Here is my problem: in 2006 I updated my w2k to sp4. this went smoothly. by early december 2008 (i was very careless i know) i catch a very bad virus (most probably Rootkit typ). First i got a blue screen, then after rebooting tcp/ip was disabled (tcp/ip transport is not installed). through researches on the net i started to clean my system with tools found such as: gmer, RunThis, CatchMe, SDFix. slowly i got my internet back and slowly stabilized the OS. But then I had to find out that my SP4 level was reset to SP3. I logged in to microsoft and run the upgrade to get SP4 back. but this failed. i tried several ways to achieve this (e.g. automatic, manual, online, offline) but to no avail.
Where is the hook? every time the update process reaches the point of closing the work, the process stops at a particular location. Let me try to describe this as good as possible (i must translat it from the german screen):
-1- window name: Service Pack 4 Setup - Error
msg content: when updating the system an error has occurred.
-2- window name: sp4iis
msg content: the event can not be registered (or something similar)
-3- window name: program error
msg content: sp4iis.exe has created an error and will be closed. stat the program new.
My Handicap: i have setup my system in germany but i work in jordan. all my original disks are at home in europe. i am not allowed to just go the simple way of reformatting the whole HD. this would be disastrous as i have all my data and many installed programs on it. so any solution must be in cleaning, search and destroy etc.
found malicious apps when i was cleaning: i have found a few things when i cleaned the system:
1 - in winnt\system32\drivers\ there was a folder "etc" with the following files in it (hosts / imhosts.sam / networks / protocol / services). i'm not sure if this is malicious.
2 - in winnt\system32\ i found (iifgEtqo.dll / oqtEgfii.ini / oqtEgfii.ini2 / rxxkcauw.dll / wuackxxr.ini)
3 - further Spybot reported that registry will be updated and found redirect for search pages.
4 - another report from Spybot was "NT startup - value deleted - load"
Solution: ok, so that is my most imminent problem i have to solve. my top most priority is to get SP4 back. there are various SW and HW i can't use e.g. acronis for mirroring, U3 usb memory etc.
Anyone here having experience getting my w2k back to SP4? Thank you in advance and read you later.
QUICK EDIT: i did make a search on the net for my problem. but unfortunately i could not find any solution to it - not even by microsoft. the youngest post on this issue is as old as 2 years.
Edited by crapelli, 03 May 2009 - 01:41 AM.