This is my Logs attached. please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by adzimhilman, Jul 4, 2013.

  1. adzimhilman

    adzimhilman Private E-2

    I have some problem with my laptop, when I scan my system, my Avira detect some virus named TR/Crypt.XPACK.Gen3. I don't know how to fix it, my Avira only detect but can't take an action about this, when I try to update my antivirus but it always found an error. My system run slower than before. I need some help, I know guys, you're the best about this.. thank's for helping me
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    
    :Services
    SSHNAS
    IBUpdaterService
     
    :Files
    C:\Documents and Settings\Zim zim HiIman adzim\Application Data\ilividmoviestoolbardla
    C:\Documents and Settings\Zim zim HiIman adzim\Application Data\searchresultstb
    C:\Documents and Settings\Zim zim HiIman adzim\Local Settings\Application Data\iLivid
    C:\Documents and Settings\All Users\Application Data\Wincert
    C:\Documents and Settings\All Users\Application Data\IBUpdaterService\ibsvc.exe
    C:\Documents and Settings\All Users\Application Data\IBUpdaterService
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Wincert\WIN32C~1.DLL
    C:\PROGRA~1\MOVIES~1\Datamngr\mgrldr.dll
    C:\Users\user\AppData\Local\Smartbar\Application\QuickShare.exe
    C:\Users\user\AppData\Local\Smartbar
    C:\Program Files (x86)\Search Settings
    C:\Documents and Settings\Administrator\Application Data\searchqutoolbar
    C:\Documents and Settings\All Users\Application Data\Babylon
    C:\Documents and Settings\hilman\Application Data\Mozilla\Firefox\Profiles\3zms4w46.default\bProtector_extensions.sqlite
    C:\Documents and Settings\hilman\Application Data\Mozilla\Firefox\Profiles\3zms4w46.default\searchplugins\funmoods.xml
    C:\Documents and Settings\hilman\Application Data\searchquband
    C:\Documents and Settings\hilman\Local Settings\Application Data\Google\Chrome\User Data\Default\bProtector Web Data
    C:\Documents and Settings\hilman\Local Settings\Application Data\Google\Chrome\User Data\Default\bprotectorpreferences
    C:\Documents and Settings\Zim zim HiIman adzim\Application Data\BabSolution
    C:\Documents and Settings\Zim zim HiIman adzim\Application Data\Babylon
    C:\Documents and Settings\Zim zim HiIman adzim\Local Settings\Application Data\Babylon
    C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
    C:\WINDOWS\Tasks\Automatic Maintenance.job
    C:\Documents and Settings\Zim zim HiIman adzim\Local Settings\Temp\*.*
    
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=-
    
    [HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-1008\Software\Microsoft\Windows\CurrentVersion\run]
    "MSMSGS"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Babylon]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Prod.cap\ (Claro)
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\DataMngr]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{99079a25-328f-4bd4-be04-00955acaa0a7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-1008\Software\Datamngr]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-1008\Software\DataMngr_Toolbar]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-500\Software\Blabbers]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-500\Software\DataMngr]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-500\Software\DataMngr_Toolbar]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531}]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
    [-HKEY_USERS\S-1-5-21-2052111302-507921405-839522115-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\SYSTEM\CurrentControlSet\Services\IBUpdaterService]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\CurrentControlSet\Services\SSHNAS]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. adzimhilman

    adzimhilman Private E-2

    my system run faster than before,my mozilla homepage return to first mozilla homepage. in my task manager the processes change to normal, from 50 processes to 45 processes (I really don't know about this, but I remember that my processes increase to 50 until 52 when I started got malware problem).
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks much better now but you have v9 infecting Google Chrome. Back up your Chrome bookmarks and then uninstall Chrome. Then delete the below folder:

    C:\Documents and Settings\Zim zim HiIman adzim\Local Settings\Application Data\Google\Chrome\

    Then you can redownload and reinstall Chrome from the below link:

    Google Chrome 27.0.1453.116 Stable



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  5. adzimhilman

    adzimhilman Private E-2

    I have done uninstall my google chrome and delete this folder :
    C:\Documents and Settings\Zim zim HiIman adzim\Local Settings\Application Data\Google\Chrome\
    but I have another problem.. I found some TR/Crypt.XPACK.Gen3 when I scan with my Avira at this folder :
    C:\WINDOWS\SoftwareDistribution
    My avira only detect but can not take any action.
    Another problem is my Avira antivirus can not do an update. It always failed when reach 100%. What should I do ?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just a false detection. Notice the below lines in your log [WARNING] ''. This detection is probably an error. Please send us this file immediately for further analysis.

    Uninstall it and then reboot. After reboot, redownload and reinstall. You can get the paid and free versions form the appropriate links below:

    Avira AntiVir Premium 2013 13.0.0.3737

    Avira Free Antivirus 2013 13.0.0.3737
     
    Last edited: Jul 5, 2013
  7. adzimhilman

    adzimhilman Private E-2

    When I have some lag then I open task manager, in applications column there is some unknown program has running, it named Sysfader and Notifier. It shown for a while and immediately disappear. And my system run slower again.I don't know what is that..
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sysfader is part of Windows. It has been know to cause slowdowns. See the below:

    http://beyondteck.blogspot.com/2006/05/how-to-stop-sysfaderexe-error.html

    Notifier is a process name used by many dozens of legit programs. Not sure which one you have.

    Do you still have MGtools installed? That is did you run the final instructions. I just noticed something that was cleaned up by my last fixed but it may not have fully gone away. You never allowed HijackThis to run properly. That is you never clicked the Accept button twice per the instructions in the READ & RUN ME FIRST. If you had other windows open ( including your browser ) you may not have noticed the popup notification because it does not pop to the top.

    Uninstall the below junk. This may take care of the items I just noticed.
    Movies Toolbar for Firefox (Dist. by Bandoo Media, Inc.)
    Movies Toolbar for Internet Explorer (Dist. by Bandoo Media, Inc.)
     
  9. adzimhilman

    adzimhilman Private E-2

    Yes, I still have it installed. I will try again. about your link for Avira before. I try to install it but there is a notification when it run the Setup :
    Avira free antivirus requires at least Win XP 32 bit SP3, win Xp 64 bit SP 2, and win server 2003 SP2 that make I can not install Avira from your link before because my system is Win Xp 32 bit SP 2.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh so that means you must be using an OLD version of Avira which really is not a good idea. Also probably the reason it would not update.

    I notice your PC is also rather old and slow by today's standards and also that you only have about 1/3 of the minimum amount of memory we recommend for running Windows XP. You have only 1 GB. Probably another reason why you have not updated to Win XP SP3 ?? You do realize that SP2 is a security risk!!
     
  11. adzimhilman

    adzimhilman Private E-2

    I have follow the intructions for the Sysfader. Now It run faster, I attached my Mglogs with allowed HijackThis and I have uninstall that junk
    (Movies Toolbar for Firefox (Dist. by Bandoo Media, Inc.)
    Movies Toolbar for Internet Explorer (Dist. by Bandoo Media, Inc.)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay there is still a process from this running: DatamngrCoordinator.exe

    We will remove this below along with some additional leftovers.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dts.search.ask.com/sidebar.html?src=ssb&gct=ds&appid=418&systemid=406
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dts.search.ask.com/sidebar.html?src=ssb&gct=ds&appid=418&systemid=406
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.v9.com/web/?utm_sourc...hiXHTS543216L9A300_090310FB2200VCE2EYZAX&ts=0
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O23 - Service: Datamngr Coordinator (DatamngrCoordinator) - Bandoo Media Inc. - C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe

    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    :Services
    DatamngrCoordinator
     
    :Files
    C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe
    C:\Program Files\Movies Toolbar
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    Your PC will remain slow due to inadequate memory. Your logs show insufficent free memory and when you reinstall an antivirus, it will get worse.
    Code:
    Total Physical Memory 1.024,00 MB 
    Available Physical Memory 160,85 MB
     
  13. adzimhilman

    adzimhilman Private E-2

    It's much better now. I have started to update my windows to SP3. What the reason that make my physical memory low, is that because so much data ? and how to increase a physical memory ?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Beacuse you simply do not have enough memory to run what you are running. You could disable some items from starting at bootup and/or uninstall software that you don't need or don't use. You have to decide these things for yourself. These are not malware issues. Two items I question are the below. Do you know what they are and why you need them:

    O23 - Service: DCSHost.exe - Unknown owner - C:\Documents and Settings\All Users\Application Data\DatacardService\DCSHost.exe
    O23 - Service: Wsys Service (WsysSvc) - Wsys Co., Ltd. - C:\Documents and Settings\All Users\Application Data\eSafe\eGdpSvc.exe
     
  15. adzimhilman

    adzimhilman Private E-2

    After reboot I check the system and the result is
    O23 - Service: Wsys Service (WsysSvc) - Wsys Co., Ltd. - C:\Documents and Settings\All Users\Application Data\eSafe\eGdpSvc.exe
    is still remain.
    Truthfully, I don't know anything about them. I don't know what things that useful for me or not. because I have been given this laptop by my brother.There is another way to make my system run faster ?
    btw Thank you so much for helping me, your intruction is very simple that can make me understand
     
    Last edited: Jul 5, 2013
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes of course it is. We did not attempt to remove it. It is most likely related to the below:

    http://www.safenet-inc.com/data-protection/content-security-esafe/

    But I do not see anything installed related to it.


    Okay but you will have to learn that, because I cannot decide what you use and do not use. I have no idea how you use your PC. Also again this is not a Malware Forum topic. I will help you remove a few items including these two services I question and then after that, you can go to the Software Forum for additional help.

    Do you use Internet Download Manager ?
    Do you use E:\other soft\Athan\Athan.exe ?
    Do you use ChicaPasswordManager ?
    Do you use Pixillion ?

    DO NOT DO ANY of the below if your PC is still in the process of updating to SP3!!!! Wait for it to finish..



    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Services
    WsysSvc
    DCSHost.exe
     
    :Files
    C:\Documents and Settings\All Users\Application Data\DatacardService\DCSHost.exe
    C:\Documents and Settings\All Users\Application Data\eSafe\eGdpSvc.exe
    C:\Documents and Settings\All Users\Application Data\DatacardService
    C:\Documents and Settings\All Users\Application Data\eSafe
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "GrooveMonitor"=-
    "Windows Defender"=-
    "WinampAgent"=-
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    "SunJavaUpdateSched"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. adzimhilman

    adzimhilman Private E-2

    When I try to install SP 3 Pack there's some problem. there is an error, I have attached the screenshot for the error message. I have try to visit the related knowledge based article at
    http://support.microsoft.com/kb/Q327101
    but I don't understand what is boot.ini and the others
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You modified your boot.ini file when you installed those Tuneup utilities. The file now has the below lines in it:
    Code:
    [boot loader]
    timeout=0
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=CQXBN0 /Kernel=TUKernel.exe
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=CQXBN0-BAK
    Microsoft is not happy with this modication and thus will not install SP3. You need to edit the file ( carefully ) and put it back so be the below:
    Code:
    [boot loader]
    timeout=0
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
    That is you delete the line that ends with /Kernel=TUKernel.exe

    And on the next line you need to remove the below text
    (TuneUp Backup)
    /TUTag=CQXBN0-BAK

    Then save the file and reboot.

    Note that the boot.ini file is write protected so you will have to right click on it and select Properties. Then uncheck the Read Only box and click Apply to save the change. Then you will be able to edit the boot.ini file. Make sure you edit it properly to be how I illustrated above in the second code box example.
     
  19. adzimhilman

    adzimhilman Private E-2

    I already update my Xp to SP 3 (I set back the boot.ini by uninstall the custom setting from Tune Up Utility 2008 and then I uninstall that Tune Up Utility 2008). After update to SP 3, I run the OTM and then JTR like the procedur, and I have get the log from C:\Mgtools\getlogs.bat.

    My system run faster after scanning but it will turn to slow again after any minute, even to right-click for refresh it takes any second. that also happen to my mozilla. Can i install an antivirus now ? I already uninstall Pixillion too.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but there is nothing we can do about this here. You are not having malware problems. You need more memory and really an newer style PC with quad core processors to run more modern software more efficiently.

    Yes! We are finished other than doing final instructions.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  21. adzimhilman

    adzimhilman Private E-2

    I already do all your intructions, now I create a new account in my laptop. Thank you so much for helping me. Your help has been invaluable to me and I don't know how I would have managed without your help and support. Again, thank you so much. I sincerely appreciate your generosity :)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds