Posted 26 April 2007 - 06:32 PM
Can someone please enlighten me as to how there are shifty programs running while I am in safe mode? Does safe mode have its own .ini? Is it possible to have a script run on my machine and manipulate the .ini to allow non-essential system files to run in safe mode? I am on my laptop right now, and it is difficult to get a hjt log posted seeing as I can only run in safe mode and the usb drivers are not there to support my flash drive. If there is something specific that would help from any type of log I would be happy to type it out, but I will throw this tower in my aquarium before I type the whole log.
The proc in question is IEXPLORE.EXE and there are multiple instances running at all times. It seems to be in cahoots with a drwtsn32.exe proc that I think should not be there because I am not utilizing any debugging features (unless safe mode includes one). With that said, 64% of my CPU is taken up by csrss, but I am in safe mode; minimal.
Now the issue that really pisses me off is the fact that I cannot start services from the cmd prompt.
I enter; at xx:xx /interactive cmd.exe, press enter and it flips me the bird and says "service not started".
However, I am able to launch spybot from the not so clean cmd. (The mouse with a relentless hour-glass-lamprey turns into a full hour glass when hovered above the start menu not allowing me to right or left click... real cute). After spybot runs it finds some junk and gets hung up while shreding one .dll and one reg key.
winsys2f.dll courtesy of smitfraud-c
IE Set reg key from what SB calls Win32.VB.ahq
One last inquiry. SB tells me winsys2f.dll is located in a directory that does not exsist on my machine (I did trying view all folders). WTF?
I am horribley confused, but intrigued. So please let me know if you can offer up any suggestions. If someone could tell me a way to get into a clean windows enviorment I have the SW to blast this thing, but I cannot get it to stop running!! ANY comments, empathy or suggestions are welcome. Thanks, and as this is my first posting on the internet ever!! I am sort of excited to hear from you.