Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Hundreds of VERY strange Registry keys

Status
Not open for further replies.

fumei

Technical User
Oct 23, 2002
9,349
0
0
CA
Hi folks, I have been trying to find some help on this one.

System:
P4 2.8 , 1 Gb RAM, Windows 2000 SP4

System Symptoms:

I have hundreds (and I mean literally hundreds) of Registry keys, such as this:

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\CommonClient\NByosJ1kzgOrW49GTF72dMTQexV6wa2Q+4Bu/Gkfw9tKQqY3\aHyYeKDO6lhu9C8I7MQ8UfhRE4KDkwL8FP6Q/A==

Key Values

Name:
7GyCONTJqYpek6MiEkMz7fzoVF++U5CUaXRZqPxKq9JqDZu8GlE55Jnm98c=

Value (Binary):
53 2A 0C CD 18 B2 FD 09 S*.I.2ý.
05 88 55 10 23 B2 E0 4A ..U.#2àj
F4 7E 31 7D 70 F8 36 A0 ô~1}pø6
EC 54 C2 18 2F D5 6A AF iTÂ./Õj¯
43 A8 52 C8 C"RÈ

I copied some of the names of the keys into a text editor - the name is 5 pages long.

- any CD writing software will not load, With Task Manager open there is a brief blink of SOMETHING loading (running), then it disappears. No matter how I try to load the executable to ANY CD writing software, they will not. Therefore I can not back up any data to CD.

- even with Administrator rights, the system will not allow any Program Removal through Control Panel

- even with Admin rights, system will not allow any termination of either applications, or processes through Task Manager

- full screen display of any image files lasts about a half second, then main graphic application recaptures focus (Photoshop, PolyView)

- MS Word does not display any cursor

Action Taken:

full virus scan - nothing found
on-line scan - nothing found

I can not find any information about such keys anywhere yet. thought I would toss this one out here.

I wish I could find a way to post a screen dump of RegEdit...it looks very very strange.

Any thoughts and/or suggestions would be welcome. I understand that it is most likely this sucker is going to need a full software (OS and everything) install again. But I have a lot of data I would like to try and save. I pesonally think I have a problem.

Gerry
 
Is it possible to flash the bios by booting from a floppy?
Like a win 98 recovery floppy?

If you're going through Hell...keep going... (Winston Churchill)
RocKeRFelLerZ
 
Gee I may be able to find a Win 95 boot disk....Never used 98.

At work we have bootable McAfee CD's. I tried one, but it would not boot.

Gerry
 
Some simple ideas:

Have you tried taking out the BIOS battery for a while to make it reset to default?

Perhaps you could get Partition Magic boot disks?
IF they booted, you could format MBR...(?)
[ponder]
If all fails - how about taking off the seal of the BIOS, erase it, put an older, non-infected BIOS-Chip on it and update?

If good advice can't help it, how 'bout some blunder...

Gives me the creeps how %$§ing smart some little programming $%§#'s are...
 
Gives YOU the creeps. These little f&^%s are mostly children. Very clever kids, but kids. This is the equivalent to fart jokes and prank phone calls. Except these have real effects on real people and business.

I have been fighting these, these....words escape me for the time being.

They have me tagged.

The last time, I was quite definitely taken over by a zombie. I was on dial-up then. Here is what would happen.

I could dial-up and reach the DNS server. And that was it. I could not resolve any further. Could not use SMTP (so could not reach my POP3 server = no email); could not use HTTP ( so could not use the web); could not use FTP ( so I could not even transfer work files).

I could ping to the DNS server, by using the specific IP, but NOTHING beyond that. Zip, Nada.

YET, watching the monitor of traffic I could see Mb upon Mb of traffic going in and out of my system. A classic case of being hacked to be part of a Denial of Service attack.

I had a network sniffer to see what I could do to identify where things were coming from. Once I started that, these little ( pardon me I do NOT want to allow my frustration and anger to exceed my normal politeness), start to PHONE me. I would get phone calls saying "You'll never find us.Hahahahahah". I turned over tapes of these conversations to the police, as they rapidly turned into "You are going to die for this".

I know, I know. Unbelieveable. Still have copy of the tapes. They sounded like kids. Anyway, the local phone company was not helpful at all, didn't seem to give a crap. They traced the phone number to what are known as "phantom numbers". Never heard of them. They are numbers that phone companies sell, and are only used for OUTGOING calls. A call TO that number will never reach anywhere. It is a outgoing service only. Can you say...what the hell? can use you...nefarious maybe?

The local phone Security did not respond well. Nowever, I did force them to acknowledge that the calls were coming from outside their area. I contacted the national phone company Security folks. They took it very seriously. Tracked it through various jumps, into the States, to the Cayman Islands, to Russia where they lost the trace.

My point being is that with the way things are, it could still be anyone, anywhere. This is the way of the 'Net, and I have been using it since ARPNET. There are a number of clever ( I will not say smart) people out there, for whom this is fun.

It is only going to get worse. Especially as so many of us are wedded to a system with outrageous holes. Why on earth does an operating system constantly asks if anyone is there? A a few comon locations, sure, but Windows is asking, and saying hello to thousands of ports. Plus this lateast critical security warning about JPEG vulnerabilities....this is now utterly, utterly stupid. We have 700 technical support people; they used to be admin types, but now they are simply "patch boys". That is all they do. Constantly, incessantly patch things.

For me, if I can get some sort of my network back, I am finally, after 30 years of using computers, really done. That is it. I am tired of this crap. Time to retire and let you youngin' try and find a way.

Good luck.

Gerry
 
fumei

I also do a lot of digital photography. With the problem your having, and not enough gigs of space to put the data,and OpSys problems, try to go to one of the photo sites like clubphoto, ofoto, shutterfly, etc and upload your files (works best if you have DSL or Cable modem).

I too am experiencing some type of mischief. My system takes forever to start up and shutdown, like 4 minutes to start or shutdown. While it is doing this the hard drive is blinking like crazy so data is going somewhere but the system is going nowhere.

hope the above is some help
 
Do those places let you upload Gb of data??? I will check them out.

I have three machines on my home network. One of them now takes 71 minutes (or more) from the Windows progress bar starting, to the final desktop appearing. Over an hour!!!

Can you say..., oh never mind, this is a public forum.

Gerry
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top