This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Serious problem with safe mode

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just reformatted my computer and the all of a sudden I slowed down and started getting all these warnings. Symantec kept picking up these viruses. I suppose it got them all because some are in quarantine and when I do a full scan I don't get any, except one. C:\\WINDOWS\SYSTEM32\winnqz32.dll keeps getting spotted and Symantec can't get rid of it. Ad-aware didn't pick anything up, but Ewido got a bunch of Trojans and other adware. Ewido successfully quaranteend all but one. Unfortunately I didn't save a log and I forgot what its name was. winnqz32.dll keeps getting detected. I ran Ewido again and saved a log. A lot of the Trojans were back and i suspect winnqz32.dll is involved. Here is my latest Ewido and HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 2:21:29 AM, on 7/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Comodo\Personal Firewall\cmdagent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Symantec\SAV8\vptray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Comodo\Personal Firewall\CPF.exe
C:\PROGRA~1\Symantec\SAV8\DefWatch.exe
C:\Program Files\Comodo\LaunchPad\CLPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\CURITY~1\WACLT~1.EXE
C:\PROGRA~1\COMMON~1\SKS~1\userinit.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Symantec\SAV8\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\runner\Desktop\Hijackthis\HijackThis.exe
C:\Program Files\Comodo\Personal Firewall\cpfupdat.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - URLSearchHook: (no name) - {64B411E1-A727-A6D0-069B-FB4A3283A1BF} - C:\WINDOWS\system32\dkmlbu.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\Symantec\SAV8\vptray.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Comodo Personal Firewall] C:\Program Files\Comodo\Personal Firewall\CPF.exe sysrestart
O4 - HKLM\..\Run: [Comodo Launch Pad Tray] C:\Program Files\Comodo\LaunchPad\CLPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uuvs] C:\WINDOWS\CURITY~1\WACLT~1.EXE
O4 - HKCU\..\Run: [Raao] "C:\PROGRA~1\COMMON~1\SKS~1\userinit.exe" -vt yax
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Win32 Classes -
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O20 - AppInit_DLLs: notepad.dll C:\WINDOWS\system32\notepad.dll
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Personal Firewall\cmdagent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\Symantec\SAV8\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\Symantec\SAV8\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 2:15:56 AM 7/4/2006

+ Scan result:



C:\System Volume Information\_restore{EF4F0590-D523-4E92-8F7A-5967DB591573}\RP13\A0003779.exe -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EF4F0590-D523-4E92-8F7A-5967DB591573}\RP13\A0003778.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EF4F0590-D523-4E92-8F7A-5967DB591573}\RP13\A0003777.exe -> Downloader.PurityScan.cq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{EF4F0590-D523-4E92-8F7A-5967DB591573}\RP13\A0003776.exe -> Dropper.Small : Cleaned with backup (quarantined).
:mozilla.9:C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.7:C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.


::Report end
Hello Cgull and Welcome to TomCoyote,

Please do the following:

Please set your system to show all files; please see here if you're unsure how to do this.


Scan with HijackThis. Place a check against each of the following:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKCU\..\Run: [Uuvs] C:\WINDOWS\CURITY~1\WACLT~1.EXE
O16 - DPF: Win32 Classes -
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O20 - AppInit_DLLs: notepad.dll C:\WINDOWS\system32\notepad.dll

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\CURITY~1\WACLT~1.EXE<=file (starts with WACLT and located in folder that starts with CURITY)
C:\WINDOWS\system32\notepad.dll<=file
Exit Explorer.

Please go to Panda ActiveScan.
Once you are on the Panda site click the Scan your PC button
A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, by using Add Reply.
Let us know if any problems persist.
When fixing files with HijackThis, this error occured: An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: notepad.dll C:\WINDOWS\system32\notepad.dll) Error #5 - Invalid procedure call or argument Please email me at [removed], reporting the following: * What you were trying to fix when the error occurred, if applicable * How you can reproduce the error * A complete HijackThis scan log, if possible Windows version: Windows NT 5.01.2600 MSIE version: 6.0.2900.2180 HijackThis version: 1.99.1 This message has been copied to your clipboard. Click OK to continue the rest of the scan. Also, neither files you asked me to delete in explorer were there. Should I go ahead with the scan you suggested?
ok so here is my Active Scan log:


Incident Status Location

Adware:Adware/PurityScan Not disinfected C:\WINDOWS\SYSTEM32\dkmlbu.dll
Virus:Trj/DNSChanger.GG Disinfected C:\WINDOWS\TEMP\win10.tmp.exe
Virus:Trj/DNSChanger.GG Disinfected C:\Documents and Settings\runner\Local Settings\Temporary Internet Files\Content.IE5\O1UHKHMN\L[1].exe
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\runner\Application Data\Mozilla\Firefox\Profiles\u72xa98j.default\cookies.txt[.advertising.com/]


And here is my new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:28:19 AM, on 7/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Personal Firewall\cmdagent.exe
C:\PROGRA~1\Symantec\SAV8\vptray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Comodo\Personal Firewall\CPF.exe
C:\Program Files\Comodo\LaunchPad\CLPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Symantec\SAV8\DefWatch.exe
C:\PROGRA~1\COMMON~1\SKS~1\userinit.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Symantec\SAV8\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\??curity\w?aclt.exe
C:\Documents and Settings\runner\Desktop\Hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {64B411E1-A727-A6D0-069B-FB4A3283A1BF} - C:\WINDOWS\system32\dkmlbu.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\Symantec\SAV8\vptray.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Comodo Personal Firewall] C:\Program Files\Comodo\Personal Firewall\CPF.exe sysrestart
O4 - HKLM\..\Run: [Comodo Launch Pad Tray] C:\Program Files\Comodo\LaunchPad\CLPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Raao] "C:\PROGRA~1\COMMON~1\SKS~1\userinit.exe" -vt yax
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Personal Firewall\cmdagent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\Symantec\SAV8\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\Symantec\SAV8\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Usually ewido gets rid of the Purity Scan problem.

Reboot your computer into SafeMode. You can do this by restarting
your computer and continually tapping the F8 key until a menu appears.

Use your up arrow key to highlight SafeMode then hit enter.
IMPORTANT: Do not open any other windows or
programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode.

Please post (reply) with ewido report scan and hijackthis log.
Try this and see if this works.

Download BootSafe
Save it to the Desktop.
Double click the BootSafe icon to start the program.
Select Safe Mode – Minimal
Click the Reboot button


Now, run BootSafe once again
Select: Normal Restart
Click the Reboot button for the computer to reboot in Normal Mode.
Umm…. The exact same thing happens in safe mode. Just a black screen with safe mode in all four corners. A text box does pop up but it goes away before I can read anything. I must note though that my computer is now stuck in safe mode. Clt+Alt+Del lets me restart but even when I hit F8 and reboot in normal mode it goes back to the black safe mode. I'm on my Dad's computer right now.
Have the Windows xp cd ready.


Please do the following:
  • Put in XP cd
  • Shut computer down
  • start it back up again
  • Rapidly hit the f12 button
  • You should see a boot screen window pop up
  • Highlight your cd drive with the arrow keys and then hit enter
  • you will get a little message that says "press any key to boot off the cd" Make sure to press a key quickly.
  • Your computer should now be booting from the cd. (Illukka, if he gets an error at this point that his computer doesn't have a HDD, tell me and I'll give you the steps)
  • your screen should now look like this:
    [external image: Posted Image]
  • Press the "R" button
  • You should now get a screen like this:[external image: Posted Image]
  • Unless you have a special config, press "1"
  • then it will ask for your admin password. If you didn't set one, just press the enter key.
  • If all is well, you will get this prompt: c:\windows>_
  • at this point, type in:
    fixboot c:
  • then press the "y" key and hit the enter button
  • Take out the xp cd when it is done and restart your computer.
Hopefully it will work now.
If not, don't worry, there's more to try :)
I put in my xp disc and nothing happens. I restart and hit F12 till it starts beeping and nothing happens. I shut down and turn back and and hit F12 till it starts beeping and nothing happens. I'm not sure if this is the reason, but I have a pirated copy of XP.
I am afraid that I cannot help you. You need to obtain legal copy of Windows. I volunteered at a place which had purchased a computer from dealer which had pirated Windows XP. I could never install the Windows updates and the computer was crippled and susceptible to infections. The organization got rid of the computer and bought new one. Although at least they did not pay for the other computer because I discovered the Windows was pirated.
What about my other options? Are you telling me that you just basically had me shut down my own computer? There must be another way.
I did not know you had pirated Windows. I was trying to help. But if the disk will not work, I cannot help. I am sorry. I am also saying that even if I could, your computer would be at risk from what I experienced in the past. You need to have legal copy of Windows.
If I go into msconfig and under the BOOT tab uncheck the safe mode I can get back into normal windows. I am having trouble from here getting it to stay that way though. Should I use that dayam Boot program to reboot normally and then change my msconfig from custom to normal boot?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI