I can't start my computer in normal mode.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Organisms, Sep 13, 2005.

  1. Organisms

    Organisms Private E-2

    I'm sad. I don't want to reformat either because then I will loose too much.
    There is not much to show you guys either.
    I'll post a HJT log anyway.
    Logfile of HijackThis v1.99.1
    Scan saved at 8:46:47 PM, on 9/13/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Owner\Desktop\Games\HijackThis\hijackthis.exe

    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - Global Startup: dcnu.exe
    O20 - AppInit_DLLs: repairs.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I will let the spyware geeks check your log file, but it is pretty clean from what I see. Actually, there is so little there probably because you are in some sort of safe or diagnostic mode.

    I would go to start, run and type in msconfig and make sure Normal Startup is checked and not diagnostic or selective. If you have to check Normal Startup, reboot and do a complete scan per our tutorial and let us know how it goes.
     

    Attached Files:

  3. Organisms

    Organisms Private E-2

    I was in selective mode, but when I try to boot with normal mode my computer restarts right before the like choose your user menu pops up.
     
  4. Organisms

    Organisms Private E-2

    This is making me so ****ing frustrated you cannot imagine it.
    At least I didn't have all of my music on my computer, I still have cds. ;(
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I dont understand that. When you select Normal, it should ask to reboot. There might be something in your startup that didnt go away causing this as well. A program like CCLeaner has a startup tool, might be worth a look. Im not aware of spyware that causes this, maybe one of the guys here would know.
     
  6. Organisms

    Organisms Private E-2

    I really have no idea what causes this....
    I probably will have to reformat anyway...
    Can you burn disks in safe mode?
     
  7. theefool

    theefool Geekified

    If I understand correctly, within msconfig, you have selective startup and "Load Startup Items" unchecked?

    But, when you recheck that item, or just use the radial button next to "Normal Startup" the computer shuts you down? Does it shut down immediately? Does it reboot? Do you get a quick blue flicker, then reboot (this may be a bsod error).
     
  8. Organisms

    Organisms Private E-2

    No, I can't startup AT ALL IN NORMAL MODE, only safe mode.
     
  9. theefool

    theefool Geekified

    Another question, I'm assuming you are posting from another computer, and not the computer that can't boot into normal mode, even within msconfig with selective startup with the following unchecked:

    Process System.ini File (unchecked)
    Porcess WIn.ini File (unchecked)
    Load System Services (unchecked)
    Load Startup Items (unchecked)

    I know this is frustrating, I've been in situations, while working on computers at work that get very frustrating. Also, I may repeat questions that others may have asked, I'm only painting a picture for my mind.
     
  10. Organisms

    Organisms Private E-2

    I'm on the comp that can't start in normal mode using safe mode with networking enabled.
     
  11. Organisms

    Organisms Private E-2

    I tried that and it still didn't work, also I'm going to sleep for the night. Signing off at 11 PM EST. Goodbye.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually the below are bad:

    O4 - Global Startup: dcnu.exe
    O20 - AppInit_DLLs: repairs.dll

    I would look for dcnu.exe in the below path:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dcnu.exe

    And repairs.dll is probably in c:\windows\system32
     
  13. Organisms

    Organisms Private E-2

    Dncu.exe is not there.
    Also, I have tried to delete repairs.dll before but it is being used.
     
  14. Organisms

    Organisms Private E-2

    Dammit, **** xxxxxxxxxxxxxxxxxxxxxx [EDIT by chaslang profanities removed! Do not do this again!]
    Donate 100$ to me so I can buy myself DVDs.
    Some might be porno.
     
    Last edited by a moderator: Sep 14, 2005
  15. Organisms

    Organisms Private E-2

    I was joking down there, anyway do you suggest reformat at this point?
     
  16. theefool

    theefool Geekified

    No problem.

    Start HijackThis, then choose the "Open the Misc Tools Section" button. Once the misc tools section comes up, select the "Delete a file on reboot". A window will appear titled "Enter file to delete on reboot...". Migrate to the location of the file you wish to delete, in this case:
    c:\windows\system32\repairs.dll

    Press open
    Then press yes to reboot. Attach another Hijackthis log here:
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to fix the registry entries shown in HJT too:

    O4 - Global Startup: dcnu.exe
    O20 - AppInit_DLLs: repairs.dll

    Also the dcnu.exe needs to be located. It is probably in another Startup folder if not in the last one a gave.
     
  18. Organisms

    Organisms Private E-2

    I gave up. Reformatted.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds