Appreciate some help.
Helping someone with malware problems:
http://forums.tomcoyote.org/index.php?show…30&#entry195493
Some reports have incomplete data appearing to point to problems with regedit.
Asked them to use sfc /scannow, but it is no-go:
"…it asked for a the Windows XP Home Edition Service Pack 2 cd…….I never had a service pack 2 CD, I bought the upgrade and then windows automatically updated to service pack 2 after I installed it. In fact I think I had XP before service pack two came out. Every time it asked for the CD it said it was not the correct CD and told me to retry??
Any easy suggestions??
Thank you in advance for the help.
Thanks for the reply, Bobbi Flekman.
Thought sfc /scannow could replace damaged files, etc., and also take care of any other errors, like NTVDM.
It appears that the individual keeps getting the following when attempting sfc:
The CD you provided is the wrong CD.
Please insert the Windows XP Professional Service Pack 2 CD into your CD-ROM drive.
There are also some malware files that just do not want to go away.
Do you think a repair install should be done if the system cannot be cleaned up?
Thought sfc /scannow could replace damaged files, etc., and also take care of any other errors, like NTVDM.
Yep.. But as you know sometimes things fail. So I hoped that this would help.
QUOTE(FZWG @ Aug 7 2005, 09:14 PM)
…
The CD you provided is the wrong CD.
Please insert the Windows XP Professional Service Pack 2 CD into your CD-ROM drive.
…
She probably installed (or got it installed) as SP-1. She updated through Windows Update to SP-2. Therefore the disc is indeed different. Windows expects a SP-2 one now…. When this gets resolved, she can slipstream the CD to a SP-2 one.
http://www.theeldergeek.com/slipstreamed_xpsp2_cd.htm
"…When this gets resolved she can slipstream the CD to a SP-2 one…"
Catch 22: she will need to slipstream the CD to a SP-2 before sfc /scannow works!!
Arrrghhhh!!!
You do not need to slipstream a cd for this and even if you do the same problem will still occur. The problem is that windows cannot find the I386 folder. You need to point it at the directory that contains the I386 folder, not at the I386 folder itself. For example, if the path is d:\i386 then then just browse to d:\ and click ok. What happens is windows gets installed from, say, the E:\ drive and then you put the cd in the F:\ drive or maybe they partitioned the hard drive and the drive letters changed that way.. Now you would think that they would make sfc smart enough to search whatever drive you put the cd in but they don't. Go figure.
As far as SP2 goes, they did make sfc smart enough to know where to get the different versions of the files. It knows when to go to the cd and when to go to C:\WINDOWS\ServicePackFiles
If they have room on the hard drive for about 450 MB then have them copy the complete I386 folder from the hard drive to C:\, or whatever their root install drive is. SFC will run much faster that way and if the system needs to replace a file during bootup they will be there. You need to change the following reg key to point to c:\, notice that mine points to e:\. If they run it from the cd then just change it to point to the proper drive. Have them browse the CD to make sure of where the I386 folder is, some OEM cds will put it inside another folder.
rand1038,
Thank you for the useful information.
So the sequence of events should be:
-Go to the XP CD and locate the folder called: I386 (Starts with the letter “I”)
-Copy I386 to C:\ on the hard drive (You should end up with a folder that looks like: C:\I386)
-Run regedit and navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Setup
Look for: SourcePath
Right click Source Path
Select: Modify
In the value data enter: C:\ or C: (whichever works)
Restart the computer
Try sfc /scannow once again
Or use the reg-merge:
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup]
"SourcePath"="c:\\"
Thanks again for the help.
Yes. Don't bother with a reg merge, it's easy enough to edit the registry on this one.
If they still have problems then have them export that key (its a pretty long one) and check the service pack paths to make sure they are correct.
"ServicePackSourcePath"="c:\\windows\\ServicePackFiles"
"ServicePackCachePath"="c:\\windows\\ServicePackFiles\\ServicePackCache"
The file name starts with the letter "eye" I386.
Thanks, rand1038!!
Looks as if she tried running sfc /scannow, but still no-go.
Is the following what she should find in the Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
Source Path = C: (or should it be C:\)
ServicePackSourcePath = C:\Windows\ServicePackFiles
ServicePackCachePath = C:\Windows\ServicePackFiles\ServicePackCache
Certainly appreciate your help.
Have her export that key and post it so you can see what is there. It should look pretty much the same as what I posted.
She may be missing the service pack files. Hopefully not but its possible.
Check the key she posts then have her check the locations for the service pack files. Maybe those values don't point to the actual SPF folders or the folders don't exist.
Sounds good.
What if she is missing the Service Pack Files?!
"Check the key she posts then have her check the locations for the service pack files…"
On the above…can't seem to find C:\Windows\ServicePackFiles on my own computer!!
Can you provide some enlightment?
Thanks again.
I have it on mine. I downloaded the full service pack image from MS. I'm not sure what you get if you slipstream an install on XP, I haven't done it, but if it is the same as 2000 (which it probably is) then you don't get any "extra" folders.
How was your system installed?
For the incremental updates you get the C:\WINDOWS\$NtUninstallKB903235$ type of folders which are used for rolling back patches.
Have her check on her machine and see if she has the servicepackfiles folder. If she doesn't she can download the service pack files and copy the I386 folder to c:\windows\ServicePackFiles so she ends up with I386 as a subfolder there.
Took out the hard way to do things, see next post.