Win XP - cannot boot into safe mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by pauliwood, Jan 9, 2005.

  1. pauliwood

    pauliwood Private First Class

    Have been infected some some nasties. I want to boot into safe mode and run adaware, spybot and goto Trendmicro.com, yet, when i get to the startup option screen, I select safe mode with networking, the computer then re-boots back to the startup option screen.

    Same for all safe mode options.

    Any ideas?

    Thanks in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the stuff below as best as you can. If you cannot boot in safe mode with networking , run the online scans in normal boot mode. As long as you can get into safe mode without networking run the other steps in safe mode. If you can never get into safe mode, tell us that and run everything in normal boot mode.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. pauliwood

    pauliwood Private First Class

    Ok,

    I will do as listed in the sticky files.

    Search & Destory
    Adaware
    Did the Trendmicro, found a few things it was not able to remove.

    Shall I run the new beta Microsoft AntiSpyware as well?

    Thanks for your help.

    Not able to boot into safe mode at all, tried repairing Windows XP to see if that would fix the safe mode boot problem, did not work.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. pauliwood

    pauliwood Private First Class

    I was not aware that you had already ran and tested the microsoft program, was curious of it's capabilities. Looks as if I have my answer. Thanks.

    Ran the Norton test and the trend-micro test, running the rest of the scans before I post my hijack log, thanks for your help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sure the MS Antispyware will be good eventually. When we think the time is right, we will more than likely put it in the list of tools to use.
     
  7. pauliwood

    pauliwood Private First Class

    Ok, how's this for a kick in the nuts, when I finally go to run Hijackthis, good ole Windows gives me:

    Hijackthis has encountered a problem and needs to close. We are sorry for the inconvenience.

    I have re-booted and tried 3 times to run, and all 3 times I get this error message.

    I've tried to run both:

    Do a system scan and save a log file and

    Do a system scan only

    Any ideas? Do I need to break out the sledge hammer? GGrrrrrrrrr.


    Oh yes, cannot boot into safe mode.
     
  8. pauliwood

    pauliwood Private First Class

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that really stinks! I think there may be a way to edit a boot.ini file on your PC to stop this. Do you have your original bootable Windows XP CD so we can try booting to the recovery console?

    The HijackThis problem could be related to some malware.
     
  10. pauliwood

    pauliwood Private First Class

    Yes, I have the original CD, and can boot to the recovery console. Did it last night, wasn't sure where to go from there to change the boot.ini file.

    Thanks, will wait to hear back.
     
  11. pauliwood

    pauliwood Private First Class

    Ok, back in business, used fixboot from recovery console to create new boot options, then changed back in msconfig.


    Still cannot run Hijackthis without getting the Microsoft Error, getting popups as soon as my pc boots.
     
  12. Adrynalyne

    Adrynalyne Guest

    At rcon, type:

    bootcfg /rebuild

    At the Os Load Identifier Question type

    Windows XP

    At the OS Load Options

    For rtm and sp1, type: /fastdetect

    For sp2, type: /noexecute=optin /fastdetect (assuming this isn't an AMD 64 CPU)
     
  13. pauliwood

    pauliwood Private First Class

    Thanks Adrynalyne,

    Did that, got back in, now I just need to get the spyware out of my system, and unfortunately safe mode booting is not working, and Hijackthis cannot complete it's scan.

    Just waiting to hear back from chaslang on the next step to rid my pc of this awful spyware and malware.

    Thanks for your response.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Thanks for jumping in while I was away Adryn! That's where I was head next!

    Any ideas why safe mode boot will not work?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Pauliwood,

    I want you to go here: http://www.merijn.org/files/hijackthis1982.zip

    And get the older version 1.98.2 version of HJT. Yes that's correct the old version. Then unzip the executable (don't overwrite your 1.99 version) somewhere and try to run it. Do you get the same error? If not, post a log from this version.
     
