Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

SP2, NIS mess...day three

Status
Not open for further replies.

fellowsheep

IS-IT--Management
Aug 24, 2004
6
US
Hi folks, I've encountered quite a mess with a SOHO client that I just had to share. Advice is of course welcomed...

Client had attempted to install SP2 on a Dell Dimension 4300s running XP Pro, and had encountered an error which resulted in uninstall, but she didn't remember the error specifically and didn't think the uninstall was complete. This machine had nearly everything installed; no less than four spyware programs (Spybot, Adware, Counterspy, Pest Patrol, maybe another); Norton IS 2004; Norton System Works 2002; tons of other apps. There was at one time an indication of the ucsearch.ocx Trojan, but I found no evidence of it upon inspection. Then the "fun" began...

Disabled all startup processes & attempted to install SP2 from disk. Seemed near completion when the "Access Denied" failure was encountered. Retried from safe mode & got the same thing. I found the link and the next day reset permissions to default with secedit (from safe mode w/networking), and got SP2 to install (from safe mode w/nw). Note that the permissions reset also removed a couple of other user accounts, but not the main one which has Admin priveledges. I've probably left something out because it took a while to get to this point...but here is where it got ugly...

Upon restart in normal mode w/SP2 installed, Norton autoprotect generates an "Access Denied C:\" error. Some log indicated that the OS had exclusive rights to C:\! I did get the initial Norton caution about Windows Firewall vs. Norton's & dual alerts, but dismissed it leaving both active (have done so without issues on several machines). To make a long story a bit shorter, here's the current situation:

Windows firewall now disabled, all startup processes disabled (same result with selective & all enabled BTW), on boot NIS generates the Access Denied error which hangs NIS so I can't bring it up to disable it's firewall. Browsers are not able to access any IP (even local router:DW6000, and local AP:LinksysWAP54G), but ping works for any local IP, Yahoo, Google, etc. Uninstall NIS hangs...and get this: No Network Connections are displayed (the "window can't obtain a list...make sure Network Connections service is running"...and it is running). Even the LAN adapter cannot be displayed (wanted to check & change properties).

Tried System Restore to prior SP1 date & it failed with a Norton autoprotect access denied. Then disabled Norton services & was able to boot without Norton access denied error, but still couldn't uninstall NIS. From that point I initiated another Restore attempt (since autoprotect isn't running) & had to go home for the day. If it succeeded, I plan to uninstall NIS if possible, then repeat the SP2 install, followed by NIS reinstall. At least that's the plan for day three...wish me luck!

Also can't get the WPC54G card in her Win2k laptop to obtain an IP from the DW6000 if WEP is enabled (still talks to the access point), but that's another post...

Chris
 
The saga continues...just spoke w/client & the restore failed again, so I guess plan is for her to back up application data (she only has iterative now) & we'll do a clean format & reinstall tomorrow.

Unless someone has a winner recommendation?
 
I had a similar problem and eventually discovered that my client had been using p2p programs to download music, which in turn led to his machine getting a really nasty, persistent search tool installed. This search tool was not eliminated by adaware or spybot or hijackthis, so he didn't realize it was a problem...until he loaded SP2! The result was the tcp stack was completely hammered, and none of his software could communicate to the web. If you pinged 127.0.0.1 it would show as active, if you ran ipconfig you would see that the adapter was being given MS internal IP addressing, which of course indicated it wasn't able to communicate with the router.

The only way I figured this out was by using the winsock fixer you can get at below link. Once we did that the search tool (trojan/malware) sprang back to life. It wasn't worth trying to fix at that point so we formatted and reinstalled from scratch. SORRY you're stuck too!


Check this thread 779-955694 for info on the winsock fixer, don't bother with the manual fix (didn't work).
 
I think it (clean install) is the only way to go with the machine in such a state. It wouldn't hurt to do an image backup or similar of the faulty machine first in case you find out later down the track you have lost some important data.

All the best.
 
Thanks folks, I'll have her try the stack rebuid/reset, but I also had her buy a One-touch backup drive today. I'm planning to rebuild the drive from scratch tomorrow.

I found it really weird that everthing looked normal with ipconfig & ping...but network connections (including the LAN adapter) could not be displayed.

...ugh, it gets worse. Client just called & the one-touch back-up software won't install. Hopefully it will recognize the drive anyway & she can copy folders over...

Yuk,
Chris
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top