Solved

XP Activation error after manual clean of NICEWARE

Posted on 2010-11-08
9
705 Views
Last Modified: 2012-05-10
HELP!!!!

I am running XP SP3.

Two days ago I managed to install an EXE that had a Trojan in it. Kaspersky did not pick it up pre installation.

After running Kapsersky, it appeared but would not get rid of it. The issue I have is called NICEWARE.

Basically it pops IE8 over and over again with adverts.

I did some research and saw that IFY.EXE was causing the issue.

I looked in MSCONFIG and it formed part of my Boot Up.

So......................

Switched into Safe Mode. Deleted IFY and all the others from TEMP and PRE FETCH.

Rebooted, rescanned and then Windows said I needed to activate my product.

Looked in Registry and it looks like something is stuck in SOFTWARE / CURRENT VERSION / RUN

Thus I now have two issues. I have attempted to get rid of IE8 using REVO but it did not seem to work. In fact I would say it failed half way through. Never seen REVO fail.

Thus I went in Control Panel, and I think IE8 has gone.................except lo & behold.............adverts popping in IE8.

Second part of crisis is that I cannot activate my genuine product.

I click activate, opens a blue window with two failed images, or at least I think they are failed images. Nothing happens, cant click anything, cant do anything with it in Safe Mode.

Really out of options.....................

Thanks

Julian
0
Comment
Question by:77Seven
9 Comments
 
LVL 1

Accepted Solution

by:
neuroskunk earned 125 total points
Comment Utility
First of all, do this:
Input XP installation CD in tray.
Start - Run - sfc /scannow
After complete - reboot.
This command restore broken system files.
0
 

Author Comment

by:77Seven
Comment Utility
Hi neuro skunk, I have removed my CD drive. I can go try borrow one, is there anyway I can get those files?

Is that what you think is wrong a broken sys file?

0
 
LVL 7

Assisted Solution

by:compaqus
compaqus earned 125 total points
Comment Utility
I would recommend Spyboot to clean the system

 http://www.safer-networking.org/en/mirrors/index.html

Then we'll get to the activation part.

0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 125 total points
Comment Utility
Might be best to remove those problem files/RUN entries while the drive is slaved to another machine.
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 

Author Comment

by:77Seven
Comment Utility
Tried that from CD (borrowed a drive), it was struggling with DLLs.

I have just tried again...will update ASAP
0
 

Author Comment

by:77Seven
Comment Utility
Its saying that files required must be copied to the DLL cache.

I have a CD drive attached via USB. It has my original gen CD in. I try RETRY, makes no differnce?

any ideas??
0
 
LVL 1

Expert Comment

by:neuroskunk
Comment Utility

Try to mount or unarchive iso image, but I afraid, sfc command too simple for asking location of files.

Also try to activate by Microsoft key update tool
http://www.microsoft.com/genuine/selfhelp/pkuinstructions.aspx

I dont advice you install any new third-party software in this situation.
And NEVER use more than one antivirus at time. It can lead to seriuos problems.
0
 
LVL 22

Assisted Solution

by:optoma
optoma earned 125 total points
Comment Utility
Download IE8 stanalone installer and install IE8 in safe mode with command prompt.
On reboot to normal mode, activation process should continue normally.
http://www.microsoft.com/windows/internet-explorer/worldwide-sites.aspx

Then run these in normal mode
Run TdssKiller and Hitmanpro.
http://support.kaspersky.com/viruses/solutions?qid=208280684
http://www.surfright.nl/en/hitmanpro

If still having issue run Combofix and post log here
http://www.bleepingcomputer.com/combofix/how-to-use-combofix


>Tools may be required to be downloaded on another machine and transferred via removable device

>If they still dont run, redownload them but rename them prior to saving them
0
 

Author Closing Comment

by:77Seven
Comment Utility
None of it worked. I had to rebuild machine. Gutted....

Great advice though
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

cPanel is a Unix based web hosting control panel that provides a graphical interface and automation tools designed to simplify the process of hosting a web site. cPanel utilizes a 3 tier structure that provides functionality for administrators, rese…
It is only natural that we all want our PCs to be in good working order, improved system performance, so that is exactly how programs are advertised to entice. They say things like:            •      PC crashes? Get registry cleaner to repair it!    …
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now