Win XP - cannot boot into safe mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by pauliwood, Jan 9, 2005.

  1. pauliwood

    pauliwood Private First Class

    That folder is there, yet the program does not appear in Add/Remove programs.

    Must have deleted the program but left behind the folder.


    Delete the folder?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Delete the folder and anything in it and have HJT fix the line for it.

    Then get RegistrarLite install and start searching for those CLSIDs. If you don't know what I mean or need help trying to do that, tell me.
     
  3. pauliwood

    pauliwood Private First Class

    I think that did it, can you check my Hijack log one last time?

    I can't thank you enough for the rapid responses and dedication to fix this problem, along with the other people's posts you have been helping along the way.

    Thanks a million!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! That looks better! And that was after a reboot and running an IE session right! Maybe you should take a quick right now (even with the browser open this time).
     
  5. pauliwood

    pauliwood Private First Class

    Yes, after a re-boot, opened up Avant Browser, went to a couple pages. This log is after opening up IE, then going to ESPN.com and Download.com, then running Hijack with this Avant Browser open.

    Also, chucked the MS Java for Sun Java, and grabbed the Spyware Blocker Programs, thanks for posting that tutorial as well.

    Any special settings for Sygate Firewall, that's what I use.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay looking good! As far as the firewall! You have to police yourself and becareful when you give applications permission to go out or come in. You need to know what the application is before you say yes. Anytime you install something new or uninstall and reinstall you may get a message about some component looking to get out. It's up to you to decide what's good and what's bad and also even if good you can also say no to allowing it access to the internet. I do this last one all the time for applications that I feel have no business needing anything from the net.

    One last comment I also sat on. This line in you HJT:
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe (file missing)

    That would appear to me that something is missing for your WinPcap program. Do you need this?
     
  7. pauliwood

    pauliwood Private First Class

    Yeah, I'm pretty good about having Sygate have every program that needs to access the web ask permission first.

    As for the Service thing, no clue what that is, I can remove that as well then?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. pauliwood

    pauliwood Private First Class

    Not sure, I don't recall installing that program. I suppose I can leave it be for now.

    Also, ran Avast for the first time during a re-boot, and it still found some Trojans in the Windows\system32 folder, is that merely reminants of what we cleaned out, or did they re-spawn do you think?

    Thanks again for all the help!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Malware is real good at leaving stuff all over the place and it is not always easy to find all the pieces. What were the file names that Avast found? Did it fix them?
     
  11. pauliwood

    pauliwood Private First Class

    You know, I forget the names, it wasn't able to repair the files, so I took a chance and deleted them, and have not had any programs fail to run so far.

    Next time, I will write them down should I find anything.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So therefore I assum we are finished here! Right?
     
  13. pauliwood

    pauliwood Private First Class

    Sorry for the late reply, yes, I believe we are all set, thanks again for all your time and help!!

    Couldn't have done it without you.


    Thanks to all the other people on this board who help so many others as well!!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds