Virus hampering boot on Windows Vista

Solved/Closed
Report
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014
-
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
-
My laptop Windows Vista opens to a gray screen with the words Microsoft windows Vista at the top and Memory diagnostic tool at the bottom. Memory diagnostic tool said no errors. Ran diagnostic on F12 key -- said no problem. Ran Avast anti virus -- found nothing. The only way to open computer is to select Microsoft Windows Vista -- select Enter and wait through numerous beeps. I got instructions from Ambucias to download ZHPDiag2, start a new topic in virus-security and send the URL from the test.

HTML link<a href="http://speedy.sh/rqd5z/ZHPDiag.txt">Download at SpeedyShare</a>

download link http://speedy.sh/rqd5z/ZHPDiag.txt


I hope this is what you need. It still installed with mostly French so I had to guess a little.

103 replies

Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

Do ZHPFix (the application on your desktop) and we will see after for SpeedCleaner. :)
And yes, you can empty the bin.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

Ok I found a couple more applications I did not want or install. Maybe I can get rid of them later too.

Thanks for your time and assistance
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

Which applications ?

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

Rapport de ZHPFix 2014.3.25.5 par Nicolas Coolman, Update du 25/03/2014
Fichier d'export Registre :
Run by owner at 4/7/2014 5:45:49 PM
High Elevated Privileges : OK
Windows Vista Home Premium Edition, 32-bit Service Pack 1 (Build 6001)

Recycle Bin emptied (03mn AMs)
Prefetcher emptied

========== Software ==========
ABSENT Uninstall Process: c:\program files\reimage\reimage repair\uninst.exe
ABSENT Uninstall Process: c:\program files\speedypc software\speedypc\uninstall.exe

========== Process memory ==========
REMOVES Reboot: Memory Process: C:\Windows\Tasks\SpeedyPC Pro.job
REMOVES Reboot: Memory Process: C:\Windows\Tasks\SpeedyPC Update Version3.job
REMOVES Reboot: Memory Process: C:\Windows\Installer\bc6db.msi
REMOVES Reboot: Memory Process: C:\Windows\Reimage.ini

========== Registry keys ==========
REMOVES:³ Service: ReimageRealTimeProtection
REMOVES: HKLM\Software\Reimage
REMOVES: HKLM\Software\SpeedyPC Software
REMOVES:³ HKLM\SYSTEM\CurrentControlSet\Services\ReimageRealTimeProtection
REMOVES:³ HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair
REMOVES:³ HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{604CD5A1-4520-4844-B064-A3D884B77E91}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
REMOVES:³ CLSID Extra Buttons: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

========== Folders ==========
No folders empty CLSID Local user

========== Files ==========
REMOVES Reboot: c:\users\public\desktop\pc scan & repair by reimage.lnk
REMOVES Reboot: c:\program files\reimage\reimage repair\reimagerepair.exe
REMOVES Reboot: c:\program files\speedypc software\speedypc\speedypc.exe
REMOVES Reboot: c:\program files\reimage\reimage repair\reiguard.exe
REMOVES Reboot: c:\windows\tasks\speedypc pro.job
REMOVES Reboot: c:\windows\tasks\speedypc update version3.job
REMOVES Reboot: c:\windows\system32\websteroids.b324755f3f87.dll
REMOVES Reboot: c:\translate
REMOVES Reboot: c:\windows\reimage.ini
Deletes temporary Windows (61) (2,423,700 octets)
REMOVES Flash Cookies (105) (34,230 octets)

========== System restore ==========
No System Restore Point created


========== Summary ==========
4 : Process memory
11 : Registry keys
1 : Folders
11 : Files
2 : Software
1 : System restore


End of clean in 11mn AMs

========== Path to file report ==========
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R1].txt - 4/7/2014 6:08:53 PM [2753]
I have not yet restarted the computer as I got a message to do so.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

I noticed that PC image and repair was not deleted. It was one the programs that installed themselves without me selecting it. The application worked on deleting it for about 30 min. I checked with Task Manager and it was still running. Finally, it appeared to be finished but the desktop icon at least is still there. I didn't take off the icon because I suspected some the files were still there.

