Virus hampering boot on Windows Vista

Solved/Closed
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014 - Mar 29, 2014 at 07:07 PM
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 - May 14, 2014 at 03:13 AM
My laptop Windows Vista opens to a gray screen with the words Microsoft windows Vista at the top and Memory diagnostic tool at the bottom. Memory diagnostic tool said no errors. Ran diagnostic on F12 key -- said no problem. Ran Avast anti virus -- found nothing. The only way to open computer is to select Microsoft Windows Vista -- select Enter and wait through numerous beeps. I got instructions from Ambucias to download ZHPDiag2, start a new topic in virus-security and send the URL from the test.

HTML link<a href="http://speedy.sh/rqd5z/ZHPDiag.txt">Download at SpeedyShare</a>

download link http://speedy.sh/rqd5z/ZHPDiag.txt


I hope this is what you need. It still installed with mostly French so I had to guess a little.
Related:

103 responses

2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 7, 2014 at 12:56 AM
Hello,

Do ZHPFix (the application on your desktop) and we will see after for SpeedCleaner. :)
And yes, you can empty the bin.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 7, 2014 at 11:54 AM
Ok I found a couple more applications I did not want or install. Maybe I can get rid of them later too.

Thanks for your time and assistance
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 7, 2014 at 01:28 PM
Hello,

Which applications ?

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 7, 2014 at 07:11 PM
Rapport de ZHPFix 2014.3.25.5 par Nicolas Coolman, Update du 25/03/2014
Fichier d'export Registre :
Run by owner at 4/7/2014 5:45:49 PM
High Elevated Privileges : OK
Windows Vista Home Premium Edition, 32-bit Service Pack 1 (Build 6001)

Recycle Bin emptied (03mn AMs)
Prefetcher emptied

========== Software ==========
ABSENT Uninstall Process: c:\program files\reimage\reimage repair\uninst.exe
ABSENT Uninstall Process: c:\program files\speedypc software\speedypc\uninstall.exe

========== Process memory ==========
REMOVES Reboot: Memory Process: C:\Windows\Tasks\SpeedyPC Pro.job
REMOVES Reboot: Memory Process: C:\Windows\Tasks\SpeedyPC Update Version3.job
REMOVES Reboot: Memory Process: C:\Windows\Installer\bc6db.msi
REMOVES Reboot: Memory Process: C:\Windows\Reimage.ini

========== Registry keys ==========
REMOVES:³ Service: ReimageRealTimeProtection
REMOVES: HKLM\Software\Reimage
REMOVES: HKLM\Software\SpeedyPC Software
REMOVES:³ HKLM\SYSTEM\CurrentControlSet\Services\ReimageRealTimeProtection
REMOVES:³ HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair
REMOVES:³ HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{604CD5A1-4520-4844-B064-A3D884B77E91}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
REMOVES:³ CLSID Extra Buttons: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

========== Folders ==========
No folders empty CLSID Local user

========== Files ==========
REMOVES Reboot: c:\users\public\desktop\pc scan & repair by reimage.lnk
REMOVES Reboot: c:\program files\reimage\reimage repair\reimagerepair.exe
REMOVES Reboot: c:\program files\speedypc software\speedypc\speedypc.exe
REMOVES Reboot: c:\program files\reimage\reimage repair\reiguard.exe
REMOVES Reboot: c:\windows\tasks\speedypc pro.job
REMOVES Reboot: c:\windows\tasks\speedypc update version3.job
REMOVES Reboot: c:\windows\system32\websteroids.b324755f3f87.dll
REMOVES Reboot: c:\translate
REMOVES Reboot: c:\windows\reimage.ini
Deletes temporary Windows (61) (2,423,700 octets)
REMOVES Flash Cookies (105) (34,230 octets)

========== System restore ==========
No System Restore Point created


========== Summary ==========
4 : Process memory
11 : Registry keys
1 : Folders
11 : Files
2 : Software
1 : System restore


End of clean in 11mn AMs

========== Path to file report ==========
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R1].txt - 4/7/2014 6:08:53 PM [2753]
I have not yet restarted the computer as I got a message to do so.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 7, 2014 at 07:24 PM
I noticed that PC image and repair was not deleted. It was one the programs that installed themselves without me selecting it. The application worked on deleting it for about 30 min. I checked with Task Manager and it was still running. Finally, it appeared to be finished but the desktop icon at least is still there. I didn't take off the icon because I suspected some the files were still there.

What did the report tell you? I am just curious -- no problems. I have just tried to figure out what is going on.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 7, 2014 at 07:27 PM
Sorry I did not notice your question. PC Image and Repair installed itself as did PCtech Hotline and Speed Cleaner
0

Didn't find the answer you are looking for?

Ask a question
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 8, 2014 at 04:35 PM
Hello,

It's OK, ZHPFix did a good work.

Run again ZHPDiag and send the report on SpeedyShare please.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 9, 2014 at 05:54 PM
tried to run ZHPDiag again. I got a message asking me to upgrade to version 2014.4.9.16. My version is 2014.3.2.28.35. Most of the instructions were in French. Oui and Non I could figure out. Then a message box popped with words I could not read and the older version opened. Do you want me to run the older version. If I logged on as admin I might be able to get the newer one if you want that.

Sorry -- I just don't know much French.
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 10, 2014 at 02:45 AM
Hello,

Otherwise you can try to uninstall ZHPDiag and then reinstall, as the last time.
But you can run the older version still.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 10, 2014 at 04:58 PM
I didn't quite trust myself to deal with a new version. At least I have worked with the older one before so I used it. I hope I did correctly. I clicked on Full options and it ran twice. Here is the result of the first run.

http://speedy.sh/3Zu6u/ZHPDiagapril-10-1.txt
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 10, 2014 at 05:01 PM
http://speedy.sh/U4VaV/ZHPDiagapril-10-2.txt

Here is the second run. I did not click on it twice. It simply ran ran twice and they were different.
What virus are we dealing with anyway?
If I messed up, just tell me and I will do it again.
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 11, 2014 at 09:18 AM
Hello,

Good.
Try to uninstall Reimage Repair and SpeedyPC Pro.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 11, 2014 at 05:50 PM
I had to log on as admin but I did get them uninstalled. What next?
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 12, 2014 at 05:45 AM
Hello,

OK good job.

Run again ZHPDiag and send the report please.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 12, 2014 at 09:30 AM
OK Will do.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 12, 2014 at 10:01 AM
http://speedy.sh/YH2Zb/ZHPDiagapril-12-1.txt

http://speedy.sh/aUe5G/ZHPDiagapril-12-2.txt

Here are the two reports that were generated.
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 12, 2014 at 11:05 AM
Hello,

1. Close all applications

2. Select and copy all lines which are into this link : https://dl.dropboxusercontent.com/u/32869654/For%20ErieE.txt

3. ZHP Diag created a short cut on your desktop called ZHP Fix, launch ZHP Fix (For Windows 7 click right to run as admin. Answer yes if you get an enquiry as to weither you want to run it or not

4. Click on the the Import button and the lines will automatically paste themselves.

5. Click on the Go button to clean

6. Confirm by clicking OK

7. ZHP Fix will ask if you wish to empty the bin, click on your choice...it may take time

8. A report will appear on your desktop and on C:\ZHP\ZHPFix[R1].txt which you can copy and paste in your reply.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 12, 2014 at 06:51 PM
Rapport de ZHPFix 2014.3.25.5 par Nicolas Coolman, Update du 25/03/2014
Fichier d'export Registre :
Run by owner at 4/12/2014 5:48:54 PM
High Elevated Privileges : OK
Windows Vista Home Premium Edition, 32-bit Service Pack 1 (Build 6001)

Recycle Bin emptied (25mn AMs)
Prefetcher emptied

========== Software ==========
REMOVES: Speed Cleaner
ABSENT Uninstall Process: c:\programdata\package cache\{541ac74f-d2f8-4430-9f75-45fae734edac}\speedcleanersetup.exe

========== Process memory ==========
REMOVES Reboot: Memory Process: C:\Windows\Installer\bc6db.msi
REMOVES Reboot: Memory Process: C:\Windows\Reimage.ini

========== Registry keys ==========
REMOVES: HKLM\Software\reimage
REMOVES:³ CLSID Extra Buttons: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}

========== Registry values ==========
REMOVES RunValue: Speed Cleaner

========== Folders ==========
No folders empty CLSID Local user

========== Files ==========
REMOVES Reboot: c:\translate
REMOVES Reboot: c:\windows\reimage.ini
REMOVES Reboot: c:\users\public\desktop\speed cleaner.lnk
REMOVES Reboot: c:\windows\installer\{3a196b37-3f16-40b8-b0d2-e43333acce8d}\guy1.ico
REMOVES Reboot: c:\programdata\microsoft\windows\start menu\programs\speed cleaner.lnk
REMOVES Reboot: c:\windows\installer\{3a196b37-3f16-40b8-b0d2-e43333acce8d}\guy.ico
REMOVES Reboot: c:\program files\speed cleaner\speed cleaner.exe
Deletes temporary Windows (91) (123,687,333 octets)
REMOVES Flash Cookies (0) (0 octets)

========== System restore ==========
No System Restore Point created


========== Summary ==========
2 : Process memory
2 : Registry keys
1 : Registry values
1 : Folders
9 : Files
2 : Software
1 : System restore


End of clean in 40mn AMs

========== Path to file report ==========
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R1].txt - 4/7/2014 5:08:53 PM [2833]
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R2].txt - 4/12/2014 5:49:19 PM [1874]

I hope I did this correctly.
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 12, 2014 at 07:00 PM
Hello,

Good job. :)

Some problems are persisting ?

Run again ZHPDiag and host the report please.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 12, 2014 at 07:14 PM
http://speedy.sh/7vVGt/ZHPDiagapril-12-second-run.txt

I wasn't sure how you wanted it but it seemed a little long for copy and paste so I uploaded it.
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 13, 2014 at 05:11 AM
Hello,

OK, run again ZHPFix as the last time but with this lines : https://dl.dropboxusercontent.com/u/32869654/For%20ErieE2.txt

Host the report.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 13, 2014 at 04:43 PM
Rapport de ZHPFix 2014.3.25.5 par Nicolas Coolman, Update du 25/03/2014
Fichier d'export Registre :
Run by owner at 4/13/2014 3:40:33 PM
High Elevated Privileges : OK
Windows Vista Home Premium Edition, 32-bit Service Pack 1 (Build 6001)

Recycle Bin emptied (06mn AMs)
Prefetcher emptied

========== Software ==========
REMOVES: Speed Cleaner
ABSENT Uninstall Process: c:\programdata\package cache\{541ac74f-d2f8-4430-9f75-45fae734edac}\speedcleanersetup.exe

========== Process memory ==========
REMOVES Reboot: Memory Process: C:\Windows\Installer\bc6db.msi
REMOVES Reboot: Memory Process: C:\Windows\Reimage.ini

========== Registry keys ==========
REMOVES:³ CLSID Extra Buttons: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}

========== Folders ==========
No folders empty CLSID Local user

========== Files ==========
REMOVES Reboot: c:\translate
REMOVES Reboot: c:\windows\reimage.ini
REMOVES Reboot: c:\users\public\desktop\speed cleaner.lnk
REMOVES Reboot: c:\windows\installer\{3a196b37-3f16-40b8-b0d2-e43333acce8d}\guy1.ico
REMOVES Reboot: c:\programdata\microsoft\windows\start menu\programs\speed cleaner.lnk
REMOVES Reboot: c:\windows\installer\{3a196b37-3f16-40b8-b0d2-e43333acce8d}\guy.ico
Deletes temporary Windows (20) (261,786 octets)
REMOVES Flash Cookies (0) (0 octets)

========== System restore ==========
No System Restore Point created


========== Summary ==========
2 : Process memory
1 : Registry keys
1 : Folders
8 : Files
2 : Software
1 : System restore


End of clean in 19mn AMs

========== Path to file report ==========
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R1].txt - 4/7/2014 5:08:53 PM [2833]
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R2].txt - 4/12/2014 4:49:19 PM [1955]
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R2]april 12.txt - 4/12/2014 4:53:33 PM [1955]
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R4].txt - 4/13/2014 3:40:40 PM [1847]

Here's what I got.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 13, 2014 at 04:58 PM
There's a quarantine file. Do you need that? There are some other files that will not open.
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Apr 13, 2014 at 05:29 PM
Hello,

No thanks it's OK. :)

Some problems are persisting ?

Run again ZHPDiag and send the report, to see if all is clean.

Gabriel.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 13, 2014 at 09:32 PM
http://speedy.sh/6rUYn/ZHPDiagapril13-second-run.txt

Here is what I got. Speed Cleaner still sticks like glue as a desktop shortcut.
0
ErieE Posts 37 Registration date Thursday March 27, 2014 Status Member Last seen April 15, 2014
Apr 13, 2014 at 09:57 PM
Should I log on administrator when I run these. I have just be logging on as me.
0