Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows Server

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-19-2008, 04:10 AM
FUBARinSFO
 
Posts: n/a
SAFEBOOT registry subkeys missing, can't boot into safe mode

Hi:

Windows 2003 Server, can't boot into safe mode. Upon further
inspection, subkeys for SAFEBOOT are missing from HKEY_LOCAL_MACHINE
\SYSTEM\CurrentControlSet\Control\SafeBoot registry. That is, not
even Minimal nor Network keys are present. ContolSet002, ...,
ControlSet004 are either missing SafeBoot key entirely or the subkeys
as above.

1. What is the procedure to restore these keys, short of a reinstall
of the opsys?

2. Any idea how this could have happened? If a virus/trojan, I didn't
seen anything suspicious under run/runonce (cursory inspection).

Thank you in advance for your help.

-- Roy Zider

Used ERD Commander 2005 for boot.

Reply With Quote
  #2 (permalink)  
Old 07-19-2008, 04:49 AM
Ace Fekay [MVP]
 
Posts: n/a
Re: SAFEBOOT registry subkeys missing, can't boot into safe mode

In news:a9afadc2-185d-4073-b19b-40416e0890a8@h1g2000prh.googlegroups.com,
FUBARinSFO <file1303@gmail.com> typed:
> Hi:
>
> Windows 2003 Server, can't boot into safe mode. Upon further
> inspection, subkeys for SAFEBOOT are missing from HKEY_LOCAL_MACHINE
> \SYSTEM\CurrentControlSet\Control\SafeBoot registry. That is, not
> even Minimal nor Network keys are present. ContolSet002, ...,
> ControlSet004 are either missing SafeBoot key entirely or the subkeys
> as above.
>
> 1. What is the procedure to restore these keys, short of a reinstall
> of the opsys?
>
> 2. Any idea how this could have happened? If a virus/trojan, I didn't
> seen anything suspicious under run/runonce (cursory inspection).
>
> Thank you in advance for your help.
>
> -- Roy Zider
>
> Used ERD Commander 2005 for boot.


This does sounds like malware got your machine. Take a look at the link
below to see if it helps. Another option is to boot up from the Windows 2003
CD and run an upgrade. This will keep all current settings and roles. If the
CD is integrated with the same SP level, then just re-run Windows Update. If
not, run the current SP, then run Windows Update.

Restoring Safe Mode with a .REG file
http://blog.didierstevens.com/2007/0...th-a-reg-file/

--
Regards,
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
MVP Microsoft MVP - Directory Services
Microsoft Certified Trainer

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Infinite Diversities in Infinite Combinations


Reply With Quote
  #3 (permalink)  
Old 07-19-2008, 05:04 PM
FUBARinSFO
 
Posts: n/a
Re: SAFEBOOT registry subkeys missing, can't boot into safe mode

Ace:

Yes, indeed it was from an earlier infection. a Win32/Bagle worm
variant
Restore from older backup is not overwriting registry
http://groups.google.com/group/micro...f4712?lnk=raot

I'll do a repair from the install CD, but at some point it's about
time to do a fresh install. Thanks.

-- Roy
Reply With Quote
  #4 (permalink)  
Old 07-19-2008, 05:05 PM
FUBARinSFO
 
Posts: n/a
Re: SAFEBOOT registry subkeys missing, can't boot into safe mode

Ace:

Further, I did have the Didier Stevens link open in IE when I posted
the note. Just haven't done it, since it wasn't definitive.

-- Roy
Reply With Quote
  #5 (permalink)  
Old 07-20-2008, 07:08 AM
Ace Fekay [MVP]
 
Posts: n/a
Re: SAFEBOOT registry subkeys missing, can't boot into safe mode

In news:1d3c5c18-eaa2-4e81-a452-a3c7153d5fda@w8g2000prd.googlegroups.com,
FUBARinSFO <file1303@gmail.com> typed:
> Ace:
>
> Further, I did have the Didier Stevens link open in IE when I posted
> the note. Just haven't done it, since it wasn't definitive.
>
> -- Roy


This would be the better option to running an ugrade. Let's hope for the
best. If this doesn't work, then let's go for running the upgrade. Of
course, the ultimate option is a clean reinstall.

Ace


Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows Server


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:26 PM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109