# Computer infected can't even run in Safe Mode!

Q: Computer infected can't even run in Safe Mode!

A: Computer infected can't even run in Safe Mode!

Hi all,

My computer started running verrrrrrrrrrrrry slowly two days ago. It's so slow that nothing is usable. I tried to do a system restore, but all restore points are gone before April 30. Restoring the April 30 restore point fails with an error.

Tried various spyware and rootkit removal software and nothing helps. Desperate...

Here's my HijackThis log:

Thanks! Bob

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:33:35 PM, on 5/10/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files (x86)\Intuit\QuickBooks 2009\QBW32.EXE
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http... Read more

A:Computer infected? Only runs OK in safe mode

When done, DDS will open two (2) logs: DDS.txt
Attach.txt <--- will be minimized in the task tray

Save both reports to your desktop.
Include the contents of both logs in your next post.

The scan will instruct you to post Attach.txt as an attachment.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as... Read more

I am visiting my kids and my ex-in laws got scammed by a FakeAV.  The person they talked to installed windows 8 and now it boots only to safe mode.

Here are the Hijack This logs, DDS logs.

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 12:12:54 PM, on 8/29/2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17028)

Boot mode: Safe mode with network support
Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Ron and Karen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\89NEVL99\HijackThis.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSear... Read more

A:Not exactly sure what computer is infected with but boots only to safe mode

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/546184 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
If you do need help please continue with Step 2 below.

Hi, Suddenly today our PC shut down spontaneously.  I can turn it on and sometimes get to the safe mode screen, but when I hit enter to get safe mode, the computer once again shuts down.  If I immediately try to restart, the computer won't even get to the first page without shutting down.  What to do?
thanks!  Barbara

A:Infected? Computer won't start long enough to get into safe mode

Is Safe Mode with Networking any better? What is your Operating system? Did you notice if you had any malware pop up or you were removing some before this happened.

Can anyone help? This is an old computer- but I have always been able to use it. My daughter decided to "borrow it" and it hasn't been the same. I downloaded "hijackThis" and here is what it showed: Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:05:20 PM, on 11/2/2009Platform: Windows Vista SP1 (WinNT 6.00.1905)MSIE: Internet Explorer v7.00 (7.00.6001.18319)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\system32\taskeng.exeC:\Program Files\Windows Defender\MSASCui.exeC:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exeC:\Program Files\Gamevance\gamevance32.exeC:\Program Files\QuickTime\QTTask.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXEC:\Program Files\Java\jre1.6.0_07\bin\jusched.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\AIM6\aolsoftware.exeC:\Windows\system32\wuauclt.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\IObit\Advanced SystemCare 3\Awc.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\Windows\system32\Sear... Read more

A:Computer Infected? Keeps showing desktop in safe mode

Hi all - this is my first ever post to a forum - normally I google my problems and find the solution, however this one seems pretty gruesome. I have checked around various forums for a day now, with no luck so far. As I am new to this, please excuse any gross violations of etiquette Here is the scenario:

A friend of mine from work approached me about some of his computer problems (frequent pop-ups, etc...), as I installed AVAST! Home for him a few months back. (His PC specs are: - compaq presario desktop, windows XP home SP2, AMD Sempron 3200+, 1ghz, 512m RAM, 80gb HD)
I suspected that he had not kept his free registration current, and that Avast expired and he had accumulated some viruses, spyware, trojans, etc... So trying to help out, I met him at the computer store, recommended that he purchase Zone Alarm Internet security (antivirus, anti-spyware, firewall...) and installed it for him. After installation, a dialog box opened suggesting I restart the computer, which I did(thinking back to my own machine, I do not recall having to restart after installing zone alarm - I think I may have inadvertently messed up here, because I had not even scanned for viruses/spyware, yet once the computer restarted, it would not boot normally) - I had to start in safe mode with networking. I figured that I would scan for viruses in safe mode anyway, and that should get rid of whatever was causing the problem. Found 39 infected files - Zone Alarm cleaned all but one of them - it reported... Read more

A:Severely infected computer - will now only boot into safe mode

My computer started displaying the System Tool pop up and the dreadful blue screen that said there was an error within the computer and the program was closing to save it (paraphrased of course-the screen came and went so fast)it then said if recent hardware had be installed try uninstalling it then it restarted. It went from that to now only being able to boot in safe mode. Now the wireless network is disabled...it says connection status unknown- the dependency service or group failed to start.
DDS (Ver_10-12-12.02) - NTFSx86 MINIMAL
Run by msladydebbie at 23:09:48.71 on Wed 03/02/2011
Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_21
Microsoft? Windows Vista? Home Basic 6.0.6002.2.1252.1.1033.18.2813.2347 [GMT -6:00]

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe

A:Infected With System Tool Computer Only Boots In Safe Mode

***before wasting your time reading this, I'm running Vista and don't know if it will work on XP or earlier systems***

Hi guys, I am by no means a tech expert. So do the following at your own risk.

In step 2 of the self-removal process I need to reboot my computer in safe mode with networking. I do that and soon after my computer logs me off and restarts. What gives?

A:Infected with antivirus security pro - safe mode shuts down computer

I'll report this topic to appropriate helpers.
1. Please let us know what Windows version you have and if it's 32- or 64-bit.
2. Is the computer bootable in any mode?
Hold on there....

Ok my moms computer has a virus that has messed with the safe mode registry item and can't boot into safe mode. And before I new about the registry item I had set the computer to automatically boot in safe mode,like an idiot, assuming it would force it in but now it is stuck in a boot loop. When it tries to go into safe mode, it goes through the list of files loading then it stops listing files and reboots. So how do I get it to stop the reboot so I can get into safe mode so I can get rid of the little butt munch. PLS PLS PLS PLS HELP!!!!!

A:Computer infected with virus and stuck in safe mode boot loop

You could try and use a System Restore Point via Recovery Console -> How to Perform a System Restore in Windows XP through the Recovery Console | eHow.com

You could try a Repair Install which recreates the Basic Windows Registry.

(both the above require a Windows XP cd)

You could try 'fixing' the bad Safe Mode Registry keys -> Restoring Safe Mode with a .REG file ? Didier Stevens

This morning we had a power outage and when I turned my computer back on, it would not boot. I tried several times to hard boot, with no luck. Then I tried safe mode. Ran an antivirus scan and it showed malware and several infections which it cleaned. The computer still would not boot normally. I then ran chkdsk, still would not boot normally. I have ran malware bytes, registry repair and the registry defrag program as well as done a disk clean up. It still will not boot in normal mode.
Since my last problems that you helped me with, I have upgraded to a broadband internet connection and have a home network. The 2 other computers on the network are fine.
A week ago, I had purchased Avast internet security and had problems immediately. It would not allow me to connect to the internet. That was uninstalled and I went back to the free Avast antivirus, Zone alarm and Spyware blaster. I was very unhappy with Avast customer service and support iYogi and decided I did not want Avast on my computer at all. I have since downloaded PC tools free antivirus. Once I have my computer operational again, I am open to suggestions.
Fortunately, I did not change anything on the other 2 computers. Just mine.
Running Windows XP 3 .
Thank you.

A:[SOLVED] computer will not boot except in safe mode or safe mode with networking.

what are you running
video card
cpu
m/board
ram
power supply
brand
model
wattage

check the listings in the bios for voltages and temperatures and post them

the outage may have damaged the psu

19 more replies

I am running using Dell Inspiron with windows vista. A couple days ago, I got on the computer and then it froze, at fist the program I was using froze, and then I got a circle next to the arrow, but could still move the arrow, then the arrow stops moving. CTL ALT DEL does not work, so i must do a hard reboot, try to boot in safe mode and all the files come up but then it goes no where and the computer either restarts or I reboot it.

I have run all types of tests and nothing comes up. Today I got the blue screen of death twice, but after reboot, it goes away. I do not have a Boot Disk and have tried all the tests in the F8 command. Currently I am running an expanded memory test, but figured I would get this out there before I go insane.

Any ideas would be MUCH appreciated.

Hello, I'm hoping someone would be able to help me resolve this so that I can avoid having to reinstall Windows. Here's the situation: my laptop suddenly cannot boot up anymore; it usually hangs when the "Please wait..." dialog shows up with the text "Windows is starting up...", but sometimes it goes as far as the login prompt, then hangs after I enter my credentials and press Enter. When it hangs I cannot even move my mouse cursor. I can only think of two things I did out of the ordinary that created this mess:
I installed the driver for the Turtle Beach AudioAdvantage Micro USB stick audio card before my PC started hanging. However, after I installed the driver I was forced to reboot, and my computer rebooted just fine.
I closed my laptop's lid to put it in sleep mode while MyDefrag (formerly JkDefrag) was running. I have done this in the past without any issues, but this time when I exited sleep mode my computer was hanging, so I forced a reboot. This trouble started after I rebooted.

I am able to boot up in Safe Mode, but not Safe Mode with Networking, which leads me to think that maybe some network related drivers got corrupted. Some more info on my setup:
I have Windows XP Pro SP3 installed (v5.1.2600)
I have Avira AntiVir and Comodo Firewall installed
I am not using Hibernation
Audio: SigmaTel STAC9751
Graphics: Intel 945 GMS
Chipset: Mobile Intel 945 GMS Express
Netcard: Realtek RTL8101L
Wifi: Intel PRO/wireless 3945

Hello,
I have this problem with my laptop - sometimes I cannot login - after choosing the user the screen freezes or after logging in it works only for a few minutes in regular mode (I can do things over those minutes like open firefox, but I cannot open folders, sometimes I can open the task manager or even some programs) but then it freezes and I have to shutdown the computer manually by pushing the power button. When I tried pushing crtl+alt+del I got a message "The logon process was unable to display security and logon options when ctrl+alt+delete was pressed. If the operatin system does not respond, press esc or restart the computer by using the power switch". I don't know if this helps, but I try to add as much as I can. Sorry it it's not relevant - my knowledge about computers and IT is minimal.
The computer runs fine in safe mode.
So I tried system restore to a week before when the computer was still fine and it didn't work. So I reinstalled a graphics driver (Intel HD Graphics Driver) as I found on the internet that similar problems got fixed by reinstalled videocard drivers. And it worked, everything started to run smoothly again in the regular mode. As normally I allowed windows updates and after restarting my computer, the problems came back.
I assumed that the problem was the updates so I uninstalled most of them (KB2930275; KB2923961; KB2925418; KB2929755; KB2929733 and KB2918077) but the problem was still there and I was unable to unin... Read more

A:Solved: Computer freezes in regular mode but works in safe mode

7 more replies

I am working on my sister's PC here. Last week she saw a popup that she says looked like a MS update. She clicked on it and has been having problems ever since. The software "FOUND" lots of malware and redirected her to a site to buy their software

The PC is a Dell XPS 400 running XP Media Edition SP 3. When you try to boot the machine in normal mode sometimes it just hangs once it reaches the desktop and other times I get a blue screen that says IRQL_NOT_LESS_OR_EQUAL STOP 0x0000000A (0xe1023C58, 0x00000002, 0x00000000, 0x805E1CA5). I booted it into safe mode and ran AVG (last updated on 12/23/08) AVG found the following which was moved to virus vault. C:\Documents & Settings\Steve\Local Settings\Temporary Internet Files\Content.IE5\RT27SPSR\freescan[2].htm - Virus ounf Fake Aert Object moved to virus vault.

I can't open anything in normal mode. I booted the machine in safe mode with networking I get a webpage not found message when I try to go to Microsoft's update site. I can get to Microsoft.com. using my PC I downloaded the exe file for Malwarebytes' Anti-Malware copied it onto a thumbdrive then over to her PC. It looked like it installed but when I run it all I get is an hourglass for about 2 minutes then the cusor returns. The program doesn't appear to start. Any advie? Thanks in advance.

A:Computer unresponsive in normal mode Having problem scanning in safe mode

Unfortunately i cannot find any command line search results for MBAM.
I can also not find any portable version of MBAM that isn't warez.

Is there nothing that you can do in normal mode?
Keep trying, and if you can get into normal mode and run a quick scan then please give us logs so we can analyze them.

Post back then

8 more replies

Hi guys. I have a Sony vaio model number: vpcee23fx. Ever since last week my computer freezes after start up. Like I turn it on, it gets past all the boot up animations and what not and everything works perfect. Then like 5 minutes later it completely freezes I can't move my mouse or push any keys. Nothing works and I have to manually shut it down by holding the power button. It works perfect in safe mode. It never freezes and I'm free to use it how ever long I want. But not in normal mode, nope. Just freezes. Please help I need my computer for school work :(.. Ps. I I'm a nooby when it comes to computers

A:Computer freezes few minutes after start up in normal mode but not in safe mode HELP

Hello EyyJayy & welcome to TSF

Perform a Clean Boot & see if the problem persists.

Post back.

Lately I have been having problems with my computer.
It turns itself off (it doesn't say "Windows is shutting down..", it just dies.) when I am using it. It turns off after a few hours, sometimes after a few minutes. Then I would have to wait a few minutes until I can turn it on. Because it would not turn on no matter how much you pressed the power button, so the only thing to do was to leave it for a while, and then it world turn on.

But now when you turn on the computer, it turns off seconds after you log in, and then the blue screen of death appears. The next time I tried to turn it on, I got the option to boot in safe mode, and it doesn't turn off. I left it on for a whole day and it didn't turn off.

My computer is a Dell Dimension 5150, running Windows XP Sp2 (I think). I will post more details soon, because the option for running in safe mode does not come up when I turn the computer on. I don't know how to boot up in safe mode because I am a computernoob .
I am typing this on my other computer if you're wondering.
Thanks.

A:Computer turns itself off on normal mode, but doesn't turn itself off on safe mode.

reboot your computer ,as it reboots tap the (f8)key choose last know good configuration

2 more replies

Hi i really need some help. I got a virus notification from mcaffee saying i have trojandownloader:win32/renos.dz and i selected remove and thought it would be fine. But the next day the computer kept restarting and ie and mozilla would not open. They only opened in safe mode with netoworking so i tried to download virus protection but when i tried to install it the computer would restart so i renamed the programs which it worked for so i could install it. I installed malware and it got rid of some files but it has not solved the issue. Also when in safe mode and using the internet the page always redirects to other pages like smartbizsearch and the internet just does not function properly. I downloaded HiJackThis from safe mode and renamed it so i could use it. I downloaded dds as instructed and here my log for it:DDS (Ver_09-05-14.01) - NTFSx86 NETWORK Run by Himesh at 16:00:46.10 on 03/06/2009Internet Explorer: 7.0.6001.18000Microsoft? Windows Vista? Home Basic 6.0.6001.1.1252.44.1033.18.3000.2377 [GMT 1:00]SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svchost.exe -k rpcssC:\Windows\System32\svchost.exe -k secsvcsC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC: ... Read more

A:Cannot open IE or Mozilla in normal mode has to be in Safe Mode and computer keeps restarting

The logs from before were done in safe mode these are the ones from normal mode.DDS log:DDS (Ver_09-05-14.01) - NTFSx86 Run by Himesh at 16:27:33.45 on 04/06/2009Internet Explorer: 7.0.6001.18000Microsoft? Windows Vista? Home Basic 6.0.6001.1.1252.44.1033.18.3000.1826 [GMT 1:00]SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svchost.exe -k rpcssC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\System32\svchost.exe -k NetworkServiceC:\Windows\System32\svchost.exe -k secsvcsC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\system32\SLsvc.exeC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Windows\system32\agrsmsvc.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Progra... Read more

3 more replies

Hi All,

Been having this problem since yesterday. Whenever I start up windows, it freezes after a couple of minutes. Tried going into safe mode to run virus scan (Avira and Malwarebytes) but both freeze halfway through scanning and I have to do a hard reset. No idea at all what is wrong with it.

Also find that when I try to open Adobe PDF Reader, it shows this message when I am in normal mode. 'The windows installer service could not be accessed. This can occur if you are running in safe mode, or if the windows installer is not correctly installed.' Right after that, it freezes. Not sure if that's relevant.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:22:47 AM, on 2/4/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe

A:Computer freezes in normal mode after a few minutes and then in safe mode when running virus scans

3 more replies

Sir I am using windows xp service pack3 for last 4 years, It was working fine. till past few days.. when sudden power failure caused it giving following error "windows cannot find local profile..." I created new profile and copied the files from old profile to this.
Though system was working fine. one of my software MPLAB IDE was not working  it used to give unspecified error and stop. So I used registry cleaner in safe mode and MPLAB IDE was started working properly. But window become slow at the start . It takes almost 5-10 minutes to get original screen. Also When I start explorer it holds up for a while (20-25 sec ).In safe mode everything works well. What may be the problem?

A:Computer is very slow in normal mode but fast in safe mode

The registry cleaner probably removed things that some startup programs needed, so now they get stuck and slow. Considering the problem and that you had to create a new user profile, I'd probably just reinstall windows fresh. (But maybe some other people have ideas for fixing it instead)

7 more replies

A few days ago, my laptop started acting strangely, like when I opened skype, the program initially would not allow calls and would freeze then eventually would freeze with any use whatsoever, followed by any others that were open, until the only option was to shut down the computer. I have suspected that skype is the culprit, but even when not using it, the same process would occur, except starting with a different program. Even before the computer froze up, I was unable to use Task Manager or System Restore. For task manager, an error box came up that said something like "security tools unable to initialize," but I can't recall the exact words and couldn't do a screengrab.

So I booted up again in Safe Mode with Networking and everything worked fine, though it isn't terribly convenient to have to use it. I ran GMER and MBAM, and the scans came back clean. ComboFix was able to eliminate some problem files when I used it, though, but when I try to boot up into Normal Mode the problem still persists, though at this point I'm reasonably sure that it isn't a virus. I've also gone through Event Logs, and I've seen some reports of memory slowing down, as well as my System Information for Windows saying that BIOS is reporting the wrong values for the memory. Also ran a scan of the system, which reported that there were corrupted files that it could not fix. I have the CBS log, but I don't have the knowledge or experience that I can make heads or tails of it, though I a... Read more

Hi,My Computer which has Win Xp Sp3 is behaving like it is in safe mode , eventhough it is in normal mode .I noticed this because ,1. Avira Antivir Guard and Update cannot be launched bcz Scheduler is not running.2 . I tried to start scheduler ( under services.msc ) , but can't start it bcz of error 1084 ( safe mode situation ) .3 . I can't use Windows Update , bcz of error Error number: 0x8007043C ( same safe mode condition )4 . I ensured that BITS was set to automatic , but it can't run bcz of 1084 error.I have scanned with Malwarebytes, Spybot S&D , SuperAnti Spyware ( in real safe mode) - No DetectionHere is the dds log ,DDS (Ver_09-09-24.01) - NTFSx86 NETWORK Run by Administrator at 16:45:23.03 on Mon 09/28/2009Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_12Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.112 [GMT 5.5:30]AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}FW: ZoneAlarm Security Suite Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\system32\svchost.exe -k netsvcsC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Avira\AntiVir Desktop�... Read more

A:Safe Mode Error, WinXpSp3 behaves like it is in safe mode even in normal mode

2 more replies

I can only open a computer in the safe mode. I have tried changing the mode manually and it wont work. It was reset to factory standards and now won't go back. Please help. I am using someone else's computer to get answers. Thank you.

A:How to open the computer in normal mode and not safe mode

Hold the "Windows" key and the "R" key. Type msconfig in the window that opens:

Go to the "boot" tab and uncheck "safe boot":

Click "Apply" and "OK" and restart the PC. It should then boot in normal mode.

1 more replies

dell inspiron 2200. What tells my computer that it is in safe mode as opposed to normal mode. When I boot up, I get the options screen and I choose normal mode. The computer boots up normally and loads all the drivers. But when I get to the desktop screen it shows as being in safe mode. What is the registry is tellin g the computer it is in safe mode. I was playing around with the registry and I think I may have inadvertently changed a setting som ewhere to make the computer always boot into safe mode, and I want to undo that change. But I dont know where in the registry to look

A:computer in normal mode thinks it is in safe mode

I was playing around with the registryDon't.But when I get to the desktop screen it shows as being in safe modeDoes it say "Safe Mode" in all 4 corners?If not, what does make you think, you're in safe mode?Did you try system restore?

2 more replies

Hi,

Last week my home computer got a virus - PRO ANTI VIRUS 2009. I panicked and shut down my computer. When I got to the office, I searched on how to remove it and was advise to download MALWAREBYTES and run it on safe mode. I did that and run the program on my home computer three times. The last run showed 0 infection. Thinking that I now have a virus free computer, I tried to run it on Normal Mode. But my home computer won't open on Normal Mode!!! I tried pressing F8 and running everything from Safe Mode with Networking, Normal Mode, even system restore, etc.

Oh I also tried to run the system restore disk and just start from scratch, but my computer says it cannot be run on Safe Mode.

Please help as I think it will be expensive to bring to a technician...unless I really have no choice!

A:Computer does not start in Normal Mode, Only in Safe Mode

Hi,

Disable any script blocker, and then double click dds.scr to run the tool.When done, DDS will open two (2) logs: DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.

1 more replies

A friend of mine brought me her computer to see if I could fix. When it goes into the normal mode, I cannot get on the internet, however when I go to safe mode with networking I can.I have run a chkdsk /f to fix any problems with the hard drive-none were found. I tried going into safe mode and clicking on the last know good config-nothing changed. I'm downloading vista sp1.Also running a malwarebyte.here is the hijackthis logfile of HijackThis v1.99.1Scan saved at 12:19:34 PM, on 7/12/2010Platform: Unknown Windows (WinNT 6.00.1904)MSIE: Internet Explorer v7.00 (7.00.6000.17037)Running processes:C:\Windows\Explorer.EXEC:\Windows\SMINST\CD Creator.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1JVSK78Q\Windows6.0-KB936330-X86-wave0[1].exeC:\d79964e80b89565a84a521d605b3bbbd\spinstall.exeC:\Program Files\Malwarebytes' Anti-Malware\mbam.exeC:\Windows\system32\FirewallControlPanel.exeC:\Program Files\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/... Read more

A:computer works in safe mode, not in normal mode

2 more replies

Hello,

I seem to be having quite the problem on a computer of mine. After recently installing the directx sdk I am unable to logon through normal or safe mode. When I try to boot up normally, I log in but then the monitors go black but everything else seems to run. Pressing ctrl alt delete works and brings up the screen again but if I try to select task manager for example the screen goes black again. When I boot up through safe mode the computer restarts seconds after loading the windows logon screen. Any ideas on how to get into the computer. I'm pretty sure that uninstalling directx can solve my issues but I just can't get in.

Thanks

A:Computer can't boot through safe mode or normal mode

Hello rtsrangel and welcome to Seven Forums.

If you created a System Repair Disc you can use it to boot your computer. Then you can access various System Recovery Options such as system restore. You could then restore your computer to an earlier date/time prior to when you installed the directx sdk.

System Repair Disc - Create

Or perhaps your computer manufacturer created a hidden recovery partition. You can usually access this partition by turning on your computer and immediately clicking the F8 key (top of keyboard.) Keep clicking until you see the Advanced Boot Options screen. From here you should be able to select Repair Your Computer.

System Recovery Options

Please post back if any of this helps or not.

2 more replies

Sorry if this has been asked before or if this is the wrong forum but ever since I tried to install the Catalyst 16.2 drivers for my AMD HD 6670 (the last set of drivers available for this card as it's now considered 'legacy') my computer has refused to do anything in normal mode and I have been using it in Safe Mode for the past few days.

On the day that it started, I went to sleep and woke up to find that the driver installation had failed and found my computer was running very slowly so I decided to restart it. When I restarted the computer wouldn't do anything at startup and would say 'not responding' if I tried to click anything. Although I sometimes managed to open up Windows Explorer, when I press download the bar you get when searching for files etc. to do with loading reaches the end and just doesn't do anything (staying in the libraries page).

I've followed a few instructions and completely uninstalled the drivers in safe mode, I've run MalwareBytes, I've run ESET's online virus scanner, and I've tried to run Avast's boot mode scan (it didn't work, it just booted into my normal mode on my computer which also, didn't work).

My computer is absolutely fine in Safe Mode and runs faster than I've seen it run in a while.

Thanks for the help.

A:Computer Hangs in Normal Mode but not Safe Mode

Catalyst should have created a Windows Restore Point. So, if you can get it to boot into safe mode, you should use system restore to rectify the failed Catalyst install.

Windows should have a workable driver for your 6670 in its driver database. You can also go to website of the maker of the card for the latest driver.

To make your PC work better out of Safe mode.

If you reinstall Catalyst to get your driver. I have found you can disable the AMD External Events in Services.
You can use Blackviper.com to streamline you services.

0 more replies

I have Wxp Pro on a Dell pc. I get no pop-ups, but programs are slow to open and slow to run. I can't start the pc in safe mode by using F2, F8, F12, etc. When those keys are used, the pc ignores it and starts normally.
When a browser window is open, I can open a site, can scroll thru the site, but can't click on any links or buttons. It acts as if it is just a graphic.
One strange thing, if I minimize the browser window, then maximize it again, I can then surf inside the site.

I have run Ccleaner and Ada-ware. I then ran Rkill, then SuperAnti-spyware and Malwarebytes. Running a full scan on both. SuperAnti found 53 items, quarantined all, but no help. Malware did not find any issues.
I've tried a system restore, but keep getting "can't restore system.......".

Any fast help is appreciated, this is for a school secretary's pc.
Phil

A:Am I infected? Can't start Wxp in safe mode

9 more replies

Hi, I had McAfee running and it found a trojan, so i removed it right? For some odd reason my PC restarted(blue screen of death, something about memory) Every time i try to boot normally it gives me the blue screen. so now im in safe mode typing this. I've done multiple full scans on Mcafee and it still says one or more errors could not be fixed because of an error. anyways it been like this all day. I just downloaded avast version 4.8 and currently scanning my system. Any suggestions of help? I'd rather not delete the entire contents of my hard drive and reinstall vista.

Edit 1-avast! Virus Cleaner Tool - version 1.0.211 Ansi

Edit 2- Currently scanning with AVG 8.5 Free Trial Safe Mode

Edit-3 It seems that AVG has cleaned my computer right, i can now boot up normally and my mcafee says im secure.tt

Edit-4 Mcafee is on overload again, my computer got blue screen again. and i am currently scanning with mcafee.

Edit-5 Mcafee has been uninstalled by me and now running avg once more

A:Help, infected laptop, currently in safe mode.

10 more replies

Browser keeps crashing and PC still very slow. I couldn't do anything unless I was in safe mode. Initially, the icons on desktop were almost completely gone. System is 7 Premium, 3 GB RAM, AMD processor. Thanks for getting me started on getting out of this nightmare.

A:Slow Infected PC; ran JRT and ADW from safe mode

Please reboot your computer and update Malwarebytes. This time do a FULL scan and post the new log here

DDS.com

DDS.pifDisable any script blocking protection
Double click the dds icon to run the tool.
When done, DDS will open two (2) logs: DDS.txt
Attach.txt <--- will be minimized in the task tray

Save both reports to your desktop.
Include the contents of both logs in your next post.

The scan will instruct you to post Attach.txt as an attachment.

9 more replies

I would be very grateful for some help sorting out a friend's PC please.

I've read the First Steps page but cannot carry out all of the suggested scans.

When I boot the PC normally, it works very slowly loading XP Home, then suddenly reboots itself before getting to the login screen. I discovered that it will run in Safe Mode with Networking and I'm using it now to create this thread!

I've run dds.scr and the scan result is pasted below. (Attach.txt is included here in a zipped file). When I try to run GMER nothing happens. The egg timer appears for a few seconds but nothing more. I have downloaded SPTDinst-v162-x86.exe. Executing this file results in a popup stating "No SPTD version was detected". The Uninstall button was greyed-out but the Install button looked inviting, so I clicked it and was prompted to re-start Windows. I restarted XP in Safe Mode and it appeared to load SPTD.sys.

Before looking at this forum I was going to attempt a Windows re-install and backed up My Documents onto a USB memory stick, which I then scanned with Avira on a another laptop. This revealed 16 music files, which had been downloaded with Limewire (I presume), all containing the same virus - EXP/ASF.GetCodec.Gen. I've uninstalled LimeWire now.

I have tried to install Avira AntiVir Personal (in Safe Mode) but, after extracting a load of files to a Temp folder, it gets part way through 'Preparing Installation...' then crashes(?).

I don't know what to try n... Read more

A:Infected PC only works in Safe mode - Help please

Please close this thread - I have wiped the system and re-installed XP. It seemed like the smartest thing to do...

1 more replies

Hi, last fri I received an email via my yahoo account from UPS ( which I now now is not). I think this is a nasty virus has worms too.Avira scanned the file before I unzipped it, I did not get any warning, even though I had updated avira files before, then it went spirling downhill!!I had so many windows opening up, I immediately disconnected from the net then proceded to virus scan with Avira. At the end of the scan, it could not help as it was infected. I could not open the report, even though there were warnings.I tried Spybot scan which found a majority of problems which I allowed the fix. I did not think it wise to go on the net as I kept getting Internet Explorer pages opening up.All during this time I was getting Norton virus updates and warnings - I dont have nortons so ignored them and did not open any of the files. Just closed at the X them and made sure i was disconnected from net.After spybot cleaned up, I used ATF to clean my temp files and then turned off and re-started.Since then I can not log on to windows, even in safe mode and adminstrator. I tried and logging on a number of times in a variety of ways but it keeps logging me out. I am not getting past the log on page.I cannot seem to get into windows and think I must have messed up somewhere. I have my external drive plugged in and was about to back up my monthly documents but decided to reply to my emails before! Hence now cannot access anything. I have spent the weekend reading forums and page... Read more

A:infected with UPS virus. Cannot log on even in safe mode

81 more replies

I have an infection in my DropBox.
I am hoping i disconnected before it got to my local box, but cannot tell because, I logged off/shutdown the system.
Windows 7, booting up, trying to go into Safe Mode, with networking.
As soon as it comes up, I try to log in (Still disconnected from the network, and it reboots the system.
Is this something new, or maybe unrelated?

A:Lucky Infected and No Safe Mode now?

Welcome to BC...

This is the second time this week that someone has posted not being able to boot into safe mode. Please
start a new topic in the Malware Removal forum and let the pros see if it is a new malware or just a coincidence.

Please follow the instructions in the Malware Removal and Log Section Preparation Guide starting at Step 6.
If you cannot complete a step, then skip it and continue with the next.
When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.

DO NOT bump your new topic. Wait for a response from one of the Team Members.

1 more replies

Microsoft did a scan in safe mode, but my computer is still running slow. i cant figure it out. i have one care as my anti virus, and malware bytes. i've ran both and nothing is showing up, any suggs would be greatly appreated.

thanks,
Lindaga35

A:am i still infected? scanned in safe mode already

Please reboot your computer and update Malwarebytes. This time do a FULL scan and post the new log here

5 more replies

Hi guys. I just joined this site and this is my first post. My desktop has been infected with Malware/Viruses and won't boot in any mode (safe, safe + networking, last good setting, or normal mode). The closest thing I get is when i go to safe mode and i get a total black screen with no start button or taskbar and on each of the four corners says "safe mode". However, I cannot do anything else on the screen. (Using laptop right now due to desktop being down)

After some research on the web I found that I could try the Avira Rescue CD and would hopefully remove the malware/virus. It's been almost a week but if memory suits me right, the virus was called Cleanup Antivirus. I also was experiencing google redirects. I have already finished most of the steps on the following Avira rescue cd instructions website:

I am currently stuck on step 7 part 2&3. The reason for this is because in the command line, I type exactly what is instructed but the only thing it does is in the next line says:

"Devices" (text is in a neon greenish-blue font) (This is when i type in "ls /mnt")
When i type in " /mnt " it then says "/bin/ash: /mnt: Permission denied"

Not sure what to do because I have already restarted my computer and tried all modes including safe and normal but am still unable to get my normal computer settings.

I would get my log files with Hijack ... Read more

More replies

I'm not able to use internet in regular mode of windows xp. If i restart in safe mode with network support I can access the internet.I have checked everything concerning driver issues etc. The ip is correctly assigned. I have done several scans wit MBAM, I've used registry cleaners, etc. It all started a couple weeks ago when the pc started working very slow. I did a disk cleanup, defragmented the harddisk, did registry cleans, scanned for viruses etc. It was a bit better but not too much. After a few days the internet stopped working on my pc.Is there any solution to fix this problem?Hereby the DDS.txt log:DDS (Ver_10-03-17.01) - NTFSx86 Run by Zjefne at 13:56:09,23 on vr 24/09/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.447.221 [GMT 2:00]AV: Panda Antivirus Pro 2010 *On-access scanning enabled* (Updated) {EEE2D94A-D4C1-421A-AB2C-2CE8FE51747A}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\system32\svchost.exe -k netsvcsC:\Program Files\Panda Security\Panda Antivirus Pro 2010\TPSrv.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\PROGRAM FILES\PANDA SECURITY\PANDA ANTIVIRUS PRO 2010\WebProxy.exesvchost.exesvchost.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\A... Read more

A:Infected? No internet, just in safe mode

3 more replies

I can't start up my computer in any mode ,not even safe mode. Is there anything I can do besides reinstall windows? I checked in BIOS and it said primary and secondary ide slave not detected how do I fix this problem?

A:I can't start up my computer in any mode, not even safe mode.

Did you check the cable connections inside your computer?
Shimsar

2 more replies

XP pro version 2002 and is a 32 bit system.  There is no mfg. name to the computer it is a home built  computer from parts of other computers and items from Tiger Direct, and was built for me 5 yrs. ago by a friend who said he knew very well the ins and outs of building a computer for me....it worked for about 8 months  then issues started  ....the smoke cleared and it has been proved not to be true, I have long ago stopped conversing with and going to him for computer help. he can never cure this boot up problem it has.
I have a few docs. and family images that were yet to be saved / backed up, so a complete reinstall is a possibility.  see **** below

The problem:  The computer will not boot normally, I have had this issue since Nov. 2013 . I have been  reading the web for solutions since Nov. 2013  and trying this and that  and have made no head way.  Tomorrow I will attempt to use  GETxPUD on a DVD and boot with that, and see how far I get.  I am using my son's computer right now, to type this.

**** Trouble began before I could use my external drive and make a back up.  So there is no back up to resort to.   when it does make boot progress it some times will get to the screen where the words XP and the colored four window paned window is,with the bar graph below,  and that stays on the screen for approx.  30 secs give or take and then the screen goes black.  The red HD ... Read more

A:Help... my computer will not boot into safe mode or any mode...

A system that does not boot at all...or complete booting into the O/S...well, my first suspects would be hardware items.  Guilty until proven innocent via testing or substitution of parts into another known good working system...that's the approach I would take.

If it were me...I'd take it to a local computer shop and pay the  to have someone check it out and tell me what might the problems be (never assume there is only one problem).

In today's world...it's hard to not know someone who is capable of doing the same thing for free.  The problem with that is...most users with system problems have no idea how mistaken their estimates of a person's capabilities might be...if the knowledgebase was there, there would be no need to consult someone else:).

I'd be comfortable with the opinion of someone who actually has credentials that attest to her/his ability to properly diagnose and honestly depict the actual problems with a system.

That said...any onscreeen error messages that may have provided clues that something was amiss...before Nov 2013?

Louis

Looking back at previous topics by you...it seems that you have been having issues with this system for about 8 months, including initiating a malware topic that was not responded to.  Same system?

5 more replies

Hi everybody.

My computer has been infected with a virus for the past few months and I've been using Safe Mode most of the time. It all started when last night, I installed Spyware Doctor on my computer. It told me to restart my computer so I did so. (Note: I installed Spyware Doctor using Safe Mode with networking.)
When it restarted, I went to Safe Mode. All the time, I log in as Owner and not Administrator. When I clicked on Owner, it says "Loading Your Personal Settings..." Then it goes to the usual Safe Mode black screen and this time it said "Logging Off... Saving Your Settings..." and goes back to the log in screen.
The same thing happened when I logged into Administrator.
Next thing I did, I tried going to Normal Mode. But, my desktop picture is the only thing that shows. A couple of minutes later, it goes back to the Welcome screen.
Further information, I tried to use the last known good configuration, but it still wouldn't work.

I really need help. Thanks for your cooperation!

You can try booting from your XP CD and performing a Repair. Aside from that, you will likely need to reinstall XP.

1 more replies

I've been in France the last 9 months studying and when I came back, my parents told me to look at their computer since it has been acting weird and they could only use it in safe mode. They had been using it without any virus protection it seems. So I dowloaded Super antiSpyware, MalwareBytes and Avast, and scanned the computer with each of them. Superanti spyware found about 1700 infections, malware bytes found 260 more, including koobface.worm, and avast found 4 viruses. I managed to be able to start the computer in normal mode but it freezes many times, so it is very ineffective to use it like that. I don't know what else is wrong with it as I've run out of knowledge of how to fix the problems. I managed to run DDS in normal mode, but was unable to run gmer, both in normal and safe mode. It said there was an unexpected error and it must close.Here is my dds log. Anything else you'd like me to do, just tell me.DDS (Ver_10-03-17.01) - NTFSx86 Run by David at 1:35:00.38 on Sun 06/06/2010Internet Explorer: 7.0.6001.18000Microsoft? Windows Vista? Home Basic 6.0.6001.1.1252.1.1033.18.1915.1146 [GMT -4:00]SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLau... Read more

A:was infected with koobface.worm, must use safe mode

3 more replies

Hey guys,So my girlfriends computer had a virus on it called Windows System Defender. It installed itself while browsing the internet, no we don't remember what site it was. I looked up ways to remove it and I did everything it said to do and even removed an instances of it from the Registry. It still persists and continues to come back,we think. After running a bunch of virus scanners it appears that I have gotten rid of the original virus but now have a new one that we can't figure out what it is and won't pop up on virus scanners. It also won't let us boot up in safe mood. It gives us a blank blue screen when we try to do so. I have posted a HJT log to see if that will show anything. Any help is much appreciated. Thanks.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:20:16 PM, on 11/3/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16915)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Intel\Wireless\Bin\S24EvMon.exeC:\Program Files\Intel\Wireless\Bin\WLKeeper.exeC:\WINDOWS\system... Read more

A:Infected With Virus and Can't Boot to Safe Mode

Problem has been resolved.

2 more replies

Hello,

I'm using a spare computer to try and resolve an issue with my laptop.

Earlier I was using Firefox but Internet Explorer suddenly began to pop up. After a few tries using Task Master, I was able to shut off IE. But I wanted to search for any trojans or viruses and attempted to scan using Malwarebytes. This program shut down after a few seconds of scanning. When I attempted again, it said "Windows cannot access the specified device, path, or file."

I tried to run HijackThis in Safe Mode to try and get a log but got the exact same message as above about Windows not being able to access.

Any assistance would be GREATLY appreciated!

A:Badly Infected - Cannot Run HijackThis in Safe Mode

16 more replies

Hi,
My computer is running windows 7 64bit and got infected with win32.sality.bh. I am not able to run any program except kaspersky. I had a full scan and removed all threats it could find but apparently the so called anti virus is not as powderful as it described. i still cant open any program. I tried to run in safe mode but cant do it without msconfig. any idea how can i run in safe mode? thanks in advance.

More replies

Hi,

Had Issues for a while with being directed to random sites while using google and random pop ups,

Had the Yellow shield pop up in the task bar telling me i had to restart the system, after restart the Colour of the font in Firefox had changed to black and was running slow and freezing, 3-4 minutes in and the system would freeze only relief being the restart button.

3/4 restarts down the line im here , after the Windows XP loading screen goes off the screen just stays black no welcome page

EDIT EXTRA: It seems the wpa.dbl fil was modified at the time of the attack

Hijack This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:40:42, on 15/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.micros... Read more

More replies

A user came to me with a laptop that does not connect to the internet at all in normal mode. (Wired or wireless, DHCP or static IP, IPv4 or IPv6)
Connects to the network perfectly fine, but no internet connection.
Unless in safe mode then the internet works just fine. (which led me to think malware was the root of the problem)
Nothing else appears to be wrong/off; just lost internet connection.

ipconfig /release /renew... nothing
ipconfig /dnsflush /dnsregister... nothing
Tried new drivers... nothing
reset winsock... nothing
Scanned with McAfee... Clean
Scanned with MBAM... Clean
rkill... clean
tdsskiller... clean
running a hjt now, but thought I would post here first and see if it may well be something else.

NOTE: If you think this should be posted in networking then let me know and i'll gladly create a new thread there. I will not post my HJT until recommended, and that will go into the appropriate thread

Thanks in advance for your help. I've been using this site for years, first time I couldn't find a fix and need to post.

A:Internet Connection In safe mode only. Am I infected?

Uninstall your antivirus and let us know if you can connect

1 more replies

hi i'm new to the forum, and need some serious help. i clicked the wrong thing, and now i have some virus on my computer, here is what i have tired so far

1. I ran my virus software AVG, but when it starts scanning, it goes like 5 mins then just shuts down, the program still stays open but the scanning window just shuts without completing the scan

2. I ran Ad-ware, and it scans till it gets to the HKEY scan then locks up.

3. I made system recovery disks through the AVG software, but i can;t get the computer to boot of the disk, and i don;t know how to get it to work.

4. I tired restarting in safe mode, to run the virus programs again and the computer will not go into safe mode, it says there was an error and i must start it normally.

following systoms:
-when i start internet explorer it goes right to google, and types in "free porn" and searches out....(no idea why it does this)
-when i open up my documents, windows freezes and has an error then shuts down
-when i start the computer a toolbar pops up on the right side with ads for spyware, porn, insurance and other things.
-also some other things, i can;t really explain

now i been reading on here about HijackThis, so i downloaded that and got the log file. I also got Ewido, i ahevnt; ran a scan yet. i know a little about computers but i can't get anything to work or get this thing off. so here is the log file
------------------------
Logfile of HijackThis v1.99.1
Scan saved at 8:50:45 PM, on 12/... Read more

A:Infected and wont restart in safe mode

14 more replies

I am available Mon - Thur, but will monitor my post and go to the computer if necessary over the weekend. This is an elderly woman's laptop done as a volunteer project and I will receive no compensation for my services.

I get redirected trying to go to bleeping computer and had to use safe mode to download and post.

Here is my log:

DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 11.0.9600.17344
Run by Judy Gilman at 9:28:45 on 2014-11-05
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.4008.3250 [GMT -5:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\svchost.exe -k secsvcs

A:Win 7 infected with redirect. Can only use Chrome in safe mode.

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/554855 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
If you do need help please continue with Step 2 below.

2 more replies

Hi - I am running a win 7 OS and am infected with the FBI moneypack virus. It is not allowing me to enter either 'safe mode' or 'safe mode w/ networking' or 'safe mode with command prompt'.

When I log in to the computer using a different user I don't have this issue.

A:FBI Moneypack Virus - Infected even in safe mode

Hi gsms123

I will be handling your log to help you get cleaned up. Please give me some time to do up a fix and I will get back to you as soon as possible.

White Warrior

23 more replies

My XP machine has a problem.  It gave me the Moneypak page on boot up and won't boot into safe mode.

I made a ubuntu startup disk and used that to backup my data files.  Also, ran some antivirus boot disks (Kaspersky, Bitdefender, and AVG), but it did not fix the problem.  However, they did get rid of the Moneypak page that was showing on startup.  Now when doing a normal boot, I see my desktop for about 1 or 2 seconds, then get a beige screen which changes quickly to a white screen and hear the hard drive spinning - probably loading things.  When I hold the power button to reboot, the blank page shuts down and I can briefly see my normal desktop full of icons again. Not enough time though to run any programs.

Since I can access my files by booting into Ubuntu, I assume the problem could be fixed by manually removing the right files or making some other changes, but I don't know which.

Can anyone help me get my machine working again?  Your assistance is much appreciated.

A:Infected with Moneypak - can't boot into safe mode

more replies

XP Pro SP3 machine boots fine normally but can not get past the driver loads in safe mode. It just starts over. Seems to stop at the MUP.sys line. I've copied in a different MUP.sys file but it didn't help.
Original problem is something is starting up about 9 instances of Windows Explorer in full screen on multiple advertising sites and hanging the PC for a while. Also get memory location errors popping up at regular intervals. Memory test is good and the sticks are now 4 days new but still get the errors that don't hang anything but the messages just reoccur.
Ran Malwarebites and deleted old user profiles, temp files and got Windows updates current. Didn't see any odd programs installed or notice any crazy processes but haven't sorted each little one out yet. Have antivirus on it but not detecting anything.

A:XP Pro Infected boots OK but not booting into safe mode

Video card or internal?

2 more replies

Today, my laptop became infected with the FBI malware.  It has disable my ability to use Safe Mode in any way.

I urgently need assistance.   Thanks.

A:Infected with FBI Virus - Safe Mode is not accessible

3 more replies

Hi Guys,

My WinXP Sony Vaio VGN-215M has been infected by what the Dr. Web demo identified as 'NTRootkit.83'. The first symptom I noticed was .EXE files starting to disappear, including my Norton Antivrus. Another problem I noticed is my wireless network connection has disappeared (no networks show up anymore).

I have tried a variety of tools including the McAffeee Rootkit tool beta, but it seems this one is still sticking around. Dr. Web support indicated I should reboot in safe mode and then run Dr. Web to remove it, BUT; when I try a reboot in any form of safe mode, it:

a) reboots
b) shows the loading screen, and then goes through a list of drivers on the bottom of the screen
c) reboots itself back into normal mode

So effectively I cannot reboot into safe mode.

I have output the following Hijackthis logfile, if this helps:

Logfile of HijackThis v1.99.1
Scan saved at 8:19:25 PM, on 16/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Apoint\Apoint.exe

A:Infected with NTRookit.83 - Can't reboot in safe mode

Still getting nowhere.

Installed Dr. Web antivirus, and just like my Norton, the .exe files for the program disappear. This is one nasty litte trojan.. please help!

1 more replies

okay... so i was trying to get into safemode so i could run an antivirus scan, problem is whenever i tried going in safemode the blue screen would pop up and computer would restart. now for some dumb reason i thought maybe i could get in safemode if i used msconfig and selected safe mode from the boot menu. so the computer restarted and now it boots in safemode but the blue screen and restart happen everytime now. ive tried "start windows normally" but that boots in safemode.... ive tried "last known good config..." and that too boots in safemode. so now im stuck, i cant get on windows. any help please?

im willing to start over but i dont know how to do that from here

A:STUCK in safe mode boot, safe mode doesnt work and restarts, REPEAT

11 more replies

A:Infected With Numerous Items. Can Only Boot In Safe Mode

Hi, PaulDH Welcome.Please download ComboFix from Here or Here to your Desktop.**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**Please, never rename Combofix unless instructed.Close any open browsers.Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-----------------------------------------------------------Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
-----------------------------------------------------------Close any open browsers. WARNING: Combofix will disconnect your machine from the Internet as soon as it startsPlease do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.If there is no internet connection after running Combofix, then restart your computer to restore back your connection.-----------------------------------------------------------Double click on combofix.exe & follow the prompts.When finished, it will produce a report for you. Please post the "C:\ComboFix.t... Read more

12 more replies

I have a relatively new Vista Home system which was running fine until last night, when running an exe windows showed the command prompt listing keygen.exe, and serial.exe. Then another was listed, and Windows said something had stopped responding, and it would shut down in 1 minute. It restarted, and after the boot screen, microsoft loading bar the screen usually just remains black, and eventually reboots. Sometimes you see the vista logon scree and it says please wait, only to go black and do the same. Although there's also a short delay with a black background only with a cursor, I can load in safe mode. Here I've run a full AVG anti spyware (formerly ewido) scan which some stuff, unfortunately I can't find reports of that or Avast AV I ran, but I thin it picked up a keygen archive, and deleted 1/2 trojans, moved some other stuff to the chest. In add/remove programs I've found an un-installed some oberon media entries, including big kahuna reef 2, galapago, and others. It's still the same, desperate for help, thanks in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:22, on 09/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Minefield\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Pa... Read more

A:Infected with trojan, Vista won't start aside from safe mode

Quote:

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Hello and welcome to the forums

My name is Katana and I will be helping you to remove any infection(s) that you may have.

Please observe these rules while we work:
1. If you don't know, stop and ask! Don't keep going on.
3. Please continue to respond until I give you the "All Clear"
(Just because you can't see a problem doesn't mean it isn't there)

If you can do those three things, everything should go smoothly

----------------------------------------------------------------------------------------

I apologize for the delay in responding, but as you can probably see the forums are quite busy.
Unfortunately there are far more people needing help than there are helpers.

Installed Programs

Please could you give me a list of the programs that are installed.Start HijackThis
Click on the Misc Tools button
Click on the Open Uninstall Manager button.
You will see a list with the programs installed in your computer.
Click on save list button and specify where you would like to save this file.
When you press Save button a notepad will open with the contents of that file.
Simply copy and ... Read more

3 more replies

I'm trying to help fix a friend's infected machine. I don't know what caused it but i can not run most of the malware removal tools.

The XP SP2 PC is getting continuous bad image errors pointing to a file called "UACxtcujhcadh.dll" - not a valid Windows Image.
Can not run any program without these error messages and the standard malware tools won't run.

The machine will only boot into safe mode, otherwise will get a blue screen with Driver_IRQL_Not_Less_or_Equal after login.
I've run a RootRepeal and will include the log.

Thank you in advance for any suggestions. Any idea which infection I might be dealing with here?

A:Infected, Can't run removal tools, only boot into safe mode

Go ahead and close this. I can not get any programs to run. RootRepeal can not access the boot sector and it throws up an error that it can not read the registry.

I'm going to wipe this machine so this can be closed.

2 more replies

I am working for someone and using their computer. I have accidentally infected this computer and do not have access to the Administrator account to change/revert things. I am in safe mode now and can access the internet. I have tried calling places like Symantec to get help over the phone and there is not much they can do without admin access. I will post the DDS log at the end. The GMER was not able to scan my computer, most likely because of the infection.

I apologize, I do not remember the exact names of the infection or the "antispyware program" that was running after. The virus started with an S and sounded like syndavi. The "antispyware program" was called AntiSpyware _______. I have Symantec Endpoint protection on this computer. I can restart out of safe mode to find these but I would rather not make anything worse as it is not my computer. Is this possible to fix without admin access? Will pay well if it is able to be resolved. Thank you so much for your help!
DDS (Ver_10-11-27.01) - NTFSx86 NETWORK
Run by vevans at 13:00:33.75 on Fri 12/03/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1367 [GMT -5:00]

AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE

A:Infected with no admin access, running in safe mode now

3 more replies

My cousin's mouse stopped working on his computer after installing a game expansion. He asked me to try to fix it and I noticed his computer was heavily infected with viruses. I've removed a lot of malicious files through Malwarebytes' Anti-Malware; however, the mouse still doesn't work, and I think there are still viruses. I also tried to reinstall the drivers for the mouse off the manufacturer's website(Logitech), but it didn't help. Since the mouse only works in safe mode, I can only run GMER in safe mode.DDS (Ver_10-03-17.01) - NTFSx86 NETWORK Run by Administrator at 19:10:45.24 on Mon 09/20/2010Internet Explorer: 7.0.6000.16643Microsoft? Windows Vista? Home Premium 6.0.6000.0.1252.1.1033.18.2813.2149 [GMT -7:00]AV: McAfee VirusScan *On-access scanning enabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svcho... Read more

A:Mouse only works in safe mode, infected with viruses

11 more replies

I have a relatively new Vista Home system which was running fine until last night, when running an exe windows showed the command prompt listing keygen.exe, and serial.exe. Then another was listed, and Windows said something had stopped responding, and it would shut down in 1 minute. It restarted, and after the boot screen, microsoft loading bar the screen usually just remains black, and eventually reboots. Sometimes you see the vista logon scree and it says please wait, only to go black and do the same. Although there's also a short delay with a black background only with a cursor, I can load in safe mode. Here I've run a full AVG anti spyware (formerly ewido) scan which some stuff, unfortunately I can't find reports of that or Avast AV I ran, but I thin it picked up a keygen archive, and deleted 1/2 trojans, moved some other stuff to the chest. In add/remove programs I've found an un-installed some oberon media entries, including big kahuna reef 2, galapago, and others. Tried system restore which couldn't log in, with same black screen problem. I'd rather not re install as I the systems nicely setup, plus I don't have Vista Home Premium CD, only an ultimate which. It's still the same, desperate for help, thanks in advance.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:22, on 09/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode with network suppor... Read more

More replies

I've tried everything I. The F8 menu, I'm in a reboot/launch repair loop.
I've tried kaspersky recovery disk and advair boot disk and can not get the virus off so I can atleast boot into windows and fix this.
Ideas? Should I try FRST64?

A:Infected with a virus can't boot windows even into safe mode

Should I try FRST64?

Please do and post its report.

3 more replies

Ever since I got that virus my computer has only been able to start in safe mode with networking. Whenever I boot up my comp, the typical windows xp screen would load and then a blue screen would flicker for a mili sec (too fast for me to read!) and then I am presented with the option of booting it into safe mode. I have ran Malwarebytes anti malware and it seems to have gotten rid of most of them, but one or sometimes two keep coming back. The trojan "HKEY_Local_Machine\software\tdss" would come back every time I reboot and run malware. If I dont get rid of it, it will re direct me to a different site (about viruses) whenever I click on links. When I get rid of it, links work fine. And I was unable to run adware and and spybot in sm, I have ran stinger though...Logfile of Trend Micro HijackThis v2.0.2Scan saved at 18:45:20, on 10/23/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)Boot mode: Safe mode with network supportRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Internet Explorer\Iexplore.exeC:\Program Files\Trend Micro\Hija... Read more

A:infected with xp anitvirus 2009 and can only access safe mode

13 more replies

Hello,

I have a Dell laptop which is infected with Infected Antivirus Security Pro, will not let me start in safe mode:
Windows 7 Home Premium, P4 Dual Core T4300 2.10GHz, 4.00 GB,  64Bit 500GB HD.

I tried running malwarebytes and all .exe file execution are blocked by Antivirus Security Pro, tried to restart in safe mode as soon as it gets to desktop it shuts down and restarts.

Need help removing please, Thank you

A:Infected with Antivirus Security Pro, will not let me start in safe mode

Before you do anything just try and "activate" it using this code, its a longshot but sometimes it works and you will be able to run malwarebytes and other tools

AA39754E-715219CE

See video for help on to do this

6 more replies

Hello, I have probably 20 hours into trying to repair a Dell Inspiron 6400 running Windows XP Pro. The most frustrating part of this is that tools that I believe might help, such as Malwarebytes AntiMalware, Hijack This and RootRepeal are being blocked from installation or running by something...even in Safe Mode. I have tried the rename files names to get them to work...they still do not open. It is the "something" that I have been unable to find.
I was able to load Spyware Doctor, but when scanning it would hang up on one program...so it never finished. I was able to run Virut (it cleaned files, unable to open some) and right now Symantec Trojan.Vundo Removal Tool is running.
I have done a Windows Repair Installation which means I rolled back to SP1. I can get Internet access in Safe Mode, not in regular mode. When I try to update Windows it stops in the middle and says I have an error. I get a "spoolsv" error when the machine starts. From reading it appeared this is a Windows update issue. I did look for excessive SPL's and there were none. When in Internet Explorer I get the red letter warnings that I am infected with 18 trojans and should scan my machine. I did not click on scan my machine. Typically when trying to go to a antivirus/malware site I am blocked or Explorer/Mozilla closes.
I got regedit to work by renaming it reg-edit. The other above mentioned programs did not work even when renamed. Another program that will not work... Read more

More replies

Ok I will list the problems in order that they occured...

-Went to a site, suddenly I get the infamous fake spyware icon (the blue shield) and it says I have all these viruses and starts scanning

-I try to open up AVG and it's locked. I try MBAM and it's locked. Thankfully super antispyware works. and finds 4 of the trojan dropper and gen combo

- I delete and restart my computer in safe mode when I GET A BIG BLUE screen telling me that there was a problem (something like hardware problem or changes). This has never happened to me! I usually run safe mode and run my scans and boom my problem is solved but somehow it seems to be blocked!

-On the bright side my computer WILL load in regular mode but I seem to have the yahoo redirect problem. I ran trend micro, AVG, MBAM, and super antispywar and they dectect NOTHING. Please help! I'm really out of ideas on what to do. I ran a combo fix but it didn't take long and really had nothing in the log that stood out. If I need to post a hijack log I will gladly but I'll have to get back to the infected computer.

More replies

Hello,I am dealing with a problem a few days now and I can't find a solution for it.When i boot my pc, windows load to desktop and after a minute or so i get a blue screen with the error message:QUOTESTOP: 0x0000008E (0xC0000005, 0x80635AC1, 0xB490796C, 0x00000000)Also nod32 icon was red but i couldn't click on it (windows were buzy loading other programs).I booted pc in safe mode and tried to run nod32 but it wouldn't start. I uninstalled it and tried to install Kaspersky but due to safe mode i couldn't install it. I then downloaded malwarebytes and run a full scan.This is the log from the scan:QUOTEMalwarebytes' Anti-Malware 1.44Database version: 3554Windows 5.1.2600 Service Pack 2 (Safe Mode)Internet Explorer 6.0.2900.218014/1/2010 12:46:54 ???mbam-log-2010-01-14 (00-46-54).txtScan type: Full Scan (C:\|G:\|H:\|)Objects scanned: 554114Time elapsed: 1 hour(s), 37 minute(s), 26 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 6Registry Values Infected: 3Registry Data Items Infected: 1Folders Infected: 2Files Infected: 4Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft&#... Read more

A:Infected, Blue Screen, PC only Boots in Safe Mode

2 more replies

The compter is locked.  I have tried to restore system earlier date- did not work.  I get into the advance boot options window but when I chose either of the safe modes-  it shuts down before I can get to anything-Edit: Moved topic from Am I infected? What do I do? to the more appropriate forum, at the request of Malware Removal staff. ~ Animal

A:fbi money pak virus removal- has infected my safe mode- HELP

Don't give up on System Restore after one try!  I have removed this virus twice this week for people and they have a newer version than anyone talks about on forums or can see in removal videos on Youtube.

My solution was to run system restore more than once trying a couple different restore points till one completed successfully.  In one case, it said it was unsuccessful but when the computer rebooted normally afterwards, it actually was successful.

Press F8 when rebooting to bring up boot options and select "Repair Your Computer".  Log in as administrator and select system restore and try again if you can on an available restore point before the infection.  It may take a few tries.

Post back here if it is not.

15 more replies

Hi folks,

I'm on windows XP.

When computer first loads up I get this message:
"avgwdsvc.exe encountered a problem and needed to close"

internet explorer and firefox do not work. However, IE works when started "with no add ons" and firefox works in safe mode. Email works.

I'm worried I have a virus. I'm not able to run avg to do a virus check because it crashes every time it is loaded.

I've installed and run three anti malware programs but the problem is still present

Would really appreciate some help.

Cheers,

More replies

Hi,

I have a laptop running windows 7 that has been infected with Antivirus Security Pro.  When I try to start in Safe Mode the computer keeps restarting before I can do anything.

I can not seem to start any programs.

A:Infected with Antivirus Security Pro, will not let me start in safe mode

36 more replies

W32/Blaster.worm has infected laptop. Can't get on web. Can't get in safe mode.
From my cell phone I have been researching and it seems to be an old virus.
I am getting security warning/malicious program.
Firewall warning: Hidden file transfer to remote host has been detected. There is a remote host transfer IP: 25.92.229.139.
And it make a pig squeal sound when I start it up!

A:W32/Blaster.worm has infected laptop. Can't get on web. Can't do safe mode.

2 more replies

Hello,

Could someone please help, I have lost control of my laptop. If I boot into normal mode the computer freezes and I have to turn it off manually. In safe mode I cant run Hijackthis or Avast. Microsoft Security Essentials cannot update.

I have ran TDSSKiller and pasta the log below. It found 8 threats but dont know what to do it them.

Im running Win 7 Pro.

Any help would be much appreciated, thanks
15:00:04.0499 2600 TDSS rootkit removing tool 2.7.41.0 Jun 20 2012 20:53:32
15:00:04.0619 2600 ============================================================
15:00:04.0619 2600 Current date / time: 2012/06/21 15:00:04.0619
15:00:04.0619 2600 SystemInfo:
15:00:04.0619 2600
15:00:04.0619 2600 OS Version: 6.1.7601 ServicePack: 1.0
15:00:04.0619 2600 Product type: Workstation
15:00:04.0619 2600 ComputerName: Scorpio
15:00:04.0619 2600 Windows directory: C:\Windows
15:00:04.0619 2600 System windows directory: C:\Windows
15:00:04.0619 2600 Running under WOW64
15:00:04.0619 2600 Processor architecture: Intel x64
15:00:04.0619 2600 Number of processors: 4
15:00:04.0619 2600 Page size: 0x1000
15:00:04.0619 2600 Boot type: Safe boot with network
15:00:04.0619 2600 ============================================================
15:00:05.0039 2600 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder... Read more

A:Badly Infected - Cannot Run Avast or HijackThis in Safe Mode

Hello again, I was reading through other posts and installed combo fix. Maybe this might be of some help too

Thanks

ComboFix 12-06-21.01 - Administrator 21/06/2012 15:44:35.1.4 - x64 NETWORK
Microsoft Windows 7 Professional 6.1.7601.1.1252.353.1033.18.8089.6972 [GMT 1:00]
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Access Centre\AppData\Local\TempDIR
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\instsrv.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-05-21 to 2012-06-21 )))))))))))))))))))))))))))))))
.
.
2012-06-21 13:50 . 2012-06-21 13:50 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3BFA3D38-DCC1-4969-9747-699DB7E1B76A}\offreg.dll
2012-06-18 11:27 . 2012-06-18 19:33 -------- d-----w- c:\users\Administrator.AccessCentre-PC\AppData\Roaming\EndNote
2012-06-18 11:27 . 2012-06-18 11:27 -------- d-----w- c:\program files (x86)\Co... Read more

2 more replies

i have windows home xp edtion on parkard bell.in safe mode it is fine,but when on normal bootup mode it will hang up after 2mins aprox(then restart saying crit error,check hardware etc and being to dump files kernel),on a blue screen.

i tried a different graphics card,but no joy.so i replaced the hdd drive and put a fresh copy of windows xp pro edtion on,but it loads all the files(i have not pressed f6)i just let it run its course on the disc,then it hangs up on the blue screen again with the words(crit error 0x0000007f)check hardware etc and if this is the first time you have seen it try starting windows again.

A:Solved: xp safe in safe mode fine...mormal mode blue screen

Start in Safe Mode and look in C:\Windows\Minidump for crash log files with a dmp extension, like Mini071008-01.dmp. Zip 4-5 of the latest ones and post here as a ZIP or RAR attachment. The log file contains information useful to determine what caused the error, most likely hardware.

2 more replies

I'm new here and in hopes of getting this resolved. I just installed the new Norton Systemworks 2005 and rebooted after installation. When the boot screen got up to the blue screen with the Windows XP logo before displaying the login names where you put in your password, it just stops. I restarted a few times and waiting a few more times thinking it may need to 'finish' installing. But each time gave the same results. Finally, I went in with 'Safe Mode' and got in with no problems. Tried again in normal mode after looking around for any obvious problems (none found)... back to square one. Tried again in 'Safe Mode with Networking' and it failed like normal mode so I suspected a networking problem??? The last thing I tried which made me mad is that I tried to uninstall Norton Systemworks in 'Safe Mode' and that failed!! Anyone in these forums know the cure? :dead:

A:Unable to get to login screen, works in Safe Mode but in Safe Mode w/ Networking

Just a thought

Safe-Mode
Start \ Run \ msconfig \ diagnostic startup
disable any services attached to your most recent install and restart
should get warning next boot about using msconfig, its ok
One key service that needs to be available is the installer service
Try the uninstall, if doesn't complete
Try the uninstall string in the registry only if you know what you are doing

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

Under it you will see a list of installed programs. Some don?t show up as words but you can figure out what they are by looking at their values. What you are looking for is the uninstall string. Double click that key as if you were going to modify its value. Do a CTRL + C to copy and then exit the registry editor.

Go to START \ RUN and paste the uninstall sting and hit enter. This should launch the uninstall.

Just a thought though as I am not infront of a test system at the moment. You should research this a little further so you have a clear understanding of what you can and can't do with msconfig.

or simpler yet

Safe-Mode

Start \ Programs \ Access. \ System Tools \ System Restore

Select restore point prior to install of whats giving you the problem.

Again, Good Luck

PS If you try to install it again, turn of antivirus and other open programs etc..

1 more replies

My PC has been infected with 'Internet Security' and i have followed all the steps on
http://www.bleepingcomputer.com/virus-removal/remove-internet-security-2012 but have not successfully got my computer back.

I located the virus files and rename to virus and virus2.

I then ran:
FixNCR.reg
tdsskiller.exe -> can't load driver -> does not find a rootkit infection
Malwarebytes anti-malware -> 38 days old version as i cannot access internet -> found and remove internet security (log attached)
Spyware doctor -> failed to set up due to lack of internet. starts automatically when booting up the PC.

they seem to have stopped 'internet Security' however i cannot connect to the internet, cannot enable mcafee, cannot boot on safemode (get blue screen saying i should check my computer for viruses or recent changes), cannot do system restore to a previous date. I suspect some sort of stubborn rootkit infection.

outputs from dds.txt:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by SanchezPrieto Family at 0:47:17 on 2012-02-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1425 [GMT 11:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe

A:Infected with 'Internet Security' and unable to boot on any safe mode

Hello al345 and welcome to BC.

Sorry about the delay, do you still need help?

75 more replies

Hi,

I am infected with the System Care Antivirus on a Windows XP machine. When I try to boot into Safe Mode (both with or w/out Networking), I get a Windows blue screen of death. I have removal instructions that I can follow, but those depend on launching Safe Mode. Any suggestions? Is there a rescue disc that I could try?

[Note: The machine does boot into normal Windows mode].

Thanks!

FrisB

A:Infected w System Care Antivirus -- Can't Boot Into Safe Mode

I'll report this topic to appropriate helpers.
Hold on there....

4 more replies

My laptop has been infected by malware/spyware. This is the first time i have joined any forum so look forward to your help. I have been working in safe mode since 2 days and need immediate help as this is my company laptop and i need access to programs that i cant get in safe mode.
Below is the HJT log report and attached is DDS. I could not run GMER in safe mode, let me know what to do. I also see that their is an "iexplore" process running in task manager which is a Trojan, as it launches itself after regular intervals even after i kill the process.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:25:25 PM, on 3/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe

Hello and Welcome to TSF.

Hello and Welcome to TSF.

Quote:

this is my company laptop

We are sorry but this forum is intended for the home user.

This thread shall now be closed.

------------------------------------------------------

1 more replies

I am having the same issue posted by KellyV6726.  I have the "Antivirus security pro" virus but can't follow the fix instructions because it won't let me boot in Safe Mode of any form.   I followed the instructions from Aaflec in KellyV6726's  post and created a FRST.txt file, which I'll paste below.  Since Aaflec took Kelly's FRST file and created a fix file, I am hoping someone can do the same for me - or tell me how to do it.  (I initially posted this issue in the "Am I infected" forum, but received no replies so I'm assuming that was not the right place!)

The contents of my FRST file:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013
Ran by SYSTEM on MININT-K0HBV6E on 01-11-2013 14:12:54
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [nwiz] - nwiz.exe /install
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NVHotkey] - rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
HKLM\...\Run: [ccApp] - C:\Program Files\Common F... Read more

A:Infected with Antivirus Security Pro and cannot start Windows 7 in Safe Mode

26 more replies

Hi - I was following another post where Afflack (splng?) was helping someone with the same issue.  I was able to create a FRST text file as he instructed.  However, in the post I was following, Afflack took this info and created a fix file for the user's computer.  I am hoping the same can be done for me.  Here is the contents of the FRST scan.  If I need to provide anything else, please let me know.
Thanks - Dinx

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013
Ran by SYSTEM on MININT-K0HBV6E on 01-11-2013 14:12:54
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [nwiz] - nwiz.exe /install
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NVHotkey] - rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
HKLM\...\Run: [ccApp] - C:\Program Files\Common Files\Symantec Shared\ccApp.exe [115560 2010-06-09] (Symantec Corporation)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Micr... Read more

A:Infected with Antivirus Security Pro and cannot start Windows 7 in Safe Mode

Sorry for the mis-spelling - the person who was helping was Aaflac.

3 more replies

Good day to everyone, especially those lovely people at BleepingComputer.com.

Tonight (Monday 1st July 2013) around 22:30pm my monitor went blank and was then replaced by a full screen message stating that it was the United Kingdom Police (Cheshire Police Authority), with a pic of the Metropolitan Police top man Bernard Hogg-whathisname.  It told me to cough up £100, payable by ukash or paysafe only.

Obviously it's a ransomware scam, and it's not the first one that I've had on my PC. You guys very kindly helped me get rid of my last one (Live Platinum Security virus).

I'm running Windows Vista, with Malaware (trial version) and Pandasoft AV software.  So much for Pandasoft....

One major problem that I have however...  I cannot create any DDS logs or download anything.  As soon as I log into my PC, the ransomware automatically kicks in, locking me out of my computer.
I've tried booting it into safe mode, both with and without networking, and all what happens is that  as soon as I log in, the PC instantly goes into restart mode.  This virus is an evil little bugger, I'll tell you!

As I work a 12-hour shift, I won't be able to reply or do much until late in the evening (UK time).

Thanking you in advance with helping me kill this nasty virus off my PC.

Best regards,

Graham

A:Infected with PCeU ukask/paysafe ransomware, cannot access safe mode

28 more replies

Hi,

I have been goin through and taking help from various threads here and I appreciate every person who is supporting others in some way or another .. THis is a great team work. Kudos to all.
Coming to my problem, My Computer Acer 1640, Windows Home edition, with 512mb was infected with Advanced Virus Remover. Initially disabled every Windows utility of my computer and then my system went dead (black screen). Safe mode was no better. Eventually one day, my lap gave me a desktop on safe mode and i went on to create a new user with all administrative rights. This might sound stupid, but i am not a computer whiz and jus did thing my way. Then using the new user, i went into registry and also local services. In local services i was able to start my McAfee and run a scan. Although this was not that helpful since my networking was not available, it did motivate me to look further. Eventually one day, I could get my internet working in safe mode. I downloaded Malwarebytes and it cleaned up most of the rubbish. I still was restricted from using Systerm restore and many other functions but using registry edit, i figured to activate system restore. But my current problem is that i am not able to log on to windows normally even though i tried doin the same using F8 option.

I wanted to restore my system to a previous date and get it runnign properly and this is possible only if i can log bak to windows normally.

pls help

I appreciate eveyrone who has taken time to read thru this, ... Read more

More replies

Hello

I've posted the message below in the Virus, etc. Removal Logs forum already. I'm new here (first time infected with a virus!) and so don't know which forum is really the most appropriate to get the quickest useful response. Apologies if posting in more that one thread is against etiquette.

Ed

------------------------------
My PC has been infected with a UK version of the FBI MoneyPak virus, claiming to come from the Police Central e-Crime Unit (PCeU) and demanding ?100 via uKAsh or paysafe care to unlock my computer.

I have Windows Vista Home Premium.

I have tried to follow the advice on the Norton support site and here on bleeping computer by starting the computer in safe mode. But as soon as I log in, the virus takes over the whole screen so I cannot use my browzer to download any software to try to fix it.

The only thing I am able to do when the virus screen has appeared is to use Ctrl-Alt-Delete to bring up the screen which gives options:
Lock this computer
Switch User
Log off
Shut down, etc.

If I try to start Task Manager, it flashes for half a second then disappears and the virus screen takes over again.

I'm completely stuck. What help or advice you can offer.

Ed

A:Infected with UK Police MoneyPak virus - Safe Mode doesn't work

Hello Sheddy71,

Since no logs were included in the other topic nor in this one. This is the forum you should start with. I have deleted the other topic in the log forum to avoid confusion for everyone. Thank you for choosing Bleeping Computer for your Malware Removal needs.

Someone with malware experience should reply to you here shortly. Please be patient while your topic is evaluated by our volunteer helpers.

2 more replies

My computer is infected with a search hijacker. I've tried malwarebytes, trend micro and super-antispyware, but haven't been able to remove it. Now, windows won't even start - it gets hung up after the initial window xp screen, leaving just a blank black screen; i.e. the desktop never comes up. Thanks for the help. Here is the DDS log:DDS (Ver_09-12-01.01) - NTFSx86 NETWORK Run by Joe at 20:43:06.21 on Tue 12/15/2009Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.721 [GMT -5:00]AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\system32\svchost.exe -k netsvcssvchost.exesvchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Internet Explorer\iexplore.exeC:\WINDOWS\system32\rundll32.exeC:\Documents and Settings\Joe\Desktop\dds.scr============== Pseudo HJT Report ===============uStart Page = hxxp://www.google.com/uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0�... Read more

A:Infected with search hijacker; now windows doesn't open except in safe mode

13 more replies

I can download and run DDS, but it gets killed before I get the log. Ditto with RootRepeal and HijackThis. When I try rkill, it seems to work, but then I immediately get a "personalized settings" pop-up, which runs briefly, then (I'm assuming) undoes whatever rkill achieved. None of the malware removers I've tried (Malware Bytes, SpyBot, Windows Defender, AdAware) run to completion. I've tried exefix, which again, seems to run fine, but the tools still won't finish. Upon normal boot, Windows XP launches, then the "Personalized settings" thing pops up first, followed by "Protection System"--a virus I've been able to read about online, but none of the fixes I've seen elsewhere seem to work. Windows Defender makes an appearance, but when I try to start it, it says "Access is denied. Error code: 0x80070005." I also have some redirect problems when trying to find solutions online, but I can work around it by going to the site in question (e.g., bleepingcomputer) and searching internally for my problems. When I try and run in safe mode, I get a blue screen: STOP: 0x0000007E(0XC000005, 0x8537009, 0XF7C7B3E0, 0XF7C7B0DC).Any help at all would be greatly appreciated! I assume the first step is figuring out how to get a DDS, RootRepeal or HijackThis log, but I'm totally flummoxed. Would listing my processes help?I got D.D.S. to run! Here are the results.I'm trying RootRepeal again next.DDS (Ver_09-10-26.01) - NTFSx86 Run by Matt at 10:3... Read more

A:Infected: safe mode=blue screen, can't run any spyware removal tools

I realize there's a policy against "bumping" threads here, but my computer's getting progressively worse. Yesterday, the system tray disappeared, and today, Windows XP no longer loads; I get a blue screen no matter which configuration I try. I'm guessing that my best bet is going to be salvaging whatever I can from the hard drive and reformatting Windows XP, but before I go that route, I thought I'd give this one last shot! If any of you wonderful, overworked volunteers is able to take a look in the next day or too, I'd greatly appreciate it.

Much thanks,

Plautus

25 more replies

Hi Folks.
I am new to the forum.
One of my PCs is acting strange. XP SP3 system.
Cleaned some things with Mbam.
But noticed that when I boot into Safe mode, McAfee Real Time scanner is off. If I turn it on, 3 seconds later it gets turned off. Seem like a virus.
McAfee scans are clean. MBam scans are now clean.
Several online scanners come up clean
several free scanners come up clean (occasional tracking cookie)
Combofix runs to stage 50, prints "deleting files" and the PC immediately reboots.
Usually jusched.exe crashes after startup.
Feels like something is lurking in there.
Any help is appreciated.
Below is the HJT log.

Thx.
David

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:32:37 PM, on 2/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe

A:Mcafee Real time scan disabled in Safe Mode - Infected?

2 more replies

I booted into safe mode to try an fix a issue I selected to boot with command prompt butb I have a all black screen an can't get out of safe mode now I restarted the laptop a few times still the same 'anyone know how to fix this?

More replies

Hello,

Recently my dad's computer had a corrupted hive and boot.ini. Via this website, I was instructed to run a chkdsk /r while in the recovery console. Everytime I used his OS disk to get into the recovery console, it prompted me for a password and I didn't know it (nor could I leave it blank). I decided to use my OS disk from my computer and I could fix the problem. Now, though, everytime I startup the computer, it prompts me to start windows normally, in safe mode, in safe mode with networking... To give further information...on that same screen there is an option for Windows XP and Windows XP Home Edition. Don't know if that has something to do with it. They both work though when I press enter on either one. Could anyone help me stop the computer from prompting me??? Thank you for any help.

More replies

I recently attempted to clean my brother's computer after he aquired a virus from the torrent file program he uses. Regardless, I cleaned a trojan and a backdoor from his system from safe mode. I can not boot in normal mode. Everytime i try the system gets hung up at the windows loading screen then the screen turns black and sits there. I have to hard reboot. I ahve used a repar CD and i have come across an error 0x800700b7, i have also recived this when i tried to work around this problem "identifier {9dea862c-5cdd-4e70-acc1-f32b344d4795}"

OS= Win 7

A:System will only start in Safe mode, Clean virus in safe mode

You can spend a lot of time trying to fix the boot problem and clean the virus from the computer, or you can nuke it and reinstall Windows. I wouldn't bother trying to fix it, personally - I'd back up what I could and then I'd install Windows again.

9 more replies

A:Infected with malware - no gmail, search results do not resolve, and safe mode loop

17 more replies

my problem has been getting worse over the past few days. I am usually very good at removing this stuff but for some reason this one is giving me trouble. I have run malwarebytes and does not pick up anything. when i go to IE and search on an engine, the results i click on send me to other pages. i cannot get into safe mode, give me the blue screen of death. now other programs are not letting me in, outlook etc... please help!! DDS (Ver_09-12-01.01) - NTFSx86 Run by denhom at 9:37:00.81 on Fri 01/22/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2729 [GMT -5:00]AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}============== Running Processes ===============C:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exesvchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\Symantec AntiVirus\DefWatch.exeC:\Program Files\LogMeIn\x86\RaMaint.exeC:\Program Files\LogMeIn\x86\LogMeIn.exeC:\Program Files\LogMeIn\x86\LMIGuardian.exeC:\Program Files\Symantec AntiVirus... Read more

A:Infected with somthing, browser redirecting, cant get into safe mode, blue screen of death

Hello While we understand your frustration at having to wait, please note that Bleeping Computer deals with several hundred requests for assistance such as yours on a daily basis. As a result, our backlog is quite large as are other comparable sites that help others with malware issues. Although our HJT Team members work on hundreds of requests each day, they are all volunteers who work logs when they can and are able to do so. No one is paid by Bleeping Computer for their assistance to our members.

13 more replies

Hi,

Last night my PC was infected after visiting a normal blog. Immediately my PC was getting false messages of "intruder alerts" and prompts for running a scan. Although I clicked on the "x" to close the window rather than "Yes", the next thing I know I see a blue icon on my desktop for Security Tools.

It ran a fake scan - trying to tell me I had numerous malicious spyware programs. I ignored this, but now I can't use task manager, malwarebytes and spybot get blocked so they can't perform a scan, firefox runs really slow (nothing new there...), and often gets redirected to sites promoting symantec products, or won't let me access the internet - blocking various searches like when I googled "Security Tool virus removal".

I also get a rapid fire of windows alerts telling me my PC is under attack.

It has also downloaded a "Windows Security Centre" icon which looks to be a fake as this looks to be what is driving the alerts telling me my PC is under attack - the icons however are remarkably similar to the official microsoft security centre logos.....

I attempted to reboot the PC in safe mode, but this doesn't work as immediately it jumps into the BSOD after selecting any of the safe mode options - although when I reboot in normal mode this is fine.

It seems like this is just one of the variants of the security tools virus...

A:Security Tool - PC infected, applications blocked and BSOD when trying to boot in safe mode - HELP!!

Primary MirrorSecondary MirrorSecondary MirrorRar Mirrors - Only if you know what a RAR is and can extract it.
Primary MirrorSecondary MirrorSecondary MirrorExtract RootRepeal.exe from the archive (If you did not use the "Direct Download" mirror).Open on your desktop.Click the tab.Click the button.Check all seven boxes: Push OkCheck the box for your main system drive (Usually C:), and press Ok.Allow RootRepeal to run a scan of your system. This may take so... Read more

1 more replies

I have an infected Dell laptop running Windows XP Pro SP3. On startup, it displays a System Shutdown pop-up with a one-minute timer and the message, "The system process C:\Windows\system32\services.exe terminated unexpectedly with status code -1073741482. The system will now shut down and restart."

When I booted it into Safe Mode, I found AVCare (which I removed). Spybot S&D also caught Monopod attempting to set a startup item in the registry (which I blocked). There's more garbage on the system, because it still reboots itself.

I booted it again into Safe Mode (logged in as Administrator) and tried installing SDFix and MBAM from a flash drive. I was able to install both of them, but they both crash when I run them. SDFix crashes right after I type "Y" to start the scan, and crashes explorer.exe along with it. I was able to start MBAM after installing, but it crashed as soon as I clicked "Start Scan", and I when I try to run it again I get the message, "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

Any help would be very much appreciated.