What did the report tell you? I am just curious -- no problems. I have just tried to figure out what is going on.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

Sorry I did not notice your question. PC Image and Repair installed itself as did PCtech Hotline and Speed Cleaner
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

It's OK, ZHPFix did a good work.

Run again ZHPDiag and send the report on SpeedyShare please.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

tried to run ZHPDiag again. I got a message asking me to upgrade to version 2014.4.9.16. My version is 2014.3.2.28.35. Most of the instructions were in French. Oui and Non I could figure out. Then a message box popped with words I could not read and the older version opened. Do you want me to run the older version. If I logged on as admin I might be able to get the newer one if you want that.

Sorry -- I just don't know much French.
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

Otherwise you can try to uninstall ZHPDiag and then reinstall, as the last time.
But you can run the older version still.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

I didn't quite trust myself to deal with a new version. At least I have worked with the older one before so I used it. I hope I did correctly. I clicked on Full options and it ran twice. Here is the result of the first run.

http://speedy.sh/3Zu6u/ZHPDiagapril-10-1.txt
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

http://speedy.sh/U4VaV/ZHPDiagapril-10-2.txt

Here is the second run. I did not click on it twice. It simply ran ran twice and they were different.
What virus are we dealing with anyway?
If I messed up, just tell me and I will do it again.
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

Good.
Try to uninstall Reimage Repair and SpeedyPC Pro.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

I had to log on as admin but I did get them uninstalled. What next?
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

OK good job.

Run again ZHPDiag and send the report please.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

OK Will do.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

http://speedy.sh/YH2Zb/ZHPDiagapril-12-1.txt

http://speedy.sh/aUe5G/ZHPDiagapril-12-2.txt

Here are the two reports that were generated.
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

1. Close all applications

2. Select and copy all lines which are into this link : https://dl.dropboxusercontent.com/u/32869654/For%20ErieE.txt

3. ZHP Diag created a short cut on your desktop called ZHP Fix, launch ZHP Fix (For Windows 7 click right to run as admin. Answer yes if you get an enquiry as to weither you want to run it or not

4. Click on the the Import button and the lines will automatically paste themselves.

5. Click on the Go button to clean

6. Confirm by clicking OK

7. ZHP Fix will ask if you wish to empty the bin, click on your choice...it may take time

8. A report will appear on your desktop and on C:\ZHP\ZHPFix[R1].txt which you can copy and paste in your reply.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

Rapport de ZHPFix 2014.3.25.5 par Nicolas Coolman, Update du 25/03/2014
Fichier d'export Registre :
Run by owner at 4/12/2014 5:48:54 PM
High Elevated Privileges : OK
Windows Vista Home Premium Edition, 32-bit Service Pack 1 (Build 6001)

Recycle Bin emptied (25mn AMs)
Prefetcher emptied

========== Software ==========
REMOVES: Speed Cleaner
ABSENT Uninstall Process: c:\programdata\package cache\{541ac74f-d2f8-4430-9f75-45fae734edac}\speedcleanersetup.exe

========== Process memory ==========
REMOVES Reboot: Memory Process: C:\Windows\Installer\bc6db.msi
REMOVES Reboot: Memory Process: C:\Windows\Reimage.ini

========== Registry keys ==========
REMOVES: HKLM\Software\reimage
REMOVES:³ CLSID Extra Buttons: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}

========== Registry values ==========
REMOVES RunValue: Speed Cleaner

========== Folders ==========
No folders empty CLSID Local user

========== Files ==========
REMOVES Reboot: c:\translate
REMOVES Reboot: c:\windows\reimage.ini
REMOVES Reboot: c:\users\public\desktop\speed cleaner.lnk
REMOVES Reboot: c:\windows\installer\{3a196b37-3f16-40b8-b0d2-e43333acce8d}\guy1.ico
REMOVES Reboot: c:\programdata\microsoft\windows\start menu\programs\speed cleaner.lnk
REMOVES Reboot: c:\windows\installer\{3a196b37-3f16-40b8-b0d2-e43333acce8d}\guy.ico
REMOVES Reboot: c:\program files\speed cleaner\speed cleaner.exe
Deletes temporary Windows (91) (123,687,333 octets)
REMOVES Flash Cookies (0) (0 octets)

