Weird problem with XP SP2 !!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by peyz, Nov 15, 2006.

  1. peyz

    peyz Private E-2

    My problem could be an incomplete or faulty installation from a CD. This may be the root of my problems, such as the sudden "windows genuine" validation trouble.

    Why I say faulty or incomplete, because in the control panel, “system” , it does show SP2 installed.
    Yet there are many things missing, such as windows firewall, or that red shield in the quick launch menu ( pertaining to firewall, automatic windows update/AV ).
    And my internet explorer 7 suddenly vanished, and even the previous version does not function properly !!

    After installation of SP2, not only it damaged a lot of programs in my computer, it also did something to my newly installed “Internet Explorer 7”.

    Not only the “Internet Explorer 7” is nowhere to be seen, hence no “Info bar” to continue with the validation, but also my previous version of “Internet Explorer” also is not functioning properly !!


    I have tried the different suggestions made at microsoft’s website, which are:
    1- In “Add or remove programs” and “updates” slot checked, I remove it.
    But in MY computer, after checking the “updates” box, the SP2 does NOT show !!
    Therefore, I cannot remove it by this means.

    2- after installation of this SP2, all the previous “restore points” in my comp, have been wiped clean, so I do not have any date prior to the installation date to restore my comp to !!

    3- I have also tried typing the following .exe program, in the “run” program , but the message says it cannot find the SP2 folder !!!
    c:\windows\$NtServicePackUninstall$\spuninst\spuninst.exe

    Please help me remove the current SP2 update, so I can download the proper SP2 update directly from the Microsoft website.
    I do NOT want to use the CD again ( for obvious reasons ).

    Thank you

    Peyz
     
  2. Robert

    Robert Sergeant

    Presumably your genuine XP1 CD did not install correctly for some reason, and the problem got worse when you installed XP2 update. If that is the case in your situation I would format and start again. Install XP1 - activate and then put in the xp2 update followed by IE7 (if you must - I use either Firefox or Opera)
    If however your XP1 CD is not an authentic M$ product then you will not be able to activate it and the only answer is to get the genuine thing!
    The Academic version of XP is reasonbly priced I believe.
     
  3. peyz

    peyz Private E-2

    Dear Robert,

    My original SP1 was working perfectly.... until this last installation of SP2 !!

    and I do use firefox, but I dont see any harm in having the IE7 either.
     
  4. Robert

    Robert Sergeant

    OK I misunderstood your original post. In your case I would still format the whole shooting match reinstall XP1 - activate it and then install XP2 upgrade. If everything is working satisfactorily then put in IE7 and that should do it.
    Others more expert than I may have a different or better solution but I see no other responses so far
    HTH
    Robert
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Existing malware on a system will screw up the installation of sp/2 ....would do a restore to before the sp/w installation ....do the read and run in the malware section to rid your system of crap ...then re-download sp/2.
     
  6. peyz

    peyz Private E-2

    Dear Robert,

    At this moment, I am not in the states, and I dont have access to my original XP CD.
    Which sort of makes "re-installing XP" or even "slip streaming" impossible for me.

    However, I do have my SP2 CD.
    Do you think it would resolve my problem (even if temporarily, until I get back to the states ), if I attempt to install the SP2 once more?

    This is based on the presumption that maybe the first installation was faulty or incomplete, and the new one may take care of that.
    Do you think this may solve things?

    And if yes, will the new installation eat up into my hard disk space, or will it write OVER the previous one?


    ---------------

    Dear TimW,
    Before the attempt to install SP2, I did use my Adaware program to check the whole comp for any spyware and malware.
    As well as my Norton corporate version of AV.
    Both came up clean.

    (Unless you meant something else by "do the read and run in malware section ..." , which I didnt understand ... which is normal, simply because I dont know much about computers ! :) and those "**** for dummies" series is targetted at people like me :) )

    Also as I said earlier, one of the problems I cannot remove SP2 is because it wiped my "system restore" clean of any points prior to the installation !!!!
    So, I'm quite helpless in that aspect !



    Once again, thank you both
    Peyz
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Neither Norton nor Ad-aware will find all malware on a system ...
    Read and run first - Malware section
    http://forums.majorgeeks.com/showthread.php?t=35407

    When sp/2 is installed it creates a restore point so you can go back if it fails ...however, I wouldn't try reinstalling sp/2 at this point.

    Run this first and report back:
    Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

    http://www.bitdefender.com/scan8/ie.html
     
  8. peyz

    peyz Private E-2

    Dear TimW,

    I did go through almost all those steps regarding the malware.

    all except the Panda scan, simply because the pop up window that emerges after you click on the "scn my pc" , had an error message everytime.
    ( yes, I did use my dysfunctional internet explorer for these programs ).

    Also I didnt do the HijackThis.
    In case you like to see that one also, I can do that too.

    I am glad to know each one of these scans did rid my comp of a lot of trojans and viruses and spywares.

    I am attaching the results of these along with this post.


    Do you think if I attempt to re-install SP2 ( again ), now it should work ?

    Thanks
    Peyz
     

    Attached Files:

  9. peyz

    peyz Private E-2

    ... and here's the last one:

    I did try to upload the html version of bdscan, but it wasnt accepted !

    p
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have at least 2 viruses running that bitscan caught ...will request that the mod's move the thread into the malware section.

    Wait till the malware guys give you a clean bill of health before trying sp/2 again.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in the READ & RUN ME properly.

    You did not do all of step 2. And you did not follow the directions for disabling MSconfig (i.e. you must select Normal Startup as requested in the READ ME).

    Also you need to uninstall Viewpoint Media Player as requested in step 0 of the READ ME.

    Address those three items and then attach a new log from GetRunKey and then also follow the directions in step 7 to install, rename and run HijackThis properly and attach a log from HijackThis.
     
  12. peyz

    peyz Private E-2

    Thank you Tim.

    Dear chaslang
    I did the 3 required tasks.
    And have attached the new runkeys.txt to this post, as well as the HJT one.
    However, I didn’t remove any viruses from the results of HijackThis, as I understand someone like me may remove some critical components of the computer without realizing it !
    Do you think I should do that?


    Also on shutting down, a message appears repeatedly ( 2-3 times, on every shut down ), for the past few days.

    It says :

    “End program – Explorer.exe

    This program is not responding

    To return to windows …
    If you choose to end the ….”

    Could be related to my dysfunctional internet explorer.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good because HijackThis is not a malware detection tool. It does not show you malware. It merely presents a running process list and also lists a variety of registry keys. It makes no inferences as to whether anything in the log is bad or good and in most cases, most of what is in a log is normal. If you hade made the mistake that many misinformed people make and assume HijackThis is showing you a list of malware and you had it fix the problems, you would be in big trouble (especially if HJT was not installed properly because no backups would be made to restore from).

    I still see Viewpoint Media Player in your newfiles.txt log. Did you uninstall it? Or did it not show in Add/Remove programs?


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2
    Mozilla Firefox (1.5.0.8)

    Then install the current version of FireFox from: Mozilla Firefox


    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_47a6.dll"
    O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
    O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
    O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1139001474640

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\System32\sfg_47a6.dll
    C:\WINDOWS\System32\kdpupd.dll

    Now run Ccleaner.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Nov 19, 2006
  14. peyz

    peyz Private E-2

    I did remove the “viewpoint …” from the add/remove program.
    The newfiles.txt was done BEFORE this.
    However, the runkeys.txt and HJT was done AFTER its removal.

    Two questions:
    1- If I uninstall my current firefox, and install the upgrade, will my bookmarks and favorites get transferred automatically? Or shd I do something different during the un-install of the current version?

    2- will the java programs be re-installed automatically, or shd I do it manually?





    Btw, I still have that irritating problem with the message about the explorer. And my internet explorer is still acting up and isn’t working !
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the order things are listed in the READ & RUN ME. Please remember to always follow steps in the order listed. There is a method to our madness. ;)

    They should remain and still be there. However if you want to be sure you can always back them up first or you could just download the new version and install it right over the old version.