  16. pauliwood

    pauliwood Private First Class

    Got my PC to boot into safe mode. Someone at TweakXp.com suggested:
    If you are using Nero's InCD, upgrade to the latest release.

    I just uninstalled it, and it allowed me to boot into safe mode. Going to retry the previous steps before running Hijack, will download the older version if the newer version continues to give me errors.

    Thansks, I think we are getting there!!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good to know about Nero's InCD! Do you know what version you had and what you upgraded to?
     
  18. pauliwood

    pauliwood Private First Class

    Not sure what version I had. The newest version on their website is 4.3.11.1

    I actually uninstalled the program, figured I had nothing to lose, can always re-install it.

    The Nero package came with my DVD Burner.
     
  19. pauliwood

    pauliwood Private First Class

    Ok, here is my HijackThis log file from the newest verion of Hijack this. Did run the scans from safe mode.

    Thank you!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a load of problems including the lastest VX2 infection. Do the following while I look at your HJT log. It will take a while to run the find.bat file mentioned below. Make sure you wait for it to complete.

    Download the below tools:

    http://www.downloads.subratam.org/DllCompare.exe

    Pocket KillBox


    VX2.BetterInternet Finder XP/2k - Version Msg126

    Generic Find It Tool - NT/2000/XP


    Extract all the files from the Generic Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also have another problem we need get fixed before attacking the VX2 issue.

    Please download the following tool: LSP - Fix

    Now run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the calsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move calsp.dll into the Remove section.

    Now, do the same for aklsp.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    Also, you need to disable Spybot's TeaTimer function or it will get in our way. You do this by clicking Mode, Advanced, Tools, Resident screen. And disable all the Spybot resident protections for now.
     
    Last edited: Jan 11, 2005
  22. pauliwood

    pauliwood Private First Class

    Did as you said for LSP, disabled Tea Timer from spy Bots, running Findit now, will post the file you requested after it completes.


    Whew, I knew I got hit hard, just not this hard.

    Thanks for all your help and all the other board moderators and helpers.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You got hit worse than you think. This is going to take a number of steps and reboots to clear up completely. Here is another part of the cleanup:

    Some of the below stuff (like the O1 - Hosts lines and the yuoiyo.exe or similar process) will come back it is part of the VX2 infection we will be working on repairing.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    D:\WINDOWS\System32\msupd4.exe
    D:\WINDOWS\System32\yuoiyo.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://D:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O2 - BHO: (no name) - {08D9BCA0-C530-BF59-EB2E-E3BF17686296} - D:\WINDOWS\System32\mgqiazos.dll
    O2 - BHO: (no name) - {1419B852-BB22-7B3C-0B4B-1EF0C318D7AD} - D:\WINDOWS\System32\yladwqae.dll
    O2 - BHO: - {264DF37D-E5B9-4735-BE12-518D20F66341} - D:\WINDOWS\lbbho.dll
    O2 - BHO: (no name) - {27E0B508-6B0E-EA49-BE91-0687B28990CE} - D:\WINDOWS\System32\kmdablve.dll
    O2 - BHO: (no name) - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - (no file)
    O2 - BHO: (no name) - {6DFE48BF-3DC4-DA46-ADA2-851A5F1E31CD} - D:\WINDOWS\System32\icprlcrv.dll
    O2 - BHO: (no name) - {84865702-83C9-6C50-F3CF-98512A97239A} - D:\WINDOWS\System32\tkkwqcfp.dll
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
    O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
    O2 - BHO: (no name) - {A8BBC0A6-E13D-36C0-C294-202D9BE199DA} - D:\WINDOWS\System32\bwfcjxrm.dll
    O2 - BHO: (no name) - {CAA1DA65-158B-728E-10E8-D5382B0590C7} - D:\WINDOWS\System32\hfxvjzpa.dll
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
    O23 - Service: Miscrosoft Updates Service 4 - Unknown - D:\WINDOWS\System32\msupd4.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    D:\Program Files\Toolbar <--- the whole folder
    D:\WINDOWS\System32\msupd4.exe
    D:\WINDOWS\System32\yuoiyo.exe
    D:\WINDOWS\System32\mgqiazos.dll
    D:\WINDOWS\System32\yladwqae.dll
    D:\WINDOWS\lbbho.dll
    D:\WINDOWS\System32\kmdablve.dll
    D:\WINDOWS\System32\icprlcrv.dll
    D:\WINDOWS\System32\tkkwqcfp.dll
    D:\WINDOWS\System32\bwfcjxrm.dll
    D:\WINDOWS\System32\hfxvjzpa.dl

    Now reboot in normal mode and post a new HJT log.

    I guess you logged out for the night! So I have to tell you that the find.bat log may not be valid anymore because these VX2 infections normally mutate at each reboot. But it's okay if you already ran it. Post the output anyway. Some of the data will be valid and need cleanup. But NOTE: from now on if you are asked to post a log from find.bat, DO NOT REBOOT afterwards. You will have to wait for us to post a fix for you. You can disconnect from the Internet but no reboots. Otherwise it will prolong the cleanup.
     
    Last edited: Jan 12, 2005
  24. Adrynalyne

    Adrynalyne Guest

    Other than what you are already going through?

    Believe it or not--bad drivers can do this.
     
  25. pauliwood

    pauliwood Private First Class

    Chaslang,

    Ok, did not know that about Findit, actually fell asleep while it was running. I will run a new one today while at work and post it around 8pm EST.

    Meanwhile, ran Hijackthis, would not let me stop the msupd4.exe process.

    Removed everything in the next step.

    Rebooted into safe mode, did not find any of the .dll's that you mentioned in the D:\windows\systems32 folder
    did not see the D:\Program Files\Toolbar folder

    Deleted msupd4.exe, it would not allow me to delete yuoiyo.exe

    Here is the new Hijackthis log file and the Findit log file.
     

    Attached Files:

  26. pauliwood

    pauliwood Private First Class

    Newest FindIt Log file, will keep computer on throughout the day, just disconnecting from the web.

    Thanks again for all the help and support.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HJT and after exiting ALL browser windows (including this one) Fix the below items:
    O2 - BHO: (no name) - {08D9BCA0-C530-BF59-EB2E-E3BF17686296} - (no file)
    O2 - BHO: (no name) - {1419B852-BB22-7B3C-0B4B-1EF0C318D7AD} - (no file)
    O2 - BHO: (no name) - {27E0B508-6B0E-EA49-BE91-0687B28990CE} - (no file)
    O2 - BHO: (no name) - {6DFE48BF-3DC4-DA46-ADA2-851A5F1E31CD} - (no file)
    O2 - BHO: (no name) - {84865702-83C9-6C50-F3CF-98512A97239A} - (no file)
    O2 - BHO: (no name) - {A8BBC0A6-E13D-36C0-C294-202D9BE199DA} - (no file)
    O2 - BHO: (no name) - {CAA1DA65-158B-728E-10E8-D5382B0590C7} - (no file)

    Now Exit HJT!

    Here are the files that we need to delete using Killbox.

    D:\WINDOWS\System32\ir42l5ho1.dll
    D:\WINDOWS\System32\k444lehq1h4e.dll
    D:\WINDOWS\system32\guzygz.dll
    D:\WINDOWS\system32\pumzpm.exe
    D:\WINDOWS\system32\zpuozu.dll
    D:\WINDOWS\system32\quyaqy.dat
    D:\WINDOWS\system32\yuoiyo.exe
    and D:\WINDOWS\System32\guard.tmp

    And here is how you need to do it.

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Replace on Reboot.

    Now you are going to repeat the below steps for every file except D:\WINDOWS\System32\guard.tmp (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in D:\WINDOWS\System32\ir42l5ho1.dll


    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Use Dummy.
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste D:\WINDOWS\System32\guard.tmp into the box. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to
    reboot Normally.

    After it reboots get another findit.bat log and post it. Also post a new HJT log.

    Also run Windows Explorer and look in the D:\WINDOWS\System32 folder and tell me if you see the guard.tmp file. If so, right click on it and select Delete. Tell me if that works?
     
  28. pauliwood

    pauliwood Private First Class

    Ran HJT, ran Pocket Killbox, re-booting now and will be sending a new HJT log and findit.log


    Thanks!
     
  29. pauliwood

    pauliwood Private First Class

    Upon re-boot, a DOS Window opened with this in the title bar:

    D:\WINDOWS\System32\pumzpm.exe

    Then the error message

    Title Bar: 16 bit MS-DOS Subsystem

    D:\WINDOWS\System32\pumzpm.exe
    The NTVDM CPU has encountered an illegal instruction.
    CS:07cc IP:da7c OP:fe ff 00 00 00 Choose 'Close' to terminate application.

    Two options, close or ignore

    Did I delete/replace something I shouldn't have?

    Please advise, thanks!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! I expected that!
    Notice the file name is what we deleted: D:\WINDOWS\system32\pumzpm.exe


    I need the last HJT and find.bat logs!
     
  31. pauliwood

    pauliwood Private First Class

    Ok, I'll click ignore and run hijack and findit!
     
  32. pauliwood

    pauliwood Private First Class

    Also run Windows Explorer and look in the D:\WINDOWS\System32 folder and tell me if you see the guard.tmp file. If so, right click on it and select Delete. Tell me if that works?



    Appears that it worked, the file deleted.

    Running Hijackthis now.
     
  33. pauliwood

    pauliwood Private First Class

    Latest Hijackthis log file.

    findit log on it's way!
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    D:\Documents and Settings\All Users\Start Menu\Programs\Startup\ygpuyp.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {08D9BCA0-C530-BF59-EB2E-E3BF17686296} - (no file) <---- did you forget to do all of these last time
    O2 - BHO: (no name) - {1419B852-BB22-7B3C-0B4B-1EF0C318D7AD} - (no file)
    O2 - BHO: (no name) - {27E0B508-6B0E-EA49-BE91-0687B28990CE} - (no file)
    O2 - BHO: (no name) - {6DFE48BF-3DC4-DA46-ADA2-851A5F1E31CD} - (no file)
    O2 - BHO: (no name) - {84865702-83C9-6C50-F3CF-98512A97239A} - (no file)
    O2 - BHO: (no name) - {A8BBC0A6-E13D-36C0-C294-202D9BE199DA} - (no file)
    O2 - BHO: (no name) - {CAA1DA65-158B-728E-10E8-D5382B0590C7} - (no file)
    O4 - Global Startup: ygpuyp.exe

    Then see if you can find this file with windows explorer
    D:\Documents and Settings\All Users\Start Menu\Programs\Startup\ygpuyp.exe

    If so, right click on it and try to delete it. Tell me if all those steps work.
     
  35. pauliwood

    pauliwood Private First Class

    O2 - BHO: (no name) - {08D9BCA0-C530-BF59-EB2E-E3BF17686296} - (no file) <---- did you forget to do all of these last time
    O2 - BHO: (no name) - {1419B852-BB22-7B3C-0B4B-1EF0C318D7AD} - (no file)
    O2 - BHO: (no name) - {27E0B508-6B0E-EA49-BE91-0687B28990CE} - (no file)
    O2 - BHO: (no name) - {6DFE48BF-3DC4-DA46-ADA2-851A5F1E31CD} - (no file)
    O2 - BHO: (no name) - {84865702-83C9-6C50-F3CF-98512A97239A} - (no file)
    O2 - BHO: (no name) - {A8BBC0A6-E13D-36C0-C294-202D9BE199DA} - (no file)
    O2 - BHO: (no name) - {CAA1DA65-158B-728E-10E8-D5382B0590C7} - (no file)



    Nope, I checked those to be fixed last time.

    I will re-run the steps as you indicated. Shall I send the findit log after it finishes, or do these steps first?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normally! I would suggest that during cleanup steps you should not even be connected to the internet. And I hope you do exit all browsers (IE) and Windows Explorer sessions before you run HJT. It will have problems fixing things if you do not.

    Wait for find.bat to complete and then fix the stuff with HJT and tell me if you were able to do what I asked (stop process, fix HJT lines, delete file).

    Then we will see what to do next.
     
  37. pauliwood

    pauliwood Private First Class

    All of the above steps worked, ygpuyp.exe was not found in the start menu, so I could not click it to delete it. Have not re-booted, waiting for your advice.

    And yes, I make sure to exit out of all browsers IE and File Manager Explorer.

    Thanks!
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Reboot! And then post a new HJT log after reboot. Let me know if anymore error messages occur!
     
  39. pauliwood

    pauliwood Private First Class

    Those darn no files are back in O2 - BHO's !!!

    Got the same error messgae as before for pumzpm.exe and the same error message popped up for yuoiyo.exe
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run PocketKillbox, Copy and Paste D:\WINDOWS\System32\yuoiyo.exe into the box. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No to the quesion about reboot.

    Then exit Killbox!


    Copy and paste the information in the below quote box to notepad. Save it to your Desktop as type "all files" and name it fixvx2.reg. Doubleclick it and grant it permission to merge in the registry entries.


    Now reboot! Post a new HJT log. Any messages?

    After reboot look for this file:
    D:\WINDOWS\System32\yuoiyo.exe

    If found, try to delete it. Tell me the results.
     
  41. pauliwood

    pauliwood Private First Class

    Ok, did everything, re-booted, found that file, deleted it without error, booted without error messages at startup.

    Shall I re-boot and run hijackthis again?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Let's be safe and make sure we got all of this nasty crap!
     
  43. pauliwood

    pauliwood Private First Class

    Hopefully my final Hijacklog and final burden on your time :)

    I thought I had my pc well protected, need to read the how to protect yourself tutorial I guess!
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not yet!!! You still have
    O2 - BHO: (no name) - {08D9BCA0-C530-BF59-EB2E-E3BF17686296} - (no file)
    O2 - BHO: (no name) - {1419B852-BB22-7B3C-0B4B-1EF0C318D7AD} - (no file)
    O2 - BHO: (no name) - {27E0B508-6B0E-EA49-BE91-0687B28990CE} - (no file)
    O2 - BHO: (no name) - {6DFE48BF-3DC4-DA46-ADA2-851A5F1E31CD} - (no file)
    O2 - BHO: (no name) - {84865702-83C9-6C50-F3CF-98512A97239A} - (no file)
    O2 - BHO: (no name) - {A8BBC0A6-E13D-36C0-C294-202D9BE199DA} - (no file)
    O2 - BHO: (no name) - {CAA1DA65-158B-728E-10E8-D5382B0590C7} - (no file)

    Try fixing again. Then scan again. I don't need a log just tell me if they are gone. We may need another reboot in between and for you to open and close a browser to be sure.
     
  45. pauliwood

    pauliwood Private First Class

    Nope. Ran Hijackthis, deleted them, re-booted, ran Hijackthis, and they are back.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall MS Antispyware and then try fixing them. Don't forget the reboot inbetween. If that does not work will have to manually search the registry for those CLSIDs and then delete them. We should use Registrar Lite to do that.
     
  47. pauliwood

    pauliwood Private First Class

    I uninstalled MS Spyware the first night we started attacking these varmits.....I'll double check add/remove programs to be sure.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Look at your HJT log:

    O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
     
  49. pauliwood

    pauliwood Private First Class

    Hmmm....the first night you told me it gives false positives, I went to the start button, programs, then the MS folder and used the uninstaller program.

    Shall I delete it from the Hijackthis program?
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this folder on your hard disk: D:\Program Files\Microsoft AntiSpyware ?
    Do you see the program in Add/Remove Programs?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds