Can't Go To Safe Mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by arcueil_1, Oct 20, 2005.

  1. arcueil_1

    arcueil_1 Private E-2

    During the last 24 hours, I have tried countless times to restart on Safe Mode in order to do some proper basic checks for spyware, bots and viruses (I suspected some kind of infection after noticing an unusual number pop-ups being blocked). Obviously if I can't go to Safe Mode, I can't do the checks as per instucted on the sticky by Major Attitude. (I have all of the programs listed there and have once before solved a somewhat serious issue here, with no problems, so I'm familiar with the process.) Anyhow, I did all the checks on regular mode regardless (with the sole exception of the on-line scans; I used Anti-Vir instead) and came up with absolutely nothing. I think that HJT logs are useless if I can't go to Safe Mode (I may be wrong), so I also think that it is vital that I figure out how to be able to go to SM. All I get now is absolutely nothing when I press F8 upon restart. Once I give up and let go of the button, the laptop (Toshiba L10) starts in normal mode. Also, the settings on all the programs are maxed out, for maximum depth of scan... What gives? Please help. Thanx.

    PS: BTW, this computer is new -- only two or three weeks old -- the old computer being a Toshiba A50.
     
  2. arcueil_1

    arcueil_1 Private E-2

    I forgot to say that I use XP SP2 fully updated, Pentium M CPU 1.6 and 80G hard disk.
     
  3. arcueil_1

    arcueil_1 Private E-2

    I also forgot to read the new version of Major Attitude's sticky. In it, I found a link to instructions (from Symantec) on how to start on SM by using msconfig (i.e. without using the F8 key). I will try that now and report on the results.
     
  4. arcueil_1

    arcueil_1 Private E-2

    OK... I was able to get into Safe Mode by using msconfig, with no problems. (Before I did that, I turned off System Restore and enabled viewing of hidden files [3 steps], as per instructed by Major Attitude.) I performed the following checks:

    1) CCleaner: all cleaned up and no issues found.
    2) AntiVir: negative.
    3) Stinger: negative.
    4) Ad-Aware: negative.
    5) VX2 Cleaner: negative.
    6) Spybot -- Search & Destroy: negative.
    7) Kill2Me: negative.
    8) CWShredder: positive [FOUND: CWS.MSconfig]. (I didn't attempt repair because I want to wait for a reply first.)
    9) HJT: scanned and saved log.

    The computer is still blocking more pop-ups than normal... something may not be right. Please advice if I should post an attachment of the HJT log. Thanx.
     
  5. arcueil_1

    arcueil_1 Private E-2

    Please note that the XP I use is the Chinese (PRC) version... Chaslang may remember me from about three months ago.
     
  6. arcueil_1

    arcueil_1 Private E-2

    I performed the HJT scan again, this time on Normal Mode (the proper way, right?) and saved the log. Sorry for the multiple little posts!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean you found my sticky! ;) Glad to see the new tip helped you get into safe mode.

    Let CWShredder fix whatever it finds.

    Follow the below to post a HijackThis log!

    Make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis
     
  8. arcueil_1

    arcueil_1 Private E-2

    Hi, Chaslang. Right! it was your sticky. :)

    I performed all the checks again and the results were exactly the same as before. However, this time I removed CWS.MSConfig with CWShredder. I also made a new scan with HJT and it's enclosed as an attachment. Note: I haven't noticed any more excessive pop-ups being blocked, so maybe things are OK now... What do you think?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. arcueil_1

    arcueil_1 Private E-2

    Thank you, Chaslang. I'll look into using a different firewall right away. I'll probably end up using the second one on the list. Is that program too complex? Also, do I simply turn off the MS XP Firewall after installing the new firewall? BTW, do you know what the CWS.MSConfig thing that CWShredder picked up and removed is?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All firewalls add some complexity to your administration work on your PC. It is a necessary evil.

    Yes! That is mentioned in the How to protect thread.

    One of the many,many forms of CWS hijackers. See this and you will see what I mean by many:

    http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082843
     
  12. arcueil_1

    arcueil_1 Private E-2

    Thanx for your help and all your answers. You fellars at Major Geeks are the best. Cheers.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds