help system working badly

Discussion in 'Malware Help (A Specialist Will Reply)' started by neuma, Apr 7, 2007.

  1. neuma

    neuma Private E-2

    ok tha main proble is that when I'm starting windows it takes a very looong time to start since a few weeks and when it finally ends starting an it has to star showing the desktop it automatically reboot itself...it takes about 3 or 4 reboouts of this kind to finally start windows correctly

    pls help me
    I did almost everything on the malware removal tutorial..and it seems that eliminated a lot of things..the only thing I couldn't perform was the online antivirus issue cause the pc has not internet connection anymore..I run the latest AVG antivirus and it found no problems... I'm writing from a friend pc..

    here is the files and logs I could get
     

    Attached Files:

  2. neuma

    neuma Private E-2

    here are the other ones
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are using a very old version of ShowNew. Please download and use the current version and attach a new log. However note that your problems may not be due to malware. They may be just due to what you are running.

    If you shutdown ZoneAlarm, do you get internet access?

    Uninstall CounterSpy now since we are finished with it!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now also attach a new log from GetRunKey!

    Is it running any better now?
     
  4. neuma

    neuma Private E-2

    here is the new .log you asked for...
    I have no internet connection not beacuase the pc can't do it. it is just because we stop the provider service...cause I'm switching to another one
     

    Attached Files:

  5. neuma

    neuma Private E-2

    A little question.. since i run the fix me you gave me ..I see everything I didn't before..i.e: the system volume folders and a lot of hidden folders...I know it may be useful but is kinda annoying
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were supposed to do that in step 2 of the READ ME. Since you did not do step 2, the fix I gave you included a fix to do it for you. It is the only way to see files hidden by malware. If it bothers you that much, you can go back to step 2 of the READ ME and do the opposite of what it says. We are basically finished anyway since it does not appear that you have any malware to remove.

    Note: you did not attach the follow up log from GetRunKey as requested.
     
  7. neuma

    neuma Private E-2

    yes I did included them in a previous post..in case you don't see it here is again..the new getrnkeys and shownew logs
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not include the log from GetRunKey last time. And in this one it is obvious that you now are using MSconfig to control startups so I will not even be looking at it.

    Are you having any malware problems? If not, , it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. neuma

    neuma Private E-2

    hi..thnx ..my pc is much better now
    but I still havce a problem..spybot still detcts the same files he supposedly deleted in safe mode
    What can I do? I've run your tutorial 3 times but they keep showing up

    I attached a txt with the files it still detects
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Accelerator Plus is not a problem as long as you are using the current version. Older versions were considered adware.
    The HKEY_USERS registry key being found is a minor issue that is not really going to cause you any problems. You can try doing the below but make sure all browsers and other applications are shutdown before running the fix.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds