Jump to content

XP Home Security 2012


Recommended Posts

  • Replies 103
  • Created
  • Last Reply

Top Posters In This Topic

This is a list from the laptop event viewer, does this tell you anything?

==== Event Viewer Messages From Past Week ========

.

1/9/2012 9:02:29 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

1/9/2012 9:02:29 PM, error: Service Control Manager [7000] - The NetBios over Tcpip service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

1/9/2012 8:29:28 AM, error: Service Control Manager [7023] - The iPod Service service terminated with the following error: Security must be initialized before any interfaces are marshalled or unmarshalled. It cannot be changed once initialized.

1/9/2012 6:55:39 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.

1/9/2012 6:55:39 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.

1/7/2012 6:52:14 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: NetBT

1/12/2012 8:40:03 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

1/12/2012 8:37:37 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avipbb avkmgr Fips intelppm NetBT SASDIFSV SASKUTIL ssmdrv

1/12/2012 8:37:22 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

.

==== End Of File ===========================

Link to post
Share on other sites

In that case we can use an USB drive. NOTE: no need to create the vesamenu.c32 file in Notepad now, as it will be created after you finish the steps below!

Download http://unetbootin.sourceforge.net/unetbootin-xpud-windows-latest.exe & http://noahdfear.net/downloads/bootable/xPUD/xpud-0.9.2.iso to the desktop of your clean computer

  • Insert your USB drive
  • Press Start > My Computer > right click your USB drive > choose Format > Quick format
  • Double click the unetbootin-xpud-windows-387.exe that you just downloaded
  • Press Run then OK
  • Select the DiskImage option then click the browse button located on the right side of the textbox field.
  • Browse to and select the xpud-0.9.2.iso file you downloaded
  • Verify the correct drive letter is selected for your USB device then click OK
  • It will install a little bootable OS on your USB device
  • Once the files have been written to the device you will be prompted to reboot ~ do not reboot and instead just Exit the UNetbootin interface
  • After it has completed do not choose to reboot the clean computer simply close the installer

Link to post
Share on other sites

Run ntbrhive.exe one time on the flashdrive (if you already did that, do not do it again!). You'll receive a message that your flash drive is ready to collect hives.

Then boot in xPUD as instructed and follow the steps I posted in post #75 from here: "Boot the Sick computer with the CD you just burned" (except that instead of CD, you boot from USB).

Link to post
Share on other sites

Run ntbrhive.exe one time on the flashdrive (if you already did that, do not do it again!). You'll receive a message that your flash drive is ready to collect hives.

Then boot in xPUD as instructed and follow the steps I posted in post #75 from here: "Boot the Sick computer with the CD you just burned" (except that instead of CD, you boot from USB).

I checked the flash drive and there isn't anything on there with the name ntbrhive.exe...? Did I do something wrong?

Link to post
Share on other sites

Try Del or F11 and see if any of these bring up the boot order menu. If not, then enter the Bios and change the boot order manually (usually there is a Boot menu in Bios where you can specify what device to boot first from). You can access the BIOS by tapping F2 or Del usually.

Link to post
Share on other sites

In that case, please do the following:

Please go to Start=>Run (alternatively use Windows key+R), type regedit and click OK.

Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root

Right-Click Root and select Permissions...

Under Security type, highlight Everyone and put a check mark in the box under Allow next to Full Control.

Click Apply and OK.

Let me know if you were able to do this.

Link to post
Share on other sites

Yes, it allowed me to execute the fix.reg. Still no internet. I went to the network setup wizard, like I was going to add a new pc. It said found disconnected network hardware: (Wireless Network Connection) Atheros Wireless Network Adapter. Also my wireless switch does nothing. When I press it usually lights up.

Link to post
Share on other sites

Wow finally! :)

Next, it is very important we reset the permissions on the registry key we altered. This needs to be done to ensure your computer's security.

Please go to Start=>Run (alternatively use Windows key+R), type regedit and click OK.

Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root

Right-Click Root and select Permissions...

Under Security type, highlight Everyone and put a check mark in the box under Allow next to Read (the checkmark should still be there, only change it if it is not). Remove the checkmark in the box under Allow next to Full Control. It should look like in this image:

permissions.png

Click Apply and OK.

I think your computer is pretty clean already as it is. Do you have any problem left at this point? Please rerun DDS and post me a new attach.txt log (no need for dds.txt).

Link to post
Share on other sites

My apologies, I thought we ran it before and didn't double check.

Your version of Adobe Reader is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Adobe components and update:

  • Download the latest version of Adobe Reader Version X. and save it to your desktop.
  • Uncheck the "Free McAfee Security plan Plus" option or any other Toolbar you are offered
  • Click the download button at the bottom.
  • If you use Internet Explorer and do not wish to install the ActiveX element, simply click on the click here to download link on the next page.
  • Remove all older version of Adobe Reader: Go to Add/remove and uninstall all versions of Adobe Reader, Acrobat Reader and Adobe Acrobat.
    If you are unsure of how to use Add or Remove Programs, the please see this tutorial:How To Remove An Installed Program From Your Computer
  • Then from your desktop double-click on Adobe Reader to install the newest version.
    If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the "Adobe Setup - Welcome" window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.

Your Adobe Reader is now up to date!

Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system.

  • Download the latest version of Java Runtime Environment (JRE) Version 7u2.
  • Look for "JDK 7u2 (JDK or JRE).
  • Click the "Download JRE" button at the right.
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
    • Select "Windows x86 Offline" and click on jre-7-windows-i586.exe

    [*]Save it to your desktop

    [*]Close any programs you may have running - especially your web browser.

    [*]Uninstall all older versions of Java (any item with Java Runtime Environment, JRE or J2SE in the name).

    [*]Reboot your computer once all Java components are removed.

    [*]Install the newest version by double clicking (run as Administrator for Windows Vista/Seven) the downloaded file.

Please launch MBAM, update it and run a full scan. Post me the resulting log.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.