Tech Problem Aggregator

Infected? No internet, just in safe mode

Q: Infected? No internet, just in safe mode

I'm not able to use internet in regular mode of windows xp. If i restart in safe mode with network support I can access the internet.I have checked everything concerning driver issues etc. The ip is correctly assigned. I have done several scans wit MBAM, I've used registry cleaners, etc. It all started a couple weeks ago when the pc started working very slow. I did a disk cleanup, defragmented the harddisk, did registry cleans, scanned for viruses etc. It was a bit better but not too much. After a few days the internet stopped working on my pc.Is there any solution to fix this problem?Hereby the DDS.txt log:DDS (Ver_10-03-17.01) - NTFSx86 Run by Zjefne at 13:56:09,23 on vr 24/09/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.447.221 [GMT 2:00]AV: Panda Antivirus Pro 2010 *On-access scanning enabled* (Updated) {EEE2D94A-D4C1-421A-AB2C-2CE8FE51747A}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\system32\svchost.exe -k netsvcsC:\Program Files\Panda Security\Panda Antivirus Pro 2010\TPSrv.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\PROGRAM FILES\PANDA SECURITY\PANDA ANTIVIRUS PRO 2010\WebProxy.exesvchost.exesvchost.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\WINDOWS\system32\svchost -k PandaC:\WINDOWS\system32\svchost.exe -k hpdevmgmtC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\WINDOWS\Explorer.EXEC:\Program Files\LogMeIn\x86\RaMaint.exeC:\Program Files\LogMeIn\x86\LogMeIn.exeC:\Program Files\LogMeIn\x86\LMIGuardian.exeC:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdvserv.exeC:\WINDOWS\system32\lxdvcoms.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\Panda Security\Panda Antivirus Pro 2010\PsCtrls.exeC:\Program Files\Panda Security\Panda Antivirus Pro 2010\PavFnSvr.exeC:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exeC:\Program Files\Panda Security\Panda Antivirus Pro 2010\PsImSvc.exeC:\Program Files\Panda Security\Panda Antivirus Pro 2010\PskSvc.exeC:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exeC:\WINDOWS\system32\svchost.exe -k imgsvcC:\Program Files\Panda Security\Panda Antivirus Pro 2010\pavsrv51.exeC:\Program Files\Panda Security\Panda Antivirus Pro 2010\AVENGINE.EXEC:\Program Files\Panda Security\Panda Antivirus Pro 2010\APVXDWIN.EXEC:\Program Files\Babylon\Babylon-Pro\Babylon.exeC:\WINDOWS\system32\ctfmon.exeC:\Documents and Settings\ik\Bureaublad\dds.scr============== Pseudo HJT Report ===============uStart Page = hxxp://search.babylon.com/home?AF=7748uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8mWindow Title = Telenet InternetuInternet Connection Wizard,ShellNext = iexploreuSearchAssistant = hxxp://www.google.com/ieuSearchURL,(Default) = hxxp://www.google.com/search?q=%suURLSearchHooks: myBabylon English Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\mybabylon_english\tbmyB1.dllBHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dllBHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No FileBHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dllBHO: Windows Live Aanmelden - Help: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dllBHO: Babylon IE plugin: {9cfaccb6-2f3f-4177-94ea-0d2b72d384c1} - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dllBHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dllBHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dllBHO: myBabylon English Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\mybabylon_english\tbmyB1.dllBHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dllBHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dllBHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllTB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dllTB: myBabylon English Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\mybabylon_english\tbmyB1.dllTB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dllTB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No FileTB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No FileuRun: [ctfmon.exe] c:\windows\system32\ctfmon.exemRun: [APVXDWIN] "c:\program files\panda security\panda antivirus pro 2010\APVXDWIN.EXE" /smRun: [SCANINICIO] "c:\program files\panda security\panda antivirus pro 2010\Inicio.exe"mRun: [Babylon Client] c:\program files\babylon\babylon-pro\Babylon.exe -AutoStartIE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.htmlIE: Translate this web page with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htmIE: Translate with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Action.htmIE: {2D663D1A-8670-49D9-A1A5-4C56B4E14E84}IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exeIE: {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htmIE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exeIE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dllIE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLLDPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cabDPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cabDPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cabDPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/NL-BE/a-UNO1/GAME_UNO1.cabDPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cabDPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cabDPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cabDPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cabDPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabDPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cabDPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabDPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} - hxxp://update.hpphoto.com/download/HPSWUpdate.ocxDPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cabDPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cabHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLLNotify: avldr - avldr.dllNotify: LMIinit - LMIinit.dllNotify: mhdtmla - mhdtmla.dllSSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll============= SERVICES / DRIVERS ===============R0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [2010-6-11 28552]R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [2010-6-11 41144]R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-12-26 54752]R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k panda --> c:\windows\system32\svchost -k Panda [?]R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2007-5-19 12856]R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2007-5-19 47640]R2 lxdv_device;lxdv_device;c:\windows\system32\lxdvcoms.exe -service --> c:\windows\system32\lxdvcoms.exe -service [?]R2 lxdvCATSCustConnectService;lxdvCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdvserv.exe [2009-2-4 98984]R2 Panda Software Controller;Panda Software Controller;c:\program files\panda security\panda antivirus pro 2010\PsCtrlS.exe [2010-6-11 173312]R2 PAVDRV;pavdrv;c:\windows\system32\drivers\pavdrv51.sys [2010-6-11 84024]R2 PAVFNSVR;Panda Function Service;c:\program files\panda security\panda antivirus pro 2010\PavFnSvr.exe [2010-6-11 169216]R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [2010-6-11 163336]R2 PavPrSrv;Panda Process Protection Service;c:\program files\common files\panda security\pavshld\PavPrSrv.exe [2010-6-11 62768]R2 PAVSRV;Panda On-Access Anti-Malware Service;c:\program files\panda security\panda antivirus pro 2010\PAVSRV51.EXE [2010-6-11 291584]R2 PskSvcRetail;Panda PSK service;c:\program files\panda security\panda antivirus pro 2010\psksvc.exe [2010-6-11 28928]R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\pavtpk.sys --> c:\windows\system32\PavTPK.sys [?]S2 gupdate;Google Updateservice (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-7 135664]S3 23a5;23a5;\??\c:\windows\system32\23a5.sys --> c:\windows\system32\23a5.sys [?]S3 2d59;2d59;\??\c:\windows\system32\2d59.sys --> c:\windows\system32\2d59.sys [?]S3 432A;432A;\??\c:\windows\system32\432a.sys --> c:\windows\system32\432A.sys [?]S3 9f24;9f24;\??\c:\windows\system32\9f24.sys --> c:\windows\system32\9f24.sys [?]S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\adm8511.sys [2006-10-31 20160]S3 ATMEL FVNETusbASKEY (AR)®;ATMEL FVNETusbASKEY (AR)® Service for SANTIS WLAN USB Adapter;c:\windows\system32\drivers\vnetusbk.sys --> c:\windows\system32\drivers\vnetusbk.sys [?]S3 ATMEL WinXP PCMCIAFVNETR (2ARC)®;ATMEL WinXP PCMCIAFVNETR (2ARC)® Service for SANTIS WLAN PC Card;c:\windows\system32\drivers\fvnetr51.sys --> c:\windows\system32\drivers\fvnetr51.sys [?]S3 ced6;ced6;\??\c:\windows\system32\ced6.sys --> c:\windows\system32\ced6.sys [?]S3 f9f8;f9f8;\??\c:\windows\system32\f9f8.sys --> c:\windows\system32\f9f8.sys [?]S3 fsssvc;De service Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]S3 NETIMFLT01050097;PANDA NDIS IM Filter Miniport v1.5.0.97;c:\windows\system32\drivers\netimflt.sys --> c:\windows\system32\drivers\netimflt.sys [?]S4 LMIRfsClientNP;LMIRfsClientNP; [x]============== File Associations ===============JSEFile=c:\progra~1\pandas~1\pandaa~1\PAVSCRIP.EXE "%1" %*VBEFile=c:\progra~1\pandas~1\pandaa~1\PAVSCRIP.EXE "%1" %*VBSFile=c:\progra~1\pandas~1\pandaa~1\PAVSCRIP.EXE "%1" %*=============== Created Last 30 ================2010-09-24 11:55:39 0 ----a-w- c:\documents and settings\ik\defogger_reenable2010-09-23 18:54:16 0 d--h--w- c:\windows\$hf_mig$2010-09-23 18:43:05 0 d-----w- C:\found.0002010-09-23 10:31:10 0 d-----w- c:\documents and settings\ik\DoctorWeb2010-09-22 19:37:30 0 d-----w- c:\program files\ESET2010-09-22 16:38:13 0 d-sha-r- C:\cmdcons2010-09-21 17:36:35 39424 -c--a-w- c:\windows\system32\dllcache\grpconv.exe2010-09-21 17:36:35 39424 ----a-w- c:\windows\system32\grpconv.exe2010-09-21 17:01:35 77312 ----a-w- c:\windows\MBR.exe2010-09-21 17:01:29 256512 ----a-w- c:\windows\PEV.exe2010-09-21 17:01:29 161792 ----a-w- c:\windows\SWREG.exe2010-09-21 17:01:28 98816 ----a-w- c:\windows\sed.exe2010-09-20 18:20:23 0 d-----w- c:\docume~1\ik\applic~1\Malwarebytes2010-09-20 18:19:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2010-09-20 18:19:57 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes2010-09-20 18:19:56 20952 ----a-w- c:\windows\system32\drivers\mbam.sys2010-09-20 18:19:56 0 d-----w- c:\program files\Malwarebytes' Anti-Malware2010-09-20 17:54:45 0 d-----w- c:\docume~1\ik\applic~1\GlarySoft2010-09-20 17:51:55 0 d-----w- c:\program files\Glary Utilities2010-09-20 17:18:04 0 d--h--r- c:\documents and settings\ik\Onlangs geopend2010-09-14 07:20:34 0 d-----w- c:\windows\system32\fkuab.dll2010-09-09 07:17:04 751104 ----a-w- c:\windows\system32\dlo17.dll2010-08-26 19:59:05 112 ----a-w- c:\docume~1\alluse~1\applic~1\A62IU73B2.dat==================== Find3M ================================= FINISH: 13:56:46,29 ===============

A: Infected? No internet, just in safe mode

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.In order for me to see the status of the infection I will need a new set of logs to start with.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.DeFogger: Please download DeFogger to your desktop.Double click DeFogger to run the tool. The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will appear Click OKDeFogger may ask you to reboot the machine, if it does - click OKDo not re-enable these drivers until otherwise instructed.Download DDS:Please download DDS by sUBs from one of the links below and save it to your desktop:Download DDS and save it to your desktopLink1Link2Link3Please disable any anti-malware program that will block scripts from running before running DDS.Double-Click on dds.scr and a command window will appear. This is normal.Shortly after two logs will appear: DDS.txt Attach.txtA window will open instructing you save & post the logsSave the logs to a convenient place such as your desktopCopy the contents of both logs & post in your next replyScan With RKUnHookerPlease Download Rootkit Unhooker Save it to your desktop.Now double-click on RKUnhookerLE.exe to run it.Click the Report tab, then click Scan.Check (Tick) Drivers, Stealth,. Uncheck the rest. then Click OK.Wait till the scanner has finished and then click File, Save Report.Save the report somewhere where you can find it. Click Close.Copy the entire contents of the report and paste it in a reply here.Note** you may get this warning it is ok, just ignore"Rootkit Unhooker has detected a parasite inside itself!It is recommended to remove parasite, okay?"information and logs:In your next post I need the following1.logs from DDS2.log from RKUnHooker3.let me know of any problems you may have hadGringo

3 more replies
Answer Match 73.5%

A user came to me with a laptop that does not connect to the internet at all in normal mode. (Wired or wireless, DHCP or static IP, IPv4 or IPv6)
Connects to the network perfectly fine, but no internet connection.
Unless in safe mode then the internet works just fine. (which led me to think malware was the root of the problem)
Nothing else appears to be wrong/off; just lost internet connection.

disable/enable adapter... nothing
ipconfig /release /renew... nothing
ipconfig /dnsflush /dnsregister... nothing
Tried new drivers... nothing
reset winsock... nothing
Scanned with McAfee... Clean
Scanned with MBAM... Clean
rkill... clean
tdsskiller... clean
running a hjt now, but thought I would post here first and see if it may well be something else.

NOTE: If you think this should be posted in networking then let me know and i'll gladly create a new thread there. I will not post my HJT until recommended, and that will go into the appropriate thread

Thanks in advance for your help. I've been using this site for years, first time I couldn't find a fix and need to post.

A:Internet Connection In safe mode only. Am I infected?

Uninstall your antivirus and let us know if you can connect

1 more replies
Answer Match 71.82%

My PC has been infected with 'Internet Security' and i have followed all the steps on
http://www.bleepingcomputer.com/virus-removal/remove-internet-security-2012 but have not successfully got my computer back.

