Author Topic: Re: *** URGENT *** Vile viruses that are proving difficult to resolve.  (Read 35801 times)

0 Members and 1 Guest are viewing this topic.

nexar

  • Guest
Re: Do I need to run all the s/w in 'Logs to assist cleaning malware'?
« Reply #45 on: February 19, 2013, 06:27:16 PM »
I've now successfully run FF and IE and MSAccess in SafeMode.

Please help.

Helloooo where are you?

Nexar

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
So safe mode works OK.. This would indicate a conflict with one of the programmes running in normal mode

We will clean boot to see if that resolves the problem I will then try to determine where the conflict is

Step 1: Start the System Configuration Utility

1.Click Start, click Run, type msconfig, and then click OK.
2.The System Configuration Utility dialog box is displayed.

Step 2: Configure selective startup options

1.In the System Configuration Utility dialog box, click the General tab, and then click Selective Startup.
2.Click to clear the Process SYSTEM.INI File check box.
3.Click to clear the Process WIN.INI File check box.
4.Click to clear the Load Startup Items check box. Verify that Load System Services and Use Original BOOT.INI are checked.
5.Click the Services tab.
6.Click to select the Hide All Microsoft Services check box.
7.Click Disable All, and then click OK.
8.When you are prompted, click Restart to restart the computer.

Step 3: Log on to Windows

1.If you are prompted, log on to Windows.
2.When you receive the following message, click to select the Don't show this message or launch the System Configuration Utility when Windows start check box, and then click OK.

Notes?
Quote
You have used the System Configuration Utility to make changes to the way Windows starts.
?The System Configuration Utility is currently in Diagnostic or Selective Startup mode, causing this message to be displayed and the utility to run every time Windows starts.
?Choose the Normal Startup mode on the General tab to start Windows normally and undo the changes you made using the System Configuration Utility.

Do all programmes now work as advertised

nexar

  • Guest
Got to item 7 of Step 2 but I think it's hung.  No activity on screen or disk after clicking OK.  OK button still appears on the screen depressed (like I feel ;))

Man please don't disappear for so long.  Getting a bit panicky at this end.  Don't have your knowledge so I worry about everything.

Thanks for all your help.  Very much appreciated.

Nexar

nexar

  • Guest
Whenever I move the cursor over the 'System Configuration Utility' window I get the hour glass cursor.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
How many items were remaining after the MS services were hidden ?

I am currently switching between 8/7 and XP so there mat be some minor delays

nexar

  • Guest
12 that I can see on the frozen window.  The last visible one is Windows CardSpace.  Of the 12 the following are Stopped:

Adobe Flash Player Upd..
Google Update Service (...
Google Updater Service
Windows CardSpace

the following are showing as Running:

Apple Mobile Device
avast! Antivirus
avast! Firewall
Bonjour Service
Cisco Systems, Inc. VPN ...
EpsonBidirectionalService
EvtEng

The only one that has Stop Pe.... (Pending I presume) is
Google Update Service (...

This particular line is ABOVE the the other 'Google Update Service (...'  that has stopped.

Hope you understand all of this.

Nexar

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
OK close with task manager then restart msconfig, hide MS services and leave the ticks in the Avast services, that is probably the cause of the blockage

nexar

  • Guest
Sorry no.  It hangs after I click OK

There are a bunch of other Services beyond Windows Cardspace.  Quite a few of them are already 'Stopped' but there are still a few running.

I could kill the process again and make a note of all of them if that helps.

Nexar

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Yes please as one of the services is hanging

nexar

  • Guest
Ok Here goes.  These are all of the Service AFTER hiding the MS ones.

Adobe Flash Play Upd...   Stopped
Apple Mobile Device     Running
avast! Antivirus       Running
avast! Firewall        Running
Bonjour Service     Running
Cisco Systems, Inc. VPN  ... Running
EpsonBidirectionalService   Running
EvtEng    Running
Google Update Service (...    Stop Pe...
Google Update Service ( ...   Stopped
Google Updater Service    Stopped
Windows CardSpace   Stopped
iPod Service  Stopped
Java Quick Starter    Running
MBAMSScheduler  Running
MBAMService   Running
Machine Debug Manager Running
Mozilla Maintenance Ser...   Stopped
MySQL   Running
NVIDIA Display Driver Se...     Running
Office Source Engine    Stopped
Pml Driver HPZ12    Running
SonicWall VPN Clien Ser...   Stopped
RegSrvc    Running
Spectrum24 Event Monitor   Running
ServiceLayer    Stopped
STI Simulator   Running
Synergy Client    Running
TeamViewer8    Running
URT Client Service   Start Pe...
VAIO Entertainment Agg...   Stopped
VAIO Entertainment Tas...   Stopped
VAIO Entertainment TV ...   Stopped
VAIO Event Service    Stopped
VAIO Media Integrated ...    Stopped
VAIO Media Integrated ...    Stopped
VAIO Media Integrated ...    Stopped
VAIO Media Gateway Se...   Stopped
VAIO Cooporated Initiali...   Stopped
VAIO Entertainment Upn   Stopped
VAIO Entertainment Dat...  Stopped
VNC Server Version 4    Stopped

OUCH  That was painful.  OK that's the lot that are left after 'Hide All Microsoft Services' is clicked and BEFORE clicking OK.

Thanks again

Nexar

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
avast! Antivirus       Running
avast! Firewall        Running

Leave these two with the tick in and remove the tick from the ones running
Then click OK

nexar

  • Guest
I did that before and it still hung!!  Look back 2/3 posts and you'll see.

Can I run this in Safe Mode?  Maybe that will help.

Let me know.

Where are you from Essexboy?  Are you an English bloke.  I'm a UK citizen as well.  Not born English but lived here most of my life.

Regards

Nexar

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
No the MSConfig does not affect safe mode

Download  Windows Repair (all in one)  from this site

Install the programme then run



Go to step 3 and allow it to run SFC



On the start repairs tab click start


Select the following  items and tick restart system when finished


nexar

  • Guest
Hahaha.... you don't ask for much at 20 past 9 in the night.  I'm going to have to do this in the morning and report back to you tomorrow.

Sorry Essexboy.  I'm very glad for your perseverance but there is a limit to my abilities to concentrate beyond 9 pm

Thanks again and we'll speak tomorrow.

Nexar

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Not a problem my time is yours