Windows XP responding unexpectedly

Status
Not open for further replies.

vibs_0825

Right off the assembly line
I am using the Windows XP Professional(No SP2). When I open the Taskmanager, or Regedit window, it will imediately go to background and i cannot see it on My windows. The same problem i am facing with the installtion of any software. It is going in background. Just for your information i have formatted the PC and reinstall the Win XP again , then also problem exist. Please let me know the solution to it.
 

Batistabomb

Deadman Walking
be some more clear , going background means are they disappearing ?

if so the monitor may be the exact culprit
 
OP
V

vibs_0825

Right off the assembly line
I am using Laptop, when i open the task manager , it will be on the screen for 10-20 secs and then it will go to background, and i can see the task mager green icon, but when i click on restore, it won't restore, however for regedit and startup tab (by running msconfig), it is disappearing in 4-5 seconds, then i need to reinvoke the application and again it disappears. This thing happening again and again.

My Microsoft office is working fine and the Internet is also working fine, the basic windows utility won't work.

I also want to tell one thing that while opening any application, some times back it was opening in notepad (system restore, windows media player....) any application except MS office, for that i have reinstall the windows and the issue resolved.But still the issue of disappearing is continuing now also.

Let me know if you need more info.

Please let me know the solution ASAP any one?
 
Last edited:

sakumar79

Technomancer
1. Try in Safe Mode.
2. Run Antivirus scan, antimalware scan, etc with latest updates. This also is better to be done in safe mode as it will remove files better...

Arun
 
OP
V

vibs_0825

Right off the assembly line
Thanks for help the issue has been resolved. It was infected with the virus funny ust scandal.exe

Please follow the method given below.
Automatic remover = Download from this URL:

*www.geocities.com/six519/Remover.zip

Manual Method
Software used to build the virus= AutoIt V3
drop Files- killer.exe(4084 kb) in c:\windows\
lsass.exe(3920kb) in c:\documents and settings\all users\start menu\programs\startup
smss.exe(4088kb) in all root drives and in c:\windows
autorun.inf(1kb) in all root drives with a script

[autorun]
open=smss.exe
shell\Open\Command=smss.exe
shell\open\Default=1
shell\Explore\Command=smss.exe
shell\Autoplay\command=smss.exe

Funny UST Scandal.avi.exe(228kb) in all root drives

Registry Entries-HKLM\Software\Microsoft\WindowNT\CurrentVersion\Winlogon=shell(killer.exe)
HKCU\Software\Microsoft\windows\Currentversion\Run=runonce(c:\windows\smss.exe)


HOw to remove this lame virus????

-first download taskiller in *www.rsdsoft.com/task_killer/index.php4 and install it to
your computer because you cant use taskmanager to terminate the virus(the virus automatically close taskmanager).

-run taskiller and left click it on the system tray(the one with a skull icon)

-click processes

-to close the virus, select process and click yes to the question

(process to close)
1.killer.exe
2.lsass.exe
3.smss.exe

note: close only file that have the same icon of Funny UST Scandal.avi.exe


CMD STEPS
1-now, click "start" then "run"
2-type "cmd" without quotes
3-type "cd\" without quotes
4-type "attrib -h -s smss.exe" without quotes
5-type "attrib -h -s autorun.inf" without quotes
6-type "start c:" without quotes(a new window will open)
7-select smss.exe,autorun.inf,Funny UST Scandal.avi.exe and delete it

-if theres any drive or a partition type "d:" in command prompt without quotes
"d" is the drive letter then repeat the CMD STEPS number 4-7 above.......

-now type this on the command prompt "cd windows" without quotes(na naman!)
-type "attrib -h -s smss.exe" without quotes(uli)
-type "start c:\windows" without quotes(hay naku!)
-delete the file smss.exe
-now, goto c:\documents and settings\all users\startmenu\programs\startup
-delete lsass.exe

-click "start" then "run"
-type "regedit" without quotes then delete the registry entries above....

HAPPY TROUBLESHOOTING
 
Status
Not open for further replies.
Top Bottom