Sasser problem - a countdown of zero seconds...
#1
Sasser problem - a countdown of zero seconds...
How do you get into a laptop that has been hit by the Sasser virus which, upon logging on, immediately reboots?
When it first got hit the countdown was 5 minutes. The user (the sister of my boss) ignored each countdown and reboot until the up time was less than 30 seconds(!). By the time my boss got to look at it, it was too late - he didn't have enough time to fix it. Now the countdown time is zero seconds.
One of the support guys at work has looked at the machine and can't even get in via safe mode and/or via the admin account. Booting via a floppy or CD doesn't work either.
Other than wiping the hard drive, is there a way of fixing this machine?
The machine is running XP.
When it first got hit the countdown was 5 minutes. The user (the sister of my boss) ignored each countdown and reboot until the up time was less than 30 seconds(!). By the time my boss got to look at it, it was too late - he didn't have enough time to fix it. Now the countdown time is zero seconds.
One of the support guys at work has looked at the machine and can't even get in via safe mode and/or via the admin account. Booting via a floppy or CD doesn't work either.
Other than wiping the hard drive, is there a way of fixing this machine?
The machine is running XP.
#3
and the reg key to delete is...
HKLM\software\microsoft\windows\currentversion\run
on the right pane, there should be something "uncheck.... %..." sorry i cant remember the exact line but it's something like in the quote.
HKLM\software\microsoft\windows\currentversion\run
on the right pane, there should be something "uncheck.... %..." sorry i cant remember the exact line but it's something like in the quote.
#5
From another PC over the network (assuming you have a network and a second PC!)
That's presuming the shut down countdown starts when you log on, not as the system boots.
That's presuming the shut down countdown starts when you log on, not as the system boots.
Trending Topics
#9
Originally Posted by bioforger
y doesnt bootin from floppy or CD work?
Then u could use recovery console and ASR to restore a backup of your registry, u do have a backup right?
Then u could use recovery console and ASR to restore a backup of your registry, u do have a backup right?
#11
Hang on, you don't need to log onto the machine to remotely edit the registry.
Get the PC to the CTRL-ALT-DELT screen and leave.
Fire up RegEdit on another PC on the LAN.
On the Registry menu, choose "Connect Network Registry"
Find the infected PC or type in it's name.
Navigate to the key suba posted and delete it.
That should do the trick.
Get the PC to the CTRL-ALT-DELT screen and leave.
Fire up RegEdit on another PC on the LAN.
On the Registry menu, choose "Connect Network Registry"
Find the infected PC or type in it's name.
Navigate to the key suba posted and delete it.
That should do the trick.
#12
Scooby Regular
Join Date: Nov 2003
Location: where the wild roses grow
Posts: 5,122
Likes: 0
Received 0 Likes
on
0 Posts
Assuming of course the PC is networked.
If it's not, have you tried starting the PC in Safe Mode Jerome? (repeatedly hit F8 as the POST sequence ends, when the startup menu shows select Safe Mode).
If it's not, have you tried starting the PC in Safe Mode Jerome? (repeatedly hit F8 as the POST sequence ends, when the startup menu shows select Safe Mode).
#14
Scooby Regular
Join Date: Nov 2003
Location: where the wild roses grow
Posts: 5,122
Likes: 0
Received 0 Likes
on
0 Posts
Yep, you're in trouble there. Have a look at Microsoft.com and the antivirus provider sites to see if there's a patch you can apply via a command prompt.
If not you're probably going to have to run a reinstall/repair.
If not you're probably going to have to run a reinstall/repair.
#15
No network. ERD Commander will let you boot from a CD and access the registry to edit out the keys.
If the machine config isn't that valuable, slave the HD up to another PC or do a parallel install of Windows to copy the data off. Then blow it away and rebuild.
If the machine config isn't that valuable, slave the HD up to another PC or do a parallel install of Windows to copy the data off. Then blow it away and rebuild.
#16
Scooby Regular
Join Date: Sep 2002
Location: The biosphere
Posts: 7,824
Likes: 0
Received 0 Likes
on
0 Posts
In safe mode it still reboots.
Thread
Thread Starter
Forum
Replies
Last Post