I located the virus files and rename to virus and virus2.

I then ran:
FixNCR.reg
tdsskiller.exe -> can't load driver -> does not find a rootkit infection
Malwarebytes anti-malware -> 38 days old version as i cannot access internet -> found and remove internet security (log attached)
Spyware doctor -> failed to set up due to lack of internet. starts automatically when booting up the PC.

they seem to have stopped 'internet Security' however i cannot connect to the internet, cannot enable mcafee, cannot boot on safemode (get blue screen saying i should check my computer for viruses or recent changes), cannot do system restore to a previous date. I suspect some sort of stubborn rootkit infection.

Please help me to remove this virus.

outputs from dds.txt:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by SanchezPrieto Family at 0:47:17 on 2012-02-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1425 [GMT 11:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k ... Read more

A:Infected with 'Internet Security' and unable to boot on any safe mode

Hello al345 and welcome to BC.

Sorry about the delay, do you still need help?

75 more replies
Answer Match 62.58%

Some photos and mail seen only SAFE mode - - but not regular mode in BOTH Internet explorer AND Firefox. Hi for some reason I am no longer able to look at Just SOME photos on web sites on this One Win7 computer, nor See my email in Yahoo main INBOX , , , unless I am in SAFE mode. Not sure how to tell what I did wrong or if missing dlls or other settings. But does work ok just in SAFE mode. However I also get the Blue screen of death once in a while. Below is what I got when doing the "hijack scan" Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:09:06 PM, on 4/23/2013 Platform: Unknown Windows (WinNT 6.01.3505 SP1) MSIE: Internet Explorer v10.0 (10.00.9200.16537) Boot mode: Normal Running processes: C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe C:\Program Files (x86)\ASUS\ASUS Instant On\AsInstantOn.exe C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe C:\Users\JIMMY\AppData\Local\Akamai\netsession_win.exe C:\Users\JIMMY\AppData\Roaming\SearchProtect\bin\cltmng.exe C:\Users\JIMMY\AppData\Local\Akamai\netsession_win.exe C:\UPS\WSTD\WSTDMessaging.exe C:\Program Files (x86)\ASUS\AI Manager\AsShellApplication.exe C:\Program Files\TRENDnet\TEW-641PC_TEW-643PI\WlanCU.exe C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe C:\UPS\WSTD\UPSNA1Msgr.exe C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe C:\Program Files (x86)\ControlCent... Read more

More replies
Answer Match 62.58%

PLEASE HELP!
My internet will not work in regular mode, only safe mode with networking. My trading platform works perfectly in regular mode so I know my connection is ok. I have done HijackThis and have come up with this report..

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:19:52 PM, on 10/10/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Big Wayne\Desktop\HijackThis.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Fil... Read more

A:[SOLVED] Internet explorer will not work in regular mode, only safe mode w/networking

Quote:





Originally Posted by wleger2981


PLEASE HELP!
My internet will not work in regular mode, only safe mode with networking. My Norton is out of date as well, but as soon as I get back up and running I will install a newer version..ANy help on this matter is greatly appreciated..




Please do not post your Hijack this logs here. Due to Forum Rules we cannot assist in malware removal here. Have you tried a different browser (Chrome, Firefox etc)? When you say IE only works in Safe Mode with Networking, Do you mean you boot the computer normally and use IE (safe mode) or are you booting the computer into Safe Mode with Networking? In other words you can't boot normally?
If you feel you are infected, please click on the Virus/Trojan link in my signature and post there for more help.

4 more replies
Answer Match 62.58%

Hi guys,

I am having this problem since couple of days, my wireless internet connection is working fine i can go in my messenger but i cant browse any websites at all in normal mode.. i tried piniging these websites it comes back fail. but it works totally fine in safe mode, pls pls help me out as I have to study for my exams.

Thanks guys
Sunny
 

A:My internet not working on normal mode but works fine in safe mode PLS HELP

10 more replies
Answer Match 62.58%

I have tried to run IE7 in normal mode and I always get a "The address is not valid" window. I have a good internet connection and Firefox works flawlessly. I do not have connection problems. If I ran IE7 in Safe Mode with Networking, I can bring up webpages with no problems. I thought that upgrading to IE8 would cure the problem but I am still getting the exact same problem. I have tried checking many things and have tried many suggestions that I have found through web searches but nothing works. Please help!

A:Internet Explorer will work in Safe Mode with Networking but not in normal mode

what firewall do you have

1 more replies
Answer Match 62.58%

Hello everyone,

I have a Dell Optiplex GX270 with a pentium 4 processor, yes I know, old, but it works. It is running on Windows XP Pro, version 2002 with service pack 3. I have cable internet connected to a Linksys WRT100 router. As of late, my computer has been acting a little funny. I cannot seem to browse the internet for more than 5 minutes (with either Firefox 3 or IE 8) in normal mode, but the computer shows that I am connected to the internet. I was connected via a usb wireless adaptor, but since it has been acting strange, I have removed the wireless adaptor with the software and am now connected through an ethernet cord to the router which is connected to the cable modem.

The internet works fine in safe mode with networking though. Plus, in normal mode, I am able to update services such as McAfee virus scan and Spybot, as well as remote connect to another computer, which require internet although the internet browsers say that it is not connected. I have ran Spybot, Ad-Aware, and McAfee virus scan already as well, all have not found anything. My roommate's laptop is able to connect to the network, via ethernet and wireless adapter, thus I do not believe it is either the router or modem. In device manager, my network adaptor icons did not show either an "x" or "!" icon. I have tried "WinsockxpFix" but that does not seem to solve my problem. I have tried going into "msconfig" to disable all of the "startup" pro... Read more

A:Internet only works in safe mode or for short time normal mode

10 more replies
Answer Match 62.58%

When I open IE it just stays as a blank screen a warning use to appear saying something about an appcrash but I messed around with it reset the settings. Also system restore wont work neither will a recovery, Im really in need of some help here.

A:Help Internet explorer wont work in normal mode, only in safe mode Windows Vista

Please post the exact warning. It should mention a particular App.

11 more replies
Answer Match 62.58%

I just did a clean re-install of Vista x64 on a new hard drive (old drive crashed). Here's the problem:

Using my ISP (Roadrunner Carolinas) speed test site; I get around 200 to 400 kbps download speeds using IE in normal mode. If I boot to Safe Mode, I get around 3500 to 4500 kbps, which is what it should be (this is what I used to get in normal mode before I re-installed Vista).

Running the same speed test with Firefox, I get around 1500 to 2000 kbps in normal mode, but if I try to download a file it transfers at only the 200 to 400 kbsp rate (if I'm lucky).

Here's more detail about the system and what I've done so far:

Installed all updates including SP2.
Using Windows Firewall, no anti-virus.
Updated network drivers directly from NVidia (Chipset is nForce750i)
Updated graphics card drivers directly from NVidia
Disabled all LAN protocols except for Client for Microsoft Networks and IPv4
Connected via ethernet cable directly to cable modem, no router.
I've deliberately refrained from loading anything but the basics until I can get this sorted out.

This really the second clean install I've done in 24 hrs. After the first one, I upgraded and added a lot of software and add-ons before I figured out the connection problem; so I decided the easiest fix would be to re-format and start over, checking each step to see what caused the slow-down. Unfortunately once I did the second clean install I tested right away and I had the connection problem from the get-go. Since then... Read more

A:Vista x64 new install: Slow internet connection in normal mode; fast in safe mode

run msconfig and uncheck startups that you are POSITIVE are safe to do so. See if your speed picks up. Then allow one startup at a time.

MSCONFIG: speeding up Windows Vista startup

7 more replies
Answer Match 62.16%

Hi guys, I'm new to the forum and really hoping you can help me :)

My internet has not been working on my laptop, which happened very suddenly 2-3 days ago. The connection is fine on my other computer and phone, so I know its not the internet itself. Even on the laptop, it SAYS the wifi is connected, but its not working. Firefox was instantly crashing, it wouldn't even bring up the browser window. Chrome gives me a "DNS address not found" error for every site I try and IE wont load anything.

I've tried flushing my DNS, using that ipconfig /refresh and /renew thing. I've tried troubleshooting the wifi connection, disabling/enabling it. I ran a Malware Bytes scan and only found a couple of "pup" programs/cookies that have been deleted. Currently running a SuperAntiSpyware scan.

The thing is, I tried using the internet in Safe Mode with Networking and it works just fine! So that means a program or something on my computer is causing it, right? There were issues with my Teredo Tunneling Psuedo-Interface driver the other day, it had a yellow triangle with an exclamation mark, but I did a couple of fixes that I found on help sites and that exclamation is gone now.

Please help, I really want to use my laptop on the internet again ;_;

Oh, and the specs for my comp are:
Lenovo Win7 PC
Intel(R) Core(TM) i5-2410M CPU @ 2.30 GHz
RAM: 6 GB
Windows 7 - 64 bit operating system

A:Internet works in safe mode w/ networking but not normal mode

In Network and Sharing Center, there is a wizard to troubleshoot connection problems. If that doesn't work, you could "set up a new connection".

3 more replies
Answer Match 62.16%

Below is my DDS log. Attached is my attach file. Even in safe mode, my internet explorer and firefox seem to be hijacked and taking me to different sites.

DDS (Ver_09-03-16.01) - NTFSx86 NETWORK
Run by Donald Ford at 11:29:46.42 on Tue 04/28/2009
Internet Explorer: 8.0.6001.18702
Microsoft? Windows Vista? Home Premium 6.0.6001.1.1252.1.1033.18.1982.1396 [GMT -4:00]

AV: Rising Internet Security *On-access scanning enabled* (Outdated)
FW: Rising Internet Security *enabled*

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Windows\Explorer.EXE
C: ... Read more

A:Internet only in safe mode and normal mode won't run antispyware programs

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the resul... Read more

2 more replies
Answer Match 62.16%

I am new to this forum. I have dell inspiron N5110 laptop that started acting up about a month ago. Internet works sometimes in normal mode. Works in safe mode every time. Have tried everything suggested on web to get working. Restored to factory defaults, tried removed and reinstalled drivers. Any help would be appreciated. Running in safe mode now.

A:[SOLVED] internet works in safe mode but not normal mode

I'd guess you have some kind of malware on your computer, have you run a virus scan? I'd followup with something like malwarebytes.

10 more replies
Answer Match 62.16%

Hi! I'm just a new here, hope someone can help and give advice here. (Sorry if this is not the right thread to start my topic)

Scenario: (this is my first time to encounter this problem)

While playing facebook games last monday, my computer get BSOD and restarts. After booting up on windows, I found out that my internet connection was gone.I tried to restart but still no connection. I use my laptop and other PC to checked if there's internet and yes they are still connected. I restart my pc again and found out after boot up a message box appear says "No AMD graphics driver is installed, or the AMD driver is not functioning properly. Please install the AMD driver appropriate for your amd hardware"

I did uninstall / install my driver but the message box still prompting after restart.
Still no internet connection.

Anyone experience this?
Sorry for my bad english.

Specs:
Intel i3 2120
Asrock H61 U3S3
Sapphire 7770 OC Edition
500 WD Blue
4GB Geil DDR3 1333mhz
550w Hec Cougar 80

A:No internet in normal mode but works in safe mode with networking

The first thing i would do is stay in safe mode and run a virus scan.

-edit-
Also check for a system restore point.

Use your Install DVD. When on the install now screen choose repair in the left side of screen. Select your OS. Then When at the GUI select system restore. Choose a date before all this happened.

9 more replies
Answer Match 62.16%

I am new to this forum. I have dell inspiron N5110 laptop that started acting up about a month ago. Internet works sometimes in normal mode. Works in safe mode every time. Have tried everything suggested on web to get working. Restored to factory defaults, tried removed and reinstalled drivers. Any help would be appreciated. Running in safe mode now.
Some background:
Wireless issue, have wired to router with no internet problem.
ISP is Comcast
Cable wireless gateway is a Xfinity Arris TC8305C
Came with McAffee which I removed. Was using Malwarebytes and Spybot search and destroy. Removed them only using Microsoft essentials. Have tried turning off firewall and essentials.
Kids have PC and Xbox wired to router. Also have another laptop and wireless XBOX connections, all with no problems.
Sys info: Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz, Intel64 Family 6 Model 42 Stepping 7
Processor Count: 4
RAM: 4003 Mb
Graphics Card: Intel(R) HD Graphics 3000, 1809 Mb
Hard Drives: C: Total - 461838 MB, Free - 408628 MB;
Motherboard: Dell Inc., 02KWJK
Antivirus: Microsoft Security Essentials, Updated and Enabled
 

A:Solved: internet works in safe mode but not normal mode

16 more replies
Answer Match 62.16%

Hi,

My Internet is not working in normal but works fine in Safe mode. This weird thing started 2 months back and it's continuing. Its really frustrating. Could some body please help me...

I have followed the 5 steps that were mentioned ..

1) I have Installed AVG recently.

2) Run an Online scan
Could Not complete as I am unable to connect to Internet in Normal mode. I am able to connect Internet in Safe Mode Only.
Unable to run Panda Active Scan in Safe mode.

Step 3) Installing Immediate Protection
Installed Spy Blaster.
Installed IESPYPAD.
Step 4) Update your Operating System
I am on Microsoft XP Home SP2 and IE7.

Step 5) The log files

Deckard's System Scanner v20071014.68
Run by murthy on 2008-08-29 22:03:21
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- HijackThis (run as murthy.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:42 PM, on 8/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\sy... Read more

A:Internet working Safe mode not works in normal mode

Bump Please.
 

1 more replies
Answer Match 62.16%

Hi all, my laptop has been acting crazy the past couple of days. First of all, I was watching a movie on it and it just shut down. when I tried restarting it in normal mode i would get to the welcome symbol after what seemed an eternity of loading, but then the screen just went black. when I opened in safe mode with networking, everything was fine. So then I went to msconfig and unchecked the two items i was allowed to. rebooted the system and I could get into normal mode again.

So the problem now is that normal mode is acting like safe mode meaning that the bottom toolbar looks the same as in safe mode as well as any of the other open windows. also, after i tried restarting it again, i get this dialogue when I try to connect to my wifi " the dependency service or group failed to start.".

thanks for any help.

A:normal mode acting like safe mode and now internet not working

also, other hardware is not working such as audio and printers.

3 more replies
Answer Match 62.16%

Hi, this is my first post on SevenForums.

My internet speed is really slow. I'm lucky if I can reach 1Mbps when I start up Normally. However, when I start up in Safe Mode with Networking I can reach 12Mbps.

The computer is fairly old (8/9 years old maybe) and I've only just upgraded from XP to Windows 7 Ultimate 32bit. When I was running XP I connected to my router using a Linksys USB wireless network adapter. After upgrading to Windows 7 I couldn't use the Linksys anymore as I couldn't find any drivers so I installed a Belkin Desktop PCI Card F5D5000. I managed to connect to the internet straight away and this is when I first noticed the slow speed. I've updated the drivers directly from the Belkin site but it hasn't improved the speed .

I've tried connecting to the same router using WiFi on a laptop and the internet speed is fine (14Mbps). I contacted my ISP Talk Talk and asked them to test the connection but they didn't find any faults with either the line or hardware.

I've also tried switching off my Anti-Virus program but this doesn't make a difference either.

Could anything else be slowing the internet down? Any ideas would greatly appreciated.

Dave

A:Very slow internet in normal mode but fast in Safe mode

Hi Dave, and welcome to SevenForums!

I'm not an expert in this area but I suggest you try a Clean Boot as next step. You disable all non-MS services and reboot. If that works you can enable one service at a time to find out if it's a specific service that is causing the slow Internet.
How to perform a clean boot in Windows
Clean Boot assumes the problem is not with Windows itself but a 3rd party product or conflict, while Safe Mode loads minimum necessary drivers etc and without any start up programs.

It could also be caused by malware, that in Safe Mode isn't allowed to start during normal autostart procedures. So scan with a couple of good antivirus/antimalware products, for example Malwarebytes | Free Anti-Malware & Internet Security Software

8 more replies
Answer Match 61.74%

My computer wouldn't boot past advanced options menu for a quite a while. So I was messing around in safe mode running anti virus software an it booted normally finally . But after that I went into add/remove programs and got rid of some stuff and I'm not sure if the internet was working before I did that because I did it right when the computer booted up again. However it does work in safe mode
 

A:Internet working in safe mode but not normal mode

do a tcp/ip reset

What firewall / security suite or anti-virus do you currently have on the PC - or you have ever had on the PC in the past - any trial ware - like Norton, kaspersky or Mcafee or any free security suites like zonealarm, AVG , Webroot etc
------------------------------------------------------------------------

TCP/IP stack repair options for use with Vista, Windows 7, Windows 8/8.1 and Windows 10

For Windows Vista through to Windows 10
Start> Programs> Accessories> and right click on Command Prompt, select "Run as Administrator" to open a command prompt box
(A new dialogue box - black with white font, will appear on the screen )​
For Windows 8 & 10
To open a Cmd Prompt or an Administrator Cmd prompt from the Desktop. Use Windows + X Keys together and choose Command Prompt (Admin) from the list.
Or Right click on the windows icon - bottom left hand side - A menuu appears - choose Command Prompt (Admin)​
In the command prompt window that opens, type the following commands:

Note: Type only the text in bold and red for the following commands.
Reset WINSOCK entries to installation defaults: netsh winsock reset catalog and press enter

Reset IPv4 TCP/IP stack to installation defaults. netsh int ipv4 reset reset.log and press enter

Reset IPv6 TCP/IP stack to installation defaults. netsh int ipv6 reset reset.log and press enter
​ReStart (reboot) the machine.

If you receive the message
The requested operation requir... Read more

14 more replies
Answer Match 61.74%

I had some viruses on my computer and I had to remove them with McAfee and Malwarebytes. I have run scans since then, and it is saying that it doesn't find anything, but I still can't browse. HELP!Mod Edit: Topic moved from HJT to more appropriate forum~ TMacK

A:Can't browse the internet in normal mode, but can in safe mode

Hello and welcome to Bleeping Computer.Please subscribe to your topic so that you will be notified as soon as I post a reply, instead of you having to check the topic all of the time. This will allow you to get an email notification when I reply.To subscribe, go to your topic, and at the top right hand corner by your first post, click the Options button and then click Track this topic. The bullet the immediate notification bubble. Then press submit.Lets take a look with Malwarebytes (just another time with an updated version, i am aware that you have run it before)Please download Malwarebytes' Anti-Malware from here:MalwarebytesPlease rename the file BEFORE downloading to zztoy.exe instead of mbam-setup.exeMBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.Double Click zztoy.exe to install the application.* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.* If an update is found, it will download and install the latest version.* Once the program has loaded, select "Perform Full Scan", then click Scan.* The scan may take some time to finish,so please be patient.* When the scan is complete, click OK, then Show Results to view the results.* Make sure that everything is checked, and clic... Read more

10 more replies
Answer Match 61.74%

I'm using windows 7 64-bit operating system with internet explorer 11, and Firefox. I can use my browsers while in safe mode to upload / download information. However, after starting windows normally the browsers no longer work, that is, when I start IE I get the "This page cannot be displayed" message even though the url is microsoft.com and Firefox give me the Mozilla Crash Reporter form. I've checked the internet connection in network and sharing and see the connection is made; also when I run MS Security Essentials it gets the current updates. So it seems that it is just a browser issue. Thought someone might have an idea of how I can get my browsers working again.

More replies
Answer Match 61.74%

I have tried the following:

No proxy server is being used (box is unchecked)

All of the drivers appear to be working fine

I have run Hitman, Superantispyware and Malwarebytes (in safe mode). They each detected different problems.

Any other ideas before I take this to the computer shop?

A:Internet working in safe mode but not normal mode

try adwcleaner its free
https://toolslib.net/downloads/finish/1/

also resetting ie maybe help

1 more replies
Answer Match 61.74%

My internet wont work unless I'm in 'Safe Mode With Network Support'. This just started 2 days. All other computers on my network are fine, except this one. Can anyone suggest anything?

I'm running Windows XP.

I've done countless virus scans and adware scans.

I got frustrated last time with hijack this, so I just checked off everything and clicked "Fix". That didnt work.

I managed to fix some things in the Event Viewer. Now I get Event 7031 and that is the only error I receive. Details -
"The Workstation Service Library service terminated unexpectedly. It has done this 397 time(s). The following corrective action will be taken in 3000 milliseconds: Restart the service.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp."
One time I thought I had it fixed, but like 10 min later it went back into safe mode.

Ran something called Win Sock XP fix which basically restored tcp/ip settings but that didnt work. That was a temporary fix. NOw I'm stuck without a clue.

Ran symantec a few times. Found a few viruses, but they got deleted quickly. Here's a list of viruses they found and fixed.

userint32.exe virus name W32.Allim
rdriv.sys virus name Trojan Horse
msaccrt.exe virus name W32.Allim
lanmany.exe virus name Backdoor.Staprew.B
aight.exe virus name Backdoor.Trojan

Does anyone have any reccommendations? Re-formatting isnt really an option.
 

A:internet works in safe mode... not in normal mode :(

11 more replies
Answer Match 61.74%

Hi all,

I've had this problem since yesterday (5/25/15) and haven't managed to find a fix for it yet. The issue is that although I have internet access--and Google even boots up how it normally would--I am unable to access websites. I am able to search perfectly fine, but the connections "time out" and do not connect. When I decided to troubleshoot, I received "-website name- is online, but network is unable to connect". I am still able to access the internet on my phone and other devices.

Thank you for any and all help!

UPDATE: I now am unable to view the Google homepage on startup with Google Chrome.
 

A:Able to access internet in Safe Mode, not normal mode

Welcome aboard

Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
Attached logs won't be reviewed.

Please, observe following rules:

Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
If you're stuck, or you're not sure about certain step, always ask before doing anything else.
Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
Never run more than one scan at a time.
Keep updating me regarding your computer behavior, good, or bad.
The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

 

33 more replies
Answer Match 61.74%

I'm unable to browse the internet in normal mode, I've made a post in the "Am I infected? What do I do?" section, but I still have no luck. I've tried alot of things to fix this problem, it's all in http://www.bleepingcomputer.com/forums/t/188811/able-to-browse-in-safe-mode-but-not-in-normal-mode/? This is the HiJackThis.log in normal mode,Logfile of Trend Micro HijackThis v2.0.2Scan saved at 20:32:44, on 2008/12/30Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exec:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exeC:\Program Files\Logitech\QuickCam10\QuickCam10.exeC:\Program Files\Windows Live\Messenger\MsnMsgr.ExeC:\Program Files\BitComet\BitComet.exeC:\Program Files\TaskSwitchXP\TaskSwitchXP.exeC:\Program Files\DAEMON Tools Lite\daemon.exeC:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exeC:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exeC:\Program Files\Or... Read more

A:Able to browse internet in safe mode, but not in normal mode

Welcome to the BleepingComputer Forums. Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again. Double click on RSIT.exe to run RSIT. Click Continue at the disclaimer screen. Please post the contents of log.txt. Thank you for your patience.Please see Preparation Guide for use before posting about your potential Malware problem. If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped. While we are working on your HijackThis log, please: Reply to this thread; do not start another! Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so. Do not run any other tool until instructed to do so! Let me know if any of the links do not work or if any of the tools do not work. Tell me about problems or symptoms that occur during the fix. Do not run any other programs or open any other windows while doing a fix. Ask any questions that you have regarding the fix(es... Read more

2 more replies
Answer Match 61.74%

I have a two laptop a dell inspiron core i5 and an asus laptop. I have a problem on my dell laptop, it is having a hard time connecting to the internet. I have the right ssid and password but it takes too long/slow to connect compare to the asus laptop.
I recently found out that my connection works well when I put it into the safe mode with network option and it doesn't work well with normal mode.
I read that using 'hijack this' would help solve the problem, but I don't know how to use nor analyze it.
Any help is very much appreciated. Thanks!
Here's the copy of the 'hijack this'
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:39:22 PM, on 6/25/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe
C:\Windows\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Mozilla Firefox\pl... Read more

More replies
Answer Match 61.74%

Hello,

I'm running a Gateway NV Series and as of last night I have fallen victim to the problem that Windows 7 seems to be plagued with. My internet has completely stopped working, both Ethernet and Wireless. I have tried many of the fixes suggested in this forum and others, but none of them have worked. So I booted into safe mode with networking and low and behold, the wireless and Ethernet work just fine here.

Why is this?

I don't like to run the internet on safe mode, and I would to have my computer back working at normal capacity. How can I fix this?

Specs on my laptop are here:
Gateway - Laptop with AMD Athlon™ X2 Dual-Core Processor - NightSky Black - NV5211u

A:No Internet in Normal Mode; Works in Safe Mode

Hi and Welcome to SF.

Your safe mode loads up with the bare essentials to get things working. Using builtin drivers i would think and no third party softwares. If your safe mode don't work, more than likely u have a system/hardware issue.

As for your normal mode, go into Device Manager, any noticable issues?

9 more replies
Answer Match 61.74%

when i turn my computer on im not able to get on the internet, or access my networking in the control panel. If i go in to safemode with networking i can access the net no problem, just cant figure out why it runs super slow and i cant access the net in regular mode.
 

A:my internet is not working in regular mode only in safe mode

something is blocking in normal mode - it could be firewall/security suite

what firewall/security suite do you have ?

moved to networking forum
 

3 more replies
Answer Match 61.74%

Hey all, I have a massive problem with my internet connection, but first..the backstory..

I got a piece of malware through a bad download (i believe) which gave me Antivirus system PRO, I'm sure some of you have heard of it. It hijacked my comp, wouldn't let me open any programs, the internet, etc. Real nasty.

I went through safe mode and took it out manually, I believe I got it all, and now, everything in normal mode seems to be working okay, except the internet.

I have full connectivity while in normal mode, strong signal. However, IE will not open up any web page, RSS feeds arn't coming in, etc. HOWEVER, in safe mode, IE is a beauty..works just fine, any page quickly and easily.

I've tried a few things thus far,

ipconfig comes back as media "disconnected"
tried sfc scannow, didn't help anything.
tried netsh winsock reset, and another netsh command, can't remember which one...nadda.
ipconfig refresh and renew didn't work, probably because everything is disconnected

I'm out of ideas! Anyone, please help if you can! I'm a student going into finals, and things arn't looking too hot not having my comp in good form.

Thank you for reading, and I would appreciate any kind of help. I've visited this site before, I know you guys are good!
 

A:Solved: No Internet is Normal Mode, ONLY in Safe Mode!

10 more replies
Answer Match 61.74%

I am a complete novice when it comes to computers, i know basics but am struggling to get my computer up and running properly. I have a really fast broadband with virgin media but this only works properly on safe mode. whilst in normal mode it comes on and off and takes a long time to load each page. I have heard of HIJACK THIS and downloaded it but am unable to read the log files ect to see what should and shouldnt be there and need help to find out how to find and solve my problem. all i ask is for a little patience as this a new learning experience for myself. hope someone can help.

A:internet only working normally in safe mode and on/off in normal mode.....HELP!

Is your internet the only slow thing or is it your whole computer?If your computer works OK and its just the internet that's slow, run and post a MiniToolbox log as This Topic says to do.If your whole PC is slow/unresponsive, it may be best to start a topic in the Am I Infected? forum.

3 more replies
Answer Match 61.74%

Hello,

I have windows xp and recently had a virus along with some adwares (PCDefender). Anyways, I was able to remove the virus by using "malwarebytes" by running it the safe mode/w netowking. After I ran the full scan and rebooted in the normal mode, I was unable to use the internet; so I call up my ISP (verizon) and they help me check my connectin in ms dos by using ip config and cpl other thgs not sure but I was able get connection.

I was able to connect the internet in the safe mode but coundn't in normal mode. Please help.

thx

A:Internet access in Safe mode\not in Normal Mode

Hello and welcome to TSF

We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

---------------------------------------------------------------------------------------------

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please start a new thread in our Virus/Trojan/Spyware forum along with the required logs

1 more replies
Answer Match 60.48%

I NEED HELP WITH THIS.  I HAVE DONE ALL I KNOW.  I RAN RUNSCANNER WITH HIJACKTHIS AND DO NOT UNDERSTAND THE OUTCOME.  PLEASE ADVISE.  THANKS.  PIA

A:NO INTERNET IN NORMAL MODE BUT HAS IT IN SAFE MODE

On 1 Apr...you initiated the following malware topic, http://www.bleepingcomputer.com/forums/t/448436/non-responses-from-computer/ .
 
Due to failure by you to respond, the topic was closed a week ago.
 
Do you want that topic reopened?  No one in the Win 7 Forum can assist you with malware issues.
 
Louis

1 more replies
Answer Match 60.48%

why?!?!? i tryed a lot of stuff but nothing ever works

A:why can i go on the internet in safe mode but not in regular mode?!?!?!?

You might be experiencing a sever infection or a system corruption ( the files that dont run in safe mode but real mode might have been corrupted such as drivers ) but these are all assumptions right now. Please get into safe mode with networking. Click on greyknights link below and follow the instructions for a malware clean-up. Get a hjt log and post it under hjt log help forum. Lets see what happens. Let us know.

regards.

5 more replies
Answer Match 60.48%

I found bleepingcomputer.com in trying to find a fix for the Security Suite malware. I followed the instructions, and ran malwarebytes. The malware is gone, but now I have another problem: I cannot connect to the internet while running Windows in normal mode. I have tried to run it in safe mode with networking, and the connection works fine.

I also have another problem with random crashes and a BSOD (which I cannot fix nor find a cause for).

Please help! I appreciate any input.

Thanks!

A:internet in safe mode vs. normal mode

are you sure the virus is gone? Run a antivirus and let it fully scan. It sounds like one of the processes is causing this. It might be causing the BSOD as well. You could also try to do a system restore if you have a restore point from before the problem started

Run avg free antivirus or avira free antivirus and if they dont pick up anything try spybot. I cant believe that the malware is completely gone and the connection not work while it is working in safe mode.

3 more replies
Answer Match 60.48%

Alright so I am working with my brother and on his computer he got a new modem and ever since he can surf the internet in safe mode but cannot browse the internet in regular mode. However in regular mode he can run windows update. Tried winsock, there are no proxy settings in IE 8, reset IE 8, /flushdns, disabled all services in msconfig and still nothing in regular mode. Had Norton but uninstalled it and ran norton removal tool to no avail...Any ideas?

More replies
Answer Match 60.48%

Hope someone can help me out and I'm in the right section.
Runs great in safe mode.
Running Vista Ultimate
IE 8

Cable modem.
speedtest.net
Download 4.64 Mb/s
Upload 1.32 Mb/s
Ping 70

Avira anti-virus
Defender disabled.

I tried removing 3rd party software in startup but that was no help.
Ran Spybot S&D. It's clean. Had a couple of tracking cookies.

Ran Hijackthis. There are 3 items in there that I've uninstalled some time ago but I'm unable to remove from the log.
Acronis
Avg
Comodo

HT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:42:36 PM, on 4/21/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://overview.mail.yahoo.com/products/classic
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\... Read more

More replies
Answer Match 60.48%

Hi,My Computer which has Win Xp Sp3 is behaving like it is in safe mode , eventhough it is in normal mode .I noticed this because ,1. Avira Antivir Guard and Update cannot be launched bcz Scheduler is not running.2 . I tried to start scheduler ( under services.msc ) , but can't start it bcz of error 1084 ( safe mode situation ) .3 . I can't use Windows Update , bcz of error Error number: 0x8007043C ( same safe mode condition )4 . I ensured that BITS was set to automatic , but it can't run bcz of 1084 error.I have scanned with Malwarebytes, Spybot S&D , SuperAnti Spyware ( in real safe mode) - No DetectionHere is the dds log ,DDS (Ver_09-09-24.01) - NTFSx86 NETWORK Run by Administrator at 16:45:23.03 on Mon 09/28/2009Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_12Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.112 [GMT 5.5:30]AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}FW: ZoneAlarm Security Suite Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\system32\svchost.exe -k netsvcsC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Avira\AntiVir Desktop�... Read more

A:Safe Mode Error, WinXpSp3 behaves like it is in safe mode even in normal mode

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies
Answer Match 59.64%

I have an infection in my DropBox.
I am hoping i disconnected before it got to my local box, but cannot tell because, I logged off/shutdown the system.
Windows 7, booting up, trying to go into Safe Mode, with networking.
As soon as it comes up, I try to log in (Still disconnected from the network, and it reboots the system.
Is this something new, or maybe unrelated?

A:Lucky Infected and No Safe Mode now?

Welcome to BC...
 
This is the second time this week that someone has posted not being able to boot into safe mode. Please
start a new topic in the Malware Removal forum and let the pros see if it is a new malware or just a coincidence.
 
Please follow the instructions in the Malware Removal and Log Section Preparation Guide starting at Step 6.
If you cannot complete a step, then skip it and continue with the next.
In Step 6 there are instructions for downloading and running FRST which will create two logs.
When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.
After doing this, please reply back in this thread with a link to the new topic so we can close this one.
 
DO NOT bump your new topic. Wait for a response from one of the Team Members.

1 more replies
Answer Match 59.64%

I would be very grateful for some help sorting out a friend's PC please.

I've read the First Steps page but cannot carry out all of the suggested scans.

When I boot the PC normally, it works very slowly loading XP Home, then suddenly reboots itself before getting to the login screen. I discovered that it will run in Safe Mode with Networking and I'm using it now to create this thread!

I've run dds.scr and the scan result is pasted below. (Attach.txt is included here in a zipped file). When I try to run GMER nothing happens. The egg timer appears for a few seconds but nothing more. I have downloaded SPTDinst-v162-x86.exe. Executing this file results in a popup stating "No SPTD version was detected". The Uninstall button was greyed-out but the Install button looked inviting, so I clicked it and was prompted to re-start Windows. I restarted XP in Safe Mode and it appeared to load SPTD.sys.

Before looking at this forum I was going to attempt a Windows re-install and backed up My Documents onto a USB memory stick, which I then scanned with Avira on a another laptop. This revealed 16 music files, which had been downloaded with Limewire (I presume), all containing the same virus - EXP/ASF.GetCodec.Gen. I've uninstalled LimeWire now.

I have tried to install Avira AntiVir Personal (in Safe Mode) but, after extracting a load of files to a Temp folder, it gets part way through 'Preparing Installation...' then crashes(?).

I don't know what to try n... Read more

A:Infected PC only works in Safe mode - Help please

Please close this thread - I have wiped the system and re-installed XP. It seemed like the smartest thing to do...

1 more replies
Answer Match 59.64%

I have Wxp Pro on a Dell pc. I get no pop-ups, but programs are slow to open and slow to run. I can't start the pc in safe mode by using F2, F8, F12, etc. When those keys are used, the pc ignores it and starts normally.
When a browser window is open, I can open a site, can scroll thru the site, but can't click on any links or buttons. It acts as if it is just a graphic.
One strange thing, if I minimize the browser window, then maximize it again, I can then surf inside the site.

I have run Ccleaner and Ada-ware. I then ran Rkill, then SuperAnti-spyware and Malwarebytes. Running a full scan on both. SuperAnti found 53 items, quarantined all, but no help. Malware did not find any issues.
I've tried a system restore, but keep getting "can't restore system.......".

Any fast help is appreciated, this is for a school secretary's pc.
Phil

A:Am I infected? Can't start Wxp in safe mode

Welcome aboard Download Security Check from HERE, and save it to your Desktop. * Double-click SecurityCheck.exe * Follow the onscreen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt; please post the contents of that document.=============================================================================Please download MiniToolBox and run it.Checkmark following boxes:Report IE Proxy SettingsReport FF Proxy SettingsList content of HostsList IP configurationList last 10 Event Viewer logList Users, Partitions and Memory sizeClick Go and post the result.=============================================================================Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform quick scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here.Be sure to restart the computer.The log can also be found here:C... Read more

9 more replies
Answer Match 59.64%

Hi, last fri I received an email via my yahoo account from UPS ( which I now now is not). I think this is a nasty virus has worms too.Avira scanned the file before I unzipped it, I did not get any warning, even though I had updated avira files before, then it went spirling downhill!!I had so many windows opening up, I immediately disconnected from the net then proceded to virus scan with Avira. At the end of the scan, it could not help as it was infected. I could not open the report, even though there were warnings.I tried Spybot scan which found a majority of problems which I allowed the fix. I did not think it wise to go on the net as I kept getting Internet Explorer pages opening up.All during this time I was getting Norton virus updates and warnings - I dont have nortons so ignored them and did not open any of the files. Just closed at the X them and made sure i was disconnected from net.After spybot cleaned up, I used ATF to clean my temp files and then turned off and re-started.Since then I can not log on to windows, even in safe mode and adminstrator. I tried and logging on a number of times in a variety of ways but it keeps logging me out. I am not getting past the log on page.I cannot seem to get into windows and think I must have messed up somewhere. I have my external drive plugged in and was about to back up my monthly documents but decided to reply to my emails before! Hence now cannot access anything. I have spent the weekend reading forums and page... Read more

A:infected with UPS virus. Cannot log on even in safe mode

I tried ... logging on a number of times in a variety of ways but it keeps logging me out. I am not getting past the log on page.I have spent the weekend reading forums and pages and pages of advise. I read this forum thread as well as thread: http://thinkinginpixels.com/quick-fixes/fi...onlog-off-loop/I really need my documents and cannot afford to loose them as there are files I need to send to my mortgage lender asap.mandyRe: LogOn/LogOff LoopGo ahead with the thinkinginpixels instructions: That is your best chance to get back in to Windows. It will take several hours to complete, and you should then be able to use Windows and retrieve the documents that you need. The instructions provide a series of logical steps that are relatively easy to follow and should lead to a positive result. Any problems, let us knowShould that fail (unlikely) we can help you get those documents by another means.Let us know how you are getting on.'Alien

81 more replies
Answer Match 59.64%

Microsoft did a scan in safe mode, but my computer is still running slow. i cant figure it out. i have one care as my anti virus, and malware bytes. i've ran both and nothing is showing up, any suggs would be greatly appreated.

thanks,
Lindaga35

A:am i still infected? scanned in safe mode already

Please reboot your computer and update Malwarebytes. This time do a FULL scan and post the new log here

5 more replies
Answer Match 59.64%

I am trying to fix my father's desktop computer, which he seems to have sufficiently filled with Malware. I am having a very hard time dealing with this, and am hoping for some help. Here are some of the things I know so far: It is a Dell running XP. Currently, I cannot run task manager, either in normal or safe mode. I cannot install Hijack This, MalwareBytes, or any other program in an effort to remove anything. Some of the names I have run across are "AntiMalware Doctor", "Security Tool", as well as the "Microsoft Security Essentials Alert" (particularly when I try to run taskmgr or regedit in the normal mode). I have been able to access regedit when in Safe Mode with Command Prompt... That is as far as I have gotten. I found some junk that seems to be related, but each restart brings me the same "Microsoft Security Essentials Alert" when I reboot and try for the taskmanager. As I can't seem to run anything on the desktop, I am using my laptop to try to download any potentially useful programs and move them over with a jump drive, but nothing will load. Any thoughts or recommendations would be greatly appreciated!!!!!!!I was just able to run TDSS Killer in Safe Mode from the Command Prompt, which appeared to be successful. Here is the log... I hope I copied it in right, as it appears huge! TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:442010/09/25 10:48:32.0734 ===============... Read more

A:Computer infected can't even run in Safe Mode!

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. Please include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.We need to create an OTL ReportPlease download OTL from one of the following mirrors:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.In the custom scan box paste the following:CODEmsconfigsafebootminimalactivexdrivers32netsvcs%SYSTEMDRIVE%\*.exe/md5st... Read more

2 more replies
Answer Match 59.64%

Hi, I had McAfee running and it found a trojan, so i removed it right? For some odd reason my PC restarted(blue screen of death, something about memory) Every time i try to boot normally it gives me the blue screen. so now im in safe mode typing this. I've done multiple full scans on Mcafee and it still says one or more errors could not be fixed because of an error. anyways it been like this all day. I just downloaded avast version 4.8 and currently scanning my system. Any suggestions of help? I'd rather not delete the entire contents of my hard drive and reinstall vista.

I tried downloading Malwarebytes but when i try to run it, it won't open.

Edit 1-avast! Virus Cleaner Tool - version 1.0.211 Ansi

Edit 2- Currently scanning with AVG 8.5 Free Trial Safe Mode

Edit-3 It seems that AVG has cleaned my computer right, i can now boot up normally and my mcafee says im secure.tt

Edit-4 Mcafee is on overload again, my computer got blue screen again. and i am currently scanning with mcafee.

Edit-5 Mcafee has been uninstalled by me and now running avg once more

A:Help, infected laptop, currently in safe mode.

Please help anyone?

10 more replies
Answer Match 59.64%

Hi guys. I just joined this site and this is my first post. My desktop has been infected with Malware/Viruses and won't boot in any mode (safe, safe + networking, last good setting, or normal mode). The closest thing I get is when i go to safe mode and i get a total black screen with no start button or taskbar and on each of the four corners says "safe mode". However, I cannot do anything else on the screen. (Using laptop right now due to desktop being down)

After some research on the web I found that I could try the Avira Rescue CD and would hopefully remove the malware/virus. It's been almost a week but if memory suits me right, the virus was called Cleanup Antivirus. I also was experiencing google redirects. I have already finished most of the steps on the following Avira rescue cd instructions website:

http://forum.avira.com/wbb/index.php?page=Thread&threadID=82163

I am currently stuck on step 7 part 2&3. The reason for this is because in the command line, I type exactly what is instructed but the only thing it does is in the next line says:

"Devices" (text is in a neon greenish-blue font) (This is when i type in "ls /mnt")
When i type in " /mnt " it then says "/bin/ash: /mnt: Permission denied"

Not sure what to do because I have already restarted my computer and tried all modes including safe and normal but am still unable to get my normal computer settings.

I would get my log files with Hijack ... Read more

More replies
Answer Match 59.64%

Browser keeps crashing and PC still very slow. I couldn't do anything unless I was in safe mode. Initially, the icons on desktop were almost completely gone. System is 7 Premium, 3 GB RAM, AMD processor. Thanks for getting me started on getting out of this nightmare.

A:Slow Infected PC; ran JRT and ADW from safe mode

Let's start with a scan using DDS. See if you can get into 'safe mode with networking' :

Download DDS from one of these links:
DDS.com

DDS.pifDisable any script blocking protection
Double click the dds icon to run the tool.
When done, DDS will open two (2) logs: DDS.txt
Attach.txt <--- will be minimized in the task tray

Save both reports to your desktop.
Include the contents of both logs in your next post.

The scan will instruct you to post Attach.txt as an attachment.

9 more replies
Answer Match 59.22%

hi i'm new to the forum, and need some serious help. i clicked the wrong thing, and now i have some virus on my computer, here is what i have tired so far

1. I ran my virus software AVG, but when it starts scanning, it goes like 5 mins then just shuts down, the program still stays open but the scanning window just shuts without completing the scan

2. I ran Ad-ware, and it scans till it gets to the HKEY scan then locks up.

3. I made system recovery disks through the AVG software, but i can;t get the computer to boot of the disk, and i don;t know how to get it to work.

4. I tired restarting in safe mode, to run the virus programs again and the computer will not go into safe mode, it says there was an error and i must start it normally.

following systoms:
-when i start internet explorer it goes right to google, and types in "free porn" and searches out....(no idea why it does this)
-when i open up my documents, windows freezes and has an error then shuts down
-when i start the computer a toolbar pops up on the right side with ads for spyware, porn, insurance and other things.
-also some other things, i can;t really explain

now i been reading on here about HijackThis, so i downloaded that and got the log file. I also got Ewido, i ahevnt; ran a scan yet. i know a little about computers but i can't get anything to work or get this thing off. so here is the log file
------------------------
Logfile of HijackThis v1.99.1
Scan saved at 8:50:45 PM, on 12/... Read more

A:Infected and wont restart in safe mode

14 more replies
Answer Match 59.22%

I've been in France the last 9 months studying and when I came back, my parents told me to look at their computer since it has been acting weird and they could only use it in safe mode. They had been using it without any virus protection it seems. So I dowloaded Super antiSpyware, MalwareBytes and Avast, and scanned the computer with each of them. Superanti spyware found about 1700 infections, malware bytes found 260 more, including koobface.worm, and avast found 4 viruses. I managed to be able to start the computer in normal mode but it freezes many times, so it is very ineffective to use it like that. I don't know what else is wrong with it as I've run out of knowledge of how to fix the problems. I managed to run DDS in normal mode, but was unable to run gmer, both in normal and safe mode. It said there was an unexpected error and it must close.Here is my dds log. Anything else you'd like me to do, just tell me.DDS (Ver_10-03-17.01) - NTFSx86 Run by David at 1:35:00.38 on Sun 06/06/2010Internet Explorer: 7.0.6001.18000Microsoft? Windows Vista? Home Basic 6.0.6001.1.1252.1.1033.18.1915.1146 [GMT -4:00]SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLau... Read more

A:was infected with koobface.worm, must use safe mode

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that it happens. Somethings to remember while we are working together.1.Please do not run any other tool untill instructed to do so!2.Please reply to this thread, do not start another!3.Please tell me about any problems that have occurred during the fix.4.Please tell me of any other symptoms you may be having as these can help also.5.Please try as much as possible not to run anything while executing a fix.If you follow these instructions, everything should go smoothly.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.Gmer is the best but can be hard to get a log lets try this and see what we get.Scan With RKUnHookerPlease Download Rootkit Unhooker Save it to your desktop.Now double-click on RKUnhookerLE.exe to run it.Click the Report tab, then click Scan.Check (Tick) Drivers, Stealth, Files, Code Hooks. Uncheck the rest. then Click OK.Wait till the scanner has finished and then click File, Save Report.Save the report somewhere where you can find it. Click Close.Copy the entire contents of the report and paste it in a reply here.Note** you may get this warning it is ok, just ignore... Read more

3 more replies
Answer Match 59.22%

My XP machine has a problem.  It gave me the Moneypak page on boot up and won't boot into safe mode.
 
I made a ubuntu startup disk and used that to backup my data files.  Also, ran some antivirus boot disks (Kaspersky, Bitdefender, and AVG), but it did not fix the problem.  However, they did get rid of the Moneypak page that was showing on startup.  Now when doing a normal boot, I see my desktop for about 1 or 2 seconds, then get a beige screen which changes quickly to a white screen and hear the hard drive spinning - probably loading things.  When I hold the power button to reboot, the blank page shuts down and I can briefly see my normal desktop full of icons again. Not enough time though to run any programs.
 
Since I can access my files by booting into Ubuntu, I assume the problem could be fixed by manually removing the right files or making some other changes, but I don't know which.
 
Can anyone help me get my machine working again?  Your assistance is much appreciated.
 
 

A:Infected with Moneypak - can't boot into safe mode

Hello and welcome to Bleeping Computer. I am sorry that you are having troubles with your computer and will try my best to help you. I know that being infected is very frustrating, but I will be here to help you through the whole process of cleaning. Removing malware can be difficult and complicated and will most likely take many steps, so please stick with me until I have declared your computer clean. I always recommend printing my instructions before following them in case you cannot keep this webpage open. Please be sure to alway follow all steps exactly as they are written and let me know what happens each time. Stop and ask if something unexpected happens or if you are unsure of how to proceed.Please respect my volunteered time and stay with me until I declare your computer clean. If you are going to be delayed for a while, please let me know.Are you booting Ubuntu from a CD? Do you have a USB flash drive available?

more replies
Answer Match 59.22%

I am visiting my kids and my ex-in laws got scammed by a FakeAV.  The person they talked to installed windows 8 and now it boots only to safe mode. 
 
Here are the Hijack This logs, DDS logs.
 
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 12:12:54 PM, on 8/29/2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17028)

Boot mode: Safe mode with network support
Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Ron and Karen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\89NEVL99\HijackThis.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSear... Read more

A:Not exactly sure what computer is infected with but boots only to safe mode

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/546184 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of t... Read more

2 more replies
Answer Match 59.22%

I am available Mon - Thur, but will monitor my post and go to the computer if necessary over the weekend. This is an elderly woman's laptop done as a volunteer project and I will receive no compensation for my services.
 
I get redirected trying to go to bleeping computer and had to use safe mode to download and post.
 
Here is my log:
 
DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 11.0.9600.17344
Run by Judy Gilman at 9:28:45 on 2014-11-05
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.4008.3250 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\wbem\wmiprvse.exe... Read more

A:Win 7 infected with redirect. Can only use Chrome in safe mode.

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/554855 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of t... Read more

2 more replies
Answer Match 59.22%

Hi,
My computer is running windows 7 64bit and got infected with win32.sality.bh. I am not able to run any program except kaspersky. I had a full scan and removed all threats it could find but apparently the so called anti virus is not as powderful as it described. i still cant open any program. I tried to run in safe mode but cant do it without msconfig. any idea how can i run in safe mode? thanks in advance.

More replies
Answer Match 59.22%

XP Pro SP3 machine boots fine normally but can not get past the driver loads in safe mode. It just starts over. Seems to stop at the MUP.sys line. I've copied in a different MUP.sys file but it didn't help.
Original problem is something is starting up about 9 instances of Windows Explorer in full screen on multiple advertising sites and hanging the PC for a while. Also get memory location errors popping up at regular intervals. Memory test is good and the sticks are now 4 days new but still get the errors that don't hang anything but the messages just reoccur.  
Ran Malwarebites and deleted old user profiles, temp files and got Windows updates current. Didn't see any odd programs installed or notice any crazy processes but haven't sorted each little one out yet. Have antivirus on it but not detecting anything.

A:XP Pro Infected boots OK but not booting into safe mode

Video card or internal?

2 more replies
Answer Match 59.22%

Hi,

Had Issues for a while with being directed to random sites while using google and random pop ups,

Had the Yellow shield pop up in the task bar telling me i had to restart the system, after restart the Colour of the font in Firefox had changed to black and was running slow and freezing, 3-4 minutes in and the system would freeze only relief being the restart button.

3/4 restarts down the line im here , after the Windows XP loading screen goes off the screen just stays black no welcome page

EDIT EXTRA: It seems the wpa.dbl fil was modified at the time of the attack

Hijack This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:40:42, on 15/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.micros... Read more

More replies
Answer Match 59.22%

Today, my laptop became infected with the FBI malware.  It has disable my ability to use Safe Mode in any way. 
 
Through reading on this site and Norton, I found initial instructions on downloading FARBAR Recovery Scan Tool.
 
I urgently need assistance.   Thanks.
 

A:Infected with FBI Virus - Safe Mode is not accessible

Hello anewbie1! Welcome to BleepingComputer Forums! My name is Georgi and and I will be helping you with your computer problems.Before we begin, please note the following:I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.The logs can take some time to research, so please be patient with me.Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.Instructions that I give are for your system only!Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Please perform all steps in the order received. If you can't understand something don't hesitate to ask.Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions. Please download Farbar Recovery Scan Tool and save it to a flash drive.Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.Plug the flashdrive into the infected PC. If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.If you are using... Read more

3 more replies
Answer Match 59.22%

Hey guys,So my girlfriends computer had a virus on it called Windows System Defender. It installed itself while browsing the internet, no we don't remember what site it was. I looked up ways to remove it and I did everything it said to do and even removed an instances of it from the Registry. It still persists and continues to come back,we think. After running a bunch of virus scanners it appears that I have gotten rid of the original virus but now have a new one that we can't figure out what it is and won't pop up on virus scanners. It also won't let us boot up in safe mood. It gives us a blank blue screen when we try to do so. I have posted a HJT log to see if that will show anything. Any help is much appreciated. Thanks.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:20:16 PM, on 11/3/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16915)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Intel\Wireless\Bin\S24EvMon.exeC:\Program Files\Intel\Wireless\Bin\WLKeeper.exeC:\WINDOWS\system... Read more

A:Infected With Virus and Can't Boot to Safe Mode

Problem has been resolved.

2 more replies
Answer Match 59.22%

Hi Guys,

My WinXP Sony Vaio VGN-215M has been infected by what the Dr. Web demo identified as 'NTRootkit.83'. The first symptom I noticed was .EXE files starting to disappear, including my Norton Antivrus. Another problem I noticed is my wireless network connection has disappeared (no networks show up anymore).

I have tried a variety of tools including the McAffeee Rootkit tool beta, but it seems this one is still sticking around. Dr. Web support indicated I should reboot in safe mode and then run Dr. Web to remove it, BUT; when I try a reboot in any form of safe mode, it:

a) reboots
b) shows the loading screen, and then goes through a list of drivers on the bottom of the screen
c) reboots itself back into normal mode

So effectively I cannot reboot into safe mode.

I have output the following Hijackthis logfile, if this helps:

Logfile of HijackThis v1.99.1
Scan saved at 8:19:25 PM, on 16/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Apoint\Apoint.exe
C:\Programme\ATI Technologies\ATI Co... Read more

A:Infected with NTRookit.83 - Can't reboot in safe mode

Still getting nowhere.

Installed Dr. Web antivirus, and just like my Norton, the .exe files for the program disappear. This is one nasty litte trojan.. please help!
 

1 more replies
Answer Match 59.22%

Hi - I am running a win 7 OS and am infected with the FBI moneypack virus. It is not allowing me to enter either 'safe mode' or 'safe mode w/ networking' or 'safe mode with command prompt'.

When I log in to the computer using a different user I don't have this issue.

Can you please help?

A:FBI Moneypack Virus - Infected even in safe mode

Hi gsms123

I will be handling your log to help you get cleaned up. Please give me some time to do up a fix and I will get back to you as soon as possible.

White Warrior

23 more replies
Answer Match 59.22%

Hi all,

My computer started running verrrrrrrrrrrrry slowly two days ago. It's so slow that nothing is usable. I tried to do a system restore, but all restore points are gone before April 30. Restoring the April 30 restore point fails with an error.

Tried various spyware and rootkit removal software and nothing helps. Desperate...

Here's my HijackThis log:

Thanks! Bob

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:33:35 PM, on 5/10/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intuit\QuickBooks 2009\QBW32.EXE
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http... Read more

A:Computer infected? Only runs OK in safe mode

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below I will review and take the steps necessary with you to get your machine back in working order clean and free of malware.Thanks and again sorry for the delay.Download OTL to your desktop.Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.When the window appears, underneath Output at the top change it to Minimal Output.Under the Standard Registry box change it to All.Check the boxes beside LOP Check and Purity Check.Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as... Read more

2 more replies
Answer Match 59.22%

Hello,

I'm using a spare computer to try and resolve an issue with my laptop.

Earlier I was using Firefox but Internet Explorer suddenly began to pop up. After a few tries using Task Master, I was able to shut off IE. But I wanted to search for any trojans or viruses and attempted to scan using Malwarebytes. This program shut down after a few seconds of scanning. When I attempted again, it said "Windows cannot access the specified device, path, or file."

I tried to run HijackThis in Safe Mode to try and get a log but got the exact same message as above about Windows not being able to access.

Any assistance would be GREATLY appreciated!
 

A:Badly Infected - Cannot Run HijackThis in Safe Mode

16 more replies
Answer Match 58.8%

A few days ago I picked up the Internet Security 2010 virus. We have Malwarebytes on the laptop so I did a scan with it and cleaned what it found. I then tried to restart in safe mode and run the scan again but the safe mode went straight to a blue screen that says PAGE_FAULT_IN_NONPAGED_AREA.

I then restarted the laptop in normal mode and now I have no internet connection. I also can't access any firewall modes. Now when I run malwarebytes it comes back clean. Any help would be greatly appreciated. The laptop is a Dell inspiron e1705 and has windows xp. We use AVG free for virus protection. I do have internet access with my desktop.

Update: I can no longer start windows in normal mode or safe mode. Either one takes me to the Blue Screen

A:Internet Security 2010 problems....no safe mode or internet connection on laptop

Any ideas??

1 more replies
Answer Match 58.38%

okay... so i was trying to get into safemode so i could run an antivirus scan, problem is whenever i tried going in safemode the blue screen would pop up and computer would restart. now for some dumb reason i thought maybe i could get in safemode if i used msconfig and selected safe mode from the boot menu. so the computer restarted and now it boots in safemode but the blue screen and restart happen everytime now. ive tried "start windows normally" but that boots in safemode.... ive tried "last known good config..." and that too boots in safemode. so now im stuck, i cant get on windows. any help please?

im willing to start over but i dont know how to do that from here
 

A:STUCK in safe mode boot, safe mode doesnt work and restarts, REPEAT

11 more replies
Answer Match 58.38%

Hello,

Could someone please help, I have lost control of my laptop. If I boot into normal mode the computer freezes and I have to turn it off manually. In safe mode I cant run Hijackthis or Avast. Microsoft Security Essentials cannot update.

Malwarebytes Anti-Malware has not found any infections.

I have ran TDSSKiller and pasta the log below. It found 8 threats but dont know what to do it them.

Im running Win 7 Pro.

Any help would be much appreciated, thanks
15:00:04.0499 2600 TDSS rootkit removing tool 2.7.41.0 Jun 20 2012 20:53:32
15:00:04.0619 2600 ============================================================
15:00:04.0619 2600 Current date / time: 2012/06/21 15:00:04.0619
15:00:04.0619 2600 SystemInfo:
15:00:04.0619 2600
15:00:04.0619 2600 OS Version: 6.1.7601 ServicePack: 1.0
15:00:04.0619 2600 Product type: Workstation
15:00:04.0619 2600 ComputerName: Scorpio
15:00:04.0619 2600 UserName: Administrator
15:00:04.0619 2600 Windows directory: C:\Windows
15:00:04.0619 2600 System windows directory: C:\Windows
15:00:04.0619 2600 Running under WOW64
15:00:04.0619 2600 Processor architecture: Intel x64
15:00:04.0619 2600 Number of processors: 4
15:00:04.0619 2600 Page size: 0x1000
15:00:04.0619 2600 Boot type: Safe boot with network
15:00:04.0619 2600 ============================================================
15:00:05.0039 2600 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder... Read more

A:Badly Infected - Cannot Run Avast or HijackThis in Safe Mode

Hello again, I was reading through other posts and installed combo fix. Maybe this might be of some help too

Thanks

ComboFix 12-06-21.01 - Administrator 21/06/2012 15:44:35.1.4 - x64 NETWORK
Microsoft Windows 7 Professional 6.1.7601.1.1252.353.1033.18.8089.6972 [GMT 1:00]
Running from: c:\users\Administrator.AccessCentre-PC\Downloads\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Access Centre\AppData\Local\TempDIR
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\instsrv.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-05-21 to 2012-06-21 )))))))))))))))))))))))))))))))
.
.
2012-06-21 13:50 . 2012-06-21 13:50 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3BFA3D38-DCC1-4969-9747-699DB7E1B76A}\offreg.dll
2012-06-18 11:27 . 2012-06-18 19:33 -------- d-----w- c:\users\Administrator.AccessCentre-PC\AppData\Roaming\EndNote
2012-06-18 11:27 . 2012-06-18 11:27 -------- d-----w- c:\program files (x86)\Co... Read more

2 more replies
Answer Match 58.38%

I have a relatively new Vista Home system which was running fine until last night, when running an exe windows showed the command prompt listing keygen.exe, and serial.exe. Then another was listed, and Windows said something had stopped responding, and it would shut down in 1 minute. It restarted, and after the boot screen, microsoft loading bar the screen usually just remains black, and eventually reboots. Sometimes you see the vista logon scree and it says please wait, only to go black and do the same. Although there's also a short delay with a black background only with a cursor, I can load in safe mode. Here I've run a full AVG anti spyware (formerly ewido) scan which some stuff, unfortunately I can't find reports of that or Avast AV I ran, but I thin it picked up a keygen archive, and deleted 1/2 trojans, moved some other stuff to the chest. In add/remove programs I've found an un-installed some oberon media entries, including big kahuna reef 2, galapago, and others. It's still the same, desperate for help, thanks in advance.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:22, on 09/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Minefield\firefox.exe
C:\Users\Kristian\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Pa... Read more

A:Infected with trojan, Vista won't start aside from safe mode

Quote:




Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.




Hello and welcome to the forums

My name is Katana and I will be helping you to remove any infection(s) that you may have.

Please observe these rules while we work:
1. If you don't know, stop and ask! Don't keep going on.
2. Please reply to this thread. Do not start a new topic.
3. Please continue to respond until I give you the "All Clear"
(Just because you can't see a problem doesn't mean it isn't there)

If you can do those three things, everything should go smoothly

----------------------------------------------------------------------------------------


I apologize for the delay in responding, but as you can probably see the forums are quite busy.
Unfortunately there are far more people needing help than there are helpers.


Installed Programs

Please could you give me a list of the programs that are installed.Start HijackThis
Click on the Misc Tools button
Click on the Open Uninstall Manager button.
You will see a list with the programs installed in your computer.
Click on save list button and specify where you would like to save this file.
When you press Save button a notepad will open with the contents of that file.
Simply copy and ... Read more

3 more replies
Answer Match 58.38%

I'm trying to help fix a friend's infected machine. I don't know what caused it but i can not run most of the malware removal tools.

The XP SP2 PC is getting continuous bad image errors pointing to a file called "UACxtcujhcadh.dll" - not a valid Windows Image.
Can not run any program without these error messages and the standard malware tools won't run.

The machine will only boot into safe mode, otherwise will get a blue screen with Driver_IRQL_Not_Less_or_Equal after login.
I've run a RootRepeal and will include the log.

Thank you in advance for any suggestions. Any idea which infection I might be dealing with here?

A:Infected, Can't run removal tools, only boot into safe mode

Go ahead and close this. I can not get any programs to run. RootRepeal can not access the boot sector and it throws up an error that it can not read the registry.

I'm going to wipe this machine so this can be closed.

2 more replies
Answer Match 58.38%

Hi folks,

I'm on windows XP.

When computer first loads up I get this message:
"avgwdsvc.exe encountered a problem and needed to close"

internet explorer and firefox do not work. However, IE works when started "with no add ons" and firefox works in safe mode. Email works.

I'm worried I have a virus. I'm not able to run avg to do a virus check because it crashes every time it is loaded.

I've installed and run three anti malware programs but the problem is still present

Would really appreciate some help.

Cheers,

More replies
Answer Match 58.38%

I have a relatively new Vista Home system which was running fine until last night, when running an exe windows showed the command prompt listing keygen.exe, and serial.exe. Then another was listed, and Windows said something had stopped responding, and it would shut down in 1 minute. It restarted, and after the boot screen, microsoft loading bar the screen usually just remains black, and eventually reboots. Sometimes you see the vista logon scree and it says please wait, only to go black and do the same. Although there's also a short delay with a black background only with a cursor, I can load in safe mode. Here I've run a full AVG anti spyware (formerly ewido) scan which some stuff, unfortunately I can't find reports of that or Avast AV I ran, but I thin it picked up a keygen archive, and deleted 1/2 trojans, moved some other stuff to the chest. In add/remove programs I've found an un-installed some oberon media entries, including big kahuna reef 2, galapago, and others. Tried system restore which couldn't log in, with same black screen problem. I'd rather not re install as I the systems nicely setup, plus I don't have Vista Home Premium CD, only an ultimate which. It's still the same, desperate for help, thanks in advance.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:22, on 09/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode with network suppor... Read more

More replies
Answer Match 58.38%

I am infected with numerous items. Can only boot in SafeMode. Removed multiple items multiple times.EMachines, T6412, AMD Athlon 64, 3400+, 2.19 GHz, 1.37 GB of Ram, Windows XP SP2Can only boot in Safe Mode.Booted without Internet. And Unplugged Ethernet from computer.Pop-ups include:Your computer is not protected against spyware....Internet attack attempt detected......your computer is infected with spyware...Your Computer is working slowly.....Windows Security Center System Warningfull screen "Threat: CoolWebSearch"Windows Security Centerfull screen "Threat Name: TrojanDownloader.XS"SpyBot (updated to the latest) has removed the following but they do not stay removed and I have removed them again many times. Wait 10 minutes, ran SpyBot again, they return again without rebooting.:ClientManCoolWWWSearchCoolWWWSearch.008kCoolWWWSearch.Aff.ledllCoolWWWSearch.AffWinshowCoolWWWSearch.BlowSearchCoolWWWSearch.BootconfCoolWWWSearch.DreplaceCoolWWWSearch.GonnasearchCoolWWWSearch.LeftoversCoolWWWSearch.SmartSearchCoolWWWSearch.SvcinitCoolWWWSearch.WCADWCoolWWWSearch.WinResCoolWWWSearch.WinSearchCoolWWWSearch.YexeMicrosoft.WindowsSecurityCenter.TaskManagerSmitfraud-C.Smitfraud-C.genericSmitfraud-C.gpToolbarCCWin32.Small.nyRan AVG Antivirus numerous times - Vault items. Some repeat:Trojan horse Downloader.Purityscan.yTrojan horse Downloader.Agent.15.ATrojan Horse Sheur.BJSJTrojan horse Generic10.VYBTrojan horse Downloader.Generic7.MCBTrojan horse Downloader.Generic7.... Read more

A:Infected With Numerous Items. Can Only Boot In Safe Mode

Hi, PaulDH Welcome.Please download ComboFix from Here or Here to your Desktop.**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**Please, never rename Combofix unless instructed.Close any open browsers.Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-----------------------------------------------------------Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
-----------------------------------------------------------Close any open browsers. WARNING: Combofix will disconnect your machine from the Internet as soon as it startsPlease do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.If there is no internet connection after running Combofix, then restart your computer to restore back your connection.-----------------------------------------------------------Double click on combofix.exe & follow the prompts.When finished, it will produce a report for you. Please post the "C:\ComboFix.t... Read more

12 more replies
Answer Match 58.38%

Ok I will list the problems in order that they occured...

-Went to a site, suddenly I get the infamous fake spyware icon (the blue shield) and it says I have all these viruses and starts scanning

-I try to open up AVG and it's locked. I try MBAM and it's locked. Thankfully super antispyware works. and finds 4 of the trojan dropper and gen combo

- I delete and restart my computer in safe mode when I GET A BIG BLUE screen telling me that there was a problem (something like hardware problem or changes). This has never happened to me! I usually run safe mode and run my scans and boom my problem is solved but somehow it seems to be blocked!

-On the bright side my computer WILL load in regular mode but I seem to have the yahoo redirect problem. I ran trend micro, AVG, MBAM, and super antispywar and they dectect NOTHING. Please help! I'm really out of ideas on what to do. I ran a combo fix but it didn't take long and really had nothing in the log that stood out. If I need to post a hijack log I will gladly but I'll have to get back to the infected computer.

Please help! Thanks! I hope I don't have to reformat!

More replies
Answer Match 58.38%

The compter is locked.  I have tried to restore system earlier date- did not work.  I get into the advance boot options window but when I chose either of the safe modes-  it shuts down before I can get to anything-Edit: Moved topic from Am I infected? What do I do? to the more appropriate forum, at the request of Malware Removal staff. ~ Animal

A:fbi money pak virus removal- has infected my safe mode- HELP

Don't give up on System Restore after one try!  I have removed this virus twice this week for people and they have a newer version than anyone talks about on forums or can see in removal videos on Youtube. 
 
My solution was to run system restore more than once trying a couple different restore points till one completed successfully.  In one case, it said it was unsuccessful but when the computer rebooted normally afterwards, it actually was successful.
 
Press F8 when rebooting to bring up boot options and select "Repair Your Computer".  Log in as administrator and select system restore and try again if you can on an available restore point before the infection.  It may take a few tries.
 
Post back here if it is not.

15 more replies
Answer Match 58.38%

Ever since I got that virus my computer has only been able to start in safe mode with networking. Whenever I boot up my comp, the typical windows xp screen would load and then a blue screen would flicker for a mili sec (too fast for me to read!) and then I am presented with the option of booting it into safe mode. I have ran Malwarebytes anti malware and it seems to have gotten rid of most of them, but one or sometimes two keep coming back. The trojan "HKEY_Local_Machine\software\tdss" would come back every time I reboot and run malware. If I dont get rid of it, it will re direct me to a different site (about viruses) whenever I click on links. When I get rid of it, links work fine. And I was unable to run adware and and spybot in sm, I have ran stinger though...Logfile of Trend Micro HijackThis v2.0.2Scan saved at 18:45:20, on 10/23/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)Boot mode: Safe mode with network supportRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Internet Explorer\Iexplore.exeC:\Program Files\Trend Micro\Hija... Read more

A:infected with xp anitvirus 2009 and can only access safe mode

Hello, Imaloser. to BleepingComputer.comMy name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)Please give me some time to look over your computer's log(s).Please take note of the following:In the meantime, please refrain from making any changes to your computer.Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.Finally, please reply using the button in the lower left hand corner of your screen.We Need to Run ComboFixNote to readers of this post other than the starter of this thread:ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.About 1 in 100 times the computer will not longer be able to boot after running Combofix. This requires experienced hands to restore the system to bootability.There are several malware infections that "target" Combofix. Experienced Helpers are aware of these infections, and take steps to remove them prior to the use of Combofix. If you do not, various things can happen depending on the infection -- from Combofix being unable to run, to the dele... Read more

13 more replies
Answer Match 58.38%

W32/Blaster.worm has infected laptop. Can't get on web. Can't get in safe mode.
From my cell phone I have been researching and it seems to be an old virus.
I am getting security warning/malicious program.
Firewall warning: Hidden file transfer to remote host has been detected. There is a remote host transfer IP: 25.92.229.139.
And it make a pig squeal sound when I start it up!
Please help! Thank you!

A:W32/Blaster.worm has infected laptop. Can't get on web. Can't do safe mode.

Please do the following:Download the appropriate version for your system of the Farbar Recovery Scan Tool and save it to a flash drive.Plug the flashdrive into the infected PC.Enter System Recovery Options.To enter System Recovery Options from the Advanced Boot Options:Restart the computer.As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.Use the arrow keys to select the Repair your computer menu item.Choose your language settings, and then click Next.Select the operating system you want to repair, and then click Next.Select your user account and click Next.To enter System Recovery Options by using Windows installation disc:Insert the installation disc.Restart your computer.If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.Click Repair your computer.Choose your language settings, and then click Next.Select the operating system you want to repair, and then click Next.Select your user account an click Next.On the System Recovery Options menu you will get the following options:Startup RepairSystem RestoreWindows Complete PC RestoreWindows Memory Diagnostic ToolCommand PromptSelect Command PromptIn the command window type in notepad and press Enter.The notepad opens. Under File menu select Open.Select "Computer" and find your flash drive letter and close the notepad.In the command window type e:\frst.exe (for x64 bit version type e:... Read more

2 more replies
Answer Match 58.38%

My cousin's mouse stopped working on his computer after installing a game expansion. He asked me to try to fix it and I noticed his computer was heavily infected with viruses. I've removed a lot of malicious files through Malwarebytes' Anti-Malware; however, the mouse still doesn't work, and I think there are still viruses. I also tried to reinstall the drivers for the mouse off the manufacturer's website(Logitech), but it didn't help. Since the mouse only works in safe mode, I can only run GMER in safe mode.DDS (Ver_10-03-17.01) - NTFSx86 NETWORK Run by Administrator at 19:10:45.24 on Mon 09/20/2010Internet Explorer: 7.0.6000.16643Microsoft? Windows Vista? Home Premium 6.0.6000.0.1252.1.1033.18.2813.2149 [GMT -7:00]AV: McAfee VirusScan *On-access scanning enabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svcho... Read more

A:Mouse only works in safe mode, infected with viruses

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. Please include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.We need to create an OTL ReportPlease download OTL from one of the following mirrors:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.In the custom scan box paste the following:CODEmsconfigsafebootminimalactivexdrivers32netsvcs%SYSTEMDRIVE%\*.exe/md5st... Read more

11 more replies
Answer Match 58.38%

I am working for someone and using their computer. I have accidentally infected this computer and do not have access to the Administrator account to change/revert things. I am in safe mode now and can access the internet. I have tried calling places like Symantec to get help over the phone and there is not much they can do without admin access. I will post the DDS log at the end. The GMER was not able to scan my computer, most likely because of the infection.

I apologize, I do not remember the exact names of the infection or the "antispyware program" that was running after. The virus started with an S and sounded like syndavi. The "antispyware program" was called AntiSpyware _______. I have Symantec Endpoint protection on this computer. I can restart out of safe mode to find these but I would rather not make anything worse as it is not my computer. Is this possible to fix without admin access? Will pay well if it is able to be resolved. Thank you so much for your help!
DDS (Ver_10-11-27.01) - NTFSx86 NETWORK
Run by vevans at 13:00:33.75 on Fri 12/03/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1367 [GMT -5:00]

AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Pr... Read more

A:Infected with no admin access, running in safe mode now

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the resu... Read more

3 more replies
Answer Match 58.38%

Hi, Suddenly today our PC shut down spontaneously.  I can turn it on and sometimes get to the safe mode screen, but when I hit enter to get safe mode, the computer once again shuts down.  If I immediately try to restart, the computer won't even get to the first page without shutting down.  What to do?
thanks!  Barbara

A:Infected? Computer won't start long enough to get into safe mode

Is Safe Mode with Networking any better? What is your Operating system? Did you notice if you had any malware pop up or you were removing some before this happened.

4 more replies
Answer Match 58.38%

Hello,I am dealing with a problem a few days now and I can't find a solution for it.When i boot my pc, windows load to desktop and after a minute or so i get a blue screen with the error message:QUOTESTOP: 0x0000008E (0xC0000005, 0x80635AC1, 0xB490796C, 0x00000000)Also nod32 icon was red but i couldn't click on it (windows were buzy loading other programs).I booted pc in safe mode and tried to run nod32 but it wouldn't start. I uninstalled it and tried to install Kaspersky but due to safe mode i couldn't install it. I then downloaded malwarebytes and run a full scan.This is the log from the scan:QUOTEMalwarebytes' Anti-Malware 1.44Database version: 3554Windows 5.1.2600 Service Pack 2 (Safe Mode)Internet Explorer 6.0.2900.218014/1/2010 12:46:54 ???mbam-log-2010-01-14 (00-46-54).txtScan type: Full Scan (C:\|G:\|H:\|)Objects scanned: 554114Time elapsed: 1 hour(s), 37 minute(s), 26 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 6Registry Values Infected: 3Registry Data Items Infected: 1Folders Infected: 2Files Infected: 4Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft&#... Read more

A:Infected, Blue Screen, PC only Boots in Safe Mode

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies
Answer Match 58.38%

Hi,
 
I have a laptop running windows 7 that has been infected with Antivirus Security Pro.  When I try to start in Safe Mode the computer keeps restarting before I can do anything.
 
I can not download any malware removal or any other software.
 
I can not seem to start any programs.

A:Infected with Antivirus Security Pro, will not let me start in safe mode

Hi there,my name is Marius and I will assist you with your malware related problems.Before we move on, please read the following points carefully. First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding. Perform everything in the correct order. Sometimes one step requires the previous one. If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem. Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me. Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts. If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed. Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean. My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.    Scan with FRST (Recovery Environment)To run FRST on Vista and Windows7:For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.Plug the flashdrive into ... Read more

36 more replies
Answer Match 58.38%

Hello, I have probably 20 hours into trying to repair a Dell Inspiron 6400 running Windows XP Pro. The most frustrating part of this is that tools that I believe might help, such as Malwarebytes AntiMalware, Hijack This and RootRepeal are being blocked from installation or running by something...even in Safe Mode. I have tried the rename files names to get them to work...they still do not open. It is the "something" that I have been unable to find.
I was able to load Spyware Doctor, but when scanning it would hang up on one program...so it never finished. I was able to run Virut (it cleaned files, unable to open some) and right now Symantec Trojan.Vundo Removal Tool is running.
I have done a Windows Repair Installation which means I rolled back to SP1. I can get Internet access in Safe Mode, not in regular mode. When I try to update Windows it stops in the middle and says I have an error. I get a "spoolsv" error when the machine starts. From reading it appeared this is a Windows update issue. I did look for excessive SPL's and there were none. When in Internet Explorer I get the red letter warnings that I am infected with 18 trojans and should scan my machine. I did not click on scan my machine. Typically when trying to go to a antivirus/malware site I am blocked or Explorer/Mozilla closes.
I got regedit to work by renaming it reg-edit. The other above mentioned programs did not work even when renamed. Another program that will not work... Read more

More replies
Answer Match 58.38%

Hello,
 
I have a Dell laptop which is infected with Infected Antivirus Security Pro, will not let me start in safe mode:
Windows 7 Home Premium, P4 Dual Core T4300 2.10GHz, 4.00 GB,  64Bit 500GB HD.
 
I tried running malwarebytes and all .exe file execution are blocked by Antivirus Security Pro, tried to restart in safe mode as soon as it gets to desktop it shuts down and restarts.
 
Need help removing please, Thank you

A:Infected with Antivirus Security Pro, will not let me start in safe mode

Before you do anything just try and "activate" it using this code, its a longshot but sometimes it works and you will be able to run malwarebytes and other tools
 
AA39754E-715219CE
 
See video for help on to do this
http://www.youtube.com/watch?v=y58O8bqx9sQ

6 more replies
Answer Match 58.38%

Hi all - this is my first ever post to a forum - normally I google my problems and find the solution, however this one seems pretty gruesome. I have checked around various forums for a day now, with no luck so far. As I am new to this, please excuse any gross violations of etiquette Here is the scenario:

A friend of mine from work approached me about some of his computer problems (frequent pop-ups, etc...), as I installed AVAST! Home for him a few months back. (His PC specs are: - compaq presario desktop, windows XP home SP2, AMD Sempron 3200+, 1ghz, 512m RAM, 80gb HD)
I suspected that he had not kept his free registration current, and that Avast expired and he had accumulated some viruses, spyware, trojans, etc... So trying to help out, I met him at the computer store, recommended that he purchase Zone Alarm Internet security (antivirus, anti-spyware, firewall...) and installed it for him. After installation, a dialog box opened suggesting I restart the computer, which I did(thinking back to my own machine, I do not recall having to restart after installing zone alarm - I think I may have inadvertently messed up here, because I had not even scanned for viruses/spyware, yet once the computer restarted, it would not boot normally) - I had to start in safe mode with networking. I figured that I would scan for viruses in safe mode anyway, and that should get rid of whatever was causing the problem. Found 39 infected files - Zone Alarm cleaned all but one of them - it reported... Read more

A:Severely infected computer - will now only boot into safe mode

6 more replies
Answer Match 58.38%

I've tried everything I. The F8 menu, I'm in a reboot/launch repair loop.
I've tried kaspersky recovery disk and advair boot disk and can not get the virus off so I can atleast boot into windows and fix this.
Ideas? Should I try FRST64?

A:Infected with a virus can't boot windows even into safe mode

 

Should I try FRST64?

 
Please do and post its report.

3 more replies
Answer Match 58.38%

Can anyone help? This is an old computer- but I have always been able to use it. My daughter decided to "borrow it" and it hasn't been the same. I downloaded "hijackThis" and here is what it showed: Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:05:20 PM, on 11/2/2009Platform: Windows Vista SP1 (WinNT 6.00.1905)MSIE: Internet Explorer v7.00 (7.00.6001.18319)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\system32\taskeng.exeC:\Program Files\Windows Defender\MSASCui.exeC:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exeC:\Program Files\Gamevance\gamevance32.exeC:\Program Files\QuickTime\QTTask.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXEC:\Program Files\Java\jre1.6.0_07\bin\jusched.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\AIM6\aolsoftware.exeC:\Windows\system32\wuauclt.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\IObit\Advanced SystemCare 3\Awc.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\Windows\system32\Sear... Read more

A:Computer Infected? Keeps showing desktop in safe mode

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. Please include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.Please download OTL from following mirror:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.Push the button.Two reports will open, copy and paste them in a reply here:OTL.txt <-- Will be openedExtra.txt <-- Will be minimizedIn the upper right hand corner ... Read more

2 more replies
Answer Match 57.96%

Title says it all. Done an avast scan and removed everything found from that. Did a Spybot scan not long ago and it found the Virtumonde virus.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:51:38, on 08/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toggle.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acro... Read more

More replies
Answer Match 57.96%

i have windows home xp edtion on parkard bell.in safe mode it is fine,but when on normal bootup mode it will hang up after 2mins aprox(then restart saying crit error,check hardware etc and being to dump files kernel),on a blue screen.

i tried a different graphics card,but no joy.so i replaced the hdd drive and put a fresh copy of windows xp pro edtion on,but it loads all the files(i have not pressed f6)i just let it run its course on the disc,then it hangs up on the blue screen again with the words(crit error 0x0000007f)check hardware etc and if this is the first time you have seen it try starting windows again.

Thankyou for all your time.
 

A:Solved: xp safe in safe mode fine...mormal mode blue screen

Start in Safe Mode and look in C:\Windows\Minidump for crash log files with a dmp extension, like Mini071008-01.dmp. Zip 4-5 of the latest ones and post here as a ZIP or RAR attachment. The log file contains information useful to determine what caused the error, most likely hardware.
 

2 more replies
Answer Match 57.96%

I'm new here and in hopes of getting this resolved. I just installed the new Norton Systemworks 2005 and rebooted after installation. When the boot screen got up to the blue screen with the Windows XP logo before displaying the login names where you put in your password, it just stops. I restarted a few times and waiting a few more times thinking it may need to 'finish' installing. But each time gave the same results. Finally, I went in with 'Safe Mode' and got in with no problems. Tried again in normal mode after looking around for any obvious problems (none found)... back to square one. Tried again in 'Safe Mode with Networking' and it failed like normal mode so I suspected a networking problem??? The last thing I tried which made me mad is that I tried to uninstall Norton Systemworks in 'Safe Mode' and that failed!! Anyone in these forums know the cure? :dead:
 

A:Unable to get to login screen, works in Safe Mode but in Safe Mode w/ Networking

Just a thought

Safe-Mode
Start \ Run \ msconfig \ diagnostic startup
disable any services attached to your most recent install and restart
should get warning next boot about using msconfig, its ok
One key service that needs to be available is the installer service
Try the uninstall, if doesn't complete
Try the uninstall string in the registry only if you know what you are doing

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

Under it you will see a list of installed programs. Some don?t show up as words but you can figure out what they are by looking at their values. What you are looking for is the uninstall string. Double click that key as if you were going to modify its value. Do a CTRL + C to copy and then exit the registry editor.

Go to START \ RUN and paste the uninstall sting and hit enter. This should launch the uninstall.

Just a thought though as I am not infront of a test system at the moment. You should research this a little further so you have a clear understanding of what you can and can't do with msconfig.

or simpler yet

Safe-Mode

Start \ Programs \ Access. \ System Tools \ System Restore

Select restore point prior to install of whats giving you the problem.

Again, Good Luck

PS If you try to install it again, turn of antivirus and other open programs etc..
 

1 more replies
Answer Match 57.96%

***before wasting your time reading this, I'm running Vista and don't know if it will work on XP or earlier systems***
 
Hi guys, I am by no means a tech expert. So do the following at your own risk.
 
About a month ago I contracted internet AIDS. The FBI virus is the worst virus I've ever had on my computer, and it did some serious damage. It even messed with my Xbox live account by tampering with my payment methods. Luckily, they weren't credit cards. If you have any access to credit cards from your computer I suggest removing them immediately upon contracting this virus. I can't remember how the virus started but I did notice some differences, and my Xbox Live account became unusable before my computer did. One day it randomly popped up on my computer and it became what I thought to be almost useless. I could only log in for about 30 seconds before the virus popped up. I wasn't thinking and left it plugged in (I don't know if this made a difference - as I said I'm no expert) for a couple weeks and then I couldn't even get to the desktop like I could before. When I started the computer and pressed F8 and selected 'Repair Computer' and tried logging in as the administrator, my password had been changed. When I tried starting it in safe mode, it logged in, logged off, shut down, restarted, and logged back in normally right away. Then the virus would pop up. After a while the virus just stopped popping up and my computer would white screen, giving me absolutely no co... Read more

More replies
Answer Match 57.96%

My laptop has been infected by malware/spyware. This is the first time i have joined any forum so look forward to your help. I have been working in safe mode since 2 days and need immediate help as this is my company laptop and i need access to programs that i cant get in safe mode.
Below is the HJT log report and attached is DDS. I could not run GMER in safe mode, let me know what to do. I also see that their is an "iexplore" process running in task manager which is a Trojan, as it launches itself after regular intervals even after i kill the process.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:25:25 PM, on 3/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\amit\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\amit\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amit\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amit\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\taskmgr... Read more

A:infected by malware/spyware.. running PC in safe mode since 2 days..need help

Hello and Welcome to TSF.


Quote:




this is my company laptop




We are sorry but this forum is intended for the home user.

Please contact your company's IT department for help and best of luck with your issues.

This thread shall now be closed.

------------------------------------------------------

1 more replies
Answer Match 57.96%

In step 2 of the self-removal process I need to reboot my computer in safe mode with networking. I do that and soon after my computer logs me off and restarts. What gives?

A:Infected with antivirus security pro - safe mode shuts down computer

I'll report this topic to appropriate helpers.
1. Please let us know what Windows version you have and if it's 32- or 64-bit.
2. Is the computer bootable in any mode?
Hold on there....

3 more replies
Answer Match 57.96%

Hi,
 
I am infected with the System Care Antivirus on a Windows XP machine. When I try to boot into Safe Mode (both with or w/out Networking), I get a Windows blue screen of death. I have removal instructions that I can follow, but those depend on launching Safe Mode. Any suggestions? Is there a rescue disc that I could try?
 
[Note: The machine does boot into normal Windows mode].
 
Thanks!
 
FrisB

A:Infected w System Care Antivirus -- Can't Boot Into Safe Mode

I'll report this topic to appropriate helpers.
Hold on there....

4 more replies
Answer Match 57.96%

I am having the same issue posted by KellyV6726.  I have the "Antivirus security pro" virus but can't follow the fix instructions because it won't let me boot in Safe Mode of any form.   I followed the instructions from Aaflec in KellyV6726's  post and created a FRST.txt file, which I'll paste below.  Since Aaflec took Kelly's FRST file and created a fix file, I am hoping someone can do the same for me - or tell me how to do it.  (I initially posted this issue in the "Am I infected" forum, but received no replies so I'm assuming that was not the right place!) 
 
The contents of my FRST file:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013
Ran by SYSTEM on MININT-K0HBV6E on 01-11-2013 14:12:54
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery
 
The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [nwiz] - nwiz.exe /install
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NVHotkey] - rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
HKLM\...\Run: [PDVDDXSrv] - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [140520 2009-06-24] (CyberLink Corp.)
HKLM\...\Run: [ccApp] - C:\Program Files\Common F... Read more

A:Infected with Antivirus Security Pro and cannot start Windows 7 in Safe Mode

Hello Dinx I would like to welcome you to the Malware Removal section of the forum.Around here they call me Gringo and I will be glad to help you with your malware problems.Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!Please do not run any tools unless instructed to do so.We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.Please do not attach logs or use code boxes, just copy and paste the text.Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.Please provide feedback about your experience as we go.A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", th... Read more

26 more replies
Answer Match 57.96%

My computer started displaying the System Tool pop up and the dreadful blue screen that said there was an error within the computer and the program was closing to save it (paraphrased of course-the screen came and went so fast)it then said if recent hardware had be installed try uninstalling it then it restarted. It went from that to now only being able to boot in safe mode. Now the wireless network is disabled...it says connection status unknown- the dependency service or group failed to start.
DDS (Ver_10-12-12.02) - NTFSx86 MINIMAL
Run by msladydebbie at 23:09:48.71 on Wed 03/02/2011
Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_21
Microsoft? Windows Vista? Home Basic 6.0.6002.2.1252.1.1033.18.2813.2347 [GMT -6:00]

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Users\msladydebbie\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

==... Read more

A:Infected With System Tool Computer Only Boots In Safe Mode

Hello and welcome to Bleeping Computer We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far. Upon completing the steps below another staff member will review your topic an do their best to resolve your issues. If you have already posted a DDS log, please do so again, as your situation may have changed. Use the 'Add Reply' and add the new log to this thread. Thanks and again sorry for the delay. We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scr DDS.pifDouble click on the DDS icon, allow it to run. A small box will open, with an explaination about the tool. No input is needed, the scan is running. Notepad will open with the results. Follow the instructions that... Read more

26 more replies