can i safely say dat the spyware has been removed from the com?Nope. I've just fixed your internet connections only.
Good to hear about it. That leaves just the registry for fixing, of which HijackThis will do the job.Originally posted by hiphop2009:i think avg anti spyware has removed the fake csrss.exe file for me liao. cant find it anywhere. i think i post it tonight and continue to remove. coz i going out soon. thanks mayi!
hohoho. think i screwed up the com. everytime i wan to post something on sgforum den dat com will hav blue screen of death and restart. hmm...Originally posted by ndmmxiaomayi:Good to hear about it. That leaves just the registry for fixing, of which HijackThis will do the job.
See you at night!
Originally posted by ndmmxiaomayi:i cant delete ntos.exe. it says it is being used by another program. anyway to help?
Nope. I've just fixed your internet connections only.
[b]Step 1
Download Itty Bitty Process Manager by Merijn from one the links below:
Merijn
DKnoppix
Bleeping Computer
Unite The Cows
Major Geeks
CastleCops
SpywareInfo[*]Locate the ibprocman.zip that you've downloaded earlier.
Note: Be very careful when killing this process. There's a legitimate csrss.exe which is located in C:\Windows\system32. The fake one is in C:\Windows.
[*]Right click on ibprocman.zip and select Extract All....
[*]Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
[*]Click on the Browse button. Click on Desktop. Then click OK.
[*]Check (tick) the Show extracted files box.
[*]Double click on IBProcMan.exe to start it.
[*]Locate C:\WINDOWS\csrss.exe. Click once to select it. Click on the Kill Process button to end it.
Step 2
Next, open HijackThis and select Do a system scan only.
Check (tick) these lines:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O4 - HKLM\..\Run: [csrss] C:\WINDOWS\csrss.exe
O4 - HKCU\..\Run: [userinit] C:\WINDOWS\system32\ntos.exe
O23 - Service: Remote Procedure Call System(RPCS) (RpcS) - Unknown owner - C:\WINDOWS\system32\Windox.exe (file missing)
Click on Fix checked button.
Step 3
Go to C:\Windows\system32 and locate Windox.exe. Zipped up this file and email me. My email address is in my profile.
Step 4
Show hidden files and folders[*]Open My Computer.
[*]Go to Tools > Folder Options.
[*]Select the View tab.
[*]Scroll down to Hidden files and folders.
[*]Select Show hidden files and folders.
[*]Uncheck (untick) Hide extensions of known file types.
[*]Uncheck (untick) Hide protected operating system files (Recommended).
[*]Click Yes when prompted.
[*]Click OK.
[*]Close My Computer.
Step 5
Restart your computer in Safe Mode.[*]When you see BIOS screen, start pressing F8.
[*]A boot menu will appear shortly.
[*]Using the up down arrows, select Safe Mode and press the Enter key.
[*]Windows will now load.
[*]Log in to your usual account.
Delete these files.
C:\WINDOWS\system32\ntos.exe
C:\WINDOWS\csrss.exe
C:\WINDOWS\system32\Windox.exe
Reboot into Normal Mode and post back a new HijackThis log.[/b]
Right click on My Computer, select Properties.Originally posted by hiphop2009:hohoho. think i screwed up the com. everytime i wan to post something on sgforum den dat com will hav blue screen of death and restart. hmm...
Did you fix the line with HijackThis first, then attempt to delete the file? Otherwise, the registry traces will prevent it from being deleted.Originally posted by hiphop2009:i cant delete ntos.exe. it says it is being used by another program. anyway to help?
when i use hijiackthis to delete this:Originally posted by ndmmxiaomayi:Did you fix the line with HijackThis first, then attempt to delete the file? Otherwise, the registry traces will prevent it from being deleted.
Originally posted by ndmmxiaomayi:hais. thanks mayi, but i think i screwed the com. when i start, it says windows cannot load coz system 32.hal.dll file is missing. i use xubuntu to start n realise the harddisk's file inside the system 32 file missing. muz be i use the compaq recovery thing den halfway den i juz switched it off. haiss. i only got one win XP CD with me though....how how how? i use xubuntu but i cant seems to copy the system 32 files (which i copied from another computers into my external harddisk) to the harddrive. help mayi help!
Download KillBox by Option^Explicit. Save it to your desktop.
Locate these two files and zipped them up. Email them to me.
[b]C:\WINDOWS\windosnwa.exe
C:\WINDOWS\system32\Windox.exe
Open HijackThis, select Do a system scan only.
Put a tick for these lines:
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\ntos.exe,
O4 - HKCU\..\Run: [userinit] C:\WINDOWS\system32\ntos.exe
O23 - Service: GrayPigeonServer - Unknown owner - C:\WINDOWS\windosnwa.exe (file missing)
O23 - Service: Remote Procedure Call System(RPCS) (RpcS) - Unknown owner - C:\WINDOWS\system32\Windox.exe (file missing)
Click Fix checked.
Next, start KillBox.
Select Delete on Reboot button. Copy the bolded files below.
C:\WINDOWS\system32\ntos.exe
C:\WINDOWS\windosnwa.exe
C:\WINDOWS\system32\Windox.exe
Go to KillBox, select File > Paste From Clipboard.
Then click on the red button with a white X
Your computer will reboot, if it doesn't, just reboot manually.
KillBox will delete these files on reboot, so your system might take some time to start.
Post a new HijackThis log.[/b]
Wah, just nice I was researching about your error and about to write a guide on it.Originally posted by hiphop2009:hais. thanks mayi, but i think i screwed the com. when i start, it says windows cannot load coz system 32.hal.dll file is missing. i use xubuntu to start n realise the harddisk's file inside the system 32 file missing. muz be i use the compaq recovery thing den halfway den i juz switched it off. haiss. i only got one win XP CD with me though....how how how? i use xubuntu but i cant seems to copy the system 32 files (which i copied from another computers into my external harddisk) to the harddrive. help mayi help!
Originally posted by ndmmxiaomayi:haha. hmm. i think nvm, i juz return dat com back to compaq to service bah. nt feeling well. n lots of quizz and test coming up. sianx.....
Wah, just nice I was researching about your error and about to write a guide on it.
But since it's a recovery CD, I don't know if it works.
Boot up the XP Recovery CD, type R to use the Recovery Console
Then enter the administrator's password to log in.
In the Command Line, type in the following line by line. After each line, press Enter.
[b]cd C:\WINDOWS\ServicePackFiles\i386
copy hal.dll c:\Windows\System32
By the way, to use the Linux method, you need to use Knoppix, not Xubuntu. Xubuntu can't do the job.[/b]
did dat. lol. anyway. thanx! i am off to bed liao. =)Originally posted by ltachi:dont fret.first of all go to www.download.com
search for 'AD-AWARE SE PERSONAL'.download it.then do a scan.removed all of my spyware.good stuff man![]()
Running via CD right? If yes, it will get stuck for a while. CD reading speeds are slower.Originally posted by hiphop2009:haha. hmm. i think nvm, i juz return dat com back to compaq to service bah. nt feeling well. n lots of quizz and test coming up. sianx.....
hmm, when i run knoppix, it seems to be stuck lehz. dunnoe why. hmm....
nvm, thanks a million for the trouble mayi!. so pai seh lehz.....
coz, the thing is, wireless connection got prob. den windows say firewall cannot be started and all those crap.Originally posted by ndmmxiaomayi:It's lagging because it has so many things running.
And why is Itty Bitty Process Manager running directly via WinRAR?
Windows Firewall can't start... I think it's related to school... because the homepage is a school website.Originally posted by hiphop2009:coz, the thing is, wireless connection got prob. den windows say firewall cannot be started and all those crap.
IBM laptop, den hav all those thinkvantage stuff. dats why a lot of processes. but it isnt laggy, the prob is, wireless cant connect.....hmm....