    You already have the new version installed. You just did not uninstall all the old versions.


    Please explain your exact problems! I think the only thing you said about Windows Explorer is you get an error message when you shutdown your PC. Is that correct? If so, this more than likely not due to malware. Please describe your IE problem.

    Your system appears to already be running SP2 according to your logs!
     
  16. peyz

    peyz Private E-2

    Part 1 :

    Dear chaslang,

    I did as you recommended.

    Did the removal of the java programs, upgraded the firefox to version 2.0
    And now both runkeys and new files text doc’s are after the recent removals.

    I did fix the said problems in hijackthis scan. All except the second one, which was nowhere to be seen !!
    This is the one :
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>

    Looked for it, but it wasn’t there!!

    Then, went to safe mode and tried to find those two files in the system32 folder.
    C:\WINDOWS\System32\sfg_47a6.dll
    C:\WINDOWS\System32\kdpupd.dll
    Again, to no avail.
    They were missing too !


    This isn’t good, is it ?

    Ccleaner’s run too.

    Did the IE procedure, but couldn’t find the “Offline content” tab or option to delete.
     

    Attached Files:

  17. peyz

    peyz Private E-2

    Part 2:


    Now, onto the problem with my “Internet Explorer” and that error message.

    1- one of the main problems I came to you guys IS this problem with my Internet Explorer.
    A little background:
    Don’t know whether it is due to an incomplete or faulty installation of SP2, but eversince this upgrade, I haven’t been able to use the IE ( version 6 ) !
    Clicking on its desktop icon got me nowhere … except another “shortcut to IE” icon appearing on the desktop !
    Having purchased my Dell from the States, I see no reason why suddenly ( after installation of this SP2 , by CD - I must add ) have problems validating my windows.
    Each time I go through the process of validating, it just stops and gets stuck in the 3rd step of validation( where one needs to install or activate AtiveX from the info bar. Simply because I don’t see any info bar on my IE !! ) see PIC 1 - validation scrn shot.JPG attachment, plz.

    The only way to open an IE is clicking on the warning icon on my quick launch tray ( telling me I need to validate my windows and may be a victim of software counterfeiting – when I have NOT changed my original XP Home edition at all ) and voila, an IE opens up but with the following error message:
    See “ PIC 2 - windows valid'n error.JPG” attachment, plz.

    I also have tried to troubleshoot my way, using the Dell “Help and Support” program, which gets me nowhere as I presume it runs on the troublesome IE !!
    Ironic, isn’t it ?
    ( or it could be a mistake in IE configuration or … )


    2- For the past 2 days, everytime I try to shut down, that error message appears:

    It says :

    “End program – Explorer.exe

    This program is not responding

    To return to windows …
    If you choose to end the ….”

    Sometimes, 2-3 times in a row !
    And unless I click on “end now”, it just wont stop!

    BTW, I also cannot use the “defrag” program anymore, as the following message appears ( see “defrag.JPG” attachment ) !!
     

    Attached Files:

    Last edited: Nov 22, 2006
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem! HJT probably was able to delete them.


    Are you sure? It is not a tab! It is just a check box with in the Delete Files window that pops up.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your remaining issues are now outside the realm of topics for his forum. Sounds like you may need to do a repair install back to your original Win XP version from your CD. Seem like you either have files missing, or as one error message points out, a mismatch in versions from different SP levels of Windows.

    There have been dozens of issues that people have had with using Windows Update. This is also a topic better discussed in the Software Forum.


    Since we have removed a bunch of issues, attempting another install of your Win XP SP2 update may or may not help!
     
  20. peyz

    peyz Private E-2

    1- Oh, yeah. silly me, I did see the "offline content" and did delete it.
    my bad.

    2- Yes, I truly believe the crux of the issue is the installation of this SP2.
    whether it is an incomplete installation or faulty one , it is beyond me.
    I think I will take your suggestion and take this to the software forum.

    But thanks a million for helping me get rid of a whole bunch of malware and other critical issues.

    Thank you both, chaslang and TimW.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds