In selective startup mode, next step?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kingaling, Mar 13, 2005.

  1. kingaling

    kingaling Private E-2

    What a mess.

    Windows XP SP1 Professional is the OS.
    Browser was hijacked, could not access internet. Ran Ad-Aware immediately, quarantined a ton of stuff, but was unable to get online. This has been going on for days. I know I will forget stuff that I have done.

    Most recent, followed as much of the READ ME FIRST post as I could.
    I have had to download a ton of stuff on my Mac and burn CDs.

    With system restore disabled, hidden files enabled.
    In safe mode,
    Ran Stinger- nothing found
    Ran CCleaner
    Ran Adaware SE without plug in (Mac would not load)
    Ran Spy Bot without DSO exploit (Mac would not load)- nothing found except DSO exploit
    Ran CWShredder
    Ran Kill2me
    Ran Avast!- one ancient virus found from 8/15/03 in backup files
    Ran Winsockfix and repaired internet connection.
    Went to Trend Micros Scan Online- found three things it could not fix
    ceres.dll, CUUSAPI.DLL, irsrvs\mfiltis.dll

    Other info, in the beginning of this process, I had the about:blank hijack, with Workstation Net Login. Hijack This took care of that.
    My question- I am still in selective startup mode, on the startup items, ffisearch and desktop.exe are disabled, but there along with NEWDOT~1. What next?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are probably having a problem accessing the internet due to NEWDOT~1.
    If you have a method to get programs onto this PC, download and install, Microsoft® Windows AntiSpyware Make sure you update it. But I would recommend not scanning immediately. After install and update, I would boot into safe mode and run a full scan. It will possible take care of a few other problems you mentioned. After that, follow the steps below.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. kingaling

    kingaling Private E-2

    So i got impatient- went online with the afflicted PC updated everything to the specs, and already had copy of MS Antispyware started the process again. Changed the startup process one at a time, starting with the desktop.exe. Rebooted in safe mode, ran all the stuff i was supposed to. Ran Hijack this and fixed the problem line (thouroughly read it, I have a good idea now of what is legitimate). Did this for the ffisearch again. There are gone from the startup process. I will run Hijack This - in safe mode or not?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is always run in normal mode unless a specific request for a safe mode log is made. Please reboot you PC once and bring it up in normal mode. Then open and close a few broweser sessions. Then exit all browser sessions and get a HJT log and post it as an attachment per my instructions.
     
  5. kingaling

    kingaling Private E-2

    Here it is- I had a little trouble getting here. I hope this is done correctly. Thanks for helping.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds