Task bar and icons are gone

Nizmo

Member
My uncle put all my programs on the computer. the only cd that i own is my windows 98 cd. Should i install that?
 

Nizmo

Member
Ok i tried to format the comptuer but it wouldnt let me. it said Cannot format this drive. Also i couldnt install windows 98 because it said it cant install from this version of windows. Most of your advice has taught me things about my comptuer but some of it i cant do. The problem is that i have to task bar at all so i cant go into the start menu and click on anything and also there is no icons like my comptuer or anything. So the only way i can get into something is form ctrl alt delete and then i have to click on new task in that menu screen. When i put a cd in that usually comes up with auto run nothing happens so i cant open a cd that easily. Im not sure whats wrong with my computer but ill try anything besides smashing it :). I ran the ad aware thing 6 times and it put the things it found into a folder then when i delete that folder it jst finds them files again the next time i scan my comptuer. Its confusing. But i think that a system restore could help because it worked for me all the other times some thing bad happened. But the only thing is that i cant click on the start menu and go into help and support to get into system restore. So if you knew the command thing (C:\..... thing) then i could type that in and get into it.
 
can you not start in safe mode ??? reboot then keep tapping F8 and choose to start in safe mode then try a restore or repair :)
 

Nizmo

Member
i did that but all i could see was a white screen with system restore as the heading on that blue bit with white writing. im not sure what to do but on many other websites they have said its spyware,virus,settings jumbled up and one other guy said that he fixed that problem from when his power went out for 30 minutes. Would it be easier if i just take the computer to a fixing place? or is this an easy problem to fix? because on google it seems like alot of people have this problem
 
Nizmo said:
Most of your advice has taught me things about my comptuer but some of it i cant do. The problem is that i have to task bar at all so i cant go into the start menu and click on anything ...

Nizmo, you can press Windows button on your keyboard (between CTRL and ALT) to activate start menu.
 

Nizmo

Member
pressing that button doesnt do anything :(. Dont worry i dont think ill be able t fix this problem. i been on google looking for an answer for 5 hours now havnt found any way to fix the problem. Everone else is talking about how they close there explorer in task manager and they get there taskbar back. But i dont have an explorer in my task manager.Is there a way to make it so i can use online games again? Because thats just about the only thing i use this comptuer for. i can open most other things but i cant login to any online things.
 

Nizmo

Member
Some sites said that windows 98 had less bugs on it. I am wanting to install that but it says i cant install it from this version of windows. I tried to format my drive but it wouldnt let me. Is there any formatting programs that could help? Any advice for installing windows 98 would help.
 
Don't know how to help you, Nizmo :confused:


Last chance, try to doubleclick reg file from this RAR. Read info too, if your Windows are not installed at C, change drive letter. Of course, reboot after doubleclickin reg file.
 

Attachments

From the apppearance of Netsky (a virus, rather than just spyware carbage) I'd suggest a pass with Stinger as well
http://vil.nai.com/vil/stinger/

I wonder if there's a restore point you can go back to when it worked better - there'll probably still be a lot of cleanup.

I use Win98SE, but I wouldn't really recommend it (getting ready to upgrade to XP, grudgingly, but I'll hold off until I can jump the install straight to SP2 instead of 1001 piecemeal patches).

Win98SE is falling off the radar for software support, though if you have older versions of the software, that's not a great problem.

It IS resistant to a lot of the worms that go through holes in XP, but has some other vulnerabilities which will not be patched as they are not deemed to be critical, in this last-ditch extended support phase.
 
Nizmo said:
Some sites said that windows 98 had less bugs on it.

ack who told you that ?!

I was a die hard 98/98se user for almost 4 years and then as an experiment i tried xp sure i had loads of probs to start with with misconfigured drivers and the forget to get SP1 installed scenario but...... so far so good when you apply the correct patches for your hardware and install good reliable anti virus /firewall and regular cleans with spyware tools it runs pretty much ROCK SOLID often for weeks on end with the occasional reboot for some software that REQUIRES a reboot its not crashed for a few months last crash was initiated by me by pluging a usb device in and forgetting to use safe removal of hardware function before disconnecting :)
 

Nizmo

Member
LTR12101B system restore wont work the screen comes up but nothing loads in the screen. I am trying this stinger program rite now. I guess im kinda lucky because windows 98 wouldnt install for me so that kinda good luck for me :). But what i want to know is that if i format my computer will that make it so i cant enter windows or anything? Because i realized the windows folder is also in there. Will i lose windows xp when i format the computer?
 

Nizmo

Member
ok i got the stinger program. I have a LOT of programs installed on my computer. But so far stinger has found this virus W32/Netsky.d.eml!exe does anyone know what this is?
 
OK from symantecs database

When W32.Netsky.D@mm is executed, it performs the following actions:

Creates a mutex named "[SkyNet.cz]SystemsMutex." This mutex allows only one instance of the worm to execute.


Copies itself as %Windir%\winlogon.exe.


Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.

Adds the value:

"ICQ Net" = "%Windir%\winlogon.exe -stealth"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.


Deletes the values:


Taskmon
Explorer
Windows Services Host
KasperskyAV

from the registry keys:


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Notes:
Some of these registry key values are typically associated with the worms W32.Mydoom.A@mm and W32.Mydoom.B@mm.
The W32.Mimail.T@mm worm may add the registry key value "KasperskyAV."

Deletes the values:


System.
msgsvr32
DELETE ME
service
Sentry

from the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Deletes the values:


d3dupdate.exe
au.exe
OLE

from the registry key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Deletes the value:

System.

from the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RunServices


Deletes the registry keys:


HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\
InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Explorer\PINF
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WksPatch


Note: The worms W32.Mydoom.A@mm and W32.Mydoom.B@mm add a value to the first key, so that explorer.exe loads their backdoor components.

If it is between 6:00am and 9:00am on a Tuesday, March 2, 2004, the PC speaker will beep in a continuous loop. Each beep will be for a random period of time, at a random frequency.


Scans the following file types on drives C through Z for email addresses:


.dhtm
.cgi
.shtm
.msg
.oft
.sht
.dbx
.tbb
.adb
.doc
.wab
.asp
.uin
.rtf
.vbs
.html
.htm
.pl
.php
.txt
.eml


Note: Due to a bug in the code, the worm will search a file for email addresses if the extension is a sub-string of one of the aforementioned extensions.

For example, the worm will scan the files with the .txt, .tx, and .t extensions.

Uses its own SMTP engine to send itself to the email addresses it found above, sending to each address once. The worm uses the local DNS server (retrieved via an API), if available, to perform an MX lookup for the recipient address. If the local DNS fails, it will perform the lookup from the following list of hard-coded servers:


145.253.2.171
151.189.13.35
193.141.40.42
193.189.244.205
193.193.144.12
193.193.158.10
194.25.2.129
194.25.2.129
194.25.2.130
194.25.2.131
194.25.2.132
194.25.2.133
194.25.2.134
195.185.185.195
195.20.224.234
212.185.252.136
212.185.252.73
212.185.253.70
212.44.160.8
212.7.128.162
212.7.128.165
213.191.74.19
217.5.97.137
62.155.255.16


The email has the following characteristics:

From: <spoofed>

Subject: (One of the following)
Re: Your website
Re: Your product
Re: Your letter
Re: Your archive
Re: Your text
Re: Your bill
Re: Your details
Re: My details
Re: Word file
Re: Excel file
Re: Details
Re: Approved
Re: Your software
Re: Your music
Re: Here
Re: Re: Re: Your document
Re: Hello
Re: Hi
Re: Re: Message
Re: Your picture
Re: Here is the document
Re: Your document
Re: Thanks!
Re: Re: Thanks!
Re: Re: Document
Re: Document

Body: (One of the following)
Your file is attached.
Please read the attached file.
Please have a look at the attached file.
See the attached file for details.
Here is the file.
Your document is attached.


Attachment: (One of the following)
your_website.pif
your_product.pif
your_letter.pif
your_archive.pif
your_text.pif
your_bill.pif
your_details.pif
document_word.pif
document_excel.pif
my_details.pif
all_document.pif
application.pif
mp3music.pif
yours.pif
document_4351.pif
your_file.pif
message_details.pif
your_picture.pif
document_full.pif
message_part2.pif
document.pif
your_document.pif


The worm avoids sending email to addresses containing the following strings:


skynet
messagelabs
abuse
fbi
orton
f-pro
aspersky
cafee
orman
itdefender
f-secur
avp
spam
ymantec
antivi
icrosoft
if stinger allows removal do so immediately

then try fix everything that it breaks and remove the registery entries above by hand if needed :)

this indeed seems to be the root of all your problems with your icons and taskbar as it removes some stuff from the run services as per above mentioned :(

there is a removal tool here

called FxNetsky.exe read the whole page as it details how to :)
 

Nizmo

Member
The virus programs said i have got no viruses now. And i ran the Fxnetsky.exe twice but still no fix.What do you meant by remove the registry? Do you mean remove the ones that the virus breaks down?
 
http://www.pandasoftware.com/download/utilities/ - another clean/remove/repair tool, not sure that netsky itself would be responsible, as the first rule of a clever virus is not to draw too much attention, but it looks like a lot of reg keys get trashed by this one.

If Stinger already removed it, you may need to run FXNETSKY with the line described in the notes to just fix the registry, in case Stinger didn't do a 100% cleanup/repair .... Stinger is usually pretty good on zapping the ones it knows though, and it knows most of the most common infections.
 

Nizmo

Member
I have just found this out. There are 4 processes going on in my task manager. They are NISSERV.exe NISUM.exe SYMPROXYSVC.exe and system idle process. Each of these seem different. When i close NISSUM and SYSMPROXYSVC, NISSERV will get 99% cpu process.I tried to find out about them on google but i couldnt get the downloads to the synmatec internet security program. Do you think this could be the problem with my computer?
 
Program Name: nisserv

Executable Name: NISSERV.EXE

Required: Yes

Comments: Norton Personal Firewall



Program Name: Nisum

Executable Name: NISUM.EXE

Required: Yes

Comments: Norton Personal Firewall



SYMPROXYSVC - Norton Internet Security or NPF
 

Nizmo

Member
I installed 98 and its all better. Now i just need to find out the difference in home and xp before i go buy one. I posted this same sort of msg in the 98 forum but im not sure if the same people reply.
 
Top