Solved

edit start up programs without starting windows

Posted on 2013-01-28
10
1,391 Views
Last Modified: 2013-11-22
I am trying to remove a virus from a computer which runs as soon as windows starts, I need to be able to disable the virus so I can deal with it but the whole screen has been taken over by a fake security program called PCeU which is asking for £100 to "unlock" the computer. I am unable to use task manager or the run command even in safe mode, I have tried last known good configuration and also tried using a windows disc to use system restore but apparently there are no restore points. I would like to be able to take this program out of the start up list as if I was using msconfig to access system configuration. Is this possible by accessing the hard drive using another computer and editing a file? The system is Windows 7 Home Premium.
0
Comment
Question by:it4
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +3
10 Comments
 
LVL 6

Expert Comment

by:CaptainGiblets
ID: 38827536
Can you press F8 while the PC is booting to force it to boot into safe mode?

From there you will be able to disable everything that boots on starting by clicking start > run > msconfig

you can also ammend the registry if things are still starting up.
0
 
LVL 9

Expert Comment

by:TunerML
ID: 38827540
You could also try using a recovery/rescue disc available free from many anti-virus companies to do a full scan of the system and remove the virus.

Kasperksy is available here: http://support.kaspersky.com/viruses/rescuedisk,

AVG, Avast and the other major players all have their various versions some free some not.
0
 
LVL 6

Expert Comment

by:CaptainGiblets
ID: 38827541
Sorry ignore my answer, i missed the line where you already said you had tried safe mode.
0
Salesforce Made Easy to Use

On-screen guidance at the moment of need enables you & your employees to focus on the core, you can now boost your adoption rates swiftly and simply with one easy tool.

 
LVL 6

Expert Comment

by:CaptainGiblets
ID: 38827574
There are 2 ways i can think of but could risk spreading the virus so make sure the other pc has good AV on it first.


1 - connect another PC to same subnet and try to access the registry over the network, however i have never tried this on a none domain pc so i dont know if it will work with just the ip address.

2 - plug your hard drive into a working pc, go into the registry editor and click file and then "load hive"

You should then be able to edit the other registry i think the file is located at C:\windows\system32\config

The keys you will be looking for are

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
 HKCU\Software\Microsoft\Windows\CurrentVersion\Run
 HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
 
For Windows 64-bit users you may also find entries listed under the following keys:-
 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
 HKLM\SOFTWARE\Wow6432Node\\Microsoft\Windows\CurrentVersion\RunOnce
 
Occasionally the following keys will also be used - primarily by malware:-
 
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
0
 
LVL 16

Accepted Solution

by:
Brian Pringle earned 500 total points
ID: 38827705
I use Ultimate Boot CD 4 Windows (http://www.ubcd4win.com).  You can either use the standard installation or you can customize it.

It does require for you to have a Windows XP computer or the XP installation disc (i386 folder) to build your own bootable disc.  

After booting, you will see a desktop similar to Windows XP.  From there, you can run regedit, load the hives listed above, and edit them.  

Just make sure that you UNLOAD the hives after editing them for them to get saved properly.
0
 
LVL 16

Expert Comment

by:Brian Pringle
ID: 38827707
UBCD4Win will work with Windows 7, even though it is based on Windows XP.
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 38827901
I will second the recommendation for the Kapersky Rescue Disk.  It boots by itself since it is a Linux Live disk.  You need an active internet connection so it can download it's current definitions but it will scan your hard without booting up Windows.
0
 
LVL 28

Expert Comment

by:Thomas Zucker-Scharff
ID: 38828018
If you are going to use an alternate boot disk, I highly suggest one created with SARDU, that way you have everything (including the kitchen sink) in one place.  This generally means booting to a USB device - but SARDU creates that for you.  See my article:

http://www.experts-exchange.com/Storage/Misc/A_3038-Boot-Disks-UBCD-UBCD4Win-and-SARDU.html
0
 

Author Closing Comment

by:it4
ID: 38876977
Thanks that worked
0
 
LVL 28

Expert Comment

by:Thomas Zucker-Scharff
ID: 38877023
I highly suggest you create a disk with SARDU anyway.  It will include UBCD if you wish, but it has so much more.  I use it all the time.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Malware seems to be getting smarter and smarter. If you are having trouble being able to launch your malware removal tools such as (and recommended): MalwareBytes, HiJackThis, ComboFix, etc. you can try some of the workarounds listed below. 1. Ma…
Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question