msconfig question

Discussion in 'Software' started by whale844, Dec 15, 2009.

  1. whale844

    whale844 Private E-2

    Hey guys,

    I'm a newbie here, hoping someone might be able to help me out with some suggestions. Here's the low-down...

    My labtop was hit by a virus the day after Thanksgiving. Dell Inspiron 9400 running Windows XP. Long story short, when I ran my Norton AV it removed 2 of the 5 trojans it found, the other three it said must be removed manually. I read the thorough Norton AV instructions online on how to do this, it said to use msconfig to set the computer to restart in Safe Mode. So I did. Well, upon restart, the infamous blue screen of death. Oh no!!

    After trying every trick known to me to repair Windows, I ended up partitioning the hard drive and installing a second copy of Windows XP. That worked, I had full access to all files. I ran the computer cleanup procedure from the Malware forum here. Ran CClean, SuperAntiSpyware, Malwarebytes, the whole ball of wax. BIG difference and all threats are now gone! Woohoo!

    Tonight i tried to reboot under the first copy of Windows. Since I tried the "repair" option in the Windows Repair Console, and stopped mid-way, Windows Setup tries to resume. When it gets to the point where you're shown the Windows Desktop, you're still booting in Safe Mode (ahh...thanks msconfig and Norton...) and you receive the pop-up "Windows Setup cannot run under Safemode and will now restart" and thus starts the vicious loop.

    Question: is there a way to access msconfig for that first Windows Account on my computer? Is that the reason it keeps booting in Safe Mode? Or do I have other issues I'm not aware of? BTW the second copy of XP is running fine, no problems, in fact I'm logged in on it as I'm posting here.

    Thanks in advance!!

    W844
     
  2. sach2

    sach2 Major Geek Extraordinaire

    Boot into the second copy of Windows. Go to the drive your first copy is on (probably C: ) in Explorer. So in Explorer>Tools>Folder Options>View tab> tick "Show Hidden Files"; also untick "Hide Protected Operating System Files" (you may have to scroll the window to see this one).

    Now the boot.ini file should be visible on C: (or the letter for your first Windows partition) open it with NotePad and delete the ":/Safeboot" part where it appears at the end of one of the lines.
     
  3. whale844

    whale844 Private E-2

    OK, I did that and it worked great. But when I logged in to my old Windows user account, I got a pop up that the system was infected with a worm, then a blue screen message saying a Windows process ended unexpectedly. Great - back to the drawing board.

    Thanks for your help, anyone have any other suggestions?
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes!

    Repeat the cleaning procedure on the original partition also.

    dr.m
     
  5. whale844

    whale844 Private E-2

    Do I have to be logged in on the original Windows copy, or can I log in on the copy loaded onto the partition?

    BTW, something is definitely up, my browser changed (it put me back to IE7)and I can't access any websites, all I get is a redirect window that pops up.

    Thanks for your help Dr. M!
     
  6. padams

    padams First Sergeant

    Partition 1 - Original XP Install
    Partition 2 - New Partition You Created

    Log into partition 2 and scan partition 1 with all the anti malware software in the cleaning procedure. Next try logging into partition 1 and going through the complete cleaning procedure.
     
  7. whale844

    whale844 Private E-2

    Will do - thanks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds