![]() ![]() |
Nov 18 2009, 05:00 PM
Post
#91
|
|
![]() Authentic Member Group: Malware Expert Posts: 179 Joined: 14-June 05 Member No.: 34,633 Operating System: XP Pro & Vista |
Hi arfon,
While working with the serv.txt log you uploaded I noticed that it appears some essential service keys are missing from your registry, and I need to verify. Please load MiniXP and Registry Editor PE, no user hive necessary, then copy and paste the contents of the code box below into a command window. CODE @echo off reg save HKLM\_REMOTE_SYSTEM\ControlSet005\services "%userprofile%\desktop\services.hiv" exit cls A file named services.hiv should appear on the desktop. Please upload that file to my submission channel. |
|
|
|
Nov 18 2009, 05:21 PM
Post
#92
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 4-October 09 Member No.: 88,235 Operating System: windows xp |
hi dave
file has been uploaded arfon |
|
|
|
Nov 18 2009, 05:49 PM
Post
#93
|
|
![]() Authentic Member Group: Malware Expert Posts: 179 Joined: 14-June 05 Member No.: 34,633 Operating System: XP Pro & Vista |
Received, thanks!
This may take me a while. |
|
|
|
Nov 18 2009, 08:51 PM
Post
#94
|
|
![]() Authentic Member Group: Malware Expert Posts: 179 Joined: 14-June 05 Member No.: 34,633 Operating System: XP Pro & Vista |
I found only a couple of inconsistencies and have fixed them.
Please download this file to the MiniXP desktop. Start Registry Editor PE, no user hive necessary. Once loaded, double click the downloaded file on the desktop. When it closes, exit the registry editor, wait for the All Finished message and restart to see if the machine will boot normally. |
|
|
|
Yesterday, 04:07 PM
Post
#95
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 4-October 09 Member No.: 88,235 Operating System: windows xp |
Hi Dave
sorry to say but the last updated file was not succesful .one thing i noticed on boot up that i havent seen before, just before the windows xp logo with strobing lights a mesage in top left corner . INVALID BOOT INI FILE BOOTING FROM C:\ WINDOWS\ dont know if that has any relevance Many thanks Arfon |
|
|
|
Yesterday, 09:15 PM
Post
#96
|
|
![]() Authentic Member Group: Malware Expert Posts: 179 Joined: 14-June 05 Member No.: 34,633 Operating System: XP Pro & Vista |
I'd like to make sure the hive was successfully imported. Please load MiniXP and Registry Editor PE, no user hive necessary, then copy and paste the contents of the code box below into a command window.
CODE @echo off reg save HKLM\_REMOTE_SYSTEM\ControlSet005\services "%userprofile%\desktop\services2.hiv" exit cls A file named services2.hiv should appear on the desktop. Please upload that file to my submission channel. Next, lets check the boot.ini file. Paste the following into the command window then post the log that opens. CODE type c:\boot.ini>%temp%\boot.txt
start notepad %temp%\boot.txt exit cls |
|
|
|
Today, 02:08 PM
Post
#97
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 4-October 09 Member No.: 88,235 Operating System: windows xp |
hello dave
i have posted a services2.hiv to your submission channel . i also ran the second boot ini file but the result in metapad came up blank. |
|
|
|
Today, 02:53 PM
Post
#98
|
|
![]() Authentic Member Group: Malware Expert Posts: 179 Joined: 14-June 05 Member No.: 34,633 Operating System: XP Pro & Vista |
The hive appears to have been merged successfully. Please take a look in Local Disk C: using Windows Explorer and tell me what files are there who's name begins with boot (like boot.ini, boot.backup, boot.basevid, etc).
This post has been edited by noahdfear: Today, 02:54 PM |
|
|
|
Today, 04:13 PM
Post
#99
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 4-October 09 Member No.: 88,235 Operating System: windows xp |
hi there are 2 files
1 boot.backup 2 boot.basevid |
|
|
|
Today, 04:21 PM
Post
#100
|
|
![]() Authentic Member Group: Malware Expert Posts: 179 Joined: 14-June 05 Member No.: 34,633 Operating System: XP Pro & Vista |
Please right click the boot.backup file and Rename to boot.ini
Still working on the next attempt at normal bootup. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
0 | dawniee | 0 | Today, 04:43 PM Last post by: dawniee |
|||
![]() |
2 | Ticker | 268 | Today, 03:59 PM Last post by: LDTate |
|||
![]() |
0 | Laertes | 8 | Today, 01:03 PM Last post by: Laertes |
|||
![]() |
5 | Calvin.sparta | 129 | Today, 09:45 AM Last post by: Calvin.sparta |
|||
|
Time is now: 20th November 2009 - 07:03 PM |