Results 1 to 10 of 81

Thread: BraveSentry removed? - problems remain

Hybrid View

  1. #1
    Join Date
    Jul 2007
    Posts
    39
    Judy,

    I'll wait to see if anyone has any suggestions. In the meantime, I'll pick up a new hardrive & have it at the ready if needed!!

    Thanks, pk

  2. #2
    Start the Recovery Console, and then replace the Explorer.exe file

    1. Put the Windows XP CD into the CD ROM tray and close the tray. You may get a popup window asking about installing Windows XP. If you do, just close that window.
    2. Then restart your computer
    3. This should cause your computer to boot from the CD instead of the hard drive..(if not your you'll need to enter the BIOS and set the boot order so the CD ROM is first in the list.)
    4. You should get a "Press any key to boot from CD" message! Press a key to do that otherwise it will by pass the CD boot.
    5. After it boots up, you will see it load a bunch of files (be patient it can take a little while) and eventually you will see a menu where you can select the "Recovery Console" by pressing R It is normally the middle item in the list. Press R
    6. You will see a list of possible Windows partitions with numbers next to them. Select your Windows Installation (which is C:\Windows) by typing the number next to it (which should be 1) and press enter.
    7. It will ask you for the Administrator password is next (so make sure you know it). It you never gave it a password it is probably blank. If it is blank, just press enter. If you have set one then type it in and hit enter. It will tell you if you enter the wrong password.
    8. When you enter the correct password you will get a prompt that looks like this: C:\WINDOWS>

    Now from this command prompt window, here is what I want you to do. Enter the below commands (the commands are in bold black, comments in purple text).
    copy c:\windows\system32\dllcache\explorer.exe c:\windows\explorer.exe
    exit <--- this will exit the Recovery Console and boot to Windows

    Restart the computer to Normal Mode.

    W32.Sasser Removal Tool

    To prevent shutdown:
    Start -> Run
    Type cmd
    click "OK"

    At the command prompt:
    Type shutdown -a
    Press the Enter key
    Type exit
    Press the Enter key

    Download and Run the FxSasser.exe file from: http://securityresponse.symantec.com...r/FxSasser.exe.

    The process will take around 15 minutes to complete!

    Download and Run the MS Patch: http://www.microsoft.com/technet/sec.../ms04-011.mspx
    a-squared Team - www.emsisoft.com

    "Only those who fail greatly can ever achieve greatly" - Robert F. Kennedy
    Microsoft Most Valuable Professional - Consumer Security (2007-2008)
    Member - Alliance of Security Analysis Professionals - Since 2006
    Linux Registered User # 363218

  3. #3
    Join Date
    Jul 2007
    Posts
    39
    Quote Originally Posted by ShadowPuterDude View Post
    8. When you enter the correct password you will get a prompt that looks like this: C:\WINDOWS>

    Now from this command prompt window, here is what I want you to do. Enter the below commands (the commands are in bold black, comments in purple text).
    copy c:\windows\system32\dllcache\explorer.exe c:\windows\explorer.exe
    exit <--- this will exit the Recovery Console and boot to Windows
    When I type in the command it says "The system cannot find the file specified". I've tried it twice & doubled checked that I typed it in correctly.

    pk

  4. #4
    Boot to the recovery console. At the Command Prompt:

    Type map
    press enter

    Note the drive letter for your CD drive.

    Type the following commands at the command prompt, pressing enter after each command:
    expand D:\i386\explorer.ex_ C:\windows\
    exit


    Replace D with the drive letter for your CD Drive.
    a-squared Team - www.emsisoft.com

    "Only those who fail greatly can ever achieve greatly" - Robert F. Kennedy
    Microsoft Most Valuable Professional - Consumer Security (2007-2008)
    Member - Alliance of Security Analysis Professionals - Since 2006
    Linux Registered User # 363218

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •