Forum Home Forum Home > Topics not related to music > General discussions
  New Posts New Posts RSS Feed - Windows XP Service Startup issue
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Topic ClosedWindows XP Service Startup issue

 Post Reply Post Reply Page  12>
Author
Message Reverse Sort Order
chopper View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: July 13 2005
Location: Essex, UK
Status: Offline
Points: 20029
Direct Link To This Post Topic: Windows XP Service Startup issue
    Posted: May 29 2010 at 17:35
OK, I seem to be all sorted now. Turned out I had a virus called TDSS. With the help of Dr Web, which cleared a process from memory and a few other nasties as well, and a program called TDSSKiller.exe all my services now start okay so hopefully my web searches won't get diverted either.

Thanks for your help everyone.
Back to Top
chopper View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: July 13 2005
Location: Essex, UK
Status: Offline
Points: 20029
Direct Link To This Post Posted: May 29 2010 at 06:05
Originally posted by A Person A Person wrote:

My computer was slowing way down, but it turned out there was a dust bunny in the fan on my video card, it's sped up considerably since then. LOL


Check out a freeware program called SpeedFan. I had a problem with my PC shutting down on it's own. Turned out to be overheating, SpeedFan will tell you the temperature of your CPU and hard disk. If the CPU is running hot then dust on the fan is a likely cause. It certainly was on mine.
Back to Top
chopper View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: July 13 2005
Location: Essex, UK
Status: Offline
Points: 20029
Direct Link To This Post Posted: May 29 2010 at 06:03
Originally posted by James James wrote:


However, I use Firefox with AdBlock + and I am usually very careful.  Of course, that doesn't mean I could not still get one, of course.


Exactly. I too have Firefox with AdBlock but it hasn't stopped me picking up something untoward.
Back to Top
A Person View Drop Down
Forum Senior Member
Forum Senior Member
Avatar

Joined: November 10 2008
Location: __
Status: Offline
Points: 65760
Direct Link To This Post Posted: May 28 2010 at 22:16
My computer was slowing way down, but it turned out there was a dust bunny in the fan on my video card, it's sped up considerably since then. LOL

Edited by A Person - May 28 2010 at 22:16
Back to Top
VanderGraafKommandöh View Drop Down
Prog Reviewer
Prog Reviewer
Avatar

Joined: July 04 2005
Location: Malaria
Status: Offline
Points: 89372
Direct Link To This Post Posted: May 28 2010 at 22:09
Damn, I might have one without realising it then... or would it be obvious if I did?

However, I use Firefox with AdBlock + and I am usually very careful.  Of course, that doesn't mean I could not still get one, of course.


Edited by James - May 28 2010 at 22:09
Back to Top
Falx View Drop Down
Forum Senior Member
Forum Senior Member
Avatar

Joined: May 05 2010
Location: New Zealand
Status: Offline
Points: 859
Direct Link To This Post Posted: May 28 2010 at 20:03
Originally posted by James James wrote:

Have you got a HijackThis log?  I'm not sure if RootKits will show up on there though.

I often use CCleaner to clear my Registry.  Of course, that won't really help your situation but it's a useful bit of software.

Rootkits are way over HijackThis's head, they normally live in c:\windows\system32\drivers and are loaded while the OS is booting. The only way to get rid of them is to pull the hard disk and scan it in another computer, or boot off a live CD (e.g. ERD Commander) and remove the file yourself, if you know where it is.

=F=
"You must go beyond the limit of the limit of your limits!" - Mr. Doctor
"It is our duty as men and women to proceed as though the limits of our abilities do not exist." - Pierre Teilhard de Chardin
Back to Top
Falx View Drop Down
Forum Senior Member
Forum Senior Member
Avatar

Joined: May 05 2010
Location: New Zealand
Status: Offline
Points: 859
Direct Link To This Post Posted: May 28 2010 at 20:00
Originally posted by Slartibartfast Slartibartfast wrote:

Bill Gates is evil and must be destroyed. Tongue

If Bill Gates is the Emperor, then Steve Jobs is Darth Vader Ermm
"You must go beyond the limit of the limit of your limits!" - Mr. Doctor
"It is our duty as men and women to proceed as though the limits of our abilities do not exist." - Pierre Teilhard de Chardin
Back to Top
chopper View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: July 13 2005
Location: Essex, UK
Status: Offline
Points: 20029
Direct Link To This Post Posted: May 28 2010 at 17:46
Running Dr Web now, it's found another bit of the TDSS virus I thought I'd cleared.
Back to Top
VanderGraafKommandöh View Drop Down
Prog Reviewer
Prog Reviewer
Avatar

Joined: July 04 2005
Location: Malaria
Status: Offline
Points: 89372
Direct Link To This Post Posted: May 28 2010 at 14:10
Have you got a HijackThis log?  I'm not sure if RootKits will show up on there though.

I often use CCleaner to clear my Registry.  Of course, that won't really help your situation but it's a useful bit of software.
Back to Top
Slartibartfast View Drop Down
Collaborator
Collaborator
Avatar
Honorary Collaborator / In Memoriam

Joined: April 29 2006
Location: Atlantais
Status: Offline
Points: 29630
Direct Link To This Post Posted: May 28 2010 at 12:08
Bill Gates is evil and must be destroyed. Tongue
Released date are often when it it impacted you but recorded dates are when it really happened...

Back to Top
Epignosis View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: December 30 2007
Location: Raeford, NC
Status: Offline
Points: 32524
Direct Link To This Post Posted: May 28 2010 at 10:09
Originally posted by Dean Dean wrote:

Originally posted by Epignosis Epignosis wrote:

Originally posted by Dean Dean wrote:

Originally posted by chopper chopper wrote:

Thanks for the advise everyone. I'm going to try Dr Web at least (speed isn't really an issue, I'll just leave it running overnight if I have to).  Something else is also redirecting some of my web searches to another search engine so I need to get rid of that as well.
 
Quite why anyone thinks this is going to benefit them I don't know. If I want to go to a site for a reason and they divert elsewhere, I'm not going to think "Oh ok, I'll have a look here instead". Just Censored off will you.
 
Rant over.
Shocked stop!
 
This is what rootkits do! You are definitely infected and anything you send or recieve is suspect. The reasonn it shows on Themes and DHCP is because it patches itself into whatever is in your boot sequence (msconfig ->startup) - those fail because the patch failed, but other processes were patched and didn't fail,which is why your search is being redirected.
 
I don't trust av software to 100% remove a rootkit - most just remove the symptoms, which will return again sometime in the future - the only guaranteed safe recovery is reformat your harddrive and reinstall XP. Dead


You may be right Dean, but I've not had a single problem since November.  Granted it took three days, ten different programs, and screwing around in the registry among other things.

Assuming there is still a rootkit problem somewhere on my hard drive, what would cause it to "return in force?"
Rootkits patch themselves into the operating system so they load before any antiviral software, to do this they attack the o/s at quite a low level and infect as much of it they can, if it has attached itself to a little used piece of the o/s it may be months before that is ever used, but once it is, out pops the virus. It could be anything, even just plugging a new piece of hardware could invoke an infected dll.
 
You've been okay for 7 months, you're probably safe.
 
I have to admit that for an Admin looking after a dozen desktop PC's three days and ten programs is far to time consuming for me - it takes me a hour to reinstall XP and Office and another hour to restore any data files from backups - I could ghost them, but that's impractical. If the user has lost anything, it's not my problem - they should have backed it up. (yeah, I'm Mr Hard Nose)


I'm just really stubborn, I guess.  LOL Embarrassed
Back to Top
Dean View Drop Down
Special Collaborator
Special Collaborator
Avatar
Retired Admin and Amateur Layabout

Joined: May 13 2007
Location: Europe
Status: Offline
Points: 37575
Direct Link To This Post Posted: May 28 2010 at 09:59
Originally posted by Epignosis Epignosis wrote:

Originally posted by Dean Dean wrote:

Originally posted by chopper chopper wrote:

Thanks for the advise everyone. I'm going to try Dr Web at least (speed isn't really an issue, I'll just leave it running overnight if I have to).  Something else is also redirecting some of my web searches to another search engine so I need to get rid of that as well.
 
Quite why anyone thinks this is going to benefit them I don't know. If I want to go to a site for a reason and they divert elsewhere, I'm not going to think "Oh ok, I'll have a look here instead". Just Censored off will you.
 
Rant over.
Shocked stop!
 
This is what rootkits do! You are definitely infected and anything you send or recieve is suspect. The reasonn it shows on Themes and DHCP is because it patches itself into whatever is in your boot sequence (msconfig ->startup) - those fail because the patch failed, but other processes were patched and didn't fail,which is why your search is being redirected.
 
I don't trust av software to 100% remove a rootkit - most just remove the symptoms, which will return again sometime in the future - the only guaranteed safe recovery is reformat your harddrive and reinstall XP. Dead


You may be right Dean, but I've not had a single problem since November.  Granted it took three days, ten different programs, and screwing around in the registry among other things.

Assuming there is still a rootkit problem somewhere on my hard drive, what would cause it to "return in force?"
Rootkits patch themselves into the operating system so they load before any antiviral software, to do this they attack the o/s at quite a low level and infect as much of it they can, if it has attached itself to a little used piece of the o/s it may be months before that is ever used, but once it is, out pops the virus. It could be anything, even just plugging a new piece of hardware could invoke an infected dll.
 
You've been okay for 7 months, you're probably safe.
 
I have to admit that for an Admin looking after a dozen desktop PC's three days and ten programs is far to time consuming for me - it takes me a hour to reinstall XP and Office and another hour to restore any data files from backups - I could ghost them, but that's impractical. If the user has lost anything, it's not my problem - they should have backed it up. (yeah, I'm Mr Hard Nose)
What?
Back to Top
Epignosis View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: December 30 2007
Location: Raeford, NC
Status: Offline
Points: 32524
Direct Link To This Post Posted: May 28 2010 at 09:45
Originally posted by Dean Dean wrote:

Originally posted by chopper chopper wrote:

Thanks for the advise everyone. I'm going to try Dr Web at least (speed isn't really an issue, I'll just leave it running overnight if I have to).  Something else is also redirecting some of my web searches to another search engine so I need to get rid of that as well.
 
Quite why anyone thinks this is going to benefit them I don't know. If I want to go to a site for a reason and they divert elsewhere, I'm not going to think "Oh ok, I'll have a look here instead". Just Censored off will you.
 
Rant over.
Shocked stop!
 
This is what rootkits do! You are definitely infected and anything you send or recieve is suspect. The reasonn it shows on Themes and DHCP is because it patches itself into whatever is in your boot sequence (msconfig ->startup) - those fail because the patch failed, but other processes were patched and didn't fail,which is why your search is being redirected.
 
I don't trust av software to 100% remove a rootkit - most just remove the symptoms, which will return again sometime in the future - the only guaranteed safe recovery is reformat your harddrive and reinstall XP. Dead


You may be right Dean, but I've not had a single problem since November.  Granted it took three days, ten different programs, and screwing around in the registry among other things.

Assuming there is still a rootkit problem somewhere on my hard drive, what would cause it to "return in force?"
Back to Top
Dean View Drop Down
Special Collaborator
Special Collaborator
Avatar
Retired Admin and Amateur Layabout

Joined: May 13 2007
Location: Europe
Status: Offline
Points: 37575
Direct Link To This Post Posted: May 28 2010 at 09:35
Originally posted by chopper chopper wrote:

Thanks for the advise everyone. I'm going to try Dr Web at least (speed isn't really an issue, I'll just leave it running overnight if I have to).  Something else is also redirecting some of my web searches to another search engine so I need to get rid of that as well.
 
Quite why anyone thinks this is going to benefit them I don't know. If I want to go to a site for a reason and they divert elsewhere, I'm not going to think "Oh ok, I'll have a look here instead". Just Censored off will you.
 
Rant over.
Shocked stop!
 
This is what rootkits do! You are definitely infected and anything you send or recieve is suspect. The reasonn it shows on Themes and DHCP is because it patches itself into whatever is in your boot sequence (msconfig ->startup) - those fail because the patch failed, but other processes were patched and didn't fail,which is why your search is being redirected.
 
I don't trust av software to 100% remove a rootkit - most just remove the symptoms, which will return again sometime in the future - the only guaranteed safe recovery is reformat your harddrive and reinstall XP. Dead
What?
Back to Top
chopper View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: July 13 2005
Location: Essex, UK
Status: Offline
Points: 20029
Direct Link To This Post Posted: May 28 2010 at 08:52
Thanks for the advise everyone. I'm going to try Dr Web at least (speed isn't really an issue, I'll just leave it running overnight if I have to).  Something else is also redirecting some of my web searches to another search engine so I need to get rid of that as well.
 
Quite why anyone thinks this is going to benefit them I don't know. If I want to go to a site for a reason and they divert elsewhere, I'm not going to think "Oh ok, I'll have a look here instead". Just Censored off will you.
 
Rant over.
Back to Top
Falx View Drop Down
Forum Senior Member
Forum Senior Member
Avatar

Joined: May 05 2010
Location: New Zealand
Status: Offline
Points: 859
Direct Link To This Post Posted: May 28 2010 at 07:33
Originally posted by Epignosis Epignosis wrote:

Originally posted by chopper chopper wrote:

Originally posted by Epignosis Epignosis wrote:

You may recall I had a rootkit issue about six months ago

It was a nightmare.  I even fell into the trap of forcing my PC to start in safe mode- this particular virus had disabled safe mode altogether, which meant my computer wouldn't boot up at all
I wound up having to boot from my Windows XP disc and do all manner of Geek things.

It took three days, ten different programs, and some intensive manual tweaking to get things back to normal.  Dead
Thanks, I've just read that thread, you mentioned "I ran a program that took over seven hours just to scan both drives, and it caught myriad things I wouldn't have thought of" - what program was that?

I'm pretty sure that was drweb-cureit.

No guarantees of course, but this one and Malwarebytes Anti-malware proved to be the most effective. 

Doctor Web just takes forever because it's slow, its detection rate isn't that great¹. But it's useful to have, and is the only effective way of removing the Mebroot trojan (nasty lil' bugger) I've found.

¹ http://www.virus.gr/portal/en/content/2009-08%2C-10-august-05-september

=F=


Edited by Falx - May 28 2010 at 07:41
"You must go beyond the limit of the limit of your limits!" - Mr. Doctor
"It is our duty as men and women to proceed as though the limits of our abilities do not exist." - Pierre Teilhard de Chardin
Back to Top
Epignosis View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: December 30 2007
Location: Raeford, NC
Status: Offline
Points: 32524
Direct Link To This Post Posted: May 28 2010 at 07:28
Originally posted by chopper chopper wrote:

Originally posted by Epignosis Epignosis wrote:

You may recall I had a rootkit issue about six months ago

It was a nightmare.  I even fell into the trap of forcing my PC to start in safe mode- this particular virus had disabled safe mode altogether, which meant my computer wouldn't boot up at all
I wound up having to boot from my Windows XP disc and do all manner of Geek things.

It took three days, ten different programs, and some intensive manual tweaking to get things back to normal.  Dead
Thanks, I've just read that thread, you mentioned "I ran a program that took over seven hours just to scan both drives, and it caught myriad things I wouldn't have thought of" - what program was that?


I'm pretty sure that was drweb-cureit.

No guarantees of course, but this one and Malwarebytes Anti-malware proved to be the most effective. 


Back to Top
chopper View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: July 13 2005
Location: Essex, UK
Status: Offline
Points: 20029
Direct Link To This Post Posted: May 28 2010 at 07:23
Originally posted by Epignosis Epignosis wrote:

You may recall I had a rootkit issue about six months ago

It was a nightmare.  I even fell into the trap of forcing my PC to start in safe mode- this particular virus had disabled safe mode altogether, which meant my computer wouldn't boot up at all
I wound up having to boot from my Windows XP disc and do all manner of Geek things.

It took three days, ten different programs, and some intensive manual tweaking to get things back to normal.  Dead
Thanks, I've just read that thread, you mentioned "I ran a program that took over seven hours just to scan both drives, and it caught myriad things I wouldn't have thought of" - what program was that?
Back to Top
Falx View Drop Down
Forum Senior Member
Forum Senior Member
Avatar

Joined: May 05 2010
Location: New Zealand
Status: Offline
Points: 859
Direct Link To This Post Posted: May 28 2010 at 07:22
Originally posted by Dean Dean wrote:

It's possibly a rootkit (virus) that's attempting to take over those services. If it is, then you're stuffed - lots of apps claim to remove rootkits, but none of them do. You can try doing a system restore but that's unlikely to work either.


Or you pay someone like me to fix it... I removed a pretty nice rootkit from one computer this week, AVG Free (!) was the only antivirus that picked it up LOL

=F=
"You must go beyond the limit of the limit of your limits!" - Mr. Doctor
"It is our duty as men and women to proceed as though the limits of our abilities do not exist." - Pierre Teilhard de Chardin
Back to Top
chopper View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: July 13 2005
Location: Essex, UK
Status: Offline
Points: 20029
Direct Link To This Post Posted: May 28 2010 at 07:16
Originally posted by Dean Dean wrote:

It's possibly a rootkit (virus) that's attempting to take over those services. If it is, then you're stuffed - lots of apps claim to remove rootkits, but none of them do. You can try doing a system restore but that's unlikely to work either.

Thanks for breaking it to me gently Dean. LOL and thanks to the others for the advice.
 
I've removed some more malware but still have the problem. Don't think I'll go for the system restore at the moment as it's an inconvenience rather than a major problem. I'm wondering why a rootkit type virus would want to take over my Themes service. DHCP I can maybe understand.
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down



This page was generated in 0.172 seconds.
Donate monthly and keep PA fast-loading and ad-free forever.