========== System restore ==========
No System Restore Point created


========== Summary ==========
2 : Process memory
2 : Registry keys
1 : Registry values
1 : Folders
9 : Files
2 : Software
1 : System restore


End of clean in 40mn AMs

========== Path to file report ==========
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R1].txt - 4/7/2014 5:08:53 PM [2833]
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R2].txt - 4/12/2014 5:49:19 PM [1874]

I hope I did this correctly.
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

Good job. :)

Some problems are persisting ?

Run again ZHPDiag and host the report please.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

http://speedy.sh/7vVGt/ZHPDiagapril-12-second-run.txt

I wasn't sure how you wanted it but it seemed a little long for copy and paste so I uploaded it.
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

OK, run again ZHPFix as the last time but with this lines : https://dl.dropboxusercontent.com/u/32869654/For%20ErieE2.txt

Host the report.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

Rapport de ZHPFix 2014.3.25.5 par Nicolas Coolman, Update du 25/03/2014
Fichier d'export Registre :
Run by owner at 4/13/2014 3:40:33 PM
High Elevated Privileges : OK
Windows Vista Home Premium Edition, 32-bit Service Pack 1 (Build 6001)

Recycle Bin emptied (06mn AMs)
Prefetcher emptied

========== Software ==========
REMOVES: Speed Cleaner
ABSENT Uninstall Process: c:\programdata\package cache\{541ac74f-d2f8-4430-9f75-45fae734edac}\speedcleanersetup.exe

========== Process memory ==========
REMOVES Reboot: Memory Process: C:\Windows\Installer\bc6db.msi
REMOVES Reboot: Memory Process: C:\Windows\Reimage.ini

========== Registry keys ==========
REMOVES:³ CLSID Extra Buttons: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}

========== Folders ==========
No folders empty CLSID Local user

========== Files ==========
REMOVES Reboot: c:\translate
REMOVES Reboot: c:\windows\reimage.ini
REMOVES Reboot: c:\users\public\desktop\speed cleaner.lnk
REMOVES Reboot: c:\windows\installer\{3a196b37-3f16-40b8-b0d2-e43333acce8d}\guy1.ico
REMOVES Reboot: c:\programdata\microsoft\windows\start menu\programs\speed cleaner.lnk
REMOVES Reboot: c:\windows\installer\{3a196b37-3f16-40b8-b0d2-e43333acce8d}\guy.ico
Deletes temporary Windows (20) (261,786 octets)
REMOVES Flash Cookies (0) (0 octets)

========== System restore ==========
No System Restore Point created


========== Summary ==========
2 : Process memory
1 : Registry keys
1 : Folders
8 : Files
2 : Software
1 : System restore


End of clean in 19mn AMs

========== Path to file report ==========
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R1].txt - 4/7/2014 5:08:53 PM [2833]
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R2].txt - 4/12/2014 4:49:19 PM [1955]
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R2]april 12.txt - 4/12/2014 4:53:33 PM [1955]
C:\Users\owner\AppData\Roaming\ZHP\ZHPFix[R4].txt - 4/13/2014 3:40:40 PM [1847]

Here's what I got.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

There's a quarantine file. Do you need that? There are some other files that will not open.
Posts
13334
Registration date
Saturday January 29, 2011
Status
Security contributor
Last seen
December 24, 2016
39
Hello,

No thanks it's OK. :)

Some problems are persisting ?

Run again ZHPDiag and send the report, to see if all is clean.

Gabriel.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

http://speedy.sh/6rUYn/ZHPDiagapril13-second-run.txt

Here is what I got. Speed Cleaner still sticks like glue as a desktop shortcut.
Posts
37
Registration date
Thursday March 27, 2014
Status
Member
Last seen
April 15, 2014

Should I log on administrator when I run these. I have just be logging on as me.