article describing a registry edit for disk cleanup. Got a link? ;)
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.